TestForge User Guide

A complete walkthrough — from signing up to running production audits. TestForge audits any web application just by pasting its URL. No SDK, no source code, no browser extensions.

Welcome to TestForge

TestForge is an AI-powered automated testing platform that audits web applications for bugs, security vulnerabilities, compliance gaps, and performance issues — all without needing access to your source code.

30s
Average audit time
162+
Automated checks
5
Compliance suites
3
Browser engines

What TestForge checks:

Try it now — free

Paste any URL and get a complete audit report in under 60 seconds.

Run Free Audit →

Step 1: Sign Up

1

Create your account

Go to testforge.kavachbrowser.com and click "Start Free" or "Get Started". Fill in your name, email, and a password. You can also sign up with Google.

2

Check your email

After signing up, check your inbox for a verification email from TestForge. Click the link inside to confirm your email address.

What you get for free: 3 projects, 100 tests per month, AI test generation, basic security audits, email reports, and the Cloudflare bypass engine. No credit card needed.

Step 2: Pay ₹10 & Get Verified

1

Go to the payment page

After signing up, you'll be redirected to the /pay page. This is a one-time ₹10 verification fee to activate your account.

2

Pay via UPI

Send ₹10 to the UPI ID shown on the page. You can use any UPI app — GPay, PhonePe, Paytm, or your bank app. Click the quick-pay buttons to open your app directly with the details pre-filled.

Note: The payment note will say "TestForge" — this helps us identify your payment.
3

Submit your UTR

After paying, copy the 12-digit UPI Transaction ID (UTR) from your payment app (e.g., 419812345678). Paste it into the input field and click "Submit payment for verification".

4

Wait for activation

Your payment is queued for manual verification. Once an admin approves it (usually within a few hours), your account switches to "Verified" status and you get full access.

You can still use TestForge while waiting! The instant audit page (/audit) works without verification.

Step 3: Run Your First Audit

1

Go to the audit page

Navigate to testforge.kavachbrowser.com/audit. You'll see a clean form asking for your application's URL.

2

Enter your app details

FieldRequired?What to enter
Application URLYesThe full URL of your web app (e.g., https://myapp.com)
Project NameOptionalA friendly name like "Client CRM" or "E-Commerce Store"
Test EmailOptionalA login email if your app requires authentication
Test PasswordOptionalThe password for the test account
GitHub RepoOptionalLink your repo for CI/CD auto-fixes
3

Click "Run Full Analysis"

The audit engine runs through 6 stages automatically. You'll see a live progress tracker:

  1. Initializing — Setting up the browser engine
  2. Crawling pages — Discovering all pages, forms, and API endpoints
  3. AI generating tests — Creating smart test cases based on your app's structure
  4. Running compliance — Checking STQC, VAPT, DPDP standards
  5. Executing browser tests — Running real Playwright tests
  6. Building report — Assembling your audit report
How long does it take? Most audits complete in 30–90 seconds. Larger apps (50+ pages) may take up to 3 minutes.

Authenticated Audits (Testing Protected Pages)

If your app has a login wall, provide test credentials so TestForge can log in and audit protected pages:

  1. Enter the login email and password in the form
  2. If your app uses OTP-based 2FA, pre-generate the OTP and paste it in the optional OTP field
  3. TestForge will automatically detect email/password fields, fill them, click submit, and wait for OTP screens
  4. Session cookies are reused for all subsequent audit tests
Security tip: Use a dedicated test account with limited permissions. Never use production admin credentials. Credentials are encrypted at rest.

Step 4: Understanding Your Results

After the audit completes, you'll see a detailed report with these metrics:

Pages Found
Number of pages discovered during crawl
Bugs Detected
Total vulnerabilities & issues found
AI Test Cases
AI-generated test scenarios
Compliance Score
Overall compliance rating (CERT-In + STQC + DPDP)

What each section means

Bug Severity Levels

LevelMeaningAction
CriticalActive exploit possible (SQLi, exposed credentials)Fix immediately
MajorSignificant risk (missing auth, data leaks)Fix within 24 hours
MinorLow risk (missing headers, info disclosure)Fix within a sprint
InfoBest practice recommendationReview and address

Step 5: The Dashboard

After logging in, the Dashboard is your home base. It gives you a bird's-eye view of everything:

Dashboard Sections

TabWhat it shows
OverviewTotal tests run, bugs found, pass rate chart, recent activity feed
ProjectsAll your projects with test counts, bug counts, last scan date, and quick actions (Scan / Report / Team / Delete)
QA TestingDetailed test management: suites, individual test runs, bug tracking, CI/CD scheduling
AnalyticsTest pass rates over time, bug trends, coverage heatmaps
Pro tip: The Projects page shows a "Last Scan" timestamp and test/bug counts for each project. Click "Report" to generate a shareable PDF-style report for your client or team.

Step 6: Managing Projects

1

Create a project

Go to Dashboard → Projects → click "+ New Project". Enter a name, website URL, login URL, GitHub repo, and optional test credentials.

2

Run a scan

Click the "Scan" button on any project card. This runs a full audit on that project's URL. Results are stored and the project's test/bug counts update automatically.

3

Generate reports

Click "Report" to create a detailed, printable report. It opens in a new tab with a professional layout you can share with clients or save as PDF.

