Manifest position 636 · CrUX rank bucket 1000
https://www.netflix.com
Coverage complete
Coverage-complete audit of four representative unauthenticated paths. Authenticated browsing, playback, account settings, payment completion, help/media/jobs/shop subdomains, and logged-in cancellation were not covered because they require credentials, a commercial commitment, or use distinct properties.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | Default and dark-preference screenshots are byte-identical; computed color-scheme is normal rather than light dark. F03 low: The page is fixed to a dark palette rather than explicitly integrating the user color-scheme preference. |
respect-user-preferencesrespects-reduced-motion | pass | medium | Reduced-motion emulation matched and document.getAnimations() returned zero; CSS contains a reduced-motion rule. |
respect-user-preferencesrespects-contrast | pass | medium | Forced-colors screenshot preserves readable text, outlines, fields, and all primary controls. |
implement-natural-interactionsview-transitions | issues | high | CSS inspection found no view-transition rules; the signup and login journey uses ordinary page swaps. F04 low: Public state and route changes have no authored View Transition treatment. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No scroll-linked animation, parallax, scrollytelling, or entry reveal exists on the representative public pages. |
implement-natural-interactionsphysical-gestures | pass | medium | Representative controls use ordinary click, focus, native scrolling, and disclosure interactions; no custom pointer-driven gesture was observed. |
provide-guided-navigationscroll-state-aware-chrome | not-applicable | high | The tested public pages have no sticky or affixed chrome whose state needs to react to scroll position. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip, transient menu, or edge-sensitive popover appears in the representative unauthenticated surfaces. |
provide-guided-navigationdirects-attention | pass | medium | The hero, focused Sign In control, Get Started action, and numbered/section hierarchy visibly direct attention on desktop and mobile. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | Desktop and mobile screenshots show the on-load banner covering the hero or form; on 360x800 it consumes roughly the upper quarter of the viewport. F01 high: The consent notice obscures core acquisition content on every tested entry surface. |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | The DOM probe found zero dialog, popover, or details elements while screenshots show an overlay and the page contains accordion disclosures. F02 medium: Consent and FAQ disclosure UI do not use the most appropriate native primitives. |
maximize-content-reduce-noisereduced-chrome | pass | medium | Outside the consent notice, the page gives the viewport to content and uses restrained chrome with a clear hero and content sections. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | medium | Layout captures on home, login, and signup all report 0px horizontal overflow at 360px. |
adapt-to-the-form-factorcomponent-level-responsiveness | pass | medium | Live CSS inspection found three container rules, and mobile/desktop screenshots show components reflowing rather than simply shrinking. |
adapt-to-the-form-factorinput-modality-aware | issues | high | The 360px probe measured Sign In at 77x32, Learn more at 117x40, and footer links around 21px high, although keyboard focus was visible. F05 medium: Several mobile controls and links fall below a comfortable 44 CSS pixel touch target. |
support-core-task-successclear-purpose-and-primary-action | pass | medium | The home H1, price statement, email field, and Get Started button make the offer and next action explicit; login and signup each have a single clear task. |
support-core-task-successprimary-flow-completion | pass | medium | The public pre-commit journey reaches signup plan choice and login without dead ends; the audit intentionally did not create or purchase a real account. |
support-core-task-successclear-system-state-and-recovery | issues | high | On landing and login forms, empty submission moved focus to the first field but yielded no role=alert/aria-live message or explicit error text in the probe. F06 medium: Empty form submission does not expose clear, inspectable error messaging or an announced recovery state. |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse measured LCP 4.1s, TBT 266ms, max potential FID 452ms, and TTI 16.9s; the trace recorded two long tasks and 114.6ms TBT. F07 high: Mobile lab loading is outside the good LCP range and interaction readiness is delayed. |
be-fast-and-stablevisual-stability | pass | medium | Observed CLS was 0.0015 on home and 0 on login/signup, with no visible late jump in screenshots. |
