Manifest position 232 · CrUX rank bucket 1000

https://my.xhsocial.com

Coverage complete

All 58 catalog checks received conclusive outcomes across five representative paths. No local source was provided; critique only.

Attempts
1 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
passhighDark-mode emulation activates a substantial prefers-color-scheme: dark token set and the captured surface remains usable.
respect-user-preferences
respects-reduced-motion
issueshighUnder prefers-reduced-motion: reduce, getAnimations() still reported eight running animations, each with a 2000 ms duration and unbounded iterations.
F01 medium: Reduced-motion preference does not suppress continuous animation
respect-user-preferences
respects-contrast
issueshighLighthouse found 13 contrast failures, including the age-verification banner at 2.15:1 and supporting text at 1.75:1, both below 4.5:1.
F02 high: Important text has insufficient contrast
implement-natural-interactions
view-transitions
issueshighCSS inspection found no view-transition rules or declarations, while navigation is through ordinary cross-document links across the primary listing, category, and detail journey.
F03 low: Route changes have no View Transition treatment
implement-natural-interactions
scroll-driven-animations
not-applicablehighNo scroll-linked animation surface was present; ordinary scrolling is static, so there is no scroll-animation implementation to judge.
implement-natural-interactions
physical-gestures
not-applicablehighNo custom swipe, pull, carousel, or gesture-driven surface was observed on the representative paths.
provide-guided-navigation
scroll-state-aware-chrome
issueshighThe homepage screenshot and 4,528 px content layout show a fixed, dense header/sidebar shell; CSS inspection found no scroll-state or scroll-progress treatment.
F04 low: Long listing chrome does not respond to scroll position
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip or edge-sensitive anchored overlay was opened on the representative paths.
provide-guided-navigation
directs-attention
passhighScreenshots show clear active navigation treatment, page headings, and category grouping that orient the user after navigation.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighDesktop screenshots of the homepage, categories, detail, and signup routes show the same large modal covering most of the first viewport before interaction.
F05 high: Consent modal obscures the primary content on every sampled entry path
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighDOM probes found zero dialog elements and no role=dialog entry despite the visually modal, page-blocking consent surface.
F06 high: The blocking consent UI is not exposed as a semantic dialog
maximize-content-reduce-noise
reduced-chrome
issueshighThe first viewport contains a top navigation row, age banner, sale banner, persistent 190 px sidebar, promotional buttons, and the blocking consent modal, leaving limited room for the content grid.
F07 medium: Promotional chrome competes heavily with content
adapt-to-the-form-factor
responsive-no-horizontal-scroll
issueshighLayout evidence on both homepage and video detail reported scrollWidth/innerWidth 1,038 px against a 360 px visual viewport, producing 678 px horizontal overflow.
F08 critical: The desktop layout is rendered at 1,038 px inside a 360 px viewport
adapt-to-the-form-factor
component-level-responsiveness
issueshighThe CSS feature probe found zero container rules, and the global desktop shell remained 1,038 px wide at a 360 px visual viewport.
F09 medium: Reusable components do not use container-level adaptation
adapt-to-the-form-factor
input-modality-aware
issueshighProgrammatic focus showed outline-style none and zero-width outlines on search, login, and promotion buttons. Lighthouse also found target-size failures, and the probe found many 16–20 px interactive targets.
F10 high: Keyboard focus is invisible on core controls and some targets are too small
support-core-task-success
clear-purpose-and-primary-action
passhighThe homepage H1 identifies trending free videos and cards are immediately linked to detail pages.
support-core-task-success
primary-flow-completion
passhighA homepage video link resolved to a populated video-detail page, demonstrating the representative discovery-to-detail path.
support-core-task-success
clear-system-state-and-recovery
issueshighThe unknown-route test displayed a bare “503 Service Temporarily Unavailable” nginx page with no site navigation, retry, search, or link home.
F11 high: Unknown routes return a raw server error with no recovery path
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse measured LCP 3.8 s, FCP 2.9 s, and Speed Index 4.8 s; the root document alone took 1.76 s in that run.
