{
  "url": "https://web.spaggiari.eu",
  "auditedAt": "2026-07-27T12:35:55.422Z",
  "mode": "report",
  "status": "completed",
  "statusDetail": "Coverage complete. 34 findings: 0 critical, 15 high, 15 medium, 4 low.",
  "page": {
    "appType": "hybrid",
    "framework": "Server-rendered PHP with Vue 2.7, jQuery, and jQuery UI enhancement",
    "notes": "Root redirects to the public ClasseViva login. The sitemap contains only the login and /sdf/; /sdf/ returns 404. Product/detail links redirect to the separate www.spaggiari.eu host and were excluded."
  },
  "evidenceUsed": [
    "screenshot",
    "DOM inspection",
    "layout metrics",
    "evaluate probes",
    "DevTools trace",
    "HAR",
    "Lighthouse",
    "axe-core",
    "headers",
    "cookies",
    "trackers",
    "secrets",
    "images",
    "heap summaries",
    "robots.txt and sitemap.xml",
    "raw HTML/no-JavaScript comparison"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "component-specific-light-dark-theme",
    "accessibility",
    "adapt-scrollbar-to-contrast-preferences",
    "same-document-transitions",
    "cross-document-transitions",
    "group-element-transitions",
    "faster-spa-view-transitions",
    "scrollytelling",
    "parallax-scroll-effects",
    "scroll-entry-exit-effects",
    "carousel-slide-effects",
    "physics-based-easing",
    "individual-transform-properties",
    "animate-element-entry-exit",
    "animate-to-from-top-layer",
    "animate-to-intrinsic-sizes",
    "dynamic-sibling-animations",
    "interactive-content-reveal",
    "pull-to-reveal",
    "swipe-to-remove",
    "shrinking-header-on-scroll",
    "scroll-progress-indicator",
    "scroll-position-aware-elements",
    "scroll-snap-realtime-feedback",
    "scroll-snap-state-sync",
    "scroll-target-on-load",
    "soft-edge-content-fade",
    "scrollability-affordance-hints",
    "anchor-positioning-tab-underline",
    "position-aware-tooltips",
    "interest-triggered-tooltips",
    "interest-triggered-action-previews",
    "directional-navigation-transitions",
    "carousel-snap-highlights",
    "navigation-drawer",
    "stack-drill-down",
    "persistent-app-tours",
    "persistent-toast-notifications",
    "light-dismiss-a-dialog",
    "platform-controls-dismiss-dialog",
    "declarative-dialog-popover-control",
    "animated-select-picker",
    "branded-select-styling",
    "brand-consistent-forms",
    "custom-select-picker-layouts",
    "rich-media-picker",
    "complex-shapes",
    "shaped-cutouts",
    "overflow-clipping-control",
    "visually-texture-content",
    "apply-webgl-shaders",
    "interactive-content-in-3d-scenes",
    "highlight-text-ranges",
    "prevent-text-wrapping",
    "customize-scrollbar-color-and-thickness",
    "export-html-media-from-canvas",
    "fluid-scaling",
    "calculate-with-intrinsic-sizes",
    "css-layout",
    "size-aware-styling",
    "content-based-styling",
    "child-state-based-styling",
    "design-token-reactivity",
    "dynamic-sibling-styling",
    "form-fields-automatically-fit-contents",
    "improve-text-layout-and-legibility",
    "forms",
    "accessible-error-announcement",
    "required-field-feedback",
    "validate-input-after-interaction",
    "identify-inp-causes",
    "schedule-tasks-by-priority",
    "optimize-preload-priority",
    "improve-next-page-load-performance",
    "interactions-in-complex-layouts",
    "performance",
    "visually-stable-font-fallbacks",
    "break-up-long-tasks",
    "identify-heavy-scripts",
    "optimize-script-priority",
    "defer-rendering-heavy-content",
    "defer-work-until-scroll-ends",
    "optimize-image-priority",
    "conditional-async-dependencies",
    "expose-canvas-content-to-browser-features",
    "move-dom-element-without-losing-state",
    "precise-text-alignment",
    "visually-stable-mixed-fonts",
    "css",
    "html",
    "reduce-style-repetition",
    "security",
    "privacy",
    "batch-analytics-events",
    "full-session-analytics",
    "calculate-total-foreground-time",
    "passkeys",
    "passkey-registration",
    "passkey-authentication",
    "passkey-reauthentication",
    "passkey-conditional-create",
    "passkey-management",
    "flicker-free-client-side-ab-testing",
    "consistent-cross-document-transitions",
    "stabilize-reactive-state",
    "resilient-context-menus-and-nested-dropdowns",
    "persistent-top-layer-ui",
    "detect-initial-visibility-state",
    "sequence-distributed-events",
    "translator",
    "language-detection",
    "support-global-calendar-systems",
    "capture-location-agnostic-data",
    "format-human-readable-durations",
    "manage-recurring-intervals",
    "calculate-event-differentials",
    "coordinate-global-events",
    "model-partial-time-concepts",
    "search-hidden-content",
    "select-menu-interaction",
    "style-parent-with-has",
    "autofill-address-form",
    "autofill-payment-form",
    "autofill-sign-in-form",
    "autofill-sign-up-form",
    "autofill-highlight-inputs",
    "deliver-optimized-decorative-images",
    "resolution-optimized-pseudo-elements",
    "deprioritize-background-fetches",
    "efficient-background-processing",
    "webmcp",
    "agentic-forms",
    "agentic-javascript-tools",
    "language-model",
    "summarizer"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/login-desktop.png",
      "caption": "Styled authentication page at desktop viewport",
      "condition": "desktop",
      "findingIds": [
        "F01",
        "F07",
        "F10",
        "F19",
        "F26"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/login-mobile.png",
      "caption": "Authentication page at 360x800",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F04",
        "F07",
        "F09",
        "F10",
        "F19"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/login-dark.png",
      "caption": "Authentication page under dark preference",
      "condition": "prefers-color-scheme: dark",
      "findingIds": [
        "F01"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/login-high-contrast.png",
      "caption": "Authentication page under increased contrast preference",
      "condition": "prefers-contrast: more",
      "findingIds": [
        "F02"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/login-focus-mobile.png",
      "caption": "Login field focused on mobile",
      "condition": "keyboard focus, viewport: 360x800",
      "findingIds": [
        "F06",
        "F11",
        "F18"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/login-empty-submit.png",
      "caption": "State after empty credential submission",
      "condition": "empty form submission",
      "findingIds": [
        "F12",
        "F30"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/sdf-desktop.png",
      "caption": "Sitemap-listed /sdf/ returns generic nginx 404",
      "condition": "desktop",
      "findingIds": [
        "F23",
        "F28"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-login-rendered.png",
      "caption": "Transient ERR_INVALID_RESPONSE captured during discoverability run",
      "condition": "browser load",
      "findingIds": [
        "F27",
        "F28"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-login-crawler.png",
      "caption": "JavaScript-disabled login page loses credential controls",
      "condition": "JavaScript disabled",
      "findingIds": [
        "F26"
      ]
    },
    {
      "type": "layout",
      "path": "evidence/login-layout-mobile.json",
      "caption": "Mobile layout metrics and CLS",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F04",
        "F09",
        "F20"
      ]
    },
    {
      "type": "trace",
      "path": "evidence/login-trace",
      "caption": "DevTools performance trace",
      "condition": "desktop load",
      "findingIds": []
    },
    {
      "type": "trace-summary",
      "path": "evidence/login-trace-summary.json",
      "caption": "Compact trace timings and long-task summary",
      "condition": "desktop load",
      "findingIds": [
        "F13"
      ]
    },
    {
      "type": "har",
      "path": "evidence/login-network",
      "caption": "HAR 1.2 network capture",
      "condition": "desktop load",
      "findingIds": []
    },
    {
      "type": "har-summary",
      "path": "evidence/login-network-summary.json",
      "caption": "Compact resource, origin, and delivery summary",
      "condition": "desktop load",
      "findingIds": [
        "F14",
        "F34"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Lighthouse mobile performance, accessibility, best-practices, and SEO report",
      "condition": "mobile profile",
      "findingIds": [
        "F02",
        "F13",
        "F14",
        "F15",
        "F16",
        "F17",
        "F18",
        "F21",
        "F22",
        "F29",
        "F33"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/home-dom.json",
      "caption": "Rendered login DOM and CSS inventory",
      "condition": "desktop",
      "findingIds": [
        "F03",
        "F05",
        "F06",
        "F08",
        "F12",
