Inclusive ForgeCheck my storefront

Last updated 31 August 2026

How the audit works

Six routes, three widths, a ruleset written for WooCommerce, and a journal that records what happened in order. Here is each step, and what it costs you.

One: you prove the shop is yours

We do not scan a storefront past three pages until its owner has confirmed they own it. Proof is a DNS record or a meta tag, whichever is easier for you, and our companion plugin can place the meta tag for you.

This is a deliberate limit, not a formality. A scanner that audits any address on request is a scanner that can be pointed at a competitor, and we would rather be an auditor.

Two: we walk the buying path

Not a crawl of your whole site. We open the home page, a category, a simple product, a variable product, search, the cart, the checkout up to the payment step, the account page and a missing page, in three viewport widths.

The checkout is walked as a buyer walks it: an item goes into the cart, and the form is filled as far as the payment step. Most generic scanners never see this page, because it needs a session to exist.

Three: the rules run

Every rule is a deterministic function over a snapshot of the page. It names the element it fired on, the WCAG success criterion it maps to and the matching clause of EN 301 549, so a finding can be checked by someone who does not trust us.

Eight rules are written for WooCommerce specifically: labels and autocomplete on checkout fields, payment errors that are never announced, variation swatches that the keyboard cannot reach, quantity steppers with no name, cart updates that happen in silence, coupon results shown only in colour, and required fields marked only by a theme class. Seven more apply to any storefront.

A page that will not render inside the time budget is marked as skipped and named in the report as needing a manual check. It is not silently dropped: a page nobody looked at must not read as a page that passed.

Four: you get the fix, not just the finding

A finding without a fix is homework. Each one comes with the change to make, and for the common themes we ship the snippet. Fixes go into your theme and your templates, never into a script that repaints the page in the browser.

Five: the journal records it

Found, assigned, fixed, re-tested: each one is a line in an append-only journal, and each line carries the hash of the line before it. Change a date afterwards and every hash below it stops matching, which is the whole point.

The export is a printable folder: what was checked, what was found, what was done, when, with a screenshot before and after. It is the thing you hand over when someone asks what you did.

What this does not cover

  • An automated scan finds part of what WCAG asks for. The report says which part, and names the source for that figure.
  • We do not audit PDF invoices, mobile apps or anything outside the storefront.
  • We do not write your legal documents. We generate a statement from your own results for your adviser to review.