Skip to content
Website building

Website check: law, security and accessibility in 48 points

To check whether your website meets legal, security and accessibility requirements, paste one of the two prompts in this guide into Claude or ChatGPT. The bot asks a few short questions, goes through the site in 48 points and returns a report: what's OK, what's missing and what's most urgent. There is one prompt for people who have the site's code, and one for people whose site was built for them or who built it on WordPress or Wix. This is a technical check, not legal advice.

The prompt checks your website in 48 points: privacy policy, cookies, security and accessibility. At the end you get a clear report with what's OK, what's missing and what's most urgent.

It's also the best way to check the work of whoever built your site.

Which prompt fits you?

  • You have the site's code on your computer (Next.js, React, HTML etc.): prompt 1, paste it into Claude Code, Codex or Cursor.
  • Someone else built it for you, or you built it on WordPress, Wix, Site123 or Shopify: prompt 2, paste it into regular Claude (claude.ai) or ChatGPT.

How to use it (3 steps)

  1. Copy the right prompt (the copy button in the corner of the block).
  2. Paste it into the tool and send. The bot will ask a few short questions (the site's link, where your audience is etc.).
  3. Answer, wait, and get the report.

Prompt 1: if you have the code (Claude Code / Codex)

Prompt 1 - website check with code access
Task: a full compliance, security and accessibility audit of my website.

Safety rules (mandatory):
- Read only. Do not change code, do not create a branch, do not commit or push.
- One exception: you may create a single report file - docs/COMPLIANCE-REPORT.md.
- If you find an exposed API key, password or token - note only the file and line. Never copy the value itself into the report.
- On the live site: never submit real forms, no load tests, request flooding or hacking attempts. Passive checks only.
- If a tool (Lighthouse, axe, pa11y etc.) is not installed - ask me before installing it. If I say no, check manually and say so.

Before you start - ask me these questions and wait for the answers:
1. What is the live site's address?
2. Is your audience only in Israel, or also in Europe / the US? (decides whether to check GDPR / CCPA and WCAG 2.1)
3. Which languages is the site in?
4. Does the site have: sign-up / payment / a mailing list / a chat or AI bot / user-uploaded content / affiliate links?
5. Who is the accessibility coordinator (if there is one)?

How to check:
Go through all the code, the config files (headers, middleware, server/hosting settings such as vercel.json, next.config, .htaccess), every page in every language, the forms, the chats, the API and the live site. Where possible, run tools: Lighthouse, axe-core or pa11y, a headers check, a broken-links check.

Accessibility standard, by the answer to question 2:
- Israel only: IS 5568 = WCAG 2.0 level AA (Israeli Equal Rights for Persons with Disabilities Regulations, 2013).
- Europe too: WCAG 2.1 level AA (under the European Accessibility Act), which also covers the Israeli standard.

Status for each item:
✅ OK | ❌ Missing | ⚠️ Partial | ➖ Not relevant (explain in one sentence) | ❓ Needs a manual check (can't be verified automatically - don't guess!)

Format for each item:
Status | Item | What you found (file/page/line) | What's missing | How to fix (short)

Important: check all 48 items at the same level of detail. Don't cut the last items short. If you run out of space - stop and tell me, and I'll say "continue".

A. Law and privacy
1. Privacy policy - exists, up to date, in every site language, linked from the footer and from every form
2. Terms of use page
3. Refund / cancellation policy - if anything is sold or there is a paid service
4. Cookie banner - real consent before pixels and analytics load, including a reject option
5. Form consent - explicit consent to store details, and separate consent for marketing emails
6. Minimal data collection - forms ask only for required fields
7. Laws by country - Israel: the Privacy Protection Law and Amendment 13, the anti-spam law (section 30A of the Communications Law), the Consumer Protection Law. International audience: basic GDPR / CCPA
8. Right to be forgotten - a button or a defined way to request data deletion
9. Double opt-in - if there is a mailing list
10. Affiliate disclosure - if there are affiliate links
11. Age verification - if the content requires it
12. Recording / chat storage notice - if there are voice calls or an AI chat that stores conversations

