Manifest position 356 · CrUX rank bucket 1000
https://secure.bankofamerica.com
Coverage complete
The requested secure origin serves a JavaScript bootstrap that rendered the public www.bankofamerica.com homepage; the report judges that resulting experience and three representative public archetypes.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | DOM reports color-scheme normal while authored markup declares only light; CSS probe found no prefers-color-scheme: dark rule. The dark capture stayed blank because body visibility never recovered under that condition. F1 medium: No system-driven dark theme |
respect-user-preferencesrespects-reduced-motion | issues | high | Under prefers-reduced-motion: reduce, a 500 ms animation still existed and the CSS probe found no prefers-reduced-motion rule. F2 low: Reduced-motion preference is not implemented |
respect-user-preferencesrespects-contrast | pass | medium | The prefers-contrast screenshot kept text, controls, card outlines, and the login form visible; Lighthouse contrast failures were ordinary-color defects captured separately, not disappearance under the preference. |
implement-natural-interactionsview-transitions | issues | high | CSS probe found no view-transition usage across a route-heavy MPA with tabs, menus, dialogs, and product navigation. F3 low: Route and state changes lack View Transitions |
implement-natural-interactionsscroll-driven-animations | pass | medium | DOM/CSS probe found no scroll-linked effect or scroll-handler-driven parallax on the representative pages. |
implement-natural-interactionsphysical-gestures | pass | medium | Representative homepage, card listing, checking, and security surfaces use ordinary links, buttons, and carousel controls; no custom pointer gesture that fights native scrolling was observed. |
provide-guided-navigationscroll-state-aware-chrome | issues | high | CSS probe found no scroll-state query or position-aware chrome; long pages keep static navigation without a progress or return affordance. F4 low: Long pages have static, non-responsive navigation chrome |
provide-guided-navigationanchored-positioning | pass | medium | No tethered tooltip or edge-positioned contextual menu appeared on the representative paths; the checking dialog remained fully within the viewport. |
provide-guided-navigationdirects-attention | pass | medium | Card tabs, selected states, page headings, navigation labels, and the branded 404 recovery links clearly indicate location and next steps. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | The checking page opens with a mandatory ZIP-code modal over dimmed content, while cookie banners cover the bottom of checking, card, login, and error states. F5 high: Load-time modal and sticky notices obscure product content |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | DOM probe found zero native dialog and popover elements despite modal/help/privacy layers; landmarks include custom DIV:dialog nodes. F6 medium: Custom dialog layers replace native top-layer primitives |
maximize-content-reduce-noisereduced-chrome | issues | high | Homepage first viewport combines login, four card promotions, product banners, and a sticky cash-offer strip; mobile is dominated by the card ad before core banking actions. F7 medium: Promotional chrome crowds out core banking content |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | medium | At 360x800, layout metrics reported scrollWidth 360, clientWidth 360, and horizontalOverflowPx 0; the mobile screenshot shows a single-column adaptation. |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | CSS probe found no @container rules; reusable cards and navigation are controlled only by viewport breakpoints. F8 low: Reusable components do not use container queries |
adapt-to-the-form-factorinput-modality-aware | issues | high | Lighthouse failed target-size; the DOM probe found many 16–20 px-high links and several focused login controls with outline none. F9 high: Small targets and missing focus indicators impair input |
support-core-task-successclear-purpose-and-primary-action | issues | high | At 360x800 the first viewport omits the login form and is dominated by four credit-card promotions, making the secure banking action unclear. F10 high: Mobile first viewport hides the secure banking task |
support-core-task-successprimary-flow-completion | pass | medium | The public product-discovery flow was followed from the homepage to credit-card and checking product surfaces; each presents a clear product CTA. Authenticated account access was not attempted without credentials. |
support-core-task-successclear-system-state-and-recovery | issues | high | Clicking Log in with both required fields empty produced no visible error, no role=alert/aria-invalid node, and no focus transfer in the evaluate probe. F11 high: Empty login submission gives no actionable error |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB. F12 critical: Homepage load and main-thread work are far outside good ranges |
