Manifest position 612 · CrUX rank bucket 1000

https://www.turkiye.gov.tr

Coverage complete

Coverage-complete public-surface audit. Authenticated/post-login services were excluded because no credentials or test account were supplied.

Attempts
1 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighThe dark-mode screenshot is pixel-identical to the default capture, and the computed root color-scheme is “normal”.
F01 medium: No user-preference-driven dark theme
respect-user-preferences
respects-reduced-motion
issueshighUnder prefers-reduced-motion: reduce, the header and search block still run 1 second fadeIn/fadeInDown animations and many 0.3–1 second transitions remain active.
F02 medium: Reduced-motion preference does not suppress non-essential entrance motion
respect-user-preferences
respects-contrast
issueshighThe prefers-contrast: more screenshot is unchanged from the default capture and no adaptive color-scheme is declared.
F03 low: High-contrast preference produces no adaptation
implement-natural-interactions
view-transitions
issueshighThe platform probe found no view-transition CSS despite the browser API being available; observed route changes are full abrupt navigations.
F04 low: Route and state changes do not use View Transitions
implement-natural-interactions
scroll-driven-animations
passhighPlatform probe found no scroll-linked animation CSS and visual review found no parallax/scrollytelling effect that would require a scroll handler; no misuse was observed.
implement-natural-interactions
physical-gestures
passhighMobile screenshots show native vertical document scrolling and explicit carousel/navigation controls; no custom pointer-driven gesture that fights platform scrolling was observed.
provide-guided-navigation
scroll-state-aware-chrome
issueshighDOM/computed evidence shows a fixed header, while the platform probe found no container/scroll-state rules or scroll timeline; the header does not adapt to page position.
F05 low: Fixed navigation is not scroll-state aware
provide-guided-navigation
anchored-positioning
issueshighThe document-verification share menu is registered through edPopover JavaScript; the platform probe found no CSS anchor positioning rules or native popovers.
F06 low: Transient menus rely on custom JavaScript positioning
provide-guided-navigation
directs-attention
passhighInternal pages expose breadcrumb navigation, search results retain the query, and the verification flow exposes a four-step progress meter.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighLoad screenshots across homepage, listing, content, form, and login show immediate content with no consent wall, popup, or interstitial obscuring it.
maximize-content-reduce-noise
semantic-dismissible-primitives
passhighNo blocking modal appears on load; disclosure and menu controls expose aria-expanded/aria-controls, and the tested flow remains dismissible/cancellable.
maximize-content-reduce-noise
reduced-chrome
passhighMobile screenshots prioritize search, services, results, and form content; the header collapses to one compact bar.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighAt 360×800, layout metrics report scrollWidth=clientWidth=360 and zero horizontal overflow; all representative mobile screenshots reflow.
adapt-to-the-form-factor
component-level-responsiveness
issueshighThe representative pages reflow on mobile, but the platform probe found zero @container rules and computed container-type remains normal.
F07 low: Responsive behavior is viewport-only rather than component-aware
adapt-to-the-form-factor
input-modality-aware
issueshighLighthouse reports 13 target-size failures; the direct probe found 44 visible interactive elements below 24 px in one dimension, including 11×11 carousel controls and 16 px-high footer links.
F08 high: Numerous interactive targets are too small for reliable touch
support-core-task-success
clear-purpose-and-primary-action
passhighThe first viewport prominently exposes service search and five plainly labelled service categories; verification and login screens state purpose and primary action.
support-core-task-success
primary-flow-completion
passhighA search query returned 14 linked results, the public verification flow clearly states four stages, and login offers five authentication routes plus cancel/recovery; completion beyond authentication was intentionally not attempted without credentials.
support-core-task-success
clear-system-state-and-recovery
passhighInvalid verification submission shows a required-field error, the login page provides cancel and forgot-password actions, and the unknown route gives Back and Home recovery.
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse measured LCP 4.7 s, FCP 3.6 s, and performance 0.74; the separate trace measured LCP 2.46 s, showing variability around/above the good threshold.
