Manifest position 322 · CrUX rank bucket 1000

https://cdn.33apk.com

Coverage complete

Atomic coverage complete. The host is a genuine single-page static infrastructure disclaimer; external surveza.ai legal documents were not treated as templates of cdn.33apk.com.

Attempts
1 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighThe dark-mode screenshot is pixel-identical in layout and palette to the light capture; the computed CSS probe found no color-scheme, prefers-color-scheme, or light-dark() support.
F01 medium: The page ignores the user’s dark color-scheme preference.
respect-user-preferences
respects-reduced-motion
passhighThe page has no active animations and no auto-advance, so there is no non-essential motion to suppress.
respect-user-preferences
respects-contrast
issueshighThe prefers-contrast: more capture preserves the normal palette, while axe measures the secondary 12 px text at only 4.11:1.
F18 medium: High-contrast preference does not improve already marginal text contrast.
implement-natural-interactions
view-transitions
passmediumThe only interactions are native navigation/mail links; there is no abrupt same-document state swap or same-site route transition, and no custom JavaScript transition work.
implement-natural-interactions
scroll-driven-animations
not-applicablehighNo parallax, scrollytelling, entry reveal, carousel, or other scroll-linked motion exists.
implement-natural-interactions
physical-gestures
not-applicablehighNo gesture-driven control or scroll-snap surface exists; only ordinary links are interactive.
provide-guided-navigation
scroll-state-aware-chrome
not-applicablehighThe single static view has no persistent navigation chrome or long-form position-dependent control.
provide-guided-navigation
anchored-positioning
not-applicablehighThere are no tooltips, popovers, or menus to anchor.
provide-guided-navigation
directs-attention
passmediumThe single view has a clear two-column reading order, visibly underlined links, and a prominent support contact; there are no in-page jumps or moved-focus states needing additional cues.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighNo pop-up, interstitial, consent wall, or content-obscuring banner appears on load.
maximize-content-reduce-noise
semantic-dismissible-primitives
not-applicablehighNo overlay, disclosure, custom select, or dismissible rich control exists.
maximize-content-reduce-noise
reduced-chrome
passhighThe card is content-led, with minimal navigation and no competing application frame.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighMobile scrollWidth equals clientWidth (360 px), horizontal overflow is 0, and content reflows to one column.
adapt-to-the-form-factor
component-level-responsiveness
not-applicablemediumNo component is reused in differently sized parent containers; the single page layout adapts adequately through its one viewport breakpoint.
adapt-to-the-form-factor
input-modality-aware
issueshighThe focused Terms link computed to outline-style none and no box shadow; the stylesheet includes :focus { outline: 0 } and a:hover/a:active outline removal without a :focus-visible replacement.
F02 high: Keyboard focus is deliberately removed from links.
support-core-task-success
clear-purpose-and-primary-action
passhighThe opening text clearly states the domain purpose and responsibility; support contact is prominent.
support-core-task-success
primary-flow-completion
passmediumThe only primary action is contacting support, exposed as a direct mailto link; legal-policy links have real hrefs.
support-core-task-success
clear-system-state-and-recovery
not-applicablehighThe root is a static informational document with no loading, submission, empty, partial-completion, or success state.
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse measured LCP at 2.8 s (good is at most 2.5 s) and FCP at 2.5 s, while the first-party trace measured LCP 1.15 s on an unthrottled run.
F03 medium: Mobile LCP misses the good Core Web Vitals threshold.
be-fast-and-stable
visual-stability
passhighObserved CLS was 0.006 desktop and 0.041 mobile, both within the good threshold.
be-fast-and-stable
efficient-main-thread
passhighTrace and both layout runs found zero long tasks; TBT was 0 ms.
be-fast-and-stable
efficient-resource-delivery
issueshighHAR identified three parser-inserted VeryHigh-priority stylesheets; DOM confirms they are synchronous head links. Lighthouse estimates 1,740 ms render-blocking savings and 76 KiB cache savings.
F04 medium: Render-blocking styles and a remote font delay first render.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighYandex Metrika tag.js transfers about 90 KiB, 58% of the entire 156 KiB load; Lighthouse reports about 47 KiB unused JavaScript.
F05 medium: Analytics dominates JavaScript delivery on a static disclaimer page.
be-inclusive
names-roles-labels
issueshighaxe reports a critical image-alt violation for body > img; the image primitive also found the injected 1×1 GIF without alt.
F06 high: A dynamically injected tracking image has no text alternative or presentational role.
be-inclusive
sufficient-contrast
issueshighaxe found nine 12 px text/link nodes at #7d7d7d on white with a 4.11:1 ratio, below the required 4.5:1.
F07 high: Small gray body text fails WCAG AA contrast.
be-inclusive
structure-and-focus
issueshighThe DOM probe found no h1-h6 elements; axe flags page-has-heading-one, and the focus probe found outline-style none.
F08 high: The page has no heading structure and keyboard focus is invisible.
be-inclusive
legible-text
passmediumText wraps without clipping at 360 px and uses a readable family and line layout; contrast is assessed separately and fails its dedicated check.
be-inclusive
zoom-reflow-targets-and-media
issueshighReflow has no overflow and scaling is permitted, but link focus is invisible and compact policy links lack robust target treatment.
F02 high: Keyboard focus is deliberately removed from links.
follow-best-practices
no-console-errors
passmediumLighthouse did not report console errors or uncaught exceptions, and all first-party content rendered.
follow-best-practices
sound-document-and-assets
