Manifest position 364 · CrUX rank bucket 1000
https://ok.ru
Coverage complete
Atomic coverage complete across four anonymous public archetypes. Authenticated feeds, account settings, messaging, checkout, and destructive account actions were not covered because no credentials were supplied.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | Under prefers-color-scheme: dark, the screenshot remains a light surface; computed html color-scheme is light and background remains rgb(235,237,240). F1 medium: Dark preference is ignored |
respect-user-preferencesrespects-reduced-motion | pass | high | Computed CSS includes a prefers-reduced-motion rule disabling toast motion; under emulation only one already-finished tooltip animation was reported. |
respect-user-preferencesrespects-contrast | pass | high | Forced-colors screenshot keeps text, fields, icons, consent controls, and primary actions visible. |
implement-natural-interactionsview-transitions | issues | high | Representative public navigation uses ordinary page links, and no transition treatment was observed in the route captures; content swaps are abrupt. F16 low: Route changes do not provide continuity |
implement-natural-interactionsscroll-driven-animations | pass | medium | Representative screenshots, rendered DOM/CSS, Lighthouse and targeted probes showed the expected behavior with no contradictory signal in the audited paths. |
implement-natural-interactionsphysical-gestures | pass | medium | Representative screenshots, rendered DOM/CSS, Lighthouse and targeted probes showed the expected behavior with no contradictory signal in the audited paths. |
provide-guided-navigationscroll-state-aware-chrome | pass | high | Representative screenshots, rendered DOM/CSS, Lighthouse and targeted probes showed the expected behavior with no contradictory signal in the audited paths. |
provide-guided-navigationanchored-positioning | pass | medium | Representative screenshots, rendered DOM/CSS, Lighthouse and targeted probes showed the expected behavior with no contradictory signal in the audited paths. |
provide-guided-navigationdirects-attention | pass | high | Representative screenshots, rendered DOM/CSS, Lighthouse and targeted probes showed the expected behavior with no contradictory signal in the audited paths. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | Desktop and 360px screenshots show the fixed cookie banner covering the OK logo and “Log in to OK” heading; on mobile it occupies much of the first viewport. F2 high: The cookie banner obscures the primary task on load |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | The rendered probe found zero dialog, popover, and details elements while a modal-like consent layer blocks content at the top of every captured page. F17 medium: The consent overlay is custom rather than a semantic overlay primitive |
maximize-content-reduce-noisereduced-chrome | issues | high | On groups and videos, a top consent bar, left navigation and ads, and a fixed bottom login acquisition bar consume substantial viewport space around the primary cards. F19 medium: Non-content chrome crowds public content |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | At 360x800 the layout primitive measured scrollWidth=clientWidth=360 and horizontalOverflowPx=0. |
adapt-to-the-form-factorcomponent-level-responsiveness | pass | high | Desktop and 360px screenshots show the same login component adapting from a centered card to full-width mobile controls. |
adapt-to-the-form-factorinput-modality-aware | issues | high | The rendered probe found 17 visible interactive targets below 24px in at least one dimension, including the 18px-high account-recovery control and multiple 16px-high navigation links. F18 medium: Several controls have undersized hit areas |
support-core-task-successclear-purpose-and-primary-action | pass | high | Representative screenshots, rendered DOM/CSS, Lighthouse and targeted probes showed the expected behavior with no contradictory signal in the audited paths. |
support-core-task-successprimary-flow-completion | pass | high | Representative screenshots, rendered DOM/CSS, Lighthouse and targeted probes showed the expected behavior with no contradictory signal in the audited paths. |
support-core-task-successclear-system-state-and-recovery | issues | high | Clicking submit with empty fields produced no visible validation/error state and no :invalid controls; email and password inputs have no autocomplete values. F13 high: The login form gives no blank-submit recovery and omits autofill tokens |
be-fast-and-stablegood-core-web-vitals | issues | high | Mobile Lighthouse measured LCP 7.5s, FCP 6.7s, TBT 330ms and performance 0.49; the trace corroborated a 2.66s LCP in a lighter desktop run. F6 high: The anonymous entry page is slow and script-heavy |
be-fast-and-stablevisual-stability | pass | high | Layout observer measured CLS 0 on the 360px capture; Lighthouse CLS was 0.048, within the good range. |
be-fast-and-stableefficient-main-thread | issues | high | Mobile Lighthouse measured LCP 7.5s, FCP 6.7s, TBT 330ms and performance 0.49; the trace corroborated a 2.66s LCP in a lighter desktop run. F6 high: The anonymous entry page is slow and script-heavy |
be-fast-and-stableefficient-resource-delivery | issues | high | Mobile Lighthouse measured LCP 7.5s, FCP 6.7s, TBT 330ms and performance 0.49; the trace corroborated a 2.66s LCP in a lighter desktop run. HAR recorded 424 requests, including 297 scripts and 4.64MB transferred script bytes; Lighthouse estimated 1,752KiB unused JavaScript and 556KiB unused CSS. F6 high: The anonymous entry page is slow and script-heavy F7 high: Hundreds of scripts and substantial unused code ship before login |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | HAR recorded 424 requests, including 297 scripts and 4.64MB transferred script bytes; Lighthouse estimated 1,752KiB unused JavaScript and 556KiB unused CSS. F7 high: Hundreds of scripts and substantial unused code ship before login |
