Manifest position 931 · CrUX rank bucket 1000
https://web.whatsapp.com
Partial after retries
Public login/linking was audited, but 18 of 58 atomic checks require a linked WhatsApp account. The run is not coverage-complete and is not scored.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | Desktop screenshots captured with default media and prefers-color-scheme: dark are visually identical light surfaces, despite dark tokens existing elsewhere in the CSS. F1 medium: The public login surface does not follow the system dark-theme preference. |
respect-user-preferencesrespects-reduced-motion | pass | high | Reduced-motion emulation matched and getAnimations() returned no active animation; CSS includes explicit reduced-motion overrides. |
respect-user-preferencesrespects-contrast | pass | high | CSS inspection found forced-colors and prefers-contrast rules for focus, highlights and loading effects. |
implement-natural-interactionsview-transitions | blocked | medium | Attempted to exercise the phone-login state change, but the authenticated application and representative route transitions require account linking. |
implement-natural-interactionsscroll-driven-animations | blocked | medium | The login surface has no meaningful scroll-linked experience; authenticated lists and chat scrolling require account linking and could not be inspected. |
implement-natural-interactionsphysical-gestures | blocked | medium | Representative chat gestures, drawers and message actions require account linking and could not be exercised. |
provide-guided-navigationscroll-state-aware-chrome | blocked | medium | Authenticated chat/list navigation and its scroll chrome require account linking. |
provide-guided-navigationanchored-positioning | blocked | medium | Authenticated menus, tooltips and popovers require account linking; no representative overlay exists on the login surface. |
provide-guided-navigationdirects-attention | blocked | medium | Representative in-app navigation is behind account linking. |
maximize-content-reduce-noiseno-intrusive-interruptions | pass | high | The initial desktop screenshot shows the linking task directly, with no popup, consent wall or obscuring interstitial. |
maximize-content-reduce-noisesemantic-dismissible-primitives | not-applicable | high | Check judged out of scope for this condition. |
maximize-content-reduce-noisereduced-chrome | pass | high | The desktop first viewport is a focused login card with only brand, task instructions, security reassurance and footer links. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | issues | high | The 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible. F2 critical: The login card is clipped and unusable at a 360 px viewport. |
adapt-to-the-form-factorcomponent-level-responsiveness | pass | high | CSS inspection found multiple @container rules and logical inset/padding declarations for component adaptation. |
adapt-to-the-form-factorinput-modality-aware | issues | high | The focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high. F3 high: Keyboard focus is not visibly indicated and several actions expose very small visual targets. |
support-core-task-successclear-purpose-and-primary-action | pass | high | The desktop screenshot clearly says “Scan to log in”, gives three numbered steps and offers phone-number login. |
support-core-task-successprimary-flow-completion | blocked | medium | End-to-end task completion requires scanning the QR code or authenticating a phone number with a real WhatsApp account. |
support-core-task-successclear-system-state-and-recovery | blocked | medium | Authenticated loading, error, offline and recovery states require a linked account and controlled failures. |
be-fast-and-stablegood-core-web-vitals | issues | high | The trace measured FCP 2.99 s and LCP 5.96 s; Lighthouse measured FCP/LCP 8.1 s and a 0.58 performance score. F4 high: The lightweight login screen paints slowly. |
be-fast-and-stablevisual-stability | pass | high | The mobile layout observer measured CLS 0.00016 and Lighthouse measured CLS 0. |
be-fast-and-stableefficient-main-thread | issues | high | HAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates. F5 high: The login route ships the authenticated application bundle before it is needed. |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates. F5 high: The login route ships the authenticated application bundle before it is needed. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | HAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates. F5 high: The login route ships the authenticated application bundle before it is needed. |
be-inclusivenames-roles-labels | pass | high | Visible actions expose role=button with text-derived names, there are no img elements needing alt, and Lighthouse accessibility scored 100. |
be-inclusivesufficient-contrast | pass | high | Lighthouse accessibility, including automated contrast checks, scored 100 on the public login surface. |
be-inclusivestructure-and-focus | issues | high | The focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high. DOM/evaluate probes found no h1-h3 elements and no anchors; all visible actions are div role=button. Combined with absent visible focus, this weakens structural navigation even though Lighthouse automated accessibility scored 100. F6 medium: The login document lacks semantic headings and uses generic div controls. F3 high: Keyboard focus is not visibly indicated and several actions expose very small visual targets. |
be-inclusivelegible-text | issues | high | The 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible. F2 critical: The login card is clipped and unusable at a 360 px viewport. |
be-inclusivezoom-reflow-targets-and-media | issues | high | The 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible. The focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high. F2 critical: The login card is clipped and unusable at a 360 px viewport. F3 high: Keyboard focus is not visibly indicated and several actions expose very small visual targets. |
