Release — v0.9.12
Overview
Release v0.9.12 covers the second half of August, and most of it is about making the site do what it says. The Analyzer can now audit pages on other sites — and whole sites, up to 24 pages a run — by loading them in a real browser on our servers, and it charges only for work that came back. The money path was audited end to end: Artisan is the one plan on sale, it is sold to a verified account, no GST is added, and the tokens a plan includes now actually arrive. The portfolio builder becomes a product of its own that can publish to auricartisan.com/p/your-handle, the account dashboard is rebuilt in four sections, and the contact page routes messages to the right inbox with a reply time for each. Underneath all of it, the whole site moved to one design, and a long list of accessibility failures — many of them caught by the site’s own engine — were fixed.
1. Highlights
+- The Analyzer can now audit pages on other sites: a real browser on our servers loads the page and runs the full accessibility engine, so contrast and target sizes are measured rather than guessed.
- Scan Site works in production. It crawls up to 24 pages a run, reports progress page by page, and scores the site on its mean rather than on its home page.
- You are charged only for work that came back. A page that fails to load, times out or is refused costs nothing, and a crawl is billed per page actually audited.
- Artisan is the plan on sale, as a one-time pass that does not auto-renew. Specialist and Industrial Pro are marked Coming soon and cannot be bought.
- A purchase now needs a signed-in account with a verified email address, so what you pay for belongs to your account rather than to one browser.
- No GST is added at checkout. Auric Artisan is not GST-registered, so the price shown is the total.
- The tokens a plan includes are now granted when you buy or renew it. Before this release, nothing did that automatically.
- The portfolio builder moved to /portfolio/ and can publish to
auricartisan.com/p/your-handle, with a QR code, its own themes and accents taken from your own palettes. - The account dashboard is four sections, with a device list that marks the session you are in and a danger zone that asks for your password again.
- The contact page routes seven topics to three inboxes, states a reply time for each, and takes screenshots you can draw on.
- The whole site moved to one design — homepage, header, footer, right-click menu, dropdowns, pricing, legal, documentation and article pages.
- Added a contrast checker, a contrast map in the accessibility library, a 50-check WCAG 2.2 checklist, and API endpoints for the five colour collections.
- The site no longer downloads an offline copy of itself in the background. It does that when you ask.
2. The Analyzer scans other sites, and whole sites
+Until this release the Analyzer ran entirely in your browser, and a browser cannot fetch a page on another site — CORS forbids it. The plans listed URL analysis that, for most addresses, could not run. It now can. When you are signed in and analyse an address, a headless Chromium on our servers loads the page, runs the same accessibility engine the Analyzer uses everywhere else, and returns the audit together with the rendered page. Your browser then runs the rest of the analysis over that page exactly as it always has, so a report reads and scores the same whether the work happened in your tab or on a server.
The split is deliberate. Contrast, APCA and target sizes only exist once styles are resolved and the page is laid out; a parsed copy of the HTML reports defaults for all three, which reads as “no contrast problems”. So those measurements come from the real browser, and the Analyzer applies them last so that nothing computed afterwards can replace a measurement with a guess.
Scan Site. Whole-site scanning works in production. The server discovers same-origin links, renders each page in a real browser and streams results back one page at a time, so the progress panel counts completed, failed and found pages as they happen instead of sitting at zero for two minutes. The headline score is the mean across the pages scanned — a report on the home page alone would hide exactly the pages the scan was run to find. A page that fails to render is recorded and skipped rather than ending the crawl. Crawls are capped at 24 pages a run; that is a decision about the cost of browser time, not a limit of the engine, and the Pages field now reads the current cap from the server instead of offering a maximum the server would not honour.
| Plan | Single-page analysis | Whole-site scan |
|---|---|---|
| Apprentice (free) | 20 URL analyses a month | Not included |
| Artisan | 250 pages analysed a month — one token per page, from the 250 tokens the plan includes | Up to 24 pages a run |
| Specialist, Industrial Pro | Coming soon — not on sale in this release | |
When you are charged. Both meters — the monthly allowance and tokens — are written after the browser returns a report. A page that fails to load, times out, or is refused costs nothing; a crawl that discovers twenty pages and renders fourteen is a fourteen-page charge. Your allowance is checked before a browser opens, so being over it is answered in milliseconds rather than after a fifteen-second scan. And if recording the charge fails, you still get your report.
Reports you can trust. Getting a remote scan to run exposed a number of places where the report was wrong, and all of them are fixed:
- One report, one score. The score ring and the summary sentence beside it could name two different numbers; the summary is now rebuilt whenever the score is.
- The single-page scan had been running only a sliver of the rule catalogue. It now runs the full catalogue, the same as Scan Site, and a rule filter that matches nothing can no longer produce a clean-looking report.
- The security audit now sees the response headers the page was actually served with. Before, every server-scanned site was graded as sending no security headers at all.
- The contrast grader reads modern colour values —
color(srgb …), percentage and slash-separatedrgb(), and alpha — instead of misreading most of them. - A missing
altattribute and a deliberate decorativealt=""are no longer treated as the same thing, which had been costing correctly marked pages points. - The Performance card uses the timings of the real load (time to first byte, DOMContentLoaded, load, first contentful paint, transfer size) instead of saying “Lab estimate” while holding measurements.
- The page-by-page breakdown shows each page’s title, scores and findings rather than dashes and
[object Object]. - The A11y+ card leads with the engine’s impact-weighted score, and criteria that were not tested stay “not tested” instead of counting as passes.
The exported report. The export is now roughly three times as complete. Each of its thirteen scoring categories explains what it measures, how it is scored, what its bands mean and how to fix a low score. A category that was not measured says “Not scored” rather than printing 0, and a run that measured nothing can no longer print a conformance claim on its cover. Markdown reports escape content from the scanned page. The export code loads only when you press an export button, so the Analyzer page got lighter while the report got larger. The new documentation article Understanding your accessibility report explains scores, severity, and what WCAG conformance actually claims.
Sites that turn scanners away. The scanner presents as the Chromium it is and identifies itself through X-Purpose and From headers, rather than through a user-agent string that naive bot filters block on sight. It waits for the page to load rather than for the network to go silent, which never happens on a site running analytics or a chat widget. A refusal (403 or 429) is retried once as a phone. Sites behind an active bot challenge or a login still cannot be scanned remotely, and the message says so and suggests auditing from a browser already on the page.
Refusals are not failures. Signed out, out of allowance, or on a plan without the feature, the Analyzer now says which — with a Sign in or See plans button — instead of “Couldn’t reach the target” above a list of internal strategies. Advice to run npm run analyzer, meant for a developer on their own machine, no longer appears on the live site.
3. Buying a plan: what is for sale, and what changed
+The purchase path was audited end to end in this release and corrected wherever the site said one thing and the code did another. The short version: one plan is on sale, it is sold to an account, the price you see is the price you pay, and what you buy now arrives.
Artisan is the plan on sale. Specialist and Industrial Pro now carry a Coming soon label. Their prices and features stay on the pricing page, because they show where the product is going, but they cannot be bought: the buttons are withdrawn, and every server path that can start a purchase refuses them, so hiding a button is not the only thing standing between a visitor and a tier that is not for sale. The “Most Popular” badge that sat on Specialist is gone; Artisan’s card says “Available now”, which is something you can check.
An account first, with a verified address. A purchase now needs a signed-in account whose email address has been verified. Before, a guest could pay and the plan was recorded only in that browser’s storage — clearing site data or opening the site on a phone lost something that had been paid for. Separately, an account that had not yet clicked its verification link could pay and then read as free everywhere. Both are closed. If your address is not verified yet, checkout says so and offers to resend the link rather than failing at the moment of payment.
A pass, described as a pass. Artisan is one payment for the term you pick, and it does not renew automatically — there is no subscription to cancel. The dashboard used to describe a new plan as “cancelling” minutes after someone paid; it now reads “active until [date]. Does not renew automatically.” The end-of-plan control is shown to every paying customer and offers a refund request where there is no future charge to cancel. Refunds follow the 7-day window in the refund policy.
No GST. Auric Artisan is not GST-registered, so no GST is added or collected: the price shown is the total, and receipts are payment receipts rather than tax invoices. The subscription and billing policy said this correctly, but two code paths had been adding 18% to orders from India regardless. They now read the setting that says tax collection is off, and the advertising page no longer prints a GST line either.
Tokens that arrive. The tokens included with a plan were never granted by buying or renewing it — only a manual claim button did that. Fulfilment now grants them, once per plan and billing period, so a payment notification delivered twice cannot grant them twice. Tool tokens are spendable on our servers for the first time, and are charged only for work that runs there. The free plan’s 100 starter tokens no longer lock it out of its 20 monthly analyses once they are spent. And the token bar now quotes what your account will actually be charged; it had been quoting a different, dearer model than the one that charged you.