issueshighLighthouse flags unsized images and the image primitive reports missing width/height on the logo and injected tracking image; a measured mobile CLS of 0.041 corroborates small late movement.
F09 low: Images lack explicit intrinsic dimensions.
follow-best-practices
browser-platform-hygiene
issueshighLighthouse’s inspector-issues audit scored 0; the same run also reports third-party-cookie issues associated with the tracking stack.
F10 low: Chrome reports inspector issues during load.
be-discoverable
title-and-description
issueshighThe title is only “Surveza” and there is no meta description; Lighthouse fails meta-description.
F11 medium: Search metadata does not describe the page.
be-discoverable
crawlable-and-mobile-friendly
passhighAll visible links have real hrefs, link text is descriptive, a viewport meta exists, and no robots directive blocks indexing.
be-discoverable
canonical-and-indexing-signals
issueshighThe page returns 200 and is indexable, but the probe found no canonical; /robots.txt and /sitemap.xml both return generic nginx 404 pages.
F12 medium: The public page lacks canonical, robots, and sitemap signals.
be-discoverable
structured-and-shareable-metadata
issueshighThe probe found zero Open Graph tags and zero JSON-LD blocks despite the page representing the Surveza organization and infrastructure purpose.
F13 low: The organization/disclaimer page has no share preview or structured metadata.
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS and nosniff are present, but CSP, clickjacking protection, Referrer-Policy, and Permissions-Policy are absent; HSTS is only max-age=1.
F14 high: Browser security policy headers are materially incomplete.
be-private-and-secure
data-minimisation-and-third-parties
issueshighHAR shows 15 of 21 requests and 125,587 of 156,021 bytes are third-party; Yandex Webvisor is enabled, five third-party origins load, and four SameSite=None analytics cookies are set.
F15 high: A static disclaimer loads extensive session analytics and cookie synchronisation without an on-page choice.
be-private-and-secure
in-context-permissions-and-modern-auth
not-applicablehighThe page requests no browser permission and exposes no authentication flow.
be-private-and-secure
defensive-browser-policies
issueshighNo CSP/frame-ancestors, X-Frame-Options, Referrer-Policy, or Permissions-Policy is present and HSTS is effectively disabled at max-age=1.
F14 high: Browser security policy headers are materially incomplete.
be-resilient
progressive-enhancement
passhighRaw HTML contains 100% of rendered content words and is not a JavaScript shell.
be-resilient
resilient-runtime-behaviour
not-applicablehighNo overlay, menu, reactive state, or asynchronous core dependency exists to exercise.
be-resilient
offline-and-installable
not-applicablehighThis is a brochure/disclaimer page rather than an app; no installability or offline app experience is reasonably required.
be-resilient
network-and-http-failure-states
issueshighBoth /robots.txt and /sitemap.xml returned the generic nginx 404 document with no branding, explanation, home link, or recovery action.
F16 medium: Missing routes return a dead-end server error page.
be-internationalised
lang-dir-and-logical-properties
passmediumhtml lang="en" is correct; content is intentionally English/LTR and the flex layout does not depend on physical source ordering.
be-internationalised
locale-aware-data
not-applicablehighThe page renders no dates, numbers, prices, currencies, or durations requiring locale formatting.
be-internationalised
time-zone-correctness
not-applicablehighNo events, schedules, or stored/displayed times exist.
be-trustworthy
no-dark-patterns
passmediumNo upsell, confirmshaming, disguised advertisement, continuity trap, or coercive consent wall is shown; privacy collection is judged separately.
be-trustworthy
humane-error-handling
not-applicablehighThere are no forms or user-editable fields.
be-trustworthy
trustworthy-input-assistance
not-applicablehighThere are no inputs requiring autocomplete or assistance.
be-trustworthy
safe-commercial-and-account-flows
not-applicablehighThe page explicitly conducts no transactions and exposes no subscription, checkout, auth, or account flow.
be-sustainable
optimised-assets
passhighThe complete image transfer is only 12.8 KiB; the main decorative asset is WebP and the logo is SVG at an appropriate display size.
be-sustainable
no-wasteful-work
issueshighThe static page initiates tracking scripts, beacons, cookie-sync images, and redirects that do not support its content task.
F17 medium: Third-party tracking is disproportionate to this static page’s user value.
be-sustainable
third-party-and-media-budget
issueshighThird parties account for 80% of transferred bytes; the 90 KiB Yandex script alone outweighs all first-party content threefold and initiates redirects and background requests.
F17 medium: Third-party tracking is disproportionate to this static page’s user value.
be-agent-ready
structured-agent-capabilities
not-applicablehighThis static infrastructure disclaimer has no transactional or productivity capability that warrants a WebMCP tool.
be-agent-ready
on-device-inference
not-applicablehighNo summarisation, generation, translation workflow, or other inference task is part of this page.
be-memory-efficient
no-leak-under-repeated-interaction
not-applicablehighThe page has no representative repeatable interaction beyond native links; fabricating one would not test a real session behavior.
be-memory-efficient
bounded-footprint
passmediumThe static page heap summary is proportionate: 71,390 nodes in the V8 snapshot graph and 2.94 MiB total self size.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumNo Detached* constructor appears among retained top constructors; no dynamic component lifecycle or repeating timer-driven UI exists.

Provenance

Canonical report: results/atomic/reports/0322-cdn_33apk_com.json
Report SHA-256: ff1e597591bdff505a08e8535d29bfaae12821c62a61baa64e94540165835230
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/cdn_33apk_com/2026-07-19T23-01-35-044Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/cdn_33apk_com/2026-07-19T23-01-35-044Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.