{
  "url": "https://bdvenlinea.banvenez.com",
  "auditedAt": "2026-07-27T21:26:10.983Z",
  "mode": "report",
  "status": "completed",
  "statusDetail": "Atomic audit completed across the public login and linked user-management form. Authenticated account pages were not entered because no credentials were supplied; they are explicitly outside the representative unauthenticated scope.",
  "page": {
    "appType": "spa",
    "framework": "Angular 6.1.10",
    "notes": "Public username-first banking login with a linked account-management form, PWA manifest/service worker, client-rendered content and desktop promotional background."
  },
  "evidenceUsed": [
    "screenshot",
    "dom",
    "layout-metrics",
    "evaluate-probe",
    "discoverability",
    "har",
    "trace",
    "headers",
    "cookies",
    "trackers",
    "images",
    "secrets",
    "heap-summary",
    "Lighthouse 13.4.1/axe-core"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "component-specific-light-dark-theme",
    "accessibility",
    "adapt-scrollbar-to-contrast-preferences",
    "same-document-transitions",
    "cross-document-transitions",
    "group-element-transitions",
    "faster-spa-view-transitions",
    "scrollytelling",
    "parallax-scroll-effects",
    "scroll-entry-exit-effects",
    "carousel-slide-effects",
    "physics-based-easing",
    "individual-transform-properties",
    "animate-element-entry-exit",
    "animate-to-from-top-layer",
    "animate-to-intrinsic-sizes",
    "dynamic-sibling-animations",
    "interactive-content-reveal",
    "pull-to-reveal",
    "swipe-to-remove",
    "shrinking-header-on-scroll",
    "scroll-progress-indicator",
    "scroll-position-aware-elements",
    "scroll-snap-realtime-feedback",
    "scroll-snap-state-sync",
    "scroll-target-on-load",
    "soft-edge-content-fade",
    "scrollability-affordance-hints",
    "anchor-positioning-tab-underline",
    "position-aware-tooltips",
    "interest-triggered-tooltips",
    "interest-triggered-action-previews",
    "directional-navigation-transitions",
    "carousel-snap-highlights",
    "navigation-drawer",
    "stack-drill-down",
    "persistent-app-tours",
    "persistent-toast-notifications",
    "light-dismiss-a-dialog",
    "platform-controls-dismiss-dialog",
    "declarative-dialog-popover-control",
    "animated-select-picker",
    "branded-select-styling",
    "brand-consistent-forms",
    "custom-select-picker-layouts",
    "rich-media-picker",
    "complex-shapes",
    "shaped-cutouts",
    "overflow-clipping-control",
    "visually-texture-content",
    "apply-webgl-shaders",
    "interactive-content-in-3d-scenes",
    "highlight-text-ranges",
    "prevent-text-wrapping",
    "customize-scrollbar-color-and-thickness",
    "export-html-media-from-canvas",
    "fluid-scaling",
    "calculate-with-intrinsic-sizes",
    "css-layout",
    "size-aware-styling",
    "content-based-styling",
    "child-state-based-styling",
    "design-token-reactivity",
    "dynamic-sibling-styling",
    "form-fields-automatically-fit-contents",
    "improve-text-layout-and-legibility",
    "forms",
    "accessible-error-announcement",
    "required-field-feedback",
    "validate-input-after-interaction",
    "identify-inp-causes",
    "schedule-tasks-by-priority",
    "optimize-preload-priority",
    "improve-next-page-load-performance",
    "interactions-in-complex-layouts",
    "performance",
    "visually-stable-font-fallbacks",
    "break-up-long-tasks",
    "identify-heavy-scripts",
    "optimize-script-priority",
    "defer-rendering-heavy-content",
    "defer-work-until-scroll-ends",
    "optimize-image-priority",
    "conditional-async-dependencies",
    "expose-canvas-content-to-browser-features",
    "move-dom-element-without-losing-state",
    "precise-text-alignment",
    "visually-stable-mixed-fonts",
    "css",
    "html",
    "reduce-style-repetition",
    "security",
    "privacy",
    "batch-analytics-events",
    "full-session-analytics",
    "calculate-total-foreground-time",
    "passkeys",
    "passkey-registration",
    "passkey-authentication",
    "passkey-reauthentication",
    "passkey-conditional-create",
    "passkey-management",
    "flicker-free-client-side-ab-testing",
    "consistent-cross-document-transitions",
    "stabilize-reactive-state",
    "resilient-context-menus-and-nested-dropdowns",
    "persistent-top-layer-ui",
    "detect-initial-visibility-state",
    "sequence-distributed-events",
    "translator",
    "language-detection",
    "support-global-calendar-systems",
    "capture-location-agnostic-data",
    "format-human-readable-durations",
    "manage-recurring-intervals",
    "calculate-event-differentials",
    "coordinate-global-events",
    "model-partial-time-concepts",
    "search-hidden-content",
    "select-menu-interaction",
    "style-parent-with-has",
    "autofill-address-form",
    "autofill-payment-form",
    "autofill-sign-in-form",
    "autofill-sign-up-form",
    "autofill-highlight-inputs",
    "deliver-optimized-decorative-images",
    "resolution-optimized-pseudo-elements",
    "deprioritize-background-fetches",
    "efficient-background-processing",
    "webmcp",
    "agentic-forms",
    "agentic-javascript-tools",
    "language-model",
    "summarizer"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "Desktop login at 1440x900",
      "condition": "viewport: 1440x900",
      "findingIds": [
        "F01",
        "F18"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "Mobile login at 360x800",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F04",
        "F12",
        "F21"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/dark.png",
      "caption": "Login under dark preference",
      "condition": "prefers-color-scheme: dark",
      "findingIds": [
        "F01"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/high-contrast.png",
      "caption": "Login under increased contrast preference",
      "condition": "prefers-contrast: more",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/gestion-desktop.png",
      "caption": "User-management form at desktop",
      "condition": "viewport: 1440x900",
      "findingIds": [
        "F02",
        "F05",
        "F11",
        "F25",
        "F26",
        "F28"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/gestion-mobile.png",
      "caption": "User-management form at mobile",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F26"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "Browser-rendered login",
      "condition": "JavaScript enabled",
      "findingIds": [
        "F23"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "Crawler/no-JS login view",
      "condition": "JavaScript disabled",
      "findingIds": [
        "F23"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/gestion-discoverability-rendered.png",
      "caption": "Browser-rendered management route",
      "condition": "JavaScript enabled",
      "findingIds": [
        "F23"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/gestion-discoverability-crawler.png",
      "caption": "Crawler/no-JS management route",
      "condition": "JavaScript disabled",
      "findingIds": [
        "F23"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/dom.json",
      "caption": "Rendered login DOM and computed styles",
      "condition": "default",
      "findingIds": [
        "F03",
        "F08",
        "F27"
      ]
    },
    {
      "type": "other",
      "path": "evidence/comprehensive-probe.json",
      "caption": "Metadata, CSS, controls, routes, robots/sitemap and platform probe",
      "condition": "default",
      "findingIds": [
        "F01",
        "F02",
        "F03",
        "F04",
        "F11",
        "F12",
        "F15",
        "F16",
        "F17",
        "F18",
        "F20",
        "F21",
        "F24",
        "F27",
        "F28"
      ]
    },
    {
      "type": "layout",
      "path": "evidence/layout-mobile.json",
      "caption": "Mobile overflow, CLS and long-task observation",
      "condition": "viewport: 360x800",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Security response headers",
      "condition": "default",
      "findingIds": [
        "F19",
        "F22"
      ]
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Cookie security attributes",
      "condition": "default",
      "findingIds": [
        "F19"
