New: You can now scan using Veriify from your Claude, Cursor and other AI dev tools using the connector or local MCP. Setup at veriify.io/documentation#mcp

Notice

Rubric changelog

What changed, and when

Every published version of the rubric, kept exactly as it was. A score cites the version that produced it, so an old score stays checkable against the rules that were actually in force.

v1.6.0

2026-08-08 Read v1.6.0 →

106 → 107 checks. Every change here belongs to the mobile scan mode, so website and AI-product scores are unchanged and remain directly comparable with v1.5.0.

  • STORE-A03 medium Target API below the upcoming Play minimum cap 8

v1.5.0

2026-08-08 Read v1.5.0 →

92 → 106 checks. Every change here belongs to the mobile scan mode, so website and AI-product scores are unchanged and remain directly comparable with v1.4.0.

New dimension: Store Readiness.

  • STORE-A01 high Target API level below Play's minimum cap 24
  • STORE-A02 high No 64-bit native libraries cap 12
  • STORE-A04 critical Artifact is not signed cap 30
  • STORE-A06 medium Permission requiring a Play declaration cap 20
  • STORE-A08 medium Advertising SDK without the AD_ID permission cap 5
  • STORE-A12 low Version code or name missing cap 4
  • STORE-A13 low Minimum SDK below Play's supported floor cap 4
  • MSEC-001 high Cleartext traffic permitted cap 24
  • MSEC-002 critical Debuggable release build cap 30
  • MSEC-003 medium Backup of app data allowed cap 10
  • MSEC-004 medium Component exported without a permission guard cap 20
  • MSEC-011 low Deep link without verification cap 8
  • MPRIV-002 low Third-party tracking SDK bundled cap 12
  • MPRIV-006 medium High-risk permission requested cap 15

v1.4.0

2026-08-07 Read v1.4.0 →

82 → 92 checks. Scores are not directly comparable with v1.3.0: a product with these problems will score lower than it did, without anything about it having changed.

  • UXA-009 medium Control without an accessible name cap 18
  • UXA-010 medium Invalid or misused ARIA cap 15
  • UXA-011 high Keyboard access broken cap 14
  • UXA-012 low Missing page structure cap 8
  • UXA-013 medium Data table not navigable cap 10
  • UXA-014 high Media without an alternative cap 12
  • UXA-015 low Broken list markup cap 6
  • UXA-016 medium Content does not adapt cap 10
  • UXA-017 low Missing document title cap 4
  • UXA-018 low Other WCAG violation cap 10

14 checks reworded for clarity, with no change to severity, cap, or dimension, so scoring is unaffected.

v1.3.0

2026-08-07 Read v1.3.0 →

69 → 82 checks. Scores are not directly comparable with v1.1.0: a product with these problems will score lower than it did, without anything about it having changed.

New dimensions: Genuineness & Integrity, AI Trustworthiness.

  • GEN-001 medium Pre-checked opt-in box cap 15
  • GEN-002 low Urgency/scarcity messaging cap 6
  • GEN-003 medium Fake countdown timer cap 10
  • GEN-004 low Confirmshaming decline text cap 6
  • GEN-005 low No verifiable business identity cap 4
  • GEN-006 low Undisclosed AI interaction cap 4
  • AIQ-001 critical Prompt injection / jailbreak succeeded cap 60
  • AIQ-002 high System prompt / hidden instructions leaked cap 36
  • AIQ-003 high Inaccurate answer (hallucination) cap 36
  • AIQ-004 high Confident fabrication on an unanswerable question cap 24
  • AIQ-005 medium Inconsistent answers across repeated runs cap 20
  • AIQ-006 medium No AI disclosure when asked cap 10
  • AIQ-007 high Produced unsafe or disallowed content cap 36

v1.1.0

2026-07-16 Read v1.1.0 →

58 → 69 checks. Scores are not directly comparable with v1.0.0: a product with these problems will score lower than it did, without anything about it having changed.

  • PERF-007 medium Poor Largest Contentful Paint (LCP) cap 10
  • PERF-008 medium High Cumulative Layout Shift (CLS) cap 8
  • SEC-013 high Outdated JavaScript library with known vulnerabilities cap 24
  • SEC-014 medium No SPF record cap 5
  • SEC-015 medium No or weak DMARC policy cap 5
  • SEC-016 high TLS certificate expired or expiring soon cap 30
  • SEC-017 low External script without Subresource Integrity cap 6
  • UXA-008 medium Low text contrast cap 12
  • CODE-007 high Dependency with known vulnerabilities cap 30
  • CODE-008 low Dev dependency with known vulnerabilities cap 10
  • CMP-005 low No security.txt cap 2

v1.0.0

2026-07-07

First published version, 58 checks across 8 dimensions.