B. Content and copyright
13. Reviews and testimonials - signs of fake testimonials (usually ❓)
14. Unsupported claims - promised results, numbers or "the best" without proof
15. Image copyright - a source or license for every image (usually ❓)
16. Font and icon licenses
17. Open-source licenses - no license that forces you to open your code (GPL etc.), and credits where required
18. Offensive-content filtering - if there is user content or an open chat

C. Security
19. HTTPS enforced everywhere, including HSTS
20. Security headers - CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
21. Protection from SQL injection / XSS - server-side validation and sanitization of every input
22. Bot blocking on forms (reCAPTCHA / Turnstile / honeypot) - check in the code, not by submitting forms
23. Rate limiting on forms, chat and API - check in the code, not by flooding
24. Hidden system errors - no stack traces shown to users
25. Session timeout - if there is a login
26. External payments only - no card details stored in the database
27. API keys - not exposed in client code or in the repo (including git history). Don't copy values!
28. Automatic backup of customer data
29. Third-party scripts - a list of all of them, what each one collects, and whether it loads only after consent

D. Technical and user experience
30. Mobile-friendly on every page
31. Easy forms - clear fields, the right keyboard type (phone/email), clear error messages
32. Analytics (GA4 / Pixel / TikTok) - working and tied to cookie consent

E. Accessibility
33. Accessibility statement - a page in every language, linked from the footer, with the conformance level, update date, what was and wasn't made accessible, and the accessibility coordinator's details (name, phone, email)
34. Accessibility plugin - make sure it isn't an "overlay" used instead of real accessibility in the code
35. Color contrast - 4.5:1 for normal text, 3:1 for large text and components
36. Keyboard navigation - logical Tab order, visible focus, no traps, a "skip to content" link
37. Images - meaningful alt, empty alt for decorative images
38. Headings - one H1 per page, a proper hierarchy
39. Language and direction - correct lang and dir (for Hebrew lang="he" dir="rtl")
40. Forms - a label for every field, linked errors (aria-describedby), required fields marked
41. Buttons and links - an accessible name for every button, including icons (WhatsApp, chat, hamburger, social)
42. Animations - respect prefers-reduced-motion, a way to stop moving content longer than 5 seconds, no flashing
43. Text zoom to 200% without breaking, 320px width without horizontal scrolling
44. Screen readers - landmarks (header/nav/main/footer), valid ARIA
45. Video and audio - captions and a way to pause
46. Chats, popups and widgets - usable with a keyboard and a screen reader
47. Downloadable documents (PDF) - accessible, if there are any
48. Scores - axe / pa11y and Lighthouse Accessibility for every main page

End of the report:
- A summary table: how many ✅ / ❌ / ⚠️ / ➖ / ❓
- A list of gaps by urgency: 🔴 legal requirement / 🟠 security / 🟡 recommended
- For each gap: effort (small/medium/large) and what you need from me (a decision, content, an account etc.)
- A list of all ❓ items with an explanation of what to check manually
- Save it as docs/COMPLIANCE-REPORT.md and show me the report here.
- Don't fix anything.

Note: this is a technical check, not legal advice.

Prompt 2: WordPress, Wix or a site built for you

Prompt 2 - website check without code
You are a professional website auditor. The task: check my website for law, privacy, security and accessibility, and give me a clear report in plain language. I'm not technical - explain every term in one sentence.

Step 1 - before you start, ask me these questions and wait for the answers:
1. What is the link to the site?
2. What is the site built on? (WordPress / Wix / Site123 / Shopify / someone built it for me and I don't know)
3. Is your audience only in Israel, or also in Europe / the US?
4. Which languages is the site in?
5. What does the site have: a contact form / sign-up / payment / a mailing list / a chat or bot / affiliate links?
6. Was the site built by someone else? (if so - at the end, prepare a list of questions for me to ask them)

Step 2 - ask me to run 2 free checks and paste the results to you:
- PageSpeed Insights: https://pagespeed.web.dev - paste the Accessibility score and the list of issues
- WAVE: https://wave.webaim.org - paste the number of Errors and Contrast Errors
(optional: https://securityheaders.com - paste the grade)
If I don't want to - continue without them and mark what wasn't checked.

