Manifest position 232 · CrUX rank bucket 1000
https://my.xhsocial.com
Coverage complete
All 58 catalog checks received conclusive outcomes across five representative paths. No local source was provided; critique only.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | pass | high | Dark-mode emulation activates a substantial prefers-color-scheme: dark token set and the captured surface remains usable. |
respect-user-preferencesrespects-reduced-motion | issues | high | Under prefers-reduced-motion: reduce, getAnimations() still reported eight running animations, each with a 2000 ms duration and unbounded iterations. F01 medium: Reduced-motion preference does not suppress continuous animation |
respect-user-preferencesrespects-contrast | issues | high | Lighthouse found 13 contrast failures, including the age-verification banner at 2.15:1 and supporting text at 1.75:1, both below 4.5:1. F02 high: Important text has insufficient contrast |
implement-natural-interactionsview-transitions | issues | high | CSS inspection found no view-transition rules or declarations, while navigation is through ordinary cross-document links across the primary listing, category, and detail journey. F03 low: Route changes have no View Transition treatment |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No scroll-linked animation surface was present; ordinary scrolling is static, so there is no scroll-animation implementation to judge. |
implement-natural-interactionsphysical-gestures | not-applicable | high | No custom swipe, pull, carousel, or gesture-driven surface was observed on the representative paths. |
provide-guided-navigationscroll-state-aware-chrome | issues | high | The homepage screenshot and 4,528 px content layout show a fixed, dense header/sidebar shell; CSS inspection found no scroll-state or scroll-progress treatment. F04 low: Long listing chrome does not respond to scroll position |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip or edge-sensitive anchored overlay was opened on the representative paths. |
provide-guided-navigationdirects-attention | pass | high | Screenshots show clear active navigation treatment, page headings, and category grouping that orient the user after navigation. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | Desktop screenshots of the homepage, categories, detail, and signup routes show the same large modal covering most of the first viewport before interaction. F05 high: Consent modal obscures the primary content on every sampled entry path |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | DOM probes found zero dialog elements and no role=dialog entry despite the visually modal, page-blocking consent surface. F06 high: The blocking consent UI is not exposed as a semantic dialog |
maximize-content-reduce-noisereduced-chrome | issues | high | The first viewport contains a top navigation row, age banner, sale banner, persistent 190 px sidebar, promotional buttons, and the blocking consent modal, leaving limited room for the content grid. F07 medium: Promotional chrome competes heavily with content |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | issues | high | Layout evidence on both homepage and video detail reported scrollWidth/innerWidth 1,038 px against a 360 px visual viewport, producing 678 px horizontal overflow. F08 critical: The desktop layout is rendered at 1,038 px inside a 360 px viewport |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | The CSS feature probe found zero container rules, and the global desktop shell remained 1,038 px wide at a 360 px visual viewport. F09 medium: Reusable components do not use container-level adaptation |
adapt-to-the-form-factorinput-modality-aware | issues | high | Programmatic focus showed outline-style none and zero-width outlines on search, login, and promotion buttons. Lighthouse also found target-size failures, and the probe found many 16–20 px interactive targets. F10 high: Keyboard focus is invisible on core controls and some targets are too small |
support-core-task-successclear-purpose-and-primary-action | pass | high | The homepage H1 identifies trending free videos and cards are immediately linked to detail pages. |
support-core-task-successprimary-flow-completion | pass | high | A homepage video link resolved to a populated video-detail page, demonstrating the representative discovery-to-detail path. |
support-core-task-successclear-system-state-and-recovery | issues | high | The unknown-route test displayed a bare “503 Service Temporarily Unavailable” nginx page with no site navigation, retry, search, or link home. F11 high: Unknown routes return a raw server error with no recovery path |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse measured LCP 3.8 s, FCP 2.9 s, and Speed Index 4.8 s; the root document alone took 1.76 s in that run. F12 high: Mobile LCP is outside the good range |
