Manifest position 299 · CrUX rank bucket 1000
https://www.mediafire.com
Coverage complete
Coverage-complete public-site audit across five representative paths. Authenticated file management, destructive upload completion, payment submission, and account creation were intentionally not covered.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | Under emulated prefers-color-scheme: dark, the body remained rgb(255,255,255), color-scheme computed to normal, and the dark screenshot was visually identical to light. F01 medium: Dark preference is ignored. |
respect-user-preferencesrespects-reduced-motion | issues | high | With prefers-reduced-motion: reduce active, getAnimations() still reported the 4,000 ms buttonPulse animation running. F02 medium: Reduced-motion preference does not stop non-essential pulsing. |
respect-user-preferencesrespects-contrast | pass | high | The prefers-contrast screenshot retained visible text and controls, and Lighthouse color-contrast passed. |
implement-natural-interactionsview-transitions | issues | high | CSS/platform inspection found no view-transition rules while primary navigation uses ordinary cross-document links. F03 low: Route changes use abrupt full-document swaps. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No scroll-linked animation is present, so there is no implementation to judge. |
implement-natural-interactionsphysical-gestures | not-applicable | high | No gesture-driven carousel, swipe, pull, or snap interaction is present on representative public paths. |
provide-guided-navigationscroll-state-aware-chrome | issues | high | The mobile landing page is 11,442 px tall, but CSS inspection found no scroll-state, progress, or sticky position feedback. F04 low: The very long landing page offers no position-aware navigation. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip or edge-positioned anchored popover is exposed on the representative public paths. |
provide-guided-navigationdirects-attention | pass | high | Headings, direct CTA labels, and page-specific content visibly orient users on the tested paths. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | Desktop and mobile screenshots show a fixed consent banner covering the lower 90-190 px, including pricing CTA content and login secondary actions. F06 medium: The cookie banner obscures primary content on every tested entry state. |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | DOM inspection found two div role=dialog elements with manual onclick dismissal and iframe content; no dialog or popover primitives were used. F05 medium: Overlays are hand-built divs rather than platform primitives. |
maximize-content-reduce-noisereduced-chrome | pass | high | Outside the consent overlay, screenshots show content-led layouts with restrained header chrome. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | issues | high | At 360x800, pricing and about layout captures reported scrollWidth 370 vs clientWidth 360, a 10 px horizontal overflow. F07 medium: Two representative templates overflow the mobile viewport. |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | Loaded CSS inspection found zero @container rules and zero logical sizing patterns despite cards and controls being reused across templates. F08 low: Reusable components depend only on viewport-era CSS. |
adapt-to-the-form-factorinput-modality-aware | issues | high | Geometry probe found footer and policy links only 15-21 px tall, below a comfortable touch target, though keyboard focus on the main CTA was visible. F09 low: Several visible links have undersized touch boxes. |
support-core-task-successclear-purpose-and-primary-action | pass | high | The first viewport clearly states file storage/sharing and exposes the Upload Files Now primary action. |
support-core-task-successprimary-flow-completion | issues | high | The CTA href says /upgrade/, its form action is /trial_account_signup.php, and activating it opens an invisible reCAPTCHA instead of a file picker or clearly explained signup step. F10 high: The primary “Upload Files Now” action hides an account/captcha detour. |
support-core-task-successclear-system-state-and-recovery | issues | high | A real HTTP 404 displays only a JavaScript history Back link and instructions to contact the administrator; there is no home, search, or relevant destination CTA, and the title remains generic. F11 medium: The 404 state provides weak recovery. |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse measured LCP 12.2 s, TBT 350 ms, and time-to-interactive 12.4 s (performance 0.62); the independent trace measured FCP/LCP 2.82 s and one 120 ms task. F12 high: Lab loading performance misses the LCP and responsiveness bar. |
