Manifest position 432 · CrUX rank bucket 1000

https://www.pornpics.com

Coverage complete

Coverage-complete report-mode audit. Representative public templates, search, login validation, localization and 404 recovery were covered. Authenticated favorites/profile/upload, sign-up completion, voting/comments, age-verification completion and external affiliate destinations were not covered because they require accounts, identity data, side effects or leave the first-party site.

Attempts
2 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighSystem dark emulation did not retint the light surface; no prefers-color-scheme CSS exists.
F001 medium: The manual theme control does not follow the operating-system color preference.
respect-user-preferences
respects-reduced-motion
passhighNo running page animations were present and the stylesheet has no motion rules, so reduced-motion users receive a static experience.
respect-user-preferences
respects-contrast
passhighForced-colors/high-contrast emulation retained visible text, controls and borders throughout the first mobile viewport.
implement-natural-interactions
view-transitions
issueshighNo authored View Transition rules were found for route/state changes.
F002 low: Route and major state changes use abrupt document swaps rather than View Transitions.
implement-natural-interactions
scroll-driven-animations
not-applicablehighNo parallax, scrollytelling or scroll-linked reveal feature exists on the representative pages, so there is no scroll-linked animation implementation to evaluate.
implement-natural-interactions
physical-gestures
passmediumBrowsing uses native links and scrolling; no custom pointer-driven gestures or scroll handlers that fight platform behavior were observed.
provide-guided-navigation
scroll-state-aware-chrome
issueshighA 108,770px mobile listing has no reactive sticky chrome or progress cue.
F003 low: Very long listing pages provide no scroll-state-aware navigation or progress cue.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip, attached popover, context menu or edge-positioned overlay requiring CSS anchor positioning appears in the representative browse/login/detail flows.
provide-guided-navigation
directs-attention
passmediumEach navigation destination exposes a specific H1 and active contextual taxonomy; the 404 provides a clear return link.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighThe cookie notice is fixed over lower first-viewport content on desktop and mobile.
F004 medium: A fixed consent banner obscures content in the first viewport on every tested public template.
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighThe consent overlay is a custom fixed div; no dialog or popover primitive is present.
F005 low: The fixed consent surface is an ad-hoc div rather than an explicit semantic overlay/banner primitive.
maximize-content-reduce-noise
reduced-chrome
passhighOutside the compact global header/nav and consent notice, the gallery grid dedicates nearly all visible space to the primary content.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighAt the narrow viewport, layout reported scrollWidth=clientWidth=450 and zero horizontal overflow; the mobile screenshot shows a single-column adaptive layout.
adapt-to-the-form-factor
component-level-responsiveness
issueshighNo container queries were found in the shared stylesheets.
F006 low: Responsive behavior is entirely viewport-based rather than component-aware.
adapt-to-the-form-factor
input-modality-aware
issueshighPrimary focused controls have no visible focus style and some hit targets are below 24px.
F007 medium: Keyboard focus is not visibly exposed on key controls and some targets are too small.
support-core-task-success
clear-purpose-and-primary-action
passhighHomepage, category and detail templates each use a direct H1 and put the browse/view content immediately below the header.
support-core-task-success
primary-flow-completion
passhighThe representative journey completed from homepage taxonomy to category listing to gallery detail; search also resolved a query to the matching category.
support-core-task-success
clear-system-state-and-recovery
passhighBlank login submission exposes field-specific required messages and aria-invalid; the 404 clearly states failure and links back to the main page.
be-fast-and-stable
good-core-web-vitals
issueshighStandard Lighthouse throttling measured LCP 5.6s and FCP 3.1s, outside good ranges.
F008 high: Mobile LCP misses the good Core Web Vitals range under standard Lighthouse throttling.
be-fast-and-stable
visual-stability
passhighLayout observers measured CLS 0 on mobile and 0.000011 on desktop; the principal images reserve dimensions.
be-fast-and-stable
efficient-main-thread
passhighTrace recorded one 55.9ms long task and only 5.9ms total blocking time; Lighthouse TBT was 67ms.
be-fast-and-stable
efficient-resource-delivery
issueshighCritical CSS, delayed LCP rendering and oversized legacy images add avoidable delivery cost.
F009 high: Critical CSS and unoptimised images delay meaningful content.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighLighthouse estimated 224KiB unused JS and 28KiB unused CSS.
F010 medium: The homepage ships substantial unused JavaScript and CSS.
be-inclusive
names-roles-labels
issueshighTwo linked certification images have no alt and their links have no discernible name.
F011 medium: Some image links in the age-information surface have no accessible name.
be-inclusive
sufficient-contrast
issueshighObserved text combinations measured 2.92:1 and 3.63:1, below 4.5:1.
F012 medium: Several text/link combinations fail WCAG contrast minimums.
be-inclusive
structure-and-focus
issueshighSearch and menu controls lose visible focus indication.
F013 high: Visible keyboard focus is missing on primary controls.
be-inclusive
legible-text
passhighHeadings, controls and body copy are readable without clipping in desktop/mobile screenshots; page-specific H1 text remains visible on listing/detail/login templates.
be-inclusive
zoom-reflow-targets-and-media
issueshighinitial-scale=0.8 and sub-24px targets weaken mobile/zoom usability.
F014 medium: The viewport scale and compact targets weaken zoom/touch usability.
follow-best-practices
no-console-errors
issueshighAnonymous load logs an identity-provider signed-out error.
F015 low: The homepage logs an identity-provider error for signed-out visitors.
follow-best-practices
sound-document-and-assets
issueshighDocument doctype/charset are valid, but certification images lack explicit dimensions.
