
HTML Snippet — Faq Page Snippet
Minimal SAMPLE HTML (faq-page-snippet) for meta/JSON-LD/DOM parser tests.
- File
- HTML · Source
- Use case
- Editor testingWeb assets· Conversion set
Favicons, web app manifests, service workers, robots and sitemap files, Open Graph images, and .well-known resources — for testing web tooling, crawlers, PWA installers, and asset pipelines.

Minimal SAMPLE HTML (faq-page-snippet) for meta/JSON-LD/DOM parser tests.

Minimal SAMPLE HTML (jsonld-inline-faq) for meta/JSON-LD/DOM parser tests.

Minimal SAMPLE HTML (meta-description-sample) for meta/JSON-LD/DOM parser tests.

Minimal SAMPLE HTML (open-graph-sample) for meta/JSON-LD/DOM parser tests.

A true variable font: three interpolating masters compiled through fontTools varLib, so the wght axis carries real gvar and HVAR deltas rather than an fvar record over static outlines. Five named instances and a STAT table with a Regular-to-Bold linked value. Original typeface, free to use.

The wght variable font wrapped as WOFF — the same fvar/gvar payload in the web container, for testing that a compressor or a CDN pipeline preserves variation data. Original typeface, free to use.

The wght variable font wrapped as WOFF2 — the same fvar/gvar payload in the web container, for testing that a compressor or a CDN pipeline preserves variation data. Original typeface, free to use.

A single-axis variable font on the registered wdth axis, built from 3 interpolating masters so the deltas are real — advance widths and glyph boxes narrow and widen with the axis. Named instances and a STAT table are included. Original typeface, free to use.

A single-axis variable font on the registered slnt axis, built from 2 interpolating masters so the deltas are real — the whole face shears forward as slnt goes negative, with the axis maximum equal to the default. Named instances and a STAT table are included. Original typeface, free to use.

A single-axis variable font on the registered opsz axis, built from 3 interpolating masters so the deltas are real — stems thicken and tracking opens at small optical sizes and reverse at display sizes. Named instances and a STAT table are included. Original typeface, free to use.

A two-axis variable font (weight by width) built from seven masters, with all nine named instances from Condensed Regular to Expanded Black and a two-axis STAT table. For testing instance pickers, axis sliders, and CSS font-variation-settings with more than one axis in play. Original typeface, free to use.

The two-axis variable font as WOFF2 — the container a real site would ship. For testing that variation tables survive Brotli packing and that a two-axis slider still works after decompression. Original typeface, free to use.

All four registered axes in one face — weight, width, slant and optical size — from eight axis-extreme masters. The font a variation UI should be tested against before it meets a real four-axis release. Original typeface, free to use.

The four-axis variable font as WOFF2. For testing web font loaders and CSS font-variation-settings against a face with more axes than a typical release. Original typeface, free to use.

A variable font whose outlines are CFF2 rather than glyf, so the variation deltas live inside blended charstrings and there is no gvar table at all. The case that breaks tools which assume every variable font is TrueType-flavoured. Original typeface, free to use.

The two-axis font with its width axis pinned to Condensed and its weight axis left live — the shipping shape for a site that wants one width but the whole weight range. For testing that a loader reads the reduced fvar rather than the original axis list. Original typeface, free to use.

A real static instance cut from the wght variable font at 300 — outlines interpolated once and baked, fvar and gvar stripped, usWeightClass set to match. For testing static-versus-variable fallback paths and family/style grouping. Original typeface, free to use.

A real static instance cut from the wght variable font at 400 — outlines interpolated once and baked, fvar and gvar stripped, usWeightClass set to match. For testing static-versus-variable fallback paths and family/style grouping. Original typeface, free to use.

A real static instance cut from the wght variable font at 500 — outlines interpolated once and baked, fvar and gvar stripped, usWeightClass set to match. For testing static-versus-variable fallback paths and family/style grouping. Original typeface, free to use.

A real static instance cut from the wght variable font at 700 — outlines interpolated once and baked, fvar and gvar stripped, usWeightClass set to match. For testing static-versus-variable fallback paths and family/style grouping. Original typeface, free to use.

A real static instance cut from the wght variable font at 900 — outlines interpolated once and baked, fvar and gvar stripped, usWeightClass set to match. For testing static-versus-variable fallback paths and family/style grouping. Original typeface, free to use.

