Open Source MIT License

Scan any website for compliance issues in 60 seconds

65 rules across GDPR, WCAG 2.2, security, and transparency. One command. HTML, JSON, CSV, SARIF, and PDF reports. Built for CI/CD.

$ npx complytest scan https://your-site.com

65 rules across 4 compliance categories

Every rule includes rationale, evidence collection, and remediation hints. Built on real regulatory requirements.

Consent & Privacy

19 rules

GDPR Article 7 consent, cookie enforcement, banner validation, Google Consent Mode v2, consent withdrawal, granular tiers, and DSA dark pattern detection.

GDPR ePrivacy EDPB TCF 2.2

Accessibility

21 rules

All 9 WCAG 2.2 new success criteria, color contrast, ARIA validation, keyboard navigation, focus management, target size, accessible authentication, and consent banner accessibility.

WCAG 2.2 EAA ADA

Security

19 rules

CSP headers and quality, HSTS, HTTPS enforcement, secure cookies, Subresource Integrity, COOP/COEP, Permissions-Policy, CORS, TLS version, and certificate expiry.

OWASP PCI DSS CSP

Transparency

6 rules

Privacy policy presence, terms of service, data controller identification, contact information, complaint mechanisms, and ad disclosure.

DSA GDPR Art 13 FTC

Reports in every format you need

Generate compliance reports for your team, CI/CD pipeline, or regulatory filings.

HTML

Interactive dashboard with charts and drill-downs

JSON

Machine-readable for CI/CD and API integrations

CSV

Spreadsheet-ready for compliance teams

SARIF

GitHub Security tab integration

PDF

Shareable reports for stakeholders and auditors

How it works

1

Install

No configuration needed. Run directly with npx or install globally.

2

Scan

Real browser testing with Playwright. Detects cookies, consent banners, accessibility issues, and security headers.

3

Report

Get a detailed compliance score with category breakdowns, failing rules, and remediation hints.

$ npx complytest scan https://example.com
 
Results for https://example.com
Scanned in 4.2s
 
  Score: 72% (47/65 rules passed)
  consent          WARN  14/19
  accessibility    PASS  19/21
  security         FAIL  8/19
  transparency     PASS  6/6
  18 failing rules:
    - consent.cookies_before_consent: 8 non-essential cookies
    - security.hsts: Missing Strict-Transport-Security header
    ...

Need continuous monitoring?

Complicer is the managed platform built on ComplyTest. Automated daily scans, team routing, SLO monitoring, Jira integration, and legal-grade audit trails.