Rules · frame-title
Failure reference
Frames without a title.
Payment widgets, maps and chat bubbles ride in iframes. Untitled, each is announced as just "frame" — content with no door sign.
What fails — and who it fails
The failure, in plain language.
Third-party embeds (PSP forms, consent tools, maps, video players) shipped without a title attribute.
Detection — what the machine can and cannot judge
How the scanner finds it.
- Every iframe is checked for a title describing its content.
The legal reading — factual, not fearful
Where this sits in enforcement.
Payment iframes make this a checkout-path finding — the sector and the flow regulators look at first for commerce services.
The fix — by pattern
The pattern that clears it.
- <iframe src="https://psp.example/card">
+ <iframe src="https://psp.example/card" title="Kartenzahlung — sicheres Formular">Fix the template, not the page — one change typically clears every instance at once. The triage engine groups findings by template pattern for exactly that reason.
Verification — resolution is evidence, not a checkbox
Fixed means a scan said so.
On monitored domains, mark the finding fixed and the next scan verifies it: zero remaining instances converts the finding to Resolved, and both the claim and the confirmation land in the append-only ledger. Criteria that need human judgement close through sign-off in the coverage matrix — covered by the right method, never by assumption.
Related failures:
See where your templates stand.
A complimentary assessment renders up to 25 public pages in an EU-hosted browser and shows every instance of this failure — grouped, ranked, and honest about what still needs a human.