Manifest position 651 · CrUX rank bucket 1000

https://www.paramountplus.com

Coverage complete

Coverage-complete remote audit. Account flows returned reproducible 403 failures and are recorded as site issues rather than untested blockers.

Attempts
1 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighThe 2.71 MB stylesheet probe found zero prefers-color-scheme, prefers-reduced-motion, prefers-contrast, or forced-colors rules; dark and contrast captures are visually unchanged. Lighthouse also measured consent-link contrast at 3.58:1.
F02 medium: The stylesheet does not respond to color, motion, or contrast preferences.
respect-user-preferences
respects-reduced-motion
issueshighThe 2.71 MB stylesheet probe found zero prefers-color-scheme, prefers-reduced-motion, prefers-contrast, or forced-colors rules; dark and contrast captures are visually unchanged. Lighthouse also measured consent-link contrast at 3.58:1.
F02 medium: The stylesheet does not respond to color, motion, or contrast preferences.
respect-user-preferences
respects-contrast
issueshighThe 2.71 MB stylesheet probe found zero prefers-color-scheme, prefers-reduced-motion, prefers-contrast, or forced-colors rules; dark and contrast captures are visually unchanged. Lighthouse also measured consent-link contrast at 3.58:1. Lighthouse scored accessibility 83: three content images lacked alt attributes, two consent links were 3.58:1 rather than 4.5:1, and heading order skipped from H1 to H3.
F02 medium: The stylesheet does not respond to color, motion, or contrast preferences.
F09 high: The consent and content markup has concrete accessibility failures.
implement-natural-interactions
view-transitions
issueshighThe fetched stylesheet corpus contained zero view-transition, animation-timeline/scroll-timeline, scroll-snap, or overscroll rules across landing and listing styles.
F03 medium: Navigation and carousel interactions do not use declarative transition or scroll primitives.
implement-natural-interactions
scroll-driven-animations
issueshighThe fetched stylesheet corpus contained zero view-transition, animation-timeline/scroll-timeline, scroll-snap, or overscroll rules across landing and listing styles.
F03 medium: Navigation and carousel interactions do not use declarative transition or scroll primitives.
implement-natural-interactions
physical-gestures
issueshighThe fetched stylesheet corpus contained zero view-transition, animation-timeline/scroll-timeline, scroll-snap, or overscroll rules across landing and listing styles.
F03 medium: Navigation and carousel interactions do not use declarative transition or scroll primitives.
provide-guided-navigation
scroll-state-aware-chrome
issueshighBrowse/search captures show fixed header/category rails, while stylesheet inspection found no scroll-state container query, anchor positioning, or scroll timeline usage.
F04 low: Navigation chrome lacks modern scroll-state and attention cues.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip, popover, or edge-positioned menu requiring an anchor was present in the representative unauthenticated surfaces.
provide-guided-navigation
directs-attention
issueshighBrowse/search captures show fixed header/category rails, while stylesheet inspection found no scroll-state container query, anchor positioning, or scroll timeline usage.
F04 low: Navigation chrome lacks modern scroll-state and attention cues.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighDesktop and 360x800 screenshots show a custom consent dialog covering roughly half to almost all of the viewport before interaction; it repeats on landing, browse, movies and search fresh sessions.
F01 high: The consent experience obscures the content on every fresh page load.
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighDesktop and 360x800 screenshots show a custom consent dialog covering roughly half to almost all of the viewport before interaction; it repeats on landing, browse, movies and search fresh sessions.
F01 high: The consent experience obscures the content on every fresh page load.
maximize-content-reduce-noise
reduced-chrome
passhighAfter separating the consent interruption, screenshots show content-led hero and poster-grid layouts with restrained site chrome.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighMobile layout measured scrollWidth=clientWidth=360, horizontalOverflowPx=0, with viewport meta present.
adapt-to-the-form-factor
component-level-responsiveness
issueshighAcross 2.71 MB of fetched CSS the probe found zero @container rules and zero logical-property matches, despite reusable catalog cards and rails.
