Manifest position 314 · CrUX rank bucket 1000

https://myactivity.google.com

Partial after retries

The signed-out landing page was inspected, but 14 of 58 atomic checks require authenticated My Activity surfaces or flows and were blocked by the login boundary. This is not a completed audit.

Attempts
3 / 3
Judged checks
44 / 58
Blocked
14
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighDesktop screenshot under prefers-color-scheme: dark remained white; computed color-scheme was normal.
F1 medium: The signed-out page does not honor the user’s dark color-scheme preference.
respect-user-preferences
respects-reduced-motion
passhighUnder prefers-reduced-motion: reduce the signed-out surface exposed no running animations; no auto-advance or nonessential motion was present.
respect-user-preferences
respects-contrast
passhighThe prefers-contrast: more capture retained visible text, controls, links, and illustration with no missing content.
implement-natural-interactions
view-transitions
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
implement-natural-interactions
scroll-driven-animations
passhighThe signed-out page has no scroll-linked experience, scroll handlers, parallax, or scrollytelling; the 800px mobile layout fits without page scroll.
implement-natural-interactions
physical-gestures
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
provide-guided-navigation
scroll-state-aware-chrome
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
provide-guided-navigation
anchored-positioning
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
provide-guided-navigation
directs-attention
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighDefault desktop and mobile captures show no popup, interstitial, consent wall, or banner obscuring the sign-in content.
maximize-content-reduce-noise
semantic-dismissible-primitives
not-applicablehighNo overlay, disclosure, picker, or rich transient control exists on the signed-out landing page.
maximize-content-reduce-noise
reduced-chrome
passhighThe first viewport is content-first: a compact header, centered explanation and action, and small footer with no heavy framing.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighAt 360x800, scrollWidth, clientWidth and innerWidth were all 360px; horizontal overflow was 0 and viewport meta was present.
adapt-to-the-form-factor
component-level-responsiveness
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
adapt-to-the-form-factor
input-modality-aware
passhighVisible signed-out controls are at least 40px high for primary header targets; Lighthouse target-size audits passed and native links retain keyboard focus behavior.
support-core-task-success
clear-purpose-and-primary-action
passhighThe first viewport says “Welcome to My Activity”, explains the data-management purpose, and presents prominent Sign in actions.
support-core-task-success
primary-flow-completion
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
support-core-task-success
clear-system-state-and-recovery
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse lab LCP was 2.7 s, just outside the good <=2.5 s range; CLS was 0 and TBT 24 ms. A separate raw-CDP trace measured LCP 1.18 s and zero blocking, showing variance but not clearing the slower result.
F2 medium: Mobile lab LCP is outside the good range on a very small signed-out page.
be-fast-and-stable
visual-stability
passhighMobile layout observation reported CLS 0 with no shift entries; Lighthouse also measured CLS 0.
be-fast-and-stable
efficient-main-thread
passhighTrace reported zero long tasks and 0 ms total blocking time; Lighthouse TBT was 24 ms.
be-fast-and-stable
efficient-resource-delivery
issueshighHAR transferred 505,713 bytes; Lighthouse found missing high fetch priority on LCP, font-display delay and a short cache lifetime.
F3 medium: Critical delivery is heavier and less prioritized than the signed-out surface requires.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighLighthouse estimated 159KiB unused JavaScript and 13KiB unused CSS on the static signed-out route.
F4 medium: The signed-out page ships substantial unused JavaScript and CSS.
be-inclusive
names-roles-labels
passhighLighthouse accessible-name/role audits passed; the sole illustration is decorative with empty alt in rendered DOM and controls have names.
be-inclusive
sufficient-contrast
issueshighLighthouse found the inline Learn more link has only 1.23:1 contrast with surrounding text and no non-color distinction.
F5 medium: The inline “Learn more” link is distinguishable only by a low-contrast color difference.
be-inclusive
structure-and-focus
issueshighDOM has no h1 or main landmark and begins with an h2; interactive controls otherwise expose names and native focus behavior.
F7 low: The main page title starts at h2 and there is no h1/main landmark.
be-inclusive
legible-text
passhighDesktop and mobile captures show unclipped, comfortably spaced text with a readable measure and no cramped wrapping.
be-inclusive
zoom-reflow-targets-and-media
issueshighViewport content is user-scalable=no with maximum-scale=1; Lighthouse fails zoom. Mobile reflow itself has no overflow and no media requires captions.
F6 high: The viewport explicitly prevents mobile zoom.
follow-best-practices
no-console-errors
passhighLighthouse best-practices score was 1.0 and did not report console errors or uncaught exceptions.
follow-best-practices
sound-document-and-assets
passhighDocument has HTML doctype, UTF-8 charset, correctly dimensioned 360x200 image, and no aspect-ratio issue; Lighthouse best practices scored 1.0.
follow-best-practices
browser-platform-hygiene
passhighLighthouse best practices scored 1.0 with no deprecated API, vulnerable library, paste-prevention, source-map, or permission-on-load finding. BFCache no-store is proportionate for a privacy-sensitive account property.
be-discoverable
title-and-description
issueshighTitle is descriptive but no meta description exists in rendered or raw content.
