Manifest position 195 · CrUX rank bucket 1000

https://vid30s.com

Coverage complete

Atomic coverage complete. The requested host redirects through xpvid.cc and vidoy.com to the audited final origin https://vidoy.asia/.

Attempts
1 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighThe light-preference screenshot is pixel-identical to the default dark page, and :root declares only color-scheme: dark.
F01 medium: Hard-coded dark theme ignores a light system preference
respect-user-preferences
respects-reduced-motion
passhighComputed animation probe under reduce found zero active animations; CSS sets animation and transition duration to 0.01ms.
respect-user-preferences
respects-contrast
issueshighThe prefers-contrast screenshot is unchanged; axe reports white on #fb5d80 at 3:1 for the Login button.
F02 medium: Contrast preference is not honoured and the primary button is below WCAG AA
implement-natural-interactions
view-transitions
issueshighDOM/script inspection finds Turbo and class-based tab swapping but no startViewTransition call, @view-transition rule, or view-transition-name.
F03 low: Route and tab changes do not use View Transitions
implement-natural-interactions
scroll-driven-animations
not-applicablehighNo scroll-linked parallax, scrollytelling, reveal, or carousel motion exists on the audited templates.
implement-natural-interactions
physical-gestures
not-applicablehighNo gesture-driven carousel, swipe, pull-to-refresh, or overscroll interaction exists on the audited public templates.
provide-guided-navigation
scroll-state-aware-chrome
passhighThe templates use minimal non-sticky chrome; mobile content remains oriented by visible Login/Register active state and the legal page has a persistent page heading.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip, popover, menu, or other anchored overlay exists on the audited public templates.
provide-guided-navigation
directs-attention
passhighThe active auth tab has both text and an underline, and the 404 state presents one clear Back action.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighInitial desktop and mobile captures show no popup, interstitial, consent wall, or content-obscuring banner.
maximize-content-reduce-noise
semantic-dismissible-primitives
not-applicablehighNo overlay or disclosure component exists on these public templates, so there is no primitive choice to judge.
maximize-content-reduce-noise
reduced-chrome
passhighThe first viewport is content-first: brand, concise value proposition, and one auth card without competing navigation or decorative frames.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighAt 360x800, layout metrics report scrollWidth/clientWidth 360, horizontalOverflowPx 0, and the mobile screenshot shows a single-column form.
adapt-to-the-form-factor
component-level-responsiveness
issueshighThe CSS probe finds no @container rules; the auth card is adapted exclusively with max/min-width media queries.
F04 low: Reusable auth components rely only on viewport breakpoints
adapt-to-the-form-factor
input-modality-aware
issueshighThe focus probe reports outline none and no focus box-shadow for the auth tabs, submit button, eye button and Create account action; several footer/action links measure 16px high.
F05 high: Several controls have no visible keyboard focus and some targets are only 16px high
support-core-task-success
clear-purpose-and-primary-action
passhighThe first viewport states “Make money by sharing videos” and presents Login/Register as the dominant next actions.
support-core-task-success
primary-flow-completion
issueshighLighthouse captured an uncaught Cloudflare Turnstile Error 110200 while the registration form depends on cf-turnstile-response, making successful completion unreliable.
F06 high: The registration dependency throws during the primary account-creation journey
support-core-task-success
clear-system-state-and-recovery
passhighRequired controls use native validation; the forgot-password journey is explicit, and a 404 shows “Page not found!” with a Back action.
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse measured FCP 4.5s and LCP 8.9s (performance 62); the separate trace still measured LCP 2.95s, showing material run/network sensitivity.
F07 high: Cold-load Largest Contentful Paint is slow
be-fast-and-stable
visual-stability
passhighMobile layout observation reports CLS 0 with no shifts; Lighthouse reports CLS 0.001.
be-fast-and-stable
efficient-main-thread
