Scanning pages behind a login
Zylyn's servers cannot reach pages that require a login — dashboards, account settings, checkout steps, member areas. The Zylyn browser extension solves this by running the scan inside your own browser, in a tab you're already signed in to.
This matters because the highest-value accessibility defects usually live behind the login. Marketing pages get designed carefully; account settings screens rarely do.
Installing it#
Click Install Zylyn extension in the portal's top bar, or find Zylyn Accessibility Scanner in the Chrome Web Store. Chrome only at present — no Firefox or Edge build.
Using it#
- Log in to the site you want to test, as you normally would
- Navigate to the page you want to scan
- Click the Zylyn icon, or right-click and choose Scan this page with Zylyn
- Pick which Zylyn account the result should be saved to
- Results upload to your portal and appear alongyour other reports
You can also tick This page is behind a login in the Run new scan dialog to register the page for extension scanning.
What it collects#
Worth knowing, since it runs on pages containing your data:
It collects, only when you click scan: the page URL and title, your browser's viewport size, the scan findings, short truncated HTML snippets (~150 characters) of failing elements, your Zylyn account and user ID, and the request's IP and user agent.
It does not collect: your browsing history, any page you didn't explicitly scan, cookies, passwords, authentication tokens, session data, text you typed into forms, screenshots, keystrokes, mouse movement, or in-extension analytics.
Your credentials never leave your browser. The extension reads the rendered page, not your session.
Privacy on private pages#
Because findings include markup, a snippet can contain content only you can see. Zylyn applies three safeguards:
- Automatic redaction of email addresses and long digit sequences (account or card numbers) before storage. This is described as an automated safeguard, not a guarantee — it cannot catch every possible form of personal data.
- Extension scans are never made public. Unlike public-page scans they get no shareable link, no screenshot, and are not sent to Zylyn's CRM.
- Same-site frames only. Content embedded from other domains is counted but not scanned, and the report tells you when coverage was partial.
The extension requests access to the Zylyn API only — not to the sites you scan — and the accessibility engine is bundled at a pinned version, so it never downloads or executes remote code.
Scan responsibly#
- Only scan systems you're authorised to access
- Prefer a dedicated test account over your real one wherever possible, especially on anything containing customer data
- Remember that scan reports are visible to everyone on your Zylyn account, and to your managing agency if your account is managed by one
Cost#
Extension scans are charged against the same credit balance as any other scan — 1 credit per page.