4

Invite your team

Click "Team" to invite colleagues by email. Roles available:

  • Owner — Full control (created the project)
  • Admin — Manage team, run scans, delete
  • Editor — Run scans and view reports
  • Viewer — View reports only
Note: Team collaboration requires a Pro plan.

Step 7: Reading & Sharing Reports

What's in a report?

Sharing reports

Reports are stored permanently. Each report has a unique URL you can bookmark. To share:

  1. Open the report in your browser
  2. Use Ctrl+P / Cmd+P to save as PDF
  3. Share the PDF with clients or stakeholders

You can also enter a recipient email before running an audit to get the report delivered directly to their inbox.

Pricing & Plans

FreePro (Verified)
Price₹0One-time ₹10 verification
Projects3Unlimited
Tests/month100Unlimited
AI Test GenerationIncludedPriority AI (faster, smarter)
Cloudflare BypassIncludedIncluded
Page Crawl Depth10 pages100 pages
Compliance SuitesBasic securityAll 5 suites (CERT-In, STQC, DPDP, VAPT, Payment Gateway)
Cross-BrowserChromium onlyChromium + Firefox + WebKit
Analytics Dashboard—Included
Team Collaboration—Included
CI/CD Integration—Included
Email ReportsIncludedIncluded + auto-scheduled

To upgrade from Free to Pro, go to /pay after logging in to complete the ₹10 verification.

Compliance Suites

TestForge maps to 162+ compliance controls across Indian and international standards:

SuiteScopeWho needs it
CERT-InQuarterly VAPT, incident reporting, security controlsAll Indian companies handling user data
STQCFunctional, security, performance, usability standardsGovernment contractors, public sector
DPDP Act 2023Consent flows, PII exposure, data deletion, breach notificationAny company processing personal data of Indian citizens
VAPT (OWASP)All 10 OWASP categories with automated detectionAll web applications
Payment Gateway VAPTRBI-mandated checks for payment integrationsE-commerce, fintech, any app handling payments
CERT-In compliance: Indian companies must conduct quarterly VAPT audits and report incidents within 6 hours. TestForge automates the audit portion — use it regularly to stay compliant.

API & CI/CD Integration

Run audits from your pipeline

curl -X POST https://testforge.kavachbrowser.com/api/audit/run \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://your-app.com",
    "credentialProfile": {
      "loginUrl": "https://your-app.com/login",
      "username": "test@example.com",
      "password": "your-password"
    },
    "reportEmail": "qa@your-company.com",
    "browser": "chromium"
  }'

The API returns { ok: true, reportUrl, results, emailSent }. Add this to your GitHub Actions, GitLab CI, or Jenkins pipeline to run audits on every deployment.

Full audit via API (with project creation)

curl -X POST https://testforge.kavachbrowser.com/api/run-all \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_JWT_TOKEN" \
  -d '{
    "url": "https://your-app.com",
    "name": "Production Audit",
    "email": "test@example.com",
    "password": "test-password",
    "recipientEmail": "reports@your-company.com"
  }'

Reference: API Endpoints

EndpointMethodAuthPurpose
/api/audit/runPOSTNoneRun a quick audit
/api/run-allPOSTJWTFull audit + project creation + report
/api/projectsGETJWTList your projects
/api/projects/:idGETJWTGet project details
/api/projects/:id/reportPOSTJWTGenerate project report
/api/billing/requestPOSTJWTSubmit payment for verification
/api/billing/meGETJWTCheck your plan status

Frequently Asked Questions

Do I need to install anything?

No. TestForge works entirely through your browser. Just paste a URL and click run. There's no SDK, no npm package, no browser extension, and no source code access needed.

Is it safe to share my app URL?

Yes. TestForge only performs read-only analysis — it doesn't modify your application. Credentials (if provided) are encrypted at rest. We recommend using a dedicated test account, not production admin credentials.

What if my app is behind Cloudflare or a WAF?

TestForge includes a Cloudflare bypass engine that handles most WAF protections automatically. It uses Playwright (a real browser) so JavaScript challenges, CAPTCHAs, and bot detection are navigated just like a real user.

How is this different from running Lighthouse or Burp Suite?

Lighthouse checks performance/SEO. Burp Suite requires manual configuration and a proxy. TestForge combines crawling + security scanning + AI analysis + compliance mapping + browser testing into one automated run — no setup needed.

Can I test mobile apps?

TestForge currently audits web applications (including PWAs and mobile-responsive sites). Native iOS/Android app testing is on our roadmap.

How do I get my ₹10 payment approved faster?

Payment verification is manual to prevent spam. Most payments are approved within a few hours. Ensure you paste the full 12-digit UPI Transaction ID (UTR) — not the UPI ID or payment reference.

Can I use TestForge for client projects?

Yes. Many agencies use TestForge to audit client applications and deliver professional reports. The "Report" button generates a clean, branded PDF you can share directly.

Does TestForge store my data?

Audit reports are stored so you can access them later. You can delete projects anytime from the dashboard. Credentials are encrypted. We do not store screenshots of authenticated pages beyond the audit session.

What is the refund policy?

The ₹10 verification fee is non-refundable as it covers manual review costs. There are no recurring charges — it's a one-time verification.

Ready to audit your app?

Start with a free instant audit — no signup required. See results in under 60 seconds.

Run Free Audit →