Copy that matches the product. Several surfaces were selling things that did not exist, and each was corrected rather than reworded:
- “Unlimited analyses” on Artisan is now “250 pages analysed a month”, and “full-site crawls” says “up to 24 pages a run”. Vision simulations, which run in your browser, remain unlimited and are now stated separately.
- Artisan no longer grants cloud sync and version history, which its own description lists as coming soon, and those two no longer appear in upgrade prompts as reasons to buy it.
- An upgrade prompt for a feature that no buyable plan carries now says “Not available yet” and links to the roadmap, rather than selling a plan that would not unlock it. The prompt’s “14-day free trial” and “30-day money-back” lines are gone: there is no trial, and the refund window is 7 days.
- The accessibility compliance page offered a “Team” plan that never existed. It now shows the same plan cards as every other pricing surface.
- API credit packs are no longer offered to accounts whose plan cannot spend them. An existing balance is unaffected.
- The advertise page now describes what happens: a campaign is booked by request, nothing is charged on the page, and a payment link follows once we have confirmed it.
- A note beside the prices names the merchant, the currency you are charged in, and what a declined international card means.
The receipt. The payment confirmation page now carries the site’s header and footer, shows the date you paid, and keeps its order reference copyable even if a stylesheet fails to load. An old checkout test page with a free-text amount field was removed from the site.
4. Portfolios get their own builder and an address
+The portfolio builder was an account setting three clicks into the dashboard. It is now a product at /portfolio/: a toolbar that stays in view so Save and Publish follow you down a long document, an editor and a live preview that scroll independently, a section palette that opens when you want it and closes when you pick, and a workspace that uses the whole window on wide screens. The dashboard keeps a card that asks the server whether your page is live and links to it.
An address, not only a link. The snapshot link is kept: it packs the whole document into the link itself and needs no account, no server and no connection. Publishing adds the other option — auricartisan.com/p/your-handle, showing whatever you published last. Publishing is two screens. The first offers addresses built from the name already on your account, checks them against the same reserved list the server enforces, and shows the share card beside your choices. The second leads with the address, a working QR code, and whether what is live matches what you are looking at, with a republish offer when it does not. Taking the page down frees the address immediately.
The page is yours to design. A new Style pane sets the typeface pairing, the paper, the rhythm and the accent. The theme travels inside the document, so it applies to the preview, the published page and every export at once. Accents come from palettes you have saved in the Universal Library, and each is graded against the paper you chose: those that clear 4.5:1 are offered plainly, the rest are dimmed with their ratio in the title. The default accent was brand gold, which measures about 2:1 on the portfolio’s own cream paper, so published portfolios had been shipping links below AA; it is now a darker gold that clears 4.5:1.
A header of its own. Name, email, location, website and avatar are now the page’s own fields. Left blank, each follows your profile; switched off, it is left out of the published page — so the address you signed up with no longer rides along on a page where you chose a different one. Double-click the avatar to pick a picture from your computer: it is re-encoded to a 320-pixel square WebP (a 587 KB PNG became about 4 KB) and its metadata is stripped, because a portfolio is a public page. Real avatars now appear on published pages; before, photos were quietly dropped and the initial shown instead.
Pictures and Markdown. Images in Markdown sections now load from the open web on this page, and link and image destinations accept titles, balanced parentheses and the <angle> form instead of falling out as literal text.
The draft follows your account. The draft is still saved locally on every keystroke, and a signed-out builder makes no requests at all. Signed in, it is now also saved to your account, so it is there on another device. Reconciling the two never replaces real work with a fresh starter document and never overwrites the document you are typing in. Account sync for drafts ships in this release; if the account service has not picked it up yet, the builder notices once and carries on locally.
5. The account dashboard, rebuilt
+Seven account sections were four sections wearing seven names — billing appeared three times and security was split across two tabs. The dashboard is now Overview, Profile, Plan & Usage and Security & Privacy. Old links such as #billing, #api-keys, #settings and #sessions still land in the right place.
- Overview opens with a statement of your plan and usage, then the work you have saved, then at most three next steps. A step is offered only when the account is known not to have done it — the page had been telling people with two-factor already on to turn it on — and each can be dismissed. Saved items are captioned with their colours, so four palettes saved in one session can be told apart.
