{
  "url": "https://hotpic.cc",
  "auditedAt": "2026-07-17T19:48:47.725Z",
  "mode": "report",
  "status": "completed",
  "statusDetail": "Atomic coverage complete across five representative paths. Media-detail and authenticated account interiors were not covered because no stable non-sensitive detail URL or credentials were supplied.",
  "page": {
    "appType": "mpa",
    "framework": "Server-rendered PHP/Bootstrap/jQuery with Cloudflare Rocket Loader",
    "notes": "Public image/video hosting and upload service. Homepage, listing, media, search and login archetypes reviewed; explicit media screenshots are retained but not embedded in the narrative."
  },
  "evidenceUsed": [
    "screenshot",
    "dom",
    "layout-metrics",
    "evaluate-probe",
    "axe-core",
    "lighthouse",
    "trace",
    "har",
    "discoverability",
    "headers",
    "cookies",
    "trackers",
    "secrets",
    "images",
    "heap-summary",
    "curl/raw-html"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "component-specific-light-dark-theme",
    "accessibility",
    "adapt-scrollbar-to-contrast-preferences",
    "same-document-transitions",
    "cross-document-transitions",
    "group-element-transitions",
    "faster-spa-view-transitions",
    "scrollytelling",
    "parallax-scroll-effects",
    "scroll-entry-exit-effects",
    "carousel-slide-effects",
    "physics-based-easing",
    "individual-transform-properties",
    "animate-element-entry-exit",
    "animate-to-from-top-layer",
    "animate-to-intrinsic-sizes",
    "dynamic-sibling-animations",
    "interactive-content-reveal",
    "pull-to-reveal",
    "swipe-to-remove",
    "shrinking-header-on-scroll",
    "scroll-progress-indicator",
    "scroll-position-aware-elements",
    "scroll-snap-realtime-feedback",
    "scroll-snap-state-sync",
    "scroll-target-on-load",
    "soft-edge-content-fade",
    "scrollability-affordance-hints",
    "anchor-positioning-tab-underline",
    "position-aware-tooltips",
    "interest-triggered-tooltips",
    "interest-triggered-action-previews",
    "directional-navigation-transitions",
    "carousel-snap-highlights",
    "navigation-drawer",
    "stack-drill-down",
    "persistent-app-tours",
    "persistent-toast-notifications",
    "light-dismiss-a-dialog",
    "platform-controls-dismiss-dialog",
    "declarative-dialog-popover-control",
    "animated-select-picker",
    "branded-select-styling",
    "brand-consistent-forms",
    "custom-select-picker-layouts",
    "rich-media-picker",
    "complex-shapes",
    "shaped-cutouts",
    "overflow-clipping-control",
    "visually-texture-content",
    "apply-webgl-shaders",
    "interactive-content-in-3d-scenes",
    "highlight-text-ranges",
    "prevent-text-wrapping",
    "customize-scrollbar-color-and-thickness",
    "export-html-media-from-canvas",
    "fluid-scaling",
    "calculate-with-intrinsic-sizes",
    "css-layout",
    "size-aware-styling",
    "content-based-styling",
    "child-state-based-styling",
    "design-token-reactivity",
    "dynamic-sibling-styling",
    "form-fields-automatically-fit-contents",
    "improve-text-layout-and-legibility",
    "forms",
    "accessible-error-announcement",
    "required-field-feedback",
    "validate-input-after-interaction",
    "identify-inp-causes",
    "schedule-tasks-by-priority",
    "optimize-preload-priority",
    "improve-next-page-load-performance",
    "interactions-in-complex-layouts",
    "performance",
    "visually-stable-font-fallbacks",
    "break-up-long-tasks",
    "identify-heavy-scripts",
    "optimize-script-priority",
    "defer-rendering-heavy-content",
    "defer-work-until-scroll-ends",
    "optimize-image-priority",
    "conditional-async-dependencies",
    "expose-canvas-content-to-browser-features",
    "move-dom-element-without-losing-state",
    "precise-text-alignment",
    "visually-stable-mixed-fonts",
    "css",
    "html",
    "reduce-style-repetition",
    "security",
    "privacy",
    "batch-analytics-events",
    "full-session-analytics",
    "calculate-total-foreground-time",
    "passkeys",
    "passkey-registration",
    "passkey-authentication",
    "passkey-reauthentication",
    "passkey-conditional-create",
    "passkey-management",
    "flicker-free-client-side-ab-testing",
    "consistent-cross-document-transitions",
    "stabilize-reactive-state",
    "resilient-context-menus-and-nested-dropdowns",
    "persistent-top-layer-ui",
    "detect-initial-visibility-state",
    "sequence-distributed-events",
    "translator",
    "language-detection",
    "support-global-calendar-systems",
    "capture-location-agnostic-data",
    "format-human-readable-durations",
    "manage-recurring-intervals",
    "calculate-event-differentials",
    "coordinate-global-events",
    "model-partial-time-concepts",
    "search-hidden-content",
    "select-menu-interaction",
    "style-parent-with-has",
    "autofill-address-form",
    "autofill-payment-form",
    "autofill-sign-in-form",
    "autofill-sign-up-form",
    "autofill-highlight-inputs",
    "deliver-optimized-decorative-images",
    "resolution-optimized-pseudo-elements",
    "deprioritize-background-fetches",
    "efficient-background-processing",
    "webmcp",
    "agentic-forms",
    "agentic-javascript-tools",
    "language-model",
    "summarizer"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/home-desktop.png",
      "caption": "Homepage at 1440x900.",
      "condition": "viewport: 1440x900"
    },
    {
      "type": "screenshot",
      "path": "evidence/home-mobile.png",
      "caption": "Homepage at 360x800.",
      "condition": "viewport: 360x800"
    },
    {
      "type": "screenshot",
      "path": "evidence/home-dark.png",
      "caption": "Homepage with dark preference; visually identical to the hard-coded dark default.",
      "condition": "prefers-color-scheme: dark"
    },
    {
      "type": "screenshot",
      "path": "evidence/home-forced-colors.png",
      "caption": "Homepage in forced colors; content and controls remain visible.",
      "condition": "forced-colors: active, prefers-contrast: more"
    },
    {
      "type": "dom",
      "path": "evidence/home-dom.json",
      "caption": "Rendered homepage DOM and computed styles."
    },
    {
      "type": "other",
      "path": "evidence/platform-probe.json",
      "caption": "Metadata, forms, focus, feature and semantic platform probe."
    },
    {
      "type": "other",
      "path": "evidence/runtime-probe.json",
      "caption": "Runtime footprint, manifest and robots response probe."
    },
    {
      "type": "other",
      "path": "evidence/reduced-motion.json",
      "caption": "Reduced-motion media query and active animation probe.",
      "condition": "prefers-reduced-motion: reduce"
    },
    {
      "type": "layout",
      "path": "evidence/home-mobile-layout.json",
      "caption": "Mobile layout metrics: no overflow and CLS 0.",
      "condition": "viewport: 360x800"
    },
    {
      "type": "trace-summary",
      "path": "evidence/home-trace-summary.json",
      "caption": "Compact load trace summary."
    },
    {
      "type": "trace",
      "path": "evidence/home-trace.json",
      "caption": "DevTools performance trace."
