
Product
Socket Now Protects the Firefox Extension Ecosystem
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.
@vertaaux/cli
Advanced tools
Run UX and accessibility audits from the terminal or CI pipelines.
npm install -g @vertaaux/cli
Or run with npx:
npx @vertaaux/cli --help
# 1. Authenticate
vertaa login
# 2. Run an audit
vertaa audit https://example.com --wait
# 3. Check CLI health
vertaa doctor
The CLI checks for credentials in this order:
Environment variables (checked in order):
VERTAAUX_TOKENVERTAAUX_API_KEYStored credentials from interactive login:
vertaa login
Credentials are stored in ~/.vertaaux/credentials.json.
Direct token for CI/non-interactive use:
vertaa login --token <api-key>
Verify authentication:
vertaa whoami
| Command | Description |
|---|---|
audit <url> | Run UX and accessibility audit |
baseline [job-id] | Create or update audit baseline |
diff | Compare current audit against baseline |
policy init|validate|show|schema | Manage policy-as-code |
| Command | Description |
|---|---|
explain <finding-id> | Show evidence bundle for a finding |
comment | Generate PR comment from audit results |
fix <job-id> | Generate a fix patch for an issue |
fix-all <job-id> | Generate fix patches for all issues |
verify | Verify that a patch fixes an issue |
| Command | Description |
|---|---|
doctor | Diagnose CLI health (config, auth, network) |
login | Authenticate with VertaaUX |
logout | Clear stored credentials |
whoami | Show current authentication status |
init | Create .vertaaux.yml configuration |
status <job-id> | Check audit job status |
upload <file> | Upload audit results to cloud storage |
download <id> | Download audit results from cloud storage |
| Command | Alias For |
|---|---|
a11y <url> | Accessibility-focused audit (filters for a11y issues) |
scan <url> | UX scan (alias for audit) |
compare <urlA> <urlB> | Compare audits of two URLs |
Formats are per-command, not global. Each command supports a different set of formats:
| Command | Formats | Default |
|---|---|---|
audit | human, json, sarif, junit, html | human |
comment | json, markdown | markdown |
explain | human, json | human |
policy show | json, yaml | yaml |
diff | human, json | human |
Usage:
vertaa audit https://example.com --format json
vertaa audit https://example.com --format sarif > results.sarif
vertaa comment --input results.json --format markdown
The --machine global flag enables strict machine-readable mode:
{
"meta": {
"version": "0.1.0",
"timestamp": "2026-02-08T12:00:00.000Z",
"command": "audit",
"args": ["https://example.com", "--format", "json"]
},
"data": {
"scores": { "overall": 85 },
"issues": []
}
}
All diagnostic output goes to stderr, keeping stdout clean for piping:
vertaa audit https://example.com --format json | jq '.data.scores'
vertaa audit https://example.com --format json > results.json
These options work with any command:
| Option | Description |
|---|---|
-b, --base <url> | API base URL override |
-c, --config <path> | Explicit config file path |
-q, --quiet | Suppress banner and non-essential output |
--no-banner | Hide the V-mark banner |
--machine | Strict machine-readable output mode |
-v, --version | Show version number |
-h, --help | Show help for command |
| Code | Meaning | When |
|---|---|---|
0 | Success | Audit passed, no issues above threshold |
1 | Issues found | Issues at or above --fail-on severity |
2 | Error | Invalid input, validation errors, network failures |
3 | Threshold breach | Score below --threshold value |
Exit code 2 is used for all validation errors, including:
--timeout abc)--mode bogus)The CLI uses cosmiconfig for configuration file auto-detection.
.vertaaux.yml.vertaaux.yaml.vertaaux.jsonvertaaux.config.jsvertaaux.config.mjsvertaaux.config.cjspackage.json (vertaaux key)Or specify explicitly:
vertaa audit https://example.com --config path/to/.vertaaux.yml
flag > env var > config file > default
From VertaauxConfig interface in src/config/schema.ts:
| Field | Type | Default | Description |
|---|---|---|---|
mode | basic|standard|deep | basic | Audit depth |
threshold | number | 0 | Minimum passing score (0-100) |
failOn | error|warning|info | - | Fail on severity |
output.format | auto|json|sarif|... | auto | Output format |
output.groupBy | severity|category|route | severity | Issue grouping |
baseline.path | string | .vertaaux/baseline.json | Baseline file path |
baseline.autoUpdate | boolean | false | Auto-update baseline |
ci.template | github|gitlab|... | none | CI template |
timeout | number | 60000 | Audit timeout (ms) |
interval | number | 5000 | Poll interval (ms) |
# .vertaaux.yml
$schema: https://vertaaux.ai/schemas/config.json
mode: standard
threshold: 80
failOn: error
output:
format: auto
groupBy: severity
baseline:
path: .vertaaux/baseline.json
autoUpdate: false
ci:
template: github
timeout: 60000
interval: 5000
Create a starter configuration:
vertaa init
vertaa init --ci github --yes
Branch names passed via --base-branch and --branch flags are validated against an allowlist regex:
/^[a-zA-Z0-9._\/-]+$/
;, |, $, `, etc.) are rejectedmain, feature/login, release/v1.2.3Downloaded artifact filenames are validated to stay within the output directory:
../) are rejected with an errorJSON envelope output automatically filters CLI arguments containing API keys or Bearer tokens from the args metadata field.
| Variable | Purpose |
|---|---|
VERTAAUX_API_KEY | API authentication key |
VERTAAUX_TOKEN | Alternative auth token (checked first) |
VERTAAUX_API_BASE | API base URL override |
NO_COLOR | Disable colored output |
FORCE_COLOR | Force colored output |
- name: Run audit
env:
VERTAAUX_API_KEY: ${{ secrets.VERTAAUX_API_KEY }}
run: |
npx @vertaaux/cli audit https://example.com \
--format sarif \
--fail-on error \
--threshold 80
# Fail CI if score below 80
vertaa audit https://example.com --threshold 80
# Fail CI if any error-severity issues found
vertaa audit https://example.com --fail-on error
# Both
vertaa audit https://example.com --threshold 80 --fail-on error
The CLI provides branded error messages with contextual help:
vertaa error: expected a number, got "abc"
──────────────────────────────────
│ flag: --timeout
│ value: abc
│
│ hint: Run vertaa <command> --help for all options
──────────────────────────────────
For enum values, typo suggestions are provided:
vertaa error: invalid value for --mode
│ flag: --mode
│ value: depp
│
│ hint: Did you mean "deep"?
│ valid: basic, standard, deep
FAQs
Run automated UX audits, accessibility checks, and performance analysis from the terminal or CI pipelines. Supports policy gating, SARIF output, and multi-page crawling. See https://github.com/PetriLahdelma/vertaa/tree/main/cli#readme for full docs.
The npm package @vertaaux/cli receives a total of 64 weekly downloads. As such, @vertaaux/cli popularity was classified as not popular.
We found that @vertaaux/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.

Research
/Security News
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.