Manifest position 696 · CrUX rank bucket 1000
https://www.msn.com
Coverage complete
Coverage-complete atomic audit across four representative public paths. Content/article detail, authenticated account, subscription and payment flows were not covered because consent-isolated DOM recon did not expose stable article URLs and those journeys are outside the representative anonymous scope.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | pass | high | Dark-mode screenshots show the homepage and weather chrome retinted to dark surfaces. |
respect-user-preferencesrespects-reduced-motion | issues | high | With prefers-reduced-motion: reduce, objective-probe.json reports a 250 ms slideInFromBottom animation. F01 medium: Reduced-motion still animates the consent surface |
respect-user-preferencesrespects-contrast | pass | high | Forced-colors/high-contrast capture keeps consent controls and text visible; CSS includes forced-colors rules. |
implement-natural-interactionsview-transitions | issues | high | The captured page CSS contains no view-transition declarations; navigation is presented as abrupt state replacement. F02 low: Route and state changes do not expose View Transition styling |
implement-natural-interactionsscroll-driven-animations | issues | high | DOM/CSS capture contains no animation-timeline declaration despite a long feed. F03 low: Scroll-linked experience does not use declarative scroll timelines |
implement-natural-interactionsphysical-gestures | issues | high | DOM/CSS capture contains no scroll-snap declaration on the long feed. F04 low: Feed gestures lack declarative snap or overscroll affordances |
provide-guided-navigationscroll-state-aware-chrome | issues | high | Desktop/mobile captures show a long feed but no progress indicator, and CSS has no scroll-state query. F05 low: Long feeds provide no captured scroll-state-aware progress cue |
provide-guided-navigationanchored-positioning | issues | high | Captured CSS has no anchor-name/position-anchor declarations; consent and menus use fixed/absolute positioning. F06 low: Overlay positioning is manual rather than anchor-positioned |
provide-guided-navigationdirects-attention | pass | high | Desktop capture uses active navigation state and clear category labels to orient the feed. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | Desktop and mobile screenshots show a consent surface covering or dimming the personalised-news feed before interaction. F07 high: Consent interruption obscures the primary content on first load |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | Recon finds role=dialog but objective probe finds zero native dialog/popover elements; dismissal is custom-scripted. F08 medium: Consent overlay is not a native dialog |
maximize-content-reduce-noisereduced-chrome | issues | high | The first desktop viewport devotes substantial space to shortcut icons, navigation, a sponsored slot, and consent chrome before feed content. F09 medium: Advertising and navigation chrome compete with content |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | issues | high | weather-layout.json reports inner/scroll width 621 px against a 360 px visual viewport, 261 px horizontal overflow; the screenshot clips weather text and controls. F10 high: Weather page forces a desktop-sized layout on mobile |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | The weather component remains 621 px wide at a 360 px visual viewport; captured homepage CSS contains no @container rules. F11 medium: Components do not reliably adapt to their container |
adapt-to-the-form-factorinput-modality-aware | pass | high | Lighthouse target-size audit passes and consent CSS defines focus-visible outlines. |
support-core-task-successclear-purpose-and-primary-action | pass | high | MSN branding, web search, category navigation and headline cards make the news/search purpose and next actions clear. |
support-core-task-successprimary-flow-completion | pass | high | Anonymous users can reach news and weather destinations and are offered direct Reject All as well as Accept; no account wall blocks those destinations. |
support-core-task-successclear-system-state-and-recovery | issues | high | The invalid-route screenshot is an unlabelled blank dark page with no 404 explanation, back link, search, or retry. F12 high: Invalid routes fail as a blank screen |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse reports LCP 10.0 s, CLS 0.102 and TBT 520 ms; the separate trace reports LCP 3.31 s and 1.19 s blocking, confirming variable but poor load behavior. F13 high: Core Web Vitals and load responsiveness miss the good range |
