Manifest position 356 · CrUX rank bucket 1000

https://secure.bankofamerica.com

Coverage complete

The requested secure origin serves a JavaScript bootstrap that rendered the public www.bankofamerica.com homepage; the report judges that resulting experience and three representative public archetypes.

Attempts
2 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighDOM reports color-scheme normal while authored markup declares only light; CSS probe found no prefers-color-scheme: dark rule. The dark capture stayed blank because body visibility never recovered under that condition.
F1 medium: No system-driven dark theme
respect-user-preferences
respects-reduced-motion
issueshighUnder prefers-reduced-motion: reduce, a 500 ms animation still existed and the CSS probe found no prefers-reduced-motion rule.
F2 low: Reduced-motion preference is not implemented
respect-user-preferences
respects-contrast
passmediumThe prefers-contrast screenshot kept text, controls, card outlines, and the login form visible; Lighthouse contrast failures were ordinary-color defects captured separately, not disappearance under the preference.
implement-natural-interactions
view-transitions
issueshighCSS probe found no view-transition usage across a route-heavy MPA with tabs, menus, dialogs, and product navigation.
F3 low: Route and state changes lack View Transitions
implement-natural-interactions
scroll-driven-animations
passmediumDOM/CSS probe found no scroll-linked effect or scroll-handler-driven parallax on the representative pages.
implement-natural-interactions
physical-gestures
passmediumRepresentative homepage, card listing, checking, and security surfaces use ordinary links, buttons, and carousel controls; no custom pointer gesture that fights native scrolling was observed.
provide-guided-navigation
scroll-state-aware-chrome
issueshighCSS probe found no scroll-state query or position-aware chrome; long pages keep static navigation without a progress or return affordance.
F4 low: Long pages have static, non-responsive navigation chrome
provide-guided-navigation
anchored-positioning
passmediumNo tethered tooltip or edge-positioned contextual menu appeared on the representative paths; the checking dialog remained fully within the viewport.
provide-guided-navigation
directs-attention
passmediumCard tabs, selected states, page headings, navigation labels, and the branded 404 recovery links clearly indicate location and next steps.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighThe checking page opens with a mandatory ZIP-code modal over dimmed content, while cookie banners cover the bottom of checking, card, login, and error states.
F5 high: Load-time modal and sticky notices obscure product content
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighDOM probe found zero native dialog and popover elements despite modal/help/privacy layers; landmarks include custom DIV:dialog nodes.
F6 medium: Custom dialog layers replace native top-layer primitives
maximize-content-reduce-noise
reduced-chrome
issueshighHomepage first viewport combines login, four card promotions, product banners, and a sticky cash-offer strip; mobile is dominated by the card ad before core banking actions.
F7 medium: Promotional chrome crowds out core banking content
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passmediumAt 360x800, layout metrics reported scrollWidth 360, clientWidth 360, and horizontalOverflowPx 0; the mobile screenshot shows a single-column adaptation.
adapt-to-the-form-factor
component-level-responsiveness
issueshighCSS probe found no @container rules; reusable cards and navigation are controlled only by viewport breakpoints.
F8 low: Reusable components do not use container queries
adapt-to-the-form-factor
input-modality-aware
issueshighLighthouse failed target-size; the DOM probe found many 16–20 px-high links and several focused login controls with outline none.
F9 high: Small targets and missing focus indicators impair input
support-core-task-success
clear-purpose-and-primary-action
issueshighAt 360x800 the first viewport omits the login form and is dominated by four credit-card promotions, making the secure banking action unclear.
F10 high: Mobile first viewport hides the secure banking task
support-core-task-success
primary-flow-completion
passmediumThe public product-discovery flow was followed from the homepage to credit-card and checking product surfaces; each presents a clear product CTA. Authenticated account access was not attempted without credentials.
support-core-task-success
clear-system-state-and-recovery
issueshighClicking Log in with both required fields empty produced no visible error, no role=alert/aria-invalid node, and no focus transfer in the evaluate probe.
