Manifest position 716 · CrUX rank bucket 1000
https://www.facebook.com
Partial after retries
The unauthenticated login, registration, and recovery entry surfaces were inspected, but Facebook content and authenticated product journeys require an account. No test credentials were supplied, so checks requiring those journeys are blocked and this is not a completed audit.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | Dark-emulation screenshot remained a hard-coded white dialog and grey backdrop; computed color-scheme was normal. F01 medium: The public entry surface does not honor dark color preference. |
respect-user-preferencesrespects-reduced-motion | pass | high | Reduced-motion emulation was active and getAnimations() returned no running animations on the public entry state. |
respect-user-preferencesrespects-contrast | pass | high | The prefers-contrast: more screenshot retained readable text and visible controls. |
implement-natural-interactionsview-transitions | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
implement-natural-interactionsscroll-driven-animations | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
implement-natural-interactionsphysical-gestures | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
provide-guided-navigationscroll-state-aware-chrome | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
provide-guided-navigationanchored-positioning | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
provide-guided-navigationdirects-attention | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | Desktop, registration, recovery, and mobile screenshots all opened with a modal cookie wall covering the primary content. F02 high: A first-load cookie wall obscures every tested primary route, especially on mobile. |
maximize-content-reduce-noisesemantic-dismissible-primitives | pass | high | DOM reported role=dialog, aria-modal=true, and equally prominent Allow/Decline controls. |
maximize-content-reduce-noisereduced-chrome | issues | high | At 360x800 the cookie dialog consumes most of the viewport and pushes the login task behind non-task explanatory cards. F02 high: A first-load cookie wall obscures every tested primary route, especially on mobile. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | issues | high | Mobile layout reported no viewport meta and rendered a 980 CSS-pixel layout scaled to 360 physical pixels; text and controls are miniaturised. F03 high: The mobile experience is a scaled 980px desktop layout and zoom/reflow support is compromised. |
adapt-to-the-form-factorcomponent-level-responsiveness | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
adapt-to-the-form-factorinput-modality-aware | issues | high | Programmatic focus probes reported outline:none and box-shadow:none for login inputs, links, and role=button controls; many footer links are only 17px high. F07 high: Accessibility checks found contrast, labelling, ARIA, heading, focus visibility, and target-size gaps. |
support-core-task-successclear-purpose-and-primary-action | issues | high | The underlying login purpose is clear, but the first-load modal obscures it on every tested route. F02 high: A first-load cookie wall obscures every tested primary route, especially on mobile. |
support-core-task-successprimary-flow-completion | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
support-core-task-successclear-system-state-and-recovery | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
be-fast-and-stablegood-core-web-vitals | issues | high | Trace measured LCP/FCP 2.80s; mobile Lighthouse measured LCP 6.3s and Speed Index 7.9s. F05 high: The entry surface paints too slowly and performs avoidable main-thread work. |
be-fast-and-stablevisual-stability | pass | high | Mobile layout observer measured CLS 0.043 and Lighthouse measured 0.022, both within the good range. |
be-fast-and-stableefficient-main-thread | issues | high | Trace recorded two long tasks, longest 144.65ms, and 166.54ms total blocking time on the desktop load. F05 high: The entry surface paints too slowly and performs avoidable main-thread work. |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR recorded 40 requests and 2,051,856 transferred bytes for the login/consent surface. F06 high: The unauthenticated login/consent surface ships 2.05MB, dominated by 1.33MB across 24 scripts. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | HAR recorded 24 scripts transferring 1,325,452 bytes for a small unauthenticated login/consent surface. F06 high: The unauthenticated login/consent surface ships 2.05MB, dominated by 1.33MB across 24 scripts. |
be-inclusivenames-roles-labels | issues | high | Lighthouse accessibility found missing labels and required ARIA attributes; the image audit found four cookie-card images without alt text. F07 high: Accessibility checks found contrast, labelling, ARIA, heading, focus visibility, and target-size gaps. |
be-inclusivesufficient-contrast | issues | high | Lighthouse color-contrast audit failed on the mobile login route. F07 high: Accessibility checks found contrast, labelling, ARIA, heading, focus visibility, and target-size gaps. |
be-inclusivestructure-and-focus | issues | high | No h1 was present, and the focus probe found no visible outline or box shadow on focused login controls and links. F07 high: Accessibility checks found contrast, labelling, ARIA, heading, focus visibility, and target-size gaps. |
be-inclusivelegible-text | pass | high | Desktop screenshot showed readable body text with comfortable line lengths inside the consent dialog. |
be-inclusivezoom-reflow-targets-and-media | issues | high | No viewport meta was present on desktop; mobile Lighthouse also failed its viewport scaling audit. F03 high: The mobile experience is a scaled 980px desktop layout and zoom/reflow support is compromised. |
follow-best-practicesno-console-errors | issues | high | Lighthouse reported browser console errors. F12 medium: Lighthouse found console errors, deprecated API use, missing source maps, and BFCache blockers. |