        "F21",
        "F30"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/sdf-dom.json",
      "caption": "Rendered DOM for broken sitemap route",
      "condition": "desktop",
      "findingIds": [
        "F23"
      ]
    },
    {
      "type": "other",
      "path": "evidence/probe.json",
      "caption": "Metadata, form, target-size, script, focus, and DOM probe",
      "condition": "desktop",
      "findingIds": [
        "F03",
        "F05",
        "F10",
        "F11",
        "F14",
        "F15",
        "F18",
        "F20",
        "F22",
        "F23",
        "F27",
        "F29",
        "F31",
        "F33"
      ]
    },
    {
      "type": "other",
      "path": "evidence/axe.json",
      "caption": "axe-core accessibility results",
      "condition": "desktop",
      "findingIds": [
        "F02",
        "F08",
        "F16",
        "F17",
        "F18",
        "F29"
      ]
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Security response header inspection",
      "condition": "desktop",
      "findingIds": [
        "F24",
        "F25"
      ]
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Cookie audit before consent",
      "condition": "desktop",
      "findingIds": [
        "F24"
      ]
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Third-party tracker/origin audit",
      "condition": "desktop",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Client-side secret scan",
      "condition": "desktop",
      "findingIds": [
        "F24"
      ]
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Rendered image sizing and delivery audit",
      "condition": "desktop",
      "findingIds": [
        "F21",
        "F32"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline",
      "caption": "Baseline heap summary",
      "condition": "before interaction",
      "findingIds": []
    },
    {
      "type": "heap",
      "path": "evidence/heap-post",
      "caption": "Heap summary after ten interactions",
      "condition": "after repeated interaction",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/memory-probe.json",
      "caption": "Same-page heap, DOM, listener, and timer deltas",
      "condition": "ten repeated interactions",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/reduced-motion.json",
      "caption": "Animation state under reduced motion",
      "condition": "prefers-reduced-motion: reduce",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/robots.txt",
      "caption": "robots.txt used for crawlability review",
      "condition": "crawler",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/sitemap.xml",
      "caption": "sitemap.xml used for route discovery",
      "condition": "crawler",
      "findingIds": [
        "F23"
      ]
    },
    {
      "type": "other",
      "path": "evidence/login-raw.html",
      "caption": "Raw server HTML for progressive-enhancement review",
      "condition": "no browser JavaScript",
      "findingIds": [
        "F26"
      ]
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 58,
    "blocked": 0,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": true
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "Compared screenshots under default and emulated dark preference.",
      "evidence": "Desktop captures under light and prefers-color-scheme: dark are byte-identical (78,996 bytes) and show the same white and red palette.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-dark.png"
      ],
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "pass",
      "confidence": "high",
      "method": "Emulated reduced motion and queried document animations/autoplay.",
      "evidence": "Under prefers-reduced-motion: reduce, matchMedia matched and the page reported zero active animations and zero autoplay elements.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/reduced-motion.json"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "issues",
      "confidence": "high",
      "method": "Compared default/high-contrast screenshots and ran axe/Lighthouse contrast audits.",
      "evidence": "The prefers-contrast: more capture is byte-identical to the default capture, while axe found 21 contrast failures, including the primary button at 4.04:1.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-high-contrast.png",
        "evidence/axe.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "issues",
      "confidence": "high",
      "method": "Inspected rendered DOM/scripts and animation state.",
      "evidence": "The page exposes no active animations or View Transition evidence; login, language, disclosure, and project state changes are implemented by legacy scripts and abrupt swaps.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/home-dom.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F03"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "pass",
      "confidence": "medium",
      "method": "Inspected the full-page screenshot, DOM, and document animations.",
      "evidence": "The audited surface contains no parallax, scrollytelling, carousel motion, or active scroll-linked animation to implement with main-thread handlers.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "pass",
      "confidence": "medium",
      "method": "Inspected interactive elements and rendered DOM.",
      "evidence": "No custom swipe, drag, pull-to-refresh, or gesture-driven control is present; primary actions remain native links, buttons, and inputs.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "issues",
      "confidence": "high",
      "method": "Measured page height and reviewed desktop/mobile captures.",
      "evidence": "The mobile document is 6,643 CSS pixels tall, but the screenshots and DOM show no progress cue or scroll-responsive chrome.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-layout-mobile.json",
        "evidence/login-mobile.png"
      ],
      "findingIds": [
        "F04"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "issues",
      "confidence": "high",
      "method": "Inspected the language control, loaded scripts, and authored DOM.",
      "evidence": "The language dropdown is a Bootstrap-style scripted dropdown; no CSS anchor-positioning primitives or fallback positions were found.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/home-dom.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "issues",
      "confidence": "high",
      "method": "Focused a primary input, captured it, and inspected focusability.",
      "evidence": "Focusing the login field produced no visible change in the mobile screenshot, and disclosure links are removed from the tab order with tabindex=-1.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-focus-mobile.png",
        "evidence/home-dom.json"
      ],
      "findingIds": [
        "F06"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "issues",
      "confidence": "high",
      "method": "Reviewed first-load desktop and mobile screenshots.",
      "evidence": "A fixed cookie banner obscures roughly the bottom fifth of both desktop and mobile first viewports before interaction.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-mobile.png"
      ],
      "findingIds": [
        "F07"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "issues",
      "confidence": "high",
      "method": "Inspected rendered DOM for overlay/disclosure semantics.",
      "evidence": "The consent interface is a custom #cookieInfo div with duplicate button IDs; disclosures are scripted anchors rather than dialog, popover, details, or button primitives.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/home-dom.json",
        "evidence/axe.json"
      ],
      "findingIds": [
        "F08"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "issues",
      "confidence": "high",
      "method": "Compared first viewport with full DOM and layout metrics.",
      "evidence": "The login action is followed by thousands of pixels of project promotion, footer chrome, and a persistent consent bar; the mobile page is 6,643 pixels tall.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/login-layout-mobile.json"
      ],
      "findingIds": [
        "F09"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "pass",
      "confidence": "high",
      "method": "Measured narrow-viewport layout and reviewed mobile capture.",
      "evidence": "At 360x800 the layout primitive measured scrollWidth 360, clientWidth 360, horizontalOverflowPx 0, and a valid viewport meta tag.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-layout-mobile.json",
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "issues",
      "confidence": "medium",
      "method": "Inspected stylesheets/DOM and compared desktop/mobile component layouts.",
      "evidence": "The page adapts through a global mobile layout, but no component/container-query implementation was found for reused login, project, or consent components.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-mobile.png",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F10"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "issues",
      "confidence": "high",
      "method": "Measured interactive bounding boxes and captured keyboard focus.",
      "evidence": "The probe found 27 interactive elements below 44x44 CSS pixels; login inputs are 38px high, several links are 15 to 20px high, and focused input capture showed no visible focus change.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/login-focus-mobile.png"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "pass",
      "confidence": "high",
      "method": "Reviewed first-load desktop and mobile screenshots and labels.",
      "evidence": "The first viewport clearly presents personal-code/email and password fields plus credential, SPID, and CIE sign-in actions.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "pass",
      "confidence": "medium",
      "method": "Walked the available public authentication entry points without submitting credentials.",
      "evidence": "The unauthenticated boundary exposes a credential form, password recovery, and SPID/CIE alternatives with direct controls; protected completion correctly requires a real account and was not bypassed.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/home-dom.json"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "issues",
      "confidence": "high",
      "method": "Submitted the public form empty and captured the resulting page.",
      "evidence": "Submitting the empty credential form reloads essentially the same page without an inline validation message, required-state cue, or actionable recovery state.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-empty-submit.png",
        "evidence/home-dom.json"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "issues",
      "confidence": "high",
      "method": "Ran Lighthouse and a DevTools trace/layout capture.",
      "evidence": "Mobile Lighthouse measured LCP 5.4s, above the 2.5s good threshold, despite low CLS 0.014 and TBT 60ms.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/login-trace-summary.json"
      ],
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "pass",
      "confidence": "high",
      "method": "Measured layout shifts with layout observer and Lighthouse.",
      "evidence": "Layout measured CLS 0.0276 and Lighthouse measured 0.014, both within the good range; no large first-load jump was observed.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-layout-mobile.json",
        "evidence/lighthouse.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "pass",
      "confidence": "high",
      "method": "Captured a DevTools trace and Lighthouse profile.",
      "evidence": "Trace recorded zero long tasks and 0ms TBT over 5.3s; Lighthouse reported only 60ms TBT.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-trace-summary.json",
        "evidence/lighthouse.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "issues",
      "confidence": "high",
      "method": "Captured HAR, confirmed candidates against live DOM, and ran Lighthouse.",
      "evidence": "HAR recorded 1.15MB across 33 requests, 670KB of fonts, seven parser-blocking stylesheets, and eight synchronous head scripts; the HTML DOM confirms scripts have no async/defer/module attributes.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-network-summary.json",
        "evidence/probe.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F14"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "issues",
      "confidence": "high",
      "method": "Ran Lighthouse code-coverage audits and inspected script inventory.",
      "evidence": "Lighthouse estimates 59KiB unused jQuery UI JavaScript and 12KiB unused Font Awesome CSS; the page also loads Vue, jQuery, jQuery UI, and plugins for a simple login.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F15"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "issues",
      "confidence": "high",
      "method": "Ran axe-core and Lighthouse accessibility audits.",
      "evidence": "axe found missing alt text on two images, a malformed list, and content outside landmarks; Lighthouse also found accessible-name/visible-label mismatches.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/axe.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F16"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "issues",
      "confidence": "high",
      "method": "Ran axe-core and Lighthouse color-contrast audits.",
      "evidence": "axe reported 21 contrast failures; Lighthouse measured examples as low as 1.82:1 and the primary action at 4.04:1.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/axe.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F17"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "issues",
      "confidence": "high",
      "method": "Ran axe/Lighthouse and inspected headings, list markup, and focused state.",
      "evidence": "The html element has no lang, the document duplicates hidden headings, a list contains a direct span child, disclosure links use tabindex=-1, and focused input state was not visibly distinct.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/axe.json",
        "evidence/lighthouse.json",
        "evidence/login-focus-mobile.png",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F18"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "issues",
      "confidence": "high",
      "method": "Reviewed desktop and mobile screenshots at default zoom.",
      "evidence": "Desktop labels and recovery text visibly collide around the password field; mobile explanatory copy is fully justified with large word gaps.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-mobile.png"
      ],
      "findingIds": [
        "F19"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "issues",
      "confidence": "high",
      "method": "Measured mobile reflow and interactive target bounds.",
      "evidence": "The narrow viewport reflows without horizontal overflow, but 27 measured interactive elements are under 44x44 and several essential controls are only 15 to 20px high.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/login-layout-mobile.json"
      ],
      "findingIds": [
        "F20"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "pass",
      "confidence": "high",
      "method": "Ran Lighthouse best-practices console audit.",
      "evidence": "Lighthouse errors-in-console audit passed with no items, and the loaded surface completed without an uncaught exception.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "issues",
      "confidence": "high",
      "method": "Ran image audit and inspected doctype/markup with Lighthouse and DOM.",
      "evidence": "Doctype and UTF-8 are valid, but all seven images lack explicit dimensions and the DOM includes a malformed ul with a direct span child.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse.json",
        "evidence/home-dom.json"
      ],
      "findingIds": [
        "F21"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "pass",
      "confidence": "high",
      "method": "Ran Lighthouse and inspected load-time resource/permission behavior.",
      "evidence": "Lighthouse best-practices scored 1.0; console, deprecation, and third-party-cookie audits passed, and no permission prompt appeared on load.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "issues",
      "confidence": "high",
      "method": "Inspected document metadata and ran Lighthouse SEO.",
      "evidence": "The title is descriptive, but both DOM probe and Lighthouse show no meta description.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F22"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "pass",
      "confidence": "high",
      "method": "Inspected robots.txt, metadata, and anchors; ran Lighthouse SEO.",
      "evidence": "The page has a viewport meta tag, robots.txt explicitly allows the login URL, and primary destination links use real href values.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/robots.txt",
        "evidence/probe.json",
        "evidence/lighthouse.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "issues",
      "confidence": "high",
      "method": "Inspected canonical/robots/sitemap and requested the sitemap URL.",
      "evidence": "No canonical link is present and sitemap.xml advertises /sdf/, which returned a generic nginx 404 during both DOM and screenshot checks.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/sitemap.xml",
        "evidence/sdf-desktop.png",
        "evidence/sdf-dom.json"
      ],
      "findingIds": [
        "F23"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Judged page type from DOM and first viewport.",
      "evidence": "The audited host surface is an authentication entry page, not an article/product/event entity that needs rich-result schema or social sharing cards.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/home-dom.json",
        "evidence/login-desktop.png"
      ],
      "reason": "The audited host surface is an authentication entry page, not an article/product/event entity that needs rich-result schema or social sharing cards."
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "issues",
      "confidence": "high",
      "method": "Ran security-header, cookie, secret, and HAR inspections.",
      "evidence": "HTTPS and HSTS are present, but CSP permits unsafe-eval and X-Content-Type-Options and Referrer-Policy are absent.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/headers.json",
        "evidence/cookies.json",
        "evidence/secrets.json"
      ],
      "findingIds": [
        "F24"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "pass",
      "confidence": "high",
      "method": "Ran tracker, cookie, HAR, and secret scans before consent.",
      "evidence": "Tracker scan found no known trackers, cookie audit found zero cookies before consent, and HAR showed only one static asset CDN as third party.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/trackers.json",
        "evidence/cookies.json",
        "evidence/login-network-summary.json",
        "evidence/secrets.json"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "pass",
      "confidence": "medium",
      "method": "Inspected first-load behavior and authentication controls.",
      "evidence": "No permission prompt or permission-related load was observed; sign-in offers SPID and CIE identity options alongside credentials and password recovery.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/login-desktop.png"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "Inspected browser-enforced security headers.",
      "evidence": "HSTS and frame restrictions are present, but Referrer-Policy and nosniff are missing and CSP includes unsafe-eval; Permissions-Policy only limits geolocation.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F25"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "issues",
      "confidence": "high",
      "method": "Compared JavaScript-enabled and disabled browser captures and raw HTML.",
      "evidence": "With JavaScript disabled, the crawler screenshot shows an empty login panel and no usable credential form even though the full browser view provides authentication controls.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/discoverability-login-crawler.png",
        "evidence/login-raw.html"
      ],
      "findingIds": [
        "F26"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "pass",
      "confidence": "medium",
      "method": "Exercised representative controls and reviewed mobile/desktop bounds plus Lighthouse console audit.",
      "evidence": "The consent region and sign-in controls remain within both desktop and mobile viewports, no console exceptions were recorded, and disclosure interaction completed.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-mobile.png",
        "evidence/lighthouse.json"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "issues",
      "confidence": "high",
      "method": "Probed manifest/service worker and observed the browser network-failure state.",
      "evidence": "The public login behaves as an app entry point but exposes no web app manifest, service-worker controller, or offline fallback.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/discoverability-login-rendered.png"
      ],
      "findingIds": [
        "F27"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "issues",
      "confidence": "high",
      "method": "Observed live network failure and requested representative invalid/retired route.",
      "evidence": "One browser evidence run received ERR_INVALID_RESPONSE and showed Chrome’s generic error page; the sitemap-listed /sdf/ route returns an unbranded nginx 404 with no recovery links.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/discoverability-login-rendered.png",
        "evidence/sdf-desktop.png"
      ],
      "findingIds": [
        "F28"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "issues",
      "confidence": "high",
      "method": "Inspected document attributes and ran accessibility audits.",
      "evidence": "A language selector is present, but html has no lang or dir; axe and Lighthouse both flag the missing language declaration.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/axe.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F29"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Inspected rendered text and form surface for locale-sensitive data.",
      "evidence": "The unauthenticated pages contain no user-visible dates, numbers, currencies, durations, or locale-sensitive values to format.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/home-dom.json"
      ],
      "reason": "The unauthenticated pages contain no user-visible dates, numbers, currencies, durations, or locale-sensitive values to format."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Inspected rendered content for time concepts.",
      "evidence": "The unauthenticated pages expose no events, timestamps, schedules, or time-zone-sensitive controls.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/home-dom.json"
      ],
      "reason": "The unauthenticated pages expose no events, timestamps, schedules, or time-zone-sensitive controls."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "pass",
      "confidence": "high",
      "method": "Reviewed first-load consent and authentication choices.",
      "evidence": "Consent presents refuse, personalize, and accept actions at the same level; no forced continuity, pricing, disguised advertising, or confirmshaming was observed.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "issues",
      "confidence": "high",
      "method": "Submitted the sign-in form empty and inspected resulting markup/screenshot.",
      "evidence": "Empty form submission gives no clear inline error, required marker, aria-invalid state, or announced recovery message.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-empty-submit.png",
        "evidence/home-dom.json"
      ],
      "findingIds": [
        "F30"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "issues",
      "confidence": "high",
      "method": "Inspected rendered form input attributes.",
      "evidence": "The username/email and password controls both have empty autocomplete properties instead of username and current-password.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F31"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "pass",
      "confidence": "medium",
      "method": "Reviewed public authentication and recovery controls.",
      "evidence": "The available account boundary clearly distinguishes credentials, SPID, and CIE and exposes password recovery; no commercial commitment or continuity prompt is present.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/home-dom.json"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "issues",
      "confidence": "high",
      "method": "Ran the image primitive and inspected mobile layout.",
      "evidence": "All seven images lack intrinsic dimensions; four below-fold images are not lazy-loaded, two PNG assets use legacy format, and three responsive candidates have no srcset.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/images.json"
      ],
      "findingIds": [
        "F32"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "issues",
      "confidence": "high",
      "method": "Ran Lighthouse unused-code audits and reviewed HAR/script inventory.",
      "evidence": "The simple login ships 59KiB unused jQuery UI JavaScript and 12KiB unused Font Awesome CSS, in addition to multiple legacy UI libraries.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F33"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "issues",
      "confidence": "high",
      "method": "Captured HAR and reviewed resource-type/origin totals.",
      "evidence": "Three static CDN requests account for 579,650 bytes, primarily two Averta TTF files; fonts alone transfer 669,677 bytes, over half the 1.15MB page.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-network-summary.json"
      ],
      "findingIds": [
        "F34"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Judged applicability from the authentication-only host surface.",
      "evidence": "This is a sensitive authentication boundary with no declared agent-facing task; exposing sign-in actions as agent tools would require an explicit safety and consent design.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png"
      ],
      "reason": "This is a sensitive authentication boundary with no declared agent-facing task; exposing sign-in actions as agent tools would require an explicit safety and consent design."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Judged applicability from the authentication-only host surface.",
      "evidence": "The authentication entry page has no summarisation, generation, translation, or inference task where on-device AI would improve the experience.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/login-desktop.png"
      ],
      "reason": "The authentication entry page has no summarisation, generation, translation, or inference task where on-device AI would improve the experience."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "pass",
      "confidence": "medium",
      "method": "Compared baseline/post heap summaries and a same-page repeated-interaction memory probe.",
      "evidence": "After ten disclosure/dropdown interactions, same-page JS heap rose 700,716 bytes and DOM nodes by 43 with no listeners or intervals added; separate heap summaries rose 2.5%, which is bounded warm-up rather than evidence of unbounded retention.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline",
        "evidence/heap-post",
        "evidence/memory-probe.json"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "pass",
      "confidence": "medium",
      "method": "Captured and compared readable heap summaries.",
      "evidence": "Baseline heap summary is 9.39MB with 148,176 snapshot nodes, proportionate to this small Vue/jQuery login; post snapshot is 9.63MB.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline",
        "evidence/heap-post"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "medium",
      "method": "Compared constructor summaries and instrumented repeated interactions.",
      "evidence": "Neither heap summary reports Detached constructors; instrumentation across ten interactions observed zero new listeners and zero intervals.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline",
        "evidence/heap-post",
        "evidence/memory-probe.json"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F01",
        "F02"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F03"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F04",
        "F05",
        "F06"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F07",
        "F08",
        "F09"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F10",
        "F11"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F13",
        "F14",
        "F15"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F16",
        "F17",
        "F18",
        "F19",
        "F20"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F21"
      ]
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F22",
        "F23"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F24",
        "F25"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F26",
        "F27",
        "F28"
      ]
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F29"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F30",
        "F31"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F32",
        "F33",
        "F34"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "This is a sensitive authentication boundary with no declared agent-facing task; exposing sign-in actions as agent tools would require an explicit safety and consent design. The authentication entry page has no summarisation, generation, translation, or inference task where on-device AI would improve the experience.",
      "findingIds": []
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "pass",
      "findingIds": []
    }
  ],
  "paths": [
    {
      "id": "login",
      "description": "Root redirect and public authentication entry. Represents the host’s primary task, form, consent, responsive layout, preference, accessibility, performance, security, resilience, and memory behavior.",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "conditions": [
        "desktop",
        "viewport: 360x800",
        "prefers-color-scheme: dark",
        "prefers-contrast: more",
        "prefers-reduced-motion: reduce",
        "keyboard focus",
        "JavaScript disabled",
        "empty form submission",
        "ten repeated disclosure/dropdown interactions"
      ],
      "result": "issues"
    },
    {
      "id": "sitemap-route",
      "description": "The only second URL listed in sitemap.xml. Audited as the host’s alternate public route and HTTP failure state; it returned a generic nginx 404.",
      "url": "https://web.spaggiari.eu/sdf/",
      "conditions": [
        "desktop",
        "direct navigation"
      ],
      "result": "issues"
    },
    {
      "id": "external-detail-excluded",
      "description": "A representative product/detail link was followed and redirected to https://www.spaggiari.eu/, a separate host. It was documented but excluded from this host-scoped audit.",
      "url": "https://web.spaggiari.eu/www/app/default/index.php?p=cvv&s=cvv",
      "conditions": [
        "redirect inspection"
      ],
      "result": "skipped"
    }
  ],
  "findings": [
    {
      "id": "F01",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "The login surface ignores the user’s dark color-scheme preference.",
      "evidence": "Desktop captures under light and prefers-color-scheme: dark are byte-identical (78,996 bytes) and show the same white and red palette.",
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-dark.png"
      ],
      "suggestedFix": "Declare color-scheme and provide preference-driven light and dark surface, text, control, and browser-chrome colors.",
      "effort": "medium"
    },
    {
      "id": "F02",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-contrast",
      "guidanceId": "adapt-scrollbar-to-contrast-preferences",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "The page neither adapts to increased contrast nor meets baseline contrast in several controls and content panels.",
      "evidence": "The prefers-contrast: more capture is byte-identical to the default capture, while axe found 21 contrast failures, including the primary button at 4.04:1.",
      "artifacts": [
        "evidence/login-high-contrast.png",
        "evidence/axe.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Use system/high-contrast media queries and revise color tokens so text and controls retain WCAG contrast.",
      "effort": "medium"
    },
    {
      "id": "F03",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "implement-natural-interactions",
      "principleCheckId": "view-transitions",
      "guidanceId": "same-document-transitions",
      "guidanceCategory": "animation",
      "severity": "low",
      "confidence": "high",
      "summary": "State changes do not use View Transitions and provide little continuity.",
      "evidence": "The page exposes no active animations or View Transition evidence; login, language, disclosure, and project state changes are implemented by legacy scripts and abrupt swaps.",
      "artifacts": [
        "evidence/home-dom.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Add same-document View Transitions to disclosure and state changes, with a reduced-motion fallback.",
      "effort": "medium"
    },
    {
      "id": "F04",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "provide-guided-navigation",
      "principleCheckId": "scroll-state-aware-chrome",
      "guidanceId": "scroll-progress-indicator",
      "guidanceCategory": "navigation",
      "severity": "low",
      "confidence": "high",
      "summary": "A very long public login/marketing page offers no scroll-state orientation.",
      "evidence": "The mobile document is 6,643 CSS pixels tall, but the screenshots and DOM show no progress cue or scroll-responsive chrome.",
      "artifacts": [
        "evidence/login-layout-mobile.json",
        "evidence/login-mobile.png"
      ],
      "suggestedFix": "Shorten the page first; if long content remains, add a lightweight declarative progress or scroll-state cue.",
      "effort": "small"
    },
    {
      "id": "F05",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "provide-guided-navigation",