be-fast-and-stablevisual-stability | pass | high | Lighthouse CLS was 0; mobile home CLS was 0 and login only 0.0077. |
be-fast-and-stableefficient-main-thread | issues | high | Lighthouse measured LCP 12.2 s, TBT 350 ms, and time-to-interactive 12.4 s (performance 0.62); the independent trace measured FCP/LCP 2.82 s and one 120 ms task. F12 high: Lab loading performance misses the LCP and responsiveness bar. |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR recorded 79 requests and 1.60 MB transferred, including 1.34 MB of script; parser-blocking jQuery 1.7.2 and reCAPTCHA plus three blocking stylesheets were confirmed in the DOM. F13 high: Critical delivery is dominated by scripts and blocking legacy resources. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | Lighthouse estimated 707 KiB unused JavaScript and 90 KiB unused CSS; the HAR shows repeated analytics/tag-manager payloads among the largest resources. F14 medium: The page ships substantial unused code. |
be-inclusivenames-roles-labels | pass | high | Lighthouse accessibility scored 1.00; link names passed and all audited images had alt text. |
be-inclusivesufficient-contrast | pass | high | Lighthouse color-contrast passed with no failing nodes. |
be-inclusivestructure-and-focus | issues | high | DOM inspection found a visible logo H1 with no text plus the actual page H1; Lighthouse otherwise reported accessibility 1.00 and logical heading order. F15 low: Heading semantics include an empty visible H1 alongside the content H1. |
be-inclusivelegible-text | pass | high | Screenshots show readable line lengths, spacing, and unclipped primary copy across desktop/mobile paths. |
be-inclusivezoom-reflow-targets-and-media | pass | high | Viewport allows scaling, key forms reflow at 360 px, and no required audio/video media is present. |
follow-best-practicesno-console-errors | pass | high | Lighthouse errors-in-console audit passed with zero items. |
follow-best-practicessound-document-and-assets | pass | high | DOM has HTML doctype/UTF-8, Lighthouse image aspect-ratio passed, and the image probe found no missing alt text. |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse found three deprecated API warnings, three BFCache failure reasons, two large scripts without valid source maps, and an inspector issue. F16 medium: Platform hygiene is dated and blocks browser optimisations. |
be-discoverabletitle-and-description | issues | high | The About page and real 404 both report “File sharing and storage made simple”; About also reuses the generic homepage meta description. F17 medium: Distinct public pages reuse the homepage title and description. |
be-discoverablecrawlable-and-mobile-friendly | pass | high | Viewport and robots audits passed; raw content is crawlable, with one isolated javascript history link confined to the 404. |
be-discoverablecanonical-and-indexing-signals | issues | high | The homepage has no canonical link and /sitemap.xml returns HTTP 404, while robots.txt permits the public site. F18 medium: Canonical and sitemap signals are incomplete. |
be-discoverablestructured-and-shareable-metadata | issues | high | Open Graph metadata is present, but no JSON-LD or other schema.org data was found on the organization homepage. F19 low: Organization metadata is shareable but not structured. |
be-private-and-securesecure-transport-and-headers | issues | high | HTTPS is used, but HSTS is max-age=0, CSP only declares frame-ancestors, nosniff/referrer/permissions policies are absent, and 9 cookies were flagged insecure including ukey without Secure. F20 high: Transport hardening and cookie flags are materially weak. |
be-private-and-securedata-minimisation-and-third-parties | issues | high | The tracker probe found 17 third-party origins and six known trackers; HAR attributed 61 requests and 1.56 MB to third parties while the consent banner was still visible. F21 high: Tracking starts before meaningful consent and dominates transfer cost. |
be-private-and-securein-context-permissions-and-modern-auth | issues | high | The login page exposes email/password and social providers but no passkey/WebAuthn flow; password autocomplete is explicitly off. F22 medium: Authentication is password/social-only and disables password-manager hints. |
be-private-and-securedefensive-browser-policies | issues | high | HTTPS is used, but HSTS is max-age=0, CSP only declares frame-ancestors, nosniff/referrer/permissions policies are absent, and 9 cookies were flagged insecure including ukey without Secure. F20 high: Transport hardening and cookie flags are materially weak. |
