Manifest position 80 · CrUX rank bucket 1000

https://web.facebook.com

Coverage complete

Complete atomic audit of public logged-out Facebook templates. Authenticated feed/content, successful credential completion, commerce and account settings were not covered because no test account was supplied.

Attempts
1 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighDark and light captures are identical; body remains white and color-scheme is normal.
F01 medium: Logged-out Facebook ignores the user’s dark colour-scheme preference.
respect-user-preferences
respects-reduced-motion
passhighThe reduced-motion probe matched the preference and found no active animations on the initial surface.
respect-user-preferences
respects-contrast
issueshighThe contrast capture does not adapt and Lighthouse measures the accept control at 4.23:1, below 4.5:1.
F11 medium: The primary cookie acceptance label misses WCAG AA contrast.
implement-natural-interactions
view-transitions
issuesmediumExercised public links and invalid login update without an observed transition despite stylesheet text mentioning view-transition.
F02 low: Public route and state changes are abrupt.
implement-natural-interactions
scroll-driven-animations
not-applicablehighNo parallax, scrollytelling, reveal, carousel or other scroll-linked motion exists on the audited pre-auth templates.
implement-natural-interactions
physical-gestures
not-applicablehighThe audited pre-auth forms expose no swipe, pull, drag, snapping carousel or other gesture-driven control.
provide-guided-navigation
scroll-state-aware-chrome
not-applicablehighThe short pre-auth forms have no sticky/affixed scroll chrome or progress surface that needs scroll-state adaptation.
provide-guided-navigation
anchored-positioning
not-applicablemediumNo tooltip, anchored menu or edge-sensitive popover was present in the audited pre-auth states; cookie consent is modal dialog content.
provide-guided-navigation
directs-attention
passhighLogin, recovery and signup expose one prominent primary action and recovery links with clear state copy.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighA cookie dialog covers the core task on every audited route before interaction.
F03 medium: Cookie consent obscures the entire primary task on first load.
maximize-content-reduce-noise
semantic-dismissible-primitives
passhighConsent is exposed as a dialog and its role=button choice can be activated; declining removes the dialog.
maximize-content-reduce-noise
reduced-chrome
passhighAfter consent, the public surface is a focused form with minimal chrome and compact secondary footer navigation.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
issueshighRequested 360px viewport becomes a 980px CSS layout scaled to 0.367 because viewport meta is absent.
F04 high: The main logged-out route omits the viewport meta tag and renders as a scaled 980px desktop canvas on mobile.
adapt-to-the-form-factor
component-level-responsiveness
passmediumThe login probe detects @container rules, while signup and recovery serve dedicated mobile-width layouts.
adapt-to-the-form-factor
input-modality-aware
passmediumPrimary form controls are 38-44px high, major actions are 44px high, and Lighthouse target-size passes.
support-core-task-success
clear-purpose-and-primary-action
passhighThe pages say Log in to Facebook, Get started on Facebook, and Find Your Account, each with one prominent next action.
support-core-task-success
primary-flow-completion
passmediumThe public authentication flow accepts input, reports invalid identity, links to account recovery, and recovery loads a continuation form; authenticated completion was outside the logged-out scope.
support-core-task-success
clear-system-state-and-recovery
passhighErrors are visible and actionable, aria-invalid/role=alert is used, and unavailable content offers Feed, Back and Help recovery.
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse LCP is 6.9s and FCP 5.3s; trace LCP is 2.42s, indicating variable but often poor load performance.
F05 high: Mobile loading is slow.
be-fast-and-stable
visual-stability
issueshighMobile CLS is 0.0851 and four illustrations omit complete intrinsic dimensions.
F06 medium: Cookie illustrations do not reserve complete dimensions and shift the mobile layout.
be-fast-and-stable
efficient-main-thread
issueshighTrace found two >130ms tasks and 176.35ms TBT; layout independently saw two >100ms tasks.
F09 medium: Startup includes avoidable long main-thread tasks.
be-fast-and-stable
efficient-resource-delivery
issueshighInitial delivery is 9.44MB and includes a 7.4MB secondary QR image plus a VeryHigh parser stylesheet.
F07 high: A hidden/secondary QR illustration dominates initial transfer.
be-fast-and-stable
trim-unused-and-duplicate-code
issuesmediumA basic pre-auth form loads 24 scripts totaling 1.32MB before secondary interactions.
F08 medium: The simple logged-out form ships a disproportionate script payload.
be-inclusive
names-roles-labels
issueshighLighthouse finds an unlabeled consent checkbox; all four cookie illustrations lack alt text.
F10 high: The consent and image content contains missing accessible names.
be-inclusive
sufficient-contrast
issueshighThe Allow all cookies label is 4.23:1 against blue, below WCAG AA 4.5:1.
F11 medium: The primary cookie acceptance label misses WCAG AA contrast.
be-inclusive
structure-and-focus
issueshighNo semantic headings exist on login, signup or recovery, although main and alert semantics are present.
F12 medium: Public authentication pages have no semantic headings.
be-inclusive
legible-text
passmediumForm labels, instructions and errors are readable with comfortable line lengths after the intended mobile variants load.
be-inclusive
zoom-reflow-targets-and-media
issueshighMain route is scaled from 980px at 360px because viewport meta is absent; no video/audio needs captions and target-size audit passes.
F13 high: The main login variant fails mobile reflow because it lacks a viewport declaration.
follow-best-practices
no-console-errors
issueshighAn uncaught getElementsByTagName TypeError occurs in scrollToHeader.
F14 medium: Facebook logs an uncaught exception during audit load.
follow-best-practices
sound-document-and-assets
issueshighDoctype and UTF-8 pass, but four images lack complete dimensions and modern responsive sources.