follow-best-practicesno-console-errors | pass | high | Lighthouse did not report a console-errors or runtime-exception failure for the captured load. |
follow-best-practicessound-document-and-assets | issues | high | Lighthouse reported one deprecated API warning, a BFCache blocker, a missing/late charset declaration and an unsized image audit failure. F7 medium: The page triggers platform-hygiene failures. |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse reported one deprecated API warning, a BFCache blocker, a missing/late charset declaration and an unsized image audit failure. F7 medium: The page triggers platform-hygiene failures. |
be-discoverabletitle-and-description | pass | high | DOM and raw-HTML probes found the title “WhatsApp” and a descriptive login meta description in both rendered and server HTML. |
be-discoverablecrawlable-and-mobile-friendly | not-applicable | high | Check judged out of scope for this condition. |
be-discoverablecanonical-and-indexing-signals | not-applicable | high | Check judged out of scope for this condition. |
be-discoverablestructured-and-shareable-metadata | not-applicable | high | Check judged out of scope for this condition. |
be-private-and-securesecure-transport-and-headers | pass | high | Headers/cookies probes confirmed HTTPS, preload HSTS, CSP, nosniff, Secure cookies and HttpOnly on wa_ul. |
be-private-and-securedata-minimisation-and-third-parties | pass | high | The tracker probe found no known tracker domains and no third-party cookies. Secret-context inspection showed public Google API keys and certificate parsing/root-certificate literals, not a leaked private key. |
be-private-and-securein-context-permissions-and-modern-auth | blocked | medium | Camera, microphone and authenticated credential behavior cannot be exercised before account linking; the public screen alone does not prove the full auth posture. |
be-private-and-securedefensive-browser-policies | issues | high | The headers primitive confirmed HTTPS, HSTS, nosniff, CSP frame-ancestors and Permissions-Policy, but no Referrer-Policy header. The CSP also permits unsafe-inline for styles. F8 low: A Referrer-Policy header is absent from a security-sensitive application. |
be-resilientprogressive-enhancement | not-applicable | high | Check judged out of scope for this condition. |
be-resilientresilient-runtime-behaviour | blocked | medium | Authenticated menus, asynchronous message state and visibility behavior are behind account linking. |
be-resilientoffline-and-installable | pass | high | The page exposes a valid standalone web app manifest and has an active service-worker registration. |
be-resilientnetwork-and-http-failure-states | blocked | medium | Representative message/network failure states require a linked account and could not be induced. |
be-internationalisedlang-dir-and-logical-properties | pass | high | The document reports lang=en and dir=ltr; inspected CSS includes logical inset and padding properties. |
be-internationalisedlocale-aware-data | blocked | medium | No locale-sensitive dates, numbers, durations or currencies appear before login; authenticated content is blocked. |
be-internationalisedtime-zone-correctness | blocked | medium | No time data appears before login; chat timestamps and scheduling behavior require account linking. |
be-trustworthyno-dark-patterns | pass | high | The accessible login surface presents QR and phone-number alternatives without consent nagging, upsells or confirmshaming. |
be-trustworthyhumane-error-handling | blocked | medium | The phone/account forms and their validation states require progressing through an account-linked flow. |
be-trustworthytrustworthy-input-assistance | blocked | medium | No input fields are present on the initial QR screen; sign-in inputs are behind the blocked account flow. |
be-trustworthysafe-commercial-and-account-flows | blocked | medium | Account management and reauthentication are behind account linking. |
be-sustainableoptimised-assets | pass | high | The images primitive found no img elements or oversized/legacy image deliveries on the login surface; the QR and marks are vector/CSS-rendered. |
be-sustainableno-wasteful-work | issues | high | The public linking screen transfers 6.38 MB, 98.5% from static.whatsapp.net, before an account is linked; 5.81 MB is script. F9 medium: Resource use is disproportionate to the unauthenticated login task. |
be-sustainablethird-party-and-media-budget | issues | high | The public linking screen transfers 6.38 MB, 98.5% from static.whatsapp.net, before an account is linked; 5.81 MB is script. F9 medium: Resource use is disproportionate to the unauthenticated login task. |
be-agent-readystructured-agent-capabilities | not-applicable | high | Check judged out of scope for this condition. |
be-agent-readyon-device-inference | not-applicable | high | Check judged out of scope for this condition. |
be-memory-efficientno-leak-under-repeated-interaction | blocked | medium | A representative long-lived chat interaction could not be repeated without a linked account; a synthetic login-page loop would not test the core SPA. |
be-memory-efficientbounded-footprint | issues | high | A post-load heap summary reported 1,314,301 heap nodes and 74,935,444 bytes self size while the rendered DOM probe counted 323 elements. F10 high: The initial login surface has a very large JavaScript heap footprint for its visible complexity. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | blocked | medium | Only a single baseline heap was available; meaningful before/after listener, timer and detached-DOM comparison requires a representative authenticated interaction. |
Provenance
Canonical report: results/atomic/reports/0931-web_whatsapp_com.json
Report SHA-256: 3d16eb0ceda4a78a79cc726413cd28dd2ae3f42a0889321a77e59d0454e929cf
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/web_whatsapp_com/2026-07-28T12-03-30-529Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/web_whatsapp_com/2026-07-28T12-03-30-529Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.