F09 high: Mobile loading performance misses the good LCP range
be-fast-and-stable
visual-stability
passhighThe 5 s mobile layout capture reports CLS 0 with no observed shifts; homepage images that lead the viewport reserve dimensions.
be-fast-and-stable
efficient-main-thread
passhighTrace recorded one 84 ms long task and 34 ms total blocking time, while Lighthouse measured 0 ms TBT; scripting did not dominate the tested load.
be-fast-and-stable
efficient-resource-delivery
issueshighThe HAR summary identifies two VeryHigh-priority stylesheets and four classic parser-inserted head scripts without async/defer/module; the DOM confirms these script attributes are absent.
F10 medium: Parser-blocking resources lengthen the critical path
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighLighthouse estimates 22 KiB unused JavaScript and 11 KiB unused CSS on the homepage.
F11 medium: The page ships measurable unused CSS and JavaScript
be-inclusive
names-roles-labels
issueshighLighthouse flags the my.gov.az link because its aria-labelledby name omits the visible URL/new-window text.
F12 high: An interactive link’s accessible name does not match its visible label
be-inclusive
sufficient-contrast
issueshighLighthouse found seven contrast failures, including #4284be text on white/grey (3.32–3.98:1) and white text with a low-contrast teal text shadow.
F13 high: Multiple text styles fail WCAG contrast
be-inclusive
structure-and-focus
issueshighLighthouse reports landmark-one-main failure, and the homepage DOM has zero <main> elements even though internal templates do use one.
F14 high: The homepage lacks a main landmark
be-inclusive
legible-text
passhighRepresentative 360 px screenshots show readable line wrapping, stable card/form alignment, and no clipping or horizontal truncation.
be-inclusive
zoom-reflow-targets-and-media
issueshighThe 360 px layout itself has zero horizontal overflow, but Lighthouse reports 13 target-size failures across the reflowed homepage.
F15 high: Touch target sizing undermines inclusive reflow
follow-best-practices
no-console-errors
passhighLighthouse errors-in-console audit passed and no uncaught exception appeared during the representative page captures.
follow-best-practices
sound-document-and-assets
issueshighThe image audit found 26 of 35 images without width/height, 15 oversized images, 14 without responsive sources, and 24 legacy-format resources (including placeholders/icons).
F16 medium: Image delivery lacks robust intrinsic and responsive sizing
follow-best-practices
browser-platform-hygiene
issueshighLighthouse reports one BFCache failure reason, reducing instant restoration on back navigation.
F17 medium: The homepage is not eligible for back/forward cache
be-discoverable
title-and-description
passhighDOM evidence across homepage, search, information, verification, and login shows non-empty titles and a meta description.
be-discoverable
crawlable-and-mobile-friendly
passhighRobots allows all, the sitemap is populated, viewport metadata is present, and discoverability captures show 100% content coverage without JavaScript on home/list/search.
be-discoverable
canonical-and-indexing-signals
issueshighThe probe found no canonical and zero hreflang links despite Turkish and English variants; robots and sitemap are otherwise present and permissive.
F18 medium: Localized public pages omit canonical and hreflang signals
be-discoverable
structured-and-shareable-metadata
issueshighThe homepage exposes four Open Graph tags but no JSON-LD for the government organization/site or search action.
F19 low: Rich entity metadata stops at Open Graph
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS and nosniff are present, but HSTS is absent, CSP permits unsafe-inline and unsafe-eval, Referrer-Policy is unsafe-url, and all five first-party cookies use SameSite=None.
F20 critical: Security headers and cookie posture are weaker than expected for a national identity portal
be-private-and-secure
data-minimisation-and-third-parties
passhighTracker capture found no known tracker domain and only the controlled e-Devlet CDN plus first-party analytics; secrets scan found no exposed credential.
be-private-and-secure
in-context-permissions-and-modern-auth
passhighNo permission prompt appeared on load; login offers password, electronic signature, mobile signature, internet banking, and national ID card rather than password alone.
be-private-and-secure
defensive-browser-policies
issueshighThe header audit found no Permissions-Policy and neither X-Frame-Options nor CSP frame-ancestors; CSP also lacks Trusted Types/origin-isolation protections.
F21 high: Defensive browser policies are incomplete
be-resilient
progressive-enhancement
