{
  "url": "https://web.whatsapp.com",
  "auditedAt": "2026-07-28T12:03:30.529Z",
  "mode": "report",
  "status": "blocked",
  "statusDetail": "Public login/linking was audited, but 18 of 58 atomic checks require a linked WhatsApp account. The run is not coverage-complete and is not scored.",
  "page": {
    "appType": "spa",
    "framework": "Meta/React-style client application (framework not conclusively identified by primitive)",
    "notes": "Public QR/phone linking shell; authenticated chat application blocked by account linking."
  },
  "evidenceUsed": [
    "screenshot",
    "dom",
    "evaluate-probe",
    "layout-metrics",
    "trace",
    "har",
    "discoverability",
    "headers",
    "cookies",
    "trackers",
    "secrets",
    "images",
    "heap-summary",
    "lighthouse",
    "Modern Web Guidance"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "accessibility",
    "adapt-scrollbar-to-contrast-preferences",
    "same-document-transitions",
    "scrollytelling",
    "physics-based-easing",
    "shrinking-header-on-scroll",
    "position-aware-tooltips",
    "directional-navigation-transitions",
    "light-dismiss-a-dialog",
    "declarative-dialog-popover-control",
    "fluid-scaling",
    "size-aware-styling",
    "forms",
    "accessible-error-announcement",
    "identify-inp-causes",
    "visually-stable-font-fallbacks",
    "break-up-long-tasks",
    "optimize-image-priority",
    "identify-heavy-scripts",
    "improve-text-layout-and-legibility",
    "css",
    "html",
    "security",
    "privacy",
    "passkeys",
    "flicker-free-client-side-ab-testing",
    "persistent-toast-notifications",
    "translator",
    "support-global-calendar-systems",
    "coordinate-global-events",
    "deprioritize-background-fetches",
    "webmcp",
    "language-model",
    "manage-recurring-intervals"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "Desktop public login surface",
      "condition": "viewport: 1440x1000",
      "findingIds": [
        "F1",
        "F9"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "Clipped login surface at narrow viewport",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F2"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/dark.png",
      "caption": "Login surface under dark preference",
      "condition": "prefers-color-scheme: dark",
      "findingIds": [
        "F1"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/dom.json",
      "caption": "Rendered DOM and computed styles",
      "findingIds": [
        "F2",
        "F6"
      ]
    },
    {
      "type": "other",
      "path": "evidence/probe.json",
      "caption": "Metadata, semantics, styles and responsive-feature probe",
      "findingIds": [
        "F1",
        "F3",
        "F6",
        "F7",
        "F10"
      ]
    },
    {
      "type": "other",
      "path": "evidence/focus.json",
      "caption": "Keyboard focus and target-size probe",
      "condition": "keyboard-only",
      "findingIds": [
        "F3",
        "F6"
      ]
    },
    {
      "type": "layout",
      "path": "evidence/layout-mobile.json",
      "caption": "Narrow viewport layout, CLS and long tasks",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F2"
      ]
    },
    {
      "type": "trace-summary",
      "path": "evidence/load-trace-summary.json",
      "caption": "Load performance trace summary",
      "findingIds": [
        "F4",
        "F5"
      ]
    },
    {
      "type": "har-summary",
      "path": "evidence/network-summary.json",
      "caption": "Network transfer and dependency summary",
      "findingIds": [
        "F5",
        "F9"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Lighthouse performance, accessibility, best-practices and SEO run",
      "findingIds": [
        "F4",
        "F5",
        "F6",
        "F7"
      ]
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "Raw HTML versus rendered content comparison",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "Crawler/no-JS view",
      "condition": "JavaScript disabled",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "Rendered browser view",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Security response headers",
      "findingIds": [
        "F8"
      ]
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Cookie posture",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Third-party and tracker probe",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Client secret-pattern scan",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/secret-context.json",
      "caption": "Context proving certificate/API-key false positives",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Image audit",
      "findingIds": []
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.heapsnapshot",
      "caption": "Baseline heap summary",
      "findingIds": [
        "F10"
      ]
    },
    {
      "type": "other",
      "path": "evidence/reduced-motion.json",
      "caption": "Reduced-motion animation probe",
      "condition": "prefers-reduced-motion: reduce",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/robots-manifest.json",