F05 medium: The layout relies on global/physical CSS rather than component-level adaptation.
adapt-to-the-form-factor
input-modality-aware
issueshighThe focus probe found the visible logo and SIGN IN anchors computed with outline-style none, while primary CTA controls did expose solid outlines.
F21 medium: Keyboard focus is not consistently visible.
support-core-task-success
clear-purpose-and-primary-action
passhighCrawler and browser captures clearly state “A MOUNTAIN OF ENTERTAINMENT”, price, trial and a prominent signup CTA.
support-core-task-success
primary-flow-completion
issueshighDirect navigation to the landing-page signup and login links produced Varnish “Error 403 Forbidden / Error 54113” pages with no recovery action.
F06 critical: The primary signup and returning-user login destinations fail with raw 403 pages.
support-core-task-success
clear-system-state-and-recovery
issueshighDirect navigation to the landing-page signup and login links produced Varnish “Error 403 Forbidden / Error 54113” pages with no recovery action. Signup and login requests showed raw Varnish 403/54113 pages with no retry, support link, preserved context or alternate path.
F06 critical: The primary signup and returning-user login destinations fail with raw 403 pages.
F16 high: Account route failures fall through to an unbranded infrastructure error.
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse scored performance 39 with LCP 20.0 s, CLS 0.2 and TBT 320 ms; the independent mobile layout observer measured CLS 0.220 and the trace found 626 ms TBT across five long tasks.
F07 high: Load performance and visual stability are poor under measured conditions.
be-fast-and-stable
visual-stability
issueshighLighthouse scored performance 39 with LCP 20.0 s, CLS 0.2 and TBT 320 ms; the independent mobile layout observer measured CLS 0.220 and the trace found 626 ms TBT across five long tasks.
F07 high: Load performance and visual stability are poor under measured conditions.
be-fast-and-stable
efficient-main-thread
issueshighLighthouse scored performance 39 with LCP 20.0 s, CLS 0.2 and TBT 320 ms; the independent mobile layout observer measured CLS 0.220 and the trace found 626 ms TBT across five long tasks. HAR measured 4.80 MB over 64 requests; Lighthouse estimated 850 KiB unused JS and 1,645 KiB unused CSS, including a 1.36 MB stylesheet that was 98.7% unused. Three parser-inserted classic scripts lacked async/defer.
F07 high: Load performance and visual stability are poor under measured conditions.
F08 high: The landing page ships a disproportionately heavy CSS/JS payload.
be-fast-and-stable
efficient-resource-delivery
issueshighHAR measured 4.80 MB over 64 requests; Lighthouse estimated 850 KiB unused JS and 1,645 KiB unused CSS, including a 1.36 MB stylesheet that was 98.7% unused. Three parser-inserted classic scripts lacked async/defer.
F08 high: The landing page ships a disproportionately heavy CSS/JS payload.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighHAR measured 4.80 MB over 64 requests; Lighthouse estimated 850 KiB unused JS and 1,645 KiB unused CSS, including a 1.36 MB stylesheet that was 98.7% unused. Three parser-inserted classic scripts lacked async/defer.
F08 high: The landing page ships a disproportionately heavy CSS/JS payload.
be-inclusive
names-roles-labels
issueshighLighthouse scored accessibility 83: three content images lacked alt attributes, two consent links were 3.58:1 rather than 4.5:1, and heading order skipped from H1 to H3.
F09 high: The consent and content markup has concrete accessibility failures.
be-inclusive
sufficient-contrast
issueshighLighthouse scored accessibility 83: three content images lacked alt attributes, two consent links were 3.58:1 rather than 4.5:1, and heading order skipped from H1 to H3.
F09 high: The consent and content markup has concrete accessibility failures.
be-inclusive
structure-and-focus
issueshighLighthouse scored accessibility 83: three content images lacked alt attributes, two consent links were 3.58:1 rather than 4.5:1, and heading order skipped from H1 to H3. The focus probe found the visible logo and SIGN IN anchors computed with outline-style none, while primary CTA controls did expose solid outlines.
F09 high: The consent and content markup has concrete accessibility failures.
