Manifest position 278 · CrUX rank bucket 1000
https://bpexch.live
Coverage complete
Complete atomic audit of the sole unauthenticated archetype. Authenticated exchange routes were not covered because no credentials were supplied.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | Dark and prefers-contrast screenshots are pixel-identical to the default; the CSS probe found no color-scheme, prefers-color-scheme, forced-colors, or prefers-contrast rules. F01 medium: The login surface ignores dark and high-contrast preferences. |
respect-user-preferencesrespects-reduced-motion | issues | high | Under prefers-reduced-motion: reduce, links and the Login button still report 0.4s transitions; no reduced-motion rule exists. F02 low: Transitions remain enabled when reduced motion is requested. |
respect-user-preferencesrespects-contrast | issues | high | Dark and prefers-contrast screenshots are pixel-identical to the default; the CSS probe found no color-scheme, prefers-color-scheme, forced-colors, or prefers-contrast rules. F01 medium: The login surface ignores dark and high-contrast preferences. |
implement-natural-interactionsview-transitions | issues | high | CSS inspection found no view-transition declarations or API use; form state is swapped through conventional DOM/CSS behavior. F21 low: The interactive form has no transition treatment for state changes. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | The login page has no scroll-linked animation or scrollytelling surface. |
implement-natural-interactionsphysical-gestures | not-applicable | high | The login form exposes no gesture-driven or carousel interaction. |
provide-guided-navigationscroll-state-aware-chrome | not-applicable | high | This single fixed login viewport has no scrolling navigation chrome. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip, menu, popover, or positioned overlay is present. |
provide-guided-navigationdirects-attention | pass | high | Default and mobile screenshots present one centered form and a single prominent Login action with no competing navigation. |
maximize-content-reduce-noiseno-intrusive-interruptions | pass | high | Load screenshots and DOM show no popup, banner, consent wall, or full-viewport overlay obscuring the form. |
maximize-content-reduce-noisesemantic-dismissible-primitives | not-applicable | high | No overlay, dialog, disclosure, or rich custom control is present. |
maximize-content-reduce-noisereduced-chrome | pass | high | The first viewport is dominated by the compact login form; only a minimal decorative background and footer line remain. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | At 360x800, layout reported scrollWidth=clientWidth=360, zero overflow, viewport meta present, and the full form remained visible. |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | CSS inspection found no container-type or @container rules, although the card currently fits at 360px. F03 low: The component only adapts through viewport rules, not its container. |
adapt-to-the-form-factorinput-modality-aware | issues | high | Programmatically focusing both inputs and both links produced outline-style none and no box-shadow; the button shadow is always present and is not a distinct focus indicator. F04 high: Keyboard focus is not visibly indicated. |
support-core-task-successclear-purpose-and-primary-action | pass | high | The title and first viewport clearly present username/password entry and one Login button. |
support-core-task-successprimary-flow-completion | issues | high | The DOM and screenshot show only Username, Password, and Login. Both anchors have empty text; one points to #. No forgot-password or account-help action is visible. F05 high: The only public flow is a password login with no visible recovery, registration, help, or cancellation path. |
support-core-task-successclear-system-state-and-recovery | issues | high | Required fields rely only on browser validation with no live status region, while an unknown route returns Chrome’s generic HTTP 404 page with no site navigation or recovery action. F06 medium: Failure and recovery coverage is incomplete. |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse measured LCP 5.2s and TTI 5.2s (performance 0.81). A separate trace measured LCP 1.12s, so the regression is variable but reproducible in the throttled Lighthouse condition. F07 high: Cold-load LCP is slow in Lighthouse. |
be-fast-and-stablevisual-stability | pass | high | Mobile layout observation measured CLS 0.0015625 with one negligible shift. |