      "caption": "robots.txt, manifest and service-worker probe",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/guidance-retrieved.md",
      "caption": "Retrieved Modern Web Guidance used to set the bar",
      "findingIds": []
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 40,
    "blocked": 18,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": false
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "Desktop screenshots captured with default media and prefers-color-scheme: dark are visually identical light surfaces, despite dark tokens existing elsewhere in the CSS.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dark.png",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F1"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "Reduced-motion emulation matched and getAnimations() returned no active animation; CSS includes explicit reduced-motion overrides.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/reduced-motion.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "CSS inspection found forced-colors and prefers-contrast rules for focus, highlights and loading effects.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Attempted to exercise the phone-login state change, but the authenticated application and representative route transitions require account linking.",
      "reason": "Attempted to exercise the phone-login state change, but the authenticated application and representative route transitions require account linking."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "The login surface has no meaningful scroll-linked experience; authenticated lists and chat scrolling require account linking and could not be inspected.",
      "reason": "The login surface has no meaningful scroll-linked experience; authenticated lists and chat scrolling require account linking and could not be inspected."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Representative chat gestures, drawers and message actions require account linking and could not be exercised.",
      "reason": "Representative chat gestures, drawers and message actions require account linking and could not be exercised."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Authenticated chat/list navigation and its scroll chrome require account linking.",
      "reason": "Authenticated chat/list navigation and its scroll chrome require account linking."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Authenticated menus, tooltips and popovers require account linking; no representative overlay exists on the login surface.",
      "reason": "Authenticated menus, tooltips and popovers require account linking; no representative overlay exists on the login surface."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Representative in-app navigation is behind account linking.",
      "reason": "Representative in-app navigation is behind account linking."
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "The initial desktop screenshot shows the linking task directly, with no popup, consent wall or obscuring interstitial.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/desktop.png"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "confidence": "high",
      "status": "not-applicable",
      "method": "Recon-based applicability judgement against the accessible login surface and product purpose.",
      "evidence": "Check judged out of scope for this condition.",
      "reason": "No overlay, dialog, disclosure, picker or transient rich control is present on the accessible login surface."
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "The desktop first viewport is a focused login card with only brand, task instructions, security reassurance and footer links.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/desktop.png"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "The 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json",
        "evidence/dom.json"
      ],
      "findingIds": [
        "F2"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "CSS inspection found multiple @container rules and logical inset/padding declarations for component adaptation.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "The focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/focus.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F3"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "The desktop screenshot clearly says “Scan to log in”, gives three numbered steps and offers phone-number login.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/desktop.png"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "End-to-end task completion requires scanning the QR code or authenticating a phone number with a real WhatsApp account.",
      "reason": "End-to-end task completion requires scanning the QR code or authenticating a phone number with a real WhatsApp account."
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Authenticated loading, error, offline and recovery states require a linked account and controlled failures.",
      "reason": "Authenticated loading, error, offline and recovery states require a linked account and controlled failures."
