Manifest position 93 · CrUX rank bucket 1000

https://myim3.ioh.co.id

Partial after retries

The public login surface and adverse conditions were judged, but end-to-end account and commercial flows remain blocked by subscriber number and OTP authentication. No authorized test account was provided.

Attempts
3 / 3
Judged checks
56 / 58
Blocked
2
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighThe dark capture is identical to default; color-scheme is normal and no dark media rule exists
F01 medium: The login experience ignores the requested dark color scheme.
respect-user-preferences
respects-reduced-motion
passhighNo active animations were present, and the stylesheet contains explicit reduced-motion rules that disable transitions.
respect-user-preferences
respects-contrast
passhighUnder forced-colors: active, browser colors adapt and all text, the field border and the Continue control remain visible. Normal-scheme WCAG contrast failures are recorded separately under be-inclusive.
implement-natural-interactions
view-transitions
issuesmediumThe language change navigated the document and no view-transition CSS or API use was found.
F03 low: The language/state navigation has no declared transition treatment.
implement-natural-interactions
scroll-driven-animations
not-applicablehighThe accessible login view has no scroll-linked animation, parallax, scrollytelling or reveal effect to implement declaratively.
implement-natural-interactions
physical-gestures
not-applicablehighThe accessible login view has no swipe, pull, drag, carousel or other physical gesture surface.
provide-guided-navigation
scroll-state-aware-chrome
not-applicablehighThe login page fits in one viewport and has no sticky or affixed scroll chrome.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip, popover or menu is exposed on the accessible login view.
provide-guided-navigation
directs-attention
passmediumThe single login view keeps one heading, one field and one primary button in reading order, so the next step is visually unambiguous.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighNo popup, interstitial, consent wall or banner obscures the login form on load.
maximize-content-reduce-noise
semantic-dismissible-primitives
not-applicablehighNo overlay or disclosure control is present on the accessible login view.
maximize-content-reduce-noise
reduced-chrome
passhighThe viewport is almost entirely task content with no application frame, side rail, decorative panel or competing chrome.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighBoth viewports have zero horizontal overflow and the form fluidly changes width.
adapt-to-the-form-factor
component-level-responsiveness
not-applicablemediumThe accessible page exposes one fixed-context login form, not a component reused in materially different containers.
adapt-to-the-form-factor
input-modality-aware
issueshighFocus outlines are absent and language controls are far below 44x44 CSS pixels.
F04 high: Keyboard focus is invisible and language targets are too small.
support-core-task-success
clear-purpose-and-primary-action
passhighThe Indonesian heading states that an IM3 number is needed to log in, followed immediately by the labelled phone field and Continue action.
support-core-task-success
primary-flow-completion
blockedhighEnd-to-end completion requires a valid IM3 subscriber number and OTP. No test account or authorization was supplied, so proceeding could message a real subscriber.
support-core-task-success
clear-system-state-and-recovery
issueshighA short invalid value leaves Continue disabled but produces no visible or announced reason or recovery instruction.
F05 high: Invalid phone input gives no actionable state or accessible error.
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse LCP is 9.18 s and trace LCP is 4.02 s; both exceed the 2.5 s good threshold. CLS and blocking time are separately judged.
F06 high: The throttled Largest Contentful Paint is far outside the good range.
be-fast-and-stable
visual-stability
passhighObserved CLS was 0.0145 mobile and 0.0072 desktop, both comfortably below 0.1.
be-fast-and-stable
efficient-main-thread
passhighThe trace recorded zero long tasks and zero blocking time; both layout captures also recorded no long tasks.
be-fast-and-stable
efficient-resource-delivery
issueshighThe login load transfers 1.93 MB, including 1.61 MB scripts and 211 KB fonts; major document and JavaScript resources are uncompressed.
F07 high: The small login screen downloads a heavy, inefficient application payload.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighLighthouse estimates about 1,042 KiB unused JS and 69 KiB unused CSS on the one-field login route.
F08 high: Most JavaScript and CSS shipped to the login route is unused.
be-inclusive
names-roles-labels
issueshighThe form is labelled, but decorative images expose alt="." rather than empty alternative text.
F09 medium: Decorative images expose punctuation as alternative text.
be-inclusive
sufficient-contrast
issueshighFour visible text elements fail 4.5:1, with measured ratios from 3.49:1 to 4.31:1.
F10 high: Four visible text elements fail WCAG AA contrast.
be-inclusive
structure-and-focus
issueshighThere is no main landmark or h1, heading order skips levels, and focused controls have no visible outline or shadow.
F11 high: The login document lacks semantic structure and visible focus.
be-inclusive
legible-text
issueshighSmall gray helper copy is only 12px and 3.49:1 against white, reducing reading comfort.
F12 medium: Supporting text is visually weak at small sizes.
be-inclusive
zoom-reflow-targets-and-media
issueshighuser-scalable=no and maximum-scale=1 disable zoom, and language controls are undersized.
F13 critical: The viewport explicitly prevents user zoom.
F04 high: Keyboard focus is invisible and language targets are too small.
follow-best-practices
no-console-errors
issueshighThe page throws ReferenceError: Swiper is not defined from the production scripts bundle.
F14 medium: A production script throws an uncaught Swiper reference error.
follow-best-practices
sound-document-and-assets
issueshighDoctype and charset are valid, but the rendered phone-prefix image has no intrinsic width/height.
F15 low: An inline SVG image has no intrinsic dimensions.
follow-best-practices