be-inclusivenames-roles-labels | issues | high | All four representative pages expose no H1; the probe found 16 empty links, and Lighthouse found a presentation-role conflict on the logo. F5 medium: Document structure and accessible semantics are incomplete |
be-inclusivesufficient-contrast | issues | high | Lighthouse found 2.66:1 contrast for white “Sign in” text on #ff7700 plus other failures, and the viewport contains maximum-scale=1,user-scalable=no. F4 high: Critical login text fails contrast and mobile zoom is disabled |
be-inclusivestructure-and-focus | issues | high | All four representative pages expose no H1; the probe found 16 empty links, and Lighthouse found a presentation-role conflict on the logo. F5 medium: Document structure and accessible semantics are incomplete |
be-inclusivelegible-text | pass | high | Representative screenshots show readable line lengths and no clipped primary content outside the separately reported contrast issue. |
be-inclusivezoom-reflow-targets-and-media | issues | high | Lighthouse found 2.66:1 contrast for white “Sign in” text on #ff7700 plus other failures, and the viewport contains maximum-scale=1,user-scalable=no. The rendered probe found 17 visible interactive targets below 24px in at least one dimension, including the 18px-high account-recovery control and multiple 16px-high navigation links. F4 high: Critical login text fails contrast and mobile zoom is disabled F18 medium: Several controls have undersized hit areas |
follow-best-practicesno-console-errors | issues | high | Lighthouse captured an uncaught MobX error, a deprecated unload listener, six BFCache failure reasons, cookie inspector issues, and a best-practices score of 0.54. F10 medium: Runtime and browser-platform hygiene has regressions |
follow-best-practicessound-document-and-assets | issues | high | The page transfers 6.37MB and 98.5% of bytes are from third-party origins. Discovery has 23/24 images without dimensions, four oversized images, five legacy-format images, and four missing responsive sources. F14 high: Resource and image delivery is wasteful for the public shell |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse captured an uncaught MobX error, a deprecated unload listener, six BFCache failure reasons, cookie inspector issues, and a best-practices score of 0.54. F10 medium: Runtime and browser-platform hygiene has regressions |
be-discoverabletitle-and-description | pass | high | Homepage, groups, discovery, and video probes returned non-empty titles and meta descriptions. |
be-discoverablecrawlable-and-mobile-friendly | issues | high | Lighthouse found 2.66:1 contrast for white “Sign in” text on #ff7700 plus other failures, and the viewport contains maximum-scale=1,user-scalable=no. All four representative pages expose no H1; the probe found 16 empty links, and Lighthouse found a presentation-role conflict on the logo. F4 high: Critical login text fails contrast and mobile zoom is disabled F5 medium: Document structure and accessible semantics are incomplete |
be-discoverablecanonical-and-indexing-signals | issues | high | Discoverability measured only 6% raw/rendered content overlap and classified /discovery as a JS shell; crawler screenshots omit the recommendation content. /video also canonicalises to the homepage and /sitemap.xml returned 404. F11 high: Public recommendations are effectively absent without JavaScript |
be-discoverablestructured-and-shareable-metadata | pass | high | Lighthouse SEO score was 0.92 and the inspected public templates expose descriptive page metadata; no contradictory entity metadata was observed. |
be-private-and-securesecure-transport-and-headers | issues | high | Headers include CSP but permit unsafe-inline and unsafe-eval with broad sources/connect-src *, while Referrer-Policy and Permissions-Policy are absent. The page contacted 25 third-party origins and three known trackers; 14 cookies were found, several without Secure, all SameSite=None, and multiple analytics cookies last 400 days. F8 high: Browser-enforced security policy is weakened F9 high: Tracking and cookie scope are disproportionate on the anonymous login page |
be-private-and-securedata-minimisation-and-third-parties | issues | high | The page contacted 25 third-party origins and three known trackers; 14 cookies were found, several without Secure, all SameSite=None, and multiple analytics cookies last 400 days. F9 high: Tracking and cookie scope are disproportionate on the anonymous login page |
be-private-and-securein-context-permissions-and-modern-auth | issues | high | The login surface offers password and federated providers but no visible passkey/WebAuthn route; the password inputs also lack autocomplete metadata. F20 high: Password remains the primary sign-in path without a visible passkey option |
be-private-and-securedefensive-browser-policies | issues | high | Headers include CSP but permit unsafe-inline and unsafe-eval with broad sources/connect-src *, while Referrer-Policy and Permissions-Policy are absent. The page contacted 25 third-party origins and three known trackers; 14 cookies were found, several without Secure, all SameSite=None, and multiple analytics cookies last 400 days. F8 high: Browser-enforced security policy is weakened F9 high: Tracking and cookie scope are disproportionate on the anonymous login page |
be-resilientprogressive-enhancement | issues | high | Discoverability measured only 6% raw/rendered content overlap and classified /discovery as a JS shell; crawler screenshots omit the recommendation content. /video also canonicalises to the homepage and /sitemap.xml returned 404. F11 high: Public recommendations are effectively absent without JavaScript |