F016 low: A small set of certification images lacks explicit dimensions.
follow-best-practices
browser-platform-hygiene
issueshighLarge first-party bundle lacks a valid source map.
F017 low: The large first-party JavaScript bundle has no valid production source map.
be-discoverable
title-and-description
passhighHomepage, category and detail all expose descriptive titles; homepage and detail expose relevant descriptions.
be-discoverable
crawlable-and-mobile-friendly
passhighLinks use real href values, viewport metadata exists, robots allows primary public paths, and raw HTML retains 90% of rendered content.
be-discoverable
canonical-and-indexing-signals
issueshighNo canonical/hreflang signals were found and the public detail template is noindex,follow.
F018 medium: Indexing signals are incomplete and inconsistent across public templates.
be-discoverable
structured-and-shareable-metadata
issueshighThe gallery detail page has no JSON-LD or Open Graph metadata.
F019 medium: Gallery detail pages expose neither structured entity data nor social preview metadata.
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS/HSTS are present, but CSP is wildcard/unsafe and every observed cookie lacks Secure.
F020 high: A permissive CSP and insecure cookies weaken an otherwise HTTPS/HSTS transport posture.
be-private-and-secure
data-minimisation-and-third-parties
passmediumNo known tracker origins or exposed secrets were found; the only external runtime origin was Google Identity for an offered sign-in path.
be-private-and-secure
in-context-permissions-and-modern-auth
issueshighNo permission prompt occurred, but authentication exposes password/federated sign-in only and no passkey path.
F021 medium: Authentication offers password and federated login but no phishing-resistant passkey path.
be-private-and-secure
defensive-browser-policies
issueshighnosniff and Permissions-Policy are missing; frame/referrer/CSP policies are broad.
F022 high: Several browser-enforced defenses are absent or too weak.
be-resilient
progressive-enhancement
passhighRaw HTML retained 90% of rendered content, including title, H1 and description; the page is not a JS shell.
be-resilient
resilient-runtime-behaviour
passmediumThe mobile menu interaction completed without clipping/crash, standard links remained usable, and no runtime blank state appeared.
be-resilient
offline-and-installable
not-applicablehighThis is a public media/content website rather than an app whose core browsing flow is expected to work offline; a standalone manifest exists, but offline installation is not required for the audited task.
be-resilient
network-and-http-failure-states
passmediumThe representative missing route renders a clear 404 explanation and a direct return to the main page instead of a blank shell or spinner.
be-internationalised
lang-dir-and-logical-properties
issueshighSpanish content and lang are correct, but CSS relies entirely on physical directional properties.
F023 medium: Localized pages set lang correctly but the shared CSS is not writing-mode resilient.
be-internationalised
locale-aware-data
not-applicablehighThe representative templates do not present dates, prices, currencies, localized numeric inputs, durations or calendar data requiring locale-aware formatting.
be-internationalised
time-zone-correctness
not-applicablehighThe representative browse, gallery and sign-in templates expose no events, schedules, timestamps or recurring time concepts.
be-trustworthy
no-dark-patterns
passmediumThe consent banner gives Reject All and Accept All equal visual prominence, provides Manage, and the sampled browse/login flows did not force continuity or hide cancellation.
be-trustworthy
humane-error-handling
passhighSubmitting blank login fields produces concise field-specific messages and sets aria-invalid without navigation or lost context.
be-trustworthy
trustworthy-input-assistance
passhighVisible sign-in fields use username and current-password autocomplete tokens and expose programmatic labels via aria-label.
be-trustworthy
safe-commercial-and-account-flows
passmediumThe sampled account entry exposes recovery, sign-up and federated sign-in alongside the standard login; no subscription/checkout commitment was part of the audited first-party flow.
be-sustainable
optimised-assets
issueshighLegacy formats, absent responsive sources and avoidable eager/oversized imagery dominate this media-heavy site.
F024 high: The image-heavy experience sends legacy, non-responsive assets at avoidable cost.
be-sustainable
no-wasteful-work
passmediumInitial load used 28 requests and trace showed 5.9ms blocking time with no ongoing media; no known tracker or continuous background workload was observed.
be-sustainable
third-party-and-media-budget
issueshighFor an image grid the media is useful, but non-responsive legacy images create avoidable transfer cost and the initial page still downloads a 99KB identity script before login is requested.
F024 high: The image-heavy experience sends legacy, non-responsive assets at avoidable cost.
be-agent-ready
structured-agent-capabilities
not-applicablehighNo developer intent or agent-facing transaction surface was declared; this emerging capability is optional here. Public content is nevertheless exposed in semantic raw HTML and crawlable links.
be-agent-ready
on-device-inference
not-applicablehighThe audited browse, gallery and sign-in tasks have no clear need for on-device language-model or summarisation features.
be-memory-efficient
no-leak-under-repeated-interaction
passmediumAfter 10 full-page scroll cycles, DOM element count was unchanged; heap snapshot size rose about 4.8% while lazy content was exercised, and closure count slightly decreased, providing no evidence of unbounded retained growth in this window.
be-memory-efficient
bounded-footprint
passmediumBaseline heap self-size was about 10.1MB with 158,828 heap nodes, proportionate to a long image grid; rendered DOM contained 1,161 elements.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumNo Detached constructor appeared among the dominant heap constructors, rendered DOM count stayed unchanged after repetition, and closure count fell from 6,207 to 6,198.

Provenance

Canonical report: results/atomic/reports/0432-www_pornpics_com.json
Report SHA-256: 13127deff12ab75e577c0ad01914390cafa6276673b544901c8ab41825cc044d
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_pornpics_com/2026-07-26T10-32-13-966Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_pornpics_com/2026-07-26T10-32-13-966Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.