DominaresTools

All tools / Testing & code health

prodwalk

Walk your live site as each role, stopping every write request and printing no secret.

Buy prodwalk for $49

One payment of $49, plus sales tax where it applies, and every future update. Delivered as a private GitHub repository you're invited to.

See it work

prodwalk 1.0.1demo mode
prodwalk demo -q --port 8492
59/59 passed

prodwalk demo --leaky -q --port 8492
FAIL  chromium-1440x900 admin: the walk wrote nothing (a write is stopped before the network)  (POST /api/ping)
FAIL  chromium-1440x900 admin: zero console errors  (Failed to load resource: net::ERR_FAILED | Failed to fetch | Failed to load resource: net::ERR_FAILED)
FAIL  chromium-1440x900 viewer: the walk wrote nothing (a write is stopped before the network)  (POST /api/ping)
FAIL  chromium-1440x900 viewer: zero console errors  (Failed to load resource: net::ERR_FAILED | Failed to fetch | Failed to load resource: net::ERR_FAILED)
FAIL  chromium-390x844 admin: the walk wrote nothing (a write is stopped before the network)  (POST /api/ping)
FAIL  chromium-390x844 admin: zero console errors  (Failed to load resource: net::ERR_FAILED | Failed to fetch | Failed to load resource: net::ERR_FAILED)
FAIL  chromium-390x844 viewer: the walk wrote nothing (a write is stopped before the network)  (POST /api/ping)
FAIL  chromium-390x844 viewer: zero console errors  (Failed to load resource: net::ERR_FAILED | Failed to fetch | Failed to load resource: net::ERR_FAILED)
51/59 passed
Demo mode, not a live system: prodwalk 1.0.1, run on 2026-10-05. The tool's own stand-in site, served on 127.0.0.1 on our test machine and walked in a real Chromium (the demo walks only Chromium unless told otherwise); the second run makes the stand-in page send a write on its own.

What it does

prodwalk drives a real browser (Chromium, WebKit or Firefox) through your production site as several roles on several screen sizes. Every non-read request, including a beacon sent as a page closes, is stopped before the network and fails the run. Secrets come from the environment and are cut from every line it prints or stores. A watchdog ends a stalled walk with the last step that finished.

Write guard
POST, PUT, PATCH, DELETE, form submits, sendBeacon and closing-page keepalive fetches are stopped inside the browser and named as METHOD /path. You allow only the sign-in. A GET that changes data on your server is still a read to the guard, so walk a site whose reads are reads.
Secrets never printed
Passwords are read from environment variables and cut from every line prodwalk prints or stores, as typed and in the encodings a URL, form, JSON or HTML would give them. Sign-in errors are withheld because they can quote the password.
Several roles, viewports and browsers
Each role signs in on its own session. Pages can be limited to roles and screen sizes, so a viewer being offered no Save button is one line.
Stall watchdog
Exit 3 with the last step that finished when a walk stops making progress. A page that stops answering fails one check, not the run.
Console, page-error and CSP checks
Fail the walk on any of them. WebKit's reads cancelled by a navigation are not counted.

What you get

prodwalk 1.0.1: the prodwalk command and Python hooks, a stand-in demo site, example walk files and the full test suite, with 129 automated tests.

A commercial license. Use it and change it in your own projects and your clients' projects. Don't share or resell the source. Read the license.

Every update. New versions land in the same repository; git pull to get them.

Requirements

Python 3.10 or newer. Python 3.10 or newer and Playwright, with a browser it can launch (pip install "./prodwalk[browser]" then playwright install chromium). Point it only at sites you are entitled to test.

How buying works

  1. Enter your GitHub username. You'll see the account before you pay, so you can check it's yours.
  2. Pay $49, plus any sales tax shown at checkout, on Stripe's checkout page.
  3. Accept the invitation GitHub emails you. Signed in as that account, you'll also find it at github.com/dominares-tools/prodwalk/invitations. Invitations expire after 7 days; you can get a new one any time.
  4. Clone and install:
    git clone https://github.com/dominares-tools/prodwalk.git

    Private repo: sign in to GitHub on this computer first. Run gh auth login and choose HTTPS, or give git a personal access token when it asks for a password. To use an SSH key instead, clone git@github.com:dominares-tools/prodwalk.git.

    python3 -m venv .venv && . .venv/bin/activate
    pip install "./prodwalk[browser]"
    playwright install chromium

Questions

Do I need GitHub?

Yes. Access is a read-only invitation to a private repository, sent to the GitHub account you choose.

Can I get a refund?

Yes, within 14 days, no questions asked. Access ends when the refund goes through. Refund policy.

Who takes the payment?

Payments are handled by Stripe, which works out sales tax. Your receipt and card statement show Link (LINK.COM*), Stripe's checkout service.

Something wrong?

Email support@dominares.org. Every buyer of a tool shares its repository, so support happens by email rather than in GitHub issues.