be-resilientresilient-runtime-behaviour | pass | medium | Representative screenshots, rendered DOM/CSS, Lighthouse and targeted probes showed the expected behavior with no contradictory signal in the audited paths. |
be-resilientoffline-and-installable | pass | high | The homepage exposes /manifest.json and a visible install action, direct evidence of installability; the core social feed is intrinsically online. |
be-resilientnetwork-and-http-failure-states | issues | high | Clicking submit with empty fields produced no visible validation/error state and no :invalid controls; email and password inputs have no autocomplete values. F13 high: The login form gives no blank-submit recovery and omits autofill tokens |
be-internationalisedlang-dir-and-logical-properties | issues | high | The groups page declares html lang=en while its title and substantial visible group content are Russian; this gives assistive technology and translation tools the wrong language signal. F12 medium: Language metadata does not match localized content |
be-internationalisedlocale-aware-data | not-applicable | high | No locale-sensitive transaction, currency, duration, or calendar workflow was exposed in the anonymous representative paths. |
be-internationalisedtime-zone-correctness | not-applicable | high | No event scheduling or time-zone-sensitive workflow was exposed in the anonymous representative paths. |
be-trustworthyno-dark-patterns | issues | high | The first-load banner exposes “Allow all” and “Configure”; there is no equally prominent reject-all control in the captured state. F3 high: Consent presents an easy accept path but no equally direct reject path |
be-trustworthyhumane-error-handling | issues | high | Clicking submit with empty fields produced no visible validation/error state and no :invalid controls; email and password inputs have no autocomplete values. F13 high: The login form gives no blank-submit recovery and omits autofill tokens |
be-trustworthytrustworthy-input-assistance | issues | high | Clicking submit with empty fields produced no visible validation/error state and no :invalid controls; email and password inputs have no autocomplete values. F13 high: The login form gives no blank-submit recovery and omits autofill tokens |
be-trustworthysafe-commercial-and-account-flows | issues | high | The first-load banner exposes “Allow all” and “Configure”; there is no equally prominent reject-all control in the captured state. The login surface offers password and federated providers but no visible passkey/WebAuthn route; the password inputs also lack autocomplete metadata. F3 high: Consent presents an easy accept path but no equally direct reject path F20 high: Password remains the primary sign-in path without a visible passkey option |
be-sustainableoptimised-assets | issues | high | The page transfers 6.37MB and 98.5% of bytes are from third-party origins. Discovery has 23/24 images without dimensions, four oversized images, five legacy-format images, and four missing responsive sources. F14 high: Resource and image delivery is wasteful for the public shell |
be-sustainableno-wasteful-work | issues | high | HAR recorded 424 requests, including 297 scripts and 4.64MB transferred script bytes; Lighthouse estimated 1,752KiB unused JavaScript and 556KiB unused CSS. The page transfers 6.37MB and 98.5% of bytes are from third-party origins. Discovery has 23/24 images without dimensions, four oversized images, five legacy-format images, and four missing responsive sources. F7 high: Hundreds of scripts and substantial unused code ship before login F14 high: Resource and image delivery is wasteful for the public shell |
be-sustainablethird-party-and-media-budget | issues | high | The page contacted 25 third-party origins and three known trackers; 14 cookies were found, several without Secure, all SameSite=None, and multiple analytics cookies last 400 days. The page transfers 6.37MB and 98.5% of bytes are from third-party origins. Discovery has 23/24 images without dimensions, four oversized images, five legacy-format images, and four missing responsive sources. F9 high: Tracking and cookie scope are disproportionate on the anonymous login page F14 high: Resource and image delivery is wasteful for the public shell |
be-agent-readystructured-agent-capabilities | not-applicable | high | Emerging capability is not required for this consumer social surface; absence is treated as an opportunity, not a failure. |
be-agent-readyon-device-inference | not-applicable | high | No audited task clearly requires on-device inference; this emerging enhancement is not applicable. |
be-memory-efficientno-leak-under-repeated-interaction | not-applicable | high | Authenticated long-lived interactions were unavailable and the anonymous page had no safe representative open/close or route-back interaction to repeat; no synthetic action was fabricated. |
be-memory-efficientbounded-footprint | issues | high | The baseline heap summary reports 1,105,205 nodes and 74,077,369 self-size bytes for a simple anonymous login surface. A second independent load was similar, indicating a consistently large footprint. F15 medium: The login page has an unusually large in-memory footprint |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | high | Two independent heap summaries were stable (74.08MB/1,105,205 nodes versus 73.67MB/1,104,777 nodes) and no Detached* constructor appeared among dominant populations. |
Provenance
Canonical report: results/atomic/reports/0364-ok_ru.json
Report SHA-256: ea4ff06813ab10f34f507cf46a1b43687eafa3de7652819bbe3926eca8b731de
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/ok_ru/2026-07-20T06-29-30-988Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/ok_ru/2026-07-20T06-29-30-988Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.