Manifest position 129 · CrUX rank bucket 1000

https://www.instagram.com

Coverage complete

Coverage-complete anonymous-surface audit. Logged-in feed, posting, messaging, checkout/verified purchase and credentialed account completion were excluded because no test account was supplied.

Attempts
2 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
passhighLight resolved to black text/light scheme; dark resolved to #0c1014 with white text and color-scheme:dark.
respect-user-preferences
respects-reduced-motion
passhighThe media query matched and no active animations remained; only short 0.1-0.2s UI transitions were reported.
respect-user-preferences
respects-contrast
passhighControls and text remained visible under forced-colors and prefers-contrast:more.
implement-natural-interactions
view-transitions
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F03
F03 low: Anonymous route changes are abrupt and do not preserve visual continuity.
implement-natural-interactions
scroll-driven-animations
not-applicablehighNo scroll-linked animation was present on the audited anonymous login, profile, signup, or reset surfaces.
implement-natural-interactions
physical-gestures
not-applicablehighNo custom gesture-driven control was present on the audited anonymous surfaces; native scrolling was used.
provide-guided-navigation
scroll-state-aware-chrome
not-applicablehighThe audited short auth surfaces have no meaningful sticky scroll chrome to adapt.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip, popover, or anchored menu was exposed on the audited anonymous surfaces.
provide-guided-navigation
directs-attention
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F04
F04 low: Authentication-route changes provide no visual attention cue.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F01
F01 high: A consent interstitial obscures the entire primary surface on every anonymous path.
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F02
F02 medium: The consent modal is a custom ARIA dialog rather than a native dialog primitive.
maximize-content-reduce-noise
reduced-chrome
passhighOutside the consent layer, the layouts devote most space to the login or profile content with restrained chrome.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighLayout measured scrollWidth=clientWidth=360 and horizontalOverflowPx=0 with viewport metadata present.
adapt-to-the-form-factor
component-level-responsiveness
not-applicablehighNo repeated component was available in independently sized containers; viewport responsiveness was tested directly instead.
adapt-to-the-form-factor
input-modality-aware
passmediumThe representative anonymous login, profile, signup and recovery evidence showed the expected outcome without the anti-pattern targeted by this check.
support-core-task-success
clear-purpose-and-primary-action
passhighThe underlying pages clearly identify Log in, Get started, Find your account, and corresponding primary controls.
support-core-task-success
primary-flow-completion
passhighLogin, account creation, and password recovery routes were reachable with clear links and labelled inputs; no credentialed submission was attempted.
support-core-task-success
clear-system-state-and-recovery
passhighA dedicated password-recovery route and back navigation are exposed; input labels and reset guidance are visible.
be-fast-and-stable
good-core-web-vitals
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F05
F05 high: Largest Contentful Paint is far outside the good range.
be-fast-and-stable
visual-stability
passhighLayout observer measured CLS 0; Lighthouse CLS was 0.059, within the good threshold.
be-fast-and-stable
efficient-main-thread
passhighTrace TBT was 147.88ms with one 197.88ms long task; Lighthouse TBT was 300ms, needing work but not the dominant failure.
be-fast-and-stable
efficient-resource-delivery
passmediumThe representative anonymous login, profile, signup and recovery evidence showed the expected outcome without the anti-pattern targeted by this check.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F06
F06 high: The logged-out shell ships excessive, mostly unused JavaScript.
be-inclusive
names-roles-labels
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F07
F07 high: The cookie dialog has no accessible name.
be-inclusive
sufficient-contrast
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F08
F08 high: Consent-policy links fail WCAG contrast.
be-inclusive
structure-and-focus
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F09
F09 high: Primary login controls do not expose a visible keyboard focus indicator.
be-inclusive
legible-text
passhighBody text uses readable sizing and line length in the desktop dialog, with stable rendering; contrast is recorded separately.
be-inclusive
zoom-reflow-targets-and-media
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F10
F10 high: The viewport caps user zoom below the accessibility baseline.
follow-best-practices
no-console-errors
passhighLighthouse errors-in-console passed with no logged browser errors.
follow-best-practices
sound-document-and-assets
passhighDocument has HTML doctype, UTF-8 charset, responsive viewport; images primitive found no img sizing/alt issues on entry.
follow-best-practices
browser-platform-hygiene