A two-axis instance baked out of the weight-by-width variable font, with both usWeightClass and usWidthClass set to match. For testing that a family grouper reads width from OS/2 rather than guessing it from the style name. Original typeface, free to use.

A COLR version 0 colour font: three Private Use Area icons, each drawn as two layer glyphs that index CPAL palette entries, with ordinary monochrome glyf outlines underneath as the fallback. The baseline colour-font case that every modern browser supports. Original typeface, free to use.

The COLR v0 colour font as WOFF2 — for testing that a web-font pipeline keeps COLR and CPAL rather than stripping them as unknown tables. Original typeface, free to use.

A COLR version 1 colour font built as a real paint graph: a linear gradient with pad extend, a radial gradient with reflect, a repeating three-stop gradient, and a solid paint with fractional alpha. For testing gradient support, extend-mode handling, and the v1-to-v0 fallback path. Original typeface, free to use.

The COLR v1 gradient font as WOFF2 — the shape a site would actually serve. For testing that gradient paint graphs survive web-font compression intact. Original typeface, free to use.

A colour font carrying four CPAL palettes with name-table labels and palette-type flags, two of them marked usable with a light or a dark background. For testing palette pickers, the CSS font-palette property, and renderers that only ever read palette zero. Original typeface, free to use.

COLR and CPAL over CFF rather than glyf outlines. COLR is outline-agnostic by specification, but plenty of tooling assumes colour fonts are TrueType-flavoured — this is the file that finds out. Original typeface, free to use.

An OpenType-SVG colour font: one inline SVG document per icon glyph, each with its own gradient, plus glyf outlines for renderers with no SVG support. For testing the fourth colour-font path and how a rasteriser handles vector colour it has to parse rather than paint. Original typeface, free to use.

Standard and discretionary ligature substitutions in a real GSUB table: four liga ligatures including the three-glyph ffi, and two dlig ligatures that must stay off unless asked for. Each ligature's advance is the sum of its parts minus a documented tuck, so a shaping result is checkable by measuring. Original typeface, free to use.

Eighteen kerning pairs published as a GPOS pair-positioning lookup, with no legacy kern table present. Pair it with its kern-table twin to find out which table your layout engine is actually reading. Original typeface, free to use.

Contextual alternate substitution that fires on doubled letters: the second letter of aa, ee, oo, nn, ss and tt is replaced by an alternate carrying a visible baseline underscore, so a shaping result can be read straight off the page instead of out of a debug log. calt is on by default, which makes it a good test of whether a renderer applies default features at all. Original typeface, free to use.

A full 26-glyph small-capital set reachable through smcp from lowercase and c2sc from capitals. Because the lowercase of this face is unicase, the small caps sit at a third, measurable height: 560 design units against 500 for lowercase and 700 for capitals, so a failed substitution shows up as a height rather than as a subtle shape difference. Original typeface, free to use.

Three stylistic sets, each with a human-readable name published through FeatureParams in the name table — the metadata a font menu needs to show 'Squared G and R' instead of 'ss01'. For testing feature-name discovery as much as the substitution itself. Original typeface, free to use.

All four figure features over one digit set: the default is proportional lining, tnum flattens every digit to 620 units for column alignment, pnum restores the proportional widths, and onum drops five digits below the baseline and raises two above the x-height. The measurable case for testing font-variant-numeric. Original typeface, free to use.

Every feature this family defines in one face — ligatures, kerning, contextual alternates, small caps, three stylistic sets, four figure features, fractions, mark attachment, aalt and locl. The single font to point a feature-discovery UI at. Original typeface, free to use.

The all-features font as WOFF2, for testing that a web-font build step preserves GSUB, GPOS and GDEF instead of subsetting the layout tables away by default. Original typeface, free to use.

The complete face the rest of the subset set is cut from: the whole glyph repertoire with ligatures, kerning, contextual alternates, small caps, stylistic sets, figures, fractions, marks and localised forms intact. Measure it, then measure the cuts. Original typeface, free to use.

The full face as WOFF2 — the honest baseline for a subsetting benchmark, since comparing a subsetted WOFF2 against an unsubsetted TTF measures Brotli rather than the subsetter. Original typeface, free to use.