      ]
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Third-party tracker inventory",
      "condition": "default",
      "findingIds": [
        "F20",
        "F31"
      ]
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Rendered image audit",
      "condition": "default",
      "findingIds": [
        "F10",
        "F14",
        "F29"
      ]
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Client-exposed secret scan",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "har",
      "path": "evidence/network.har",
      "caption": "Full load network capture",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "har-summary",
      "path": "evidence/network-summary.json",
      "caption": "Compact network totals and dependency signals",
      "condition": "default",
      "findingIds": [
        "F08",
        "F09",
        "F13",
        "F20",
        "F30",
        "F31"
      ]
    },
    {
      "type": "trace",
      "path": "evidence/performance-trace.json",
      "caption": "DevTools performance trace",
      "condition": "default",
      "findingIds": [
        "F06"
      ]
    },
    {
      "type": "trace-summary",
      "path": "evidence/performance-trace-summary.json",
      "caption": "Compact trace timings and long tasks",
      "condition": "default",
      "findingIds": [
        "F06",
        "F07",
        "F08"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Lighthouse 13.4.1 full report",
      "condition": "mobile simulated",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/lighthouse-summary.json",
      "caption": "Selected Lighthouse metrics and audit details",
      "condition": "mobile simulated",
      "findingIds": [
        "F06",
        "F07",
        "F09",
        "F10",
        "F13",
        "F14",
        "F15",
        "F30"
      ]
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability",
      "caption": "Raw HTML versus rendered login content",
      "condition": "JavaScript disabled comparison",
      "findingIds": []
    },
    {
      "type": "discoverability",
      "path": "evidence/gestion-discoverability",
      "caption": "Raw HTML versus rendered management content and HTTP status",
      "condition": "JavaScript disabled comparison",
      "findingIds": [
        "F05",
        "F17",
        "F25"
      ]
    },
    {
      "type": "other",
      "path": "evidence/reduced-motion-probe.json",
      "caption": "Animation state under reduced-motion preference",
      "condition": "prefers-reduced-motion: reduce",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/service-worker.json",
      "caption": "Service worker registration and CacheStorage inventory",
      "condition": "default",
      "findingIds": [
        "F24"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.heapsnapshot",
      "caption": "Readable V8 heap summary at loaded login",
      "condition": "default",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/memory-metrics.json",
      "caption": "Before/after same-session repeated input metrics",
      "condition": "10 repeated input interactions",
      "findingIds": []
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 58,
    "blocked": 0,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": true
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "a screenshot or computed background under an emulated prefers-color-scheme: dark condition will reveal whether surfaces re-tint; the page CSS / a color-scheme declaration is corroborating evidence. The model chooses the ",
      "evidence": "The light and dark screenshots are byte-identical (501,542 bytes), the computed color-scheme is normal, and the CSS probe found no prefers-color-scheme rule.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dark.png",
        "evidence/comprehensive-probe.json"
      ],
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "pass",
      "confidence": "high",
      "method": "a transition video, or an in-page probe of getAnimations()/computed animation under an emulated prefers-reduced-motion: reduce condition, can show whether motion stops. The model chooses.",
      "evidence": "Under emulated prefers-reduced-motion: reduce, matchMedia was true, the stylesheet probe found a reduced-motion rule, and document.getAnimations() returned none.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/reduced-motion-probe.json",
        "evidence/high-contrast.png"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "a screenshot under emulated prefers-contrast: more / forced-colors, or an axe/contrast probe, can show whether controls and text survive. The model chooses.",
      "evidence": "The prefers-contrast: more screenshot kept the form, text, underlines and button states visible; Lighthouse color contrast passed.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/reduced-motion-probe.json",
        "evidence/high-contrast.png"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "issues",
      "confidence": "high",
      "method": "a transition video of a route/state change shows whether it animates; the page source / ::view-transition usage corroborates. The model chooses.",
      "evidence": "The CSS probe found no view-transition usage; the Angular recovery route replaces state without a declared transition.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/gestion-desktop.png"
      ],
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "not-applicable",
      "confidence": "high",
      "method": "source/CSS inspection for animation-timeline: scroll()/view(); a long-task / scroll-handler probe can flag the main-thread anti-pattern. The model chooses.",
      "evidence": "No scroll-linked animation, parallax, scrollytelling, carousel, or reveal exists on the two short form views.",
      "reason": "No scroll-linked animation, parallax, scrollytelling, carousel, or reveal exists on the two short form views."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "not-applicable",
      "confidence": "high",
      "method": "CSS inspection for scroll-snap / overscroll-behavior / physics-based easing vs custom pointermove listeners. The model chooses.",
      "evidence": "The audited login and management forms expose no gesture-driven interaction to which this check applies.",
      "reason": "The audited login and management forms expose no gesture-driven interaction to which this check applies."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "not-applicable",
      "confidence": "high",
      "method": "a transition video of scrolling, or CSS inspection for scroll-state container queries. The model chooses.",
      "evidence": "Neither short form route scrolls or has sticky/affixed chrome that needs scroll-state behavior.",
      "reason": "Neither short form route scrolls or has sticky/affixed chrome that needs scroll-state behavior."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "not-applicable",
      "confidence": "high",
      "method": "CSS inspection for anchor-name / position-anchor / position-try on overlays; a screenshot of an open overlay near a viewport edge can show drift. The model chooses.",
      "evidence": "No tooltip, popover, menu, or viewport-edge overlay was present in the exercised states.",
      "reason": "No tooltip, popover, menu, or viewport-edge overlay was present in the exercised states."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "pass",
      "confidence": "high",
      "method": "CSS inspection for ::highlight / scroll-marker; a transition video can show whether attention is cued after navigation. The model chooses.",
      "evidence": "The recovery route presents a centered “Gestión de usuarios” title, a linear form, a primary continuation state and a visible Cancel action.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "pass",
      "confidence": "high",
      "method": "a screenshot on load, or a DOM probe for full-viewport overlays present before interaction. The model chooses.",
      "evidence": "Desktop and mobile load screenshots show the task immediately with no popup, interstitial, consent wall, or content-obscuring banner.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection for popover / <dialog> / <details> vs custom overlay divs with manual dismiss handling. The model chooses.",
      "evidence": "No overlay or disclosure required a dialog/popover/details primitive; the observed actions are native links, button and form controls.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "pass",
      "confidence": "high",
      "method": "a screenshot plus layout metrics can show the proportion of the viewport given to chrome vs content. The model chooses.",
      "evidence": "Mobile dedicates the view to one compact task card; desktop promotional art does not cover or interrupt the login card.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "pass",
      "confidence": "high",
      "method": "layout metrics (scrollWidth vs innerWidth) and a screenshot at an emulated narrow mobile viewport reveal overflow. The model chooses.",
      "evidence": "At 360x800, layout measured scrollWidth=clientWidth=360 and 0 horizontal overflow; the mobile screenshot shows a fully contained card.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "issues",
      "confidence": "high",
      "method": "CSS inspection for @container / container-type; a computed-style probe of the same component in a wide vs narrow container shows whether it adapts. The model chooses.",
      "evidence": "Rendered CSS contains multiple @media width rules but the probe found no @container/container-type usage.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json",
        "evidence/comprehensive-probe.json"
      ],
      "findingIds": [
        "F03"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "issues",
      "confidence": "high",
      "method": "a focus probe (focus an element, read the computed outline) or an axe target-size check; a screenshot of a focused control corroborates. The model chooses.",
      "evidence": "The probe measured recovery links at only 15px high and the focused input itself had outline:none and no box-shadow.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/mobile.png"
      ],
      "findingIds": [
        "F04"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "pass",
      "confidence": "high",
      "method": "screenshot the first viewport and key scrolled states; inspect heading structure, nav labels, button text, and visual hierarchy; a task walkthrough can show whether the next action is obvious. The model chooses.",
      "evidence": "The first viewport identifies “BDVenlínea personas”, presents the Usuario field and Entrar action without competing calls to action.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "issues",
      "confidence": "high",
      "method": "run the flow manually with screenshots/DOM snapshots at each step; compare expected vs actual path length; inspect form requirements, navigation continuity, and blockers. The model chooses.",
      "evidence": "The direct /gestion-usuario discoverability fetch returned 404 even though Angular later painted a form; both public recovery and registration links depend on this route.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/gestion-discoverability",
        "evidence/gestion-desktop.png"
      ],
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "pass",
      "confidence": "high",
      "method": "exercise network delay/failure, invalid input, empty data and success states; screenshot the state messaging and recovery controls; inspect whether browser history and focus remain sensible. The model chooses.",
      "evidence": "Submit/continue controls visibly remain disabled until requirements are met; the management view provides an explicit Cancel action and visible field guidance.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse reports LCP/CLS/TBT directly and the model may run it; layout metrics + a layout-shift observer + a long-task observer (the evidence primitives) give the same signal first-party. The model chooses.",
      "evidence": "Lighthouse measured LCP 10.5s, FCP 6.8s, Speed Index 7.8s and performance 0.52; the independent trace measured LCP 3.06s.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/performance-trace-summary.json",
        "evidence/performance-trace.json"
      ],
      "findingIds": [
        "F06"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "pass",
      "confidence": "high",
      "method": "the layout primitive's CLS observer captures shifts; a transition video of the first seconds shows content jumping. The model chooses.",
      "evidence": "Mobile layout and Lighthouse both measured CLS 0 with no observed layout shifts.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/performance-trace-summary.json",
        "evidence/layout-mobile.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "issues",
      "confidence": "high",
      "method": "the layout primitive records long tasks; a heap summary shows the object population; Lighthouse reports TBT. The model chooses.",
      "evidence": "Lighthouse measured 258ms TBT; the trace also recorded a 51.27ms long task.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/performance-trace-summary.json"
      ],
      "findingIds": [
        "F07"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "issues",
      "confidence": "high",
      "method": "a HAR summary can reveal cache headers, redirects, render-blocking candidates, weight offenders and dependency shape; a trace/Lighthouse insight report can corroborate LCP discovery, render-blocking, font-display and doc",
      "evidence": "HAR identified seven parser-inserted classic scripts without async/defer plus render-blocking CSS; trace FCP was 3.06s and Lighthouse FCP 6.8s.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/dom.json",
        "evidence/performance-trace-summary.json"
      ],
      "findingIds": [
        "F08"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse/trace/code-coverage style evidence can flag unused JS/CSS, duplicated JavaScript and legacy code; a HAR summary shows third-party byte cost and request count. The model chooses.",
      "evidence": "Lighthouse estimated 613KiB unused JavaScript: 446,638 bytes in main (72%); it also found 24KiB unused CSS (98%).",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F09"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "issues",
      "confidence": "high",
      "method": "axe-core (injectable via the evaluate primitive) or Lighthouse's a11y audits enumerate these; a DOM probe of the accessibility-relevant attributes is a first-party alternative. The model chooses.",
      "evidence": "The images primitive and Lighthouse both found /assets/login/logo.png without alt; Lighthouse accessibility was 0.81.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-summary.json"
      ],
      "findingIds": [
        "F10"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "axe contrast rules, a Lighthouse contrast audit, or an in-page probe computing contrast ratios from computed colours. The model chooses.",
      "evidence": "Lighthouse/axe color-contrast audit passed, and screenshots show readable text against white/light-gray surfaces.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "issues",
      "confidence": "high",
      "method": "axe/Lighthouse structural audits; a focus-walk probe (tab through, read activeElement + computed outline) is a first-party alternative. The model chooses.",
      "evidence": "The DOM/evaluate probes found zero h1-h6 elements; the input’s focused outline and box-shadow were both none.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/gestion-desktop.png"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "pass",
      "confidence": "high",
      "method": "a screenshot of body and heading text, plus CSS inspection for text-wrap / text alignment / font fallback handling. The model chooses.",
      "evidence": "Desktop and mobile screenshots show unclipped Spanish labels and error text with comfortable line lengths and no horizontal overflow.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse/axe target-size, meta-viewport and media-caption audits are useful signals; screenshots at narrow and zoomed conditions plus DOM/media inspection can corroborate. The model chooses.",
      "evidence": "At 360px the layout reflowed without overflow, but the two links measured only 15px high, well below a comfortable touch target.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/mobile.png"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "issues",
      "confidence": "high",
      "method": "capture Runtime/Log CDP events, or a probe that reads collected errors; Lighthouse reports this too. The model chooses.",
      "evidence": "Lighthouse recorded a CORS error and ERR_FAILED for https://bdv81mjs.staticmon.com/tun/bdv81mjs/input/.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "issues",
      "confidence": "high",
      "method": "a DOM/source probe for doctype/charset/img dimensions; CSS inspection for repetition; Lighthouse best-practices audits cover the rest. The model chooses.",
      "evidence": "The image is 1832px wide but displays at about 307px, has no width/height attributes, no srcset, and uses PNG.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-summary.json"
      ],
      "findingIds": [
        "F14"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "pass",
      "confidence": "high",
      "method": "Lighthouse best-practices audits and DevTools inspector/deprecation signals can surface these; DOM/source probes can verify paste handlers and prompt timing. The model chooses.",
      "evidence": "Lighthouse found no deprecated API, geolocation-on-load or notification-on-load failure; no paste-prevention handler was observed.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "issues",
      "confidence": "high",
      "method": "a DOM probe reads <title> and meta[name=description]; Lighthouse SEO audits cover the same ground. The model chooses.",
      "evidence": "DOM and Lighthouse found a title but no meta[name=description].",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/lighthouse-summary.json"
      ],
      "findingIds": [
        "F15"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "issues",
      "confidence": "high",
      "method": "a DOM probe for anchor hrefs, viewport meta, and robots; Lighthouse SEO audits corroborate. The model chooses.",
      "evidence": "The explicit /robots.txt fetch returned HTTP 404 with the app shell body. Links and viewport metadata otherwise passed.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ],
      "findingIds": [
        "F16"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "issues",
      "confidence": "high",
      "method": "inspect response status and headers, <link rel=canonical>, hreflang links, robots meta, robots.txt and sitemap.xml; Lighthouse SEO audits cover several of these. The model chooses.",
      "evidence": "/sitemap.xml returned 404, no canonical or hreflang was present, and direct /gestion-usuario returned HTTP 404.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/gestion-discoverability"
      ],
      "findingIds": [
        "F17"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "issues",
      "confidence": "high",
      "method": "inspect JSON-LD/microdata and social preview tags against visible content; Lighthouse has a manual structured-data audit, and ad-hoc probes can parse schema.org blocks. The model chooses.",
      "evidence": "The probe found no Open Graph tags and no JSON-LD despite visible BDVenlínea product branding.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/desktop.png"
      ],
      "findingIds": [
        "F18"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "issues",
      "confidence": "high",
      "method": "inspect response headers / page protocol via an evaluate probe or the network layer; Lighthouse best-practices flags HTTPS and CSP issues. The model chooses.",
      "evidence": "HTTPS is used, but headers found no CSP, HSTS or nosniff; cookies found five cookies without Secure and every observed cookie had SameSite=None.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/headers.json",
        "evidence/cookies.json"
      ],
      "findingIds": [
        "F19"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "issues",
      "confidence": "high",
      "method": "inspect network requests and third-party origins; a probe of analytics/beacon calls. The model chooses.",
      "evidence": "Trackers found 10 third-party origins and three known trackers; HAR recorded 16 third-party requests and 352,659 transferred bytes, including DoubleClick and Google audiences.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/trackers.json",
        "evidence/network-summary.json",
        "evidence/comprehensive-probe.json"
      ],
      "findingIds": [
        "F20"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "issues",
      "confidence": "high",
      "method": "a probe for permission requests fired on load; source inspection for passkey / WebAuthn / navigator.credentials usage in auth flows. The model chooses.",
      "evidence": "Lighthouse confirmed no permission prompts on load, but the login exposes only a username-first flow and the probe found no WebAuthn/credential capability use.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/mobile.png",
        "evidence/comprehensive-probe.json"
      ],
      "findingIds": [
        "F21"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "inspect response headers and browser security state; Lighthouse/DevTools security audits can corroborate HSTS, clickjacking, Trusted Types, origin isolation and third-party cookie findings. The model chooses.",
      "evidence": "Headers found no HSTS, clickjacking protection, Referrer-Policy, Permissions-Policy, or CSP frame-ancestors.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F22"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "issues",
      "confidence": "high",
      "method": "load with scripting disabled or compare a no-JS fetch of the HTML against the rendered page; check for Baseline-aware fallbacks in source. The model chooses.",
      "evidence": "Discoverability measured 0% raw-to-rendered content coverage; crawler screenshots show a blank page while the browser screenshots contain both forms.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/discoverability-rendered.png",
        "evidence/discoverability-crawler.png",
        "evidence/gestion-discoverability-rendered.png",
        "evidence/gestion-discoverability-crawler.png"
      ],
      "findingIds": [
        "F23"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "pass",
      "confidence": "high",
      "method": "exercise menus near viewport edges with a screenshot; a probe of async/visibility behaviour. The model chooses.",
      "evidence": "The observed cards and controls stay within both desktop and mobile viewports; no cut-off overlay or fragile async control was present.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/service-worker.json",
        "evidence/discoverability"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "issues",
      "confidence": "medium",
      "method": "a probe for a service worker registration and a web app manifest; test behaviour offline. The model chooses.",
      "evidence": "A valid manifest and active ngsw-worker exist, but CacheStorage showed the application-shell cache empty; only three favicon/isologo assets were cached.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/service-worker.json",
        "evidence/comprehensive-probe.json"
      ],
      "findingIds": [
        "F24"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "issues",
      "confidence": "high",
      "method": "simulate failed fetches/offline mode or inspect representative 404/500 routes; screenshots and DOM snapshots of error/loading/empty states show whether recovery is possible. The model chooses.",
      "evidence": "A direct fetch of /gestion-usuario returned 404 while JavaScript rendered the management form; no route error or recovery explanation was shown.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/gestion-discoverability",
        "evidence/gestion-desktop.png"
      ],
      "findingIds": [
        "F25"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "not-applicable",
      "confidence": "high",
      "method": "a DOM probe for <html lang>/dir and CSS inspection for logical vs physical properties. The model chooses.",
      "evidence": "The audited public service is deliberately Spanish/Venezuelan and exposes no alternate-language or bidirectional surface; internationalised layout was not an applicable product intent.",
      "reason": "The audited public service is deliberately Spanish/Venezuelan and exposes no alternate-language or bidirectional surface; internationalised layout was not an applicable product intent."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "not-applicable",
      "confidence": "high",
