Manifest position 297 · CrUX rank bucket 1000

https://accounts.google.com

Partial after retries

Atomic coverage is structurally complete, but 2 checks were blocked by credential requirements and 4 active tests were not run or could not be triggered reliably.

Attempts
3 / 3
Judged checks
52 / 58
Blocked
2
Not run
4
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighThe dark-emulated screenshot is pixel-equivalent in appearance to the light capture, while the DOM reports color-scheme: normal and a white body background. The separate signup route does render dark, showing inconsistent preference support across the account journey.
F01 medium: The sign-in surface ignores the user’s dark color-scheme preference.
respect-user-preferences
respects-reduced-motion
passhighThe reduced-motion probe confirmed the emulated preference and found zero active animations.
respect-user-preferences
respects-contrast
passhighLighthouse contrast passed and the prefers-contrast screenshot retained visible text, input boundaries, and controls.
implement-natural-interactions
view-transitions
not-runhighA successful identifier-to-authentication state transition was not executed because it requires valid credentials; no equivalent safe transition was available in the Lite response.
implement-natural-interactions
scroll-driven-animations
not-applicablehighThe audited identifier and signup forms contain no scroll-linked storytelling, parallax, carousel, or reveal motion.
implement-natural-interactions
physical-gestures
not-applicablehighThe audited forms expose no gesture-driven control or scroll-snap interaction.
provide-guided-navigation
scroll-state-aware-chrome
not-applicablehighThe short, single-task sign-in form has no persistent page chrome whose behavior needs to react to scroll position.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip, popover, context menu, or anchored overlay is present on the audited states.
provide-guided-navigation
directs-attention
passhighDesktop/mobile screenshots show one H1, one outlined input, and one visually dominant Next action in reading order.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighInitial screenshots show the sign-in form immediately with no interstitial, consent wall, popup, or obscuring banner.
maximize-content-reduce-noise
semantic-dismissible-primitives
not-applicablehighNo transient overlay, dialog, disclosure, or rich custom picker is present on the audited states.
maximize-content-reduce-noise
reduced-chrome
passhighThe first viewport is dominated by the task form and explanatory copy; only compact footer links sit outside the form.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighAt 360x800, layout metrics report scrollWidth=clientWidth=360 and 0 horizontal overflow; viewport metadata is present.
adapt-to-the-form-factor
component-level-responsiveness
passhighThe form changes from a bordered centered desktop card to a full-width mobile composition without overflow or clipped controls.
adapt-to-the-form-factor
input-modality-aware
issueshighThe active focus probe found :focus-visible=true on the email input, links, and Next button, but every control computed outline-style:none and box-shadow:none. The focused-link screenshot shows no visible change, and the Lite sign-in DOM has no main landmark.
F02 high: Keyboard focus is not visibly distinguished on the sign-in controls.
support-core-task-success
clear-purpose-and-primary-action
passhighBoth sign-in and signup states state their purpose in an H1 and present one visually dominant Next action.
support-core-task-success
primary-flow-completion
blockedhighA credentialed end-to-end sign-in requires a real Google account and must not be attempted with fabricated credentials.
support-core-task-success
clear-system-state-and-recovery
not-runhighThe synthetic untrusted click did not trigger the production validation flow, so error/success/retry states were not conclusively exercised.
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse measured LCP at 4.3 s and TTI at 6.1 s (performance 0.81). A separate unthrottled trace of the Lite response measured LCP at 0.843 s, so the regression is condition/variant-sensitive rather than universal.
F03 medium: The full sign-in implementation misses the good LCP threshold under Lighthouse throttling.
be-fast-and-stable
visual-stability
passhighLayout observer and Lighthouse both measured CLS 0 with no recorded shifts.
be-fast-and-stable
efficient-main-thread
passhighThe raw trace recorded no >50 ms tasks and 0 ms TBT; Lighthouse TBT remained 193 ms.
be-fast-and-stable
efficient-resource-delivery
issueshighThe HAR shows three document redirects before the identifier page. Lighthouse reports a 686 ms longest network chain, including a 55 KB font, alongside the 4.3 s LCP.
F04 low: Redirect and font/script dependency chains delay the full sign-in render.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighLighthouse estimates 361 KiB of removable JavaScript and 165 KiB of removable CSS; two JavaScript bundles are 64–73% unused in the measured view.
F05 medium: The identifier step ships substantial code not used during initial render.
be-inclusive
names-roles-labels
passhighLighthouse accessibility scored 1.0; label and button-name audits pass, and the Google image has alt text.
be-inclusive
sufficient-contrast
passhighLighthouse color-contrast audit passes and normal/high-contrast screenshots remain legible.
be-inclusive
structure-and-focus
issueshighThe active focus probe found :focus-visible=true on the email input, links, and Next button, but every control computed outline-style:none and box-shadow:none. The focused-link screenshot shows no visible change, and the Lite sign-in DOM has no main landmark.
F02 high: Keyboard focus is not visibly distinguished on the sign-in controls.
be-inclusive
legible-text
passhighDesktop and 320/360 px screenshots show unclipped text, readable line lengths, and clear hierarchy.
be-inclusive
zoom-reflow-targets-and-media
passhighViewport scaling is not disabled, mobile reflow has no horizontal overflow, and the page contains no audio/video requiring alternatives.
follow-best-practices
no-console-errors