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "The trace measured FCP 2.99 s and LCP 5.96 s; Lighthouse measured FCP/LCP 8.1 s and a 0.58 performance score.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/load-trace-summary.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F4"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "The mobile layout observer measured CLS 0.00016 and Lighthouse measured CLS 0.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/layout-mobile.json",
        "evidence/lighthouse.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "HAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/lighthouse.json",
        "evidence/load-trace-summary.json"
      ],
      "findingIds": [
        "F5"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "HAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/lighthouse.json",
        "evidence/load-trace-summary.json"
      ],
      "findingIds": [
        "F5"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "HAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/lighthouse.json",
        "evidence/load-trace-summary.json"
      ],
      "findingIds": [
        "F5"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "Visible actions expose role=button with text-derived names, there are no img elements needing alt, and Lighthouse accessibility scored 100.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/images.json",
        "evidence/lighthouse.json"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "Lighthouse accessibility, including automated contrast checks, scored 100 on the public login surface.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/desktop.png"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "The focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high. DOM/evaluate probes found no h1-h3 elements and no anchors; all visible actions are div role=button. Combined with absent visible focus, this weakens structural navigation even though Lighthouse automated accessibility scored 100.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/focus.json",
        "evidence/probe.json",
        "evidence/dom.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F6",
        "F3"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "The 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json",
        "evidence/dom.json"
      ],
      "findingIds": [
        "F2"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "The 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible. The focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json",
        "evidence/dom.json",
        "evidence/focus.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F2",
        "F3"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "Lighthouse did not report a console-errors or runtime-exception failure for the captured load.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "Lighthouse reported one deprecated API warning, a BFCache blocker, a missing/late charset declaration and an unsized image audit failure.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F7"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "Lighthouse reported one deprecated API warning, a BFCache blocker, a missing/late charset declaration and an unsized image audit failure.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F7"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "DOM and raw-HTML probes found the title “WhatsApp” and a descriptive login meta description in both rendered and server HTML.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/discoverability.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "confidence": "high",
      "status": "not-applicable",
      "method": "Recon-based applicability judgement against the accessible login surface and product purpose.",
      "evidence": "Check judged out of scope for this condition.",
      "reason": "The robots policy deliberately allows only selected public utility routes and disallows the private application surface."
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "confidence": "high",
      "status": "not-applicable",
      "method": "Recon-based applicability judgement against the accessible login surface and product purpose.",
      "evidence": "Check judged out of scope for this condition.",
      "reason": "The private application intentionally blocks indexing; sitemap and hreflang are not required for the authenticated chat UI."
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "confidence": "high",
      "status": "not-applicable",
      "method": "Recon-based applicability judgement against the accessible login surface and product purpose.",
      "evidence": "Check judged out of scope for this condition.",
      "reason": "The login screen is not an article, product, event, organization profile or other rich public entity."
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "Headers/cookies probes confirmed HTTPS, preload HSTS, CSP, nosniff, Secure cookies and HttpOnly on wa_ul.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/headers.json",
        "evidence/cookies.json"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "The tracker probe found no known tracker domains and no third-party cookies. Secret-context inspection showed public Google API keys and certificate parsing/root-certificate literals, not a leaked private key.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/trackers.json",
        "evidence/cookies.json",
        "evidence/secrets.json",
        "evidence/secret-context.json"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Camera, microphone and authenticated credential behavior cannot be exercised before account linking; the public screen alone does not prove the full auth posture.",
      "reason": "Camera, microphone and authenticated credential behavior cannot be exercised before account linking; the public screen alone does not prove the full auth posture."
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "The headers primitive confirmed HTTPS, HSTS, nosniff, CSP frame-ancestors and Permissions-Policy, but no Referrer-Policy header. The CSP also permits unsafe-inline for styles.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F8"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "confidence": "high",
      "status": "not-applicable",
      "method": "Recon-based applicability judgement against the accessible login surface and product purpose.",
      "evidence": "Check judged out of scope for this condition.",
      "reason": "The core product is an end-to-end encrypted real-time messaging client and intrinsically requires JavaScript and an authenticated device link; no-JS operation is not a meaningful product mode."
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Authenticated menus, asynchronous message state and visibility behavior are behind account linking.",
      "reason": "Authenticated menus, asynchronous message state and visibility behavior are behind account linking."
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "The page exposes a valid standalone web app manifest and has an active service-worker registration.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/robots-manifest.json"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Representative message/network failure states require a linked account and could not be induced.",
      "reason": "Representative message/network failure states require a linked account and could not be induced."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "The document reports lang=en and dir=ltr; inspected CSS includes logical inset and padding properties.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "No locale-sensitive dates, numbers, durations or currencies appear before login; authenticated content is blocked.",
      "reason": "No locale-sensitive dates, numbers, durations or currencies appear before login; authenticated content is blocked."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "No time data appears before login; chat timestamps and scheduling behavior require account linking.",
      "reason": "No time data appears before login; chat timestamps and scheduling behavior require account linking."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "The accessible login surface presents QR and phone-number alternatives without consent nagging, upsells or confirmshaming.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/desktop.png"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "The phone/account forms and their validation states require progressing through an account-linked flow.",
      "reason": "The phone/account forms and their validation states require progressing through an account-linked flow."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "No input fields are present on the initial QR screen; sign-in inputs are behind the blocked account flow.",
      "reason": "No input fields are present on the initial QR screen; sign-in inputs are behind the blocked account flow."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Account management and reauthentication are behind account linking.",
      "reason": "Account management and reauthentication are behind account linking."