F12 high: Mobile LCP is outside the good range
be-fast-and-stable
visual-stability
passhighBoth layout captures reported CLS 0 with no observed layout shifts.
be-fast-and-stable
efficient-main-thread
passhighTrace measured two long tasks, 124 ms TBT, and 1.65 s LCP; Lighthouse separately measured 0 ms TBT, indicating bounded main-thread blocking on load.
be-fast-and-stable
efficient-resource-delivery
issueshighThe HAR recorded 143 requests and 1.86 MB transferred, with three VeryHigh parser-inserted stylesheet candidates; Lighthouse measured 1.76 s document response time.
F13 medium: The critical path includes a slow document and multiple parser-discovered styles
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighLighthouse estimated 57 KiB unused CSS, with 87–95% waste in two mobile stylesheets, plus 26 KiB unused JavaScript; HAR shows 61 script requests and about 1.0 MB script transfer.
F14 medium: The first load ships avoidable unused CSS and JavaScript
be-inclusive
names-roles-labels
issueshighLighthouse found two unnamed buttons, two unnamed links, nine label/name mismatches, and a UL containing disallowed direct children; accessibility score was 0.72.
F15 high: Interactive controls and list structure have accessibility-tree failures
be-inclusive
sufficient-contrast
issueshighLighthouse found 13 contrast failures, including the age-verification banner at 2.15:1 and supporting text at 1.75:1, both below 4.5:1.
F02 high: Important text has insufficient contrast
be-inclusive
structure-and-focus
issueshighCore buttons had no visible outline when focused, and Lighthouse found invalid list children and inappropriate role=button on a list item containing links.
F16 high: Focus visibility and semantic reading order are unreliable
be-inclusive
legible-text
passhighMain headings and card text are readable at normal desktop scale with clear typographic hierarchy; specific contrast failures are recorded separately.
be-inclusive
zoom-reflow-targets-and-media
issueshighLighthouse reports user-scalable=no in the effective viewport meta and target-size failures; direct 360 px layout evidence shows 678 px overflow.
F17 high: Zoom is disabled and narrow-screen reflow fails
follow-best-practices
no-console-errors
passhighLighthouse errors-in-console audit passed with zero recorded items.
follow-best-practices
sound-document-and-assets
passhighDOM/Lighthouse confirm HTML5 doctype, UTF-8 charset, and no image aspect-ratio failures.
follow-best-practices
browser-platform-hygiene
passhighLighthouse passed deprecations, BFCache, inspector-issues, and third-party-cookie compatibility audits.
be-discoverable
title-and-description
passhighHomepage and category probes found descriptive, localized titles and meta descriptions.
be-discoverable
crawlable-and-mobile-friendly
passhighReal href links are abundant, robots.txt returned 200 and is parseable, and Lighthouse crawlable-anchor/robots audits passed.
be-discoverable
canonical-and-indexing-signals
issueshighThe Malay page links to more than 40 language hosts, but the DOM had no hreflang links; /sitemap.xml returned 404. The canonical also points from xhsocial.com to xhamster.com, so explicit alternate signals are especially important.
F18 medium: Localized variants lack explicit hreflang and sitemap discovery signals
be-discoverable
structured-and-shareable-metadata
issueshighThe homepage probe found no JSON-LD and no Open Graph metadata despite representing a media catalog with shareable video-detail entities.
F19 medium: Content and organization pages expose no rich/share metadata
be-private-and-secure
secure-transport-and-headers
issueshighCookie evidence found three cookies without Secure, including settings and x_csrf_token; settings also uses SameSite=None. Headers omit X-Content-Type-Options and Referrer-Policy.
F20 high: Cookies and security headers are not consistently hardened
be-private-and-secure
data-minimisation-and-third-parties
issueshighThe initial HAR, captured while the consent modal was still present, recorded 117 third-party-host requests and 1.67 MB transferred, including Google, ad/media hosts, and collector.xhsocial.com.
F21 high: Third-party and analytics traffic begins before the user makes a consent choice
be-private-and-secure
in-context-permissions-and-modern-auth
issueshighThe signup surface exposed email/password, Google, and X choices; no passkey/WebAuthn action was present in the inspected public account flow.
F22 medium: Public authentication choices omit phishing-resistant sign-in
be-private-and-secure
defensive-browser-policies
issueshighThe CSP is only frame-ancestors self; headers also lack nosniff and Referrer-Policy, while Permissions-Policy allows high-entropy UA model/platform-version hints.
