Manifest position 322 · CrUX rank bucket 1000
https://cdn.33apk.com
Coverage complete
Atomic coverage complete. The host is a genuine single-page static infrastructure disclaimer; external surveza.ai legal documents were not treated as templates of cdn.33apk.com.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | The dark-mode screenshot is pixel-identical in layout and palette to the light capture; the computed CSS probe found no color-scheme, prefers-color-scheme, or light-dark() support. F01 medium: The page ignores the user’s dark color-scheme preference. |
respect-user-preferencesrespects-reduced-motion | pass | high | The page has no active animations and no auto-advance, so there is no non-essential motion to suppress. |
respect-user-preferencesrespects-contrast | issues | high | The prefers-contrast: more capture preserves the normal palette, while axe measures the secondary 12 px text at only 4.11:1. F18 medium: High-contrast preference does not improve already marginal text contrast. |
implement-natural-interactionsview-transitions | pass | medium | The only interactions are native navigation/mail links; there is no abrupt same-document state swap or same-site route transition, and no custom JavaScript transition work. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No parallax, scrollytelling, entry reveal, carousel, or other scroll-linked motion exists. |
implement-natural-interactionsphysical-gestures | not-applicable | high | No gesture-driven control or scroll-snap surface exists; only ordinary links are interactive. |
provide-guided-navigationscroll-state-aware-chrome | not-applicable | high | The single static view has no persistent navigation chrome or long-form position-dependent control. |
provide-guided-navigationanchored-positioning | not-applicable | high | There are no tooltips, popovers, or menus to anchor. |
provide-guided-navigationdirects-attention | pass | medium | The single view has a clear two-column reading order, visibly underlined links, and a prominent support contact; there are no in-page jumps or moved-focus states needing additional cues. |
maximize-content-reduce-noiseno-intrusive-interruptions | pass | high | No pop-up, interstitial, consent wall, or content-obscuring banner appears on load. |
maximize-content-reduce-noisesemantic-dismissible-primitives | not-applicable | high | No overlay, disclosure, custom select, or dismissible rich control exists. |
maximize-content-reduce-noisereduced-chrome | pass | high | The card is content-led, with minimal navigation and no competing application frame. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | Mobile scrollWidth equals clientWidth (360 px), horizontal overflow is 0, and content reflows to one column. |
adapt-to-the-form-factorcomponent-level-responsiveness | not-applicable | medium | No component is reused in differently sized parent containers; the single page layout adapts adequately through its one viewport breakpoint. |
adapt-to-the-form-factorinput-modality-aware | issues | high | The focused Terms link computed to outline-style none and no box shadow; the stylesheet includes :focus { outline: 0 } and a:hover/a:active outline removal without a :focus-visible replacement. F02 high: Keyboard focus is deliberately removed from links. |
support-core-task-successclear-purpose-and-primary-action | pass | high | The opening text clearly states the domain purpose and responsibility; support contact is prominent. |
support-core-task-successprimary-flow-completion | pass | medium | The only primary action is contacting support, exposed as a direct mailto link; legal-policy links have real hrefs. |
support-core-task-successclear-system-state-and-recovery | not-applicable | high | The root is a static informational document with no loading, submission, empty, partial-completion, or success state. |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse measured LCP at 2.8 s (good is at most 2.5 s) and FCP at 2.5 s, while the first-party trace measured LCP 1.15 s on an unthrottled run. F03 medium: Mobile LCP misses the good Core Web Vitals threshold. |
be-fast-and-stablevisual-stability | pass | high | Observed CLS was 0.006 desktop and 0.041 mobile, both within the good threshold. |
be-fast-and-stableefficient-main-thread | pass | high | Trace and both layout runs found zero long tasks; TBT was 0 ms. |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR identified three parser-inserted VeryHigh-priority stylesheets; DOM confirms they are synchronous head links. Lighthouse estimates 1,740 ms render-blocking savings and 76 KiB cache savings. F04 medium: Render-blocking styles and a remote font delay first render. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | Yandex Metrika tag.js transfers about 90 KiB, 58% of the entire 156 KiB load; Lighthouse reports about 47 KiB unused JavaScript. F05 medium: Analytics dominates JavaScript delivery on a static disclaimer page. |
be-inclusivenames-roles-labels | issues | high | axe reports a critical image-alt violation for body > img; the image primitive also found the injected 1×1 GIF without alt. F06 high: A dynamically injected tracking image has no text alternative or presentational role. |
be-inclusivesufficient-contrast | issues | high | axe found nine 12 px text/link nodes at #7d7d7d on white with a 4.11:1 ratio, below the required 4.5:1. F07 high: Small gray body text fails WCAG AA contrast. |
be-inclusivestructure-and-focus | issues | high | The DOM probe found no h1-h6 elements; axe flags page-has-heading-one, and the focus probe found outline-style none. F08 high: The page has no heading structure and keyboard focus is invisible. |
be-inclusivelegible-text | pass | medium | Text wraps without clipping at 360 px and uses a readable family and line layout; contrast is assessed separately and fails its dedicated check. |
be-inclusivezoom-reflow-targets-and-media | issues | high | Reflow has no overflow and scaling is permitted, but link focus is invisible and compact policy links lack robust target treatment. F02 high: Keyboard focus is deliberately removed from links. |
follow-best-practicesno-console-errors | pass | medium | Lighthouse did not report console errors or uncaught exceptions, and all first-party content rendered. |