- Plan & Usage reads as a statement rather than a shop: billing first, the plan switcher folded to one line naming your tier, and the API console drawn only for a plan that includes the API or an account that still holds keys. Panels with nothing to show are not drawn, and the plan badge and the sentence beside it can no longer name different plans.
- Security & Privacy is a device sheet: a readout of two-factor, backup codes and password age, then a table of signed-in devices that marks the session you are reading it in, so you are no longer offered a Revoke button for yourself. iPhones are listed as iOS rather than macOS. The analytics opt-out saves itself.
The danger zone asks again. A signed-in browser is the wrong standard of proof for erasing an account — a closed lid or a borrowed laptop is enough to have one. The danger zone now opens only after you type a confirmation sentence and your account password, stays open for five minutes with a countdown and a Lock now button, and is enforced on the server rather than only in the page. The grant belongs to the session you unlocked, not to the account, and unlock attempts are limited to five in fifteen minutes. Inside, it holds only the two things that cannot be undone — erasing this browser’s saved workspace, and deleting the account — and each still asks for its own typed word. The reversible controls that used to sit there live in the sections they belong to. If the server cannot answer, the zone says it is unavailable rather than telling you your password was wrong.
In Hindi. The dashboard is now translated throughout; the only English left is your own name, handle and address. Dates follow the site’s language rather than the browser’s, and the Hindi delete confirmation, which had been reading as nonsense, is correct.
6. Contact, feedback and replies
+The contact page was a form wearing a document’s layout. It is now a form: pick a topic from three cards grouped by the inbox they reach, and the page adjusts what the reference field asks for, the reply time, and the answers offered beside the form that might save you writing at all. A link can pre-select a topic, such as ?topic=billing.
| Topic | Inbox | Reply time |
|---|---|---|
| Billing | hello@ | 1–2 days |
| Using a tool | hello@ | 2–3 days |
| Something else | hello@ | Up to a week |
| A bug | developer@ | 2–4 days |
| API or integration | developer@ | 2–4 days |
| Security | security@ | Within 48 hours |
| Privacy or data | security@ | Within 30 days |
The reply times are ones a small team can keep, and the page says plainly that messages are read and answered by a person — no ticket queue, no bot. The form sends a topic, never an address: the mapping from topic to inbox lives on the server, so the form cannot be used to make our domain send mail to someone else. The Security topic carries a notice asking you not to paste a working exploit into a web form, with a link to the disclosure process.
- A writing surface. The message box takes bold, italic, inline code, lists, code blocks and links, and is sent as plain text, so a pasted stack trace arrives intact. The link prompt belongs to the page and refuses
javascript:,data:andfile:addresses. - Screenshots. Attach up to four images by button, paste or drop. They are downscaled to 1600 pixels in your browser and sent as attachments. Click one to draw on it — pen, highlighter or box, four colours, undo — because “look here” is most of the reason anyone attaches a screenshot.
- An acknowledgement. You now get an email confirming your message arrived, quoting your own words back — the only copy you have, since the form keeps none. A retried submission sends nothing twice. Replies from us arrive in the same email design as the rest of the site’s mail.
Feedback, everywhere. Feedback used to be reachable only from inside the Feature Kit. It can now ask on any page once you have spent real time there, and it comes back — but no sooner than a week later on that device, a fortnight after a dismissal and three months after you have sent something. It never asks on sign-in, checkout, payment or legal pages, “Don’t ask again” is permanent, and none of it loads until it opens. Bug reports and surveys are modes of the same panel. A bug report records the page, viewport, platform, language, theme and recent console errors itself, and the follow-up question adapts to the rating you gave. Drafts survive closing the panel for a day.
Contact details are optional, and asked for afterwards. After your rating and comment, the panel asks whether you would like us to be able to reply. “Add contact details” and “Send anonymously” are the same size and weight, and neither is pre-selected. Name and email are each optional. The server keeps contact details only when you went through that step, stores what they are for, and never subscribes anyone to anything; the confirmation email you receive promises no reply and no fix.
7. One design across the site
+This release moves the site onto one design system: one set of colour tokens with measured contrast pairs, one type scale, and one rule for gold — it marks where you are and the one action that matters, and it never carries small text on a light surface. Each piece was built as a sample, audited in both themes by the site’s own accessibility engine, and then shipped.