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "confidence": "high",
      "status": "pass",
      "method": "Direct browser evidence on the public login path.",
      "evidence": "The images primitive found no img elements or oversized/legacy image deliveries on the login surface; the QR and marks are vector/CSS-rendered.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/images.json",
        "evidence/desktop.png"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "The public linking screen transfers 6.38 MB, 98.5% from static.whatsapp.net, before an account is linked; 5.81 MB is script.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/desktop.png"
      ],
      "findingIds": [
        "F9"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "The public linking screen transfers 6.38 MB, 98.5% from static.whatsapp.net, before an account is linked; 5.81 MB is script.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/desktop.png"
      ],
      "findingIds": [
        "F9"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "confidence": "high",
      "status": "not-applicable",
      "method": "Recon-based applicability judgement against the accessible login surface and product purpose.",
      "evidence": "Check judged out of scope for this condition.",
      "reason": "No agent-facing surface is declared, and exposing private messaging operations to generic agents would require an explicit security and consent design."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "confidence": "high",
      "status": "not-applicable",
      "method": "Recon-based applicability judgement against the accessible login surface and product purpose.",
      "evidence": "Check judged out of scope for this condition.",
      "reason": "The unauthenticated linking task has no inference use case; authenticated message features were inaccessible."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "A representative long-lived chat interaction could not be repeated without a linked account; a synthetic login-page loop would not test the core SPA.",
      "reason": "A representative long-lived chat interaction could not be repeated without a linked account; a synthetic login-page loop would not test the core SPA."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "confidence": "high",
      "status": "issues",
      "method": "Direct screenshot, DOM/evaluate, and/or objective diagnostic evidence on the public login path.",
      "evidence": "A post-load heap summary reported 1,314,301 heap nodes and 74,935,444 bytes self size while the rendered DOM probe counted 323 elements.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F10"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "confidence": "medium",
      "status": "blocked",
      "method": "Attempted public-surface inspection and representative-flow planning; authenticated state required.",
      "evidence": "Only a single baseline heap was available; meaningful before/after listener, timer and detached-DOM comparison requires a representative authenticated interaction.",
      "reason": "Only a single baseline heap was available; meaningful before/after listener, timer and detached-DOM comparison requires a representative authenticated interaction."
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F1"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "incomplete",
      "reason": "At least one check is blocked by the account-linking wall."
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "incomplete",
      "reason": "At least one check is blocked by the account-linking wall."
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F2",
        "F3"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "incomplete",
      "reason": "At least one check is blocked by the account-linking wall."
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F4",
        "F5"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F6",
        "F3",
        "F2"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F7"
      ]
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F8"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "incomplete",
      "reason": "At least one check is blocked by the account-linking wall."
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "incomplete",
      "reason": "At least one check is blocked by the account-linking wall."
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "incomplete",
      "reason": "At least one check is blocked by the account-linking wall."