passhighThe trace reports one 89.7ms long task and 39.7ms TBT; Lighthouse TBT is 140ms, acceptable despite slow network/LCP.
be-fast-and-stable
efficient-resource-delivery
issueshighThe HAR shows vid30s.com -> xpvid.cc -> vidoy.com -> vidoy.asia plus four parser-inserted VeryHigh-priority stylesheets and 1,007,587 transferred bytes.
F08 high: Four redirects and multiple blocking styles delay useful content
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighLighthouse estimates 23,270 of 27,543 bytes of Turbo JavaScript are unused (84.5%), with about 150ms LCP savings.
F09 medium: Most of the Turbo module is unused on the landing page
be-inclusive
names-roles-labels
passhighaxe passes labels, link names, button names, image alt, heading order and main landmarks; the image has meaningful alt text.
be-inclusive
sufficient-contrast
issueshighaxe and Lighthouse both report the Login control at 3:1 instead of the required 4.5:1 for normal-size text.
F10 high: Primary action text does not meet minimum contrast
be-inclusive
structure-and-focus
issueshighThe focus probe finds multiple buttons with outline none and no replacement; axe reports the complementary aside nested inside another landmark.
F11 medium: Focus styling and landmark nesting weaken keyboard and assistive-tech navigation
be-inclusive
legible-text
passhighScreenshots show start-aligned text, bounded line lengths, readable spacing and no clipping on desktop/mobile/legal templates.
be-inclusive
zoom-reflow-targets-and-media
issueshighThe viewport meta includes maximum-scale=1; axe marks this as a critical violation even though 360px reflow itself has no overflow.
F12 critical: The viewport disables user zoom
follow-best-practices
no-console-errors
issueshighLighthouse recorded Uncaught TurnstileError 110200 from challenges.cloudflare.com during load.
F13 medium: The page throws an uncaught Turnstile exception
follow-best-practices
sound-document-and-assets
issueshighThe image probe reports a 1250px PNG rendered at 178px, no srcset, and no height attribute.
F14 medium: The hero image is oversized and incompletely dimensioned
follow-best-practices
browser-platform-hygiene
issueshighLighthouse reports cache-control:no-store with cookie modification and a live Turnstile MediaStreamTrack as actionable BFCache blockers.
F15 low: The page is ineligible for BFCache under common navigation conditions
be-discoverable
title-and-description
issueshighDOM captures show the Terms page uses “Vidoy - Make money by sharing video” and “Login or create your Vidoy creator account,” identical to the landing page.
F16 medium: Distinct pages reuse the login page title and description
be-discoverable
crawlable-and-mobile-friendly
passhighLinks use real href values, viewport metadata exists, robots allows general crawling, and the discoverability probe recovers 98% of content without JS.
be-discoverable
canonical-and-indexing-signals
issueshighNo canonical link is present, sitemap.xml returns 404, and the requested host traverses three other domains before the final page; robots otherwise allows search.
F17 medium: Canonical and sitemap signals are incomplete across a multi-domain redirect chain
be-discoverable
structured-and-shareable-metadata
issueshighThe recon probe finds zero Open Graph tags and zero JSON-LD blocks despite a public branded service landing page.
F18 low: The public organization landing page has no social or structured metadata
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS is used, but the header probe finds no CSP, HSTS, nosniff, clickjacking protection, Referrer-Policy, or Permissions-Policy.
F19 high: Core transport security headers are absent
be-private-and-secure
data-minimisation-and-third-parties
issueshighThe network evidence finds eight third-party origins and loads openfpcdn.io/fingerprintjs before any user action; 19 of 20 requests are classified cross-origin from the requested host.
F20 high: The login page loads a fingerprinting library and a broad third-party footprint by default
be-private-and-secure
in-context-permissions-and-modern-auth
issueshighThe auth DOM exposes username/password forms, while scripts and probes show no WebAuthn/passkey path; this is directly relevant to an account dashboard.
F21 medium: Authentication offers passwords only and no phishing-resistant option
be-private-and-secure
defensive-browser-policies
issueshighThe response lacks HSTS, frame-ancestors/X-Frame-Options, Referrer-Policy and Permissions-Policy; no CSP is available for Trusted Types or script restriction.
