Manifest position 696 · CrUX rank bucket 1000

https://www.msn.com

Coverage complete

Coverage-complete atomic audit across four representative public paths. Content/article detail, authenticated account, subscription and payment flows were not covered because consent-isolated DOM recon did not expose stable article URLs and those journeys are outside the representative anonymous scope.

Attempts
1 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
passhighDark-mode screenshots show the homepage and weather chrome retinted to dark surfaces.
respect-user-preferences
respects-reduced-motion
issueshighWith prefers-reduced-motion: reduce, objective-probe.json reports a 250 ms slideInFromBottom animation.
F01 medium: Reduced-motion still animates the consent surface
respect-user-preferences
respects-contrast
passhighForced-colors/high-contrast capture keeps consent controls and text visible; CSS includes forced-colors rules.
implement-natural-interactions
view-transitions
issueshighThe captured page CSS contains no view-transition declarations; navigation is presented as abrupt state replacement.
F02 low: Route and state changes do not expose View Transition styling
implement-natural-interactions
scroll-driven-animations
issueshighDOM/CSS capture contains no animation-timeline declaration despite a long feed.
F03 low: Scroll-linked experience does not use declarative scroll timelines
implement-natural-interactions
physical-gestures
issueshighDOM/CSS capture contains no scroll-snap declaration on the long feed.
F04 low: Feed gestures lack declarative snap or overscroll affordances
provide-guided-navigation
scroll-state-aware-chrome
issueshighDesktop/mobile captures show a long feed but no progress indicator, and CSS has no scroll-state query.
F05 low: Long feeds provide no captured scroll-state-aware progress cue
provide-guided-navigation
anchored-positioning
issueshighCaptured CSS has no anchor-name/position-anchor declarations; consent and menus use fixed/absolute positioning.
F06 low: Overlay positioning is manual rather than anchor-positioned
provide-guided-navigation
directs-attention
passhighDesktop capture uses active navigation state and clear category labels to orient the feed.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighDesktop and mobile screenshots show a consent surface covering or dimming the personalised-news feed before interaction.
F07 high: Consent interruption obscures the primary content on first load
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighRecon finds role=dialog but objective probe finds zero native dialog/popover elements; dismissal is custom-scripted.
F08 medium: Consent overlay is not a native dialog
maximize-content-reduce-noise
reduced-chrome
issueshighThe first desktop viewport devotes substantial space to shortcut icons, navigation, a sponsored slot, and consent chrome before feed content.
F09 medium: Advertising and navigation chrome compete with content
adapt-to-the-form-factor
responsive-no-horizontal-scroll
issueshighweather-layout.json reports inner/scroll width 621 px against a 360 px visual viewport, 261 px horizontal overflow; the screenshot clips weather text and controls.
F10 high: Weather page forces a desktop-sized layout on mobile
adapt-to-the-form-factor
component-level-responsiveness
issueshighThe weather component remains 621 px wide at a 360 px visual viewport; captured homepage CSS contains no @container rules.
F11 medium: Components do not reliably adapt to their container
adapt-to-the-form-factor
input-modality-aware
passhighLighthouse target-size audit passes and consent CSS defines focus-visible outlines.
support-core-task-success
clear-purpose-and-primary-action
passhighMSN branding, web search, category navigation and headline cards make the news/search purpose and next actions clear.
support-core-task-success
primary-flow-completion
passhighAnonymous users can reach news and weather destinations and are offered direct Reject All as well as Accept; no account wall blocks those destinations.
support-core-task-success
clear-system-state-and-recovery
issueshighThe invalid-route screenshot is an unlabelled blank dark page with no 404 explanation, back link, search, or retry.
F12 high: Invalid routes fail as a blank screen
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse reports LCP 10.0 s, CLS 0.102 and TBT 520 ms; the separate trace reports LCP 3.31 s and 1.19 s blocking, confirming variable but poor load behavior.