passhighLighthouse reports no browser console errors.
follow-best-practices
sound-document-and-assets
passhighDOM/Lighthouse confirm HTML doctype, UTF-8 charset, viewport metadata, and correctly dimensioned image with matching 2x display size.
follow-best-practices
browser-platform-hygiene
passhighLighthouse best-practices scored 1.0; no permission prompts appeared and the bfcache exclusions are security-related no-store/WebAuthn constraints.
be-discoverable
title-and-description
issueshighThe DOM probe and Lighthouse both found a descriptive title but no meta[name=description].
F08 low: The public sign-in entry has no meta description.
be-discoverable
crawlable-and-mobile-friendly
passhighLighthouse confirms crawlable anchors, a valid robots.txt, indexing allowed, and viewport metadata; link labels are descriptive.
be-discoverable
canonical-and-indexing-signals
passhighThe entry and final sign-in documents returned successful/expected redirect statuses, robots.txt allows the page, and no accidental noindex policy was found. A canonical is not appropriate for session-specific authentication continuation URLs.
be-discoverable
structured-and-shareable-metadata
not-applicablehighThe authentication form is not a public article, product, event, organization profile, or other shareable rich entity.
be-private-and-secure
secure-transport-and-headers
passhighHTTPS, HSTS, nosniff, X-Frame-Options:DENY, CSP nonces/Trusted Types, and a Secure HttpOnly __Host- cookie were directly observed.
be-private-and-secure
data-minimisation-and-third-parties
passhighTracker probe found no known tracker domains; HAR recorded only two low-byte third-party requests and secrets scan found no exposed credentials.
be-private-and-secure
in-context-permissions-and-modern-auth
passhighNo on-load permission activity was observed; Lighthouse identifies WebAuthentication API use, corroborating phishing-resistant authentication support.
be-private-and-secure
defensive-browser-policies
issueshighThe headers probe found no Referrer-Policy header and a CSP policy containing unsafe-eval. Strong compensating controls are present, including HSTS, X-Frame-Options:DENY, nosniff, nonces, and require-trusted-types-for script.
F06 medium: The authentication response has gaps in explicit browser-enforced policy.
be-resilient
progressive-enhancement
passhighDiscoverability raw fetch is HTTP 200, not a JS shell, retains title/H1, and exposes 76% of rendered content without JavaScript.
be-resilient
resilient-runtime-behaviour
passhighNo overlays can be clipped, no console/runtime errors were observed, and the simple server-rendered state remained stable.
be-resilient
offline-and-installable
not-applicablehighAuthentication is intrinsically online and should not be installable or claim offline completion.
be-resilient
network-and-http-failure-states
not-runhighOffline and HTTP-failure injection was not run against this live authentication endpoint to avoid disrupting or misrepresenting security-sensitive behavior.
be-internationalised
lang-dir-and-logical-properties
passhighThe DOM declares lang=en-US and dir=ltr, and both sign-in and signup expose a language selector.
be-internationalised
locale-aware-data
not-applicablehighThe audited states display no dates, numbers, currency, duration, or calendar data to localize.
be-internationalised
time-zone-correctness
not-applicablehighThe audited states expose no time or recurring-event concepts.
be-trustworthy
no-dark-patterns
passhighInitial sign-in/signup screenshots show no preselected consent, upsell, continuity trap, disguised ad, or confirmshaming; recovery and account creation are plainly labelled.
be-trustworthy
humane-error-handling
not-runhighThe production validation state could not be triggered reliably with the generic untrusted interaction probe, so timing and accessible announcement were not judged.
be-trustworthy
trustworthy-input-assistance
passhighThe identifier field exposes autocomplete=username and visible Email or phone labelling.
be-trustworthy
safe-commercial-and-account-flows
blockedhighCredentialed sign-in, reauthentication, account management, and cancellation/reversal states require an authorized test account.
be-sustainable
optimised-assets
passhighThe only image is a dimensioned 3.7 KB 2x logo, displayed at exactly half its natural dimensions; no oversized assets were found.
be-sustainable
no-wasteful-work
issueshighLighthouse estimates 361 KiB unused JavaScript and 165 KiB unused CSS on a screen whose core UI is one text field and one primary button.
F07 low: Unused client code adds avoidable transfer, parse, and memory cost to a simple identifier form.
be-sustainable
third-party-and-media-budget
passhighThe Lite HAR transfers 156.6 KB with 5.2 KB third-party bytes and no audio/video/autoplay media.
be-agent-ready
structured-agent-capabilities
not-applicablehighExposing sign-in or account-creation actions as general agent tools would be inappropriate for this sensitive authentication surface; no declared agent-facing intent exists.
be-agent-ready
on-device-inference
not-applicablehighThe deterministic sign-in form has no summarization or language-model task that would benefit from on-device inference.
be-memory-efficient
no-leak-under-repeated-interaction
passmediumAfter ten focus/input/clear/blur cycles, heap self-size changed from 7,936,758 to 7,941,728 bytes (+4,970 bytes, 0.06%), with no unbounded-growth signal.
be-memory-efficient
bounded-footprint
passmediumThe Lite page heap is about 7.94 MB with 178 live DOM elements and 4.77 MB JS heap used, proportionate to the form.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumThe before/after summaries show only +13 native nodes after ten cycles and no Detached* constructor among the reported top constructors.

Provenance

Canonical report: results/atomic/reports/0297-accounts_google_com.json
Report SHA-256: 58bf157b71845783d2a66083b504a3ea48a46b5078f0c37188c8d7af9c448936
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/accounts_google_com/2026-07-27T19-14-23-318Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/accounts_google_com/2026-07-27T19-14-23-318Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.