Skip to main content

White-Box Testing

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/white-box-testing

In short

White-box testing designs tests from knowledge of the code's internal structure, so that its statements, branches and paths are exercised and checked directly.

What is white-box testing?

Where black-box testing asks whether the software does what the specification says, white-box testing asks whether every part of the code has been run and behaves correctly. The tester reads the implementation and writes tests that take each branch of an if, go through loops zero, one and many times, and trigger each error-handling path.

Coverage measures guide the work. Statement coverage shows which lines ran, branch coverage whether each condition was both true and false, and path coverage whether combinations of branches were taken. Tools such as Istanbul, coverage.py and JaCoCo report these numbers, and mutation testing goes further by checking whether tests notice small deliberate changes to the code.

Most white-box testing is done by developers through unit and integration tests, since they know the code best. It is especially valuable for complex logic, security checks and code where a rarely taken branch, such as a retry after a timeout, could fail silently in production.

A common misconception is that full coverage means the code is correct. Coverage only proves that lines were executed, not that the right results were asserted, and it can't reveal behavior that is missing entirely because a requirement was never implemented. White-box tests also tend to be tied to the implementation, so they need updating more often when code is refactored.

Key takeaways

  • White-box testing uses knowledge of the code to design tests.
  • The goal is to exercise statements, branches and paths.
  • Coverage tools and mutation testing measure how thorough it is.
  • Developers do most of it in unit and integration tests.
  • High coverage doesn't prove correctness or catch missing features.

Example

Tests that cover every branchjavascript
function shippingCost(total, country) {
  if (total >= 100) return 0;               // branch 1: free shipping
  if (country === "TR") return 5;           // branch 2: domestic
  return 15;                                // branch 3: international
}

test("free above the threshold", () => expect(shippingCost(100, "DE")).toBe(0));
test("domestic rate", () => expect(shippingCost(99, "TR")).toBe(5));
test("international rate", () => expect(shippingCost(99, "DE")).toBe(15));

// npx jest --coverage  → 100% branch coverage for shippingCost

Readers ask

Who does white-box testing?

Mostly developers, because it requires reading and understanding the code. Security testers also use it when reviewing code for vulnerabilities.

What is branch coverage?

The percentage of decision outcomes, such as both the true and false side of each if statement, that the tests executed. It is stricter and more useful than plain line coverage.

What is gray-box testing?

A mix of the two approaches: tests are designed from the outside like black-box tests, but with partial knowledge of the internals, such as the database schema or architecture, to target likely problems.

Often compared

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings