Manifest position 340 · CrUX rank bucket 1000

https://login.yahoo.com

Partial after retries

55 of 58 checks were conclusively judged. End-to-end sign-in, passkey availability, and authenticated account-management safety were blocked because no Yahoo test credentials were available.

Attempts
3 / 3
Judged checks
55 / 58
Blocked
3
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighUnder emulated prefers-color-scheme: dark, the page remains a white/light-only surface; computed html color-scheme is light.
F01 high: Light-only styling ignores the user’s dark preference
respect-user-preferences
respects-reduced-motion
passhighThe reduced-motion probe confirmed the preference matched and found zero active animations on the login surface.
respect-user-preferences
respects-contrast
passhighForced-colors/high-contrast capture retains visible text, borders, controls, checkbox state, and links.
implement-natural-interactions
view-transitions
issuesmediumThe login, recovery, and account-creation journey changes views without any authored View Transition CSS; probe found no view-transition rules.
F02 low: Multi-step authentication changes are abrupt
implement-natural-interactions
scroll-driven-animations
not-applicablehighNo parallax, scrollytelling, carousel, or scroll-linked motion exists on the compact authentication surfaces.
implement-natural-interactions
physical-gestures
not-applicablehighNo gesture-driven control, swipe action, carousel, or scroll-snap interaction exists on the audited authentication surfaces.
provide-guided-navigation
scroll-state-aware-chrome
not-applicablehighThe compact sign-in and recovery forms have no meaningful scroll-reactive chrome; account creation is a conventional linear form.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip, popover, anchored menu, or transient overlay is present on the audited surfaces.
provide-guided-navigation
directs-attention
passhighStrong heading hierarchy, auto-focused first field, prominent Next button, and inline focus return after validation make the next step and moved attention clear.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighNo popup, consent wall, or interstitial obscured the authentication forms on load across three routes.
maximize-content-reduce-noise
semantic-dismissible-primitives
not-applicablehighNo overlay, disclosure, picker, or other dismissible transient control is present to require dialog/popover/details semantics.
maximize-content-reduce-noise
reduced-chrome
issuesmediumAt desktop width, a large animated-looking Yahoo Finance promotion consumes about half the first viewport and competes with the primary sign-in task.
F03 medium: Desktop promotion competes with the sign-in task
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighAt 360x800 the form reflows to one column; layout reports 360px scrollWidth, 360px clientWidth, and 0px horizontal overflow with viewport meta present.
adapt-to-the-form-factor
component-level-responsiveness
passmediumThe same authentication card changes from a desktop side panel to a full-width mobile card while preserving field and action hierarchy; no reuse context showed a failed component state.
adapt-to-the-form-factor
input-modality-aware
passhighPrimary controls are 52px tall, keyboard focus is visible, and Lighthouse target-size passed; the 18px checkbox has a larger associated text label.
support-core-task-success
clear-purpose-and-primary-action
passhigh“Sign in to Yahoo”, the username label, and a single prominent Next action make the page purpose and next step immediately clear.
support-core-task-success
primary-flow-completion
blockedhighThe unauthenticated username and recovery steps were exercised, but end-to-end sign-in requires a valid Yahoo account and secret; no credentials were available.
support-core-task-success
clear-system-state-and-recovery
issueshighA synthetic non-existent username produces only “Whoops, something went wrong.” It gives no cause, retry advice, or account-recovery link in the error itself.
F04 medium: Unknown-account errors are not actionable
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse measured 5.1s LCP (performance 69) and the raw trace measured 7.1s LCP; both are outside the good threshold.
F05 high: Largest Contentful Paint is slow
be-fast-and-stable
visual-stability
passhighMobile layout observation measured CLS 0.00287 and Lighthouse measured 0.00014, both comfortably in the good range.
be-fast-and-stable
efficient-main-thread