be-fast-and-stablevisual-stability | issues | high | Mobile layout observer measured CLS 0.214 with a 0.166 shift; 64 of 68 images lacked explicit dimensions. F13 high: Late content causes poor visual stability |
be-fast-and-stableefficient-main-thread | issues | high | Lighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB. F12 critical: Homepage load and main-thread work are far outside good ranges |
be-fast-and-stableefficient-resource-delivery | issues | high | Lighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB. F12 critical: Homepage load and main-thread work are far outside good ranges |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | Lighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB. F12 critical: Homepage load and main-thread work are far outside good ranges |
be-inclusivenames-roles-labels | issues | high | Lighthouse failed aria-required-attr and image-alt; multiple role=heading nodes lacked aria-level and an image used whitespace-only alt. F14 high: ARIA and image alternatives are malformed |
be-inclusivesufficient-contrast | issues | high | Lighthouse failed color contrast, including red #e31837 text on #f5f5f5 at 4.32:1. F15 medium: Text contrast falls below WCAG minimum |
be-inclusivestructure-and-focus | issues | high | Rendered DOM contains multiple H1s, including an empty H1 and hidden overlay headings; several focused login links and fields compute outline none. F16 high: Heading hierarchy and keyboard focus are inconsistent |
be-inclusivelegible-text | pass | medium | Desktop and mobile screenshots show readable body copy and headings without clipping; line lengths and spacing remain comprehensible on the sampled pages. |
be-inclusivezoom-reflow-targets-and-media | issues | high | Lighthouse failed target-size and the probe found many links/buttons only 16–20 px high; zoom/reflow is weakened by dense small controls. F17 medium: Touch targets are too small |
follow-best-practicesno-console-errors | pass | medium | Lighthouse errors-in-console audit scored 1 with an empty item list. |
follow-best-practicessound-document-and-assets | issues | high | Lighthouse found an incorrectly stretched hero image; images primitive found 64 missing dimensions and 15 oversized assets. F18 medium: Images are unsized, oversized, and sometimes distorted |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse found a deprecated Shared Storage API call, missing first-party source maps, and browser Inspector cookie issues. F19 medium: Deprecated API and inspection hygiene issues remain |
be-discoverabletitle-and-description | pass | medium | Rendered DOM and Lighthouse confirm a descriptive title and meta description. |
be-discoverablecrawlable-and-mobile-friendly | issues | high | The discoverability primitive fetched only 311 bytes of raw HTML with 0% rendered-word coverage and no title, H1, description, or visible content; its crawler screenshot is blank even though the JavaScript browser view is populated. F31 high: Public content is invisible to non-JavaScript crawlers |
be-discoverablecanonical-and-indexing-signals | pass | medium | The rendered page has canonical https://www.bankofamerica.com/, robots index/follow, a successful response, and es-US hreflang; Lighthouse passed canonical, status, robots, and hreflang audits. |
be-discoverablestructured-and-shareable-metadata | pass | medium | DOM probe found 3 JSON-LD blocks and 7 Open Graph properties matching the Bank of America homepage entity. |
be-private-and-securesecure-transport-and-headers | issues | high | HTTPS and HSTS are present, but CSP permits unsafe-inline and unsafe-eval; cookie evidence reports 33 of 34 cookies as insecure under its checks, including non-Secure first-party values and widespread SameSite=None. F20 high: Security policy and cookie posture are weaker than expected |
be-private-and-securedata-minimisation-and-third-parties | issues | high | Trackers/network evidence found 15 third-party origins and HAR attributes 114 requests/3.45 MB to origins outside secure.bankofamerica.com, including Tealium, Adobe, Glassbox, Glance, and OneTrust traffic. F21 high: The unauthenticated page has a broad behavioral-data footprint |
be-private-and-securein-context-permissions-and-modern-auth | pass | medium | Recon exposed a Log in with passkey option, and no geolocation or notification prompt appeared on load across screenshots and Lighthouse. |
be-private-and-securedefensive-browser-policies | issues | high | The secure response has HSTS, X-Frame-Options and frame-ancestors, but no observed Referrer-Policy, Permissions-Policy or X-Content-Type-Options and CSP still allows unsafe-inline/unsafe-eval. F22 medium: Defensive response policies are incomplete |