be-fast-and-stableefficient-main-thread | issues | high | Lighthouse measured LCP 4.1s, TBT 266ms, max potential FID 452ms, and TTI 16.9s; the trace recorded two long tasks and 114.6ms TBT. F07 high: Mobile lab loading is outside the good LCP range and interaction readiness is delayed. |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR recorded 2.62MB transferred, including 1.29MB scripts and 680KB fonts. The largest script is 762KB; Lighthouse estimates 729KiB unused JS, and the LCP image lacks fetchpriority=high. F08 medium: The landing page ships a large startup payload with avoidable unused code and an unprioritised LCP image. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | HAR recorded 2.62MB transferred, including 1.29MB scripts and 680KB fonts. The largest script is 762KB; Lighthouse estimates 729KiB unused JS, and the LCP image lacks fetchpriority=high. F08 medium: The landing page ships a large startup payload with avoidable unused code and an unprioritised LCP image. |
be-inclusivenames-roles-labels | pass | medium | Lighthouse passed button-name, label, link-name, and contrast audits; the forms expose labels and decorative hero imagery is aria-hidden. |
be-inclusivesufficient-contrast | pass | medium | Lighthouse color-contrast audit passed, and forced-colors capture keeps content and controls distinct. |
be-inclusivestructure-and-focus | issues | high | Lighthouse identifies the “Ready to watch?” H3 immediately following the H1 as an invalid heading-order element. F09 medium: The landing page heading hierarchy skips from H1 to H3. |
be-inclusivelegible-text | pass | medium | Screenshots show readable type sizes, spacing, line lengths, and no clipping across desktop and 360px layouts. |
be-inclusivezoom-reflow-targets-and-media | issues | high | Lighthouse found maximum-scale=1.0 in the viewport meta tag on home, login, and signup probes. F10 high: The viewport declaration prevents effective mobile zoom. |
follow-best-practicesno-console-errors | issues | high | Lighthouse captured “Refused to get unsafe header X-OneTrust-IsBot” from otSDKStub.js. F11 low: A third-party consent script logs a browser console error. |
follow-best-practicessound-document-and-assets | issues | high | The image probe found no width/height attributes on four images and two images over twice their display width; doctype and charset are valid and observed CLS is low. F22 low: Image markup omits intrinsic dimensions and includes oversized candidates. |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse reports cookie inspector issues and three BFCache failure reasons, led by Cache-Control: no-store on the main resource. F12 medium: The page triggers DevTools issues and cannot use the back/forward cache. |
be-discoverabletitle-and-description | issues | high | DOM probes show descriptive home metadata, but both /gb/login and /signup have document.title “Netflix”, which does not distinguish their purpose. F13 medium: Login and signup routes use the generic title “Netflix”. |
be-discoverablecrawlable-and-mobile-friendly | pass | medium | Visible navigation uses real href links and descriptive text; viewport metadata exists, and robots.txt explicitly allows major search and AI crawlers even though generic agents are denied. |
be-discoverablecanonical-and-indexing-signals | issues | high | The home probe found no canonical, no hreflang, no JSON-LD, and only an Open Graph description; /sitemap.xml redirects to NotFound. Raw HTML coverage itself is strong at 90%. F14 medium: Public acquisition pages lack several indexing and sharing signals. |
be-discoverablestructured-and-shareable-metadata | issues | high | The home probe found no canonical, no hreflang, no JSON-LD, and only an Open Graph description; /sitemap.xml redirects to NotFound. Raw HTML coverage itself is strong at 90%. F14 medium: Public acquisition pages lack several indexing and sharing signals. |
be-private-and-securesecure-transport-and-headers | issues | high | Header inspection found no enforced CSP, Referrer-Policy, or Permissions-Policy. Seven of nine observed cookies lacked Secure, while HSTS, nosniff, and X-Frame-Options were present. F15 high: Active browser security policy coverage is incomplete and many cookies omit Secure. |
be-private-and-securedata-minimisation-and-third-parties | issues | high | HAR attributed 52 of 54 requests and 2.53MB to origins other than www.netflix.com, including logging, OneTrust, Google reCAPTCHA, and geolocation; requests occur while the consent banner is still open. F16 high: Logging, consent, and third-party services create a large pre-choice network footprint. |
be-private-and-securein-context-permissions-and-modern-auth | issues | high | Login probe found an email field with autocomplete=email, a password field with no autocomplete value, and no navigator.credentials/passkey signal in loaded scripts; no permission prompt fired on load. F17 medium: The authentication surface exposes password sign-in without passkey evidence and omits the password autocomplete token. |
be-private-and-securedefensive-browser-policies | issues | high | Header inspection found no enforced CSP, Referrer-Policy, or Permissions-Policy. Seven of nine observed cookies lacked Secure, while HSTS, nosniff, and X-Frame-Options were present. F15 high: Active browser security policy coverage is incomplete and many cookies omit Secure. |