The full face subset to U+0020-U+007E (printable ASCII) — the range a Latin-only page actually needs. Layout features are kept, so lookups whose glyphs were removed are the ones you can watch disappear. Original typeface, free to use.

The latin basic subset in the container a site would serve, so a size comparison against the full WOFF2 measures the subset rather than the compressor. Original typeface, free to use.

The full face subset to the 8 codepoints of the string NOVUS 07 — the extreme case a headline-only web font gets cut down to. Layout features are kept, so lookups whose glyphs were removed are the ones you can watch disappear. Original typeface, free to use.

The headline subset in the container a site would serve, so a size comparison against the full WOFF2 measures the subset rather than the compressor. Original typeface, free to use.

The full face subset to U+0030-U+0039 (digits only) — a numeric-display cut, the shape a dashboard font ends up. Layout features are kept, so lookups whose glyphs were removed are the ones you can watch disappear. Original typeface, free to use.

The digits subset in the container a site would serve, so a size comparison against the full WOFF2 measures the subset rather than the compressor. Original typeface, free to use.

A subset cut to just the characters the kerning, ligature, small-cap and figure probes need, keeping every OpenType layout feature whose glyphs survived. Half of a pair whose only difference is the layout tables — the pair that shows what a default subsetter setting silently costs you. Original typeface, free to use.

The uncompressed TrueType (glyf) source for this container set. Every WOFF and WOFF2 file in the group is packed from exactly these bytes, so a compression comparison is measuring the container and nothing else. Original typeface, free to use.

The same TrueType (glyf) face in a WOFF container, 49 percent of the raw sfnt size. Compare it against the other three containers in this group to see how much of a web font's weight is the format and how much is the design. Original typeface, free to use.

The same TrueType (glyf) face in a WOFF2 container, 33 percent of the raw sfnt size. Compare it against the other three containers in this group to see how much of a web font's weight is the format and how much is the design. Original typeface, free to use.

The uncompressed CFF (Type 2) source for this container set. Every WOFF and WOFF2 file in the group is packed from exactly these bytes, so a compression comparison is measuring the container and nothing else. Original typeface, free to use.

The same CFF (Type 2) face in a WOFF container, 55 percent of the raw sfnt size. Compare it against the other three containers in this group to see how much of a web font's weight is the format and how much is the design. Original typeface, free to use.

The same CFF (Type 2) face in a WOFF2 container, 45 percent of the raw sfnt size. Compare it against the other three containers in this group to see how much of a web font's weight is the format and how much is the design. Original typeface, free to use.

A WOFF file carrying the optional extended-metadata block from the WOFF specification — vendor, credits, description and licence as XML alongside the font, outside the sfnt tables. Most converters drop it silently; this is the file that proves whether yours does. Original typeface, free to use.

A WOFF2 file carrying the optional extended-metadata block from the WOFF specification — vendor, credits, description and licence as XML alongside the font, outside the sfnt tables. Most converters drop it silently; this is the file that proves whether yours does. Original typeface, free to use.

One design in TrueType outlines: quadratic contours in a glyf table with a loca index. Its CFF twin carries the same design in cubic charstrings, so converting one and diffing against the other tests an outline converter rather than a whole font pipeline. Original typeface, free to use.

The same design in CFF outlines: cubic Type 2 charstrings with no glyf and no loca. The half of the pair that catches code assuming every OpenType font is TrueType-flavoured. Original typeface, free to use.

A multi-resolution favicon.ico bundling 16, 32, 48, and 64 px images of the brand mark — for testing favicon parsers, ICO decoders, and multi-image icon handling.
A scalable SVG favicon of the brand mark — the modern crisp-at-any-size icon format, for testing SVG favicon support and vector-to-raster favicon pipelines.

A 180×180 opaque PNG apple-touch-icon (iOS rounds the corners itself) — for testing home-screen icon extraction and Apple touch-icon handling.

A 32×32 Windows arrow cursor with its hotspot at the top-left tip (0,0) — for testing .cur parsers, CSS custom cursors, and ICO/CUR converters.

A 32×32 Windows crosshair cursor with its hotspot at the centre (16,16) — for testing cursor hotspot handling and .cur decoding.