F13 high: Core Web Vitals and load responsiveness miss the good range
be-fast-and-stable
visual-stability
issueshighLighthouse measured CLS 0.102, just outside the good <=0.1 range.
F14 medium: Measured layout shift exceeds the good CLS threshold
be-fast-and-stable
efficient-main-thread
issueshighTrace reports 6 long tasks, a 1021.94 ms longest task and 1190.48 ms total blocking; Lighthouse TBT is 520 ms.
F15 high: Long JavaScript tasks block interaction
be-fast-and-stable
efficient-resource-delivery
issueshighHAR summary records 294 requests and 4,499,311 transferred bytes, including 96 scripts / 2,331,227 bytes and parser-inserted high-priority candidates.
F16 high: Network delivery is heavy and script-dominated
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighHAR records 96 scripts and 2.33 MB transferred script, led by a 370 KB common bundle plus ads/auth/telemetry bundles.
F17 high: Large script and third-party payload dominates load
be-inclusive
names-roles-labels
passhighLighthouse button-name and image-alt audits pass; consent controls have visible names.
be-inclusive
sufficient-contrast
issueshighLighthouse reports 4.21:1 for #777 text on #111, below the required 4.5:1.
F18 medium: Advertisement label misses minimum contrast
be-inclusive
structure-and-focus
passhighLighthouse heading-order and main-landmark audits pass; captured CSS supplies focus-visible outlines for controls.
be-inclusive
legible-text
passhighConsent and feed text are readable at desktop and mobile sizes without observed clipping on the homepage.
be-inclusive
zoom-reflow-targets-and-media
issueshighAt 360 px, weather has 261 px horizontal overflow even though the homepage target-size audit passes.
F19 high: Mobile reflow fails on the weather tool
follow-best-practices
no-console-errors
passhighLighthouse reports no browser errors logged to the console.
follow-best-practices
sound-document-and-assets
issueshighLighthouse image-size-responsive audit fails: a 380x199 image is displayed at 380x199 where 570x299 is expected for DPR.
F20 low: Some feed images are served below device-density requirements
follow-best-practices
browser-platform-hygiene
issueshighLighthouse reports four BFCache failure reasons, including an unload handler and no-store behavior.
F21 medium: The homepage is ineligible for back/forward cache
be-discoverable
title-and-description
passhighRendered DOM has a descriptive MSN title and a substantive meta description.
be-discoverable
crawlable-and-mobile-friendly
passhighLighthouse passes crawlable anchors, robots.txt, descriptive link text and viewport audits.
be-discoverable
canonical-and-indexing-signals
issueshighObjective probe finds no link[rel=canonical] despite index,follow; public localized routes should state canonical/hreflang relationships.
F22 medium: Rendered homepage has no canonical URL
be-discoverable
structured-and-shareable-metadata
passhighHomepage exposes og:url, og:title, og:type, og:site_name, og:image and twitter:card matching MSN.
be-private-and-secure
secure-transport-and-headers
issueshighHeaders show HTTPS/HSTS/nosniff, but CSP allows unsafe-inline and unsafe-eval; cookies audit flags multiple non-Secure cookies including MUIDB and _C_Auth.
F23 high: Cookie and CSP posture weakens otherwise secure transport
be-private-and-secure
data-minimisation-and-third-parties
issueshighTracker capture finds 24 third-party origins and DoubleClick; HAR assigns 290/294 requests and 4.47 MB to other origins, including telemetry/ad endpoints.
F24 high: Anonymous load has an extensive tracking and third-party footprint
be-private-and-secure
in-context-permissions-and-modern-auth
passhighNo permission prompt appears on load; HAR shows Microsoft OAuth authorization using PKCE challenge rather than an inline password form.
be-private-and-secure
defensive-browser-policies
issueshighHeaders lack Referrer-Policy and Permissions-Policy; CSP permits unsafe-inline/unsafe-eval; Lighthouse finds 11 third-party cookies.
F25 high: Defensive policy coverage is incomplete
be-resilient
progressive-enhancement
issueshighDiscoverability capture gets HTTP 200 but 0% raw/rendered word coverage, empty #root, and no raw title, H1, or description; crawler screenshot is blank.
F26 critical: Core content is a JavaScript-only shell
be-resilient
resilient-runtime-behaviour