browser-platform-hygiene
issueshighThe large first-party vendor bundle has no valid source map; no deprecation or BFCache failures were observed.
F16 medium: Large production JavaScript has no source map.
be-discoverable
title-and-description
passhighThe raw and rendered documents include title “myIM3” and a descriptive Indonesian meta description.
be-discoverable
crawlable-and-mobile-friendly
issueshighLanguage anchors use javascript:void(), and robots.txt returns a NoSuchKey storage error; mobile layout itself reflows.
F17 medium: Navigation controls are not crawlable links and robots.txt is missing.
be-discoverable
canonical-and-indexing-signals
issueshighThe document is HTTP 200 but has no canonical or hreflang, while robots.txt and sitemap.xml are missing.
F18 medium: Public indexing signals are incomplete.
be-discoverable
structured-and-shareable-metadata
not-applicablemediumThis private account login screen does not present an article, product, event or rich public entity requiring schema.org or social-preview data.
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS, HSTS and secure cookie posture pass, but CSP is absent and a reusable hdrAuthorization value is embedded in public JavaScript.
F19 high: The authentication client lacks CSP and embeds a reusable authorization value in its public bundle.
be-private-and-secure
data-minimisation-and-third-parties
passhighThe login load makes only first-party requests, sets no cookies, loads no known trackers, and explains that the phone number is needed for verification.
be-private-and-secure
in-context-permissions-and-modern-auth
issuesmediumNo permission is requested on load, but the accessible account entry exposes phone OTP only and no passkey/WebAuthn option.
F20 medium: The account entry offers phone OTP only, with no phishing-resistant option.
be-private-and-secure
defensive-browser-policies
issueshighHSTS, nosniff and SAMEORIGIN are present; CSP, Referrer-Policy and Permissions-Policy are absent.
F21 medium: Several browser-enforced defensive policies are absent.
be-resilient
progressive-enhancement
issueshighWithout JavaScript, the login form disappears and only an enable-JavaScript message remains; content coverage is 6%.
F22 high: The login flow is unusable without JavaScript.
be-resilient
resilient-runtime-behaviour
passmediumThe accessible form remains stable through focus/edit/blur cycles, has no clipped overlays, no long tasks and no DOM growth.
be-resilient
offline-and-installable
passhighA manifest and active service worker are present, and an offline reload continues to render the login shell.
be-resilient
network-and-http-failure-states
issueshighAn unknown path produces a raw NoSuchKey XML error without navigation or recovery.
F23 medium: Unknown paths expose a raw storage error with no recovery.
be-internationalised
lang-dir-and-logical-properties
issueshighVisible selected content is Indonesian while html lang is en; CSS has extensive physical left/right declarations and zero logical property matches.
F24 medium: Language metadata and CSS do not match the visible locale or support bidirectional layout.
be-internationalised
locale-aware-data
not-applicablehighThe accessible login view displays no dates, numbers, currencies, durations or calendars requiring locale formatting.
be-internationalised
time-zone-correctness
not-applicablehighThe accessible login view handles no events, schedules, dates or times.
be-trustworthy
no-dark-patterns
passmediumThe accessible entry asks only for the phone number needed for verification, explains why, and shows no preselected upsell, nagging consent or disguised action.
be-trustworthy
humane-error-handling
issueshighAfter user interaction the invalid field provides no specific visible or announced feedback.
F05 high: Invalid phone input gives no actionable state or accessible error.
be-trustworthy
trustworthy-input-assistance
issueshighThe sign-in telephone field explicitly sets autocomplete=off.
F25 medium: The phone field disables useful browser input assistance.
be-trustworthy
safe-commercial-and-account-flows
blockedhighPricing, cancellation, sensitive account actions and reauthentication exist behind a valid subscriber number and OTP; no authorized test account was supplied.
be-sustainable
optimised-assets
passhighThe visible imagery is tiny, not oversized, and totals about 25 KB; the main visual prefix is SVG.
be-sustainable
no-wasteful-work
issueshighThe route downloads over 1 MiB of unused JavaScript plus unused CSS for a one-field login view.
F08 high: Most JavaScript and CSS shipped to the login route is unused.
be-sustainable
third-party-and-media-budget
passhighThere are no third-party requests, trackers, video or audio, and only three small image requests.
be-agent-ready
structured-agent-capabilities
not-applicablehighThis sensitive subscriber account portal declares no agent-facing intent, and exposing account actions to agents is not assumed appropriate.
be-agent-ready
on-device-inference
not-applicablehighThe accessible login task has no summarisation, generation or inference use case that would improve completion.
be-memory-efficient
no-leak-under-repeated-interaction
passmediumAcross independent baseline/post captures, ten real focus/edit/blur cycles increased snapshot self size from 11,843,582 to 12,078,902 bytes (2.0%); in-page JS heap rose about 0.54 MB while DOM stayed at 73 nodes, bounded warm-up rather than evidence of unbounded retention.
be-memory-efficient
bounded-footprint
passhighThe login view uses about 12 MB JS heap, a 11.8 MB heap-snapshot self-size baseline and 73 rendered DOM elements, proportionate to this Angular login screen.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumDOM count stayed exactly 73 through ten focus/edit/blur cycles and the bounded heap delta gives no evidence of accumulating DOM/listener state under the exercised interaction.

Provenance

Canonical report: results/atomic/reports/0093-myim3_ioh_co_id.json
Report SHA-256: d400132031a4e5d98b9c4428fa6ea1f8d53f486b6f0c11c5eb8b8def86588004
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/myim3_ioh_co_id/2026-07-27T14-12-30-553Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/myim3_ioh_co_id/2026-07-27T14-12-30-553Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.