be-fast-and-stablevisual-stability | pass | high | Both layout captures reported CLS 0 with no observed layout shifts. |
be-fast-and-stableefficient-main-thread | pass | high | Trace measured two long tasks, 124 ms TBT, and 1.65 s LCP; Lighthouse separately measured 0 ms TBT, indicating bounded main-thread blocking on load. |
be-fast-and-stableefficient-resource-delivery | issues | high | The HAR recorded 143 requests and 1.86 MB transferred, with three VeryHigh parser-inserted stylesheet candidates; Lighthouse measured 1.76 s document response time. F13 medium: The critical path includes a slow document and multiple parser-discovered styles |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | Lighthouse estimated 57 KiB unused CSS, with 87–95% waste in two mobile stylesheets, plus 26 KiB unused JavaScript; HAR shows 61 script requests and about 1.0 MB script transfer. F14 medium: The first load ships avoidable unused CSS and JavaScript |
be-inclusivenames-roles-labels | issues | high | Lighthouse found two unnamed buttons, two unnamed links, nine label/name mismatches, and a UL containing disallowed direct children; accessibility score was 0.72. F15 high: Interactive controls and list structure have accessibility-tree failures |
be-inclusivesufficient-contrast | issues | high | Lighthouse found 13 contrast failures, including the age-verification banner at 2.15:1 and supporting text at 1.75:1, both below 4.5:1. F02 high: Important text has insufficient contrast |
be-inclusivestructure-and-focus | issues | high | Core buttons had no visible outline when focused, and Lighthouse found invalid list children and inappropriate role=button on a list item containing links. F16 high: Focus visibility and semantic reading order are unreliable |
be-inclusivelegible-text | pass | high | Main headings and card text are readable at normal desktop scale with clear typographic hierarchy; specific contrast failures are recorded separately. |
be-inclusivezoom-reflow-targets-and-media | issues | high | Lighthouse reports user-scalable=no in the effective viewport meta and target-size failures; direct 360 px layout evidence shows 678 px overflow. F17 high: Zoom is disabled and narrow-screen reflow fails |
follow-best-practicesno-console-errors | pass | high | Lighthouse errors-in-console audit passed with zero recorded items. |
follow-best-practicessound-document-and-assets | pass | high | DOM/Lighthouse confirm HTML5 doctype, UTF-8 charset, and no image aspect-ratio failures. |
follow-best-practicesbrowser-platform-hygiene | pass | high | Lighthouse passed deprecations, BFCache, inspector-issues, and third-party-cookie compatibility audits. |
be-discoverabletitle-and-description | pass | high | Homepage and category probes found descriptive, localized titles and meta descriptions. |
be-discoverablecrawlable-and-mobile-friendly | pass | high | Real href links are abundant, robots.txt returned 200 and is parseable, and Lighthouse crawlable-anchor/robots audits passed. |
be-discoverablecanonical-and-indexing-signals | issues | high | The Malay page links to more than 40 language hosts, but the DOM had no hreflang links; /sitemap.xml returned 404. The canonical also points from xhsocial.com to xhamster.com, so explicit alternate signals are especially important. F18 medium: Localized variants lack explicit hreflang and sitemap discovery signals |
be-discoverablestructured-and-shareable-metadata | issues | high | The homepage probe found no JSON-LD and no Open Graph metadata despite representing a media catalog with shareable video-detail entities. F19 medium: Content and organization pages expose no rich/share metadata |
be-private-and-securesecure-transport-and-headers | issues | high | Cookie evidence found three cookies without Secure, including settings and x_csrf_token; settings also uses SameSite=None. Headers omit X-Content-Type-Options and Referrer-Policy. F20 high: Cookies and security headers are not consistently hardened |
be-private-and-securedata-minimisation-and-third-parties | issues | high | The initial HAR, captured while the consent modal was still present, recorded 117 third-party-host requests and 1.67 MB transferred, including Google, ad/media hosts, and collector.xhsocial.com. F21 high: Third-party and analytics traffic begins before the user makes a consent choice |
be-private-and-securein-context-permissions-and-modern-auth | issues | high | The signup surface exposed email/password, Google, and X choices; no passkey/WebAuthn action was present in the inspected public account flow. F22 medium: Public authentication choices omit phishing-resistant sign-in |
be-private-and-securedefensive-browser-policies | issues | high | The CSP is only frame-ancestors self; headers also lack nosniff and Referrer-Policy, while Permissions-Policy allows high-entropy UA model/platform-version hints. F23 high: The Content Security Policy protects only framing |