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F9"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "No agent-facing surface is declared, and exposing private messaging operations to generic agents would require an explicit security and consent design. The unauthenticated linking task has no inference use case; authenticated message features were inaccessible."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F10"
      ]
    }
  ],
  "paths": [
    {
      "id": "login",
      "description": "Public desktop QR-linking entry point; represents the unauthenticated shell.",
      "url": "https://web.whatsapp.com/",
      "conditions": [
        "viewport: 1440x1000",
        "prefers-color-scheme: dark",
        "prefers-reduced-motion: reduce"
      ],
      "result": "issues"
    },
    {
      "id": "login-mobile",
      "description": "Public linking entry at 360x800; represents narrow-screen reflow.",
      "url": "https://web.whatsapp.com/",
      "conditions": [
        "viewport: 360x800"
      ],
      "result": "issues"
    },
    {
      "id": "login-keyboard",
      "description": "Keyboard focus probe across all visible public actions.",
      "url": "https://web.whatsapp.com/",
      "conditions": [
        "keyboard-only"
      ],
      "result": "issues"
    },
    {
      "id": "authenticated-app",
      "description": "Chat list, conversation, composer, search, settings, media/calls and account management; not covered because a real linked account is required.",
      "url": "https://web.whatsapp.com/",
      "conditions": [
        "authenticated"
      ],
      "result": "skipped"
    }
  ],
  "findings": [
    {
      "id": "F1",
      "severity": "medium",
      "confidence": "high",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "guidanceCategory": "user-experience",
      "pathId": "login",
      "url": "https://web.whatsapp.com/",
      "summary": "The public login surface does not follow the system dark-theme preference.",
      "evidence": "Desktop screenshots captured with default media and prefers-color-scheme: dark are visually identical light surfaces, despite dark tokens existing elsewhere in the CSS.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dark.png",
        "evidence/probe.json"
      ],
      "suggestedFix": "Apply the existing dark token set to the unauthenticated login root and declare color-scheme so browser UI and all login surfaces follow the system preference.",
      "effort": "small"
    },
    {
      "id": "F2",
      "severity": "critical",
      "confidence": "high",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "responsive-no-horizontal-scroll",
      "guidanceId": "fluid-scaling",
      "guidanceCategory": "css",
      "pathId": "login-mobile",
      "url": "https://web.whatsapp.com/",
      "summary": "The login card is clipped and unusable at a 360 px viewport.",
      "evidence": "The 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible.",
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json",
        "evidence/dom.json"
      ],
      "suggestedFix": "Replace the fixed 780 px login composition with intrinsic, fluid sizing and a single-column narrow layout; do not hide overflow as a substitute for reflow.",
      "effort": "medium"
    },
    {
      "id": "F3",
      "severity": "high",
      "confidence": "high",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "input-modality-aware",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "pathId": "login-keyboard",
      "url": "https://web.whatsapp.com/",
      "summary": "Keyboard focus is not visibly indicated and several actions expose very small visual targets.",
      "evidence": "The focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high.",
      "artifacts": [
        "evidence/focus.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Use semantic anchors/buttons, provide a clear :focus-visible ring, and expand each action hit area to at least 24x24 CSS px, preferably 44x44 for touch.",
      "effort": "small"
    },
    {
      "id": "F4",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "good-core-web-vitals",
      "guidanceId": "performance",
      "guidanceCategory": "performance",
      "pathId": "login",
      "url": "https://web.whatsapp.com/",
      "summary": "The lightweight login screen paints slowly.",
      "evidence": "The trace measured FCP 2.99 s and LCP 5.96 s; Lighthouse measured FCP/LCP 8.1 s and a 0.58 performance score.",
      "artifacts": [
        "evidence/load-trace-summary.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Prioritise the login shell separately from the authenticated application and render its critical content before loading chat-only code.",
      "effort": "large"
    },
    {
      "id": "F5",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "identify-heavy-scripts",
      "guidanceCategory": "performance",
      "pathId": "login",
      "url": "https://web.whatsapp.com/",
      "summary": "The login route ships the authenticated application bundle before it is needed.",
      "evidence": "HAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/lighthouse.json",
        "evidence/load-trace-summary.json"
      ],
      "suggestedFix": "Create a minimal login entry bundle, code-split authenticated features behind successful linking, and defer non-critical scripts and styles.",
      "effort": "large"
    },
    {
