TestForge User Guide
A complete walkthrough — from signing up to running production audits. TestForge audits any web application just by pasting its URL. No SDK, no source code, no browser extensions.
Welcome to TestForge
TestForge is an AI-powered automated testing platform that audits web applications for bugs, security vulnerabilities, compliance gaps, and performance issues — all without needing access to your source code.
What TestForge checks:
- Security — SQL injection, XSS, open redirects, exposed APIs, missing headers
- Data leaks — Exposed emails, phone numbers, Aadhaar/PAN, tokens in source code
- Broken functionality — 404 pages, broken forms, JavaScript errors, slow load times
- Compliance — CERT-In, STQC, DPDP Act 2023, OWASP Top 10, RBI guidelines
- AI Recommendations — Smart fixes and improvement suggestions generated by AI
Step 1: Sign Up
Create your account
Go to testforge.kavachbrowser.com and click "Start Free" or "Get Started". Fill in your name, email, and a password. You can also sign up with Google.
Check your email
After signing up, check your inbox for a verification email from TestForge. Click the link inside to confirm your email address.
Step 2: Pay ₹10 & Get Verified
Go to the payment page
After signing up, you'll be redirected to the /pay page. This is a one-time ₹10 verification fee to activate your account.
Pay via UPI
Send ₹10 to the UPI ID shown on the page. You can use any UPI app — GPay, PhonePe, Paytm, or your bank app. Click the quick-pay buttons to open your app directly with the details pre-filled.
Submit your UTR
After paying, copy the 12-digit UPI Transaction ID (UTR) from your payment app (e.g., 419812345678). Paste it into the input field and click "Submit payment for verification".
Wait for activation
Your payment is queued for manual verification. Once an admin approves it (usually within a few hours), your account switches to "Verified" status and you get full access.
Step 3: Run Your First Audit
Go to the audit page
Navigate to testforge.kavachbrowser.com/audit. You'll see a clean form asking for your application's URL.
Enter your app details
| Field | Required? | What to enter |
|---|---|---|
| Application URL | Yes | The full URL of your web app (e.g., https://myapp.com) |
| Project Name | Optional | A friendly name like "Client CRM" or "E-Commerce Store" |
| Test Email | Optional | A login email if your app requires authentication |
| Test Password | Optional | The password for the test account |
| GitHub Repo | Optional | Link your repo for CI/CD auto-fixes |
Click "Run Full Analysis"
The audit engine runs through 6 stages automatically. You'll see a live progress tracker:
- Initializing — Setting up the browser engine
- Crawling pages — Discovering all pages, forms, and API endpoints
- AI generating tests — Creating smart test cases based on your app's structure
- Running compliance — Checking STQC, VAPT, DPDP standards
- Executing browser tests — Running real Playwright tests
- Building report — Assembling your audit report
Authenticated Audits (Testing Protected Pages)
If your app has a login wall, provide test credentials so TestForge can log in and audit protected pages:
- Enter the login email and password in the form
- If your app uses OTP-based 2FA, pre-generate the OTP and paste it in the optional OTP field
- TestForge will automatically detect email/password fields, fill them, click submit, and wait for OTP screens
- Session cookies are reused for all subsequent audit tests
Step 4: Understanding Your Results
After the audit completes, you'll see a detailed report with these metrics:
What each section means
- Pages Found: All URLs discovered during the crawl phase. More pages = more thorough audit.
- Bugs Detected: Every bug, vulnerability, or issue found. Each comes with a severity rating and fix recommendation.
- AI Test Cases: Smart tests generated specifically for your app's structure. The AI analyzes your forms, navigation, and API calls.
- Compliance Score: How well your app meets Indian regulatory standards. 80%+ is good; below 50% needs immediate attention.
Bug Severity Levels
| Level | Meaning | Action |
|---|---|---|
| Critical | Active exploit possible (SQLi, exposed credentials) | Fix immediately |
| Major | Significant risk (missing auth, data leaks) | Fix within 24 hours |
| Minor | Low risk (missing headers, info disclosure) | Fix within a sprint |
| Info | Best practice recommendation | Review and address |
Step 5: The Dashboard
After logging in, the Dashboard is your home base. It gives you a bird's-eye view of everything:
Dashboard Sections
| Tab | What it shows |
|---|---|
| Overview | Total tests run, bugs found, pass rate chart, recent activity feed |
| Projects | All your projects with test counts, bug counts, last scan date, and quick actions (Scan / Report / Team / Delete) |
| QA Testing | Detailed test management: suites, individual test runs, bug tracking, CI/CD scheduling |
| Analytics | Test pass rates over time, bug trends, coverage heatmaps |
Step 6: Managing Projects
Create a project
Go to Dashboard → Projects → click "+ New Project". Enter a name, website URL, login URL, GitHub repo, and optional test credentials.
Run a scan
Click the "Scan" button on any project card. This runs a full audit on that project's URL. Results are stored and the project's test/bug counts update automatically.
Generate reports
Click "Report" to create a detailed, printable report. It opens in a new tab with a professional layout you can share with clients or save as PDF.
Invite your team
Click "Team" to invite colleagues by email. Roles available:
- Owner — Full control (created the project)
- Admin — Manage team, run scans, delete
- Editor — Run scans and view reports
- Viewer — View reports only
Step 7: Reading & Sharing Reports
What's in a report?
