Manifest position 80 · CrUX rank bucket 1000
https://web.facebook.com
Coverage complete
Complete atomic audit of public logged-out Facebook templates. Authenticated feed/content, successful credential completion, commerce and account settings were not covered because no test account was supplied.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | Dark and light captures are identical; body remains white and color-scheme is normal. F01 medium: Logged-out Facebook ignores the user’s dark colour-scheme preference. |
respect-user-preferencesrespects-reduced-motion | pass | high | The reduced-motion probe matched the preference and found no active animations on the initial surface. |
respect-user-preferencesrespects-contrast | issues | high | The contrast capture does not adapt and Lighthouse measures the accept control at 4.23:1, below 4.5:1. F11 medium: The primary cookie acceptance label misses WCAG AA contrast. |
implement-natural-interactionsview-transitions | issues | medium | Exercised public links and invalid login update without an observed transition despite stylesheet text mentioning view-transition. F02 low: Public route and state changes are abrupt. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No parallax, scrollytelling, reveal, carousel or other scroll-linked motion exists on the audited pre-auth templates. |
implement-natural-interactionsphysical-gestures | not-applicable | high | The audited pre-auth forms expose no swipe, pull, drag, snapping carousel or other gesture-driven control. |
provide-guided-navigationscroll-state-aware-chrome | not-applicable | high | The short pre-auth forms have no sticky/affixed scroll chrome or progress surface that needs scroll-state adaptation. |
provide-guided-navigationanchored-positioning | not-applicable | medium | No tooltip, anchored menu or edge-sensitive popover was present in the audited pre-auth states; cookie consent is modal dialog content. |
provide-guided-navigationdirects-attention | pass | high | Login, recovery and signup expose one prominent primary action and recovery links with clear state copy. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | A cookie dialog covers the core task on every audited route before interaction. F03 medium: Cookie consent obscures the entire primary task on first load. |
maximize-content-reduce-noisesemantic-dismissible-primitives | pass | high | Consent is exposed as a dialog and its role=button choice can be activated; declining removes the dialog. |
maximize-content-reduce-noisereduced-chrome | pass | high | After consent, the public surface is a focused form with minimal chrome and compact secondary footer navigation. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | issues | high | Requested 360px viewport becomes a 980px CSS layout scaled to 0.367 because viewport meta is absent. F04 high: The main logged-out route omits the viewport meta tag and renders as a scaled 980px desktop canvas on mobile. |
adapt-to-the-form-factorcomponent-level-responsiveness | pass | medium | The login probe detects @container rules, while signup and recovery serve dedicated mobile-width layouts. |
adapt-to-the-form-factorinput-modality-aware | pass | medium | Primary form controls are 38-44px high, major actions are 44px high, and Lighthouse target-size passes. |
support-core-task-successclear-purpose-and-primary-action | pass | high | The pages say Log in to Facebook, Get started on Facebook, and Find Your Account, each with one prominent next action. |
support-core-task-successprimary-flow-completion | pass | medium | The public authentication flow accepts input, reports invalid identity, links to account recovery, and recovery loads a continuation form; authenticated completion was outside the logged-out scope. |
support-core-task-successclear-system-state-and-recovery | pass | high | Errors are visible and actionable, aria-invalid/role=alert is used, and unavailable content offers Feed, Back and Help recovery. |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse LCP is 6.9s and FCP 5.3s; trace LCP is 2.42s, indicating variable but often poor load performance. F05 high: Mobile loading is slow. |
be-fast-and-stablevisual-stability | issues | high | Mobile CLS is 0.0851 and four illustrations omit complete intrinsic dimensions. F06 medium: Cookie illustrations do not reserve complete dimensions and shift the mobile layout. |
be-fast-and-stableefficient-main-thread | issues | high | Trace found two >130ms tasks and 176.35ms TBT; layout independently saw two >100ms tasks. F09 medium: Startup includes avoidable long main-thread tasks. |
be-fast-and-stableefficient-resource-delivery | issues | high | Initial delivery is 9.44MB and includes a 7.4MB secondary QR image plus a VeryHigh parser stylesheet. F07 high: A hidden/secondary QR illustration dominates initial transfer. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | medium | A basic pre-auth form loads 24 scripts totaling 1.32MB before secondary interactions. F08 medium: The simple logged-out form ships a disproportionate script payload. |
be-inclusivenames-roles-labels | issues | high | Lighthouse finds an unlabeled consent checkbox; all four cookie illustrations lack alt text. F10 high: The consent and image content contains missing accessible names. |
be-inclusivesufficient-contrast | issues | high | The Allow all cookies label is 4.23:1 against blue, below WCAG AA 4.5:1. F11 medium: The primary cookie acceptance label misses WCAG AA contrast. |
be-inclusivestructure-and-focus | issues | high | No semantic headings exist on login, signup or recovery, although main and alert semantics are present. F12 medium: Public authentication pages have no semantic headings. |
be-inclusivelegible-text | pass | medium | Form labels, instructions and errors are readable with comfortable line lengths after the intended mobile variants load. |
be-inclusivezoom-reflow-targets-and-media | issues | high | Main route is scaled from 980px at 360px because viewport meta is absent; no video/audio needs captions and target-size audit passes. F13 high: The main login variant fails mobile reflow because it lacks a viewport declaration. |
follow-best-practicesno-console-errors | issues | high | An uncaught getElementsByTagName TypeError occurs in scrollToHeader. F14 medium: Facebook logs an uncaught exception during audit load. |
follow-best-practicessound-document-and-assets | issues | high | Doctype and UTF-8 pass, but four images lack complete dimensions and modern responsive sources. F15 medium: Image markup is incomplete and contributes to layout shift. |