be-fast-and-stablevisual-stability | issues | high | Lighthouse measured CLS 0.102, just outside the good <=0.1 range. F14 medium: Measured layout shift exceeds the good CLS threshold |
be-fast-and-stableefficient-main-thread | issues | high | Trace reports 6 long tasks, a 1021.94 ms longest task and 1190.48 ms total blocking; Lighthouse TBT is 520 ms. F15 high: Long JavaScript tasks block interaction |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR summary records 294 requests and 4,499,311 transferred bytes, including 96 scripts / 2,331,227 bytes and parser-inserted high-priority candidates. F16 high: Network delivery is heavy and script-dominated |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | HAR records 96 scripts and 2.33 MB transferred script, led by a 370 KB common bundle plus ads/auth/telemetry bundles. F17 high: Large script and third-party payload dominates load |
be-inclusivenames-roles-labels | pass | high | Lighthouse button-name and image-alt audits pass; consent controls have visible names. |
be-inclusivesufficient-contrast | issues | high | Lighthouse reports 4.21:1 for #777 text on #111, below the required 4.5:1. F18 medium: Advertisement label misses minimum contrast |
be-inclusivestructure-and-focus | pass | high | Lighthouse heading-order and main-landmark audits pass; captured CSS supplies focus-visible outlines for controls. |
be-inclusivelegible-text | pass | high | Consent and feed text are readable at desktop and mobile sizes without observed clipping on the homepage. |
be-inclusivezoom-reflow-targets-and-media | issues | high | At 360 px, weather has 261 px horizontal overflow even though the homepage target-size audit passes. F19 high: Mobile reflow fails on the weather tool |
follow-best-practicesno-console-errors | pass | high | Lighthouse reports no browser errors logged to the console. |
follow-best-practicessound-document-and-assets | issues | high | Lighthouse image-size-responsive audit fails: a 380x199 image is displayed at 380x199 where 570x299 is expected for DPR. F20 low: Some feed images are served below device-density requirements |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse reports four BFCache failure reasons, including an unload handler and no-store behavior. F21 medium: The homepage is ineligible for back/forward cache |
be-discoverabletitle-and-description | pass | high | Rendered DOM has a descriptive MSN title and a substantive meta description. |
be-discoverablecrawlable-and-mobile-friendly | pass | high | Lighthouse passes crawlable anchors, robots.txt, descriptive link text and viewport audits. |
be-discoverablecanonical-and-indexing-signals | issues | high | Objective probe finds no link[rel=canonical] despite index,follow; public localized routes should state canonical/hreflang relationships. F22 medium: Rendered homepage has no canonical URL |
be-discoverablestructured-and-shareable-metadata | pass | high | Homepage exposes og:url, og:title, og:type, og:site_name, og:image and twitter:card matching MSN. |
be-private-and-securesecure-transport-and-headers | issues | high | Headers show HTTPS/HSTS/nosniff, but CSP allows unsafe-inline and unsafe-eval; cookies audit flags multiple non-Secure cookies including MUIDB and _C_Auth. F23 high: Cookie and CSP posture weakens otherwise secure transport |
be-private-and-securedata-minimisation-and-third-parties | issues | high | Tracker capture finds 24 third-party origins and DoubleClick; HAR assigns 290/294 requests and 4.47 MB to other origins, including telemetry/ad endpoints. F24 high: Anonymous load has an extensive tracking and third-party footprint |
be-private-and-securein-context-permissions-and-modern-auth | pass | high | No permission prompt appears on load; HAR shows Microsoft OAuth authorization using PKCE challenge rather than an inline password form. |
be-private-and-securedefensive-browser-policies | issues | high | Headers lack Referrer-Policy and Permissions-Policy; CSP permits unsafe-inline/unsafe-eval; Lighthouse finds 11 third-party cookies. F25 high: Defensive policy coverage is incomplete |
be-resilientprogressive-enhancement | issues | high | Discoverability capture gets HTTP 200 but 0% raw/rendered word coverage, empty #root, and no raw title, H1, or description; crawler screenshot is blank. F26 critical: Core content is a JavaScript-only shell |
be-resilientresilient-runtime-behaviour | issues | high | Weather overflows by 261 px on mobile and an invalid route renders blank, showing failure to stabilise key runtime states. F27 high: Runtime layout and navigation states are brittle |
