Manifest position 171 · CrUX rank bucket 1000
https://www.youporn.com
Partial after retries
The requested homepage redirected to a regional login gate. Public login, recovery, support and legal templates were audited, but the primary content and authenticated commercial/account journeys could not be completed.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | Light and dark emulations rendered the same black surface, the root computed color-scheme was normal, and the DOM probe found no color-scheme or prefers-color-scheme token. F001 low: The interface is hard-coded dark rather than following the user color-scheme preference. |
respect-user-preferencesrespects-reduced-motion | pass | high | Both conditions reported zero active animations, so no non-essential motion continued against the preference. |
respect-user-preferencesrespects-contrast | pass | high | The forced-colors screenshot retained visible text, fields, outlines and action links. |
implement-natural-interactionsview-transitions | issues | high | The DOM probe found no view-transition token and navigation between login, reset, support and privacy is a full abrupt swap. F002 low: Route changes have no directional or continuity transition. |
implement-natural-interactionsscroll-driven-animations | pass | medium | No scroll-linked animation was present, and no scroll-animation anti-pattern was observed on the audited public templates. |
implement-natural-interactionsphysical-gestures | not-applicable | high | No gesture-driven control exists on the reachable public templates. |
provide-guided-navigationscroll-state-aware-chrome | issues | high | The privacy page is over 18,000 CSS px tall in Lighthouse, while probes found no scroll-timeline or scroll-state implementation and the screenshot shows static chrome. F003 low: Long pages provide no scroll-state-aware navigation aid. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip or transient anchored popover was present. |
provide-guided-navigationdirects-attention | issues | high | The public templates use full page swaps and static tab links with no view transition, highlight or post-navigation attention cue. F004 low: Navigation does not cue where focus or context moved. |
maximize-content-reduce-noiseno-intrusive-interruptions | pass | medium | No advertising popup or unrelated interstitial appeared; the login gate is the regionally required core surface rather than an incidental interruption. |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | The login DOM contains one role=dialog and zero dialog elements; the gate is fixed and has no native close/light-dismiss behavior. F005 medium: The authentication gate uses an ad-hoc ARIA dialog instead of the native dialog primitive. |
maximize-content-reduce-noisereduced-chrome | pass | medium | The reachable pages use restrained dark chrome and keep the login form or legal content visually primary. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | issues | high | At 360 px, layout probes measured scrollWidth 990 and 630 px horizontal overflow on both login and support. The support screenshot cuts off inputs and navigation. F006 critical: Mobile layouts retain a 990 px desktop canvas and clip primary forms. |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | The support form is clipped at 360 px and the probe found no container-query tokens on reused form/navigation components. F007 high: Forms and navigation do not adapt to their available container. |
adapt-to-the-form-factorinput-modality-aware | issues | high | The probe found many visible links only 15 to 19 px high across login, privacy and support; focus itself was visible with a 2 px outline. F008 medium: Many interactive targets are too short for reliable touch use. |
support-core-task-successclear-purpose-and-primary-action | pass | high | Login, Forgot Password and Contact Us clearly state purpose and expose one primary action. |
support-core-task-successprimary-flow-completion | blocked | high | The homepage redirected to /login/; no credentials were provided and the page states new registrations are unavailable in the audit region. |
support-core-task-successclear-system-state-and-recovery | pass | high | Native required-field messages appear, and login exposes password/email recovery plus public support links. |
be-fast-and-stablegood-core-web-vitals | issues | high | Mobile Lighthouse measured LCP 5.2 s on login and 4.3 s on privacy, both outside the good range; CLS remained 0. F009 high: Largest Contentful Paint is slow on primary public pages. |
be-fast-and-stablevisual-stability | pass | high | Login CLS was 0 and support CLS was 0.0049; Lighthouse reported CLS 0 on login and privacy. |