- Homepage. One field does two jobs: an address runs the Analyzer, words search the site, and the field says which it is about to do. Beside it, a live contrast demo computes WCAG grades as you pick two colours, and a working workflow turns one seed colour into a tonal scale, previews it under colour-vision simulation, and exports tokens as CSS, Tailwind or JSON. Colour of the Day now carries its full sheet, and the tool browser’s cards are in the page itself.
- Header, footer and bands. The header’s menus sit beside the brand, each tool button has its own visible edge, and nothing in the bar casts a shadow. The footer is about half its old height and gains a Product column — Tools, Learn, Blog, API, Download — so the bottom of every page leads back into the product. The announcement and quick-link bands stopped scrolling content that already fitted.
- The clock. The clock strip is now available on every page and off by default; turn it on in Settings → Highlights → Clock strip. It also stopped announcing the time to screen readers once a second.
- Right-click menu. Back, forward, reload and home are a strip of four; everything else sits behind a type-to-find field. The menu is keyboard-operable for the first time: the field takes focus, arrows move, Enter runs, Escape closes.
- Dropdowns. Every select on the site shares the header menu’s look, and lists of six rows or more get a search field. Arrow keys no longer skip the first option, and typing returns you to the search field.
- Search, the command palette and the guide. They now share one look, and their emoji icons are replaced by drawn icons that follow the theme. The command palette parses commands, answers colour queries, explains why a result ranked where it did, and no longer shows ads. The guide opens by saying what the page is, states how many stops its tour has, and remembers per page where you got to, offering to resume.
- Settings. The panel is wider with a section rail, because seven tabs did not fit on one line and the last one was cut off on every open. The Comfort section gains a Custom cursor switch, and the custom cursor’s ring now actually reaches the pointer instead of trailing behind it.
- Collections. Collections opens with three numbered “Start here” picks, each saying what the tool does. Cards lead with the category and carry the tool’s description, the grid loads more as you scroll (the Load more button still works without JavaScript), and there is one search instead of two.
- Pricing. The pricing page groups its sections into four bands under a sticky outline that marks where you are and carries the buy button. The comparison table is open rather than folded, and the plan cards sit four across.
- Legal and company pages. Across 22 pages, every section is open (folded legal text defeats Ctrl+F), a sticky outline tracks your position, the print button is gone in favour of the browser’s own, and related-page cards use drawn icons instead of emoji.
- Security page. /security/ gains the same outline and design. Three claims that were not true of how the site is run — scheduled key rotation, separation of duties, verified backups — were removed; specifics a technical reader can evaluate were added, including PBKDF2-SHA256 password hashing at 600,000 iterations, API keys stored as hashes and shown once, a payments section, and a list of what we do not claim.
- Download, Extension and VS Code pages. /download/, /extension and /vscode/ are now one design. The download page leads with whether your browser is ready to work offline. The browser extension is now listed on the Chrome Web Store and Firefox Add-ons, and its page describes the permissions the install prompt actually asks for. The VS Code page lists exactly what is published on the Marketplace, each with a real install link.
- Company timeline. The timeline reads downward instead of scrolling sideways, and every step shows what it contained without a click.
- First visit. The splash finishes in about a second instead of three, and the cookie notice is a bar at the bottom of the screen rather than a dialog over a blurred page. A blurred overlay that flashed for a moment on every page load is gone.
8. Documentation, Learn, Blog and the Changelog
+Documentation. The documentation index is organised by subject, with a User Guide and a Developer Reference as the two things you can do with each, plus search and an audience filter. It is served as real HTML, so it works without JavaScript and search engines can read it. Articles no longer collapse into accordions — reference is read in order and searched with Ctrl+F — and every article leads with the same facts: which of the pair it is, when it was updated, how long it takes to read, and who wrote it. A switch jumps to the other half of the pair. Headings read as sentences, long identifiers wrap at sensible points and stay copyable, tables stack into labelled rows on phones, and documentation carries no advertising.
A reading frame for articles. Learn, Blog and Changelog articles had been wearing the legal-document layout, which folded blog posts and release notes behind section toggles. All three now share one reading frame: nothing folds, a contents rail marks the section you are in, code reads as part of the sentence, and the byline names the author, with a card saying who he is when you hover or focus it. Every article now names a person as its author, backed by an author page that claims only what the site can show.
