Manifest position 12 · CrUX rank bucket 1000
https://th.xhsocial.com
Coverage complete
Atomic coverage complete across 58 checks and five representative public paths. Logged-in account management, payment, live-chat and destructive registration submission were not covered.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | pass | high | Desktop screenshots under explicit light and dark emulation show the complete surface retints appropriately. |
respect-user-preferencesrespects-reduced-motion | issues | high | The reduced-motion probe matched prefers-reduced-motion: reduce but still found eight running, infinite 2-second shimmer animations. F01 medium: Animations continue when reduced motion is requested |
respect-user-preferencesrespects-contrast | pass | high | Forced-colors screenshot keeps navigation, dialog text and controls visible with system colors. |
implement-natural-interactionsview-transitions | issues | high | The platform probe found zero view-transition rules across the loaded stylesheets, while the site exposes many route and modal state changes. F02 low: Route and state changes do not use View Transitions |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No scroll-linked animation, parallax, scrollytelling or reveal interaction exists on the representative pages, so there is no implementation to assess. |
implement-natural-interactionsphysical-gestures | not-applicable | high | No swipe, pull, draggable, carousel or other gesture-driven primary interaction was present on the audited surfaces. |
provide-guided-navigationscroll-state-aware-chrome | issues | high | The 4,011px homepage and 7,482px categories surface have static chrome; the CSS probe found no scroll-state query or scroll timeline rules. F03 low: Long pages provide no scroll-state-aware navigation cue |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip or edge-sensitive anchored transient overlay was exposed in the representative unauthenticated paths. |
provide-guided-navigationdirects-attention | pass | high | Active navigation has a visible underline, routes use descriptive Thai labels, and the 404 offers a clear home recovery link. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | The fresh-load desktop screenshot shows a large centered consent dialog covering the content before interaction. Accept and reject are both available, but the interruption dominates the page. F04 medium: Cookie dialog obscures most of the first viewport |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | The signup probe found a DIV with role=dialog and aria-modal=true; no native dialog or popover elements were present in the platform probe. F05 low: Modal surfaces use custom role=dialog containers instead of native dialog |
maximize-content-reduce-noisereduced-chrome | pass | high | Outside the consent interruption, content cards occupy the main surface and chrome remains compact relative to the long content list. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | issues | high | At a requested 360x800 viewport, layout measured scrollWidth 1024px versus clientWidth 360px, 664px of horizontal overflow. Category, detail and signup screenshots show clipped desktop surfaces; the signup panel is almost entirely off-screen. F06 critical: Desktop layout is forced into narrow viewports |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | The stylesheet probe found zero @container rules, while the reused navigation, cards and signup panel visibly clip when their available width narrows. F07 medium: Components do not adapt at container level |
adapt-to-the-form-factorinput-modality-aware | issues | high | Programmatically focused search input and submit button computed outline: none 0px. Lighthouse also reported target-spacing failures. F08 high: Keyboard focus is not visibly indicated on key controls |
support-core-task-successclear-purpose-and-primary-action | pass | high | H1, card grid, search control and category navigation clearly communicate a video-browsing purpose and next actions. |
support-core-task-successprimary-flow-completion | issues | high | The 360px signup screenshot renders its right-side registration panel beyond the viewport, leaving only a narrow clipped strip and making the primary registration options unusable. F09 high: Signup flow is clipped and cannot be completed at the tested narrow viewport |
support-core-task-successclear-system-state-and-recovery | pass | high | The deliberate missing route renders a localized not-found explanation, technical-support link and return-home action rather than a blank shell. |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse measured LCP at 3.2s (score 0.71), above the 2.5s good threshold, although CLS was 0 and TBT was 0ms. F10 medium: Lab LCP is outside the good range |