passmediumTrace total blocking time was 85.59ms with two long tasks; Lighthouse TBT was 233.5ms, elevated but not the dominant load failure.
be-fast-and-stable
efficient-resource-delivery
issueshighThe main document took 4.94s; four parser-inserted, non-async/non-defer analytics/consent scripts are in head, and one analytics script lacks compression and cache headers.
F06 high: Parser-blocking analytics and consent work delays delivery
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighThe simple sign-in form transfers 705KB across 24 scripts; Google Tag Manager alone is 169KB and third-party requests account for 841KB of 862KB total.
F07 medium: The login form ships a heavy JavaScript payload
be-inclusive
names-roles-labels
passhighLighthouse accessibility scored 100; the form probe found explicit labels for username and persistence controls, accessible action text, and alt text for both logos.
be-inclusive
sufficient-contrast
passhighLighthouse color-contrast passed with no failing nodes, and forced-colors preserved essential content.
be-inclusive
structure-and-focus
passhighA main landmark and headings are present; all interactive controls accepted visible keyboard focus, and invalid submission returned focus to #username.
be-inclusive
legible-text
passhighText remains clear and unclipped at desktop and 360px, with readable labels and instructions on sign-in, recovery, and account-creation views.
be-inclusive
zoom-reflow-targets-and-media
passhighThe mobile layout reflows without horizontal overflow, user scaling is not disabled, Lighthouse target-size passed, and there is no time-based media requiring captions.
follow-best-practices
no-console-errors
passhighLighthouse found no errors logged to the browser console.
follow-best-practices
sound-document-and-assets
issueshighThe document has valid HTML/UTF-8, but both Yahoo logo images omit width and height; one lacks srcset and both are legacy PNG.
F08 low: Logo assets omit intrinsic dimensions and responsive metadata
follow-best-practices
browser-platform-hygiene
issuesmediumLighthouse reports the page is ineligible for back/forward cache for two reasons, reducing clean browser-history restoration.
F09 medium: The page cannot use the back/forward cache
be-discoverable
title-and-description
passhighThe page exposes a descriptive title and meta description in the rendered DOM; Lighthouse title and description audits passed.
be-discoverable
crawlable-and-mobile-friendly
passhighAll visible links have real href values and descriptive text, viewport meta is present, robots.txt permits the root login page, and Lighthouse crawlable-links passed.
be-discoverable
canonical-and-indexing-signals
not-applicablehighThis is a deliberately gated authentication utility, not a public content page intended for indexing; a sitemap is not required for the login endpoint.
be-discoverable
structured-and-shareable-metadata
not-applicablehighThe page is an authentication utility, not an article, product, event, place, or other rich entity that needs JSON-LD or social-preview metadata.
be-private-and-secure
secure-transport-and-headers
passhighThe page uses HTTPS, HSTS, CSP, nosniff, X-Frame-Options DENY, strict-origin referrer policy, and all observed cookies are Secure; no sensitive client-side secrets were found.
be-private-and-secure
data-minimisation-and-third-parties
issueshighThe login load contacts 9 third-party origins, including Google Tag Manager and Google Analytics; 46 of 48 requests and 840,830 transferred bytes are classified third-party.
F10 high: Tracking footprint is excessive on the login page
be-private-and-secure
in-context-permissions-and-modern-auth
blockedhighNo permission prompt fired on load and Google federation is visible, but passkey/WebAuthn availability can only be established after identifying a real account; no account credentials were available.
be-private-and-secure
defensive-browser-policies
issueshighPermissions-Policy is absent and CSP allows all style origins plus unsafe-inline, weakening browser-enforced least privilege despite strong HSTS and frame denial.
F11 medium: Browser policy hardening is incomplete
be-resilient
progressive-enhancement
passhighRaw HTML contains 82% of rendered content and is not a JS shell; with JavaScript disabled the page shows a clear sign-in limitation and a Try again recovery action rather than a blank shell.
be-resilient
resilient-runtime-behaviour