      "method": "source inspection for Intl.* usage vs hand-rolled formatting; a probe of rendered dates/numbers under a different locale. The model chooses.",
      "evidence": "No dates, numbers, currencies, durations, or calendar data are shown or entered on the audited unauthenticated routes.",
      "reason": "No dates, numbers, currencies, durations, or calendar data are shown or entered on the audited unauthenticated routes."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "source inspection for time-zone-aware date handling vs naive local Date math. The model chooses.",
      "evidence": "No time, event, recurrence, or time-zone concept exists on the audited unauthenticated routes.",
      "reason": "No time, event, recurrence, or time-zone concept exists on the audited unauthenticated routes."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "pass",
      "confidence": "high",
      "method": "a screenshot of consent/upsell/cancel flows; source inspection for declarative button actions vs misleading controls. The model chooses.",
      "evidence": "The exercised public states show no confirmshaming, forced continuity, disguised advertising, preselected consent, or blocked cancellation.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "issues",
      "confidence": "high",
      "method": "exercise a form, submit invalid input, and observe timing and clarity of errors via a screenshot or a :user-invalid / aria-invalid probe. The model chooses.",
      "evidence": "The first screenshot of /gestion-usuario already displays “Complete la cédula, sin caracteres especiales” while the field is untouched and empty.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/gestion-desktop.png",
        "evidence/gestion-mobile.png"
      ],
      "findingIds": [
        "F26"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "issues",
      "confidence": "high",
      "method": "source/DOM inspection for autocomplete attributes on form fields; a probe of autofill affordances. The model chooses.",
      "evidence": "The DOM probe reported autocomplete=\"off\" on the username input.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/dom.json"
      ],
      "findingIds": [
        "F27"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "issues",
      "confidence": "high",
      "method": "walkthrough checkout/subscription/auth/account flows when present; screenshot pricing, confirmation, cancellation and reauthentication states; inspect passkey/autocomplete support for sign-in and payment. The model choos",
      "evidence": "The public UI exposes username-first authentication only; both “forgot” and “new client” links use /gestion-usuario, and no passkey capability was detected.",
      "pathIds": [
        "login",
        "user-management"
      ],
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/gestion-desktop.png"
      ],
      "findingIds": [
        "F28"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "issues",
      "confidence": "high",
      "method": "inspect transferred image bytes vs displayed size; source inspection for modern formats and resolution handling. The model chooses.",
      "evidence": "The logo’s natural width is 1832px versus a 307px display width, with PNG, no srcset and no intrinsic dimensions.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/images.json"
      ],
      "findingIds": [
        "F29"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "issues",
      "confidence": "high",
      "method": "a long-task / network probe for background fetches and processing while idle or backgrounded. The model chooses.",
      "evidence": "HAR transferred 1.18MB across 37 requests; Lighthouse estimated 613KiB unused JS, while analytics/monitoring requests fire before any user action.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/lighthouse-summary.json"
      ],
      "findingIds": [
        "F30"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "issues",
      "confidence": "high",
      "method": "a HAR summary shows third-party bytes, font/media weight and caching; screenshots/video reveal autoplay and decorative media; trace/layout evidence shows whether media/animation keeps work running. The model chooses.",
      "evidence": "Sixteen third-party requests transferred 352,659 bytes; GTM/gtag alone transferred about 285KiB and known trackers included Analytics and DoubleClick.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/trackers.json"
      ],
      "findingIds": [
        "F31"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "source inspection for WebMCP / agentic-tool registration and agent-readable affordances. The model chooses.",
      "evidence": "This sensitive consumer-banking login exposes no declared agent-facing product surface; scraping or transaction tools would be inappropriate without explicit intent and safeguards.",
      "reason": "This sensitive consumer-banking login exposes no declared agent-facing product surface; scraping or transaction tools would be inappropriate without explicit intent and safeguards."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "source inspection for built-in AI (language model / summariser) usage. The model chooses.",
      "evidence": "The login and account-recovery forms have no summarisation, generation, or other inference task where on-device AI would improve the experience.",
      "reason": "The login and account-recovery forms have no summarisation, generation, or other inference task where on-device AI would improve the experience."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "pass",
      "confidence": "medium",
      "method": "compare heap snapshots for retained growth - a baseline, then one taken after repeating the interaction with `--interact` about 10x (the memory-tracer methodology: baseline -> repeat -> post -> compare). Performance.getM",
      "evidence": "A same-session probe repeated input/change interaction 10 times: DOM nodes stayed at 104 and JS heap rose only about 224KB (16.03MB to 16.25MB), with no continued growth observed.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot",
        "evidence/memory-metrics.json"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "pass",
      "confidence": "medium",
      "method": "a single `heap` summary's totals (nodeCount, totalSelfSizeBytes, constructor population) plus Performance.getMetrics (Nodes, JSHeapUsedSize) give the current footprint to judge against the page's purpose. Chrome DevTools",
      "evidence": "The loaded form used about 17.55MB V8 self-size in the heap summary and 104 live DOM elements, proportionate to this small Angular view.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot",
        "evidence/memory-metrics.json"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "medium",
      "method": "the `heap` summary by constructor (Detached* nodes) compared across a before/after pair shows a growing detached-DOM population; an `evaluate` probe can sample listener/timer counts (e.g. getEventListeners-style counting",
      "evidence": "The heap summary’s largest constructors contained no Detached* population, and the repeated interaction kept DOM nodes fixed at 104.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot",
        "evidence/memory-metrics.json"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "pass",
      "findingIds": []
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "pass",
      "findingIds": []
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F03",
        "F04"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F06",
        "F07",
        "F08",
        "F09"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F10",
        "F11",
        "F12"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F13",
        "F14"
      ]
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F15",
        "F16",
        "F17",
        "F18"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F19",
        "F20",
        "F21",
        "F22"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F23",
        "F24",
        "F25"
      ]
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "not-applicable",
      "findingIds": [],
      "reason": "This contextual principle does not apply to the audited Spanish-only, unauthenticated banking form surfaces under the check-specific rationales."
