Manifest position 716 · CrUX rank bucket 1000

https://www.facebook.com

Partial after retries

The unauthenticated login, registration, and recovery entry surfaces were inspected, but Facebook content and authenticated product journeys require an account. No test credentials were supplied, so checks requiring those journeys are blocked and this is not a completed audit.

Attempts
3 / 3
Judged checks
41 / 58
Blocked
17
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighDark-emulation screenshot remained a hard-coded white dialog and grey backdrop; computed color-scheme was normal.
F01 medium: The public entry surface does not honor dark color preference.
respect-user-preferences
respects-reduced-motion
passhighReduced-motion emulation was active and getAnimations() returned no running animations on the public entry state.
respect-user-preferences
respects-contrast
passhighThe prefers-contrast: more screenshot retained readable text and visible controls.
implement-natural-interactions
view-transitions
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
implement-natural-interactions
scroll-driven-animations
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
implement-natural-interactions
physical-gestures
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
provide-guided-navigation
scroll-state-aware-chrome
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
provide-guided-navigation
anchored-positioning
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
provide-guided-navigation
directs-attention
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighDesktop, registration, recovery, and mobile screenshots all opened with a modal cookie wall covering the primary content.
F02 high: A first-load cookie wall obscures every tested primary route, especially on mobile.
maximize-content-reduce-noise
semantic-dismissible-primitives
passhighDOM reported role=dialog, aria-modal=true, and equally prominent Allow/Decline controls.
maximize-content-reduce-noise
reduced-chrome
issueshighAt 360x800 the cookie dialog consumes most of the viewport and pushes the login task behind non-task explanatory cards.
F02 high: A first-load cookie wall obscures every tested primary route, especially on mobile.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
issueshighMobile layout reported no viewport meta and rendered a 980 CSS-pixel layout scaled to 360 physical pixels; text and controls are miniaturised.
F03 high: The mobile experience is a scaled 980px desktop layout and zoom/reflow support is compromised.
adapt-to-the-form-factor
component-level-responsiveness
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
adapt-to-the-form-factor
input-modality-aware
issueshighProgrammatic focus probes reported outline:none and box-shadow:none for login inputs, links, and role=button controls; many footer links are only 17px high.
F07 high: Accessibility checks found contrast, labelling, ARIA, heading, focus visibility, and target-size gaps.
support-core-task-success
clear-purpose-and-primary-action
issueshighThe underlying login purpose is clear, but the first-load modal obscures it on every tested route.
F02 high: A first-load cookie wall obscures every tested primary route, especially on mobile.
support-core-task-success
primary-flow-completion
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
support-core-task-success
clear-system-state-and-recovery
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
be-fast-and-stable
good-core-web-vitals
issueshighTrace measured LCP/FCP 2.80s; mobile Lighthouse measured LCP 6.3s and Speed Index 7.9s.
F05 high: The entry surface paints too slowly and performs avoidable main-thread work.
be-fast-and-stable
visual-stability
passhighMobile layout observer measured CLS 0.043 and Lighthouse measured 0.022, both within the good range.
be-fast-and-stable
efficient-main-thread
issueshighTrace recorded two long tasks, longest 144.65ms, and 166.54ms total blocking time on the desktop load.
F05 high: The entry surface paints too slowly and performs avoidable main-thread work.
be-fast-and-stable
efficient-resource-delivery
issueshighHAR recorded 40 requests and 2,051,856 transferred bytes for the login/consent surface.
F06 high: The unauthenticated login/consent surface ships 2.05MB, dominated by 1.33MB across 24 scripts.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighHAR recorded 24 scripts transferring 1,325,452 bytes for a small unauthenticated login/consent surface.
F06 high: The unauthenticated login/consent surface ships 2.05MB, dominated by 1.33MB across 24 scripts.
be-inclusive
names-roles-labels
issueshighLighthouse accessibility found missing labels and required ARIA attributes; the image audit found four cookie-card images without alt text.
F07 high: Accessibility checks found contrast, labelling, ARIA, heading, focus visibility, and target-size gaps.
be-inclusive
sufficient-contrast
issueshighLighthouse color-contrast audit failed on the mobile login route.
F07 high: Accessibility checks found contrast, labelling, ARIA, heading, focus visibility, and target-size gaps.
be-inclusive
structure-and-focus
issueshighNo h1 was present, and the focus probe found no visible outline or box shadow on focused login controls and links.
F07 high: Accessibility checks found contrast, labelling, ARIA, heading, focus visibility, and target-size gaps.
be-inclusive
legible-text
passhighDesktop screenshot showed readable body text with comfortable line lengths inside the consent dialog.
be-inclusive
zoom-reflow-targets-and-media
issueshighNo viewport meta was present on desktop; mobile Lighthouse also failed its viewport scaling audit.
F03 high: The mobile experience is a scaled 980px desktop layout and zoom/reflow support is compromised.
follow-best-practices
no-console-errors
issueshighLighthouse reported browser console errors.
F12 medium: Lighthouse found console errors, deprecated API use, missing source maps, and BFCache blockers.
follow-best-practices
