Manifest position 432 · CrUX rank bucket 1000
https://www.pornpics.com
Coverage complete
Coverage-complete report-mode audit. Representative public templates, search, login validation, localization and 404 recovery were covered. Authenticated favorites/profile/upload, sign-up completion, voting/comments, age-verification completion and external affiliate destinations were not covered because they require accounts, identity data, side effects or leave the first-party site.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | System dark emulation did not retint the light surface; no prefers-color-scheme CSS exists. F001 medium: The manual theme control does not follow the operating-system color preference. |
respect-user-preferencesrespects-reduced-motion | pass | high | No running page animations were present and the stylesheet has no motion rules, so reduced-motion users receive a static experience. |
respect-user-preferencesrespects-contrast | pass | high | Forced-colors/high-contrast emulation retained visible text, controls and borders throughout the first mobile viewport. |
implement-natural-interactionsview-transitions | issues | high | No authored View Transition rules were found for route/state changes. F002 low: Route and major state changes use abrupt document swaps rather than View Transitions. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No parallax, scrollytelling or scroll-linked reveal feature exists on the representative pages, so there is no scroll-linked animation implementation to evaluate. |
implement-natural-interactionsphysical-gestures | pass | medium | Browsing uses native links and scrolling; no custom pointer-driven gestures or scroll handlers that fight platform behavior were observed. |
provide-guided-navigationscroll-state-aware-chrome | issues | high | A 108,770px mobile listing has no reactive sticky chrome or progress cue. F003 low: Very long listing pages provide no scroll-state-aware navigation or progress cue. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip, attached popover, context menu or edge-positioned overlay requiring CSS anchor positioning appears in the representative browse/login/detail flows. |
provide-guided-navigationdirects-attention | pass | medium | Each navigation destination exposes a specific H1 and active contextual taxonomy; the 404 provides a clear return link. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | The cookie notice is fixed over lower first-viewport content on desktop and mobile. F004 medium: A fixed consent banner obscures content in the first viewport on every tested public template. |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | The consent overlay is a custom fixed div; no dialog or popover primitive is present. F005 low: The fixed consent surface is an ad-hoc div rather than an explicit semantic overlay/banner primitive. |
maximize-content-reduce-noisereduced-chrome | pass | high | Outside the compact global header/nav and consent notice, the gallery grid dedicates nearly all visible space to the primary content. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | At the narrow viewport, layout reported scrollWidth=clientWidth=450 and zero horizontal overflow; the mobile screenshot shows a single-column adaptive layout. |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | No container queries were found in the shared stylesheets. F006 low: Responsive behavior is entirely viewport-based rather than component-aware. |
adapt-to-the-form-factorinput-modality-aware | issues | high | Primary focused controls have no visible focus style and some hit targets are below 24px. F007 medium: Keyboard focus is not visibly exposed on key controls and some targets are too small. |
support-core-task-successclear-purpose-and-primary-action | pass | high | Homepage, category and detail templates each use a direct H1 and put the browse/view content immediately below the header. |
support-core-task-successprimary-flow-completion | pass | high | The representative journey completed from homepage taxonomy to category listing to gallery detail; search also resolved a query to the matching category. |
support-core-task-successclear-system-state-and-recovery | pass | high | Blank login submission exposes field-specific required messages and aria-invalid; the 404 clearly states failure and links back to the main page. |
be-fast-and-stablegood-core-web-vitals | issues | high | Standard Lighthouse throttling measured LCP 5.6s and FCP 3.1s, outside good ranges. F008 high: Mobile LCP misses the good Core Web Vitals range under standard Lighthouse throttling. |
be-fast-and-stablevisual-stability | pass | high | Layout observers measured CLS 0 on mobile and 0.000011 on desktop; the principal images reserve dimensions. |
be-fast-and-stableefficient-main-thread | pass | high | Trace recorded one 55.9ms long task and only 5.9ms total blocking time; Lighthouse TBT was 67ms. |
be-fast-and-stableefficient-resource-delivery | issues | high | Critical CSS, delayed LCP rendering and oversized legacy images add avoidable delivery cost. F009 high: Critical CSS and unoptimised images delay meaningful content. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | Lighthouse estimated 224KiB unused JS and 28KiB unused CSS. F010 medium: The homepage ships substantial unused JavaScript and CSS. |
be-inclusivenames-roles-labels | issues | high | Two linked certification images have no alt and their links have no discernible name. F011 medium: Some image links in the age-information surface have no accessible name. |
be-inclusivesufficient-contrast | issues | high | Observed text combinations measured 2.92:1 and 3.63:1, below 4.5:1. F012 medium: Several text/link combinations fail WCAG contrast minimums. |
be-inclusivestructure-and-focus | issues | high | Search and menu controls lose visible focus indication. F013 high: Visible keyboard focus is missing on primary controls. |
be-inclusivelegible-text | pass | high | Headings, controls and body copy are readable without clipping in desktop/mobile screenshots; page-specific H1 text remains visible on listing/detail/login templates. |
be-inclusivezoom-reflow-targets-and-media | issues | high | initial-scale=0.8 and sub-24px targets weaken mobile/zoom usability. F014 medium: The viewport scale and compact targets weaken zoom/touch usability. |
follow-best-practicesno-console-errors | issues | high | Anonymous load logs an identity-provider signed-out error. F015 low: The homepage logs an identity-provider error for signed-out visitors. |
follow-best-practicessound-document-and-assets | issues | high | Document doctype/charset are valid, but certification images lack explicit dimensions. F016 low: A small set of certification images lacks explicit dimensions. |