be-resilientoffline-and-installable | not-applicable | high | MSN is a continuously updated news/weather service; installability is not necessary for the representative anonymous web task, though progressive rendering remains applicable and is judged separately. |
be-resilientnetwork-and-http-failure-states | issues | high | The representative invalid URL renders a blank page without status, explanation or action. F28 high: Failure routes offer no recovery |
be-internationalisedlang-dir-and-logical-properties | issues | high | The page correctly sets lang=en-gb and dir=ltr, but captured CSS repeatedly uses left/right/padding-left instead of logical properties. F29 low: Localized page still relies heavily on physical positioning |
be-internationalisedlocale-aware-data | pass | high | The en-GB weather surface renders Celsius, km/h, localized place names and relative news times. |
be-internationalisedtime-zone-correctness | not-applicable | high | No event scheduling, absolute appointment time, or other time-zone-sensitive workflow appears in the representative homepage, news, weather, or error surfaces. |
be-trustworthyno-dark-patterns | pass | high | Consent offers Reject All and Accept with comparable prominence and a direct Manage Preferences link; no confirmshaming observed. |
be-trustworthyhumane-error-handling | not-applicable | high | No authored data-submission form is present in the representative anonymous news/weather scope; search inputs do not expose a validation workflow. |
be-trustworthytrustworthy-input-assistance | pass | high | The tested public input is web/location search rather than address/payment/sign-in data, and it presents descriptive search affordances without obstructing input. |
be-trustworthysafe-commercial-and-account-flows | not-applicable | high | No checkout, subscription purchase, consented account-management, or sensitive account action is part of the representative anonymous news/weather scope. |
be-sustainableoptimised-assets | issues | high | HAR transfers 1.59 MB of images and Lighthouse flags under-resolution responsive images. F30 medium: Feed media delivery is not consistently resolution-appropriate |
be-sustainableno-wasteful-work | issues | high | The page makes 294 requests and executes six trace long tasks while contacting telemetry, advertising and auth services on anonymous load. F31 high: Load performs substantial non-content work |
be-sustainablethird-party-and-media-budget | issues | high | HAR attributes 290 requests and 4,468,134 bytes to other origins; trackers finds 24 third-party origins. F32 high: Third-party cost is disproportionate on first load |
be-agent-readystructured-agent-capabilities | issues | high | Discoverability reports a 0% raw-content coverage JS shell, and no structured agent capability is exposed in the tested public surfaces. F33 medium: Agent and non-JS clients cannot access structured core content |
be-agent-readyon-device-inference | not-applicable | high | No user task in the tested anonymous news/weather surfaces requires on-device generative inference; absence is not a failure. |
be-memory-efficientno-leak-under-repeated-interaction | issues | medium | Separate-session heap summaries grew from 1,362,220 nodes / 78.9 MB baseline to 2,994,283 nodes / 173.4 MB after ten bottom/top traversals. Session variance prevents a definitive leak attribution, but the 2.2x growth is material. F34 medium: Repeated feed traversal shows large retained growth and needs leak investigation |
be-memory-efficientbounded-footprint | issues | high | Baseline heap summary contains 1,362,220 nodes and 78.9 MB self size; post-scroll reaches 2,994,283 nodes and 173.4 MB. F35 high: Homepage memory footprint is very large |
be-memory-efficientno-detached-dom-or-unbounded-listeners | issues | medium | Node count increases by about 1.63 million after repeated traversal; summaries do not prove detached-node causality, so listener/observer and Detached* retainers require targeted analysis. F36 medium: Heap growth indicates unbounded retained state risk |
Provenance
Canonical report: results/atomic/reports/0696-www_msn_com.json
Report SHA-256: cda347c0480aaa03f5187f9c0d3ba35c3215f60965283c9a6066f80bd7291039
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_msn_com/2026-07-22T11-21-26-812Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_msn_com/2026-07-22T11-21-26-812Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.