sound-document-and-assets
issueshighDoctype and UTF-8 were valid, but all four images lacked a complete width/height pair and used PNG without responsive sources.
F11 medium: Cookie-dialog images lack dimensions, alternatives, responsive sources, lazy loading, and modern formats.
follow-best-practices
browser-platform-hygiene
issueshighLighthouse reported a deprecated API, missing source maps, four BFCache failure reasons, and console errors.
F12 medium: Lighthouse found console errors, deprecated API use, missing source maps, and BFCache blockers.
be-discoverable
title-and-description
issueshighThe title is only “Facebook”; no meta description was present.
F08 medium: The entry page has generic and incomplete search/share metadata.
be-discoverable
crawlable-and-mobile-friendly
issueshighLinks had real hrefs, but the page omitted the viewport meta and robots.txt disallowed User-agent: *.
F03 high: The mobile experience is a scaled 980px desktop layout and zoom/reflow support is compromised.
be-discoverable
canonical-and-indexing-signals
issueshighThe response succeeded and exposed a canonical, but robots.txt disallowed all generic crawlers and /sitemap.xml returned an HTML unavailable state.
F09 high: Non-JavaScript clients receive almost none of the visible login content.
be-discoverable
structured-and-shareable-metadata
issueshighThe probe found no Open Graph metadata and no description on the entry page.
F08 medium: The entry page has generic and incomplete search/share metadata.
be-private-and-secure
secure-transport-and-headers
passhighHTTPS, CSP, HSTS, nosniff, X-Frame-Options DENY, and Permissions-Policy were present; no cookies or exposed secrets were observed before consent.
be-private-and-secure
data-minimisation-and-third-parties
passhighBefore consent, cookies reported zero cookies and trackers reported no known tracker domains; only Meta-controlled delivery origins were observed.
be-private-and-secure
in-context-permissions-and-modern-auth
passhighNo permission prompt appeared on load, and the username input advertised autocomplete="username webauthn".
be-private-and-secure
defensive-browser-policies
issueshighHeaders probe found no Referrer-Policy and CSP style-src included unsafe-inline.
F10 medium: Defense-in-depth headers are incomplete.
be-resilient
progressive-enhancement
issueshighDiscoverability measured only 1% raw-to-rendered content coverage and classified the page as a JS shell.
F09 high: Non-JavaScript clients receive almost none of the visible login content.
be-resilient
resilient-runtime-behaviour
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
be-resilient
offline-and-installable
not-applicablehighFacebook is an intrinsically connected social service; installability/offline operation was not treated as required for this unauthenticated web entry surface.
be-resilient
network-and-http-failure-states
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
be-internationalised
lang-dir-and-logical-properties
passhighThe entry document declared lang=en and dir=ltr, and exposed multiple language choices.
be-internationalised
locale-aware-data
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
be-internationalised
time-zone-correctness
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
be-trustworthy
no-dark-patterns
passhighConsent choices were presented side by side with direct “Decline optional cookies” and “Allow all cookies” labels.
be-trustworthy
humane-error-handling
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
be-trustworthy
trustworthy-input-assistance
issueshighUsername used username webauthn, but the password field had an empty autocomplete token rather than current-password.
F15 medium: The password field omits the current-password autocomplete token.
be-trustworthy
safe-commercial-and-account-flows
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
be-sustainable
optimised-assets
issueshighAll four below-fold cookie-card images were PNG, lacked srcset, lacked lazy loading, and lacked complete dimensions.
F11 medium: Cookie-dialog images lack dimensions, alternatives, responsive sources, lazy loading, and modern formats.
be-sustainable
no-wasteful-work
issueshighThe small public entry surface transferred 2.05MB, including 1.33MB across 24 scripts.
F06 high: The unauthenticated login/consent surface ships 2.05MB, dominated by 1.33MB across 24 scripts.
be-sustainable
third-party-and-media-budget
passhighNo autoplay media was observed and the network capture contained no known tracker domain before consent.
be-agent-ready
structured-agent-capabilities
not-applicablehighFacebook explicitly blocks GPTBot, ClaudeBot, PerplexityBot, Google-Extended, and User-agent: * in robots.txt; agent access is therefore intentionally out of scope, not an accidental omission.
be-agent-ready
on-device-inference
not-applicablehighNo agent-facing or on-device inference task is exposed on the unauthenticated login surface, and the site explicitly blocks agent crawling.
be-memory-efficient
no-leak-under-repeated-interaction
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.
be-memory-efficient
bounded-footprint
issuesmediumA static login/consent page retained about 43.8MB self size across roughly 860k to 877k heap nodes, disproportionate to the visible task.
F13 medium: The retained heap footprint is large for the visible public task.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
blockedhighThe public entry point is an authentication wall and no test account was provided, so the authenticated interaction or state required by this check could not be exercised.

Provenance

Canonical report: results/atomic/reports/0716-www_facebook_com.json
Report SHA-256: 06b90b130562fd9592ea47a1bf0b8e0b80d7903e580c2e3765b9e008357bfa2f
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_facebook_com/2026-07-28T05-58-39-006Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/www_facebook_com/2026-07-28T05-58-39-006Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.