A complete Progressive Web App manifest with a full icon spread, shortcuts, categories, and theme colours — for testing PWA installers, manifest validators, and JSON parsers.

A sample cache-first service worker handling install, activate, and fetch events with an offline fallback — for testing service-worker registration, JS parsers, and PWA tooling.

A browserconfig.xml defining Windows Start-menu tile logos and colour — for testing MS tile configuration parsers and XML handling.

A 192×192 PNG app icon referenced by the web app manifest (purpose 'any') — for testing PWA icon pipelines and manifest icon resolution.

A 512×512 PNG app icon referenced by the web app manifest (purpose 'any') — for testing PWA icon pipelines and manifest icon resolution.

A 512×512 maskable PNG icon with the mark inside the central safe-zone and a full-bleed background — for testing maskable icon cropping across Android adaptive-icon shapes.

A 1200×630 Open Graph preview card at the exact og:image aspect ratio — for testing link-preview generators, social-card renderers, and image pipelines.

A 1200×600 Twitter summary-large-image card at the 2:1 aspect ratio — for testing Twitter/X card renderers and social preview pipelines.

A robots.txt with wildcard and per-agent rules, a crawl-delay, and a sitemap reference — for testing robots parsers and crawler policy handling.

An XML sitemap (sitemaps.org 0.9) with loc, lastmod, changefreq, and priority for several URLs — for testing sitemap parsers and crawl-scheduling tools.

A humans.txt crediting the people and stack behind a site, in the conventional TEAM/SITE block format — for testing plain-text metadata parsers.

An IAB ads.txt listing authorised digital sellers with account IDs and relationships (sample data) — for testing ads.txt parsers and ad-fraud tooling.

An RFC 9116 security.txt with Contact, Expires, Encryption, and Policy fields — normally served at /.well-known/security.txt, for testing security.txt parsers.

An Apple app-site-association file declaring Universal Links, web credentials, and app clips — normally served without an extension at /.well-known/, for testing AASA parsers (shown here as .json).

An Android Digital Asset Links file granting app-link handling to a package via a certificate fingerprint (sample) — for testing assetlinks.json parsers and App Links verification.
An SVG sprite sheet defining five reusable icons as <symbol> elements referenced by <use href='#id'> — for testing SVG sprite pipelines and icon systems. Paired with a PNG sprite twin.

A 320×64 PNG icon sprite (five 64×64 cells) — the raster twin of the SVG sprite, for testing background-position sprite techniques and sprite slicers.

PWA web app manifest SAMPLE for installability and manifest validators.

Cache-first SAMPLE service worker for PWA offline-shell registration tests.

PWA shell fixture SAMPLE (offline.html) for offline app-shell testing.

PWA shell fixture SAMPLE (index-shell.html) for offline app-shell testing.

PWA shell fixture SAMPLE (sw-register.js) for offline app-shell testing.

PWA shell fixture SAMPLE (app-shell.css) for offline app-shell testing.

192×192 PWA icon SAMPLE for manifest icon pipelines.

512×512 PWA icon SAMPLE for manifest icon pipelines.

RFC 9116 security.txt SAMPLE variant (security-txt-full.txt) for well-known parsers.

RFC 9116 security.txt SAMPLE variant (security-txt-minimal.txt) for well-known parsers.

RFC 9116 security.txt SAMPLE variant (security-txt-expired.txt) for well-known parsers.

RFC 9116 security.txt SAMPLE variant (security-txt-multi-contact.txt) for well-known parsers.

RFC 9116 security.txt SAMPLE variant (security-txt-pgp.txt) for well-known parsers.

robots.txt — Wave G SAMPLE for crawler and .well-known tooling.

humans.txt — Wave G SAMPLE for crawler and .well-known tooling.

ads.txt — Wave G SAMPLE for crawler and .well-known tooling.

change-password — Well-Known SAMPLE for crawler and .well-known tooling.

GPC — Global Privacy Control SAMPLE for crawler and .well-known tooling.

PWA shortcut descriptor SAMPLE #1 for install UI tests.

PWA shortcut descriptor SAMPLE #2 for install UI tests.

PWA shortcut descriptor SAMPLE #3 for install UI tests.

PWA shortcut descriptor SAMPLE #4 for install UI tests.

PWA shortcut descriptor SAMPLE #5 for install UI tests.