be-fast-and-stableefficient-main-thread | pass | high | Trace and layout evidence recorded zero long tasks and 0ms total blocking time. |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR recorded 808,043 transferred bytes, 38 requests, 11 stylesheets, 15 scripts, ten parser-inserted VeryHigh-priority stylesheets, and 328,015 font bytes. F08 medium: A tiny login page has an excessive render-blocking and font payload. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | The DOM/HAR show two jQuery files, two Moment files, plus Select2, daterangepicker, countdowntime, Bootstrap, Popper, WURFL, and UA parser for a two-field form. F09 medium: Duplicate and unrelated libraries are shipped on the login route. |
be-inclusivenames-roles-labels | issues | high | Lighthouse accessibility scored 0.80: the BP image has no alt and its 120px link plus a second href=# link have no discernible name. The form has no explicit visible labels beyond placeholders. F10 high: Key controls and imagery lack accessible names. |
be-inclusivesufficient-contrast | pass | high | Lighthouse color-contrast audit passed and default/high-contrast screenshots keep text and controls legible. |
be-inclusivestructure-and-focus | issues | high | Programmatically focusing both inputs and both links produced outline-style none and no box-shadow; the button shadow is always present and is not a distinct focus indicator. DOM inspection found zero headings and no main/nav/header landmark; focus probes found outline none on all focusable controls. F11 high: The page has no heading or main landmark and no visible focus treatment. F04 high: Keyboard focus is not visibly indicated. |
be-inclusivelegible-text | pass | high | Desktop and mobile screenshots show unclipped 16px field text with ample spacing and no cramped wrapping. |
be-inclusivezoom-reflow-targets-and-media | pass | high | Viewport permits scaling, the 360px layout has no overflow, fields are 45px high, and Login is 50px high; no media requires captions. |
follow-best-practicesno-console-errors | pass | high | Lighthouse errors-in-console audit passed with no logged browser errors. |
follow-best-practicessound-document-and-assets | issues | high | The images primitive reports one image with no width/height, no alt, no srcset, and JPG format; the small observed CLS was 0.0016. F12 low: The logo omits intrinsic dimensions and uses a legacy JPEG. |
follow-best-practicesbrowser-platform-hygiene | pass | high | Lighthouse passed BFCache, deprecations, inspector issues, and third-party-cookie audits; no permission prompt appeared. |
be-discoverabletitle-and-description | pass | high | DOM and raw HTML contain title “BpExch Login” and meta description “BpExch - Web Exchange”. |
be-discoverablecrawlable-and-mobile-friendly | issues | high | The fetched robots.txt contains a later `User-agent: *` and `Disallow: /`, overriding the earlier allow intent for general crawlers. The page itself has no robots meta block. F13 medium: robots.txt ultimately blocks all crawling. |
be-discoverablecanonical-and-indexing-signals | issues | high | DOM inspection found no rel=canonical. The root redirects to /Users/Login, making the preferred URL ambiguous to crawlers. F14 low: The public login has no canonical indexing signal. |
be-discoverablestructured-and-shareable-metadata | not-applicable | high | A private account login is not an article, product, event, or other rich entity needing structured/share metadata. |
be-private-and-securesecure-transport-and-headers | issues | high | Headers evidence found no CSP, HSTS, X-Content-Type-Options, Referrer-Policy, or Permissions-Policy. The AntiForgery.WebExchange cookie is HttpOnly and SameSite=Strict but not Secure. F15 high: The authentication page lacks baseline browser security controls. |
be-private-and-securedata-minimisation-and-third-parties | issues | high | Tracker evidence recorded WURFL and Cloudflare Insights; HAR shows four third-party requests and 15,374 transferred bytes, while no known advertising tracker or exposed secret was found. F16 low: The bare login route contacts unnecessary third parties. |
be-private-and-securein-context-permissions-and-modern-auth | issues | high | The only sign-in controls are username and password; source inspection found no WebAuthn/passkey affordance. No permission prompt occurred on load. F17 medium: Authentication is password-only with no phishing-resistant option. |
be-private-and-securedefensive-browser-policies | issues | high | Headers evidence found no CSP, HSTS, X-Content-Type-Options, Referrer-Policy, or Permissions-Policy. The AntiForgery.WebExchange cookie is HttpOnly and SameSite=Strict but not Secure. F15 high: The authentication page lacks baseline browser security controls. |
be-resilientprogressive-enhancement | pass | high | Discoverability evidence shows the complete login form in raw server HTML and the crawler screenshot matches the browser view; it is not a JS shell. |
be-resilientresilient-runtime-behaviour | pass | high | The only form state uses native required validation; no overlay, asynchronous shell, or fragile positioned menu is present. |