    },
    {
      "type": "har-summary",
      "path": "evidence/home-summary.json",
      "caption": "Compact network summary."
    },
    {
      "type": "har",
      "path": "evidence/home.har",
      "caption": "HAR 1.2 network capture."
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Lighthouse 13.4 report."
    },
    {
      "type": "other",
      "path": "evidence/lighthouse-summary.json",
      "caption": "Compact Lighthouse scores and failing audits."
    },
    {
      "type": "other",
      "path": "evidence/axe.json",
      "caption": "axe-core results."
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Security header audit."
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Cookie audit."
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Third-party tracker inventory."
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Client-side secret scan."
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Rendered image audit."
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "Raw HTML versus rendered discoverability analysis."
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "No-JavaScript crawler view.",
      "condition": "JavaScript disabled"
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "Rendered browser view.",
      "condition": "JavaScript enabled"
    },
    {
      "type": "dom",
      "path": "evidence/raw-home.html",
      "caption": "Raw server-rendered homepage HTML."
    },
    {
      "type": "screenshot",
      "path": "evidence/login-mobile.png",
      "caption": "Login journey on mobile.",
      "condition": "viewport: 360x800"
    },
    {
      "type": "other",
      "path": "evidence/login-probe.json",
      "caption": "Login labels, autocomplete and form probe."
    },
    {
      "type": "other",
      "path": "evidence/form-invalid-probe.json",
      "caption": "Invalid homepage upload-form submission probe."
    },
    {
      "type": "screenshot",
      "path": "evidence/albums.png",
      "caption": "Album listing archetype.",
      "condition": "viewport: 1440x900"
    },
    {
      "type": "screenshot",
      "path": "evidence/videos-mobile.png",
      "caption": "Video archetype on mobile.",
      "condition": "viewport: 360x800"
    },
    {
      "type": "screenshot",
      "path": "evidence/search.png",
      "caption": "Search results archetype.",
      "condition": "viewport: 1440x900"
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.json",
      "caption": "Baseline heap summary."
    },
    {
      "type": "heap",
      "path": "evidence/heap-post.json",
      "caption": "Heap summary after ten search-control open/close cycles."
    },
    {
      "type": "other",
      "path": "evidence/pwa-probe.json",
      "caption": "Service-worker registration and cache probe."
    },
    {
      "type": "dom",
      "path": "evidence/robots.txt",
      "caption": "Response body returned for /robots.txt (homepage HTML, not robots syntax)."
    },
    {
      "type": "dom",
      "path": "evidence/sitemap.xml",
      "caption": "Response body returned for /sitemap.xml (homepage HTML, not XML sitemap)."
    },
    {
      "type": "other",
      "path": "evidence/curl-headers.txt",
      "caption": "Main document HTTP response headers captured with curl."
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 58,
    "blocked": 0,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": true
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "a screenshot or computed background under an emulated prefers-color-scheme: dark condition will reveal whether surfaces re-tint; the page CSS / a color-scheme declaration is corroborating evidence",
      "evidence": "The default and emulated-dark screenshots are byte-identical (99,036 bytes); html reports color-scheme: normal while data-bs-theme=\"dark\" fixes the palette.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-desktop.png",
        "evidence/home-dark.png",
        "evidence/home-dom.json"
      ],
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "pass",
      "confidence": "high",
      "method": "a transition video, or an in-page probe of getAnimations()/computed animation under an emulated prefers-reduced-motion: reduce condition, can show whether motion stops",
      "evidence": "Emulated reduced motion matched true, the page had zero active animations, and authored CSS contains a reduced-motion rule.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/reduced-motion.json"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "a screenshot under emulated prefers-contrast: more / forced-colors, or an axe/contrast probe, can show whether controls and text survive",
      "evidence": "Forced-colors screenshot preserves text, dashed drop target, controls and nav labels; axe color-contrast passed.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-forced-colors.png"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "issues",
      "confidence": "high",
      "method": "a transition video of a route/state change shows whether it animates; the page source / ::view-transition usage corroborates",
      "evidence": "The platform probe found document.startViewTransition support but no authored view-transition CSS; navigation is full-page and the search field swaps instantly.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/home-desktop.png"
      ],
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and representative-template DOM/screenshot review for the capability or content type named by this check.",
      "evidence": "No scroll-linked animation or scrollytelling surface exists on the representative templates.",
      "reason": "No scroll-linked animation or scrollytelling surface exists on the representative templates.",
      "pathIds": [
        "entry"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and representative-template DOM/screenshot review for the capability or content type named by this check.",
      "evidence": "No swipe, pull, carousel or other gesture-driven interaction exists on the tested templates.",
      "reason": "No swipe, pull, carousel or other gesture-driven interaction exists on the tested templates.",
      "pathIds": [
        "entry"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "issues",
      "confidence": "high",
      "method": "a transition video of scrolling, or CSS inspection for scroll-state container queries",
      "evidence": "The homepage is 2,367 CSS px tall on mobile and listing/search DOMs are much taller, while computed navigation is static and no scroll-state treatment was found.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-mobile-layout.json",
        "evidence/search.png"
      ],
      "findingIds": [
        "F03"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and representative-template DOM/screenshot review for the capability or content type named by this check.",
      "evidence": "No tooltip, popover or edge-positioned menu was present on the representative paths.",
      "reason": "No tooltip, popover or edge-positioned menu was present on the representative paths.",
      "pathIds": [
        "entry"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "issues",
      "confidence": "high",
      "method": "CSS inspection for ::highlight / scroll-marker; a transition video can show whether attention is cued after navigation",
      "evidence": "Representative screenshots show the same navigation treatment across Upload, Search, Albums and Login; no current item marker is visible.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-desktop.png",
        "evidence/search.png",
        "evidence/login-mobile.png"
      ],
      "findingIds": [
        "F04"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "pass",
      "confidence": "high",
      "method": "a screenshot on load, or a DOM probe for full-viewport overlays present before interaction",
      "evidence": "Load screenshots show two in-flow notices that do not cover the upload task; the promotional notice has a 48×56 dismiss button.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-mobile.png"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection for popover / <dialog> / <details> vs custom overlay divs with manual dismiss handling",
      "evidence": "The DOM probe records Search as href=\"#\"; raw HTML wires click and keyup handlers to toggle an input rather than using a button/disclosure or semantic search form.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/raw-home.html"
      ],
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "pass",
      "confidence": "high",
      "method": "a screenshot plus layout metrics can show the proportion of the viewport given to chrome vs content",
      "evidence": "Desktop and mobile screenshots devote the dominant viewport area to the upload drop target and metadata form rather than decorative chrome.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-desktop.png"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "pass",
      "confidence": "high",
      "method": "layout metrics (scrollWidth vs innerWidth) and a screenshot at an emulated narrow mobile viewport reveal overflow",