PWA shortcut descriptor SAMPLE #6 for install UI tests.

PWA shortcut descriptor SAMPLE #7 for install UI tests.

PWA shortcut descriptor SAMPLE #8 for install UI tests.

Well-known security contact JSON SAMPLE #1.

Well-known security contact JSON SAMPLE #2.

Well-known security contact JSON SAMPLE #3.

Well-known security contact JSON SAMPLE #4.

Well-known security contact JSON SAMPLE #5.

Well-known security contact JSON SAMPLE #6.

Well-known security contact JSON SAMPLE #7.

Well-known security contact JSON SAMPLE #8.

.well-known SAMPLE JSON (related-website-set) for crawler and client discovery tests.

.well-known SAMPLE JSON (web-identity) for crawler and client discovery tests.

.well-known SAMPLE JSON (passkey-endpoints) for crawler and client discovery tests.

.well-known SAMPLE JSON (privacy-sandbox-attest) for crawler and client discovery tests.

.well-known SAMPLE JSON (nodeinfo-stub) for crawler and client discovery tests.

.well-known SAMPLE JSON (webfinger-resource) for crawler and client discovery tests.

.well-known SAMPLE JSON (openid-configuration-min) for crawler and client discovery tests.

.well-known SAMPLE JSON (assetlinks-extra) for crawler and client discovery tests.

SAMPLE crawler/policy text file (robots-disallow-admin) for bot and ads.txt parsers.

SAMPLE crawler/policy text file (robots-ai-bots) for bot and ads.txt parsers.

SAMPLE crawler/policy text file (humans-extended) for bot and ads.txt parsers.

SAMPLE crawler/policy text file (security-txt-contact) for bot and ads.txt parsers.

SAMPLE crawler/policy text file (ads-txt-sample) for bot and ads.txt parsers.

SAMPLE crawler/policy text file (app-ads-txt-sample) for bot and ads.txt parsers.

schema.org JSON-LD SAMPLE (faq-page) for SEO/structured-data validators.

schema.org JSON-LD SAMPLE (howto-step) for SEO/structured-data validators.

schema.org JSON-LD SAMPLE (organization) for SEO/structured-data validators.

schema.org JSON-LD SAMPLE (breadcrumb) for SEO/structured-data validators.

schema.org JSON-LD SAMPLE (software-app) for SEO/structured-data validators.

schema.org JSON-LD SAMPLE (web-page) for SEO/structured-data validators.

.well-known SAMPLE JSON (change-password-rel) for crawler and client discovery tests.

.well-known SAMPLE JSON (gpc-policy) for crawler and client discovery tests.

A robots.txt built entirely from pattern rules: `*` inside a path, `$` anchoring the end of a URL, a query-string pattern, and an Allow that carves one file out of a disallowed subtree. For testing that a robots parser implements RFC 9309 path matching rather than prefix comparison.

A robots.txt where Googlebot is named by two separate groups and every Disallow has an equal-length Allow competing with it. For testing group merging, case-insensitive product tokens, and the rule that the most specific match wins with Allow breaking ties.

A robots.txt carrying three different crawl-rate hints - an integer Crawl-delay, a fractional one alongside Request-rate and Visit-time, and a very large one - none of which are part of RFC 9309. For testing that a crawler reads or ignores rate hints without dropping the Disallow rules that share the group.

A robots.txt declaring five sitemaps - before the first group, inside two different groups, in lower case, gzipped, and on another host. For testing that a discovery crawler collects Sitemap as a file-global field instead of scoping it to the group it sits in.

A robots.txt that disallows the entire site for every crawler while allowing one media path for a single image agent. For testing full-block handling and the common misconception that a Disallow removes a URL from a search index.

A robots.txt in which real Disallow rules are surrounded by Noindex, Host, Clean-param, Nofollow and two invented fields, several with inline comments. For testing that a parser skips fields it does not implement instead of aborting or mis-binding the rules that follow.

A robots.txt that begins with a UTF-8 byte-order mark, uses CRLF line endings, and leaves trailing spaces after two rule values. For testing the byte-level tolerances RFC 9309 requires - a leading BOM must be discarded rather than glued onto the first field name.

A robots.txt using upper-case, mixed-case and indented field names, a tab-indented rule, a value with no space after the colon, and both trailing and full-line comments. For testing that field names are treated case-insensitively while path values stay case-sensitive.