passmediumThe audited forms contain no overlays or fragile menus, retain focus through validation, and render consistently across desktop/mobile route changes.
be-resilient
offline-and-installable
not-applicablehighAuthentication intrinsically requires an online identity service; no offline completion is meaningful, so a service worker/manifest is not expected for this standalone login endpoint.
be-resilient
network-and-http-failure-states
passhighThe no-JavaScript/adverse state is an explicit “We couldn’t sign you in” page with troubleshooting and Try again; validation errors remain in context with focus returned to the field.
be-internationalised
lang-dir-and-logical-properties
passmediumThe served locale declares html lang=en-GB and dir=ltr; audited copy is coherent for that locale and mobile layout survives narrow reflow.
be-internationalised
locale-aware-data
not-applicablehighThe unauthenticated sign-in and recovery views display no dates, numbers, currency, durations, or locale-sensitive data.
be-internationalised
time-zone-correctness
not-applicablehighThe audited authentication surfaces contain no times, events, recurrence, or time-zone-sensitive concepts.
be-trustworthy
no-dark-patterns
issueshigh“Stay signed in” is selected by default, opting users into persistent authentication even on a shared device unless they notice and reverse the choice.
F12 medium: Persistent sign-in is enabled by default
be-trustworthy
humane-error-handling
passhighErrors appear only after submission, set aria-invalid=true, use role=alert, return focus to the username field, and the empty case clearly says “This is required.”
be-trustworthy
trustworthy-input-assistance
issueshighThe username/email/phone field has an empty autocomplete attribute instead of autocomplete="username", preventing reliable password-manager and sign-in autofill assistance.
F13 high: The username field does not advertise autofill semantics
be-trustworthy
safe-commercial-and-account-flows
blockedhighThe public sign-in, recovery, and create-account entry views were inspected, but cancellation, sensitive-action reauthentication, passkey management, and authenticated account controls require a real account.
be-sustainable
optimised-assets
issueshighBoth logos are PNG without intrinsic dimensions; one lacks responsive sources. The assets are small, but modern format/dimension metadata is not fully used.
F14 low: Image delivery misses lightweight asset techniques
be-sustainable
no-wasteful-work
issueshighA simple login form initiates 48 requests and 705KB of scripts, including analytics, consent, and tag-manager work before authentication.
F15 high: Background analytics work is disproportionate to the form
be-sustainable
third-party-and-media-budget
issueshighThird parties account for 46 of 48 requests and 840,830 of 861,889 transferred bytes, disproportionate to the value of the unauthenticated login form.
F16 high: Third-party budget dominates total transfer
be-agent-ready
structured-agent-capabilities
not-applicablehighAuthentication is a security-sensitive flow with no declared agent-facing surface; exposing sign-in credentials as WebMCP tools is not an expected requirement.
be-agent-ready
on-device-inference
not-applicablehighThe login/recovery flow has no summarisation, generation, or language-inference task for which on-device AI would improve the experience.
be-memory-efficient
no-leak-under-repeated-interaction
passmediumAfter ten alternating invalid/empty submissions, a retained heap summary was 17.1MB versus 15.75MB baseline while DOM nodes remained exactly 138 in the same-page probe. The modest one-time growth is consistent with loading validation code and does not show unbounded accumulation.
be-memory-efficient
bounded-footprint
passmediumBaseline retained self-size was 15.75MB for the hydrated sign-in application; this is not unusually large for the observed Next.js/auth/analytics surface.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumNo Detached-named constructor appeared among retained top constructors, and ten repeated submissions left live DOM count stable at 138; no accumulating visual animations were present.

Provenance

Canonical report: results/atomic/reports/0340-login_yahoo_com.json
Report SHA-256: f8bfe545ebbbf9835585ff9f907c356593f53c24446c80147d1586e268deb04c
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/login_yahoo_com/2026-07-27T20-21-32-729Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/login_yahoo_com/2026-07-27T20-21-32-729Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.