      "evidence": "At 360×800, layout reports scrollWidth=clientWidth=360, horizontalOverflowPx=0 and viewport metadata present.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-mobile-layout.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "issues",
      "confidence": "high",
      "method": "CSS inspection for @container / container-type; a computed-style probe of the same component in a wide vs narrow container shows whether it adapts",
      "evidence": "The platform probe found no @container rules even though navigation and forms are reused in narrow and wide contexts.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/home-mobile.png",
        "evidence/home-desktop.png"
      ],
      "findingIds": [
        "F06"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "issues",
      "confidence": "high",
      "method": "a focus probe (focus an element, read the computed outline) or an axe target-size check; a screenshot of a focused control corroborates",
      "evidence": "The focus probe found outline: none on text inputs, textarea, checkboxes and radios; multiple controls measure 16×16 CSS px.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/home-mobile.png"
      ],
      "findingIds": [
        "F07"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "pass",
      "confidence": "high",
      "method": "screenshot the first viewport and key scrolled states; inspect heading structure, nav labels, button text, and visual hierarchy; a task walkthrough can show whether the next action is obvious",
      "evidence": "The first viewport presents the logo, upload navigation and a dominant “Drop files here or click to upload” target with limits and accepted formats.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-desktop.png"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "pass",
      "confidence": "high",
      "method": "run the flow manually with screenshots/DOM snapshots at each step; compare expected vs actual path length; inspect form requirements, navigation continuity, and blockers",
      "evidence": "Interaction/DOM review confirmed a clickable dropzone, required metadata fields, content settings and visible UPLOAD submit control in one continuous form; no account wall precedes it.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/platform-probe.json"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "pass",
      "confidence": "high",
      "method": "exercise network delay/failure, invalid input, empty data and success states; screenshot the state messaging and recovery controls; inspect whether browser history and focus remain sensible",
      "evidence": "requestSubmit on the empty form focused title and produced browser validation messages for both required fields after interaction.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/form-invalid-probe.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "pass",
      "confidence": "high",
      "method": "Lighthouse reports LCP/CLS/TBT directly and the model may run it; layout metrics + a layout-shift observer + a long-task observer (the evidence primitives) give the same signal first-party",
      "evidence": "Lighthouse measured LCP 1.78s, CLS 0 and TBT 148ms; trace measured LCP 1.48s and TBT 41ms.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "pass",
      "confidence": "high",
      "method": "the layout primitive's CLS observer captures shifts; a transition video of the first seconds shows content jumping",
      "evidence": "Mobile and desktop layout observers both recorded CLS 0 with no shifts over the observation window.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-mobile-layout.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "pass",
      "confidence": "high",
      "method": "the layout primitive records long tasks; a heap summary shows the object population; Lighthouse reports TBT",
      "evidence": "Trace found one 91ms long task and 41ms total blocking time; Lighthouse TBT remained 148ms, within a responsive load range.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-trace-summary.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "issues",
      "confidence": "high",
      "method": "a HAR summary can reveal cache headers, redirects, render-blocking candidates, weight offenders and dependency shape; a trace/Lighthouse insight report can corroborate LCP discovery, render-blocking, font-display and document latency",
      "evidence": "HAR lists six parser-inserted stylesheets; Lighthouse estimates 310 ms render-blocking savings and flags font-display.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-summary.json",
        "evidence/lighthouse-summary.json"
      ],
      "findingIds": [
        "F08"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse/trace/code-coverage style evidence can flag unused JS/CSS, duplicated JavaScript and legacy code; a HAR summary shows third-party byte cost and request count",
      "evidence": "Lighthouse estimates 180 KiB unused JavaScript, 48 KiB unused CSS, 14 KiB unminified JS and 8 KiB legacy JS; HAR shows 1.5 MB script content.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/home-summary.json"
      ],
      "findingIds": [
        "F09"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "issues",
      "confidence": "high",
      "method": "axe-core (injectable via the evaluate primitive) or Lighthouse's a11y audits enumerate these; a DOM probe of the accessibility-relevant attributes is a first-party alternative",
      "evidence": "axe reports no main landmark; the DOM probe shows required title and description fields with label:null.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/axe.json",
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F10"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "axe contrast rules, a Lighthouse contrast audit, or an in-page probe computing contrast ratios from computed colours",
      "evidence": "axe color-contrast passed and the forced-colors capture kept all first-viewport copy and controls visible.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-forced-colors.png"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "issues",
      "confidence": "high",
      "method": "axe/Lighthouse structural audits; a focus-walk probe (tab through, read activeElement + computed outline) is a first-party alternative",
      "evidence": "axe reports page-has-heading-one, landmark-one-main and region failures; the focus probe reports outline none for primary inputs.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/axe.json",
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "pass",
      "confidence": "high",
      "method": "a screenshot of body and heading text, plus CSS inspection for text-wrap / text alignment / font fallback handling",
      "evidence": "Desktop/mobile screenshots show 16px body copy, clear line wrapping and no clipping; mobile layout reports no horizontal overflow.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-mobile.png"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse/axe target-size, meta-viewport and media-caption audits are useful signals; screenshots at narrow and zoomed conditions plus DOM/media inspection can corroborate",
      "evidence": "axe and Lighthouse flag user-scalable=no and maximum-scale=1; the raw viewport meta confirms both values.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/axe.json",
        "evidence/lighthouse-summary.json",
        "evidence/raw-home.html"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "pass",
      "confidence": "high",
      "method": "capture Runtime/Log CDP events, or a probe that reads collected errors; Lighthouse reports this too",
      "evidence": "Lighthouse best-practices scored 1.00 and reported no console/uncaught-exception failure.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "issues",
      "confidence": "high",
      "method": "a DOM/source probe for doctype/charset/img dimensions; CSS inspection for repetition; Lighthouse best-practices audits cover the rest",
      "evidence": "The image primitive reports two images without complete dimensions; Lighthouse unsized-images scored 0.5.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-summary.json"
      ],
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "pass",
      "confidence": "high",
      "method": "Lighthouse best-practices audits and DevTools inspector/deprecation signals can surface these; DOM/source probes can verify paste handlers and prompt timing",
      "evidence": "Lighthouse best-practices scored 1.00; no permission prompt appeared, no secret was exposed and inspected forms accepted normal browser behavior.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "pass",
      "confidence": "high",
      "method": "a DOM probe reads <title> and meta[name=description]; Lighthouse SEO audits cover the same ground",
      "evidence": "Raw and rendered DOM expose a descriptive unique title and a substantive meta description.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/discoverability.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "issues",
      "confidence": "high",
      "method": "a DOM probe for anchor hrefs, viewport meta, and robots; Lighthouse SEO audits corroborate",