F15 medium: Image markup is incomplete and contributes to layout shift.
follow-best-practices
browser-platform-hygiene
issueshighAn unload event listener deprecation is reported; no permission prompt appeared on load.
F16 medium: The page registers deprecated unload listeners.
be-discoverable
title-and-description
issueshighFinal desktop document title is only Facebook and meta description is absent.
F17 medium: The desktop logged-out document has generic metadata.
be-discoverable
crawlable-and-mobile-friendly
issueshighLinks use href, but viewport meta is absent and raw HTML has only 1% of rendered words.
F18 high: Crawler/mobile signals differ across variants, and the desktop route lacks viewport metadata.
be-discoverable
canonical-and-indexing-signals
issueshighCanonical targets en-gb while final host is www; robots is valid, but /sitemap.xml responds with HTML rather than XML.
F19 medium: Indexing signals are inconsistent.
be-discoverable
structured-and-shareable-metadata
not-applicablehighThe generic login/account-gateway page is not an article, product, event, place or other rich entity requiring schema.org/share metadata.
be-private-and-secure
secure-transport-and-headers
passhighHTTPS, HSTS, CSP, nosniff and DENY framing are present; no cookies or client-side secrets were found before consent.
be-private-and-secure
data-minimisation-and-third-parties
passmediumNo known trackers or pre-consent cookies were observed; network origins are Facebook/Meta-controlled, with one Instagram identity request.
be-private-and-secure
in-context-permissions-and-modern-auth
passmediumNo permission prompt appeared on load; username uses autocomplete="username webauthn", showing passkey-capable conditional auth support.
be-private-and-secure
defensive-browser-policies
issueshighStrong HSTS, clickjacking and Permissions-Policy controls are present, but Referrer-Policy is absent and style-src allows unsafe-inline.
F20 low: The otherwise strong header set omits Referrer-Policy and permits inline styles.
be-resilient
progressive-enhancement
issueshighRaw HTML retains only 1% of rendered words and crawler view is effectively blank.
F21 high: The core logged-out content is almost absent without JavaScript.
be-resilient
resilient-runtime-behaviour
passmediumDialog dismissal, validation state, recovery navigation and unavailable-content controls remained stable without cut-off on exercised routes.
be-resilient
offline-and-installable
not-applicablehighThe audited gateway is for an intrinsically networked authenticated social service; no manifest or controlling service worker exists, and offline sign-in is not a meaningful task.
be-resilient
network-and-http-failure-states
passhighUnavailable content explains the state and offers Go to Feed, Go back and Visit Help Centre.
be-internationalised
lang-dir-and-logical-properties
passhighDocument declares lang=en and dir=ltr, rendered CSS contains logical properties, and multiple explicit language choices are offered.
be-internationalised
locale-aware-data
not-applicablehighThe audited pre-auth templates render no dates, numbers, currencies, durations or calendars requiring locale formatting.
be-internationalised
time-zone-correctness
not-applicablehighThe audited pre-auth templates contain no event times, time-zone data or DST-sensitive scheduling.
be-trustworthy
no-dark-patterns
passmediumDecline optional cookies is explicit without confirmshaming, signup commitments link to Terms/Privacy/Cookies, and account recovery is easy to find.
be-trustworthy
humane-error-handling
passhighErrors appear after submission, use aria-invalid and role=alert, and give concrete corrective text.
be-trustworthy
trustworthy-input-assistance
issueshighSignup sets autocomplete=off on all core fields and login password has no current-password token.
F22 high: Signup disables autofill and the login password lacks a suitable autocomplete token.
be-trustworthy
safe-commercial-and-account-flows
passmediumSignup states account creation terms and data use before Submit, login offers recovery, and username webauthn indicates phishing-resistant auth support; no commercial flow appears pre-auth.
be-sustainable
optimised-assets
issueshighA secondary QR JPG transfers 7.4MB; four PNG illustrations lack responsive sources and modern formats.
F23 high: A 7.4MB image is delivered for a secondary QR-login affordance.
be-sustainable
no-wasteful-work
passmediumOnly three xhr/fetch requests were seen, no autoplay media exists, and no known tracker was detected pre-consent.
be-sustainable
third-party-and-media-budget
issueshighThe login surface transfers 9.44MB, dominated by 7.4MB QR media plus 1.32MB scripts and 183KB font.
F24 high: Initial transfer is disproportionate to a basic login form.
be-agent-ready
structured-agent-capabilities
not-applicablehighFacebook explicitly disallows major AI agent crawlers including ClaudeBot, GPTBot and PerplexityBot, indicating this public gateway is intentionally not agent-facing.
be-agent-ready
on-device-inference
not-applicablehighThe login/signup/recovery tasks have no appropriate summarisation or language-model need; absence of on-device inference is not a quality gap here.
be-memory-efficient
no-leak-under-repeated-interaction
not-applicablemediumNo safe representative repeatable interaction exists on the pre-auth page without account state; separate-session heap captures cannot establish retained-growth causality.
be-memory-efficient
bounded-footprint
passmediumBaseline snapshot totals 43.6MB self size and runtime reports 20.7MB JS used for 685 live DOM nodes, proportionate though not minimal.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passlowNeither heap summary surfaces Detached* constructors among the dominant populations; no evidence of unbounded detached DOM/listeners was found in this bounded pre-auth state.

Provenance

Canonical report: results/atomic/reports/0080-web_facebook_com.json
Report SHA-256: 415ae7347d083d8cd26a5a6cde6d6be4f00cd5d65a39d4301e76fdf6bc4eb971
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/web_facebook_com/2026-07-18T06-38-53-414Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/web_facebook_com/2026-07-18T06-38-53-414Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.