be-resilientprogressive-enhancement | pass | high | Discoverability measured 100% raw/rendered word coverage, title/H1/description present without JS, and no JS shell. |
be-resilientresilient-runtime-behaviour | issues | high | DOM inspection found two div role=dialog elements with manual onclick dismissal and iframe content; no dialog or popover primitives were used. F05 medium: Overlays are hand-built divs rather than platform primitives. |
be-resilientoffline-and-installable | issues | high | No web app manifest was linked and no service worker controlled the page; the product promotes ongoing file access across devices. F23 medium: The app-like storage service has no install/offline surface. |
be-resilientnetwork-and-http-failure-states | issues | high | A real HTTP 404 displays only a JavaScript history Back link and instructions to contact the administrator; there is no home, search, or relevant destination CTA, and the title remains generic. F11 medium: The 404 state provides weak recovery. |
be-internationalisedlang-dir-and-logical-properties | issues | high | The site exposes a large language selector and lang=en-US, but loaded CSS used physical left/right properties and zero logical properties. F24 medium: The translated surface is not bidirectionally robust. |
be-internationalisedlocale-aware-data | issues | high | Pricing displays $5.83/month and $6.99 month-to-month while offering hundreds of languages, with no locale/currency alternative visible. F25 medium: Commercial data is hard-coded to US dollars. |
be-internationalisedtime-zone-correctness | not-applicable | high | The representative public marketing, pricing, login, and information pages expose no dates, events, or time-zone-sensitive data. |
be-trustworthyno-dark-patterns | issues | high | The banner says continued use means agreement, offers “I Accept” and a dismiss X but no reject/manage option, while tracker evidence confirms analytics already fires. F26 high: Consent uses implied acceptance with no equivalent reject choice. |
be-trustworthyhumane-error-handling | pass | high | Invalid login email invoked clear native browser validation before submission. |
be-trustworthytrustworthy-input-assistance | issues | high | The email field has no autocomplete token and the password field sets autocomplete=off, despite being a standard sign-in form. F27 medium: Sign-in obstructs autofill. |
be-trustworthysafe-commercial-and-account-flows | pass | high | Pricing visibly states monthly/annual amounts, cancellation, and a money-back guarantee before purchase. |
be-sustainableoptimised-assets | pass | high | Image transfer was only 85 KB; seven of eight img resources are SVG and all meaningful images have alt text. |
be-sustainableno-wasteful-work | issues | high | Six tracker families execute on load; third-party transfers total 1.56 MB and include overlapping Google tags, Hotjar, Amplitude, DoubleClick and Cloudflare analytics. F28 medium: Background analytics work is disproportionate to the landing page. |
be-sustainablethird-party-and-media-budget | issues | high | Six tracker families execute on load; third-party transfers total 1.56 MB and include overlapping Google tags, Hotjar, Amplitude, DoubleClick and Cloudflare analytics. F28 medium: Background analytics work is disproportionate to the landing page. |
be-agent-readystructured-agent-capabilities | not-applicable | high | No declared agent-facing capability exists on MediaFire itself; links to separate AI products do not make this site an agent-tool surface. |
be-agent-readyon-device-inference | not-applicable | high | No summarisation or inference use case is presented on the representative MediaFire surfaces. |
be-memory-efficientno-leak-under-repeated-interaction | pass | high | After 10 open/close help interactions, heap totals decreased from 29.94 MB/553,705 nodes to 29.72 MB/540,760 nodes. |
be-memory-efficientbounded-footprint | pass | high | Heap snapshot was about 30 MB on the script-heavy landing page and remained bounded after interaction. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | high | The repeated help interaction produced no retained node/heap growth; totals decreased in the post snapshot. |
Provenance
Canonical report: results/atomic/reports/0299-www_mediafire_com.json
Report SHA-256: 4b68526eb924dc7e166606e9c76502c67bf203494b258f8d809d06ddb48a3223
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_mediafire_com/2026-07-19T19-25-06-002Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_mediafire_com/2026-07-19T19-25-06-002Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.