      "evidence": "Fetching /robots.txt returns the homepage as text/html; Lighthouse reports 760 robots errors, and Search uses href=\"#\".",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/runtime-probe.json",
        "evidence/lighthouse-summary.json",
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F14"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "issues",
      "confidence": "high",
      "method": "inspect response status and headers, <link rel=canonical>, hreflang links, robots meta, robots.txt and sitemap.xml; Lighthouse SEO audits cover several of these",
      "evidence": "Both /robots.txt and /sitemap.xml returned the homepage with HTTP 200 and self-canonicals for those paths instead of protocol files or proper errors.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/robots.txt",
        "evidence/sitemap.xml",
        "evidence/curl-headers.txt"
      ],
      "findingIds": [
        "F15"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "issues",
      "confidence": "high",
      "method": "inspect JSON-LD/microdata and social preview tags against visible content; Lighthouse has a manual structured-data audit, and ad-hoc probes can parse schema.org blocks",
      "evidence": "Raw HTML has title and description tags but no og:image, og:type, Twitter card or JSON-LD describing the service.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/raw-home.html"
      ],
      "findingIds": [
        "F16"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "issues",
      "confidence": "high",
      "method": "inspect response headers / page protocol via an evaluate probe or the network layer; Lighthouse best-practices flags HTTPS and CSP issues",
      "evidence": "The headers primitive confirms HTTPS and nosniff but reports no Content-Security-Policy or Strict-Transport-Security.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F17"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "issues",
      "confidence": "high",
      "method": "inspect network requests and third-party origins; a probe of analytics/beacon calls",
      "evidence": "HAR attributes 616,253 of 746,826 transferred bytes to third parties; tracker evidence finds Google Analytics, Tag Manager and DoubleClick across 10 third-party origins.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-summary.json",
        "evidence/trackers.json"
      ],
      "findingIds": [
        "F18"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "issues",
      "confidence": "high",
      "method": "a probe for permission requests fired on load; source inspection for passkey / WebAuthn / navigator.credentials usage in auth flows",
      "evidence": "Login exposes email/password and Google sign-in; the probe found no authored WebAuthn flow or autocomplete tokens. No permission prompt fired on load.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/login-probe.json"
      ],
      "findingIds": [
        "F19"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "inspect response headers and browser security state; Lighthouse/DevTools security audits can corroborate HSTS, clickjacking, Trusted Types, origin isolation and third-party cookie findings",
      "evidence": "Headers include SAMEORIGIN, nosniff and strict-origin-when-cross-origin, but Permissions-Policy, CSP and HSTS are absent.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F20"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "pass",
      "confidence": "high",
      "method": "load with scripting disabled or compare a no-JS fetch of the HTML against the rendered page; check for Baseline-aware fallbacks in source",
      "evidence": "Discoverability measured 99% raw-to-rendered content coverage, isJsShell=false, with title and description present without JavaScript.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/discoverability.json"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "pass",
      "confidence": "high",
      "method": "exercise menus near viewport edges with a screenshot; a probe of async/visibility behaviour",
      "evidence": "Search toggle, dismiss button, form validation and representative routes rendered without clipping or runtime failure in desktop/mobile probes.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-mobile.png"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "issues",
      "confidence": "high",
      "method": "a probe for a service worker registration and a web app manifest; test behaviour offline",
      "evidence": "The manifest has empty name/short_name and white theme values inconsistent with the UI; no service-worker registration, controller or caches were found.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/runtime-probe.json",
        "evidence/pwa-probe.json"
      ],
      "findingIds": [
        "F21"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "issues",
      "confidence": "high",
      "method": "simulate failed fetches/offline mode or inspect representative 404/500 routes; screenshots and DOM snapshots of error/loading/empty states show whether recovery is possible",
      "evidence": "/robots.txt and /sitemap.xml both return HTTP 200 homepage HTML, demonstrating that missing/special routes do not communicate truthful failure or recovery state.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/robots.txt",
        "evidence/sitemap.xml"
      ],
      "findingIds": [
        "F22"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "issues",
      "confidence": "high",
      "method": "a DOM probe for <html lang>/dir and CSS inspection for logical vs physical properties",
      "evidence": "Raw HTML has lang=\"en\" but no dir and includes <meta name=\"google\" content=\"notranslate\"> despite hreflang variants and global use.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/raw-home.html",
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F23"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and representative-template DOM/screenshot review for the capability or content type named by this check.",
      "evidence": "Representative pages expose no user-facing dates, numbers, currency, durations or calendar data to format.",
      "reason": "Representative pages expose no user-facing dates, numbers, currency, durations or calendar data to format.",
      "pathIds": [
        "entry"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and representative-template DOM/screenshot review for the capability or content type named by this check.",
      "evidence": "No event, schedule, recurring interval or time-zone-sensitive data appears in scope.",
      "reason": "No event, schedule, recurring interval or time-zone-sensitive data appears in scope.",
      "pathIds": [
        "entry"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "issues",
      "confidence": "high",
      "method": "a screenshot of consent/upsell/cancel flows; source inspection for declarative button actions vs misleading controls",
      "evidence": "The rendered form probe shows the adult content radio checked by default, which can misclassify uploads without an explicit user choice.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F24"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "pass",
      "confidence": "high",
      "method": "exercise a form, submit invalid input, and observe timing and clarity of errors via a screenshot or a :user-invalid / aria-invalid probe",
      "evidence": "Validation occurs on submit, focuses the first invalid field and uses clear native “Please fill in this field” messages rather than premature errors.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/form-invalid-probe.json"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "issues",
      "confidence": "high",
      "method": "source/DOM inspection for autocomplete attributes on form fields; a probe of autofill affordances",
      "evidence": "The login probe shows email and password inputs with autocomplete:\"\" and no labels.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/login-probe.json"
      ],
      "findingIds": [
        "F25"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "issues",
      "confidence": "high",
      "method": "walkthrough checkout/subscription/auth/account flows when present; screenshot pricing, confirmation, cancellation and reauthentication states; inspect passkey/autocomplete support for sign-in and payment",
      "evidence": "The login journey offers password/Google sign-in but no passkey path, and omits sign-in autocomplete semantics.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/login-probe.json"
      ],
      "findingIds": [
        "F26"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "pass",
      "confidence": "high",
      "method": "inspect transferred image bytes vs displayed size; source inspection for modern formats and resolution handling",
      "evidence": "The image inventory is dominated by lightweight SVG icons; only 7.5 KB of image bytes transferred and no legacy raster format was found.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/images.json"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "issues",
      "confidence": "high",
      "method": "a long-task / network probe for background fetches and processing while idle or backgrounded",