follow-best-practicesbrowser-platform-hygiene | issues | high | Large first-party bundle lacks a valid source map. F017 low: The large first-party JavaScript bundle has no valid production source map. |
be-discoverabletitle-and-description | pass | high | Homepage, category and detail all expose descriptive titles; homepage and detail expose relevant descriptions. |
be-discoverablecrawlable-and-mobile-friendly | pass | high | Links use real href values, viewport metadata exists, robots allows primary public paths, and raw HTML retains 90% of rendered content. |
be-discoverablecanonical-and-indexing-signals | issues | high | No canonical/hreflang signals were found and the public detail template is noindex,follow. F018 medium: Indexing signals are incomplete and inconsistent across public templates. |
be-discoverablestructured-and-shareable-metadata | issues | high | The gallery detail page has no JSON-LD or Open Graph metadata. F019 medium: Gallery detail pages expose neither structured entity data nor social preview metadata. |
be-private-and-securesecure-transport-and-headers | issues | high | HTTPS/HSTS are present, but CSP is wildcard/unsafe and every observed cookie lacks Secure. F020 high: A permissive CSP and insecure cookies weaken an otherwise HTTPS/HSTS transport posture. |
be-private-and-securedata-minimisation-and-third-parties | pass | medium | No known tracker origins or exposed secrets were found; the only external runtime origin was Google Identity for an offered sign-in path. |
be-private-and-securein-context-permissions-and-modern-auth | issues | high | No permission prompt occurred, but authentication exposes password/federated sign-in only and no passkey path. F021 medium: Authentication offers password and federated login but no phishing-resistant passkey path. |
be-private-and-securedefensive-browser-policies | issues | high | nosniff and Permissions-Policy are missing; frame/referrer/CSP policies are broad. F022 high: Several browser-enforced defenses are absent or too weak. |
be-resilientprogressive-enhancement | pass | high | Raw HTML retained 90% of rendered content, including title, H1 and description; the page is not a JS shell. |
be-resilientresilient-runtime-behaviour | pass | medium | The mobile menu interaction completed without clipping/crash, standard links remained usable, and no runtime blank state appeared. |
be-resilientoffline-and-installable | not-applicable | high | This is a public media/content website rather than an app whose core browsing flow is expected to work offline; a standalone manifest exists, but offline installation is not required for the audited task. |
be-resilientnetwork-and-http-failure-states | pass | medium | The representative missing route renders a clear 404 explanation and a direct return to the main page instead of a blank shell or spinner. |
be-internationalisedlang-dir-and-logical-properties | issues | high | Spanish content and lang are correct, but CSS relies entirely on physical directional properties. F023 medium: Localized pages set lang correctly but the shared CSS is not writing-mode resilient. |
be-internationalisedlocale-aware-data | not-applicable | high | The representative templates do not present dates, prices, currencies, localized numeric inputs, durations or calendar data requiring locale-aware formatting. |
be-internationalisedtime-zone-correctness | not-applicable | high | The representative browse, gallery and sign-in templates expose no events, schedules, timestamps or recurring time concepts. |
be-trustworthyno-dark-patterns | pass | medium | The consent banner gives Reject All and Accept All equal visual prominence, provides Manage, and the sampled browse/login flows did not force continuity or hide cancellation. |
be-trustworthyhumane-error-handling | pass | high | Submitting blank login fields produces concise field-specific messages and sets aria-invalid without navigation or lost context. |
be-trustworthytrustworthy-input-assistance | pass | high | Visible sign-in fields use username and current-password autocomplete tokens and expose programmatic labels via aria-label. |
be-trustworthysafe-commercial-and-account-flows | pass | medium | The sampled account entry exposes recovery, sign-up and federated sign-in alongside the standard login; no subscription/checkout commitment was part of the audited first-party flow. |
be-sustainableoptimised-assets | issues | high | Legacy formats, absent responsive sources and avoidable eager/oversized imagery dominate this media-heavy site. F024 high: The image-heavy experience sends legacy, non-responsive assets at avoidable cost. |
be-sustainableno-wasteful-work | pass | medium | Initial load used 28 requests and trace showed 5.9ms blocking time with no ongoing media; no known tracker or continuous background workload was observed. |
be-sustainablethird-party-and-media-budget | issues | high | For an image grid the media is useful, but non-responsive legacy images create avoidable transfer cost and the initial page still downloads a 99KB identity script before login is requested. F024 high: The image-heavy experience sends legacy, non-responsive assets at avoidable cost. |
be-agent-readystructured-agent-capabilities | not-applicable | high | No developer intent or agent-facing transaction surface was declared; this emerging capability is optional here. Public content is nevertheless exposed in semantic raw HTML and crawlable links. |
be-agent-readyon-device-inference | not-applicable | high | The audited browse, gallery and sign-in tasks have no clear need for on-device language-model or summarisation features. |
be-memory-efficientno-leak-under-repeated-interaction | pass | medium | After 10 full-page scroll cycles, DOM element count was unchanged; heap snapshot size rose about 4.8% while lazy content was exercised, and closure count slightly decreased, providing no evidence of unbounded retained growth in this window. |
be-memory-efficientbounded-footprint | pass | medium | Baseline heap self-size was about 10.1MB with 158,828 heap nodes, proportionate to a long image grid; rendered DOM contained 1,161 elements. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | medium | No Detached constructor appeared among the dominant heap constructors, rendered DOM count stayed unchanged after repetition, and closure count fell from 6,207 to 6,198. |
Provenance
Canonical report: results/atomic/reports/0432-www_pornpics_com.json
Report SHA-256: 13127deff12ab75e577c0ad01914390cafa6276673b544901c8ab41825cc044d
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_pornpics_com/2026-07-26T10-32-13-966Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_pornpics_com/2026-07-26T10-32-13-966Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.