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F26",
        "F27",
        "F28"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F29",
        "F30",
        "F31"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "findingIds": [],
      "reason": "This contextual principle does not apply to the audited Spanish-only, unauthenticated banking form surfaces under the check-specific rationales."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "pass",
      "findingIds": []
    }
  ],
  "paths": [
    {
      "id": "login",
      "description": "Public login entry and primary unauthenticated banking task; represents the only entry template.",
      "url": "https://bdvenlinea.banvenez.com/",
      "conditions": [
        "desktop 1440x900",
        "mobile 360x800",
        "prefers-color-scheme: dark",
        "prefers-contrast: more",
        "prefers-reduced-motion: reduce",
        "keyboard focus",
        "JavaScript disabled crawler view"
      ],
      "result": "issues"
    },
    {
      "id": "user-management",
      "description": "Account recovery/new-user route linked from login; represents the secondary form flow.",
      "url": "https://bdvenlinea.banvenez.com/gestion-usuario",
      "conditions": [
        "desktop 1440x900",
        "mobile 360x800",
        "direct navigation",
        "JavaScript disabled crawler view"
      ],
      "result": "issues"
    }
  ],
  "findings": [
    {
      "id": "F01",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "The interface ignores the user’s dark color-scheme preference.",
      "evidence": "The light and dark screenshots are byte-identical (501,542 bytes), the computed color-scheme is normal, and the CSS probe found no prefers-color-scheme rule.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dark.png",
        "evidence/comprehensive-probe.json"
      ],
      "suggestedFix": "Declare color-scheme and provide preference-driven dark surface, text, control, and browser-chrome colors.",
      "effort": "small"
    },
    {
      "id": "F02",
      "pathId": "user-management",
      "url": "https://bdvenlinea.banvenez.com/gestion-usuario",
      "principleId": "implement-natural-interactions",
      "principleCheckId": "view-transitions",
      "guidanceId": "same-document-transitions",
      "guidanceCategory": "user-experience",
      "severity": "low",
      "confidence": "high",
      "summary": "Route changes do not use View Transitions.",
      "evidence": "The CSS probe found no view-transition usage; the Angular recovery route replaces state without a declared transition.",
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/gestion-desktop.png"
      ],
      "suggestedFix": "Add a reduced-motion-safe same-document View Transition around route/state changes.",
      "effort": "medium"
    },
    {
      "id": "F03",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "component-level-responsiveness",
      "guidanceId": "size-aware-styling",
      "guidanceCategory": "user-experience",
      "severity": "low",
      "confidence": "high",
      "summary": "The cards adapt only through viewport breakpoints, not their containing context.",
      "evidence": "Rendered CSS contains multiple @media width rules but the probe found no @container/container-type usage.",
      "artifacts": [
        "evidence/dom.json",
        "evidence/comprehensive-probe.json"
      ],
      "suggestedFix": "Give reusable form-card containers container-type and move component-specific layout changes into @container rules with a fallback where needed.",
      "effort": "medium"
    },
    {
      "id": "F04",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "input-modality-aware",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "medium",
      "confidence": "high",
      "summary": "Small link targets and absent input outline weaken touch and keyboard use.",
      "evidence": "The probe measured recovery links at only 15px high and the focused input itself had outline:none and no box-shadow.",
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/mobile.png"
      ],
      "suggestedFix": "Provide at least 44px effective touch targets and an unmistakable :focus-visible treatment on the whole input field.",
      "effort": "small"
    },
    {
      "id": "F05",
      "pathId": "user-management",
      "url": "https://bdvenlinea.banvenez.com/gestion-usuario",
      "principleId": "support-core-task-success",
      "principleCheckId": "primary-flow-completion",
      "guidanceId": "forms",
      "guidanceCategory": "forms",
      "severity": "high",
      "confidence": "high",
      "summary": "The recovery/new-user route is served with an HTTP 404 and cannot be represented reliably as a successful navigation.",
      "evidence": "The direct /gestion-usuario discoverability fetch returned 404 even though Angular later painted a form; both public recovery and registration links depend on this route.",
      "artifacts": [
        "evidence/gestion-discoverability",
        "evidence/gestion-desktop.png"
      ],
      "suggestedFix": "Serve every application route with a successful document response and preserve a clear, distinct recovery/registration journey.",
      "effort": "medium"
    },
    {
      "id": "F06",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "good-core-web-vitals",
      "guidanceId": "performance",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "The login is materially slow on a mobile Lighthouse profile.",
      "evidence": "Lighthouse measured LCP 10.5s, FCP 6.8s, Speed Index 7.8s and performance 0.52; the independent trace measured LCP 3.06s.",
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/performance-trace-summary.json",
        "evidence/performance-trace.json"
      ],
      "suggestedFix": "Prioritize the first useful login UI, reduce startup JavaScript, and verify LCP under representative mobile conditions.",
      "effort": "large"
    },
    {
      "id": "F07",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-main-thread",
      "guidanceId": "break-up-long-tasks",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Startup scripting exceeds the good responsiveness budget.",
      "evidence": "Lighthouse measured 258ms TBT; the trace also recorded a 51.27ms long task.",
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/performance-trace-summary.json"
      ],
      "suggestedFix": "Defer nonessential startup work and split remaining long tasks into yieldable units.",
      "effort": "medium"
    },
    {
      "id": "F08",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-resource-delivery",
      "guidanceId": "optimize-script-priority",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "Parser-blocking scripts and a slow dependency chain delay the login UI.",
      "evidence": "HAR identified seven parser-inserted classic scripts without async/defer plus render-blocking CSS; trace FCP was 3.06s and Lighthouse FCP 6.8s.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/dom.json",
        "evidence/performance-trace-summary.json"
      ],
      "suggestedFix": "Defer application scripts, remove body parser blockers, preload only the true critical resources, and self-host/optimize the critical font path.",
      "effort": "large"
    },
    {
      "id": "F09",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "identify-heavy-scripts",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "The page ships a large amount of unused JavaScript and CSS.",
      "evidence": "Lighthouse estimated 613KiB unused JavaScript: 446,638 bytes in main (72%); it also found 24KiB unused CSS (98%).",
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Route-split the old Angular bundle, remove unused chunks/polyfills, and load analytics and secondary code only when needed.",
      "effort": "large"
    },
    {
      "id": "F10",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-inclusive",
      "principleCheckId": "names-roles-labels",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "medium",
      "confidence": "high",
      "summary": "The visible brand logo has no text alternative.",
      "evidence": "The images primitive and Lighthouse both found /assets/login/logo.png without alt; Lighthouse accessibility was 0.81.",
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-summary.json"
      ],
      "suggestedFix": "Add concise alt text if the logo conveys the product name, or alt=\"\" if an equivalent adjacent accessible name is guaranteed.",
      "effort": "trivial"
    },
    {
      "id": "F11",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "medium",
      "confidence": "high",
      "summary": "The public views have no heading hierarchy and weak focus treatment.",
      "evidence": "The DOM/evaluate probes found zero h1-h6 elements; the input’s focused outline and box-shadow were both none.",
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/gestion-desktop.png"
      ],
      "suggestedFix": "Use a real main landmark and descriptive h1 on each route, then provide visible :focus-visible styling that follows reading order.",