be-fast-and-stableefficient-main-thread | issues | high | The CDP trace recorded one 554.46 ms long task and 504.46 ms total blocking time in the captured load window. F010 medium: A long main-thread task blocks the login page. |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR signals identified three VeryHigh parser-inserted stylesheets and two synchronous head scripts; the live DOM confirmed TrafficJunky and default-default.js are in head without async, defer or module. F011 high: Parser-blocking scripts and a long dependency chain delay content. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | The login transferred 567 KB; 400 KB was script, including 298 KB from two Google Tag Manager resources, for a simple two-field login surface. F012 medium: Analytics scripts dominate a simple login page payload. |
be-inclusivenames-roles-labels | issues | high | Lighthouse found aria-required-children and listitem failures on the privacy tab list; probes also found visible controls whose accessible naming depends only on image/title or placeholder patterns. F013 high: Accessibility semantics are invalid or missing on public templates. |
be-inclusivesufficient-contrast | issues | high | Lighthouse found 16 contrast failures on login and 12 on privacy, including white on #ec567c at 3.39:1 and footer text at 3.17:1. F014 high: Text and controls repeatedly fail minimum contrast. |
be-inclusivestructure-and-focus | issues | high | Privacy starts with H2 headings, includes an empty H4, and Lighthouse reports no main landmark plus an invalid role=tablist child structure. Keyboard focus was visible on the skip link. F015 high: Heading, landmark and ARIA structure is inconsistent. |
be-inclusivelegible-text | issues | high | The 990 px fixed canvas produces 630 px overflow at 360 px; the support and legal templates require sideways navigation, while privacy text uses long dense lines on desktop. F016 high: Long-form text is clipped and difficult to read on narrow screens. |
be-inclusivezoom-reflow-targets-and-media | issues | high | All probed pages declare user-scalable=0, and mobile layout evidence shows 630 px horizontal overflow. F017 critical: The viewport disables user scaling and the page fails mobile reflow. |
follow-best-practicesno-console-errors | pass | medium | Both pages received a 1.0 best-practices category score and no errors-in-console failure was reported. |
follow-best-practicessound-document-and-assets | issues | high | The image probe found three of six images without both dimensions, three without responsive sources and five legacy-format assets. F018 medium: Image sizing and delivery hygiene are incomplete. |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse reported three BFCache failure reasons on both login and privacy. F019 medium: The pages are not eligible for a clean back-forward cache restore. |
be-discoverabletitle-and-description | issues | high | The login probe and raw-HTML discoverability result found a descriptive title and H1 but no meta description. F020 medium: The login page has no meta description. |
be-discoverablecrawlable-and-mobile-friendly | issues | high | /robots.txt returns a 301 to /robots.txt/ and ultimately the login HTML; Lighthouse reports 913 robots errors. The viewport also disables scaling. F021 high: robots.txt is not served as a valid robots file and mobile friendliness is compromised. |
be-discoverablecanonical-and-indexing-signals | issues | high | Canonical and hreflang links and sitemap.xml are present, but the canonical robots endpoint redirects away instead of returning directives. F022 high: Indexing signals are internally inconsistent because robots.txt is broken. |
be-discoverablestructured-and-shareable-metadata | issues | high | The privacy page exposes zero JSON-LD blocks and no Open Graph tags despite being a public, indexable legal entity page. F023 low: Public informational pages lack share and structured metadata. |
be-private-and-securesecure-transport-and-headers | issues | high | HTTPS and HSTS are present, but CSP and nosniff are missing. PHPSESSID and platform cookies lack Secure; all six observed cookies use SameSite=None and none are HttpOnly. F024 high: The login surface lacks baseline security headers and sets insecure cookies. |
be-private-and-securedata-minimisation-and-third-parties | issues | high | The tracker probe found 10 third-party origins and Google Analytics, DoubleClick and Tag Manager. HAR attributed 489 KB of 567 KB to third parties. F025 high: Tracking and third-party collection are disproportionate on the login gate. |
be-private-and-securein-context-permissions-and-modern-auth | issues | high | No permission prompt fired on load, but the login DOM contains password fields and the probe found no WebAuthn or navigator.credentials implementation. F026 high: Authentication exposes password-only fields with no passkey path. |