A deliberately invalid robots.txt: a rule before any group, an empty product token, an absolute URL where a path belongs, whitespace before the colon, a non-numeric Crawl-delay, and a line with no colon at all. For testing that a parser degrades line-by-line instead of failing the whole file.

The single most common broken robots.txt in the wild: a server that answers /robots.txt with its HTML 404 page instead of a 404 status. For testing that a crawler treats unparseable markup as 'no robots.txt' and allows the site rather than inventing rules from tag names.

A sitemap index listing three child sitemaps, one dated with a plain date, one with a full W3C datetime, and one with no lastmod at all. Two of the children ship alongside it, so a crawler can be walked from index to URL.

The first child of the sitemap index: six core URLs with a deliberately uneven mix of lastmod, changefreq and priority, including one entry that carries nothing but a loc. For testing that optional sitemap fields really are optional.

The second child of the sitemap index: six URLs dated with W3C datetimes in two different timezone offsets, including a changefreq of never and a priority of 0.1. For testing datetime normalisation and priority ordering.

A sitemap whose three URLs form a complete hreflang cluster: every page lists every locale including itself and a shared x-default. This is the shape an international audit should pass, and the reference twin of the broken cluster.

A deliberately invalid hreflang cluster: an `en-UK` region that does not exist, an underscore locale, a German page that never links back, a Spanish self-reference dropped to http, and no x-default anywhere. For testing that an international audit reports each defect rather than the first one.

A sitemap using the image extension namespace: six images across three pages, with and without titles and captions, in JPEG, WebP and AVIF. For testing extension-namespace parsing and image-discovery pipelines.

A sitemap using the video extension namespace: one fully populated entry with duration, rating, view count, country restriction and tags, and one minimal entry with only the required children plus a player attribute. For testing video-sitemap parsers and their attribute handling.

A two-URL news sitemap with publication name, language, publication date and headline for an English and a German article. For testing nested extension elements and per-article language handling.

A sitemap of URLs that need both layers of escaping the format demands: ampersands written as XML entities and reserved characters percent-encoded, plus a punycode host. For testing that a parser unescapes exactly once and does not double-decode.

The plain-text sitemap format the sitemaps.org protocol also accepts: one absolute URL per line, no markup, UTF-8 encoded. For testing that a crawler supports the text form as well as XML.

A 500-URL sitemap served the way large sites serve them - gzip-compressed as sitemap-large.xml.gz. The gzip header carries mtime 0 and no embedded filename, so the bytes are stable across regenerations. For testing that a crawler decompresses .xml.gz sitemaps before parsing.

A one-line minified bundle built from two ES modules, ending in the `//# sourceMappingURL=` comment that points at the v3 map shipped beside it. For testing that a debugger, error reporter or bundler analyser follows the annotation and resolves the map relative to the bundle.

A complete v3 source map for the minified bundle: two sources with their full original text inlined in sourcesContent, two names, and five VLQ-encoded mapping segments. For testing source-map decoders and stack-trace symbolication without any network fetch of the originals.

The same v3 map with the sourcesContent array removed, which is how most production builds ship: the mappings resolve but the original text has to be fetched from the paths in `sources`. For testing the fallback path of a debugger when originals are unavailable.

The same bundle with its v3 map embedded as a base64 data: URI in the sourceMappingURL comment - the single-file form dev builds emit. For testing that a tool decodes an inline map instead of trying to fetch it as a relative path.

An index map: instead of a top-level `mappings` string it carries a `sections` array of offset-and-map pairs, the form used when several independently built chunks are concatenated. For testing decoders that assume every map has mappings at the root.

A minified stylesheet closing with the CSS form of the annotation, `/*# sourceMappingURL= */` - the comment syntax differs from JavaScript's and is a common reason a CSS map is silently ignored. For testing stylesheet source-map resolution.

The v3 map for the minified stylesheet: one source with its text inlined, an empty names array, and three segments covering the selector and both declarations. For testing that a decoder handles maps with no names at all.

A v3 map that resolves its sources through a `sourceRoot` scheme URL, uses `../` relative paths, leaves one sourcesContent entry null, and marks the second source as third-party via x_google_ignoreList. For testing URL joining and ignore-list support in a debugger.