      "evidence": "Two Tag Manager scripts plus Analytics/DoubleClick run on load; 16 script requests transfer 509 KB and Lighthouse finds substantial unused code.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-summary.json",
        "evidence/trackers.json",
        "evidence/lighthouse-summary.json"
      ],
      "findingIds": [
        "F27"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "issues",
      "confidence": "high",
      "method": "a HAR summary shows third-party bytes, font/media weight and caching; screenshots/video reveal autoplay and decorative media; trace/layout evidence shows whether media/animation keeps work running",
      "evidence": "Third parties account for 82.5% of transferred bytes (616 KB of 747 KB), led by Tag Manager and a 150 KB icon font.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/home-summary.json",
        "evidence/trackers.json"
      ],
      "findingIds": [
        "F28"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and representative-template DOM/screenshot review for the capability or content type named by this check.",
      "evidence": "No declared agent-facing intent or capability surface exists; this emerging opportunity is out of scope for this public media host audit.",
      "reason": "No declared agent-facing intent or capability surface exists; this emerging opportunity is out of scope for this public media host audit.",
      "pathIds": [
        "entry"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and representative-template DOM/screenshot review for the capability or content type named by this check.",
      "evidence": "No summarisation, language-model or other inference use case is exposed or declared on the tested paths.",
      "reason": "No summarisation, language-model or other inference use case is exposed or declared on the tested paths.",
      "pathIds": [
        "entry"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "pass",
      "confidence": "medium",
      "method": "compare heap snapshots for retained growth - a baseline, then one taken after repeating the interaction with `--interact` about 10x (the memory-tracer methodology: baseline -> repeat -> post -> compare). Performance.getMetrics (JSHeapUsedSize, Nodes) across the same before/after window is corroboration. If Chrome DevTools MCP is available, follow its memory-leak-debugging skill: capture baseline, target, and final snapshots, then use memlab or the provided comparison workflow rather than reading raw .heapsnapshot files directly. The package-native `heap` primitive remains the default path. This check is only meaningful where the page has a real interaction to repeat; for a static page with none, mark it not-applicable with a rationale rather than fabricating one",
      "evidence": "After ten real search open/close cycles, heap self-size was 12.31 MB versus 11.85 MB baseline (+3.9%); stable major constructor counts and no Detached constructor in the top population provide no unbounded-growth signal.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/heap-post.json"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "pass",
      "confidence": "medium",
      "method": "a single `heap` summary's totals (nodeCount, totalSelfSizeBytes, constructor population) plus Performance.getMetrics (Nodes, JSHeapUsedSize) give the current footprint to judge against the page's purpose. Chrome DevTools MCP heap snapshots and memlab snapshot analysis can provide the same memory distribution when available. Read summaries or derived analysis, never raw snapshots unless a dedicated heap-analysis tool is doing the analysis",
      "evidence": "Runtime probe measured 8.18 MB used JS heap and 191 DOM elements; heap summary total self-size was 11.85 MB, proportionate for this page.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/heap-baseline.json"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "medium",
      "method": "the `heap` summary by constructor (Detached* nodes) compared across a before/after pair shows a growing detached-DOM population; an `evaluate` probe can sample listener/timer counts (e.g. getEventListeners-style counting, or instrumenting addEventListener/setInterval) before and after the repeated interaction to spot growth. Chrome DevTools MCP heap snapshots plus the memory-leak-debugging skill's common-leak guidance can corroborate detached DOM, listeners, closures, globals, and unbounded caches. Caveat from the memory-tracer and Chrome DevTools MCP guidance: detached nodes can be intentional caches, so judge confidence rather than asserting a bug",
      "evidence": "Baseline/post summaries show stable Map (179), Set (145) and core library constructor populations, with no Detached node constructor among top retained populations after ten toggles.",
      "pathIds": [
        "entry"
      ],
      "artifacts": [
        "evidence/heap-post.json"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F03",
        "F04"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F06",
        "F07"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F08",
        "F09"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F10",
        "F11",
        "F12"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F14",
        "F15",
        "F16"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F17",
        "F18",
        "F19",
        "F20"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F21",
        "F22"
      ]
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F23"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F24",
        "F25",
        "F26"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F27",
        "F28"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "All checks were judged out of scope from recon: no declared agent-facing intent or applicable inference/capability surface."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "pass"
    }
  ],
  "paths": [
    {
      "id": "entry",
      "description": "Homepage and upload form, the primary image-hosting journey; reviewed desktop, mobile, preference modes, keyboard, validation, performance, security, discoverability and memory.",
      "url": "https://hotpic.cc/",
      "conditions": [
        "1440x900",
        "360x800",
        "prefers-color-scheme: dark",
        "prefers-reduced-motion: reduce",
        "forced-colors: active",
        "keyboard focus",
        "invalid form submission"
      ],
      "result": "issues"
    },
    {
      "id": "albums",
      "description": "Album listing archetype representing browsable media collections.",
      "url": "https://hotpic.cc/nsfw/",
      "conditions": [
        "1440x900"
      ],
      "result": "issues"
    },
    {
      "id": "videos",
      "description": "Video/media archetype, including mobile media presentation.",
      "url": "https://hotpic.cc/videos/",
      "conditions": [
        "360x800"
      ],
      "result": "issues"
    },
    {
      "id": "search",
      "description": "Search-results archetype and query navigation.",
      "url": "https://hotpic.cc/search/test",
      "conditions": [
        "1440x900"
      ],
      "result": "issues"
    },
    {
      "id": "login",
      "description": "Authentication/account-entry journey; inspected labels, autocomplete, methods and mobile layout.",
      "url": "https://hotpic.cc/login/",
      "conditions": [
        "360x800",
        "keyboard and DOM inspection"
      ],
      "result": "issues"
    }
  ],
  "findings": [
    {
      "id": "F01",
      "severity": "medium",
      "confidence": "high",
      "summary": "The theme is hard-coded dark instead of following the user’s color-scheme preference.",
      "evidence": "The default and emulated-dark screenshots are byte-identical (99,036 bytes); html reports color-scheme: normal while data-bs-theme=\"dark\" fixes the palette.",
      "suggestedFix": "Declare color-scheme and select light/dark tokens with prefers-color-scheme or light-dark().",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "guidanceCategory": "user-experience",
      "effort": "small",
      "artifacts": [
        "evidence/home-desktop.png",
        "evidence/home-dark.png",
        "evidence/home-dom.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F02",
      "severity": "low",
      "confidence": "high",
      "summary": "Route and state changes do not use View Transitions.",
      "evidence": "The platform probe found document.startViewTransition support but no authored view-transition CSS; navigation is full-page and the search field swaps instantly.",
      "suggestedFix": "Add progressive same-document and cross-document View Transitions, with a reduced-motion fallback.",
      "principleId": "implement-natural-interactions",
      "principleCheckId": "view-transitions",
      "guidanceId": "same-document-transitions",
      "guidanceCategory": "user-experience",
      "effort": "medium",
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/home-desktop.png"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F03",
      "severity": "low",
      "confidence": "high",
      "summary": "Navigation chrome does not communicate scroll state on long pages.",