F21 medium: Keyboard focus is not consistently visible.
be-inclusive
legible-text
passhighDesktop/mobile screenshots show readable body/hero text without clipping; the only measured contrast failures are separately recorded.
be-inclusive
zoom-reflow-targets-and-media
passhighThe 360px reflow has no horizontal overflow, viewport scaling is allowed, and Lighthouse target-size/meta-viewport audits passed.
follow-best-practices
no-console-errors
issueshighLighthouse captured a Redfast CORS failure, net::ERR_FAILED, and “om is not loaded yet!” console error from supertop JavaScript.
F10 medium: The page logs runtime/network errors during a normal load.
follow-best-practices
sound-document-and-assets
issueshighAll 22 inspected images lacked width/height, 17 below-fold images lacked loading=lazy and srcset, and HAR transferred 4.80 MB including 1.04 MB from third parties.
F19 high: Asset delivery wastes bandwidth and risks shifts.
follow-best-practices
browser-platform-hygiene
passhighLighthouse deprecation and BFCache audits passed; Notification permission remained default and no prompt fired on load.
be-discoverable
title-and-description
passhighDOM recon found a descriptive unique title and meta description on the public landing page.
be-discoverable
crawlable-and-mobile-friendly
issueshighLighthouse SEO found four non-crawlable anchors, including Manage Cookies and Legal & Support using javascript:void(0).
F11 low: Several visible footer controls are non-crawlable javascript: links.
be-discoverable
canonical-and-indexing-signals
issueshighThe page has title, description, canonical and server-rendered H1, but /sitemap.xml returned a 257 KB HTML document rather than XML, robots.txt declares no Sitemap line, and no JSON-LD was present.
F12 medium: Indexing metadata is partly sound, but sitemap and entity signals are incomplete.
be-discoverable
structured-and-shareable-metadata
issueshighThe page has title, description, canonical and server-rendered H1, but /sitemap.xml returned a 257 KB HTML document rather than XML, robots.txt declares no Sitemap line, and no JSON-LD was present.
F12 medium: Indexing metadata is partly sound, but sitemap and entity signals are incomplete.
be-private-and-secure
secure-transport-and-headers
issueshighThe HTTPS response lacked CSP, HSTS, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Six of seven observed cookies were not Secure; several also used SameSite=None.
F13 critical: Essential browser security headers are absent and most cookies lack Secure.
be-private-and-secure
data-minimisation-and-third-parties
issueshighThe consent dialog names 313 partners. A fresh load contacted 10 third-party origins and transferred 1.04 MB third-party data across 30 requests, with New Relic detected as a known tracker.
F14 high: The pre-choice privacy and third-party footprint is excessive.
be-private-and-secure
in-context-permissions-and-modern-auth
issueshighThe linked login route returned a raw 403 page, while the landing runtime exposed no WebAuthn/passkey affordance; no permission prompt fired on load.
F15 medium: No usable modern authentication path could be verified.
be-private-and-secure
defensive-browser-policies
issueshighThe HTTPS response lacked CSP, HSTS, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Six of seven observed cookies were not Secure; several also used SameSite=None.
F13 critical: Essential browser security headers are absent and most cookies lack Secure.
be-resilient
progressive-enhancement
passhighDiscoverability capture found a 200 raw document with title, H1, offer and CTA and 61% rendered-word coverage; it is not a JS shell.
be-resilient
resilient-runtime-behaviour
passhighRepresentative listing/search captures rendered stable underlying content and the landing page used a controlled consent dialog; route failures are recorded separately.
be-resilient
offline-and-installable
passhighRuntime probe found a standalone manifest with maskable icons plus an active controlling service worker and Workbox precache.
be-resilient
network-and-http-failure-states
issueshighSignup and login requests showed raw Varnish 403/54113 pages with no retry, support link, preserved context or alternate path.
F16 high: Account route failures fall through to an unbranded infrastructure error.
be-internationalised
lang-dir-and-logical-properties
issueshighThe document correctly uses lang=en-gb, but the stylesheet probe found zero sampled logical properties and 2,039 physical left/right declarations; dir is not explicitly set.