Learn is a course. Learn had been listing its articles newest first, which put the article written to be read first at the bottom. It now lists them in their numbered order, one row each, with what the article covers, how long it takes and a tick for ones you have read — read from your own history on this device. Articles open on the writing rather than a splash screen, and every one now links to the tool that does what it explains. Inside articles, the interactive demos give their display the whole panel with readouts beneath it, their controls are readable on a light page, the definition cards read as a numbered chain, the quick quiz has proper buttons, and “Continue your journey” is a list in the library’s own style.
Blog and Changelog. The blog is a reading page that gives the newest post the room and opens on its own first paragraph. The changelog is a timeline, newest first, with each release opening in place — and its search reads the changes themselves, so a question like “when did overage arrive?” finds the release that says so.
9. Accessibility tools, libraries and fixes
+- Contrast checker. The contrast checker the site had been advertising now has a page of its own at /tool/contrast-checker/: the ratio, AA and AAA grades for body text, large text and interface elements, a live preview, a one-click fix, and a shareable
?fg=&bg=link. The short address/contrast-checkernow opens it rather than the Analyzer. - A contrast map. The accessibility library now leads with the question the old list could not answer: fix a background, and what may you write on it? A map of hue against OKLCH lightness shows the passing region, with the AA and AAA thresholds drawn as contour lines. Paste a palette to see where each colour falls and how far a failing one has to move. Twelve sample foregrounds that pass on your chosen ground can be copied as CSS. The five million generated pairs are still there, as a scrollable index you can open by record id. The map is operable from the keyboard.
- A WCAG 2.2 checklist. The checklist grew from 24 colour checks to 50 across nine areas, each explaining what it means, who it affects, how to test it and the fix as code. Each says whether the Analyzer settles it (11), narrows it down (23) or needs a person (16). Results have three states, conformance is totalled per level, and evidence screenshots can be annotated with pen, arrow, box, numbered callouts and opaque redaction. The checks are real HTML, so the page reads and prints without JavaScript.
- Five collections, one design, and an API each. The colour, gradient, harmony, palette and shades collections now share one design and one scroller that keeps a single screenful in the page however far you go. On the palette, harmony and shades pages, filters now apply to the whole collection rather than to the 48 records on screen. The colour and gradient pages download a fraction of what they did (7.06 MB to 395 KB and 16.99 MB to 941 KB), fetching detail only when you open a record. Each collection gained a written guide and API endpoints to browse it, fetch one record, and read its statistics — plus one endpoint that points it at your own work:
/v1/gradient/analyse(will this ramp band, and where?),/v1/harmony/identify(which scheme do these colours form?) and/v1/shade/evaluate(does this ramp run one way, step evenly and carry text?).
Fixes across the site. The accessibility suite had only ever audited one theme; it now checks colour contrast in both, and the dark-theme failures that found were fixed. A site-wide sweep of every route, in both themes, fixed hundreds more — most of them in the Analyzer’s permanently dark panels, which had been taking dark ink from the light page. Among the rest:
- The skip link, the first control a keyboard user reaches, had unreadable text in both themes.
- The ad close button grew to 24×24 pixels, the WCAG 2.2 minimum, on nearly every page.
- Tabs across the colour picker, the guide and search now tell assistive technology which panel they control.
- Colour of the Day chips now compute their text colour for each day’s colour; the old fixed rule failed on 158 of the 345 days.
- Tooltip titles no longer use the accent colour as text, the header navigation’s open state is announced correctly, and the sign-in page no longer has two top-level headings.
- The sign-in page asks for the human check when you try to sign in, not on arrival, which brings Sign in and the Google and GitHub buttons back above the fold.
10. Offline, speed and discovery
+An offline copy when you ask for one. Opening the homepage used to download the site: on an ordinary laptop, about 115 MB within half a minute, without asking. The background download is gone — a first visit now stays at a few megabytes — and the full offline copy starts from /download/ when you ask for it, with a readable “Saving for offline” progress toast. The offline page itself had been cached in a form browsers refuse to use for navigation, so an unvisited route offline showed the browser’s error page; fixed. Social preview images, which nothing on the site displays, are no longer part of the offline copy, and the Hindi dictionaries are included only for people reading in Hindi.
Lighter pages. JavaScript and CSS are minified when the site is deployed, while the source stays readable — measured at about 43% fewer bytes. The Ishihara plate exporter stopped downloading its own larger copy of a zip library on every export.
