QA report: external/getswiftpay.xyz at hosted
No confirmed defects were found across the ten audited scenarios.
Testing on getswiftpay.xyz covered 10 scenarios focusing on UI theme switching, FAQ accordion interactions, sign-in modal behavior, route protection on footer navigation links, and external wallet connection. Nine scenarios passed and one failed during automated execution.
A single critical finding concerning the external wallet connection flow was initially raised but subsequently withdrawn upon audit review, leaving zero confirmed defects.
Coverage was limited to unauthenticated public pages and UI components, as automated interactions faced bot protection and WAF restrictions that prevented deeper authenticated feature exploration.
Run summary
| Metric | Count |
|---|
| Scenarios executed | 10 |
| Passed | 9 |
| Failed | 1 |
| Blocked | 0 |
| Findings raised | 1 |
| Issues after the audit | 0 |
| Withdrawn by the audit | 1 |
| Critical / high / medium / low | 0 / 0 / 0 / 0 |
Target: https://getswiftpay.xyz/ · Testing level: deep_feature · Stack: unknown
Issues
No issues survived the audit.
Withdrawn findings
The Critic re-examined these claims and found the evidence did not support them. They are kept here rather than deleted.
- External wallet 'Connect wallet' button does not trigger wallet connection or authentication flow (S1, critical): The 401 and 403 console errors indicate the automation harness was blocked by a bot challenge or WAF, preventing the application's scripts from loading and the button from functioning. The audit recorded that a block on automation kept this interaction from working, so the evidence describes our harness, not the application. The page reported 3 console errors during the scenario.
Scenario results
| Scenario | Priority | Result | Issues |
|---|
| S1 Connect External Wallet | high | fail | none |
| S2 Route Protection via Footer Swap Link | high | pass | none |
| S3 Route Protection via Footer Batch Settlement Link | high | pass | none |
| S4 Dismiss Sign-In Modal | medium | pass | none |
| S5 Toggle Dark Theme | medium | pass | none |
| S6 Toggle Light Theme | medium | pass | none |
| S7 Toggle System Theme | medium | pass | none |
| S8 FAQ Accordion - Dashboard Overview | low | pass | none |
| S9 FAQ Accordion - Network and Assets | low | pass | none |
| S10 Multiple FAQ Accordions | low | pass | none |
The audit
The Critic reviewed 1 finding and re-verified 1 of them live in the browser, replaying the reported steps on a fresh page.
- Widespread 403 console errors indicate a bot challenge or WAF is blocking the automation from accessing some site resources.
Coverage and caveats
In scope: Landing page UI and theme switching; FAQ accordion functionality; Authentication modal presentation and dismissal; External wallet connection flow; Deep link route protection and redirection.
Not covered: Google OAuth sign-in flow (off-origin redirection); Post-authentication dashboard features (unmapped in Explorer phase).
- The injected test wallet will automatically connect when the External Wallet option is chosen in the sign-in modal.
- Dashboard and deep application pages were not mapped because the Explorer did not complete the authentication step.
By the numbers
| Metric | Value |
|---|
| Scenarios | 9 passed, 1 failed, 0 blocked of 10 (23 planned steps) |
| Browser actions | 112 (37 clicks, 2 inputs, 17 navigations, 56 snapshots) |
| Screenshots | 29 (1 explore, 27 scenario, 1 critic), 27 captioned |
| Coverage | 1 pages, 1 forms, 2 flows, 3 console errors |
| Audit | 1 findings, 1 re-verified live, 0 confirmed, 0 promoted, 1 withdrawn |
| Model calls | 114 |
| Tokens | 781,519 input, 5,973 output, 8,921 thinking |
| Time | 7 min |
| Wallet | 0 transactions, 0 signatures, 0 refusals on chain 5042002 |
| Stage | Calls | Input | Output | Thinking | Seconds |
|---|
| explore | 28 | 269,979 | 1,580 | 2,013 | 137 |
| plan | 1 | 3,245 | 1,470 | 1,825 | 26 |
| test | 79 | 482,658 | 2,508 | 3,320 | 225 |
| critique | 5 | 24,332 | 266 | 1,425 | 28 |
| report | 1 | 1,305 | 149 | 338 | 5 |