be-fast-and-stablevisual-stability | pass | high | Layout observer measured CLS 0.0027 and Lighthouse measured CLS 0, both within the good range. |
be-fast-and-stableefficient-main-thread | pass | high | Trace recorded zero long tasks and 0ms TBT; Lighthouse also measured TBT 0ms. A separate layout window saw only two startup tasks (71ms and 150ms). |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR recorded 140 requests and 1,850,742 transferred bytes, including 61 scripts (1,048,900 bytes), 11 stylesheets and multiple parser-inserted render-blocking stylesheet candidates. F11 medium: The entry page ships a large, fragmented critical load |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | Lighthouse estimated 26KiB unused JavaScript and 57KiB unused CSS; HAR shows a 402KiB index script as the largest response. F12 medium: Unused CSS and JavaScript are shipped on initial load |
be-inclusivenames-roles-labels | issues | high | Lighthouse found two unnamed buttons and two links in the mobile homepage that are keyboard-focusable without accessible text. F13 high: Interactive controls and links lack accessible names |
be-inclusivesufficient-contrast | issues | high | Lighthouse measured contrast as low as 1.75:1 and 2.15:1 on the green age-verification banner and 3.29:1 on repeated view-count text, below the 4.5:1 minimum. F14 high: Important text fails minimum color contrast |
be-inclusivestructure-and-focus | issues | high | The focus probe found no visible outline on the search input/button; Lighthouse found unnamed controls/links, undermining a predictable keyboard focus walk. F15 high: Focus visibility and interactive semantics are unreliable |
be-inclusivelegible-text | pass | high | Screenshots show readable Thai headings/body copy with clear size hierarchy and no text clipping on the Lighthouse mobile variant; contrast defects are recorded separately. |
be-inclusivezoom-reflow-targets-and-media | issues | high | Lighthouse found the mobile viewport disables user scaling and reported undersized/overlapping targets; the 360px raw-CDP layout also overflowed by 664px. F16 high: Mobile zoom/reflow and target spacing fail accessibility expectations |
follow-best-practicesno-console-errors | pass | high | Lighthouse errors-in-console audit passed with no entries. |
follow-best-practicessound-document-and-assets | issues | high | The image audit found 29 of 36 images without width/height, 12 oversized images and 8 below-fold images without lazy loading. F17 medium: Image delivery lacks stable dimensions and appropriate sizing |
follow-best-practicesbrowser-platform-hygiene | pass | high | Lighthouse passed BFCache and deprecation audits and reported best-practices score 1.0; no prompt appeared on load. |
be-discoverabletitle-and-description | pass | high | Homepage and representative detail have descriptive, localized titles and meta descriptions. |
be-discoverablecrawlable-and-mobile-friendly | pass | high | Links use href, viewport metadata exists, robots.txt is valid, and Lighthouse SEO/crawlable-link audits passed. |
be-discoverablecanonical-and-indexing-signals | issues | high | robots.txt returned 200, but /sitemap.xml returned 404. Canonicals point from xhsocial.com to the xhamster.com host, which should be intentionally verified across all localized variants. F18 low: Sitemap discovery is incomplete |
be-discoverablestructured-and-shareable-metadata | issues | high | The representative video detail exposes Open Graph tags but no JSON-LD or microdata, despite representing a rich VideoObject. F19 medium: Video detail page omits structured video metadata |
be-private-and-securesecure-transport-and-headers | issues | high | The headers probe found CSP limited to frame-ancestors only and no X-Content-Type-Options or Referrer-Policy. Cookie audit found three insecure issues, including settings and CSRF cookies without Secure and SameSite=None cookies. F20 high: Cookies and CSP do not provide a strong secure baseline |
be-private-and-securedata-minimisation-and-third-parties | issues | high | A fresh-load HAR recorded 116 third-party requests and 1,657,764 third-party bytes while the consent dialog was still displayed; requests included Google accounts, ad/media domains and 80 requests to static-ah.xhcdn.com. F21 high: Extensive third-party traffic occurs before a consent choice |
be-private-and-securein-context-permissions-and-modern-auth | issues | high | The signup surface offers Google, X and email; the platform/runtime probes found no WebAuthn/passkey affordance while authentication is clearly relevant. No permission prompt fired on load. F22 medium: Signup offers Google, X and email but no phishing-resistant first-party path |
be-private-and-securedefensive-browser-policies | issues | high | HSTS is only one day; nosniff and Referrer-Policy are absent, Permissions-Policy only delegates two client-hint features, and CSP has no script/style/default-src controls. F23 high: Defensive response policies are incomplete |
