Manifest position 129 · CrUX rank bucket 1000
https://www.instagram.com
Coverage complete
Coverage-complete anonymous-surface audit. Logged-in feed, posting, messaging, checkout/verified purchase and credentialed account completion were excluded because no test account was supplied.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | pass | high | Light resolved to black text/light scheme; dark resolved to #0c1014 with white text and color-scheme:dark. |
respect-user-preferencesrespects-reduced-motion | pass | high | The media query matched and no active animations remained; only short 0.1-0.2s UI transitions were reported. |
respect-user-preferencesrespects-contrast | pass | high | Controls and text remained visible under forced-colors and prefers-contrast:more. |
implement-natural-interactionsview-transitions | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F03 F03 low: Anonymous route changes are abrupt and do not preserve visual continuity. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No scroll-linked animation was present on the audited anonymous login, profile, signup, or reset surfaces. |
implement-natural-interactionsphysical-gestures | not-applicable | high | No custom gesture-driven control was present on the audited anonymous surfaces; native scrolling was used. |
provide-guided-navigationscroll-state-aware-chrome | not-applicable | high | The audited short auth surfaces have no meaningful sticky scroll chrome to adapt. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip, popover, or anchored menu was exposed on the audited anonymous surfaces. |
provide-guided-navigationdirects-attention | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F04 F04 low: Authentication-route changes provide no visual attention cue. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F01 F01 high: A consent interstitial obscures the entire primary surface on every anonymous path. |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F02 F02 medium: The consent modal is a custom ARIA dialog rather than a native dialog primitive. |
maximize-content-reduce-noisereduced-chrome | pass | high | Outside the consent layer, the layouts devote most space to the login or profile content with restrained chrome. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | Layout measured scrollWidth=clientWidth=360 and horizontalOverflowPx=0 with viewport metadata present. |
adapt-to-the-form-factorcomponent-level-responsiveness | not-applicable | high | No repeated component was available in independently sized containers; viewport responsiveness was tested directly instead. |
adapt-to-the-form-factorinput-modality-aware | pass | medium | The representative anonymous login, profile, signup and recovery evidence showed the expected outcome without the anti-pattern targeted by this check. |
support-core-task-successclear-purpose-and-primary-action | pass | high | The underlying pages clearly identify Log in, Get started, Find your account, and corresponding primary controls. |
support-core-task-successprimary-flow-completion | pass | high | Login, account creation, and password recovery routes were reachable with clear links and labelled inputs; no credentialed submission was attempted. |
support-core-task-successclear-system-state-and-recovery | pass | high | A dedicated password-recovery route and back navigation are exposed; input labels and reset guidance are visible. |
be-fast-and-stablegood-core-web-vitals | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F05 F05 high: Largest Contentful Paint is far outside the good range. |
be-fast-and-stablevisual-stability | pass | high | Layout observer measured CLS 0; Lighthouse CLS was 0.059, within the good threshold. |
be-fast-and-stableefficient-main-thread | pass | high | Trace TBT was 147.88ms with one 197.88ms long task; Lighthouse TBT was 300ms, needing work but not the dominant failure. |
be-fast-and-stableefficient-resource-delivery | pass | medium | The representative anonymous login, profile, signup and recovery evidence showed the expected outcome without the anti-pattern targeted by this check. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F06 F06 high: The logged-out shell ships excessive, mostly unused JavaScript. |
be-inclusivenames-roles-labels | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F07 F07 high: The cookie dialog has no accessible name. |
be-inclusivesufficient-contrast | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F08 F08 high: Consent-policy links fail WCAG contrast. |
be-inclusivestructure-and-focus | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F09 F09 high: Primary login controls do not expose a visible keyboard focus indicator. |
be-inclusivelegible-text | pass | high | Body text uses readable sizing and line length in the desktop dialog, with stable rendering; contrast is recorded separately. |
be-inclusivezoom-reflow-targets-and-media | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F10 F10 high: The viewport caps user zoom below the accessibility baseline. |
follow-best-practicesno-console-errors | pass | high | Lighthouse errors-in-console passed with no logged browser errors. |
follow-best-practicessound-document-and-assets | pass | high | Document has HTML doctype, UTF-8 charset, responsive viewport; images primitive found no img sizing/alt issues on entry. |
follow-best-practicesbrowser-platform-hygiene | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F11 F11 medium: Deprecated unload handling blocks the back/forward cache. |