A deliberately invalid source map: version 2 instead of 3, a sources array longer than sourcesContent, a mapping segment that names an index outside `names`, and a `$` that is not in the base64 VLQ alphabet. For testing that a decoder validates the envelope before trusting the mappings.

A web app manifest whose icon array is built entirely from the awkward cases: a duplicate declaration, an entry with no sizes, sizes="any" on an SVG, a multi-size ICO, a .webp declared as image/png, a cross-origin icon and a 0x0 entry. For testing icon selection and validation logic.

A manifest exercising every icon `purpose` keyword: any, maskable, the space-separated combination, monochrome for a notification badge, and the obsolete `badge` value. For testing purpose parsing and adaptive-icon safe-zone handling.

The smallest manifest that still satisfies a browser's install criteria: name, start_url, a standalone display mode and two PNG icons, with every optional member left out. For testing installability checks against the floor rather than a fully populated document.

A deliberately invalid manifest: well-formed JSON with an empty icons array, so it parses cleanly and then fails installability. For testing that a PWA validator distinguishes a parse error from an unmet install requirement.

A manifest declaring a Web Share Target that accepts a POST of multipart form data, including two file parameters with MIME-type and extension accept lists. For testing share-target registration and the parameter renaming a share handler must perform.

A manifest registering the desktop-integration members: two file handlers with MIME and extension accept maps, a custom web+ protocol handler alongside mailto, a launch_handler client mode list, an Edge side-panel width and handle_links. For testing OS integration and manifest members a validator may not know.

A manifest with the members that turn a bare install prompt into a rich one: four screenshots split across wide, narrow and unspecified form factors, labels, categories and two shortcuts (one with its own icon). For testing rich-install eligibility rules.

A deliberately invalid manifest: start_url sits at /dashboard/ while scope is /app/, and a shortcut points at another origin entirely. Both are the kind of mistake that makes an installed app open in a browser tab. For testing scope-containment validation.

An SMTP MTA-STS policy in enforce mode listing three MX patterns, one of them a wildcard, with a seven-day max_age. RFC 8461 specifies CRLF line endings, so this fixture is written with them deliberately - for testing policy parsers that split on bare LF.

A sample machine-discoverable Do Not Track policy of the kind served at /.well-known/dnt-policy.txt, stating retention windows, exceptions and a contact for a fictional site. For testing crawlers and privacy scanners that look for the document and read its version header.

Host metadata in its original XRD form: a subject, an alias, an expiry, one property, and three Link elements including an lrdd template with a {uri} placeholder. Paired with the JRD twin that carries exactly the same data.

The JSON Resource Descriptor twin of the XRD host-meta: identical subject, alias, expiry, property and three links, expressed with lower-case JSON member names. For testing XRD-to-JRD conversion against a known answer.

A traffic-advice document opting a fictional origin into private prefetch proxy traffic at full fraction while disallowing every other agent. For testing prefetch-proxy discovery and the JSON-array (not object) top level this format uses.

The one-member server-delegation document that lets example.com host its Matrix homeserver at matrix.example.com:8448 without changing user IDs. For testing federation discovery and explicit-port handling.

The client-side twin of the Matrix delegation pair: homeserver and identity server base URLs plus an unregistered vendor key, which clients must carry through rather than reject. For testing discovery and unknown-member tolerance.

A fully populated RFC 8414 authorization-server metadata document for a fictional issuer: seven endpoints including PAR, introspection and dynamic registration, PKCE and DPoP algorithm lists, and policy URIs. Distinct from the minimal OpenID configuration already in this category.

The baseline every canonical audit should pass: one self-referential canonical, an indexable robots meta, matching hreflang self-reference and an og:url that agrees with all of them. For use as the comparison reference against the conflicting pages in this set.

Page A of a deliberately invalid two-page canonical loop: A declares B canonical while B declares A canonical, so no page in the pair is its own canonical. For testing that a crawler detects the cycle instead of following it forever.

Page B of the deliberately invalid canonical loop, closing the cycle by naming page A as its canonical. Ships with page A so the loop can actually be traversed rather than described.

A deliberately invalid page carrying two canonical tags in the head and a third in the body. Search engines ignore body-level canonicals entirely and treat multiple head-level ones as a conflict. For testing that an extractor reports position as well as value.

