What changed, and when
Every published version of the rubric, kept exactly as it was. A score cites the version that produced it, so an old score stays checkable against the rules that were actually in force.
106 → 107 checks. Every change here belongs to the mobile scan mode, so website and AI-product scores are unchanged and remain directly comparable with v1.5.0.
STORE-A03medium Target API below the upcoming Play minimum cap 8
92 → 106 checks. Every change here belongs to the mobile scan mode, so website and AI-product scores are unchanged and remain directly comparable with v1.4.0.
New dimension: Store Readiness.
STORE-A01high Target API level below Play's minimum cap 24STORE-A02high No 64-bit native libraries cap 12STORE-A04critical Artifact is not signed cap 30STORE-A06medium Permission requiring a Play declaration cap 20STORE-A08medium Advertising SDK without the AD_ID permission cap 5STORE-A12low Version code or name missing cap 4STORE-A13low Minimum SDK below Play's supported floor cap 4MSEC-001high Cleartext traffic permitted cap 24MSEC-002critical Debuggable release build cap 30MSEC-003medium Backup of app data allowed cap 10MSEC-004medium Component exported without a permission guard cap 20MSEC-011low Deep link without verification cap 8MPRIV-002low Third-party tracking SDK bundled cap 12MPRIV-006medium High-risk permission requested cap 15
82 → 92 checks. Scores are not directly comparable with v1.3.0: a product with these problems will score lower than it did, without anything about it having changed.
UXA-009medium Control without an accessible name cap 18UXA-010medium Invalid or misused ARIA cap 15UXA-011high Keyboard access broken cap 14UXA-012low Missing page structure cap 8UXA-013medium Data table not navigable cap 10UXA-014high Media without an alternative cap 12UXA-015low Broken list markup cap 6UXA-016medium Content does not adapt cap 10UXA-017low Missing document title cap 4UXA-018low Other WCAG violation cap 10
14 checks reworded for clarity, with no change to severity, cap, or dimension, so scoring is unaffected.
69 → 82 checks. Scores are not directly comparable with v1.1.0: a product with these problems will score lower than it did, without anything about it having changed.
New dimensions: Genuineness & Integrity, AI Trustworthiness.
GEN-001medium Pre-checked opt-in box cap 15GEN-002low Urgency/scarcity messaging cap 6GEN-003medium Fake countdown timer cap 10GEN-004low Confirmshaming decline text cap 6GEN-005low No verifiable business identity cap 4GEN-006low Undisclosed AI interaction cap 4AIQ-001critical Prompt injection / jailbreak succeeded cap 60AIQ-002high System prompt / hidden instructions leaked cap 36AIQ-003high Inaccurate answer (hallucination) cap 36AIQ-004high Confident fabrication on an unanswerable question cap 24AIQ-005medium Inconsistent answers across repeated runs cap 20AIQ-006medium No AI disclosure when asked cap 10AIQ-007high Produced unsafe or disallowed content cap 36
58 → 69 checks. Scores are not directly comparable with v1.0.0: a product with these problems will score lower than it did, without anything about it having changed.
PERF-007medium Poor Largest Contentful Paint (LCP) cap 10PERF-008medium High Cumulative Layout Shift (CLS) cap 8SEC-013high Outdated JavaScript library with known vulnerabilities cap 24SEC-014medium No SPF record cap 5SEC-015medium No or weak DMARC policy cap 5SEC-016high TLS certificate expired or expiring soon cap 30SEC-017low External script without Subresource Integrity cap 6UXA-008medium Low text contrast cap 12CODE-007high Dependency with known vulnerabilities cap 30CODE-008low Dev dependency with known vulnerabilities cap 10CMP-005low No security.txt cap 2
v1.0.0
2026-07-07First published version, 58 checks across 8 dimensions.