      "principleCheckId": "anchored-positioning",
      "guidanceId": "position-aware-tooltips",
      "guidanceCategory": "css",
      "severity": "low",
      "confidence": "high",
      "summary": "The language menu relies on legacy manual overlay positioning rather than anchored positioning.",
      "evidence": "The language dropdown is a Bootstrap-style scripted dropdown; no CSS anchor-positioning primitives or fallback positions were found.",
      "artifacts": [
        "evidence/home-dom.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Use popover plus CSS anchor positioning and position-try fallbacks for the language menu.",
      "effort": "medium"
    },
    {
      "id": "F06",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "provide-guided-navigation",
      "principleCheckId": "directs-attention",
      "guidanceId": "directional-navigation-transitions",
      "guidanceCategory": "navigation",
      "severity": "medium",
      "confidence": "high",
      "summary": "Focus and disclosure changes do not reliably guide keyboard users’ attention.",
      "evidence": "Focusing the login field produced no visible change in the mobile screenshot, and disclosure links are removed from the tab order with tabindex=-1.",
      "artifacts": [
        "evidence/login-focus-mobile.png",
        "evidence/home-dom.json"
      ],
      "suggestedFix": "Add a strong :focus-visible treatment, retain disclosure controls in tab order, and move focus intentionally after state changes.",
      "effort": "small"
    },
    {
      "id": "F07",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "no-intrusive-interruptions",
      "guidanceId": "light-dismiss-a-dialog",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "The consent banner obscures content on first load.",
      "evidence": "A fixed cookie banner obscures roughly the bottom fifth of both desktop and mobile first viewports before interaction.",
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-mobile.png"
      ],
      "suggestedFix": "Use a compact, semantic consent dialog or non-obscuring region with equal accept/refuse actions and preserve access to content.",
      "effort": "medium"
    },
    {
      "id": "F08",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "semantic-dismissible-primitives",
      "guidanceId": "declarative-dialog-popover-control",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "Custom div-based overlays and disclosures replace native semantic primitives.",
      "evidence": "The consent interface is a custom #cookieInfo div with duplicate button IDs; disclosures are scripted anchors rather than dialog, popover, details, or button primitives.",
      "artifacts": [
        "evidence/home-dom.json",
        "evidence/axe.json"
      ],
      "suggestedFix": "Use dialog/popover for consent and details/summary or buttons for disclosure; remove duplicate IDs.",
      "effort": "medium"
    },
    {
      "id": "F09",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "reduced-chrome",
      "guidanceId": "improve-text-layout-and-legibility",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "Marketing and consent chrome overwhelm the focused authentication task.",
      "evidence": "The login action is followed by thousands of pixels of project promotion, footer chrome, and a persistent consent bar; the mobile page is 6,643 pixels tall.",
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/login-layout-mobile.json"
      ],
      "suggestedFix": "Keep authentication and recovery content primary, collapse secondary product material, and reduce persistent chrome.",
      "effort": "medium"
    },
    {
      "id": "F10",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "component-level-responsiveness",
      "guidanceId": "size-aware-styling",
      "guidanceCategory": "css",
      "severity": "low",
      "confidence": "medium",
      "summary": "Responsive behavior is viewport-wide rather than component-aware.",
      "evidence": "The page adapts through a global mobile layout, but no component/container-query implementation was found for reused login, project, or consent components.",
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-mobile.png",
        "evidence/probe.json"
      ],
      "suggestedFix": "Define containment and container queries for reusable login, project, and consent components where their available width varies.",
      "effort": "medium"
    },
    {
      "id": "F11",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "input-modality-aware",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Many touch targets are undersized and keyboard focus is weak or invisible.",
      "evidence": "The probe found 27 interactive elements below 44x44 CSS pixels; login inputs are 38px high, several links are 15 to 20px high, and focused input capture showed no visible focus change.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/login-focus-mobile.png"
      ],
      "suggestedFix": "Provide at least 44x44 target areas and a high-contrast :focus-visible ring without relying on hover.",
      "effort": "medium"
    },
    {
      "id": "F12",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "support-core-task-success",
      "principleCheckId": "clear-system-state-and-recovery",
      "guidanceId": "accessible-error-announcement",
      "guidanceCategory": "forms",
      "severity": "high",
      "confidence": "high",
      "summary": "Empty sign-in submission provides no clear validation or recovery feedback.",
      "evidence": "Submitting the empty credential form reloads essentially the same page without an inline validation message, required-state cue, or actionable recovery state.",
      "artifacts": [
        "evidence/login-empty-submit.png",
        "evidence/home-dom.json"
      ],
      "suggestedFix": "Validate after submit/interaction, mark fields required and aria-invalid, announce a concise error, and preserve focus and entered values.",
      "effort": "small"
    },
    {
      "id": "F13",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "good-core-web-vitals",
      "guidanceId": "performance",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "Largest Contentful Paint is slow on the mobile profile.",
      "evidence": "Mobile Lighthouse measured LCP 5.4s, above the 2.5s good threshold, despite low CLS 0.014 and TBT 60ms.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/login-trace-summary.json"
      ],
      "suggestedFix": "Prioritize the actual LCP content, remove render-blocking dependencies, and reduce font/document transfer before adding more UI work.",
      "effort": "medium"
    },
    {
      "id": "F14",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-resource-delivery",
      "guidanceId": "optimize-script-priority",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "Fonts and synchronous head resources delay critical rendering.",
      "evidence": "HAR recorded 1.15MB across 33 requests, 670KB of fonts, seven parser-blocking stylesheets, and eight synchronous head scripts; the HTML DOM confirms scripts have no async/defer/module attributes.",
      "artifacts": [
        "evidence/login-network-summary.json",
        "evidence/probe.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Subset/self-host WOFF2 fonts, remove unused families, defer noncritical scripts, and inline or consolidate critical styles.",
      "effort": "medium"
    },
    {
      "id": "F15",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "identify-heavy-scripts",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "The login page ships avoidable legacy and unused code.",
      "evidence": "Lighthouse estimates 59KiB unused jQuery UI JavaScript and 12KiB unused Font Awesome CSS; the page also loads Vue, jQuery, jQuery UI, and plugins for a simple login.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Remove jQuery UI and unused icon CSS from the login bundle; load only code needed for the active authentication surface.",
      "effort": "medium"
    },
    {
      "id": "F16",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-inclusive",
      "principleCheckId": "names-roles-labels",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Accessible names, image alternatives, and semantic structure contain multiple failures.",