F11 high: Empty login submission gives no actionable error
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB.
F12 critical: Homepage load and main-thread work are far outside good ranges
be-fast-and-stable
visual-stability
issueshighMobile layout observer measured CLS 0.214 with a 0.166 shift; 64 of 68 images lacked explicit dimensions.
F13 high: Late content causes poor visual stability
be-fast-and-stable
efficient-main-thread
issueshighLighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB.
F12 critical: Homepage load and main-thread work are far outside good ranges
be-fast-and-stable
efficient-resource-delivery
issueshighLighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB.
F12 critical: Homepage load and main-thread work are far outside good ranges
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighLighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB.
F12 critical: Homepage load and main-thread work are far outside good ranges
be-inclusive
names-roles-labels
issueshighLighthouse failed aria-required-attr and image-alt; multiple role=heading nodes lacked aria-level and an image used whitespace-only alt.
F14 high: ARIA and image alternatives are malformed
be-inclusive
sufficient-contrast
issueshighLighthouse failed color contrast, including red #e31837 text on #f5f5f5 at 4.32:1.
F15 medium: Text contrast falls below WCAG minimum
be-inclusive
structure-and-focus
issueshighRendered DOM contains multiple H1s, including an empty H1 and hidden overlay headings; several focused login links and fields compute outline none.
F16 high: Heading hierarchy and keyboard focus are inconsistent
be-inclusive
legible-text
passmediumDesktop and mobile screenshots show readable body copy and headings without clipping; line lengths and spacing remain comprehensible on the sampled pages.
be-inclusive
zoom-reflow-targets-and-media
issueshighLighthouse failed target-size and the probe found many links/buttons only 16–20 px high; zoom/reflow is weakened by dense small controls.
F17 medium: Touch targets are too small
follow-best-practices
no-console-errors
passmediumLighthouse errors-in-console audit scored 1 with an empty item list.
follow-best-practices
sound-document-and-assets
issueshighLighthouse found an incorrectly stretched hero image; images primitive found 64 missing dimensions and 15 oversized assets.
F18 medium: Images are unsized, oversized, and sometimes distorted
follow-best-practices
browser-platform-hygiene
issueshighLighthouse found a deprecated Shared Storage API call, missing first-party source maps, and browser Inspector cookie issues.
F19 medium: Deprecated API and inspection hygiene issues remain
be-discoverable
title-and-description
passmediumRendered DOM and Lighthouse confirm a descriptive title and meta description.
be-discoverable
crawlable-and-mobile-friendly
issueshighThe discoverability primitive fetched only 311 bytes of raw HTML with 0% rendered-word coverage and no title, H1, description, or visible content; its crawler screenshot is blank even though the JavaScript browser view is populated.
F31 high: Public content is invisible to non-JavaScript crawlers
be-discoverable
canonical-and-indexing-signals
passmediumThe rendered page has canonical https://www.bankofamerica.com/, robots index/follow, a successful response, and es-US hreflang; Lighthouse passed canonical, status, robots, and hreflang audits.
be-discoverable
structured-and-shareable-metadata
passmediumDOM probe found 3 JSON-LD blocks and 7 Open Graph properties matching the Bank of America homepage entity.
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS and HSTS are present, but CSP permits unsafe-inline and unsafe-eval; cookie evidence reports 33 of 34 cookies as insecure under its checks, including non-Secure first-party values and widespread SameSite=None.
F20 high: Security policy and cookie posture are weaker than expected
be-private-and-secure
data-minimisation-and-third-parties
issueshighTrackers/network evidence found 15 third-party origins and HAR attributes 114 requests/3.45 MB to origins outside secure.bankofamerica.com, including Tealium, Adobe, Glassbox, Glance, and OneTrust traffic.
F21 high: The unauthenticated page has a broad behavioral-data footprint
be-private-and-secure
in-context-permissions-and-modern-auth
passmediumRecon exposed a Log in with passkey option, and no geolocation or notification prompt appeared on load across screenshots and Lighthouse.
be-private-and-secure
defensive-browser-policies
issueshighThe secure response has HSTS, X-Frame-Options and frame-ancestors, but no observed Referrer-Policy, Permissions-Policy or X-Content-Type-Options and CSP still allows unsafe-inline/unsafe-eval.
F22 medium: Defensive response policies are incomplete
be-resilient
