Manifest position 171 · CrUX rank bucket 1000

https://www.youporn.com

Partial after retries

The requested homepage redirected to a regional login gate. Public login, recovery, support and legal templates were audited, but the primary content and authenticated commercial/account journeys could not be completed.

Attempts
3 / 3
Judged checks
56 / 58
Blocked
2
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighLight and dark emulations rendered the same black surface, the root computed color-scheme was normal, and the DOM probe found no color-scheme or prefers-color-scheme token.
F001 low: The interface is hard-coded dark rather than following the user color-scheme preference.
respect-user-preferences
respects-reduced-motion
passhighBoth conditions reported zero active animations, so no non-essential motion continued against the preference.
respect-user-preferences
respects-contrast
passhighThe forced-colors screenshot retained visible text, fields, outlines and action links.
implement-natural-interactions
view-transitions
issueshighThe DOM probe found no view-transition token and navigation between login, reset, support and privacy is a full abrupt swap.
F002 low: Route changes have no directional or continuity transition.
implement-natural-interactions
scroll-driven-animations
passmediumNo scroll-linked animation was present, and no scroll-animation anti-pattern was observed on the audited public templates.
implement-natural-interactions
physical-gestures
not-applicablehighNo gesture-driven control exists on the reachable public templates.
provide-guided-navigation
scroll-state-aware-chrome
issueshighThe privacy page is over 18,000 CSS px tall in Lighthouse, while probes found no scroll-timeline or scroll-state implementation and the screenshot shows static chrome.
F003 low: Long pages provide no scroll-state-aware navigation aid.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip or transient anchored popover was present.
provide-guided-navigation
directs-attention
issueshighThe public templates use full page swaps and static tab links with no view transition, highlight or post-navigation attention cue.
F004 low: Navigation does not cue where focus or context moved.
maximize-content-reduce-noise
no-intrusive-interruptions
passmediumNo advertising popup or unrelated interstitial appeared; the login gate is the regionally required core surface rather than an incidental interruption.
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighThe login DOM contains one role=dialog and zero dialog elements; the gate is fixed and has no native close/light-dismiss behavior.
F005 medium: The authentication gate uses an ad-hoc ARIA dialog instead of the native dialog primitive.
maximize-content-reduce-noise
reduced-chrome
passmediumThe reachable pages use restrained dark chrome and keep the login form or legal content visually primary.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
issueshighAt 360 px, layout probes measured scrollWidth 990 and 630 px horizontal overflow on both login and support. The support screenshot cuts off inputs and navigation.
F006 critical: Mobile layouts retain a 990 px desktop canvas and clip primary forms.
adapt-to-the-form-factor
component-level-responsiveness
issueshighThe support form is clipped at 360 px and the probe found no container-query tokens on reused form/navigation components.
F007 high: Forms and navigation do not adapt to their available container.
adapt-to-the-form-factor
input-modality-aware
issueshighThe probe found many visible links only 15 to 19 px high across login, privacy and support; focus itself was visible with a 2 px outline.
F008 medium: Many interactive targets are too short for reliable touch use.
support-core-task-success
clear-purpose-and-primary-action
passhighLogin, Forgot Password and Contact Us clearly state purpose and expose one primary action.
support-core-task-success
primary-flow-completion
blockedhighThe homepage redirected to /login/; no credentials were provided and the page states new registrations are unavailable in the audit region.
support-core-task-success
clear-system-state-and-recovery
passhighNative required-field messages appear, and login exposes password/email recovery plus public support links.
be-fast-and-stable
good-core-web-vitals
issueshighMobile Lighthouse measured LCP 5.2 s on login and 4.3 s on privacy, both outside the good range; CLS remained 0.
F009 high: Largest Contentful Paint is slow on primary public pages.
be-fast-and-stable
visual-stability
passhighLogin CLS was 0 and support CLS was 0.0049; Lighthouse reported CLS 0 on login and privacy.
be-fast-and-stable
efficient-main-thread