issueshighDiscoverability shows 100% raw-content coverage, but the authored noscript message states e-Devlet requires JavaScript and core form behavior is script-dependent.
F22 high: Core interaction requires JavaScript despite server-rendered content
be-resilient
resilient-runtime-behaviour
passhighRepresentative mobile pages and the share/menu/login controls render within viewport bounds; no cut-off overlay, blank shell, or unstable state was observed.
be-resilient
offline-and-installable
issueshighThe platform probe found no web app manifest and the homepage exposes no service-worker registration path, despite being a high-use app-like portal.
F23 medium: The app-like public service has no installable/offline web fallback
be-resilient
network-and-http-failure-states
passhighThe unknown route renders a clear 404 explanation with Back, Home, and footer navigation instead of a blank shell.
be-internationalised
lang-dir-and-logical-properties
issueshighThe English variant correctly sets lang=en, but its first 1,000 characters still include Turkish labels such as “Ana Sayfa”, “Ana Bölümler”, banner copy, and “Yeni Sekmede Açılır”.
F24 medium: The English locale remains partly untranslated
be-internationalised
locale-aware-data
issueshighThe English route retains Turkish tax-period text and date wording instead of localized number/date content.
F25 medium: Locale-sensitive content does not fully adapt to English
be-internationalised
time-zone-correctness
not-applicablehighThe representative public pages show dates but no time-of-day, time-zone coordination, recurring event scheduling, or DST-sensitive interaction to evaluate.
be-trustworthy
no-dark-patterns
passhighNo consent wall, disguised ad, forced continuity, preselected purchase, or confirmshaming was observed; login provides an equally visible cancel action.
be-trustworthy
humane-error-handling
passhighSubmitting the empty required verification field produces the specific Turkish message “Bu alanın doldurulması zorunludur” while preserving context.
be-trustworthy
trustworthy-input-assistance
issueshighThe public verification field and both login identity/password fields explicitly use autocomplete=off; the login form itself is also autocomplete=off.
F26 high: Key identity and verification inputs disable autofill
be-trustworthy
safe-commercial-and-account-flows
passhighThe authentication surface presents multiple methods, password recovery, explicit cancel, and contextual security guidance; no commercial commitment is present in tested public flows.
be-sustainable
optimised-assets
issueshighThe image audit found 15 oversized images, 27 below-fold images without native lazy loading, and 14 images without srcset.
F27 medium: Asset sizing creates avoidable transfer waste
be-sustainable
no-wasteful-work
passhighTrace showed low blocking time, HAR found only one tiny analytics beacon beyond CDN assets, and no autoplay audio/video or persistent background media was observed.
be-sustainable
third-party-and-media-budget
issueshighThe 760 KB homepage load includes 10 font requests totaling 254 KB and 51 cross-origin CDN/analytics requests totaling about 750 KB, though no known commercial tracker was detected.
F28 medium: Font and CDN transfer cost is high for a mostly informational first view
be-agent-ready
structured-agent-capabilities
issueshighThe probe found no WebMCP surface; agents must infer search and verification semantics from page markup even though raw content is crawlable.
F29 low: High-value government tasks are not exposed as structured agent capabilities
be-agent-ready
on-device-inference
not-applicablehighThe tested search, directory, verification, and authentication tasks do not present an appropriate summarisation/generation workload where built-in on-device inference would clearly improve the experience.
be-memory-efficient
no-leak-under-repeated-interaction
passhighAfter 60 carousel state changes, heap self-size rose only ~106 KB (1.3%) and node count ~1.3% versus a fresh baseline, not evidence of unbounded retained growth.
be-memory-efficient
bounded-footprint
passhighBaseline heap was 7.97 MB self-size with 119,575 snapshot nodes for a 620-element public homepage, proportionate to the tested surface.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passhighBaseline/post heap summaries show no Detached* constructor among top retained constructors and only small bounded closure/object changes after 60 state changes.

Provenance

Canonical report: results/atomic/reports/0612-www_turkiye_gov_tr.json
Report SHA-256: 969b8456cf92d3b740cfa770666dce8ca2ecd08d18fcecdedb9a3561c12e58a4
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_turkiye_gov_tr/2026-07-21T22-41-00-588Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_turkiye_gov_tr/2026-07-21T22-41-00-588Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.