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F11
F11 medium: Deprecated unload handling blocks the back/forward cache.
be-discoverable
title-and-description
passhighEntry page has title Instagram and a descriptive account/login meta description.
be-discoverable
crawlable-and-mobile-friendly
passhighVisible navigation uses real href links, viewport is present, and Lighthouse SEO scored 1.0; crawler policy limitations are recorded separately.
be-discoverable
canonical-and-indexing-signals
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F12
F12 high: Public profile content is effectively absent without JavaScript and generic crawlers are blocked.
be-discoverable
structured-and-shareable-metadata
passhighProfile rendered title/description accurately identify the entity; no misleading structured-data block was found.
be-private-and-secure
secure-transport-and-headers
passhighHTTPS, HSTS, CSP, nosniff and frame denial are present; the CSRF cookie is Secure. Secret scan candidate was investigated and did not yield a usable exposed credential.
be-private-and-secure
data-minimisation-and-third-parties
passhighNo known tracker origin was detected before consent; optional-cookie decline is equally available and network origins were Instagram CDN and Facebook infrastructure.
be-private-and-secure
in-context-permissions-and-modern-auth
passhighNo permission prompt appeared on load; username autocomplete includes webauthn, and Permissions-Policy limits sensitive capabilities to self.
be-private-and-secure
defensive-browser-policies
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F13
F13 medium: The browser policy set is strong but has avoidable XSS/referrer gaps.
be-resilient
progressive-enhancement
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F14
F14 high: The public profile is a JavaScript shell for non-JS clients.
be-resilient
resilient-runtime-behaviour
passhighModal and auth controls remain operable at desktop and 360px without horizontal clipping; recovery navigation is present.
be-resilient
offline-and-installable
passhighThe app-like site exposes a manifest and service-worker capability.
be-resilient
network-and-http-failure-states
passhighRepresentative reset/recovery UI exists and all 49 observed requests completed HTTP 200; no blank or infinite loading state appeared.
be-internationalised
lang-dir-and-logical-properties
passhighhtml lang=en-gb and dir=ltr are set, and 78 hreflang variants include RTL languages.
be-internationalised
locale-aware-data
not-applicablehighThe observed anonymous surfaces show no dates, numbers, currency, or duration values requiring locale formatting.
be-internationalised
time-zone-correctness
not-applicablehighThe observed anonymous surfaces contain no event or time-zone data.
be-trustworthy
no-dark-patterns
passhighAllow all and Decline optional cookies are both plainly labelled and equal-width; pricing/forced continuity is absent on observed routes.
be-trustworthy
humane-error-handling
passhighLogin inputs have explicit labels and users have a dedicated password recovery route; no premature invalid-state blame was shown on load.
be-trustworthy
trustworthy-input-assistance
passhighUsername uses autocomplete="username webauthn" and fields have associated labels.
be-trustworthy
safe-commercial-and-account-flows
passhighAccount creation, Facebook login, password recovery, privacy, terms and contact-upload disclosures are visible before account commitment.
be-sustainable
optimised-assets
passhighTransferred raster imagery was WebP; the images probe found no legacy img formats or oversized img elements on entry.
be-sustainable
no-wasteful-work
passhighOnly one trace long task was observed and no runaway background request loop appeared in the 49-request capture; bundle waste is recorded separately.
be-sustainable
third-party-and-media-budget
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F15
F15 medium: The anonymous entry page uses a disproportionate resource budget.
be-agent-ready
structured-agent-capabilities
not-applicablehighNo developer intent to expose agent actions was declared, and the site explicitly excludes major AI crawler user agents.
be-agent-ready
on-device-inference
not-applicablehighNo summarisation or language-model task is part of the observed anonymous login/profile journey.
be-memory-efficient
no-leak-under-repeated-interaction
passhighHeap self size rose 0.69MB (1.8%) and nodes 1.4% across fresh captures; this does not establish unbounded retained growth.
be-memory-efficient
bounded-footprint
issueshighDirect evidence demonstrates the divergence described by linked finding(s): F16
F16 medium: The login and consent shell has a large in-memory footprint.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passhighNo evidence of unbounded listener/timer behaviour appeared during the repeated interaction window; snapshots are retained for dedicated follow-up analysis.

Provenance

Canonical report: results/atomic/reports/0129-www_instagram_com.json
Report SHA-256: cf2c69f1b3b89c03bd5c6a3addd5fc8a567ea8744cc18bad8c1e89fa6dd7d68f
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_instagram_com/2026-07-25T20-45-21-030Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_instagram_com/2026-07-25T20-45-21-030Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.