F22 high: Browser-enforced defensive policies are not configured
be-resilient
progressive-enhancement
passhighRaw server HTML contains 98% of rendered content, including title, H1 and meta description; crawler view remains complete without JavaScript.
be-resilient
resilient-runtime-behaviour
passhighLogin/Register tab toggling preserves a stable 143-element DOM and the active register form remains a visible 380x528 grid.
be-resilient
offline-and-installable
issueshighThe manifest has display: standalone and start_url /overview, but navigator.serviceWorker.getRegistrations() returns an empty list.
F23 medium: The app advertises installability but has no service worker or offline fallback
be-resilient
network-and-http-failure-states
passhighThe representative unknown route returns a purpose-built error screen with a clear Back recovery action instead of a blank shell.
be-internationalised
lang-dir-and-logical-properties
issueshighhtml lang=en is correct, but dir is absent, no logical CSS property was found, and the probe counts 12 physical left/right rules.
F24 medium: The layout is not prepared for bidirectional or alternate writing modes
be-internationalised
locale-aware-data
not-applicablehighThe audited unauthenticated and legal surfaces render no dates, currencies, durations, or locale-sensitive numeric data beyond a fixed legal update date.
be-internationalised
time-zone-correctness
not-applicablehighThe audited unauthenticated and legal surfaces expose no events, schedules, or time-zone-sensitive values.
be-trustworthy
no-dark-patterns
passhighNo consent nag, disguised ad, preselected upsell or forced continuity appears on the audited public/auth/legal surfaces; terms acceptance is unchecked and explicit.
be-trustworthy
humane-error-handling
passhighForms use required constraints and typed email/password fields; account recovery explains the action and provides a return-to-login path.
be-trustworthy
trustworthy-input-assistance
passhighLogin and registration fields use username, email, current-password and new-password autocomplete tokens appropriately.
be-trustworthy
safe-commercial-and-account-flows
issueshighThe audited public surfaces provide Terms, support and abuse email links but no visible privacy notice, account-deletion route, cancellation flow, or passkey reauthentication path.
F25 medium: Public account terms do not expose key user-control paths
be-sustainable
optimised-assets
issueshighThe 862,424-byte hero PNG is 85.6% of transferred bytes and is rendered at only 178px without responsive alternatives.
F26 high: A single oversized legacy image dominates page weight
be-sustainable
no-wasteful-work
issueshighThe initial page performs four redirects and loads FingerprintJS and Turnstile before the user begins registration.
F27 medium: Default-load work includes avoidable fingerprinting, challenge and redirect overhead
be-sustainable
third-party-and-media-budget
issueshighThe HAR totals about 1.01MB across 20 requests, including an 862KB PNG and requests to eight third-party origins.
F28 high: Third-party and media cost is disproportionate for a simple auth landing page
be-agent-ready
structured-agent-capabilities
not-applicablehighThe audited surface is a gated authentication/legal entry point, not an agent-facing capability surface; no safe public action is available to expose.
be-agent-ready
on-device-inference
not-applicablehighNo summarisation, language-model, or inference use case is present on the audited authentication and legal entry surfaces.
be-memory-efficient
no-leak-under-repeated-interaction
passmediumAfter 20 representative Login/Register toggles, DOM count stayed 143 and sampled heap increased only 47,686 bytes; heap summary growth was about 77KB with stable Object/Array counts.
be-memory-efficient
bounded-footprint
passmediumBaseline heap is proportionate for the simple page at 68,388 snapshot nodes and 3.21MB self size.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumBefore/after heap top constructors contain no Detached* population; repeated toggling did not add DOM nodes, and common Object/Array counts remained unchanged.

Provenance

Canonical report: results/atomic/reports/0195-vid30s_com.json
Report SHA-256: f7b56450fa513f77056a56d47c8d70b08b3377102c7d9cc7fd592e030810c11f
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/vid30s_com/2026-07-19T02-18-26-532Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/vid30s_com/2026-07-19T02-18-26-532Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.