Found and read. AI answer engines are now welcome to read and cite the site; robots.txt declares search=yes, ai-input=yes and says nothing about model training, which remains undecided. A new llms.txt gives those engines a short, curated map of the site. Index pages — Learn, Collections, the blog, the changelog and documentation — now ship their links in the HTML instead of the word “Loading”, so a crawler that runs no JavaScript can follow them. Articles scheduled for a future date are kept out of search until the day they publish.
Advertising. Google ads are switched on, with the site’s own house campaigns filling any slot Google does not. Documentation, pricing, legal, sign-in and checkout pages carry no ads, and the command palette no longer shows them.
11. Full change list
+- Server-side URL analysis — Added a rendering backend so the Analyzer can audit pages on other sites in a real browser, with the result merged into the usual report.
- Scan Site — Enabled whole-site scanning in production, streamed page by page, scored on the site’s mean, capped at 24 pages a run.
- Pay for work delivered — Charged allowances and tokens only after a report returns, per page actually audited, with the allowance checked before a browser opens.
- Report fidelity — Fixed the single-page rule catalogue, security headers, modern colour parsing, decorative alt text, live performance timings, the page-by-page breakdown and the A11y+ headline.
- Report export — Rebuilt the export around thirteen self-explaining categories, with “Not scored” for anything unmeasured and escaped Markdown output.
- Scanner behaviour — Identified the scanner through headers, waited for load rather than network silence, retried refusals as a phone, and refused private addresses before and after redirects.
- Analyzer messages — Distinguished refusals from failures, with Sign in and See plans actions, and removed developer-only advice from the live site.
- Coming soon tiers — Marked Specialist and Industrial Pro as Coming soon and refused them on every server purchase path.
- Account-first checkout — Required a signed-in, verified account before an order can be created.
- One-time pass wording — Described Artisan as a pass that does not renew, and made the end-of-plan control reachable and accurate.
- No GST — Stopped adding 18% to Indian orders while tax collection is switched off, and removed the GST line from the advertise page.
- Plan tokens granted — Granted included tokens on purchase and renewal, once per billing period; made tool tokens spendable; freed the free tier from its starter balance.
- Accurate plan copy — Replaced “Unlimited analyses”, stopped granting unshipped perks, removed a phantom plan and a nonexistent trial, and stopped offering credit packs that could not be spent.
- Checkout hardening — Authenticated and rate-limited order creation, removed an unlinked payment fallback, retried failed payment notifications, expired plans at period end, and fixed repeat purchases.
- Payment receipt — Gave the confirmation page the site’s chrome and the date paid; removed an old checkout test page.
- Portfolio builder — Moved the builder to its own page at /portfolio/, with a dashboard card showing whether the page is live.
- Portfolio publishing — Added publishing to auricartisan.com/p/your-handle, with suggested addresses, a QR code and a live-versus-draft comparison.
- Portfolio style — Added typeface, paper, rhythm and accent settings, with accents drawn from your own palettes and graded for contrast.
- Portfolio header and pictures — Gave the page its own identity fields, avatars from disk, working Markdown images, and draft sync to the account.
- Dashboard sections — Reorganised the dashboard into Overview, Profile, Plan & Usage and Security & Privacy, with next steps that are only offered when true.
- Device sheet — Marked the current session, identified iPhones correctly, and added a security readout.
- Danger zone — Required a typed sentence and the account password to open it, for five minutes, enforced on the server, holding only irreversible actions.
- Dashboard in Hindi — Translated the dashboard throughout.
- Contact routing — Routed seven topics to three inboxes, with a reply time per topic and a server-side topic-to-inbox map.
- Contact editor — Added formatting, screenshots with markup, an in-page link prompt, and an acknowledgement email.
- Site-wide feedback — Added paced feedback prompts on every page, bug reports with page context, surveys, and optional contact details asked after the feedback.
- Homepage — Rebuilt the homepage around one analyse-or-search field, a live contrast demo and a working colour workflow.
- Shared chrome — Redesigned the header, footer, info bands, clock strip, right-click menu, dropdowns, search, command palette, guide and settings panel.
- Page redesigns — Redesigned Collections, Pricing, the legal and company pages, Security, Contact, Download, Extension, VS Code and the company timeline.
- Reading pages — Rebuilt Documentation, the Learn index and article frame, the Blog and the Changelog; named a person as every article’s author.
- Contrast checker — Added a standalone contrast checker at /tool/contrast-checker/.
- Contrast map — Added a hue-by-lightness contrast map to the accessibility library, with threshold contours and palette placement.