be-resilientprogressive-enhancement | pass | medium | Discoverability fetch found 90% rendered-word coverage in raw HTML, with title, H1, and description present and no empty JS shell. |
be-resilientresilient-runtime-behaviour | pass | medium | Menus/overlays remained inside narrow and wide viewports, layouts had no overflow, and no broken async state was observed. |
be-resilientoffline-and-installable | not-applicable | high | The public acquisition and authentication experience is intrinsically online and is not presented as an installable application. |
be-resilientnetwork-and-http-failure-states | pass | medium | An unknown route renders a clear branded “Lost your way?” state with a Netflix Home recovery action. |
be-internationalisedlang-dir-and-logical-properties | issues | high | The page has html lang=en and uses some logical properties, but CSS inspection counted 389 physical left/right declarations and no explicit dir value. F18 medium: The global service sets language correctly but remains heavily dependent on physical-direction CSS. |
be-internationalisedlocale-aware-data | pass | medium | The /gb locale renders UK currency (£5.99), UK phone formatting, English content, and locale-specific subscription copy consistently. |
be-internationalisedtime-zone-correctness | not-applicable | high | No event time, date, recurring interval, or time-zone-sensitive value appears in the representative public paths. |
be-trustworthyno-dark-patterns | pass | medium | Pricing and cancellation are stated beside the offer, and consent presents Accept and Reject with equal visual weight plus a close action. |
be-trustworthyhumane-error-handling | issues | high | On landing and login forms, empty submission moved focus to the first field but yielded no role=alert/aria-live message or explicit error text in the probe. F06 medium: Empty form submission does not expose clear, inspectable error messaging or an announced recovery state. |
be-trustworthytrustworthy-input-assistance | issues | high | Login probe found an email field with autocomplete=email, a password field with no autocomplete value, and no navigator.credentials/passkey signal in loaded scripts; no permission prompt fired on load. F17 medium: The authentication surface exposes password sign-in without passkey evidence and omits the password autocomplete token. |
be-trustworthysafe-commercial-and-account-flows | pass | medium | The tested public flow states price and “Cancel at any time,” provides separate sign-in, and presents the plan benefits before commitment. |
be-sustainableoptimised-assets | issues | high | Image probe found all four img elements without width/height attributes, two oversized images, and two legacy-format assets; measured CLS remained low. F19 low: Image delivery is mixed: responsive sources exist, but dimensions and some sizing/format choices remain wasteful. |
be-sustainableno-wasteful-work | issues | high | HAR measured 2.62MB total, 1.29MB JavaScript and 680KB fonts; 2.53MB came from non-www origins, including consent and reCAPTCHA code before interaction. F20 medium: The anonymous landing page uses a disproportionate script, font, and external-service budget. |
be-sustainablethird-party-and-media-budget | issues | high | HAR measured 2.62MB total, 1.29MB JavaScript and 680KB fonts; 2.53MB came from non-www origins, including consent and reCAPTCHA code before interaction. F20 medium: The anonymous landing page uses a disproportionate script, font, and external-service budget. |
be-agent-readystructured-agent-capabilities | not-applicable | high | No declared intent exposes account or subscription actions to autonomous agents; emerging WebMCP capabilities are therefore out of scope for this audit. |
be-agent-readyon-device-inference | not-applicable | high | The acquisition, login, and signup surfaces have no summarisation or language-model task that would benefit from on-device inference. |
be-memory-efficientno-leak-under-repeated-interaction | pass | medium | After ten FAQ open/close cycles heap self size rose only about 0.4% and DOM element count stayed exactly 1,088, which does not indicate unbounded retained growth. |
be-memory-efficientbounded-footprint | issues | high | Baseline heap summary contained 686,116 nodes and 40.15MB self size. After ten FAQ cycles it rose only 0.4% to 40.31MB and DOM element count stayed exactly 1,088, so the concern is footprint rather than leakage. F21 medium: The steady-state heap is heavy for a mostly static acquisition page, although repeated FAQ use did not show an unbounded leak. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | medium | The readable heap summaries show no Detached* constructor among the dominant populations, while DOM count remained stable across repeated disclosure interactions. |
Provenance
Canonical report: results/atomic/reports/0636-www_netflix_com.json
Report SHA-256: 55712e6739a978e8b5e44694908be42b7ebb6f268fd8f99829426719e2e8b222
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_netflix_com/2026-07-22T01-56-07-420Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_netflix_com/2026-07-22T01-56-07-420Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.