      "effort": "small"
    },
    {
      "id": "F12",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-inclusive",
      "principleCheckId": "zoom-reflow-targets-and-media",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "medium",
      "confidence": "high",
      "summary": "Recovery and registration links have undersized touch targets.",
      "evidence": "At 360px the layout reflowed without overflow, but the two links measured only 15px high, well below a comfortable touch target.",
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/mobile.png"
      ],
      "suggestedFix": "Increase link hit areas to at least 44 CSS px while retaining the successful mobile reflow.",
      "effort": "small"
    },
    {
      "id": "F13",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "follow-best-practices",
      "principleCheckId": "no-console-errors",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "A third-party monitoring request produces console and network errors.",
      "evidence": "Lighthouse recorded a CORS error and ERR_FAILED for https://bdv81mjs.staticmon.com/tun/bdv81mjs/input/.",
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Fix the monitoring endpoint’s CORS contract or remove/contain the failing integration so login loads without console errors.",
      "effort": "small"
    },
    {
      "id": "F14",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "follow-best-practices",
      "principleCheckId": "sound-document-and-assets",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "The logo asset lacks intrinsic dimensions and is much larger than displayed.",
      "evidence": "The image is 1832px wide but displays at about 307px, has no width/height attributes, no srcset, and uses PNG.",
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-summary.json"
      ],
      "suggestedFix": "Export a right-sized modern image, add width and height, and provide responsive sources when multiple display densities are required.",
      "effort": "small"
    },
    {
      "id": "F15",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-discoverable",
      "principleCheckId": "title-and-description",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "The page has no meta description.",
      "evidence": "DOM and Lighthouse found a title but no meta[name=description].",
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/lighthouse-summary.json"
      ],
      "suggestedFix": "Add a concise, unique Spanish description for the login/account service.",
      "effort": "trivial"
    },
    {
      "id": "F16",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-discoverable",
      "principleCheckId": "crawlable-and-mobile-friendly",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "The site has no valid robots.txt.",
      "evidence": "The explicit /robots.txt fetch returned HTTP 404 with the app shell body. Links and viewport metadata otherwise passed.",
      "artifacts": [
        "evidence/comprehensive-probe.json"
      ],
      "suggestedFix": "Serve a valid text/plain robots.txt and make its policy explicit.",
      "effort": "trivial"
    },
    {
      "id": "F17",
      "pathId": "user-management",
      "url": "https://bdvenlinea.banvenez.com/gestion-usuario",
      "principleId": "be-discoverable",
      "principleCheckId": "canonical-and-indexing-signals",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "high",
      "confidence": "high",
      "summary": "Indexing signals conflict with application routing.",
      "evidence": "/sitemap.xml returned 404, no canonical or hreflang was present, and direct /gestion-usuario returned HTTP 404.",
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/gestion-discoverability"
      ],
      "suggestedFix": "Return correct 2xx statuses for public routes, add canonical URLs, and provide a sitemap consistent with robots policy.",
      "effort": "medium"
    },
    {
      "id": "F18",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-discoverable",
      "principleCheckId": "structured-and-shareable-metadata",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "low",
      "confidence": "high",
      "summary": "The branded public service has no social-preview or structured entity metadata.",
      "evidence": "The probe found no Open Graph tags and no JSON-LD despite visible BDVenlínea product branding.",
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/desktop.png"
      ],
      "suggestedFix": "Add accurate Open Graph metadata and minimal Organization/WebApplication JSON-LD matching visible content.",
      "effort": "small"
    },
    {
      "id": "F19",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "severity": "critical",
      "confidence": "high",
      "summary": "A banking login omits core security headers and sets insecure cookies.",
      "evidence": "HTTPS is used, but headers found no CSP, HSTS or nosniff; cookies found five cookies without Secure and every observed cookie had SameSite=None.",
      "artifacts": [
        "evidence/headers.json",
        "evidence/cookies.json"
      ],
      "suggestedFix": "Set a restrictive CSP, HSTS and nosniff; mark all HTTPS cookies Secure and use Lax/Strict unless cross-site behavior is strictly required.",
      "effort": "medium"
    },
    {
      "id": "F20",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-private-and-secure",
      "principleCheckId": "data-minimisation-and-third-parties",
      "guidanceId": "privacy",
      "guidanceCategory": "privacy",
      "severity": "high",
      "confidence": "high",
      "summary": "The login sends data to a broad tracking and monitoring footprint before authentication.",
      "evidence": "Trackers found 10 third-party origins and three known trackers; HAR recorded 16 third-party requests and 352,659 transferred bytes, including DoubleClick and Google audiences.",
      "artifacts": [
        "evidence/trackers.json",
        "evidence/network-summary.json",
        "evidence/comprehensive-probe.json"
      ],
      "suggestedFix": "Remove nonessential advertising/tracking from the banking login, minimize events, and load strictly necessary analytics only under a documented privacy basis.",
      "effort": "large"
    },
    {
      "id": "F21",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-private-and-secure",
      "principleCheckId": "in-context-permissions-and-modern-auth",
      "guidanceId": "passkeys",
      "guidanceCategory": "passkeys",
      "severity": "high",
      "confidence": "high",
      "summary": "The authentication entry shows no phishing-resistant sign-in option.",
      "evidence": "Lighthouse confirmed no permission prompts on load, but the login exposes only a username-first flow and the probe found no WebAuthn/credential capability use.",
      "artifacts": [
        "evidence/mobile.png",
        "evidence/comprehensive-probe.json"
      ],
      "suggestedFix": "Offer passkey/WebAuthn authentication and retain a well-protected recovery fallback.",
      "effort": "large"
    },
    {
      "id": "F22",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "severity": "critical",
      "confidence": "high",
      "summary": "Browser-enforced defenses are absent on a high-risk authentication origin.",
      "evidence": "Headers found no HSTS, clickjacking protection, Referrer-Policy, Permissions-Policy, or CSP frame-ancestors.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "suggestedFix": "Deploy HSTS, CSP frame-ancestors, a strict Referrer-Policy, a minimal Permissions-Policy, and Trusted Types where the Angular app can support it.",
      "effort": "medium"
    },
    {
      "id": "F23",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-resilient",
      "principleCheckId": "progressive-enhancement",
      "guidanceId": "stabilize-reactive-state",
      "guidanceCategory": "user-experience",
      "severity": "high",
      "confidence": "high",
      "summary": "Core login and recovery content disappear without JavaScript.",
      "evidence": "Discoverability measured 0% raw-to-rendered content coverage; crawler screenshots show a blank page while the browser screenshots contain both forms.",
      "artifacts": [
        "evidence/discoverability-rendered.png",
        "evidence/discoverability-crawler.png",
        "evidence/gestion-discoverability-rendered.png",
        "evidence/gestion-discoverability-crawler.png"
      ],
      "suggestedFix": "Server-render the essential form purpose, labels and recovery links, then hydrate/enhance behavior client-side.",
      "effort": "large"
    },
    {
      "id": "F24",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-resilient",
      "principleCheckId": "offline-and-installable",
      "guidanceId": "conditional-async-dependencies",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "The installable shell does not show evidence of a cached offline application fallback.",