- Accessibility checklist — Expanded the checklist to 50 explained WCAG 2.2 checks with three-state results and annotated evidence.
- Collection APIs — Added browse, record and statistics endpoints for five collections, plus gradient analyse, harmony identify and shade evaluate.
- Accessibility fixes — Audited both themes, fixed hundreds of contrast failures, and fixed the skip link, ad close button, tab relationships, cursor lag and sign-in fold.
- Offline on request — Stopped the automatic offline download, fixed the cached offline page, and trimmed the offline copy.
- Discovery — Allowed AI answer engines, published llms.txt, baked index links into HTML, and held future-dated articles out of search.
- Ads — Switched on Google ads with house campaigns as fallback, and kept documentation and the command palette ad-free.
12. Technical Notes
+- Tabs, not browsers. The scanner runs on Cloudflare Browser Rendering, which bills browser wall-clock time and concurrent browsers. Scans are batched as up to six tabs in one browser session, and warm sessions are reused rather than launched, which cuts both cost and queueing roughly tenfold against one browser per scan.
- The engine goes to the page. The accessibility engine is bundled into a single script and evaluated in the scanned page through the browser’s debugging protocol rather than injected as a
<script>tag, so a site with a strict Content Security Policy can still be audited. - Two numbers for one limit. The crawl cap is deployment configuration (24 pages) and the engine ceiling is code (1,000 pages). Every crawl response carries both, and
GET /auth/analyzer/limitslets the page show the real maximum. - A strict policy where it matters. Content Security Policy rules at the edge are now generated from the repository’s
_headersrather than copied by hand. The global policy permits inline script only because Cloudflare’s bot detection requires it, paired withscript-src-attr 'none'and named connection origins; the Analyzer route, which renders pages a visitor names, keeps a strict script policy. - Erasure without deletion. A new staff console handles account lifecycle and erasure by anonymising in place, because payment records must be retained. A database trigger refuses a raw delete of a user row, and the erasure receipt lists only what was actually cleared.
- Staff consoles. Staff gained consoles for the contact and feedback inbox, for account tools, for an operations status board that probes each feature and classifies traffic without storing IP addresses, for a browser-based test lab, and for granting staff roles with a recorded reason. None of them is linked or advertised to visitors, and each answers 404 to anyone without the role.
- Mail on separate keys. Contact, feedback and staff replies send through separate email-provider keys, so a burst of form traffic cannot exhaust the quota that password resets depend on.
- The draft reconcile. Portfolio drafts are local-first; the account copy is fetched after boot, a fresh starter document never counts as newer work, and a document being edited always wins.
- Precache from git. The service worker’s precache list is generated from tracked files rather than the working tree, so it can no longer ask every visitor to fetch files that do not exist in production.
- Deploys that fit. A build step prunes source trees that are tracked in the repository but never served, keeping the deployment inside the hosting platform’s file-count limit, and minifies JavaScript and CSS in the build’s own copy while preserving names and licence comments.
13. Testing & Quality
+Nearly every change in this release carries a test that was confirmed to fail with its bug put back. The Analyzer’s gate is tested against the real quota engine rather than a stub — a stub is how a gate that refused everyone and enforced nothing had survived. Purchase paths are pinned by a test that names every server file able to sell a plan, so a new one cannot quietly sell a Coming soon tier, and rupee prices are checked against the payment gateway’s per-transaction ceiling, so a price that could never be charged shows up in the suite rather than at a customer’s checkout. The accessibility suite now asserts which theme it is auditing before it audits, and Colour of the Day is checked against all 345 colours rather than today’s. Pages that the site generates or rebuilds are held to their contracts: the download page to the 45 hooks its live readouts depend on, the extension and VS Code pages to what is actually built and published, and the public menu, sitemap and feeds to containing no staff paths. The continuous-integration pipeline was rebuilt so that one failing job no longer hides the rest, with heavier suites moved to a nightly run alongside a production smoke test that checks security headers, genuine 404s and that the deployed service worker matches the code.
14. How to Report Issues
+Use the contact page and pick the topic that fits — A bug for something broken, Billing for a payment or plan question, Security for anything you would not want public. Please include steps to reproduce, browser and OS, the affected page or tool, and screenshots (you can attach up to four and mark them up). For an Analyzer problem, include the address you scanned and whether it was a single page or Scan Site. For a payment, include the order reference from your receipt. For a published portfolio, include its /p/ address. You can also report a bug from any page through the feedback panel, which records the page details for you.