be-private-and-securedefensive-browser-policies | issues | high | The main response has HSTS and X-Frame-Options, but no CSP/frame-ancestors, Referrer-Policy, Permissions-Policy or X-Content-Type-Options. F027 high: Several browser-enforced defenses are absent. |
be-resilientprogressive-enhancement | pass | high | Discoverability measured 100% rendered-content coverage in raw HTML, with title and H1 present without JavaScript. |
be-resilientresilient-runtime-behaviour | issues | high | At 360 px, the support select, text fields and top navigation extend beyond the viewport on a 990 px canvas. F028 high: Primary controls are cut off rather than repositioning at viewport edges. |
be-resilientoffline-and-installable | issues | high | A manifest and active service worker are registered, but Cache Storage contained no caches after load, providing no evidence of an offline fallback. F029 medium: The installable shell has no observable offline cache. |
be-resilientnetwork-and-http-failure-states | issues | high | A deliberately unknown URL ended at /login/ with the ordinary login page and no 404 or recovery-specific message. F030 medium: Unknown routes redirect to login instead of explaining the failure. |
be-internationalisedlang-dir-and-logical-properties | issues | high | Pages have lang=en and hreflang variants including Arabic, but probes found physical left/right properties and no logical-property tokens. F031 medium: Localized routes are advertised but layouts rely on physical CSS. |
be-internationalisedlocale-aware-data | issues | high | The privacy page renders “April 16th, 2026” while advertising many localized variants; no locale-aware date markup or Intl-driven output was observable. F032 low: Visible dates are hard-coded in English rather than locale-aware. |
be-internationalisedtime-zone-correctness | not-applicable | high | No time-zone-sensitive data is rendered in the reachable login, support or legal templates. |
be-trustworthyno-dark-patterns | issues | high | The gate states registrations are unavailable in the region while the underlying page still offers Sign Up; trackers include Analytics and DoubleClick while cookie choice is only a footer link. F033 medium: The login page presents conflicting account options and runs tracking before a clear consent choice. |
be-trustworthyhumane-error-handling | pass | medium | Validation occurs after submission and uses clear native “Please fill in this field” messages on required controls. |
be-trustworthytrustworthy-input-assistance | issues | high | Login email/password, recovery email and support fields all reported empty autocomplete values. F034 medium: Authentication and contact fields omit autocomplete tokens. |
be-trustworthysafe-commercial-and-account-flows | blocked | high | Cancellation categories are publicly findable, but pricing, subscription confirmation and authenticated account-management states require credentials and the regional gate blocks registration. |
be-sustainableoptimised-assets | issues | high | Five of six images are PNG/GIF, three lack complete dimensions and three lack responsive sources. F035 medium: Several small assets use legacy formats and lack responsive/intrinsic metadata. |
be-sustainableno-wasteful-work | issues | high | Two Google tag resources transfer 298 KB and tracking spans 10 third-party origins on a simple authentication gate. F036 medium: The login page performs avoidable analytics work. |
be-sustainablethird-party-and-media-budget | issues | high | Third-party requests account for 489 KB of 567 KB transferred, with tag-manager scripts the two largest resources. F037 high: Third parties consume most of the login transfer budget. |
be-agent-readystructured-agent-capabilities | not-applicable | high | No structured agent capability is exposed. |
be-agent-readyon-device-inference | not-applicable | high | No on-device inference use case is present on the reachable templates. |
be-memory-efficientno-leak-under-repeated-interaction | pass | medium | Node count changed only 162985 to 162997 and self size 7,980,460 to 7,982,195 bytes, with constructor populations effectively stable. |
be-memory-efficientbounded-footprint | pass | medium | The heap summary was about 8.0 MB self size and performance.memory used about 7.3 MB for a 274-element DOM, proportionate to this page. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | medium | No Detached* constructor appeared among retained top constructors, closures stayed at 8857, and only 12 nodes were added after ten repetitions. |
Provenance
Canonical report: results/atomic/reports/0171-www_youporn_com.json
Report SHA-256: 1841e2e6fb86d20a367a69b2efb0d75d320232b42ce3c76965db0a3f19b1953d
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_youporn_com/2026-07-27T16-31-25-242Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_youporn_com/2026-07-27T16-31-25-242Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.