Is your client's site accessible?
Paste an address and Curbcut fetches that page plus a few linked pages on the same site, runs a fixed set of WCAG 2.2 checks on the HTML, and hands back a scored, prioritised report in plain English. Every finding names the rule it breaks, explains who it hurts, and gives you the exact code to paste in — so the fix takes minutes rather than a specialist audit.
Honest limit: Curbcut analyses the HTML your server sends. It cannot see anything a browser draws later with JavaScript — carousels, cookie banners, embedded widgets — or content inside a canvas, so pages that rely on those can score better here than they deserve. And when a check cannot judge a page — an unreadable stylesheet, a background it cannot prove — the scan skips it rather than guess, so the report names every check it could not run and why, next to the score. Password-protected staging links (https://name:secret@host) work: the sign-in is used only for that host and never shown anywhere in the report.
The 14 checks this scan runs
- Images with no alt attribute at all (WCAG 1.1.1 A)
- Page language is not declared (WCAG 3.1.1 A)
- Missing or empty page title (WCAG 2.4.2 A)
- More than one top-level heading (h1) (WCAG 1.3.1 A)
- Skipped heading levels (WCAG 1.3.1 A)
- Form fields with no label (WCAG 3.3.2 A)
- Links with no accessible name (WCAG 4.1.2 A)
- Buttons with no accessible name (WCAG 4.1.2 A)
- Links whose text is only "click here" / "read more" / "learn more" (WCAG 2.4.4 A)
- Embedded frames (iframes) with no title (WCAG 4.1.2 A)
- Data tables with no header cells (WCAG 1.3.1 A)
- Viewport tag blocks pinch-zoom (WCAG 1.4.4 AA)
- Text too low-contrast against its background to read easily (WCAG 1.4.3 AA)
- Keyboard focus indicator removed by CSS (WCAG 2.4.7 AA)
Contrast is judged from the colours the served HTML declares, including the page's external stylesheets — same host or a public CDN host — with their unconditional @imports followed up to a small cap. Text coloured by a script, a CSS variable the scan cannot trace to a plain colour, or a stylesheet beyond those caps is skipped rather than guessed at — and so is any pair whose background is a declared colour the scan cannot prove: such a background suppresses the pair instead of being measured against a guessed backdrop. Where the page loads a runtime stylesheet generator (the Tailwind CDN script), its bg-* utility classes are treated the same way. Findings are judged under the default (light) colour scheme: dark-scheme overrides are not judged — a (prefers-color-scheme: dark) block is dropped like a print stylesheet, so it can neither produce a finding nor shadow the light-mode values where the scan can read the rule that applies them. Focus visibility is judged from the same served CSS: a keyboard focus indicator the page provably removes — outline: none, a zero-width or a fully transparent outline — is reported unless a :focus or :focus-visible rule draws a provable replacement (an outline, box-shadow or border with a resolvable, non-transparent colour and a non-zero size). A background change on focus is not proof of an indicator, an all: unset reset cannot be settled, and focus styling a runtime stylesheet generator (the Tailwind CDN script) compiles in the browser is invisible here — those are skipped, not guessed at. Keyboard trap order and deeper ARIA checks are not in this version. It scans the served HTML, not a rendered browser.