follow-best-practicessound-document-and-assets | issues | high | Lighthouse flags unsized images and the image primitive reports missing width/height on the logo and injected tracking image; a measured mobile CLS of 0.041 corroborates small late movement. F09 low: Images lack explicit intrinsic dimensions. |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse’s inspector-issues audit scored 0; the same run also reports third-party-cookie issues associated with the tracking stack. F10 low: Chrome reports inspector issues during load. |
be-discoverabletitle-and-description | issues | high | The title is only “Surveza” and there is no meta description; Lighthouse fails meta-description. F11 medium: Search metadata does not describe the page. |
be-discoverablecrawlable-and-mobile-friendly | pass | high | All visible links have real hrefs, link text is descriptive, a viewport meta exists, and no robots directive blocks indexing. |
be-discoverablecanonical-and-indexing-signals | issues | high | The page returns 200 and is indexable, but the probe found no canonical; /robots.txt and /sitemap.xml both return generic nginx 404 pages. F12 medium: The public page lacks canonical, robots, and sitemap signals. |
be-discoverablestructured-and-shareable-metadata | issues | high | The probe found zero Open Graph tags and zero JSON-LD blocks despite the page representing the Surveza organization and infrastructure purpose. F13 low: The organization/disclaimer page has no share preview or structured metadata. |
be-private-and-securesecure-transport-and-headers | issues | high | HTTPS and nosniff are present, but CSP, clickjacking protection, Referrer-Policy, and Permissions-Policy are absent; HSTS is only max-age=1. F14 high: Browser security policy headers are materially incomplete. |
be-private-and-securedata-minimisation-and-third-parties | issues | high | HAR shows 15 of 21 requests and 125,587 of 156,021 bytes are third-party; Yandex Webvisor is enabled, five third-party origins load, and four SameSite=None analytics cookies are set. F15 high: A static disclaimer loads extensive session analytics and cookie synchronisation without an on-page choice. |
be-private-and-securein-context-permissions-and-modern-auth | not-applicable | high | The page requests no browser permission and exposes no authentication flow. |
be-private-and-securedefensive-browser-policies | issues | high | No CSP/frame-ancestors, X-Frame-Options, Referrer-Policy, or Permissions-Policy is present and HSTS is effectively disabled at max-age=1. F14 high: Browser security policy headers are materially incomplete. |
be-resilientprogressive-enhancement | pass | high | Raw HTML contains 100% of rendered content words and is not a JavaScript shell. |
be-resilientresilient-runtime-behaviour | not-applicable | high | No overlay, menu, reactive state, or asynchronous core dependency exists to exercise. |
be-resilientoffline-and-installable | not-applicable | high | This is a brochure/disclaimer page rather than an app; no installability or offline app experience is reasonably required. |
be-resilientnetwork-and-http-failure-states | issues | high | Both /robots.txt and /sitemap.xml returned the generic nginx 404 document with no branding, explanation, home link, or recovery action. F16 medium: Missing routes return a dead-end server error page. |
be-internationalisedlang-dir-and-logical-properties | pass | medium | html lang="en" is correct; content is intentionally English/LTR and the flex layout does not depend on physical source ordering. |
be-internationalisedlocale-aware-data | not-applicable | high | The page renders no dates, numbers, prices, currencies, or durations requiring locale formatting. |
be-internationalisedtime-zone-correctness | not-applicable | high | No events, schedules, or stored/displayed times exist. |
be-trustworthyno-dark-patterns | pass | medium | No upsell, confirmshaming, disguised advertisement, continuity trap, or coercive consent wall is shown; privacy collection is judged separately. |
be-trustworthyhumane-error-handling | not-applicable | high | There are no forms or user-editable fields. |
be-trustworthytrustworthy-input-assistance | not-applicable | high | There are no inputs requiring autocomplete or assistance. |
be-trustworthysafe-commercial-and-account-flows | not-applicable | high | The page explicitly conducts no transactions and exposes no subscription, checkout, auth, or account flow. |
be-sustainableoptimised-assets | pass | high | The complete image transfer is only 12.8 KiB; the main decorative asset is WebP and the logo is SVG at an appropriate display size. |
be-sustainableno-wasteful-work | issues | high | The static page initiates tracking scripts, beacons, cookie-sync images, and redirects that do not support its content task. F17 medium: Third-party tracking is disproportionate to this static page’s user value. |
be-sustainablethird-party-and-media-budget | issues | high | Third parties account for 80% of transferred bytes; the 90 KiB Yandex script alone outweighs all first-party content threefold and initiates redirects and background requests. F17 medium: Third-party tracking is disproportionate to this static page’s user value. |
be-agent-readystructured-agent-capabilities | not-applicable | high | This static infrastructure disclaimer has no transactional or productivity capability that warrants a WebMCP tool. |
be-agent-readyon-device-inference | not-applicable | high | No summarisation, generation, translation workflow, or other inference task is part of this page. |
be-memory-efficientno-leak-under-repeated-interaction | not-applicable | high | The page has no representative repeatable interaction beyond native links; fabricating one would not test a real session behavior. |
be-memory-efficientbounded-footprint | pass | medium | The static page heap summary is proportionate: 71,390 nodes in the V8 snapshot graph and 2.94 MiB total self size. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | medium | No Detached* constructor appears among retained top constructors; no dynamic component lifecycle or repeating timer-driven UI exists. |
Provenance
Canonical report: results/atomic/reports/0322-cdn_33apk_com.json
Report SHA-256: ff1e597591bdff505a08e8535d29bfaae12821c62a61baa64e94540165835230
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/cdn_33apk_com/2026-07-19T23-01-35-044Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/cdn_33apk_com/2026-07-19T23-01-35-044Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.