      "evidence": "axe found missing alt text on two images, a malformed list, and content outside landmarks; Lighthouse also found accessible-name/visible-label mismatches.",
      "artifacts": [
        "evidence/axe.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Add meaningful or empty alt text, align accessible names with visible labels, repair list children, and include consent content in a landmark/dialog.",
      "effort": "small"
    },
    {
      "id": "F17",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-inclusive",
      "principleCheckId": "sufficient-contrast",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Text and the primary sign-in action fail WCAG color contrast.",
      "evidence": "axe reported 21 contrast failures; Lighthouse measured examples as low as 1.82:1 and the primary action at 4.04:1.",
      "artifacts": [
        "evidence/axe.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Darken foreground/background token pairs and test every project theme and action at WCAG AA ratios.",
      "effort": "small"
    },
    {
      "id": "F18",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Document structure and focus behavior are unreliable for keyboard and assistive-technology users.",
      "evidence": "The html element has no lang, the document duplicates hidden headings, a list contains a direct span child, disclosure links use tabindex=-1, and focused input state was not visibly distinct.",
      "artifacts": [
        "evidence/axe.json",
        "evidence/lighthouse.json",
        "evidence/login-focus-mobile.png",
        "evidence/probe.json"
      ],
      "suggestedFix": "Set lang=it, keep one logical heading sequence, repair list semantics, keep controls tabbable, and add :focus-visible styling.",
      "effort": "medium"
    },
    {
      "id": "F19",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-inclusive",
      "principleCheckId": "legible-text",
      "guidanceId": "improve-text-layout-and-legibility",
      "guidanceCategory": "css",
      "severity": "medium",
      "confidence": "high",
      "summary": "Text spacing and alignment reduce legibility around the primary form.",
      "evidence": "Desktop labels and recovery text visibly collide around the password field; mobile explanatory copy is fully justified with large word gaps.",
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/login-mobile.png"
      ],
      "suggestedFix": "Use a simple stacked field layout, normal word spacing, left alignment, and resilient line wrapping.",
      "effort": "small"
    },
    {
      "id": "F20",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-inclusive",
      "principleCheckId": "zoom-reflow-targets-and-media",
      "guidanceId": "fluid-scaling",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Mobile reflow works, but many controls remain too small for touch.",
      "evidence": "The narrow viewport reflows without horizontal overflow, but 27 measured interactive elements are under 44x44 and several essential controls are only 15 to 20px high.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/login-layout-mobile.json"
      ],
      "suggestedFix": "Increase control hit areas to at least 44x44 while preserving the existing no-overflow layout.",
      "effort": "small"
    },
    {
      "id": "F21",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "follow-best-practices",
      "principleCheckId": "sound-document-and-assets",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "Image sizing and list markup are not soundly authored.",
      "evidence": "Doctype and UTF-8 are valid, but all seven images lack explicit dimensions and the DOM includes a malformed ul with a direct span child.",
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse.json",
        "evidence/home-dom.json"
      ],
      "suggestedFix": "Add intrinsic width/height or aspect-ratio to images and keep only li elements as direct ul children.",
      "effort": "small"
    },
    {
      "id": "F22",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-discoverable",
      "principleCheckId": "title-and-description",
      "guidanceCategory": "seo",
      "severity": "medium",
      "confidence": "high",
      "summary": "The public login page has no meta description.",
      "evidence": "The title is descriptive, but both DOM probe and Lighthouse show no meta description.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Add a concise Italian meta description explaining ClasseViva access and available sign-in methods.",
      "effort": "trivial"
    },
    {
      "id": "F23",
      "pathId": "sitemap-route",
      "url": "https://web.spaggiari.eu/sdf/",
      "principleId": "be-discoverable",
      "principleCheckId": "canonical-and-indexing-signals",
      "guidanceCategory": "seo",
      "severity": "high",
      "confidence": "high",
      "summary": "Indexing signals are inconsistent because the sitemap publishes a broken URL and the login page has no canonical.",
      "evidence": "No canonical link is present and sitemap.xml advertises /sdf/, which returned a generic nginx 404 during both DOM and screenshot checks.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/sitemap.xml",
        "evidence/sdf-desktop.png",
        "evidence/sdf-dom.json"
      ],
      "suggestedFix": "Remove or repair /sdf/, return an intentional branded 404 if retired, and add a canonical URL for the public login page.",
      "effort": "small"
    },
    {
      "id": "F24",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "severity": "high",
      "confidence": "high",
      "summary": "The authentication page has weakened XSS and response-header defenses.",
      "evidence": "HTTPS and HSTS are present, but CSP permits unsafe-eval and X-Content-Type-Options and Referrer-Policy are absent.",
      "artifacts": [
        "evidence/headers.json",
        "evidence/cookies.json",
        "evidence/secrets.json"
      ],
      "suggestedFix": "Remove unsafe-eval, set X-Content-Type-Options: nosniff, and add a strict Referrer-Policy while preserving nonce-based scripts.",
      "effort": "medium"
    },
    {
      "id": "F25",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "severity": "medium",
      "confidence": "high",
      "summary": "Defensive browser policies are incomplete for a login surface.",
      "evidence": "HSTS and frame restrictions are present, but Referrer-Policy and nosniff are missing and CSP includes unsafe-eval; Permissions-Policy only limits geolocation.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "suggestedFix": "Harden CSP, add nosniff and strict referrer policy, and explicitly deny unused permissions.",
      "effort": "small"
    },
    {
      "id": "F26",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-resilient",
      "principleCheckId": "progressive-enhancement",
      "guidanceId": "stabilize-reactive-state",
      "guidanceCategory": "resilience",
      "severity": "high",
      "confidence": "high",
      "summary": "The core sign-in form is not usable without JavaScript.",
      "evidence": "With JavaScript disabled, the crawler screenshot shows an empty login panel and no usable credential form even though the full browser view provides authentication controls.",
      "artifacts": [
        "evidence/login-desktop.png",
        "evidence/discoverability-login-crawler.png",
        "evidence/login-raw.html"
      ],
      "suggestedFix": "Render a working HTML form by default and layer Vue enhancements on top without hiding the server-rendered controls.",
      "effort": "medium"
    },
    {
      "id": "F27",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-resilient",
      "principleCheckId": "offline-and-installable",
      "guidanceId": "detect-initial-visibility-state",
      "guidanceCategory": "resilience",
      "severity": "medium",
      "confidence": "high",
      "summary": "The app entry point has no installability or offline fallback.",
      "evidence": "The public login behaves as an app entry point but exposes no web app manifest, service-worker controller, or offline fallback.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/discoverability-login-rendered.png"
