Component-source checklist for agencies shipping client sites
Before using component source on a client site, verify the exact license and version, dependencies, accessibility, responsive behavior, browser and runtime limits, production data assumptions, security and network boundaries, failure behavior, customization constraints, update ownership, and the evidence the client will receive. Stop the release when a required fact is missing; a polished preview is not approval to ship.
Evidence boundary
The checklist separates a reusable agency handoff contract from three dated component screens. Each screen combines canonical public metadata with an immutable ready-package verification. Pass means the named evidence exists in the reviewed scope; Unknown means the agency still has to prove the fact in the real client project. No result represents legal advice, a security audit, client approval, or production certification.
Reviewed: by vro.dev client-handoff and public-component review. Correction owner:support@vro.dev.
Twelve checks before client acceptance
01Rights and licenseVerify the controlling license, allowed project use, attribution, redistribution, third-party assets, and any client-transfer boundary.Client handoff: License ID, version, URL, receipt, asset provenance, and responsible reviewer.
02Exact source and versionBind the reviewed source package to the canonical slug, component version, file list, and integrity record.Client handoff: Component slug/version, delivery date, file checksums, and local commit or vendor receipt.
03Framework and dependenciesCompile with only declared packages and identify runtime, bundle, maintenance, and transitive-license impact.Client handoff: Framework range, direct dependencies, lockfile state, measured client-build impact, and update owner.
04AccessibilityExercise keyboard, focus, announcements, contrast-sensitive states, reduced motion, and touch with production content.Client handoff: Manual and automated results, exceptions, remediation owner, and retest date.
05Responsive behaviorReplay narrow, wide, zoomed, long-content, and target touch layouts inside the actual page container.Client handoff: Tested viewport/zoom matrix, overflow result, touch result, and screenshots or trace references.
06Browser and runtime supportSeparate vendor declarations from browsers and devices the agency actually replayed.Client handoff: Supported matrix, observed matrix, fallback policy, exclusions, and recheck trigger.
07Content and data assumptionsReplace fixtures and validate empty, long, invalid, loading, failure, timezone, localization, and server-authority states that apply.Client handoff: Data owner, validation boundary, fixtures removed, states tested, and unresolved assumptions.
08Security, privacy, and networkReview inputs, output encoding, URLs, remote requests, secrets, personal data, consent, CSP, and dependency exposure.Client handoff: Threat review, network allowlist, data classification, consent owner, dependency scan, and exceptions.
09Failure and fallbackForce missing assets, rejected data, unsupported runtime, lifecycle changes, and unavailable services without losing essential content or action.Client handoff: Forced failures, expected fallback, observed result, monitoring signal, and recovery owner.
10Customization boundaryChange real copy, tokens, media, callbacks, and layout without breaking semantic or interaction contracts.Client handoff: Approved customizations, preserved invariants, local deviations, and design owner.
11Maintenance ownershipAssign dependency, browser, license, content, and component-update monitoring to named owners.Client handoff: Owner, support route, update cadence, triggers, and retirement or replacement plan.
12Client handoff recordDeliver the evidence above with setup, known limits, acceptance status, rollback instructions, and outstanding decisions.Client handoff: Signed acceptance scope, evidence index, open risks, rollback path, training/support notes, and next review.
Pass, fail, and unknown matrix
Three current component records screened for client handoff.
Observed: The 1.0.0 React package exposes literal navigation, address, legal, action, and wordmark inputs. Its public adapter preserves links, focus/touch states, reduced motion, and a no-network runtime across the reviewed desktop and mobile surfaces.
Agency work: Replace the fictional Maison Orra identity, verify every destination and legal line, connect the CTA, confirm target contrast and content length, and replay the final footer in the site's consent and navigation architecture.
Stop before delivery if: Fictional identity or destination remains; Legal or contact copy lacks client approval; Keyboard, touch, or reduced-motion path regresses
Observed: The 1.0.0 React package provides an accessible local date chooser. The reviewed adapter preserves unavailable states, keyboard date-grid navigation, touch targets, a polite selected-date summary, narrow layout, and reduced motion without network access.
Agency work: Connect authoritative timezone, capacity, conflict, and final booking validation on the server; replace deterministic dates; test loading, stale availability, rejected booking, localization, and confirmation recovery.
Stop before delivery if: Client-only availability is treated as authoritative; Timezone or capacity ownership is undefined; Rejected or stale booking has no useful recovery
An interactive seat-based pricing estimator with plan selection, monthly and annual billing, live quote math, visible feature context, and a caller-owned conversion action.
Observed: The published 1.1.0 React record declares local plan inputs, monthly/annual cadence, seat controls, estimate output, and caller-owned selection callbacks. The adapter uses fictional sample plans, remains responsive and keyboard/touch operable, and makes no network request.
Agency work: Replace every sample price and feature with approved commercial data, calculate authoritative checkout terms server-side, connect analytics under the site's consent contract, test taxes/regions/rounding, and prevent the displayed estimate from becoming a binding quote accidentally.
Stop before delivery if: Sample pricing or disclosure remains; Client-calculated estimate is treated as checkout authority; Regional, tax, renewal, or cancellation facts conflict with the canonical offer
Method and limits
These assessments cover the reviewed component version, ready package, and public Chromium preview evidence—not the agency's final stack, content, backend, analytics, consent, threat model, browser mix, performance budget, or client contract. They are not legal advice, a security audit, client approval, or production certification. Re-run the checklist after any source, dependency, license, content, integration, browser, or project-requirement change. Retain the controlling license and delivery receipt with the client handoff.