be-resilientoffline-and-installable | not-applicable | high | An authenticated live exchange is intrinsically online; offline transaction capability is not appropriate and no install intent is declared. |
be-resilientnetwork-and-http-failure-states | issues | high | Required fields rely only on browser validation with no live status region, while an unknown route returns Chrome’s generic HTTP 404 page with no site navigation or recovery action. F06 medium: Failure and recovery coverage is incomplete. |
be-internationalisedlang-dir-and-logical-properties | issues | high | The page has html lang=en, but CSS inspection found no logical inline/block properties and no dir declaration. F18 low: The document language is set, but the CSS is not writing-mode resilient. |
be-internationalisedlocale-aware-data | not-applicable | high | The public login displays no dates, numbers, currencies, or durations. |
be-internationalisedtime-zone-correctness | not-applicable | high | The public login displays no time or event data; its hidden UTC offset does not establish a user-visible time flow. |
be-trustworthyno-dark-patterns | pass | high | The public screenshot shows no consent wall, upsell, forced continuity wording, disguised advertisement, or preselected option. |
be-trustworthyhumane-error-handling | pass | high | Both fields validate after submit/reportValidity and expose clear native messages “Please fill in this field.” rather than premature errors. |
be-trustworthytrustworthy-input-assistance | issues | high | The username and password inputs both expose an empty autocomplete value. F19 medium: Sign-in fields omit autocomplete tokens. |
be-trustworthysafe-commercial-and-account-flows | issues | high | The DOM and screenshot show only Username, Password, and Login. Both anchors have empty text; one points to #. No forgot-password or account-help action is visible. The only sign-in controls are username and password; source inspection found no WebAuthn/passkey affordance. No permission prompt occurred on load. F05 high: The only public flow is a password login with no visible recovery, registration, help, or cancellation path. F17 medium: Authentication is password-only with no phishing-resistant option. |
be-sustainableoptimised-assets | issues | high | HAR transferred 808KB, including 328KB of fonts and 50KB of images; the sole content image is JPEG without responsive sources, while numerous decorative/vendor assets load eagerly. F20 medium: The asset budget is disproportionate to the two-field page. |
be-sustainableno-wasteful-work | issues | high | The DOM/HAR show two jQuery files, two Moment files, plus Select2, daterangepicker, countdowntime, Bootstrap, Popper, WURFL, and UA parser for a two-field form. F09 medium: Duplicate and unrelated libraries are shipped on the login route. |
be-sustainablethird-party-and-media-budget | issues | high | Tracker evidence recorded WURFL and Cloudflare Insights; HAR shows four third-party requests and 15,374 transferred bytes, while no known advertising tracker or exposed secret was found. HAR transferred 808KB, including 328KB of fonts and 50KB of images; the sole content image is JPEG without responsive sources, while numerous decorative/vendor assets load eagerly. F16 low: The bare login route contacts unnecessary third parties. F20 medium: The asset budget is disproportionate to the two-field page. |
be-agent-readystructured-agent-capabilities | not-applicable | high | No agent-facing intent is declared for this private authenticated exchange; the emerging capability is an opportunity, not a baseline failure. |
be-agent-readyon-device-inference | not-applicable | high | The two-field login has no summarisation or language-model task that would benefit from on-device inference. |
be-memory-efficientno-leak-under-repeated-interaction | pass | medium | After ten representative focus/input/clear cycles, heap self size rose only 155,812 bytes (1.7%) and closures by 12, consistent with bounded runtime variation rather than unbounded retention. |
be-memory-efficientbounded-footprint | pass | medium | The page has 75 DOM elements, about 4.1MB used JS heap via performance.memory, and an 8.94MB snapshot self-size baseline, proportionate to a small page. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | medium | Neither heap summary lists a Detached* constructor among retained populations; after ten cycles closure count changed only 5,077 to 5,089 and object count 2,555 to 2,580. |
Provenance
Canonical report: results/atomic/reports/0278-bpexch_live.json
Report SHA-256: b37931b4f22913798cb9af6099bdc02c1fd334841a1ab9d28b31c24938e4b429
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/bpexch_live/2026-07-26T03-05-53-367Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/bpexch_live/2026-07-26T03-05-53-367Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.