issueshighThe CDP trace recorded one 554.46 ms long task and 504.46 ms total blocking time in the captured load window.
F010 medium: A long main-thread task blocks the login page.
be-fast-and-stable
efficient-resource-delivery
issueshighHAR signals identified three VeryHigh parser-inserted stylesheets and two synchronous head scripts; the live DOM confirmed TrafficJunky and default-default.js are in head without async, defer or module.
F011 high: Parser-blocking scripts and a long dependency chain delay content.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighThe login transferred 567 KB; 400 KB was script, including 298 KB from two Google Tag Manager resources, for a simple two-field login surface.
F012 medium: Analytics scripts dominate a simple login page payload.
be-inclusive
names-roles-labels
issueshighLighthouse found aria-required-children and listitem failures on the privacy tab list; probes also found visible controls whose accessible naming depends only on image/title or placeholder patterns.
F013 high: Accessibility semantics are invalid or missing on public templates.
be-inclusive
sufficient-contrast
issueshighLighthouse found 16 contrast failures on login and 12 on privacy, including white on #ec567c at 3.39:1 and footer text at 3.17:1.
F014 high: Text and controls repeatedly fail minimum contrast.
be-inclusive
structure-and-focus
issueshighPrivacy starts with H2 headings, includes an empty H4, and Lighthouse reports no main landmark plus an invalid role=tablist child structure. Keyboard focus was visible on the skip link.
F015 high: Heading, landmark and ARIA structure is inconsistent.
be-inclusive
legible-text
issueshighThe 990 px fixed canvas produces 630 px overflow at 360 px; the support and legal templates require sideways navigation, while privacy text uses long dense lines on desktop.
F016 high: Long-form text is clipped and difficult to read on narrow screens.
be-inclusive
zoom-reflow-targets-and-media
issueshighAll probed pages declare user-scalable=0, and mobile layout evidence shows 630 px horizontal overflow.
F017 critical: The viewport disables user scaling and the page fails mobile reflow.
follow-best-practices
no-console-errors
passmediumBoth pages received a 1.0 best-practices category score and no errors-in-console failure was reported.
follow-best-practices
sound-document-and-assets
issueshighThe image probe found three of six images without both dimensions, three without responsive sources and five legacy-format assets.
F018 medium: Image sizing and delivery hygiene are incomplete.
follow-best-practices
browser-platform-hygiene
issueshighLighthouse reported three BFCache failure reasons on both login and privacy.
F019 medium: The pages are not eligible for a clean back-forward cache restore.
be-discoverable
title-and-description
issueshighThe login probe and raw-HTML discoverability result found a descriptive title and H1 but no meta description.
F020 medium: The login page has no meta description.
be-discoverable
crawlable-and-mobile-friendly
issueshigh/robots.txt returns a 301 to /robots.txt/ and ultimately the login HTML; Lighthouse reports 913 robots errors. The viewport also disables scaling.
F021 high: robots.txt is not served as a valid robots file and mobile friendliness is compromised.
be-discoverable
canonical-and-indexing-signals
issueshighCanonical and hreflang links and sitemap.xml are present, but the canonical robots endpoint redirects away instead of returning directives.
F022 high: Indexing signals are internally inconsistent because robots.txt is broken.
be-discoverable
structured-and-shareable-metadata
issueshighThe privacy page exposes zero JSON-LD blocks and no Open Graph tags despite being a public, indexable legal entity page.
F023 low: Public informational pages lack share and structured metadata.
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS and HSTS are present, but CSP and nosniff are missing. PHPSESSID and platform cookies lack Secure; all six observed cookies use SameSite=None and none are HttpOnly.
F024 high: The login surface lacks baseline security headers and sets insecure cookies.
be-private-and-secure
data-minimisation-and-third-parties
issueshighThe tracker probe found 10 third-party origins and Google Analytics, DoubleClick and Tag Manager. HAR attributed 489 KB of 567 KB to third parties.
F025 high: Tracking and third-party collection are disproportionate on the login gate.
be-private-and-secure
in-context-permissions-and-modern-auth
issueshighNo permission prompt fired on load, but the login DOM contains password fields and the probe found no WebAuthn or navigator.credentials implementation.
F026 high: Authentication exposes password-only fields with no passkey path.
be-private-and-secure
defensive-browser-policies