- Header — Project name, URL, generation date, total duration
- Metric Cards — Pages found, bugs detected, AI test cases, compliance score
- Summary — Key findings and pass/fail status for each audit phase
- Compliance Breakdown — Per-suite scores (CERT-In, STQC, DPDP, VAPT, Payment Gateway)
Sharing reports
Reports are stored permanently. Each report has a unique URL you can bookmark. To share:
- Open the report in your browser
- Use Ctrl+P / Cmd+P to save as PDF
- Share the PDF with clients or stakeholders
You can also enter a recipient email before running an audit to get the report delivered directly to their inbox.
Pricing & Plans
| Free | Pro (Verified) | |
|---|---|---|
| Price | ₹0 | One-time ₹10 verification |
| Projects | 3 | Unlimited |
| Tests/month | 100 | Unlimited |
| AI Test Generation | Included | Priority AI (faster, smarter) |
| Cloudflare Bypass | Included | Included |
| Page Crawl Depth | 10 pages | 100 pages |
| Compliance Suites | Basic security | All 5 suites (CERT-In, STQC, DPDP, VAPT, Payment Gateway) |
| Cross-Browser | Chromium only | Chromium + Firefox + WebKit |
| Analytics Dashboard | — | Included |
| Team Collaboration | — | Included |
| CI/CD Integration | — | Included |
| Email Reports | Included | Included + auto-scheduled |
To upgrade from Free to Pro, go to /pay after logging in to complete the ₹10 verification.
Compliance Suites
TestForge maps to 162+ compliance controls across Indian and international standards:
| Suite | Scope | Who needs it |
|---|---|---|
| CERT-In | Quarterly VAPT, incident reporting, security controls | All Indian companies handling user data |
| STQC | Functional, security, performance, usability standards | Government contractors, public sector |
| DPDP Act 2023 | Consent flows, PII exposure, data deletion, breach notification | Any company processing personal data of Indian citizens |
| VAPT (OWASP) | All 10 OWASP categories with automated detection | All web applications |
| Payment Gateway VAPT | RBI-mandated checks for payment integrations | E-commerce, fintech, any app handling payments |
API & CI/CD Integration
Run audits from your pipeline
curl -X POST https://testforge.kavachbrowser.com/api/audit/run \ -H "Content-Type: application/json" \ -d '{ "url": "https://your-app.com", "credentialProfile": { "loginUrl": "https://your-app.com/login", "username": "test@example.com", "password": "your-password" }, "reportEmail": "qa@your-company.com", "browser": "chromium" }'
The API returns { ok: true, reportUrl, results, emailSent }. Add this to your GitHub Actions, GitLab CI, or Jenkins pipeline to run audits on every deployment.
Full audit via API (with project creation)
curl -X POST https://testforge.kavachbrowser.com/api/run-all \ -H "Content-Type: application/json" \ -H "Authorization: Bearer YOUR_JWT_TOKEN" \ -d '{ "url": "https://your-app.com", "name": "Production Audit", "email": "test@example.com", "password": "test-password", "recipientEmail": "reports@your-company.com" }'
Reference: API Endpoints
| Endpoint | Method | Auth | Purpose |
|---|---|---|---|
/api/audit/run | POST | None | Run a quick audit |
/api/run-all | POST | JWT | Full audit + project creation + report |
/api/projects | GET | JWT | List your projects |
/api/projects/:id | GET | JWT | Get project details |
/api/projects/:id/report | POST | JWT | Generate project report |
/api/billing/request | POST | JWT | Submit payment for verification |
/api/billing/me | GET | JWT | Check your plan status |
Frequently Asked Questions
Do I need to install anything?
No. TestForge works entirely through your browser. Just paste a URL and click run. There's no SDK, no npm package, no browser extension, and no source code access needed.
Is it safe to share my app URL?
Yes. TestForge only performs read-only analysis — it doesn't modify your application. Credentials (if provided) are encrypted at rest. We recommend using a dedicated test account, not production admin credentials.
What if my app is behind Cloudflare or a WAF?
TestForge includes a Cloudflare bypass engine that handles most WAF protections automatically. It uses Playwright (a real browser) so JavaScript challenges, CAPTCHAs, and bot detection are navigated just like a real user.
How is this different from running Lighthouse or Burp Suite?
Lighthouse checks performance/SEO. Burp Suite requires manual configuration and a proxy. TestForge combines crawling + security scanning + AI analysis + compliance mapping + browser testing into one automated run — no setup needed.
Can I test mobile apps?
TestForge currently audits web applications (including PWAs and mobile-responsive sites). Native iOS/Android app testing is on our roadmap.
How do I get my ₹10 payment approved faster?
Payment verification is manual to prevent spam. Most payments are approved within a few hours. Ensure you paste the full 12-digit UPI Transaction ID (UTR) — not the UPI ID or payment reference.
Can I use TestForge for client projects?
Yes. Many agencies use TestForge to audit client applications and deliver professional reports. The "Report" button generates a clean, branded PDF you can share directly.
Does TestForge store my data?
Audit reports are stored so you can access them later. You can delete projects anytime from the dashboard. Credentials are encrypted. We do not store screenshots of authenticated pages beyond the audit session.
What is the refund policy?
The ₹10 verification fee is non-refundable as it covers manual review costs. There are no recurring charges — it's a one-time verification.