      "evidence": "The homepage is 2,367 CSS px tall on mobile and listing/search DOMs are much taller, while computed navigation is static and no scroll-state treatment was found.",
      "suggestedFix": "Use a sticky, state-aware header or progress/scroll affordance without hiding content.",
      "principleId": "provide-guided-navigation",
      "principleCheckId": "scroll-state-aware-chrome",
      "guidanceId": "scrollability-affordance-hints",
      "guidanceCategory": "user-experience",
      "effort": "medium",
      "artifacts": [
        "evidence/home-mobile-layout.json",
        "evidence/search.png"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F04",
      "severity": "low",
      "confidence": "high",
      "summary": "Navigation lacks a current-location or transition cue.",
      "evidence": "Representative screenshots show the same navigation treatment across Upload, Search, Albums and Login; no current item marker is visible.",
      "suggestedFix": "Expose aria-current and a clear visual current-state marker; preserve focus after in-page search reveal.",
      "principleId": "provide-guided-navigation",
      "principleCheckId": "directs-attention",
      "guidanceId": "directional-navigation-transitions",
      "guidanceCategory": "user-experience",
      "effort": "small",
      "artifacts": [
        "evidence/home-desktop.png",
        "evidence/search.png",
        "evidence/login-mobile.png"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F05",
      "severity": "medium",
      "confidence": "high",
      "summary": "The search control is an anchor with href=\"#\" and manual show/hide behavior.",
      "evidence": "The DOM probe records Search as href=\"#\"; raw HTML wires click and keyup handlers to toggle an input rather than using a button/disclosure or semantic search form.",
      "suggestedFix": "Use a button controlling a labelled search region/form, with expanded state and predictable keyboard behavior.",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "semantic-dismissible-primitives",
      "guidanceId": "declarative-dialog-popover-control",
      "guidanceCategory": "user-experience",
      "effort": "small",
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/raw-home.html"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F06",
      "severity": "low",
      "confidence": "high",
      "summary": "Shared components adapt only through viewport styling, not their container.",
      "evidence": "The platform probe found no @container rules even though navigation and forms are reused in narrow and wide contexts.",
      "suggestedFix": "Add container-type to reusable shells and use container queries where component layout depends on available space.",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "component-level-responsiveness",
      "guidanceId": "size-aware-styling",
      "guidanceCategory": "css",
      "effort": "medium",
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/home-mobile.png",
        "evidence/home-desktop.png"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F07",
      "severity": "high",
      "confidence": "high",
      "summary": "Several form controls lose visible keyboard focus and have 16px targets.",
      "evidence": "The focus probe found outline: none on text inputs, textarea, checkboxes and radios; multiple controls measure 16×16 CSS px.",
      "suggestedFix": "Provide a high-contrast :focus-visible treatment and make the complete labelled target at least 44 CSS px where practical.",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "input-modality-aware",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "effort": "small",
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/home-mobile.png"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F08",
      "severity": "medium",
      "confidence": "high",
      "summary": "Render-blocking CSS and font delivery delay the critical path.",
      "evidence": "HAR lists six parser-inserted stylesheets; Lighthouse estimates 310 ms render-blocking savings and flags font-display.",
      "suggestedFix": "Inline only critical CSS, defer non-critical styles, self-host/subset icons where useful and set an appropriate font-display.",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-resource-delivery",
      "guidanceId": "optimize-preload-priority",
      "guidanceCategory": "performance",
      "effort": "medium",
      "artifacts": [
        "evidence/home-summary.json",
        "evidence/lighthouse-summary.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F09",
      "severity": "medium",
      "confidence": "high",
      "summary": "The page ships avoidable unused and legacy front-end code.",
      "evidence": "Lighthouse estimates 180 KiB unused JavaScript, 48 KiB unused CSS, 14 KiB unminified JS and 8 KiB legacy JS; HAR shows 1.5 MB script content.",
      "suggestedFix": "Remove unused libraries/features per template, update legacy dependencies, minify and load optional upload/date code conditionally.",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "identify-heavy-scripts",
      "guidanceCategory": "performance",
      "effort": "medium",
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/home-summary.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F10",
      "severity": "high",
      "confidence": "high",
      "summary": "The primary upload form lacks programmatic labels and a main landmark.",
      "evidence": "axe reports no main landmark; the DOM probe shows required title and description fields with label:null.",
      "suggestedFix": "Wrap primary content in <main> and provide explicit <label for> elements for every field.",
      "principleId": "be-inclusive",
      "principleCheckId": "names-roles-labels",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "effort": "small",
      "artifacts": [
        "evidence/axe.json",
        "evidence/platform-probe.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F11",
      "severity": "high",
      "confidence": "high",
      "summary": "The homepage has no h1/main structure and focus styling disappears on form controls.",
      "evidence": "axe reports page-has-heading-one, landmark-one-main and region failures; the focus probe reports outline none for primary inputs.",
      "suggestedFix": "Add one descriptive h1 and semantic landmarks, then style :focus-visible consistently through the form.",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "effort": "small",
      "artifacts": [
        "evidence/axe.json",
        "evidence/platform-probe.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F12",
      "severity": "critical",
      "confidence": "high",
      "summary": "The viewport disables pinch zoom.",
      "evidence": "axe and Lighthouse flag user-scalable=no and maximum-scale=1; the raw viewport meta confirms both values.",
      "suggestedFix": "Use width=device-width, initial-scale=1 and remove maximum-scale, minimum-scale and user-scalable restrictions.",
      "principleId": "be-inclusive",
      "principleCheckId": "zoom-reflow-targets-and-media",
      "guidanceId": "fluid-scaling",
      "guidanceCategory": "css",
      "effort": "trivial",
      "artifacts": [
        "evidence/axe.json",
        "evidence/lighthouse-summary.json",
        "evidence/raw-home.html"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F13",
      "severity": "low",
      "confidence": "high",
      "summary": "Some images lack explicit intrinsic dimensions.",
      "evidence": "The image primitive reports two images without complete dimensions; Lighthouse unsized-images scored 0.5.",
      "suggestedFix": "Set width and height (or an equivalent reserved aspect-ratio) for every rendered image.",
      "principleId": "follow-best-practices",
      "principleCheckId": "sound-document-and-assets",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "effort": "small",
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-summary.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F14",
      "severity": "high",
      "confidence": "high",
      "summary": "robots.txt is not a robots file and one navigation link is not crawlable.",
      "evidence": "Fetching /robots.txt returns the homepage as text/html; Lighthouse reports 760 robots errors, and Search uses href=\"#\".",
      "suggestedFix": "Serve a valid text/plain robots.txt and give search a real destination or a semantic button instead of a fake link.",
      "principleId": "be-discoverable",
      "principleCheckId": "crawlable-and-mobile-friendly",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "effort": "small",
      "artifacts": [
        "evidence/runtime-probe.json",
        "evidence/lighthouse-summary.json",
        "evidence/platform-probe.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F15",
      "severity": "high",
      "confidence": "high",
      "summary": "Missing paths return misleading HTML and sitemap/robots signals are inconsistent.",
      "evidence": "Both /robots.txt and /sitemap.xml returned the homepage with HTTP 200 and self-canonicals for those paths instead of protocol files or proper errors.",