      "evidence": "A valid manifest and active ngsw-worker exist, but CacheStorage showed the application-shell cache empty; only three favicon/isologo assets were cached.",
      "artifacts": [
        "evidence/service-worker.json",
        "evidence/comprehensive-probe.json"
      ],
      "suggestedFix": "Configure the service worker to cache a safe unauthenticated shell and explicit offline/retry view without caching sensitive account data.",
      "effort": "medium"
    },
    {
      "id": "F25",
      "pathId": "user-management",
      "url": "https://bdvenlinea.banvenez.com/gestion-usuario",
      "principleId": "be-resilient",
      "principleCheckId": "network-and-http-failure-states",
      "guidanceId": "persistent-toast-notifications",
      "guidanceCategory": "user-experience",
      "severity": "high",
      "confidence": "high",
      "summary": "HTTP route failure is masked by a rendered form rather than handled intentionally.",
      "evidence": "A direct fetch of /gestion-usuario returned 404 while JavaScript rendered the management form; no route error or recovery explanation was shown.",
      "artifacts": [
        "evidence/gestion-discoverability",
        "evidence/gestion-desktop.png"
      ],
      "suggestedFix": "Fix route status handling and present explicit retry/back recovery for genuine HTTP/network failures.",
      "effort": "medium"
    },
    {
      "id": "F26",
      "pathId": "user-management",
      "url": "https://bdvenlinea.banvenez.com/gestion-usuario",
      "principleId": "be-trustworthy",
      "principleCheckId": "humane-error-handling",
      "guidanceId": "validate-input-after-interaction",
      "guidanceCategory": "forms",
      "severity": "medium",
      "confidence": "high",
      "summary": "The management form shows an error before the user interacts.",
      "evidence": "The first screenshot of /gestion-usuario already displays “Complete la cédula, sin caracteres especiales” while the field is untouched and empty.",
      "artifacts": [
        "evidence/gestion-desktop.png",
        "evidence/gestion-mobile.png"
      ],
      "suggestedFix": "Delay validation until blur or submit and announce the resulting error accessibly.",
      "effort": "small"
    },
    {
      "id": "F27",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-trustworthy",
      "principleCheckId": "trustworthy-input-assistance",
      "guidanceId": "autofill-sign-in-form",
      "guidanceCategory": "forms",
      "severity": "medium",
      "confidence": "high",
      "summary": "The username field explicitly disables autofill.",
      "evidence": "The DOM probe reported autocomplete=\"off\" on the username input.",
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/dom.json"
      ],
      "suggestedFix": "Use the correct autocomplete=\"username\" token and appropriate current-password/webauthn tokens in subsequent authentication steps.",
      "effort": "trivial"
    },
    {
      "id": "F28",
      "pathId": "user-management",
      "url": "https://bdvenlinea.banvenez.com/gestion-usuario",
      "principleId": "be-trustworthy",
      "principleCheckId": "safe-commercial-and-account-flows",
      "guidanceId": "passkey-management",
      "guidanceCategory": "passkeys",
      "severity": "high",
      "confidence": "high",
      "summary": "Account entry/recovery lacks modern reauthentication and clear differentiated entry points.",
      "evidence": "The public UI exposes username-first authentication only; both “forgot” and “new client” links use /gestion-usuario, and no passkey capability was detected.",
      "artifacts": [
        "evidence/comprehensive-probe.json",
        "evidence/gestion-desktop.png"
      ],
      "suggestedFix": "Separate and label recovery/registration outcomes, add phishing-resistant authentication and require proportionate reauthentication for sensitive changes.",
      "effort": "large"
    },
    {
      "id": "F29",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-sustainable",
      "principleCheckId": "optimised-assets",
      "guidanceId": "deliver-optimized-decorative-images",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "The login logo is oversized and not responsively encoded.",
      "evidence": "The logo’s natural width is 1832px versus a 307px display width, with PNG, no srcset and no intrinsic dimensions.",
      "artifacts": [
        "evidence/images.json"
      ],
      "suggestedFix": "Generate right-sized WebP/AVIF variants and responsive source selection while preserving the existing WebP background.",
      "effort": "small"
    },
    {
      "id": "F30",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-sustainable",
      "principleCheckId": "no-wasteful-work",
      "guidanceId": "efficient-background-processing",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "The tiny login performs disproportionate background and startup work.",
      "evidence": "HAR transferred 1.18MB across 37 requests; Lighthouse estimated 613KiB unused JS, while analytics/monitoring requests fire before any user action.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/lighthouse-summary.json"
      ],
      "suggestedFix": "Eliminate unused bundles and defer or batch nonessential analytics/monitoring until after consent and idle time.",
      "effort": "large"
    },
    {
      "id": "F31",
      "pathId": "login",
      "url": "https://bdvenlinea.banvenez.com/",
      "principleId": "be-sustainable",
      "principleCheckId": "third-party-and-media-budget",
      "guidanceId": "deprioritize-background-fetches",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "Third-party code consumes a large share of the login budget.",
      "evidence": "Sixteen third-party requests transferred 352,659 bytes; GTM/gtag alone transferred about 285KiB and known trackers included Analytics and DoubleClick.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/trackers.json"
      ],
      "suggestedFix": "Set a strict third-party budget, remove advertising endpoints, and defer any retained analytics.",
      "effort": "medium"
    }
  ],
  "taskList": [
    {
      "id": "T01",
      "title": "Harden authentication headers, cookies and browser policies",
      "priority": 1,
      "findingIds": [
        "F19",
        "F22"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T02",
      "title": "Remove unnecessary tracking and third-party login code",
      "priority": 2,
      "findingIds": [
        "F20",
        "F30",
        "F31"
      ],
      "guidanceId": "privacy",
      "status": "open"
    },
    {
      "id": "T03",
      "title": "Reduce startup bundles and unblock the critical rendering path",
      "priority": 3,
      "findingIds": [
        "F06",
        "F07",
        "F08",
        "F09"
      ],
      "guidanceId": "identify-heavy-scripts",
      "status": "open"
    },
    {
      "id": "T04",
      "title": "Return correct route statuses and resilient server-rendered form content",
      "priority": 4,
      "findingIds": [
        "F05",
        "F17",
        "F23",
        "F25"
      ],
      "guidanceId": "stabilize-reactive-state",
      "status": "open"
    },
    {
      "id": "T05",
      "title": "Add passkeys and clarify account recovery/registration",
      "priority": 5,
      "findingIds": [
        "F21",
        "F28"
      ],
      "guidanceId": "passkeys",
      "status": "open"
    },
    {
      "id": "T06",
      "title": "Fix headings, focus, target sizing and logo accessibility",
      "priority": 6,
      "findingIds": [
        "F04",
        "F10",
        "F11",
        "F12"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T07",
      "title": "Make validation and autofill humane",
      "priority": 7,
      "findingIds": [
        "F26",
        "F27"
      ],
      "guidanceId": "validate-input-after-interaction",
      "status": "open"
    },
    {
      "id": "T08",
      "title": "Optimize and size the logo asset",
      "priority": 8,
      "findingIds": [
        "F14",
        "F29"
      ],
      "guidanceId": "deliver-optimized-decorative-images",
      "status": "open"
    },
    {
      "id": "T09",
      "title": "Add public indexing and share metadata",
      "priority": 9,
      "findingIds": [
        "F15",
        "F16",
        "F18"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T10",
      "title": "Respect dark mode and modernize responsive/route transitions",
      "priority": 10,
      "findingIds": [
        "F01",
        "F02",
        "F03"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T11",
      "title": "Provide a safe cached offline shell",
      "priority": 11,
      "findingIds": [
        "F24"
      ],
      "guidanceId": "conditional-async-dependencies",
      "status": "open"
    },
    {
      "id": "T12",
      "title": "Repair the failing monitoring integration",
      "priority": 12,
      "findingIds": [
        "F13"
      ],
      "guidanceId": "html",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 2,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-27T21-26-10-983Z"
}