F8 low: The public signed-out landing page has no meta description.
be-discoverable
crawlable-and-mobile-friendly
passhighAll visible navigation uses real href links with descriptive text; viewport meta is present. The signed-out page returns 200 and raw content coverage is 100%.
be-discoverable
canonical-and-indexing-signals
passhighMain page returns 200, declares canonical https://myactivity.google.com/, has no accidental noindex, and its absent robots/sitemap endpoints return explicit 404s rather than contradictory rules. Localized variants were not exposed on this signed-out route.
be-discoverable
structured-and-shareable-metadata
not-applicablehighThe signed-out account utility page does not represent an article, product, organization, event, place, or other public rich entity.
be-private-and-secure
secure-transport-and-headers
passhighHTTPS, HSTS, nosniff, SAMEORIGIN, CSP, Trusted Types enforcement and secure cookies are present; no mixed-content or sensitive-secret finding was observed.
be-private-and-secure
data-minimisation-and-third-parties
passhighNo known tracker origin was detected and no sensitive secret was exposed. Five other Google-operated origins loaded supporting assets/services; the scanner’s Google API keys are public client keys, not credentials.
be-private-and-secure
in-context-permissions-and-modern-auth
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
be-private-and-secure
defensive-browser-policies
issueshighCSP/Trusted Types, HSTS, SAMEORIGIN and Permissions-Policy are present, but one script policy allows unsafe-eval and Referrer-Policy is absent.
F9 medium: The signed-out response has avoidable policy gaps.
be-resilient
progressive-enhancement
passhighRaw HTML returned 200 with 100% rendered-word coverage; the crawler screenshot preserves the complete signed-out message and actions without JavaScript.
be-resilient
resilient-runtime-behaviour
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
be-resilient
offline-and-installable
not-applicablehighMy Activity is a private, server-backed account-data tool whose core value depends on authenticated live data; no offline/installability intent was declared and no manifest/service worker exists on the signed-out page.
be-resilient
network-and-http-failure-states
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
be-internationalised
lang-dir-and-logical-properties
passhighThe page declares lang=en-US and dir=ltr; the public copy and reading order are coherent. Authenticated locale variants and authored CSS were not available.
be-internationalised
locale-aware-data
not-applicablehighThe signed-out page renders no dates, numbers, currencies, durations, calendars, or user-entered locale-sensitive data.
be-internationalised
time-zone-correctness
not-applicablehighThe signed-out page renders and accepts no time or event data.
be-trustworthy
no-dark-patterns
passhighThe landing page plainly explains why sign-in is needed, provides direct Privacy and Terms links, and shows no upsell, forced continuity, confirmshaming, or consent wall.
be-trustworthy
humane-error-handling
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
be-trustworthy
trustworthy-input-assistance
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
be-trustworthy
safe-commercial-and-account-flows
blockedhighThe requested URL exposes only a signed-out landing page. The authenticated My Activity application and its stateful controls require credentials that were not available, so this check was attempted through recon/DOM inspection but could not be executed on the core surface.
be-sustainable
optimised-assets
passhighThe only visible image is dimensioned, 10.7KiB transferred, exactly 2x its 360px display width, and not oversized; no media or heavy decorative assets exist.
be-sustainable
no-wasteful-work
issueshighThe small signed-out prompt transfers 505,713 bytes across 22 requests; Lighthouse estimates 159 KiB unused JS and 13 KiB unused CSS.
F10 medium: The public sign-in prompt performs disproportionate background and unused work.
be-sustainable
third-party-and-media-budget
passhighNo audio/video/autoplay exists, no known tracker was found, and supporting non-page-origin bytes are static Google assets; total load is moderate though reducible.
be-agent-ready
structured-agent-capabilities
not-applicablehighThis is a privacy-sensitive authenticated account-data surface with no declared agent-facing intent; exposing capabilities without an explicit authorization design would be inappropriate.
be-agent-ready
on-device-inference
not-applicablehighThe signed-out page has no summarization, generation, or language-processing task that would benefit from on-device inference. Browser API availability alone is not application use.
be-memory-efficient
no-leak-under-repeated-interaction
not-applicablehighThe accessible signed-out page has no representative repeated stateful interaction; the only primary action navigates into credential-gated authentication, so a synthetic loop was not fabricated.
be-memory-efficient
bounded-footprint
passhighBaseline heap summary reported 164,709 nodes, 617,630 edges and 7,406,126 bytes total self size, proportionate and bounded for the loaded Google shell in the observed single state.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumThe baseline heap capture completed without a Detached* population surfaced in its compact summary; no repeated public interaction exists to produce listener/timer accumulation. Confidence is medium because the authenticated long-lived app was inaccessible.

Provenance

Canonical report: results/atomic/reports/0314-myactivity_google_com.json
Report SHA-256: a4439d47a07b1c735a2b01741de134f76ee227a9c60dbc43b6eee08068d79dca
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/myactivity_google_com/2026-07-27T19-49-10-227Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/myactivity_google_com/2026-07-27T19-49-10-227Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.