be-resilientprogressive-enhancement | pass | high | Raw HTML returned 200 with title, H1 and description and retained 65% of rendered content words; it is not an empty JS shell. |
be-resilientresilient-runtime-behaviour | pass | high | Public category/detail navigation loaded robustly, the consent control remained attached in both themes, and no runtime error was reported. |
be-resilientoffline-and-installable | pass | high | A valid manifest provides start_url, scope, icons and minimal-ui display, and an active pwa.js service worker registration covers the origin. |
be-resilientnetwork-and-http-failure-states | not-applicable | high | No fetch-dependent transactional flow could be safely fault-injected without source or test credentials; the public 404 recovery state was assessed separately as passing runtime recovery. |
be-internationalisedlang-dir-and-logical-properties | issues | high | The Thai document correctly declares lang=th and offers many locale routes, but stylesheet inspection found 705 physical left/right declarations versus only 18 logical-property uses. F24 medium: Localized layout relies overwhelmingly on physical CSS properties |
be-internationalisedlocale-aware-data | pass | high | Thai content and compact view counts are localized, and a broad locale selector maps to language-specific hosts; no raw locale-sensitive date/currency data was exposed. |
be-internationalisedtime-zone-correctness | not-applicable | high | No dates, appointments, schedules, recurrence or time-zone-sensitive data appeared in the representative public paths. |
be-trustworthyno-dark-patterns | pass | high | Consent presents equally prominent accept and reject actions plus settings/privacy links; signup disclosures describe public data use and partners. |
be-trustworthyhumane-error-handling | not-applicable | high | No required-field form was exposed without proceeding into account creation; public search has no invalid-input state. |
be-trustworthytrustworthy-input-assistance | not-applicable | high | No address, payment, sign-in or data-entry field was exposed in the non-destructive first signup step; only provider/email choice links were shown. |
be-trustworthysafe-commercial-and-account-flows | issues | high | The signup/account dialog is visually clipped outside the tested 360px viewport, so consent and account choices are not proportionately available on a common form factor. F25 medium: Account entry is not reliably usable on mobile |
be-sustainableoptimised-assets | issues | high | Image inspection found 12 images more than twice their displayed width, 17 legacy-format entries and 8 below-fold images loaded eagerly. F26 medium: Asset sizing wastes transfer and decode work |
be-sustainableno-wasteful-work | pass | high | Trace found no long-running background main-thread work over the 5.7s window; resource waste is separately captured under asset and third-party checks. |
be-sustainablethird-party-and-media-budget | issues | high | HAR attributes 1.66MB of 1.85MB and 116 of 140 requests to third-party origins, disproportionate for the first content view before consent. F27 medium: Third-party cost dominates the page budget |
be-agent-readystructured-agent-capabilities | not-applicable | high | The public media browsing site declares no intent or structured agent-facing task surface; this emerging capability is not expected for this audit. |
be-agent-readyon-device-inference | not-applicable | high | No user task on the representative browsing/signup paths requires on-device inference; absence is not a failure for this site. |
be-memory-efficientno-leak-under-repeated-interaction | pass | low | After ten full-page scroll cycles, retained self size rose from 36.94MB to 39.15MB (about 6%) and node count from 686,865 to 732,788, consistent with bounded lazy-loaded content rather than unbounded cycle growth; confidence is low because snapshots were separate fresh sessions. |
be-memory-efficientbounded-footprint | pass | low | Baseline retained self size was 36.94MB for a media-heavy page, proportionate to the loaded content and 1.85MB network payload. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | low | Neither heap summary surfaced Detached constructors among the largest retained constructors; repeated scrolling increased footprint modestly without evidence of runaway listener/timer populations. |
Provenance
Canonical report: results/atomic/reports/0012-th_xhsocial_com.json
Report SHA-256: 4faa32489cb4c4671b4f29923e116eadec42c5189eced11e1b19db2e6a0fdece
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/th_xhsocial_com/2026-07-17T20-42-38-574Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/th_xhsocial_com/2026-07-17T20-42-38-574Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.