be-resilientprogressive-enhancement | issues | high | Discoverability fetched only 311 bytes of raw HTML with 0% rendered-word coverage, no title/H1/description, and a blank crawler screenshot: core public content depends on JavaScript. F23 high: Non-JavaScript crawlers receive an empty shell |
be-resilientresilient-runtime-behaviour | pass | medium | Representative navigation, tabs, dialogs, and content cards rendered without clipped menus or broken asynchronous states in the captured paths. |
be-resilientoffline-and-installable | not-applicable | high | Public marketing and online-banking transactions are not an installable/offline app surface; offline transaction completion would be inappropriate. |
be-resilientnetwork-and-http-failure-states | pass | medium | A deliberately nonexistent route produced a branded Page Not Available view with Home Page, Site Map, and Contact us recovery links. |
be-internationalisedlang-dir-and-logical-properties | pass | medium | The document declares lang=en-US, exposes an es-US hreflang alternate and an En español route; reading order was correct on sampled pages. |
be-internationalisedlocale-aware-data | pass | medium | Public prices, percentages, and dollar values are formatted consistently for en-US, and the site exposes a Spanish locale route. |
be-internationalisedtime-zone-correctness | not-applicable | high | No dates, appointments, recurring events, or time-zone-sensitive data appeared on the audited public surfaces. |
be-trustworthyno-dark-patterns | issues | high | Tracking and analytics load on first visit while the visible cookie notice offers only policy links and an X, with no equally prominent reject/control action. F24 high: Tracking begins without an equal reject/control choice |
be-trustworthyhumane-error-handling | issues | high | Clicking Log in with both required fields empty produced no visible error, no role=alert/aria-invalid node, and no focus transfer in the evaluate probe. F11 high: Empty login submission gives no actionable error |
be-trustworthytrustworthy-input-assistance | issues | high | User ID and password inputs both expose autocomplete=off instead of username/current-password, blocking standard secure password-manager/autofill assistance. F25 high: Login disables secure browser autofill |
be-trustworthysafe-commercial-and-account-flows | pass | medium | Product pages disclose headline rewards and commitments before Apply Now, and the account surface offers passkey login, recovery, enrollment, and security help. |
be-sustainableoptimised-assets | issues | high | Images audit found 15 oversized images, 15 missing srcset, 9 legacy-format assets, and 12 below-fold images without lazy loading. F26 medium: Responsive image delivery wastes bytes |
be-sustainableno-wasteful-work | issues | high | Trace measured 1,181 ms total blocking time and HAR shows extensive analytics/behavior scripts; substantial work continues beyond essential product rendering. F27 high: Background analytics and scripts consume excessive work |
be-sustainablethird-party-and-media-budget | issues | high | HAR recorded 48 scripts (2.28 MB) and 3.45 MB attributed outside the secure origin; Lighthouse page weight was 5,464 KiB. F28 high: Third-party scripts dominate the page budget |
be-agent-readystructured-agent-capabilities | not-applicable | high | No declared agent-facing capability was found, and exposing unauthenticated banking actions to agents is not assumed to be intended. |
be-agent-readyon-device-inference | not-applicable | high | No user task in the audited public surfaces requires on-device inference; absence is an emerging opportunity, not a defect. |
be-memory-efficientno-leak-under-repeated-interaction | issues | medium | Separate baseline and post-interaction heap summaries grew from 25.7 MB/378k nodes to 76.4 MB/1.11m nodes. Load timing differs, so this is medium-confidence retained-growth evidence requiring a same-session allocation investigation. F29 medium: Heap growth signal warrants leak investigation |
be-memory-efficientbounded-footprint | issues | high | The settled post-interaction homepage retained about 76.4 MB across 1.11m heap nodes, disproportionate for a public marketing/login surface. F30 medium: Homepage memory footprint is disproportionate |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | medium | Heap summaries contain no Detached* constructor among retained populations after the sampled checkbox interaction; no direct detached-DOM evidence was found. |
Provenance
Canonical report: results/atomic/reports/0356-secure_bankofamerica_com.json
Report SHA-256: 6e642b311700c25da8c25f3b08a7cd1e9897a6185f677fb09bdf2dd65f94afa0
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/secure_bankofamerica_com/2026-07-26T06-54-27-296Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/secure_bankofamerica_com/2026-07-26T06-54-27-296Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.