Manifest position 93 · CrUX rank bucket 1000
https://myim3.ioh.co.id
Partial after retries
The public login surface and adverse conditions were judged, but end-to-end account and commercial flows remain blocked by subscriber number and OTP authentication. No authorized test account was provided.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | The dark capture is identical to default; color-scheme is normal and no dark media rule exists F01 medium: The login experience ignores the requested dark color scheme. |
respect-user-preferencesrespects-reduced-motion | pass | high | No active animations were present, and the stylesheet contains explicit reduced-motion rules that disable transitions. |
respect-user-preferencesrespects-contrast | pass | high | Under forced-colors: active, browser colors adapt and all text, the field border and the Continue control remain visible. Normal-scheme WCAG contrast failures are recorded separately under be-inclusive. |
implement-natural-interactionsview-transitions | issues | medium | The language change navigated the document and no view-transition CSS or API use was found. F03 low: The language/state navigation has no declared transition treatment. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | The accessible login view has no scroll-linked animation, parallax, scrollytelling or reveal effect to implement declaratively. |
implement-natural-interactionsphysical-gestures | not-applicable | high | The accessible login view has no swipe, pull, drag, carousel or other physical gesture surface. |
provide-guided-navigationscroll-state-aware-chrome | not-applicable | high | The login page fits in one viewport and has no sticky or affixed scroll chrome. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip, popover or menu is exposed on the accessible login view. |
provide-guided-navigationdirects-attention | pass | medium | The single login view keeps one heading, one field and one primary button in reading order, so the next step is visually unambiguous. |
maximize-content-reduce-noiseno-intrusive-interruptions | pass | high | No popup, interstitial, consent wall or banner obscures the login form on load. |
maximize-content-reduce-noisesemantic-dismissible-primitives | not-applicable | high | No overlay or disclosure control is present on the accessible login view. |
maximize-content-reduce-noisereduced-chrome | pass | high | The viewport is almost entirely task content with no application frame, side rail, decorative panel or competing chrome. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | Both viewports have zero horizontal overflow and the form fluidly changes width. |
adapt-to-the-form-factorcomponent-level-responsiveness | not-applicable | medium | The accessible page exposes one fixed-context login form, not a component reused in materially different containers. |
adapt-to-the-form-factorinput-modality-aware | issues | high | Focus outlines are absent and language controls are far below 44x44 CSS pixels. F04 high: Keyboard focus is invisible and language targets are too small. |
support-core-task-successclear-purpose-and-primary-action | pass | high | The Indonesian heading states that an IM3 number is needed to log in, followed immediately by the labelled phone field and Continue action. |
support-core-task-successprimary-flow-completion | blocked | high | End-to-end completion requires a valid IM3 subscriber number and OTP. No test account or authorization was supplied, so proceeding could message a real subscriber. |
support-core-task-successclear-system-state-and-recovery | issues | high | A short invalid value leaves Continue disabled but produces no visible or announced reason or recovery instruction. F05 high: Invalid phone input gives no actionable state or accessible error. |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse LCP is 9.18 s and trace LCP is 4.02 s; both exceed the 2.5 s good threshold. CLS and blocking time are separately judged. F06 high: The throttled Largest Contentful Paint is far outside the good range. |
be-fast-and-stablevisual-stability | pass | high | Observed CLS was 0.0145 mobile and 0.0072 desktop, both comfortably below 0.1. |
be-fast-and-stableefficient-main-thread | pass | high | The trace recorded zero long tasks and zero blocking time; both layout captures also recorded no long tasks. |
be-fast-and-stableefficient-resource-delivery | issues | high | The login load transfers 1.93 MB, including 1.61 MB scripts and 211 KB fonts; major document and JavaScript resources are uncompressed. F07 high: The small login screen downloads a heavy, inefficient application payload. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | Lighthouse estimates about 1,042 KiB unused JS and 69 KiB unused CSS on the one-field login route. F08 high: Most JavaScript and CSS shipped to the login route is unused. |
be-inclusivenames-roles-labels | issues | high | The form is labelled, but decorative images expose alt="." rather than empty alternative text. F09 medium: Decorative images expose punctuation as alternative text. |
be-inclusivesufficient-contrast | issues | high | Four visible text elements fail 4.5:1, with measured ratios from 3.49:1 to 4.31:1. F10 high: Four visible text elements fail WCAG AA contrast. |
be-inclusivestructure-and-focus | issues | high | There is no main landmark or h1, heading order skips levels, and focused controls have no visible outline or shadow. F11 high: The login document lacks semantic structure and visible focus. |
be-inclusivelegible-text | issues | high | Small gray helper copy is only 12px and 3.49:1 against white, reducing reading comfort. F12 medium: Supporting text is visually weak at small sizes. |
be-inclusivezoom-reflow-targets-and-media | issues | high | user-scalable=no and maximum-scale=1 disable zoom, and language controls are undersized. F13 critical: The viewport explicitly prevents user zoom. F04 high: Keyboard focus is invisible and language targets are too small. |
follow-best-practicesno-console-errors | issues | high | The page throws ReferenceError: Swiper is not defined from the production scripts bundle. F14 medium: A production script throws an uncaught Swiper reference error. |
follow-best-practicessound-document-and-assets | issues | high | Doctype and charset are valid, but the rendered phone-prefix image has no intrinsic width/height. F15 low: An inline SVG image has no intrinsic dimensions. |
