43 automatic checks
Every website audited by ConformiteWeb goes through 43 checks covering GDPR compliance, WCAG accessibility, and technical security. Each checkpoint is listed below.
RGPD12 checks
General Data Protection Regulation compliance — cookies, consent, user rights.
Google Analytics without consent
Detection of Google Analytics trackers loaded before consent
RGPDUndeclared third-party cookies
Verification of non-consented or undeclared third-party cookies
RGPDPrivacy policy present
Existence and compliance of privacy policy
RGPDRight to access data
Validation of access rights and CNIL request mechanisms
RGPDRight to be forgotten
Verification of data deletion procedures
RGPDData retention duration stated
Clear mention of retention periods by data type
RGPDLegal basis explicit
Justification of legal basis for each processing
RGPDThird parties declared
Complete list of processors and partners
RGPDDPA signed with vendors
Data processing agreements in place
RGPDInternational transfers validated
Legal mechanisms for non-EU transfers
RGPDLegal notices compliant
Mandatory publisher information present
RGPDDPO contact visible
Data Protection Officer contact information
RGPDAccessibilité18 checks
Web accessibility according to WCAG 2.2 criteria — contrasts, keyboard navigation, ARIA, readability.
Text contrast (WCAG AA)
Minimum contrast ratio 4.5:1 for text
AccessibilitéGraphic contrast (WCAG AA)
Minimum 3:1 ratio for graphical elements
AccessibilitéComplete keyboard navigation
Access to all features via keyboard
AccessibilitéLogical tab order
Focus follows natural reading order
AccessibilitéFocus visible
Clear indication of focused elements
AccessibilitéExplicit labels
Form fields properly labeled
AccessibilitéARIA required
ARIA attributes present where needed
AccessibilitéARIA hidden appropriate
Correct use of aria-hidden
AccessibilitéNo focus trap
Keyboard not restricted in modals
AccessibilitéImage alt text
Descriptive alt text for all images
AccessibilitéVideo captions
Captions or transcripts available
AccessibilitéAudio description
Audio description for complex video
AccessibilitéNot color alone
Information conveyed without color dependency
AccessibilitéNo flashing content
Nothing flashing more than 3 times/sec
AccessibilitéResponsive at 200% zoom
Functional without loss at 200% zoom
AccessibilitéTarget size 44×44px minimum
Buttons and interactive elements large enough
AccessibilitéPage language declared
Lang attribute on <html>
AccessibilitéNo auto redirect
Redirects controlled by user
AccessibilitéSécurité13 checks
Technical website security — HTTPS, HTTP headers, protection against common attacks.
HTTPS enforced
Transport encryption enabled
SécuritéHSTS header present
Strict-Transport-Security configured
SécuritéContent Security Policy
CSP header properly configured
SécuritéX-Frame-Options
Clickjacking protection
SécuritéX-Content-Type-Options
MIME sniffing prevention
SécuritéNo inline scripts
Scripts loaded from external files
SécuritéNo eval()
Dynamic code avoided
SécuritéCSRF tokens on forms
CSRF attack protection
SécuritéNo sensitive errors
Generic error messages in production
SécuritéNo source maps
Debug files not served
SécuritéDependencies updated
No known vulnerable packages
SécuritéNo SQL injection
Parameterized queries only
SécuritéSensitive data encrypted
Encryption at rest for sensitive data
SécuritéLaunch your audit in 60 seconds
Check your website's compliance with all 43 checkpoints for free.
Start free audit