      ],
      "suggestedFix": "Add a manifest and service worker that at minimum provides a branded offline explanation and safe retry path.",
      "effort": "medium"
    },
    {
      "id": "F28",
      "pathId": "sitemap-route",
      "url": "https://web.spaggiari.eu/sdf/",
      "principleId": "be-resilient",
      "principleCheckId": "network-and-http-failure-states",
      "guidanceId": "persistent-toast-notifications",
      "guidanceCategory": "resilience",
      "severity": "high",
      "confidence": "high",
      "summary": "Network and HTTP failures fall through to generic browser/server pages.",
      "evidence": "One browser evidence run received ERR_INVALID_RESPONSE and showed Chrome’s generic error page; the sitemap-listed /sdf/ route returns an unbranded nginx 404 with no recovery links.",
      "artifacts": [
        "evidence/discoverability-login-rendered.png",
        "evidence/sdf-desktop.png"
      ],
      "suggestedFix": "Serve branded 404/offline states with retry, home, support, and sign-in recovery actions.",
      "effort": "medium"
    },
    {
      "id": "F29",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-internationalised",
      "principleCheckId": "lang-dir-and-logical-properties",
      "guidanceId": "translator",
      "guidanceCategory": "internationalization",
      "severity": "high",
      "confidence": "high",
      "summary": "The multilingual login page omits the document language and direction.",
      "evidence": "A language selector is present, but html has no lang or dir; axe and Lighthouse both flag the missing language declaration.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/axe.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Set html lang=it and dir=ltr, update lang when the user switches language, and use logical layout properties.",
      "effort": "small"
    },
    {
      "id": "F30",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-trustworthy",
      "principleCheckId": "humane-error-handling",
      "guidanceId": "validate-input-after-interaction",
      "guidanceCategory": "forms",
      "severity": "high",
      "confidence": "high",
      "summary": "Sign-in validation is silent rather than humane and actionable.",
      "evidence": "Empty form submission gives no clear inline error, required marker, aria-invalid state, or announced recovery message.",
      "artifacts": [
        "evidence/login-empty-submit.png",
        "evidence/home-dom.json"
      ],
      "suggestedFix": "Validate after interaction, retain values, associate concise field errors, set aria-invalid, and announce a summary via a live region.",
      "effort": "small"
    },
    {
      "id": "F31",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-trustworthy",
      "principleCheckId": "trustworthy-input-assistance",
      "guidanceId": "autofill-sign-in-form",
      "guidanceCategory": "forms",
      "severity": "medium",
      "confidence": "high",
      "summary": "The sign-in form does not identify fields for password-manager autofill.",
      "evidence": "The username/email and password controls both have empty autocomplete properties instead of username and current-password.",
      "artifacts": [
        "evidence/probe.json"
      ],
      "suggestedFix": "Set autocomplete=username and autocomplete=current-password, plus appropriate inputmode/capitalize behavior for the identifier.",
      "effort": "trivial"
    },
    {
      "id": "F32",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-sustainable",
      "principleCheckId": "optimised-assets",
      "guidanceId": "optimize-image-priority",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Image delivery misses sizing, lazy-loading, and responsive/modern format opportunities.",
      "evidence": "All seven images lack intrinsic dimensions; four below-fold images are not lazy-loaded, two PNG assets use legacy format, and three responsive candidates have no srcset.",
      "artifacts": [
        "evidence/images.json"
      ],
      "suggestedFix": "Add dimensions, lazy-load below-fold images, and provide responsive modern image sources where raster assets remain.",
      "effort": "small"
    },
    {
      "id": "F33",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-sustainable",
      "principleCheckId": "no-wasteful-work",
      "guidanceId": "conditional-async-dependencies",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "The login page performs and transfers avoidable framework work.",
      "evidence": "The simple login ships 59KiB unused jQuery UI JavaScript and 12KiB unused Font Awesome CSS, in addition to multiple legacy UI libraries.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Remove unused libraries/styles and conditionally load recovery/captcha code only when those states open.",
      "effort": "medium"
    },
    {
      "id": "F34",
      "pathId": "login",
      "url": "https://web.spaggiari.eu/home/app/default/login.php",
      "principleId": "be-sustainable",
      "principleCheckId": "third-party-and-media-budget",
      "guidanceId": "deprioritize-background-fetches",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Third-party font delivery dominates the page-weight budget.",
      "evidence": "Three static CDN requests account for 579,650 bytes, primarily two Averta TTF files; fonts alone transfer 669,677 bytes, over half the 1.15MB page.",
      "artifacts": [
        "evidence/login-network-summary.json"
      ],
      "suggestedFix": "Subset and self-host only required WOFF2 weights, use system fallback first, and avoid loading italic/icon fonts before needed.",
      "effort": "medium"
    }
  ],
  "taskList": [
    {
      "id": "T1",
      "title": "Repair accessible authentication semantics, contrast, focus, targets, and errors",
      "priority": 1,
      "findingIds": [
        "F12",
        "F16",
        "F17",
        "F18",
        "F19",
        "F20",
        "F30",
        "F31"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T2",
      "title": "Reduce LCP by trimming fonts and synchronous legacy dependencies",
      "priority": 2,
      "findingIds": [
        "F13",
        "F14",
        "F15",
        "F32",
        "F33",
        "F34"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T3",
      "title": "Harden CSP and response policies",
      "priority": 3,
      "findingIds": [
        "F24",
        "F25"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T4",
      "title": "Make the login progressively enhanced and provide branded failure states",
      "priority": 4,
      "findingIds": [
        "F26",
        "F27",
        "F28"
      ],
      "guidanceId": "stabilize-reactive-state",
      "status": "open"
    },
    {
      "id": "T5",
      "title": "Repair sitemap, canonical, and description metadata",
      "priority": 5,
      "findingIds": [
        "F22",
        "F23"
      ],
      "status": "open"
    },
    {
      "id": "T6",
      "title": "Honor dark and contrast preferences",
      "priority": 6,
      "findingIds": [
        "F01",
        "F02"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T7",
      "title": "Replace custom consent/disclosure chrome with semantic primitives",
      "priority": 7,
      "findingIds": [
        "F07",
        "F08",
        "F09"
      ],
      "guidanceId": "declarative-dialog-popover-control",
      "status": "open"
    },
    {
      "id": "T8",
      "title": "Modernize responsive navigation and interaction cues",
      "priority": 8,
      "findingIds": [
        "F03",
        "F04",
        "F05",
        "F06",
        "F10",
        "F11"
      ],
      "guidanceId": "size-aware-styling",
      "status": "open"
    },
    {
      "id": "T9",
      "title": "Correct language and direction metadata",
      "priority": 9,
      "findingIds": [
        "F29"
      ],
      "guidanceId": "translator",
      "status": "open"
    },
    {
      "id": "T10",
      "title": "Add intrinsic image sizing and responsive delivery",
      "priority": 10,
      "findingIds": [
        "F21"
      ],
      "guidanceId": "html",
      "status": "open"
    }
  ],
  "budget": {
    "wallClockSeconds": 1500,
    "pathCount": 3,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-27T12-35-55-422Z"
}