follow-best-practicesbrowser-platform-hygiene | issues | high | The large first-party vendor bundle has no valid source map; no deprecation or BFCache failures were observed. F16 medium: Large production JavaScript has no source map. |
be-discoverabletitle-and-description | pass | high | The raw and rendered documents include title “myIM3” and a descriptive Indonesian meta description. |
be-discoverablecrawlable-and-mobile-friendly | issues | high | Language anchors use javascript:void(), and robots.txt returns a NoSuchKey storage error; mobile layout itself reflows. F17 medium: Navigation controls are not crawlable links and robots.txt is missing. |
be-discoverablecanonical-and-indexing-signals | issues | high | The document is HTTP 200 but has no canonical or hreflang, while robots.txt and sitemap.xml are missing. F18 medium: Public indexing signals are incomplete. |
be-discoverablestructured-and-shareable-metadata | not-applicable | medium | This private account login screen does not present an article, product, event or rich public entity requiring schema.org or social-preview data. |
be-private-and-securesecure-transport-and-headers | issues | high | HTTPS, HSTS and secure cookie posture pass, but CSP is absent and a reusable hdrAuthorization value is embedded in public JavaScript. F19 high: The authentication client lacks CSP and embeds a reusable authorization value in its public bundle. |
be-private-and-securedata-minimisation-and-third-parties | pass | high | The login load makes only first-party requests, sets no cookies, loads no known trackers, and explains that the phone number is needed for verification. |
be-private-and-securein-context-permissions-and-modern-auth | issues | medium | No permission is requested on load, but the accessible account entry exposes phone OTP only and no passkey/WebAuthn option. F20 medium: The account entry offers phone OTP only, with no phishing-resistant option. |
be-private-and-securedefensive-browser-policies | issues | high | HSTS, nosniff and SAMEORIGIN are present; CSP, Referrer-Policy and Permissions-Policy are absent. F21 medium: Several browser-enforced defensive policies are absent. |
be-resilientprogressive-enhancement | issues | high | Without JavaScript, the login form disappears and only an enable-JavaScript message remains; content coverage is 6%. F22 high: The login flow is unusable without JavaScript. |
be-resilientresilient-runtime-behaviour | pass | medium | The accessible form remains stable through focus/edit/blur cycles, has no clipped overlays, no long tasks and no DOM growth. |
be-resilientoffline-and-installable | pass | high | A manifest and active service worker are present, and an offline reload continues to render the login shell. |
be-resilientnetwork-and-http-failure-states | issues | high | An unknown path produces a raw NoSuchKey XML error without navigation or recovery. F23 medium: Unknown paths expose a raw storage error with no recovery. |
be-internationalisedlang-dir-and-logical-properties | issues | high | Visible selected content is Indonesian while html lang is en; CSS has extensive physical left/right declarations and zero logical property matches. F24 medium: Language metadata and CSS do not match the visible locale or support bidirectional layout. |
be-internationalisedlocale-aware-data | not-applicable | high | The accessible login view displays no dates, numbers, currencies, durations or calendars requiring locale formatting. |
be-internationalisedtime-zone-correctness | not-applicable | high | The accessible login view handles no events, schedules, dates or times. |
be-trustworthyno-dark-patterns | pass | medium | The accessible entry asks only for the phone number needed for verification, explains why, and shows no preselected upsell, nagging consent or disguised action. |
be-trustworthyhumane-error-handling | issues | high | After user interaction the invalid field provides no specific visible or announced feedback. F05 high: Invalid phone input gives no actionable state or accessible error. |
be-trustworthytrustworthy-input-assistance | issues | high | The sign-in telephone field explicitly sets autocomplete=off. F25 medium: The phone field disables useful browser input assistance. |
be-trustworthysafe-commercial-and-account-flows | blocked | high | Pricing, cancellation, sensitive account actions and reauthentication exist behind a valid subscriber number and OTP; no authorized test account was supplied. |
be-sustainableoptimised-assets | pass | high | The visible imagery is tiny, not oversized, and totals about 25 KB; the main visual prefix is SVG. |
be-sustainableno-wasteful-work | issues | high | The route downloads over 1 MiB of unused JavaScript plus unused CSS for a one-field login view. F08 high: Most JavaScript and CSS shipped to the login route is unused. |
be-sustainablethird-party-and-media-budget | pass | high | There are no third-party requests, trackers, video or audio, and only three small image requests. |
be-agent-readystructured-agent-capabilities | not-applicable | high | This sensitive subscriber account portal declares no agent-facing intent, and exposing account actions to agents is not assumed appropriate. |
be-agent-readyon-device-inference | not-applicable | high | The accessible login task has no summarisation, generation or inference use case that would improve completion. |
be-memory-efficientno-leak-under-repeated-interaction | pass | medium | Across independent baseline/post captures, ten real focus/edit/blur cycles increased snapshot self size from 11,843,582 to 12,078,902 bytes (2.0%); in-page JS heap rose about 0.54 MB while DOM stayed at 73 nodes, bounded warm-up rather than evidence of unbounded retention. |
be-memory-efficientbounded-footprint | pass | high | The login view uses about 12 MB JS heap, a 11.8 MB heap-snapshot self-size baseline and 73 rendered DOM elements, proportionate to this Angular login screen. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | medium | DOM count stayed exactly 73 through ten focus/edit/blur cycles and the bounded heap delta gives no evidence of accumulating DOM/listener state under the exercised interaction. |
Provenance
Canonical report: results/atomic/reports/0093-myim3_ioh_co_id.json
Report SHA-256: d400132031a4e5d98b9c4428fa6ea1f8d53f486b6f0c11c5eb8b8def86588004
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/myim3_ioh_co_id/2026-07-27T14-12-30-553Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/myim3_ioh_co_id/2026-07-27T14-12-30-553Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.