F17 medium: Locale metadata is present, but the CSS is not writing-mode resilient.
be-internationalised
locale-aware-data
passhighThe en-GB landing page renders GBP pricing as £4.99 and carries en-gb language metadata; no other locale-sensitive data was present.
be-internationalised
time-zone-correctness
not-applicablehighNo user-visible event times, schedules, or time-zone-sensitive dates occur in the audited unauthenticated templates.
be-trustworthy
no-dark-patterns
passhighThe visible consent surface gives Accept and Reject equal size/prominence, and the acquisition copy states price, auto-renewal, cancellation and trial terms.
be-trustworthy
humane-error-handling
issueshighSignup and login requests showed raw Varnish 403/54113 pages with no retry, support link, preserved context or alternate path.
F16 high: Account route failures fall through to an unbranded infrastructure error.
be-trustworthy
trustworthy-input-assistance
issueshighPricing and cancellation wording are visible on the landing page, but both signup and login CTAs terminate in raw 403 pages, preventing review, completion, cancellation/account entry, or recovery.
F18 high: Commercial/account continuity is not reliable or recoverable.
be-trustworthy
safe-commercial-and-account-flows
issueshighPricing and cancellation wording are visible on the landing page, but both signup and login CTAs terminate in raw 403 pages, preventing review, completion, cancellation/account entry, or recovery.
F18 high: Commercial/account continuity is not reliable or recoverable.
be-sustainable
optimised-assets
issueshighAll 22 inspected images lacked width/height, 17 below-fold images lacked loading=lazy and srcset, and HAR transferred 4.80 MB including 1.04 MB from third parties.
F19 high: Asset delivery wastes bandwidth and risks shifts.
be-sustainable
no-wasteful-work
issueshighHAR measured 4.80 MB over 64 requests; Lighthouse estimated 850 KiB unused JS and 1,645 KiB unused CSS, including a 1.36 MB stylesheet that was 98.7% unused. Three parser-inserted classic scripts lacked async/defer. The consent dialog names 313 partners. A fresh load contacted 10 third-party origins and transferred 1.04 MB third-party data across 30 requests, with New Relic detected as a known tracker.
F08 high: The landing page ships a disproportionately heavy CSS/JS payload.
F14 high: The pre-choice privacy and third-party footprint is excessive.
be-sustainable
third-party-and-media-budget
issueshighThe consent dialog names 313 partners. A fresh load contacted 10 third-party origins and transferred 1.04 MB third-party data across 30 requests, with New Relic detected as a known tracker. All 22 inspected images lacked width/height, 17 below-fold images lacked loading=lazy and srcset, and HAR transferred 4.80 MB including 1.04 MB from third parties.
F14 high: The pre-choice privacy and third-party footprint is excessive.
F19 high: Asset delivery wastes bandwidth and risks shifts.
be-agent-ready
structured-agent-capabilities
not-applicablehighNo declared agent-facing intent or transactional tool surface was found; this emerging contextual capability is not currently applicable.
be-agent-ready
on-device-inference
not-applicablehighThe audited streaming acquisition/catalog experience has no summarisation or language-model task that clearly warrants on-device inference.
be-memory-efficient
no-leak-under-repeated-interaction
passhighAfter ten representative top/bottom scroll cycles, heap self size grew only 85,838 bytes (+0.2%); closure and native counts did not grow.
be-memory-efficient
bounded-footprint
issueshighThe readable baseline heap summary reported 43.12 MB self size and 712,397 heap nodes. Repeating scroll ten times added only 85,838 bytes (+0.2%), so no repeated-scroll leak was observed, but the initial footprint remains disproportionate.
F20 medium: The initial memory footprint is high for a mostly static acquisition page.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passhighBaseline/post heap summaries showed native count decreased by 98 and closure count decreased by 5 after repeated scrolling; no accumulating detached/listener signature appeared.

Provenance

Canonical report: results/atomic/reports/0651-www_paramountplus_com.json
Report SHA-256: 02cb865bea22fa1821cc859be3bd3f832ebdf4b01b51e0f9c2589a516c8f6a49
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_paramountplus_com/2026-07-22T04-02-27-621Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_paramountplus_com/2026-07-22T04-02-27-621Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.