be-resilientprogressive-enhancement | pass | high | Discoverability evidence found 87% raw-HTML content coverage, title/H1/description present, and no empty JS shell. |
be-resilientresilient-runtime-behaviour | issues | high | The blocking consent surface has no dialog/popover primitive, making focus, escape, and restoration behavior dependent on custom JavaScript. F24 medium: The most important overlay relies on custom runtime semantics |
be-resilientoffline-and-installable | not-applicable | high | Streaming media is intrinsically online; offline playback was judged out of scope. A manifest exists but no service-worker registration was present. |
be-resilientnetwork-and-http-failure-states | issues | high | The representative invalid route produced a raw 503 response with no retry, navigation, or preserved application context. F25 high: Server failures fall through to an unhelpful nginx page |
be-internationalisedlang-dir-and-logical-properties | pass | high | The document declares lang=ms and exposes direct language alternatives; Malay correctly uses the default left-to-right direction. |
be-internationalisedlocale-aware-data | issues | high | The my.xhsocial.com Malay page displays “GB”, “Kategori Terkenal di UK”, and United Kingdom legal text; network recommendation parameters also use locationCountry=gb and clientLanguage=en. F26 high: The Malay locale is mixed with United Kingdom targeting |
be-internationalisedtime-zone-correctness | not-applicable | high | The sampled public paths exposed no event scheduling or user-visible date/time calculation to test across time zones. |
be-trustworthyno-dark-patterns | issues | high | The modal says Reject prevents additional cookie purposes, yet the initial load before any choice contacted collector, identity, advertising, and recommendation hosts across 117 third-party-host requests. F27 medium: Consent copy and pre-consent behavior are inconsistent |
be-trustworthyhumane-error-handling | issues | high | After opening email signup, both email and password controls reported required=false; the visible email and password inputs had no associated label, and email used type=text. F28 medium: The email sign-up fields lack native constraint semantics and labels |
be-trustworthytrustworthy-input-assistance | issues | high | The public email field is type=text with autocomplete=off; the password uses new-password correctly, but the email control does not expose email autocomplete. F29 medium: Email signup disables useful autofill semantics |
be-trustworthysafe-commercial-and-account-flows | pass | high | The sampled signup surface states that registration is free, exposes terms/privacy, and offers email and federated choices without a paid commitment. |
be-sustainableoptimised-assets | issues | high | The image audit found 29 of 36 images without width/height, 14 oversized images, eight below-fold images not lazy-loaded, and 14 legacy-format assets. F30 medium: Many images lack dimensions or are oversized |
be-sustainableno-wasteful-work | pass | high | The load showed only four XHR/fetch requests and no autoplay video element on the homepage; larger third-party transfer is judged separately. |
be-sustainablethird-party-and-media-budget | issues | high | HAR attribution assigns 1.67 MB of 1.86 MB and 117 of 143 requests to non-page origins; scripts account for about 1.0 MB. F31 medium: Third-party code dominates the initial transfer |
be-agent-readystructured-agent-capabilities | not-applicable | high | No declared agent-facing intent or transactional agent surface was found; this emerging opportunity is not treated as a failure. |
be-agent-readyon-device-inference | not-applicable | high | No experience on the sampled paths required summarisation or language-model inference; this emerging capability is not applicable. |
be-memory-efficientno-leak-under-repeated-interaction | pass | high | After ten login-modal open/Escape cycles, snapshot totals decreased from 687,026 nodes/36.69 MB to 672,743 nodes/35.80 MB rather than growing. |
be-memory-efficientbounded-footprint | pass | high | The homepage snapshot self-size was about 36.7 MB for a media-heavy listing, a proportionate bounded footprint in this capture. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | high | Repeated interaction did not increase total heap nodes or edges; totals declined by 14,283 nodes and 61,901 edges. |
Provenance
Canonical report: results/atomic/reports/0232-my_xhsocial_com.json
Report SHA-256: 751424ce3e073d2ddf8473d6720c080d0090d2f7827dde316c0f20fc924f387d
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/my_xhsocial_com/2026-07-19T08-05-38-416Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/my_xhsocial_com/2026-07-19T08-05-38-416Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.