Web Application Testing Checklist for 2026
Modern web apps have five testable layers. Skipping any one ships bugs to production. Here's the full checklist we use at QA Labs — from functional to accessibility to performance.

Web applications have gotten dramatically more complex in the last five years. Client-side rendering, edge functions, microservices, third-party integrations, and real-time data have created layers of risk that didn't exist when "web testing" meant clicking through pages.
Here's the five-layer checklist we use at QA Labs. It covers everything a modern web app needs to be tested for.
Layer 1 — Functional testing
- All user flows work end-to-end
- Form validation catches bad input
- Error states display correctly
- Auth flows (signup, login, reset, logout) behave
- Permission roles gate access correctly
- Edge cases (empty inputs, huge inputs, invalid characters) handled
- Session handling is correct
- Data persists across refreshes
Layer 2 — API testing
- Every endpoint returns expected data
- Auth headers required and validated
- Rate limits enforce
- Timeouts handled gracefully
- Concurrent requests don't corrupt data
- Third-party integrations handle failures
Layer 3 — Visual testing
- Layouts consistent across Chrome, Safari, Firefox, Edge
- Responsive design works on all breakpoints
- Fonts, colors, spacing match design
- No layout shift on load
- Images, icons, graphics render correctly
- Dark mode works (if applicable)
Layer 4 — Accessibility testing
- WCAG 2.1/2.2 AA compliance
- Keyboard-only navigation works
- Screen reader compatibility (VoiceOver, NVDA, TalkBack)
- Contrast ratios meet minimums
- Form labels and ARIA attributes correct
- Focus states visible
- Reduced-motion preferences respected
Layer 5 — Performance testing
Core Web Vitals meet targets (LCP <2.5s, INP <200ms, CLS <0.1)
- Load testing at expected peak traffic
- Stress testing beyond peak
- API response times meet SLOs
- CDN caching works
- Images optimized
- Bundle size within budget
How to run this checklist
- Functional + API + Visual: Every release
- Accessibility: Every feature touching UI
- Performance: Before major releases and after infrastructure changes
- Full 5-layer: Before major launches
Common mistakes
- Testing only the happy path
- Skipping accessibility because "users don't complain"
- Ignoring visual regression until users report it
- Treating performance as a pre-launch check instead of continuous
- Not integrating any of this into CI
Key takeaways
- Modern web apps have 5 testable layers
- Functional + API + Visual = every release
- Accessibility = every UI change
- Performance = continuous, not one-off
- CI integration prevents regression on all layers
Further reading
About the author
Senior QA Engineer →Senior QA Engineer · Quality Assurance Labs



