Controls a person can’t use
Buttons in the page but invisible, covered by a toast or a sticky header, cut off by their container, or pushed off-screen.
An open-source AI QA testing plugin for Claude Code and Codex. blindqa drives your web app in a real browser with Playwright — scrolling, clicking, signing in as every role — and reports the bugs your users would actually hit. After the first run, it re-tests only what your code changes touch.
> /plugin marketplace add DevZonayed/blindqa> /plugin install blindqa@blindqa
Then ask your agent: “Set up blindqa for this repo.” Node.js 20+ and git required.
A crawl flags what a person couldn’t use — even when it’s in the DOM and a DOM test would pass.
What it finds
A test can pass while a person sees nothing. blindqa checks what a person can actually see, reach and use — for every role, at desktop and phone width.
Buttons in the page but invisible, covered by a toast or a sticky header, cut off by their container, or pushed off-screen.
A dialog closes but the page stays locked, so the rest of the form can’t be reached.
A role sees a button the API rejects — and every role’s forbidden actions are sent straight to the server too.
Negative quantities, invalid tax numbers, a due date before the issue date — saved without a word.
Developer-speak shown to users, or the error rendered behind the dialog that caused it.
Signs in as each role (password, authenticator or emailed codes, magic links) and crawls every screen it can reach — then again at 390 px through the ☰ menu.
How it works
No AI model in the test loop: every check and every judgment call is code, so runs cost zero tokens and the same screen always gets the same verdict. Your coding agent only sets things up, writes journeys and verifies what’s new.
Drive the browser, check visibility, scrolling, contrast and size, block writes, catch console and HTTP errors, index your code, work out what a change touches, compare runs.
The calls a tester makes: is this an error or blank screen, do raw ids leak to users, can a screen reader tell these buttons apart, what will this control do, did that submit work.
Claude Code, Codex or any MCP client: sets up the project, writes journeys, verifies new high-severity findings, writes the report. Never watches a run.
Read-only. One top-to-bottom pass per page for a role: every control audited, menus and dropdowns opened, “New/Add” forms checked with an empty submit. Every write request is blocked.
Short scripts for real workflows — sign in, create data, switch roles, check the figures — written once, reused on every run and every re-test.
Uses every option on every screen with valid data and records what each one really did. For test environments only.
Re-test only what changed
The first full run is paid once. After that, a change costs minutes of machine time and one short report.
A script reads every file: pages, visible labels, API routes and their permission checks, API calls, imports. 3,312 files in about half a second.
Against the indexed commit or any git ref — which labels, pages and endpoints changed, file by file.
Through imports to the pages that render a change, and from a server change to the screens that call its endpoints. Global files mean a full re-test.
Only the affected crawls and journeys, compared with the last run on the screens they re-visited: NEW, FIXED, STILL.
Commits since: 1 — Board: new empty text, hide add button modified src/components/Board.tsx — labels +1/-1Affected page routes: 1 — /▶ crawl USER — landing page ✔ 7 new, 0 fixed, 1 still▶ journey taskflow-smoke — passes / ✔ 0 new, 0 fixed, 1 stillNEW high not-humanly-visible: “Add task to Backlog” can’t be used by a person — effectively transparent (opacity 0.00)Real output from a demo app: one component edit, one re-crawled screen, the new bug found.
Any machine, any browser
Projects move between machines; browsers don’t. Each machine keeps its own mode in ~/.blindqa/machine.json —blindqa machine detect suggests one.
Safe by default
Logins, saved sessions, screenshots and reports live in one .blindqa/ folder. blindqa never edits your tracked files, crawls are read-only, and repos it clones for testing can’t push at all.
The folder ignores itself — this file included. Nothing in your repo’s own .gitignore changes.
Git’s per-clone ignore list. Local to this machine, never committed.
Refuses any push whose commits contain a .blindqa/ path — even after git add -f.
Proven in CI against a real local remote on every commit.
FAQ
Two commands in Claude Code or Codex. MIT licensed, open source — a star helps other developers find it.
> /plugin marketplace add DevZonayed/blindqa> /plugin install blindqa@blindqa