F23 high: The Content Security Policy protects only framing
be-resilient
progressive-enhancement
passhighDiscoverability evidence found 87% raw-HTML content coverage, title/H1/description present, and no empty JS shell.
be-resilient
resilient-runtime-behaviour
issueshighThe blocking consent surface has no dialog/popover primitive, making focus, escape, and restoration behavior dependent on custom JavaScript.
F24 medium: The most important overlay relies on custom runtime semantics
be-resilient
offline-and-installable
not-applicablehighStreaming media is intrinsically online; offline playback was judged out of scope. A manifest exists but no service-worker registration was present.
be-resilient
network-and-http-failure-states
issueshighThe representative invalid route produced a raw 503 response with no retry, navigation, or preserved application context.
F25 high: Server failures fall through to an unhelpful nginx page
be-internationalised
lang-dir-and-logical-properties
passhighThe document declares lang=ms and exposes direct language alternatives; Malay correctly uses the default left-to-right direction.
be-internationalised
locale-aware-data
issueshighThe my.xhsocial.com Malay page displays “GB”, “Kategori Terkenal di UK”, and United Kingdom legal text; network recommendation parameters also use locationCountry=gb and clientLanguage=en.
F26 high: The Malay locale is mixed with United Kingdom targeting
be-internationalised
time-zone-correctness
not-applicablehighThe sampled public paths exposed no event scheduling or user-visible date/time calculation to test across time zones.
be-trustworthy
no-dark-patterns
issueshighThe modal says Reject prevents additional cookie purposes, yet the initial load before any choice contacted collector, identity, advertising, and recommendation hosts across 117 third-party-host requests.
F27 medium: Consent copy and pre-consent behavior are inconsistent
be-trustworthy
humane-error-handling
issueshighAfter opening email signup, both email and password controls reported required=false; the visible email and password inputs had no associated label, and email used type=text.
F28 medium: The email sign-up fields lack native constraint semantics and labels
be-trustworthy
trustworthy-input-assistance
issueshighThe public email field is type=text with autocomplete=off; the password uses new-password correctly, but the email control does not expose email autocomplete.
F29 medium: Email signup disables useful autofill semantics
be-trustworthy
safe-commercial-and-account-flows
passhighThe sampled signup surface states that registration is free, exposes terms/privacy, and offers email and federated choices without a paid commitment.
be-sustainable
optimised-assets
issueshighThe image audit found 29 of 36 images without width/height, 14 oversized images, eight below-fold images not lazy-loaded, and 14 legacy-format assets.
F30 medium: Many images lack dimensions or are oversized
be-sustainable
no-wasteful-work
passhighThe load showed only four XHR/fetch requests and no autoplay video element on the homepage; larger third-party transfer is judged separately.
be-sustainable
third-party-and-media-budget
issueshighHAR attribution assigns 1.67 MB of 1.86 MB and 117 of 143 requests to non-page origins; scripts account for about 1.0 MB.
F31 medium: Third-party code dominates the initial transfer
be-agent-ready
structured-agent-capabilities
not-applicablehighNo declared agent-facing intent or transactional agent surface was found; this emerging opportunity is not treated as a failure.
be-agent-ready
on-device-inference
not-applicablehighNo experience on the sampled paths required summarisation or language-model inference; this emerging capability is not applicable.
be-memory-efficient
no-leak-under-repeated-interaction
passhighAfter ten login-modal open/Escape cycles, snapshot totals decreased from 687,026 nodes/36.69 MB to 672,743 nodes/35.80 MB rather than growing.
be-memory-efficient
bounded-footprint
passhighThe homepage snapshot self-size was about 36.7 MB for a media-heavy listing, a proportionate bounded footprint in this capture.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passhighRepeated interaction did not increase total heap nodes or edges; totals declined by 14,283 nodes and 61,901 edges.

Provenance

Canonical report: results/atomic/reports/0232-my_xhsocial_com.json
Report SHA-256: 751424ce3e073d2ddf8473d6720c080d0090d2f7827dde316c0f20fc924f387d
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/my_xhsocial_com/2026-07-19T08-05-38-416Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/my_xhsocial_com/2026-07-19T08-05-38-416Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.