      "suggestedFix": "Serve valid robots and sitemap resources, return truthful 404 statuses for unknown resources, and emit canonicals only for indexable pages.",
      "principleId": "be-discoverable",
      "principleCheckId": "canonical-and-indexing-signals",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "effort": "medium",
      "artifacts": [
        "evidence/robots.txt",
        "evidence/sitemap.xml",
        "evidence/curl-headers.txt"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F16",
      "severity": "low",
      "confidence": "high",
      "summary": "Share metadata is incomplete for a public media-hosting service.",
      "evidence": "Raw HTML has title and description tags but no og:image, og:type, Twitter card or JSON-LD describing the service.",
      "suggestedFix": "Add accurate Open Graph/Twitter preview fields and appropriate schema.org Organization/WebSite structured data.",
      "principleId": "be-discoverable",
      "principleCheckId": "structured-and-shareable-metadata",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "effort": "small",
      "artifacts": [
        "evidence/raw-home.html"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F17",
      "severity": "high",
      "confidence": "high",
      "summary": "HTTPS is present, but CSP and HSTS are missing.",
      "evidence": "The headers primitive confirms HTTPS and nosniff but reports no Content-Security-Policy or Strict-Transport-Security.",
      "suggestedFix": "Deploy an allowlist CSP and HSTS after validating all subdomains and third-party requirements.",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "effort": "medium",
      "artifacts": [
        "evidence/headers.json"
      ],
      "pathId": "login",
      "url": "https://hotpic.cc/login/"
    },
    {
      "id": "F18",
      "severity": "high",
      "confidence": "high",
      "summary": "Third-party analytics dominate the transferred bytes.",
      "evidence": "HAR attributes 616,253 of 746,826 transferred bytes to third parties; tracker evidence finds Google Analytics, Tag Manager and DoubleClick across 10 third-party origins.",
      "suggestedFix": "Remove duplicate analytics, collect only necessary events after consent, batch them and reduce third-party origins.",
      "principleId": "be-private-and-secure",
      "principleCheckId": "data-minimisation-and-third-parties",
      "guidanceId": "privacy",
      "guidanceCategory": "privacy",
      "effort": "medium",
      "artifacts": [
        "evidence/home-summary.json",
        "evidence/trackers.json"
      ],
      "pathId": "login",
      "url": "https://hotpic.cc/login/"
    },
    {
      "id": "F19",
      "severity": "medium",
      "confidence": "high",
      "summary": "Password login has no phishing-resistant passkey option.",
      "evidence": "Login exposes email/password and Google sign-in; the probe found no authored WebAuthn flow or autocomplete tokens. No permission prompt fired on load.",
      "suggestedFix": "Offer passkeys/WebAuthn alongside recovery methods and use correct username/current-password autocomplete tokens.",
      "principleId": "be-private-and-secure",
      "principleCheckId": "in-context-permissions-and-modern-auth",
      "guidanceId": "passkeys",
      "guidanceCategory": "security",
      "effort": "large",
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/login-probe.json"
      ],
      "pathId": "login",
      "url": "https://hotpic.cc/login/"
    },
    {
      "id": "F20",
      "severity": "medium",
      "confidence": "high",
      "summary": "Defensive response policies are incomplete.",
      "evidence": "Headers include SAMEORIGIN, nosniff and strict-origin-when-cross-origin, but Permissions-Policy, CSP and HSTS are absent.",
      "suggestedFix": "Add a minimal Permissions-Policy and CSP frame-ancestors; deploy HSTS and consider Trusted Types for dynamic HTML sinks.",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "effort": "medium",
      "artifacts": [
        "evidence/headers.json"
      ],
      "pathId": "login",
      "url": "https://hotpic.cc/login/"
    },
    {
      "id": "F21",
      "severity": "medium",
      "confidence": "high",
      "summary": "The app-like upload service is neither installable nor offline-capable in practice.",
      "evidence": "The manifest has empty name/short_name and white theme values inconsistent with the UI; no service-worker registration, controller or caches were found.",
      "suggestedFix": "Provide a complete manifest, register a service worker and show a useful offline fallback for saved/queued work.",
      "principleId": "be-resilient",
      "principleCheckId": "offline-and-installable",
      "guidanceId": "offline fallback service worker web app manifest installable pwa",
      "guidanceCategory": "resilience",
      "effort": "large",
      "artifacts": [
        "evidence/runtime-probe.json",
        "evidence/pwa-probe.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F22",
      "severity": "high",
      "confidence": "high",
      "summary": "Missing protocol and resource routes fail as a misleading successful homepage.",
      "evidence": "/robots.txt and /sitemap.xml both return HTTP 200 homepage HTML, demonstrating that missing/special routes do not communicate truthful failure or recovery state.",
      "suggestedFix": "Return correct status codes and purpose-specific error pages with clear recovery links; handle failed upload requests explicitly.",
      "principleId": "be-resilient",
      "principleCheckId": "network-and-http-failure-states",
      "guidanceId": "persistent-toast-notifications",
      "guidanceCategory": "user-experience",
      "effort": "medium",
      "artifacts": [
        "evidence/robots.txt",
        "evidence/sitemap.xml"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F23",
      "severity": "medium",
      "confidence": "high",
      "summary": "The public service discourages translation and lacks explicit direction metadata.",
      "evidence": "Raw HTML has lang=\"en\" but no dir and includes <meta name=\"google\" content=\"notranslate\"> despite hreflang variants and global use.",
      "suggestedFix": "Remove notranslate, set language/direction intentionally, and audit authored CSS for logical inline/block properties.",
      "principleId": "be-internationalised",
      "principleCheckId": "lang-dir-and-logical-properties",
      "guidanceId": "translator",
      "guidanceCategory": "internationalization",
      "effort": "medium",
      "artifacts": [
        "evidence/raw-home.html",
        "evidence/platform-probe.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F24",
      "severity": "high",
      "confidence": "high",
      "summary": "New uploads default to “Adult XXX Content.”",
      "evidence": "The rendered form probe shows the adult content radio checked by default, which can misclassify uploads without an explicit user choice.",
      "suggestedFix": "Require an explicit, neutral content-safety choice with no sensitive category preselected.",
      "principleId": "be-trustworthy",
      "principleCheckId": "no-dark-patterns",
      "guidanceId": "forms",
      "guidanceCategory": "forms",
      "effort": "small",
      "artifacts": [
        "evidence/platform-probe.json"
      ],
      "pathId": "login",
      "url": "https://hotpic.cc/login/"
    },
    {
      "id": "F25",
      "severity": "medium",
      "confidence": "high",
      "summary": "Sign-in fields omit autocomplete tokens and rely on placeholders.",
      "evidence": "The login probe shows email and password inputs with autocomplete:\"\" and no labels.",
      "suggestedFix": "Add visible labels plus autocomplete=\"username\" and autocomplete=\"current-password\".",
      "principleId": "be-trustworthy",
      "principleCheckId": "trustworthy-input-assistance",
      "guidanceId": "autofill-sign-in-form",
      "guidanceCategory": "forms",
      "effort": "trivial",
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/login-probe.json"
      ],
      "pathId": "login",
      "url": "https://hotpic.cc/login/"
    },
    {
      "id": "F26",
      "severity": "medium",
      "confidence": "high",
      "summary": "Account sign-in lacks modern credential assistance.",
      "evidence": "The login journey offers password/Google sign-in but no passkey path, and omits sign-in autocomplete semantics.",
      "suggestedFix": "Add passkey support and proper credential autocomplete; keep recovery and account controls easy to find.",
      "principleId": "be-trustworthy",
      "principleCheckId": "safe-commercial-and-account-flows",
      "guidanceId": "passkey-authentication",
      "guidanceCategory": "security",
      "effort": "large",
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/login-probe.json"
      ],
      "pathId": "login",
      "url": "https://hotpic.cc/login/"
    },
    {
      "id": "F27",
      "severity": "medium",
      "confidence": "high",
      "summary": "Duplicate analytics and unconditional libraries create avoidable work.",
      "evidence": "Two Tag Manager scripts plus Analytics/DoubleClick run on load; 16 script requests transfer 509 KB and Lighthouse finds substantial unused code.",