      "id": "F6",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "pathId": "login-keyboard",
      "url": "https://web.whatsapp.com/",
      "summary": "The login document lacks semantic headings and uses generic div controls.",
      "evidence": "DOM/evaluate probes found no h1-h3 elements and no anchors; all visible actions are div role=button. Combined with absent visible focus, this weakens structural navigation even though Lighthouse automated accessibility scored 100.",
      "artifacts": [
        "evidence/dom.json",
        "evidence/probe.json",
        "evidence/focus.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Mark “Scan to log in” as the page h1 and use native a/button elements for actions, retaining accessible names and keyboard behavior.",
      "effort": "small"
    },
    {
      "id": "F7",
      "severity": "medium",
      "confidence": "high",
      "principleId": "follow-best-practices",
      "principleCheckId": "browser-platform-hygiene",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "pathId": "login",
      "url": "https://web.whatsapp.com/",
      "summary": "The page triggers platform-hygiene failures.",
      "evidence": "Lighthouse reported one deprecated API warning, a BFCache blocker, a missing/late charset declaration and an unsized image audit failure.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Remove the deprecated API and BFCache blocker, move a UTF-8 meta charset into the first 1024 bytes, and reserve dimensions for the flagged image.",
      "effort": "medium"
    },
    {
      "id": "F8",
      "severity": "low",
      "confidence": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "pathId": "login",
      "url": "https://web.whatsapp.com/",
      "summary": "A Referrer-Policy header is absent from a security-sensitive application.",
      "evidence": "The headers primitive confirmed HTTPS, HSTS, nosniff, CSP frame-ancestors and Permissions-Policy, but no Referrer-Policy header. The CSP also permits unsafe-inline for styles.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "suggestedFix": "Send an explicit strict-origin-when-cross-origin or stricter Referrer-Policy, and continue reducing CSP unsafe-inline where feasible.",
      "effort": "trivial"
    },
    {
      "id": "F9",
      "severity": "medium",
      "confidence": "medium",
      "principleId": "be-sustainable",
      "principleCheckId": "no-wasteful-work",
      "guidanceId": "deprioritize-background-fetches",
      "guidanceCategory": "performance",
      "pathId": "login",
      "url": "https://web.whatsapp.com/",
      "summary": "Resource use is disproportionate to the unauthenticated login task.",
      "evidence": "The public linking screen transfers 6.38 MB, 98.5% from static.whatsapp.net, before an account is linked; 5.81 MB is script.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/desktop.png"
      ],
      "suggestedFix": "Keep the unauthenticated shell within a route-specific budget and fetch authenticated features only after successful linking.",
      "effort": "large"
    },
    {
      "id": "F10",
      "severity": "high",
      "confidence": "medium",
      "principleId": "be-memory-efficient",
      "principleCheckId": "bounded-footprint",
      "guidanceId": "manage-recurring-intervals",
      "guidanceCategory": "performance",
      "pathId": "login",
      "url": "https://web.whatsapp.com/",
      "summary": "The initial login surface has a very large JavaScript heap footprint for its visible complexity.",
      "evidence": "A post-load heap summary reported 1,314,301 heap nodes and 74,935,444 bytes self size while the rendered DOM probe counted 323 elements.",
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot",
        "evidence/probe.json"
      ],
      "suggestedFix": "Profile the unauthenticated entry point, avoid instantiating authenticated stores/workers before linking, and set a bounded heap budget for the login shell.",
      "effort": "large"
    }
  ],
  "taskList": [
    {
      "id": "T1",
      "title": "Ship a minimal unauthenticated bundle and defer authenticated code",
      "priority": 1,
      "findingIds": [
        "F4",
        "F5",
        "F9",
        "F10"
      ],
      "guidanceId": "identify-heavy-scripts",
      "status": "open"
    },
    {
      "id": "T2",
      "title": "Reflow the login shell at narrow widths",
      "priority": 2,
      "findingIds": [
        "F2"
      ],
      "guidanceId": "fluid-scaling",
      "status": "open"
    },
    {
      "id": "T3",
      "title": "Restore semantic structure, visible focus and adequate action targets",
      "priority": 3,
      "findingIds": [
        "F3",
        "F6"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T4",
      "title": "Apply system dark mode to the unauthenticated shell",
      "priority": 4,
      "findingIds": [
        "F1"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T5",
      "title": "Resolve deprecated API, BFCache, charset and image-sizing diagnostics",
      "priority": 5,
      "findingIds": [
        "F7"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T6",
      "title": "Send an explicit Referrer-Policy header",
      "priority": 6,
      "findingIds": [
        "F8"
      ],
      "guidanceId": "security",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 4,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-28T12-03-30-529Z"
}