follow-best-practicesbrowser-platform-hygiene | issues | high | An unload event listener deprecation is reported; no permission prompt appeared on load. F16 medium: The page registers deprecated unload listeners. |
be-discoverabletitle-and-description | issues | high | Final desktop document title is only Facebook and meta description is absent. F17 medium: The desktop logged-out document has generic metadata. |
be-discoverablecrawlable-and-mobile-friendly | issues | high | Links use href, but viewport meta is absent and raw HTML has only 1% of rendered words. F18 high: Crawler/mobile signals differ across variants, and the desktop route lacks viewport metadata. |
be-discoverablecanonical-and-indexing-signals | issues | high | Canonical targets en-gb while final host is www; robots is valid, but /sitemap.xml responds with HTML rather than XML. F19 medium: Indexing signals are inconsistent. |
be-discoverablestructured-and-shareable-metadata | not-applicable | high | The generic login/account-gateway page is not an article, product, event, place or other rich entity requiring schema.org/share metadata. |
be-private-and-securesecure-transport-and-headers | pass | high | HTTPS, HSTS, CSP, nosniff and DENY framing are present; no cookies or client-side secrets were found before consent. |
be-private-and-securedata-minimisation-and-third-parties | pass | medium | No known trackers or pre-consent cookies were observed; network origins are Facebook/Meta-controlled, with one Instagram identity request. |
be-private-and-securein-context-permissions-and-modern-auth | pass | medium | No permission prompt appeared on load; username uses autocomplete="username webauthn", showing passkey-capable conditional auth support. |
be-private-and-securedefensive-browser-policies | issues | high | Strong HSTS, clickjacking and Permissions-Policy controls are present, but Referrer-Policy is absent and style-src allows unsafe-inline. F20 low: The otherwise strong header set omits Referrer-Policy and permits inline styles. |
be-resilientprogressive-enhancement | issues | high | Raw HTML retains only 1% of rendered words and crawler view is effectively blank. F21 high: The core logged-out content is almost absent without JavaScript. |
be-resilientresilient-runtime-behaviour | pass | medium | Dialog dismissal, validation state, recovery navigation and unavailable-content controls remained stable without cut-off on exercised routes. |
be-resilientoffline-and-installable | not-applicable | high | The audited gateway is for an intrinsically networked authenticated social service; no manifest or controlling service worker exists, and offline sign-in is not a meaningful task. |
be-resilientnetwork-and-http-failure-states | pass | high | Unavailable content explains the state and offers Go to Feed, Go back and Visit Help Centre. |
be-internationalisedlang-dir-and-logical-properties | pass | high | Document declares lang=en and dir=ltr, rendered CSS contains logical properties, and multiple explicit language choices are offered. |
be-internationalisedlocale-aware-data | not-applicable | high | The audited pre-auth templates render no dates, numbers, currencies, durations or calendars requiring locale formatting. |
be-internationalisedtime-zone-correctness | not-applicable | high | The audited pre-auth templates contain no event times, time-zone data or DST-sensitive scheduling. |
be-trustworthyno-dark-patterns | pass | medium | Decline optional cookies is explicit without confirmshaming, signup commitments link to Terms/Privacy/Cookies, and account recovery is easy to find. |
be-trustworthyhumane-error-handling | pass | high | Errors appear after submission, use aria-invalid and role=alert, and give concrete corrective text. |
be-trustworthytrustworthy-input-assistance | issues | high | Signup sets autocomplete=off on all core fields and login password has no current-password token. F22 high: Signup disables autofill and the login password lacks a suitable autocomplete token. |
be-trustworthysafe-commercial-and-account-flows | pass | medium | Signup states account creation terms and data use before Submit, login offers recovery, and username webauthn indicates phishing-resistant auth support; no commercial flow appears pre-auth. |
be-sustainableoptimised-assets | issues | high | A secondary QR JPG transfers 7.4MB; four PNG illustrations lack responsive sources and modern formats. F23 high: A 7.4MB image is delivered for a secondary QR-login affordance. |
be-sustainableno-wasteful-work | pass | medium | Only three xhr/fetch requests were seen, no autoplay media exists, and no known tracker was detected pre-consent. |
be-sustainablethird-party-and-media-budget | issues | high | The login surface transfers 9.44MB, dominated by 7.4MB QR media plus 1.32MB scripts and 183KB font. F24 high: Initial transfer is disproportionate to a basic login form. |
be-agent-readystructured-agent-capabilities | not-applicable | high | Facebook explicitly disallows major AI agent crawlers including ClaudeBot, GPTBot and PerplexityBot, indicating this public gateway is intentionally not agent-facing. |
be-agent-readyon-device-inference | not-applicable | high | The login/signup/recovery tasks have no appropriate summarisation or language-model need; absence of on-device inference is not a quality gap here. |
be-memory-efficientno-leak-under-repeated-interaction | not-applicable | medium | No safe representative repeatable interaction exists on the pre-auth page without account state; separate-session heap captures cannot establish retained-growth causality. |
be-memory-efficientbounded-footprint | pass | medium | Baseline snapshot totals 43.6MB self size and runtime reports 20.7MB JS used for 685 live DOM nodes, proportionate though not minimal. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | low | Neither heap summary surfaces Detached* constructors among the dominant populations; no evidence of unbounded detached DOM/listeners was found in this bounded pre-auth state. |
Provenance
Canonical report: results/atomic/reports/0080-web_facebook_com.json
Report SHA-256: 415ae7347d083d8cd26a5a6cde6d6be4f00cd5d65a39d4301e76fdf6bc4eb971
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/web_facebook_com/2026-07-18T06-38-53-414Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/web_facebook_com/2026-07-18T06-38-53-414Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.