Manifest position 931 · CrUX rank bucket 1000

https://web.whatsapp.com

Partial after retries

Public login/linking was audited, but 18 of 58 atomic checks require a linked WhatsApp account. The run is not coverage-complete and is not scored.

Attempts
3 / 3
Judged checks
40 / 58
Blocked
18
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighDesktop screenshots captured with default media and prefers-color-scheme: dark are visually identical light surfaces, despite dark tokens existing elsewhere in the CSS.
F1 medium: The public login surface does not follow the system dark-theme preference.
respect-user-preferences
respects-reduced-motion
passhighReduced-motion emulation matched and getAnimations() returned no active animation; CSS includes explicit reduced-motion overrides.
respect-user-preferences
respects-contrast
passhighCSS inspection found forced-colors and prefers-contrast rules for focus, highlights and loading effects.
implement-natural-interactions
view-transitions
blockedmediumAttempted to exercise the phone-login state change, but the authenticated application and representative route transitions require account linking.
implement-natural-interactions
scroll-driven-animations
blockedmediumThe login surface has no meaningful scroll-linked experience; authenticated lists and chat scrolling require account linking and could not be inspected.
implement-natural-interactions
physical-gestures
blockedmediumRepresentative chat gestures, drawers and message actions require account linking and could not be exercised.
provide-guided-navigation
scroll-state-aware-chrome
blockedmediumAuthenticated chat/list navigation and its scroll chrome require account linking.
provide-guided-navigation
anchored-positioning
blockedmediumAuthenticated menus, tooltips and popovers require account linking; no representative overlay exists on the login surface.
provide-guided-navigation
directs-attention
blockedmediumRepresentative in-app navigation is behind account linking.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighThe initial desktop screenshot shows the linking task directly, with no popup, consent wall or obscuring interstitial.
maximize-content-reduce-noise
semantic-dismissible-primitives
not-applicablehighCheck judged out of scope for this condition.
maximize-content-reduce-noise
reduced-chrome
passhighThe desktop first viewport is a focused login card with only brand, task instructions, security reassurance and footer links.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
issueshighThe 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible.
F2 critical: The login card is clipped and unusable at a 360 px viewport.
adapt-to-the-form-factor
component-level-responsiveness
passhighCSS inspection found multiple @container rules and logical inset/padding declarations for component adaptation.
adapt-to-the-form-factor
input-modality-aware
issueshighThe focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high.
F3 high: Keyboard focus is not visibly indicated and several actions expose very small visual targets.
support-core-task-success
clear-purpose-and-primary-action
passhighThe desktop screenshot clearly says “Scan to log in”, gives three numbered steps and offers phone-number login.
support-core-task-success
primary-flow-completion
blockedmediumEnd-to-end task completion requires scanning the QR code or authenticating a phone number with a real WhatsApp account.
support-core-task-success
clear-system-state-and-recovery
blockedmediumAuthenticated loading, error, offline and recovery states require a linked account and controlled failures.
be-fast-and-stable
good-core-web-vitals
issueshighThe trace measured FCP 2.99 s and LCP 5.96 s; Lighthouse measured FCP/LCP 8.1 s and a 0.58 performance score.
F4 high: The lightweight login screen paints slowly.
be-fast-and-stable
visual-stability
passhighThe mobile layout observer measured CLS 0.00016 and Lighthouse measured CLS 0.
be-fast-and-stable
efficient-main-thread
issueshighHAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates.
F5 high: The login route ships the authenticated application bundle before it is needed.
be-fast-and-stable
efficient-resource-delivery
issueshighHAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates.
F5 high: The login route ships the authenticated application bundle before it is needed.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighHAR recorded 6.38 MB transferred, including 5.81 MB of JavaScript across 27 requests; Lighthouse estimated 940 KiB unused JavaScript and 161 KiB unused CSS. Several parser-inserted resources are high-priority render-blocking candidates.
F5 high: The login route ships the authenticated application bundle before it is needed.
be-inclusive
names-roles-labels
passhighVisible actions expose role=button with text-derived names, there are no img elements needing alt, and Lighthouse accessibility scored 100.
be-inclusive
sufficient-contrast
passhighLighthouse accessibility, including automated contrast checks, scored 100 on the public login surface.
be-inclusive
structure-and-focus
issueshighThe focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high. DOM/evaluate probes found no h1-h3 elements and no anchors; all visible actions are div role=button. Combined with absent visible focus, this weakens structural navigation even though Lighthouse automated accessibility scored 100.
F6 medium: The login document lacks semantic headings and uses generic div controls.
F3 high: Keyboard focus is not visibly indicated and several actions expose very small visual targets.
be-inclusive
legible-text
issueshighThe 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible.
F2 critical: The login card is clipped and unusable at a 360 px viewport.
be-inclusive
zoom-reflow-targets-and-media
issueshighThe 360x800 screenshot cuts off the QR code, heading, instructions and footer horizontally. The document hides overflow, so layout metrics report no scrollbar while content is still inaccessible. The focus probe focused each visible role=button control and computed outline:none and box-shadow:none. Visible action boxes were only 16-20 px high.