      "suggestedFix": "Consolidate analytics and conditionally load upload/date/media dependencies only when used.",
      "principleId": "be-sustainable",
      "principleCheckId": "no-wasteful-work",
      "guidanceId": "deprioritize-background-fetches",
      "guidanceCategory": "performance",
      "effort": "medium",
      "artifacts": [
        "evidence/home-summary.json",
        "evidence/trackers.json",
        "evidence/lighthouse-summary.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    },
    {
      "id": "F28",
      "severity": "high",
      "confidence": "high",
      "summary": "The third-party budget is disproportionate to the simple upload landing page.",
      "evidence": "Third parties account for 82.5% of transferred bytes (616 KB of 747 KB), led by Tag Manager and a 150 KB icon font.",
      "suggestedFix": "Set a third-party byte/request budget, remove duplicate trackers and replace the icon font with only the SVGs needed.",
      "principleId": "be-sustainable",
      "principleCheckId": "third-party-and-media-budget",
      "guidanceId": "efficient-background-processing",
      "guidanceCategory": "performance",
      "effort": "medium",
      "artifacts": [
        "evidence/home-summary.json",
        "evidence/trackers.json"
      ],
      "pathId": "entry",
      "url": "https://hotpic.cc/"
    }
  ],
  "taskList": [
    {
      "id": "T01",
      "title": "Use width=device-width, initial-scale=1 and remove maximum-scale, minimum-scale and user-scalable restrictions.",
      "priority": 1,
      "findingIds": [
        "F12"
      ],
      "guidanceId": "fluid-scaling",
      "status": "open"
    },
    {
      "id": "T02",
      "title": "Provide a high-contrast :focus-visible treatment and make the complete labelled target at least 44 CSS px where practical.",
      "priority": 2,
      "findingIds": [
        "F07"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T03",
      "title": "Wrap primary content in <main> and provide explicit <label for> elements for every field.",
      "priority": 3,
      "findingIds": [
        "F10"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T04",
      "title": "Add one descriptive h1 and semantic landmarks, then style :focus-visible consistently through the form.",
      "priority": 4,
      "findingIds": [
        "F11"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T05",
      "title": "Serve a valid text/plain robots.txt and give search a real destination or a semantic button instead of a fake link.",
      "priority": 5,
      "findingIds": [
        "F14"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T06",
      "title": "Serve valid robots and sitemap resources, return truthful 404 statuses for unknown resources, and emit canonicals only for indexable pages.",
      "priority": 6,
      "findingIds": [
        "F15"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T07",
      "title": "Deploy an allowlist CSP and HSTS after validating all subdomains and third-party requirements.",
      "priority": 7,
      "findingIds": [
        "F17"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T08",
      "title": "Remove duplicate analytics, collect only necessary events after consent, batch them and reduce third-party origins.",
      "priority": 8,
      "findingIds": [
        "F18"
      ],
      "guidanceId": "privacy",
      "status": "open"
    },
    {
      "id": "T09",
      "title": "Return correct status codes and purpose-specific error pages with clear recovery links; handle failed upload requests explicitly.",
      "priority": 9,
      "findingIds": [
        "F22"
      ],
      "guidanceId": "persistent-toast-notifications",
      "status": "open"
    },
    {
      "id": "T10",
      "title": "Require an explicit, neutral content-safety choice with no sensitive category preselected.",
      "priority": 10,
      "findingIds": [
        "F24"
      ],
      "guidanceId": "forms",
      "status": "open"
    },
    {
      "id": "T11",
      "title": "Set a third-party byte/request budget, remove duplicate trackers and replace the icon font with only the SVGs needed.",
      "priority": 11,
      "findingIds": [
        "F28"
      ],
      "guidanceId": "efficient-background-processing",
      "status": "open"
    },
    {
      "id": "T12",
      "title": "Declare color-scheme and select light/dark tokens with prefers-color-scheme or light-dark().",
      "priority": 12,
      "findingIds": [
        "F01"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T13",
      "title": "Use a button controlling a labelled search region/form, with expanded state and predictable keyboard behavior.",
      "priority": 13,
      "findingIds": [
        "F05"
      ],
      "guidanceId": "declarative-dialog-popover-control",
      "status": "open"
    },
    {
      "id": "T14",
      "title": "Inline only critical CSS, defer non-critical styles, self-host/subset icons where useful and set an appropriate font-display.",
      "priority": 14,
      "findingIds": [
        "F08"
      ],
      "guidanceId": "optimize-preload-priority",
      "status": "open"
    },
    {
      "id": "T15",
      "title": "Remove unused libraries/features per template, update legacy dependencies, minify and load optional upload/date code conditionally.",
      "priority": 15,
      "findingIds": [
        "F09"
      ],
      "guidanceId": "identify-heavy-scripts",
      "status": "open"
    },
    {
      "id": "T16",
      "title": "Offer passkeys/WebAuthn alongside recovery methods and use correct username/current-password autocomplete tokens.",
      "priority": 16,
      "findingIds": [
        "F19"
      ],
      "guidanceId": "passkeys",
      "status": "open"
    },
    {
      "id": "T17",
      "title": "Add a minimal Permissions-Policy and CSP frame-ancestors; deploy HSTS and consider Trusted Types for dynamic HTML sinks.",
      "priority": 17,
      "findingIds": [
        "F20"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T18",
      "title": "Provide a complete manifest, register a service worker and show a useful offline fallback for saved/queued work.",
      "priority": 18,
      "findingIds": [
        "F21"
      ],
      "guidanceId": "offline fallback service worker web app manifest installable pwa",
      "status": "open"
    },
    {
      "id": "T19",
      "title": "Remove notranslate, set language/direction intentionally, and audit authored CSS for logical inline/block properties.",
      "priority": 19,
      "findingIds": [
        "F23"
      ],
      "guidanceId": "translator",
      "status": "open"
    },
    {
      "id": "T20",
      "title": "Add visible labels plus autocomplete=\"username\" and autocomplete=\"current-password\".",
      "priority": 20,
      "findingIds": [
        "F25"
      ],
      "guidanceId": "autofill-sign-in-form",
      "status": "open"
    },
    {
      "id": "T21",
      "title": "Add passkey support and proper credential autocomplete; keep recovery and account controls easy to find.",
      "priority": 21,
      "findingIds": [
        "F26"
      ],
      "guidanceId": "passkey-authentication",
      "status": "open"
    },
    {
      "id": "T22",
      "title": "Consolidate analytics and conditionally load upload/date/media dependencies only when used.",
      "priority": 22,
      "findingIds": [
        "F27"
      ],
      "guidanceId": "deprioritize-background-fetches",
      "status": "open"
    },
    {
      "id": "T23",
      "title": "Add progressive same-document and cross-document View Transitions, with a reduced-motion fallback.",
      "priority": 23,
      "findingIds": [
        "F02"
      ],
      "guidanceId": "same-document-transitions",
      "status": "open"
    },
    {
      "id": "T24",
      "title": "Use a sticky, state-aware header or progress/scroll affordance without hiding content.",
      "priority": 24,
      "findingIds": [
        "F03"
      ],
      "guidanceId": "scrollability-affordance-hints",
      "status": "open"
    },
    {
      "id": "T25",
      "title": "Expose aria-current and a clear visual current-state marker; preserve focus after in-page search reveal.",
      "priority": 25,
      "findingIds": [
        "F04"
      ],
      "guidanceId": "directional-navigation-transitions",
      "status": "open"
    },
    {
      "id": "T26",
      "title": "Add container-type to reusable shells and use container queries where component layout depends on available space.",
      "priority": 26,
      "findingIds": [
        "F06"
      ],
      "guidanceId": "size-aware-styling",
      "status": "open"
    },
    {
      "id": "T27",
      "title": "Set width and height (or an equivalent reserved aspect-ratio) for every rendered image.",
      "priority": 27,
      "findingIds": [
        "F13"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T28",
      "title": "Add accurate Open Graph/Twitter preview fields and appropriate schema.org Organization/WebSite structured data.",
      "priority": 28,
      "findingIds": [
        "F16"
      ],
      "guidanceId": "html",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 5,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-17T19-38-01-054Z"
}