issueshighThe main response has HSTS and X-Frame-Options, but no CSP/frame-ancestors, Referrer-Policy, Permissions-Policy or X-Content-Type-Options.
F027 high: Several browser-enforced defenses are absent.
be-resilient
progressive-enhancement
passhighDiscoverability measured 100% rendered-content coverage in raw HTML, with title and H1 present without JavaScript.
be-resilient
resilient-runtime-behaviour
issueshighAt 360 px, the support select, text fields and top navigation extend beyond the viewport on a 990 px canvas.
F028 high: Primary controls are cut off rather than repositioning at viewport edges.
be-resilient
offline-and-installable
issueshighA manifest and active service worker are registered, but Cache Storage contained no caches after load, providing no evidence of an offline fallback.
F029 medium: The installable shell has no observable offline cache.
be-resilient
network-and-http-failure-states
issueshighA deliberately unknown URL ended at /login/ with the ordinary login page and no 404 or recovery-specific message.
F030 medium: Unknown routes redirect to login instead of explaining the failure.
be-internationalised
lang-dir-and-logical-properties
issueshighPages have lang=en and hreflang variants including Arabic, but probes found physical left/right properties and no logical-property tokens.
F031 medium: Localized routes are advertised but layouts rely on physical CSS.
be-internationalised
locale-aware-data
issueshighThe privacy page renders “April 16th, 2026” while advertising many localized variants; no locale-aware date markup or Intl-driven output was observable.
F032 low: Visible dates are hard-coded in English rather than locale-aware.
be-internationalised
time-zone-correctness
not-applicablehighNo time-zone-sensitive data is rendered in the reachable login, support or legal templates.
be-trustworthy
no-dark-patterns
issueshighThe gate states registrations are unavailable in the region while the underlying page still offers Sign Up; trackers include Analytics and DoubleClick while cookie choice is only a footer link.
F033 medium: The login page presents conflicting account options and runs tracking before a clear consent choice.
be-trustworthy
humane-error-handling
passmediumValidation occurs after submission and uses clear native “Please fill in this field” messages on required controls.
be-trustworthy
trustworthy-input-assistance
issueshighLogin email/password, recovery email and support fields all reported empty autocomplete values.
F034 medium: Authentication and contact fields omit autocomplete tokens.
be-trustworthy
safe-commercial-and-account-flows
blockedhighCancellation categories are publicly findable, but pricing, subscription confirmation and authenticated account-management states require credentials and the regional gate blocks registration.
be-sustainable
optimised-assets
issueshighFive of six images are PNG/GIF, three lack complete dimensions and three lack responsive sources.
F035 medium: Several small assets use legacy formats and lack responsive/intrinsic metadata.
be-sustainable
no-wasteful-work
issueshighTwo Google tag resources transfer 298 KB and tracking spans 10 third-party origins on a simple authentication gate.
F036 medium: The login page performs avoidable analytics work.
be-sustainable
third-party-and-media-budget
issueshighThird-party requests account for 489 KB of 567 KB transferred, with tag-manager scripts the two largest resources.
F037 high: Third parties consume most of the login transfer budget.
be-agent-ready
structured-agent-capabilities
not-applicablehighNo structured agent capability is exposed.
be-agent-ready
on-device-inference
not-applicablehighNo on-device inference use case is present on the reachable templates.
be-memory-efficient
no-leak-under-repeated-interaction
passmediumNode count changed only 162985 to 162997 and self size 7,980,460 to 7,982,195 bytes, with constructor populations effectively stable.
be-memory-efficient
bounded-footprint
passmediumThe heap summary was about 8.0 MB self size and performance.memory used about 7.3 MB for a 274-element DOM, proportionate to this page.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumNo Detached* constructor appeared among retained top constructors, closures stayed at 8857, and only 12 nodes were added after ten repetitions.

Provenance

Canonical report: results/atomic/reports/0171-www_youporn_com.json
Report SHA-256: 1841e2e6fb86d20a367a69b2efb0d75d320232b42ce3c76965db0a3f19b1953d
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_youporn_com/2026-07-27T16-31-25-242Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_youporn_com/2026-07-27T16-31-25-242Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.