Webmaster Domain Toolkit

Set up measured audit engines

Add browser measurements and full TLS probing to the 1.1.0 audit workspace.

These engines are optional downloads. The desktop app does not bundle Node, Chromium, browser dependencies, or testssl.sh. Built-in checks work without them. Missing engines appear as unavailable, and failed measurements do not receive invented scores.

Download browser engine files for 1.1.0

Install the browser engine

  1. Install Node.js 22.19 or newer with npm. Check the version with node --version. Keep this Node version available while installing the engine.
  2. Download the browser engine ZIP above and extract it into a folder you will keep. Find engines/browser inside the extracted folder. It contains package.json, package-lock.json, runner.mjs, and setup.mjs.
  3. Open a terminal in that folder and run the commands below. Replace the sample directory with your actual absolute path. Windows users can use npm.cmd if their shell cannot resolve npm.
cd /absolute/path/to/engines/browser
node --version
npm ci
npm run setup
npm test

npm ci installs the pinned local dependencies and a local Node runtime. npm run setup downloads the matching Chromium browser and prints the two paths for the app. npm test runs the browser smoke checks. Setup needs an internet connection and does not install global npm packages.

The 1.1.0 lockfile pins Lighthouse 13.5.0, Playwright 1.63.0, axe 4.13.0, chrome-launcher 1.2.1, and a development Node runtime of 22.22.0. Keep node_modules beside runner.mjs. Keep Chromium in its installed per-user cache.

Linux needs Playwright's browser system dependencies. The setup script downloads Chromium without changing system packages. Browser engine support on Windows and Linux does not substitute for native app packaging verification.

Enter the local engine paths

Open Domain audit in the app and expand Measured browser and TLS engines. Copy the paths printed by setup into the matching fields.

App fieldWhat to enter
Node executableThe printed absolute path to engines/browser/node_modules/node/bin/node on macOS/Linux or node.exe on Windows. An existing Node 22.19 or newer works too.
Browser runnerThe printed absolute path to engines/browser/runner.mjs.
TLS engineThe absolute executable path to a separately installed testssl.sh. Follow the TLS steps below.
CrUX API key (optional)Your own Google API key for CrUX field data, entered for the current session.

Engine paths save locally. The CrUX key stays in session memory and is not saved to report history or engine settings. Re-enter it after restarting the app.

Enter a target URL, select Lighthouse or rendered accessibility, and run the audit. Browser checks retain the path, port, and query string. Review each section's status and evidence before comparing runs.

Read browser results

Lighthouse loads the real page in headless Chromium with mobile emulation and simulated throttling. It records the engine version, configuration, warnings, performance score, lab LCP, CLS, and TBT. TBT is not INP. This navigation audit does not generate lab INP. Measurements vary with the page and your computer, so use matching configurations for comparisons.

Axe scans the rendered page and retains violations, DOM selectors, HTML evidence, passes, and incomplete checks. Every result requires manual review. Automated checks do not establish WCAG conformance and do not inspect logged-in or unvisited application states. Include keyboard, screen reader, and other manual assessment in your accessibility review. See the Playwright accessibility guide.

Add optional CrUX field data

Follow Google's CrUX API documentation to enable the API and obtain a key. Enter it in the CrUX field before running Lighthouse.

CrUX provides real-user LCP, CLS, and INP with metric distributions and a collection period. The app requests URL data first. If the URL has no record, it tries the origin and labels that scope clearly. Field results remain separate from Lighthouse lab measurements.

No eligible record shows as no-data. A missing key shows as not-configured. Authentication, quota, server, or network failures show as error while a successful lab report remains available. Live CrUX requests need your key. Release verification covered fallback and error behavior with response fixtures.

Install the separate TLS engine

Full TLS probing needs a complete testssl.sh distribution with its supporting files and applicable OpenSSL binary. It is not included in the browser ZIP or the app. On macOS or Linux, install Git and run the following commands using a directory you will keep.

git clone --depth 1 --branch v3.2.4 https://github.com/testssl/testssl.sh.git /absolute/path/to/testssl
/absolute/path/to/testssl/testssl.sh --version

Enter /absolute/path/to/testssl/testssl.sh in the app's TLS engine field. If the script is not executable, run chmod +x /absolute/path/to/testssl/testssl.sh. Keep the full distribution together. Copying only the script leaves required files missing.

The adapter runs the full default probe and retains protocol, cipher, certificate-chain, and vulnerability evidence. It scans one resolved IP at the explicit port, or port 443 when no port is supplied. URL paths do not change the TLS endpoint.

Native Windows full TLS probing is unavailable because testssl.sh requires a POSIX environment. This release has no Windows remote TLS adapter. Browser checks remain available on Windows. The downloaded macOS desktop distribution permits local external engines; a sandboxed App Store distribution would require a separate engine design.

testssl.sh is GPL licensed. Consult its license before redistributing it. Its supplied OpenSSL is used for protocol probing.

Resolve unavailable or failed checks

  • If the browser runner is unavailable, check both absolute paths and confirm that node_modules is beside runner.mjs. Run npm ci, npm run setup, and npm test again from the engine folder.
  • If Chromium cannot launch on Linux, install the documented Playwright system dependencies.
  • If TLS is unavailable, check the executable path, permissions, full distribution, and platform. Confirm testssl.sh --version works in your terminal.
  • If a check fails, review its reported error and retry it from the audit. Browser checks have a three-minute outer timeout. TLS checks have an eight-minute timeout. Cancel stops local engine processes.
  • If comparison is unavailable, check the target, scan options, engine versions, and TLS identity. Changed settings, incomplete rules, and measurement errors can prevent a reliable comparison.

Reports keep successful sections when another section fails. Export JSON, CSV, or printable HTML from the report dialog when you are ready to share the evidence.

Return to Webmaster Domain Toolkit downloads