follow-best-practicessound-document-and-assets | issues | high | Doctype and UTF-8 were valid, but all four images lacked a complete width/height pair and used PNG without responsive sources. F11 medium: Cookie-dialog images lack dimensions, alternatives, responsive sources, lazy loading, and modern formats. |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse reported a deprecated API, missing source maps, four BFCache failure reasons, and console errors. F12 medium: Lighthouse found console errors, deprecated API use, missing source maps, and BFCache blockers. |
be-discoverabletitle-and-description | issues | high | The title is only “Facebook”; no meta description was present. F08 medium: The entry page has generic and incomplete search/share metadata. |
be-discoverablecrawlable-and-mobile-friendly | issues | high | Links had real hrefs, but the page omitted the viewport meta and robots.txt disallowed User-agent: *. F03 high: The mobile experience is a scaled 980px desktop layout and zoom/reflow support is compromised. |
be-discoverablecanonical-and-indexing-signals | issues | high | The response succeeded and exposed a canonical, but robots.txt disallowed all generic crawlers and /sitemap.xml returned an HTML unavailable state. F09 high: Non-JavaScript clients receive almost none of the visible login content. |
be-discoverablestructured-and-shareable-metadata | issues | high | The probe found no Open Graph metadata and no description on the entry page. F08 medium: The entry page has generic and incomplete search/share metadata. |
be-private-and-securesecure-transport-and-headers | pass | high | HTTPS, CSP, HSTS, nosniff, X-Frame-Options DENY, and Permissions-Policy were present; no cookies or exposed secrets were observed before consent. |
be-private-and-securedata-minimisation-and-third-parties | pass | high | Before consent, cookies reported zero cookies and trackers reported no known tracker domains; only Meta-controlled delivery origins were observed. |
be-private-and-securein-context-permissions-and-modern-auth | pass | high | No permission prompt appeared on load, and the username input advertised autocomplete="username webauthn". |
be-private-and-securedefensive-browser-policies | issues | high | Headers probe found no Referrer-Policy and CSP style-src included unsafe-inline. F10 medium: Defense-in-depth headers are incomplete. |
be-resilientprogressive-enhancement | issues | high | Discoverability measured only 1% raw-to-rendered content coverage and classified the page as a JS shell. F09 high: Non-JavaScript clients receive almost none of the visible login content. |
be-resilientresilient-runtime-behaviour | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
be-resilientoffline-and-installable | not-applicable | high | Facebook is an intrinsically connected social service; installability/offline operation was not treated as required for this unauthenticated web entry surface. |
be-resilientnetwork-and-http-failure-states | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
be-internationalisedlang-dir-and-logical-properties | pass | high | The entry document declared lang=en and dir=ltr, and exposed multiple language choices. |
be-internationalisedlocale-aware-data | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
be-internationalisedtime-zone-correctness | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
be-trustworthyno-dark-patterns | pass | high | Consent choices were presented side by side with direct “Decline optional cookies” and “Allow all cookies” labels. |
be-trustworthyhumane-error-handling | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
be-trustworthytrustworthy-input-assistance | issues | high | Username used username webauthn, but the password field had an empty autocomplete token rather than current-password. F15 medium: The password field omits the current-password autocomplete token. |
be-trustworthysafe-commercial-and-account-flows | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
be-sustainableoptimised-assets | issues | high | All four below-fold cookie-card images were PNG, lacked srcset, lacked lazy loading, and lacked complete dimensions. F11 medium: Cookie-dialog images lack dimensions, alternatives, responsive sources, lazy loading, and modern formats. |
be-sustainableno-wasteful-work | issues | high | The small public entry surface transferred 2.05MB, including 1.33MB across 24 scripts. F06 high: The unauthenticated login/consent surface ships 2.05MB, dominated by 1.33MB across 24 scripts. |
be-sustainablethird-party-and-media-budget | pass | high | No autoplay media was observed and the network capture contained no known tracker domain before consent. |
be-agent-readystructured-agent-capabilities | not-applicable | high | Facebook explicitly blocks GPTBot, ClaudeBot, PerplexityBot, Google-Extended, and User-agent: * in robots.txt; agent access is therefore intentionally out of scope, not an accidental omission. |
be-agent-readyon-device-inference | not-applicable | high | No agent-facing or on-device inference task is exposed on the unauthenticated login surface, and the site explicitly blocks agent crawling. |
be-memory-efficientno-leak-under-repeated-interaction | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
be-memory-efficientbounded-footprint | issues | medium | A static login/consent page retained about 43.8MB self size across roughly 860k to 877k heap nodes, disproportionate to the visible task. F13 medium: The retained heap footprint is large for the visible public task. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | blocked | high | The public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised. |
Provenance
Canonical report: results/atomic/reports/0716-www_facebook_com.json
Report SHA-256: 06b90b130562fd9592ea47a1bf0b8e0b80d7903e580c2e3765b9e008357bfa2f
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_facebook_com/2026-07-28T05-58-39-006Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_facebook_com/2026-07-28T05-58-39-006Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.