F2 critical: The login card is clipped and unusable at a 360 px viewport.
F3 high: Keyboard focus is not visibly indicated and several actions expose very small visual targets.
follow-best-practices
no-console-errors
passhighLighthouse did not report a console-errors or runtime-exception failure for the captured load.
follow-best-practices
sound-document-and-assets
issueshighLighthouse reported one deprecated API warning, a BFCache blocker, a missing/late charset declaration and an unsized image audit failure.
F7 medium: The page triggers platform-hygiene failures.
follow-best-practices
browser-platform-hygiene
issueshighLighthouse reported one deprecated API warning, a BFCache blocker, a missing/late charset declaration and an unsized image audit failure.
F7 medium: The page triggers platform-hygiene failures.
be-discoverable
title-and-description
passhighDOM and raw-HTML probes found the title “WhatsApp” and a descriptive login meta description in both rendered and server HTML.
be-discoverable
crawlable-and-mobile-friendly
not-applicablehighCheck judged out of scope for this condition.
be-discoverable
canonical-and-indexing-signals
not-applicablehighCheck judged out of scope for this condition.
be-discoverable
structured-and-shareable-metadata
not-applicablehighCheck judged out of scope for this condition.
be-private-and-secure
secure-transport-and-headers
passhighHeaders/cookies probes confirmed HTTPS, preload HSTS, CSP, nosniff, Secure cookies and HttpOnly on wa_ul.
be-private-and-secure
data-minimisation-and-third-parties
passhighThe tracker probe found no known tracker domains and no third-party cookies. Secret-context inspection showed public Google API keys and certificate parsing/root-certificate literals, not a leaked private key.
be-private-and-secure
in-context-permissions-and-modern-auth
blockedmediumCamera, microphone and authenticated credential behavior cannot be exercised before account linking; the public screen alone does not prove the full auth posture.
be-private-and-secure
defensive-browser-policies
issueshighThe headers primitive confirmed HTTPS, HSTS, nosniff, CSP frame-ancestors and Permissions-Policy, but no Referrer-Policy header. The CSP also permits unsafe-inline for styles.
F8 low: A Referrer-Policy header is absent from a security-sensitive application.
be-resilient
progressive-enhancement
not-applicablehighCheck judged out of scope for this condition.
be-resilient
resilient-runtime-behaviour
blockedmediumAuthenticated menus, asynchronous message state and visibility behavior are behind account linking.
be-resilient
offline-and-installable
passhighThe page exposes a valid standalone web app manifest and has an active service-worker registration.
be-resilient
network-and-http-failure-states
blockedmediumRepresentative message/network failure states require a linked account and could not be induced.
be-internationalised
lang-dir-and-logical-properties
passhighThe document reports lang=en and dir=ltr; inspected CSS includes logical inset and padding properties.
be-internationalised
locale-aware-data
blockedmediumNo locale-sensitive dates, numbers, durations or currencies appear before login; authenticated content is blocked.
be-internationalised
time-zone-correctness
blockedmediumNo time data appears before login; chat timestamps and scheduling behavior require account linking.
be-trustworthy
no-dark-patterns
passhighThe accessible login surface presents QR and phone-number alternatives without consent nagging, upsells or confirmshaming.
be-trustworthy
humane-error-handling
blockedmediumThe phone/account forms and their validation states require progressing through an account-linked flow.
be-trustworthy
trustworthy-input-assistance
blockedmediumNo input fields are present on the initial QR screen; sign-in inputs are behind the blocked account flow.
be-trustworthy
safe-commercial-and-account-flows
blockedmediumAccount management and reauthentication are behind account linking.
be-sustainable
optimised-assets
passhighThe images primitive found no img elements or oversized/legacy image deliveries on the login surface; the QR and marks are vector/CSS-rendered.
be-sustainable
no-wasteful-work
issueshighThe public linking screen transfers 6.38 MB, 98.5% from static.whatsapp.net, before an account is linked; 5.81 MB is script.
F9 medium: Resource use is disproportionate to the unauthenticated login task.
be-sustainable
third-party-and-media-budget
issueshighThe public linking screen transfers 6.38 MB, 98.5% from static.whatsapp.net, before an account is linked; 5.81 MB is script.
F9 medium: Resource use is disproportionate to the unauthenticated login task.
be-agent-ready
structured-agent-capabilities
not-applicablehighCheck judged out of scope for this condition.
be-agent-ready
on-device-inference
not-applicablehighCheck judged out of scope for this condition.
be-memory-efficient
no-leak-under-repeated-interaction
blockedmediumA representative long-lived chat interaction could not be repeated without a linked account; a synthetic login-page loop would not test the core SPA.
be-memory-efficient
bounded-footprint
issueshighA post-load heap summary reported 1,314,301 heap nodes and 74,935,444 bytes self size while the rendered DOM probe counted 323 elements.
F10 high: The initial login surface has a very large JavaScript heap footprint for its visible complexity.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
blockedmediumOnly a single baseline heap was available; meaningful before/after listener, timer and detached-DOM comparison requires a representative authenticated interaction.

Provenance

Canonical report: results/atomic/reports/0931-web_whatsapp_com.json
Report SHA-256: 3d16eb0ceda4a78a79cc726413cd28dd2ae3f42a0889321a77e59d0454e929cf
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/web_whatsapp_com/2026-07-28T12-03-30-529Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/web_whatsapp_com/2026-07-28T12-03-30-529Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.