A page that names itself canonical while telling robots not to index it, and then contradicts that again with an agent-specific googlebot meta that permits indexing. For testing directive precedence when a page argues with itself.

The English member of a correct three-locale hreflang cluster: it lists itself, both translations and the x-default, and its canonical agrees. Ships with the German page so reciprocity can be verified across real files.

The German member of the same cluster, with lang="de" on the html element and the identical alternate block. For testing that an audit compares the annotation set rather than the document language, and that the two agree.

A deliberately invalid annotation block: `en-UK` is not a region code, `de_DE` uses an underscore, `zz` is not a language, one alternate has no hreflang attribute at all, one drops to http, there is no x-default, and the canonical points outside the cluster. For testing that every defect is reported, not just the first.

A valid Product record with a nested Offer carrying price, currency, availability, condition and shipping details, plus an AggregateRating. For testing rich-result validators and structured-data extractors against a document that should pass cleanly.

A valid NewsArticle with two authors, a publisher whose logo carries explicit pixel dimensions, three images at the aspect ratios news results expect, and both publication and modification timestamps. For testing article extraction and date normalisation.

A valid Event record for a hybrid event: both a physical Place with a postal address and geo coordinates and a VirtualLocation, plus a free Offer and a capacity. For testing array-valued properties and event date/timezone handling.

A valid Recipe with ISO 8601 durations, four ingredients, and instructions that mix flat HowToStep nodes with a nested HowToSection. For testing duration parsing and recursive instruction extraction.

A valid LocalBusiness (as a SportingGoodsStore subtype) with a postal address, geo coordinates, weekday and Saturday opening hours, and a 00:00-00:00 specification marking a holiday closure. For testing opening-hours parsing and the closed-all-day convention.

A single @graph holding four nodes wired together by @id rather than by nesting - the shape most CMS plugins emit - including a SearchAction, a breadcrumb whose last item has no URL, and one reference to a product node that lives on another page. For testing graph flattening and reference resolution.

A deliberately invalid Product record: no name, an Offer with a currency but no price, a brand with no @type, a Review with no rating, an AggregateRating with no ratingValue, and an availability given as a bare token instead of a schema.org URL. Valid JSON throughout, so the failure is semantic.

A deliberately invalid Recipe carrying six unambiguously wrong-typed values - a numeric datePublished, a prose prepTime where an ISO 8601 duration belongs, an object recipeYield, two non-numeric ratings and a misspelled @type - plus a relative @context that never resolves, an untyped image object and two ingredients crammed into one string. For testing the limits of type coercion.

Four articles of a fictional publication as RSS 2.0, with a self-referential atom:link, non-permalink tag: GUIDs, RFC 822 dates and full HTML bodies in content:encoded. One of three twins carrying identical content, so a feed converter can be diffed against a known answer.

The same four articles as Atom 1.0: tag: ids identical to the RSS twin, RFC 3339 published and updated timestamps, escaped HTML content, and both alternate and self links. For diffing an RSS-to-Atom converter against a known answer.

The third twin: the same four articles as JSON Feed 1.1, using the 1.1 `authors` array rather than the 1.0 singular form, with ids, URLs, summaries, HTML bodies and timestamps identical to the RSS and Atom files. The reference output for an XML-to-JSON feed converter.

SAMPLE HTTP security header fixture (strict-transport-security) for scanner regression.

SAMPLE HTTP security header fixture (content-security-policy-report) for scanner regression.

SAMPLE HTTP security header fixture (permissions-policy) for scanner regression.

SAMPLE HTTP security header fixture (cross-origin-opener) for scanner regression.

SAMPLE HTTP security header fixture (cross-origin-embedder) for scanner regression.

SAMPLE HTTP security header fixture (cross-origin-resource) for scanner regression.

SAMPLE HTTP security header fixture (referrer-policy-strict) for scanner regression.

SAMPLE HTTP security header fixture (x-content-type-options) for scanner regression.

SAMPLE HTTP security header fixture (x-frame-options-deny) for scanner regression.

SAMPLE HTTP security header fixture (expect-ct-legacy) for scanner regression.
We use Google Analytics and show ads via Adsterra. Non-essential cookies and ad scripts run only after you allow the matching categories. See our cookie policy.