be-discoverabletitle-and-description | pass | high | Entry page has title Instagram and a descriptive account/login meta description. |
be-discoverablecrawlable-and-mobile-friendly | pass | high | Visible navigation uses real href links, viewport is present, and Lighthouse SEO scored 1.0; crawler policy limitations are recorded separately. |
be-discoverablecanonical-and-indexing-signals | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F12 F12 high: Public profile content is effectively absent without JavaScript and generic crawlers are blocked. |
be-discoverablestructured-and-shareable-metadata | pass | high | Profile rendered title/description accurately identify the entity; no misleading structured-data block was found. |
be-private-and-securesecure-transport-and-headers | pass | high | HTTPS, HSTS, CSP, nosniff and frame denial are present; the CSRF cookie is Secure. Secret scan candidate was investigated and did not yield a usable exposed credential. |
be-private-and-securedata-minimisation-and-third-parties | pass | high | No known tracker origin was detected before consent; optional-cookie decline is equally available and network origins were Instagram CDN and Facebook infrastructure. |
be-private-and-securein-context-permissions-and-modern-auth | pass | high | No permission prompt appeared on load; username autocomplete includes webauthn, and Permissions-Policy limits sensitive capabilities to self. |
be-private-and-securedefensive-browser-policies | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F13 F13 medium: The browser policy set is strong but has avoidable XSS/referrer gaps. |
be-resilientprogressive-enhancement | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F14 F14 high: The public profile is a JavaScript shell for non-JS clients. |
be-resilientresilient-runtime-behaviour | pass | high | Modal and auth controls remain operable at desktop and 360px without horizontal clipping; recovery navigation is present. |
be-resilientoffline-and-installable | pass | high | The app-like site exposes a manifest and service-worker capability. |
be-resilientnetwork-and-http-failure-states | pass | high | Representative reset/recovery UI exists and all 49 observed requests completed HTTP 200; no blank or infinite loading state appeared. |
be-internationalisedlang-dir-and-logical-properties | pass | high | html lang=en-gb and dir=ltr are set, and 78 hreflang variants include RTL languages. |
be-internationalisedlocale-aware-data | not-applicable | high | The observed anonymous surfaces show no dates, numbers, currency, or duration values requiring locale formatting. |
be-internationalisedtime-zone-correctness | not-applicable | high | The observed anonymous surfaces contain no event or time-zone data. |
be-trustworthyno-dark-patterns | pass | high | Allow all and Decline optional cookies are both plainly labelled and equal-width; pricing/forced continuity is absent on observed routes. |
be-trustworthyhumane-error-handling | pass | high | Login inputs have explicit labels and users have a dedicated password recovery route; no premature invalid-state blame was shown on load. |
be-trustworthytrustworthy-input-assistance | pass | high | Username uses autocomplete="username webauthn" and fields have associated labels. |
be-trustworthysafe-commercial-and-account-flows | pass | high | Account creation, Facebook login, password recovery, privacy, terms and contact-upload disclosures are visible before account commitment. |
be-sustainableoptimised-assets | pass | high | Transferred raster imagery was WebP; the images probe found no legacy img formats or oversized img elements on entry. |
be-sustainableno-wasteful-work | pass | high | Only one trace long task was observed and no runaway background request loop appeared in the 49-request capture; bundle waste is recorded separately. |
be-sustainablethird-party-and-media-budget | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F15 F15 medium: The anonymous entry page uses a disproportionate resource budget. |
be-agent-readystructured-agent-capabilities | not-applicable | high | No developer intent to expose agent actions was declared, and the site explicitly excludes major AI crawler user agents. |
be-agent-readyon-device-inference | not-applicable | high | No summarisation or language-model task is part of the observed anonymous login/profile journey. |
be-memory-efficientno-leak-under-repeated-interaction | pass | high | Heap self size rose 0.69MB (1.8%) and nodes 1.4% across fresh captures; this does not establish unbounded retained growth. |
be-memory-efficientbounded-footprint | issues | high | Direct evidence demonstrates the divergence described by linked finding(s): F16 F16 medium: The login and consent shell has a large in-memory footprint. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | high | No evidence of unbounded listener/timer behaviour appeared during the repeated interaction window; snapshots are retained for dedicated follow-up analysis. |
Provenance
Canonical report: results/atomic/reports/0129-www_instagram_com.json
Report SHA-256: cf2c69f1b3b89c03bd5c6a3addd5fc8a567ea8744cc18bad8c1e89fa6dd7d68f
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_instagram_com/2026-07-25T20-45-21-030Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_instagram_com/2026-07-25T20-45-21-030Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.