Catch keyboard bugs before your users do.
A real browser presses Tab, Shift+Tab and Escape to find focus traps, invisible focus and controls hidden under sticky content. Add axe-core checks, group repeated problems, and watch for changes. Free, open source, on your own server.
Built for the people who fix sites
Everything in the report points at something you can change, and nothing pretends to be more than it is.
Presses Tab for you
A real browser tabs through every page, the way a tester does by hand. It catches keyboard traps, focus that never shows and focus hidden under sticky headers and cookie banners, and draws each page’s Tab order as a numbered map.
One mistake counts once
A broken button in a template used on 500 pages is one row with a page count, not 500 rows.
Flags checks that need a person
Uncertain results from axe-core and the keyboard walk are listed as “needs a human”, with the evidence to review.
Keeps watching
Scans each site daily or weekly on its own, shows what is new and what got fixed, and tells Slack, Discord, ntfy or your inbox when something breaks.
Runs on your server
One compose file. No Redis, no cloud account, and no page content leaves your network.
Fails your CI, not your users
A GitHub Action checks a staging site on every pull request and fails at the severity you choose.
Eight languages
The interface and the rule descriptions, in the language your team and clients read.
No magic button. The magic button does not work.
Tabwalk changes nothing on your site and never calls it compliant. It shows what is broken, where, and on how many pages.
FTC fine for an overlay vendor that claimed its widget made sites WCAG compliant.
of ADA website lawsuits in the first half of 2025 targeted sites that already had an overlay.
edits Tabwalk makes to your site. It measures, keeps a dated record and leaves the fixing to people.
Sources: FTC final order, Accessibility.Works
Questions and answers
Can I try it before installing?
Open the sample report to watch a real keyboard bug, see its fix, explore findings, and download the JSON. No signup needed. The demo is a snapshot; you run scans on your own server.
Is it really free?
Yes. The self-hosted version is AGPL-3.0 with no subscription or feature limits. You create a local admin account on your own server.
Will it make my site compliant?
No tool can. Automated checks cover only part of WCAG. Tabwalk shows what it found and lists what a person still has to check.
What does it check?
WCAG 2.2 A and AA rules from axe-core, plus a keyboard walk that finds traps, invisible focus and focus hidden under fixed content, on every page it finds through your sitemap and the links between your pages. Each problem lists the matching EN 301 549, RGAA and Section 508 clauses. Best-practice rules are shown apart as recommendations.
Can my team sign in with Google or Microsoft?
Yes. The dashboard has its own accounts, and single sign-on works with Google Workspace, Microsoft Entra ID, Keycloak or any other OpenID Connect provider.
Where does my data go?
Nowhere. Tabwalk runs on your server with its own Postgres. Pages are opened by a local browser and nothing is sent to us.
Free and open source.
The self-hosted version always will be.
Questions, ideas and pull requests are welcome. If it saves you time, a star helps other people find it.