progressive-enhancement
issueshighDiscoverability fetched only 311 bytes of raw HTML with 0% rendered-word coverage, no title/H1/description, and a blank crawler screenshot: core public content depends on JavaScript.
F23 high: Non-JavaScript crawlers receive an empty shell
be-resilient
resilient-runtime-behaviour
passmediumRepresentative navigation, tabs, dialogs, and content cards rendered without clipped menus or broken asynchronous states in the captured paths.
be-resilient
offline-and-installable
not-applicablehighPublic marketing and online-banking transactions are not an installable/offline app surface; offline transaction completion would be inappropriate.
be-resilient
network-and-http-failure-states
passmediumA deliberately nonexistent route produced a branded Page Not Available view with Home Page, Site Map, and Contact us recovery links.
be-internationalised
lang-dir-and-logical-properties
passmediumThe document declares lang=en-US, exposes an es-US hreflang alternate and an En español route; reading order was correct on sampled pages.
be-internationalised
locale-aware-data
passmediumPublic prices, percentages, and dollar values are formatted consistently for en-US, and the site exposes a Spanish locale route.
be-internationalised
time-zone-correctness
not-applicablehighNo dates, appointments, recurring events, or time-zone-sensitive data appeared on the audited public surfaces.
be-trustworthy
no-dark-patterns
issueshighTracking and analytics load on first visit while the visible cookie notice offers only policy links and an X, with no equally prominent reject/control action.
F24 high: Tracking begins without an equal reject/control choice
be-trustworthy
humane-error-handling
issueshighClicking Log in with both required fields empty produced no visible error, no role=alert/aria-invalid node, and no focus transfer in the evaluate probe.
F11 high: Empty login submission gives no actionable error
be-trustworthy
trustworthy-input-assistance
issueshighUser ID and password inputs both expose autocomplete=off instead of username/current-password, blocking standard secure password-manager/autofill assistance.
F25 high: Login disables secure browser autofill
be-trustworthy
safe-commercial-and-account-flows
passmediumProduct pages disclose headline rewards and commitments before Apply Now, and the account surface offers passkey login, recovery, enrollment, and security help.
be-sustainable
optimised-assets
issueshighImages audit found 15 oversized images, 15 missing srcset, 9 legacy-format assets, and 12 below-fold images without lazy loading.
F26 medium: Responsive image delivery wastes bytes
be-sustainable
no-wasteful-work
issueshighTrace measured 1,181 ms total blocking time and HAR shows extensive analytics/behavior scripts; substantial work continues beyond essential product rendering.
F27 high: Background analytics and scripts consume excessive work
be-sustainable
third-party-and-media-budget
issueshighHAR recorded 48 scripts (2.28 MB) and 3.45 MB attributed outside the secure origin; Lighthouse page weight was 5,464 KiB.
F28 high: Third-party scripts dominate the page budget
be-agent-ready
structured-agent-capabilities
not-applicablehighNo declared agent-facing capability was found, and exposing unauthenticated banking actions to agents is not assumed to be intended.
be-agent-ready
on-device-inference
not-applicablehighNo user task in the audited public surfaces requires on-device inference; absence is an emerging opportunity, not a defect.
be-memory-efficient
no-leak-under-repeated-interaction
issuesmediumSeparate baseline and post-interaction heap summaries grew from 25.7 MB/378k nodes to 76.4 MB/1.11m nodes. Load timing differs, so this is medium-confidence retained-growth evidence requiring a same-session allocation investigation.
F29 medium: Heap growth signal warrants leak investigation
be-memory-efficient
bounded-footprint
issueshighThe settled post-interaction homepage retained about 76.4 MB across 1.11m heap nodes, disproportionate for a public marketing/login surface.
F30 medium: Homepage memory footprint is disproportionate
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumHeap summaries contain no Detached* constructor among retained populations after the sampled checkbox interaction; no direct detached-DOM evidence was found.

Provenance

Canonical report: results/atomic/reports/0356-secure_bankofamerica_com.json
Report SHA-256: 6e642b311700c25da8c25f3b08a7cd1e9897a6185f677fb09bdf2dd65f94afa0
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/secure_bankofamerica_com/2026-07-26T06-54-27-296Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/secure_bankofamerica_com/2026-07-26T06-54-27-296Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.