Step 3 - the check:
Open the site and go through the home page, the service pages, the contact page, the footer and every legal page you find (privacy, terms, accessibility). If you don't have internet access, ask me to paste the text of the pages.

Rules:
- Never submit forms on the site.
- If something can't be checked from the outside - mark it ❓ and tell me how to check it or whom to ask. Don't guess!

Accessibility standard, by the answer to question 3:
- Israel only: IS 5568 = WCAG 2.0 level AA.
- Europe too: WCAG 2.1 level AA.

Statuses: ✅ OK | ❌ Missing | ⚠️ Partial | ➖ Not relevant | ❓ Needs a manual check / ask whoever built it

What to check:

A. Law and privacy
1. Privacy policy - exists, in every site language, linked from the footer and the forms
2. Terms of use
3. Cancellation and refund policy - if anything is sold
4. A cookie banner with a real reject option
5. A consent checkbox on forms, and separate consent for marketing emails
6. Forms ask only for what's needed
7. Laws: in Israel - the Privacy Protection Law and Amendment 13, the anti-spam law, the Consumer Protection Law. Audience abroad - basic GDPR / CCPA
8. A way to request data deletion
9. Affiliate disclosure - if there are affiliate links
10. A notice that conversations are stored - if there is a chat / bot

B. Content
11. Testimonials that look fake
12. Promises without proof ("the best", "guaranteed", numbers)
13. Images - do they look like stock? Is there credit? (usually ❓ - ask whoever built it)

C. Security (what can be seen from the outside)
14. The site opens only over https (the padlock in the browser)
15. Security headers - by securityheaders.com
16. Bot protection on forms (do you see reCAPTCHA or something similar?)
17. Technical error messages shown to visitors
18. WordPress only: signs of an old version or outdated plugins, a login page exposed at /wp-admin
19. A list of every external tool that loads (Facebook, Google and TikTok pixels, Hotjar, chats) - and whether they load before consent
20. Backups - ❓ ask whoever built it

D. User experience
21. The site looks good on a phone
22. The forms are easy to fill in
23. The WhatsApp / phone button works

E. Accessibility
24. Accessibility statement - exists, linked from the footer, with a date, conformance level and the accessibility coordinator's details (name, phone, email)
25. Accessibility plugin - explain to me that a plugin alone isn't enough under the law, and that real accessibility work is needed
26. Color contrast - by WAVE
27. Images with alternative text (alt)
28. A proper heading structure
29. lang="he" and dir="rtl" for Hebrew
30. A label for every form field
31. Icon buttons (WhatsApp, menu, social) with an accessible name
32. Navigating with the Tab key - explain how I can check it myself in 30 seconds
33. Animations and videos - can be paused, have captions
34. The PageSpeed and WAVE scores I pasted

Report format:
1. First line: an overall score out of 10 and one sentence - the site is in good shape / average / needs urgent attention.
2. A table: Status | Item | What I found | What it means in plain language | How to fix it
3. Summary: how many ✅ / ❌ / ⚠️ / ➖ / ❓
4. What to fix first: 🔴 required by law (risk of a fine or a lawsuit) / 🟠 security / 🟡 recommended
5. If the site was built by someone else: "Questions to ask whoever built your site" - a list ready to copy into WhatsApp, in a polite tone.
6. For each fix: easy (I can do it myself) / medium / needs a developer.

Note at the end of the report: this is a technical check, not legal advice. Legal documents are worth reviewing with a lawyer.

Got a report full of red?

Most websites fail this check, especially on accessibility and cookies. That doesn't mean your site is bad. It means there are things to fix before they turn into a fine or a lawsuit.

  • We go through the report with you and explain what's really urgent.
  • We fix accessibility, cookies, forms and security.
  • Or we build you a new site that converts and is accessible from the ground up.

Send us the report on WhatsApp and we'll get back to you with an estimate.

Talk to us on WhatsApp
Talk to us on WhatsApp