issueshighWeather overflows by 261 px on mobile and an invalid route renders blank, showing failure to stabilise key runtime states.
F27 high: Runtime layout and navigation states are brittle
be-resilient
offline-and-installable
not-applicablehighMSN is a continuously updated news/weather service; installability is not necessary for the representative anonymous web task, though progressive rendering remains applicable and is judged separately.
be-resilient
network-and-http-failure-states
issueshighThe representative invalid URL renders a blank page without status, explanation or action.
F28 high: Failure routes offer no recovery
be-internationalised
lang-dir-and-logical-properties
issueshighThe page correctly sets lang=en-gb and dir=ltr, but captured CSS repeatedly uses left/right/padding-left instead of logical properties.
F29 low: Localized page still relies heavily on physical positioning
be-internationalised
locale-aware-data
passhighThe en-GB weather surface renders Celsius, km/h, localized place names and relative news times.
be-internationalised
time-zone-correctness
not-applicablehighNo event scheduling, absolute appointment time, or other time-zone-sensitive workflow appears in the representative homepage, news, weather, or error surfaces.
be-trustworthy
no-dark-patterns
passhighConsent offers Reject All and Accept with comparable prominence and a direct Manage Preferences link; no confirmshaming observed.
be-trustworthy
humane-error-handling
not-applicablehighNo authored data-submission form is present in the representative anonymous news/weather scope; search inputs do not expose a validation workflow.
be-trustworthy
trustworthy-input-assistance
passhighThe tested public input is web/location search rather than address/payment/sign-in data, and it presents descriptive search affordances without obstructing input.
be-trustworthy
safe-commercial-and-account-flows
not-applicablehighNo checkout, subscription purchase, consented account-management, or sensitive account action is part of the representative anonymous news/weather scope.
be-sustainable
optimised-assets
issueshighHAR transfers 1.59 MB of images and Lighthouse flags under-resolution responsive images.
F30 medium: Feed media delivery is not consistently resolution-appropriate
be-sustainable
no-wasteful-work
issueshighThe page makes 294 requests and executes six trace long tasks while contacting telemetry, advertising and auth services on anonymous load.
F31 high: Load performs substantial non-content work
be-sustainable
third-party-and-media-budget
issueshighHAR attributes 290 requests and 4,468,134 bytes to other origins; trackers finds 24 third-party origins.
F32 high: Third-party cost is disproportionate on first load
be-agent-ready
structured-agent-capabilities
issueshighDiscoverability reports a 0% raw-content coverage JS shell, and no structured agent capability is exposed in the tested public surfaces.
F33 medium: Agent and non-JS clients cannot access structured core content
be-agent-ready
on-device-inference
not-applicablehighNo user task in the tested anonymous news/weather surfaces requires on-device generative inference; absence is not a failure.
be-memory-efficient
no-leak-under-repeated-interaction
issuesmediumSeparate-session heap summaries grew from 1,362,220 nodes / 78.9 MB baseline to 2,994,283 nodes / 173.4 MB after ten bottom/top traversals. Session variance prevents a definitive leak attribution, but the 2.2x growth is material.
F34 medium: Repeated feed traversal shows large retained growth and needs leak investigation
be-memory-efficient
bounded-footprint
issueshighBaseline heap summary contains 1,362,220 nodes and 78.9 MB self size; post-scroll reaches 2,994,283 nodes and 173.4 MB.
F35 high: Homepage memory footprint is very large
be-memory-efficient
no-detached-dom-or-unbounded-listeners
issuesmediumNode count increases by about 1.63 million after repeated traversal; summaries do not prove detached-node causality, so listener/observer and Detached* retainers require targeted analysis.
F36 medium: Heap growth indicates unbounded retained state risk

Provenance

Canonical report: results/atomic/reports/0696-www_msn_com.json
Report SHA-256: cda347c0480aaa03f5187f9c0d3ba35c3215f60965283c9a6066f80bd7291039
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_msn_com/2026-07-22T11-21-26-812Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_msn_com/2026-07-22T11-21-26-812Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.