Manifest position 936 · CrUX rank bucket 1000

https://business.facebook.com

Coverage complete

Completed atomic audit of the public unauthenticated login gateway. Authenticated Business Suite, Ads Manager, account recovery, and credentialed destinations were excluded because no test account was provided.

Attempts
3 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighThe dark-emulated capture retained the same white modal and light page palette as the default capture.
F01 medium: The public login and consent surfaces do not adapt to dark color preference.
respect-user-preferences
respects-reduced-motion
passhighprefers-reduced-motion: reduce matched; no active animations or smooth scrolling were present, and the CSS inventory contained 32 reduced-motion rules.
respect-user-preferences
respects-contrast
issueshighLighthouse found “Allow all cookies” at 4.23:1 instead of the required 4.5:1.
F02 low: The primary cookie acceptance control narrowly misses minimum text contrast.
implement-natural-interactions
view-transitions
passmediumThe audited gateway has no same-document route swap; the loaded consent state is stable and no jarring animated swap was observed.
implement-natural-interactions
scroll-driven-animations
passhighNo scroll-linked animation or parallax was present, so native scrolling is not blocked by main-thread visual effects.
implement-natural-interactions
physical-gestures
passmediumThe gateway exposes ordinary buttons and document scrolling, with no custom swipe, drag, overscroll, or pointer-driven gesture that fights platform behavior.
provide-guided-navigation
scroll-state-aware-chrome
passmediumNo sticky or affixed application chrome is used on this compact gateway, so there is no static scroll chrome obscuring content.
provide-guided-navigation
anchored-positioning
passmediumThe visible consent modal remains contained at 360px with zero horizontal overflow; no detached tooltip or manually drifting anchored surface was observed.
provide-guided-navigation
directs-attention
passhighPurpose copy leads directly to four clearly named authentication choices, while the modal presents two explicit consent actions.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighA modal consent wall obscures the core login page before user interaction.
F03 high: A blocking cookie interstitial obscures the core login content immediately on load.
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighThe overlay uses role=dialog but has no accessible name and no aria-modal; the menu trigger also lacks an accessible label.
F04 medium: The consent overlay lacks complete modal semantics.
maximize-content-reduce-noise
reduced-chrome
passmediumBehind the consent layer, the gateway is content-focused: one purpose block, four account actions, and a compact footer without a persistent app frame.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighscrollWidth, clientWidth and innerWidth were all 360px; horizontalOverflowPx was 0 and viewport metadata was present.
adapt-to-the-form-factor
component-level-responsiveness
passhighThe CSSOM probe found 31 container rules, and the consent surface reflowed from a wide desktop panel to a single-column 360px layout.
adapt-to-the-form-factor
input-modality-aware
issueshighTwenty-eight actionable footer/locale links measured only 16px high.
F05 medium: Many footer and locale links have undersized touch hit areas.
support-core-task-success
clear-purpose-and-primary-action
passhighThe body states “Get started with business tools from Meta” and exposes Facebook, Instagram, account creation, and managed-account actions.
support-core-task-success
primary-flow-completion
passmediumFor the auditable public gateway, all four authentication handoff choices are present, named, focusable, and wired as actions; credentialed destinations were intentionally excluded.
support-core-task-success
clear-system-state-and-recovery
not-applicablemediumThe pre-authentication gateway contains no local data-entry or submit result state; credential errors and recovery occur beyond the unauthenticated scope.
be-fast-and-stable
good-core-web-vitals
issueshighLighthouse LCP was 11.6s and FCP 9.7s; the independent trace LCP was 3.25s.
F06 high: Cold-load paint performance is poor.
be-fast-and-stable
visual-stability
passhighBoth instruments reported CLS 0 with no observed shifts.
be-fast-and-stable
efficient-main-thread
passhighTrace found one 60.83ms long task and 10.83ms TBT; Lighthouse TBT was 32ms, both low.
be-fast-and-stable
efficient-resource-delivery
issueshigh112 requests transferred 2.14MB; 21 stylesheets included numerous parser-inserted VeryHigh-priority render-blocking candidates.
F07 high: The login gateway has a long, heavy critical-resource path.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighThe gateway loaded 62 scripts (1.06MB) and 21 stylesheets (386KB) for a four-choice login surface.
F08 medium: The simple gateway ships disproportionate script and stylesheet volume.
be-inclusive
names-roles-labels
issueshighLighthouse found two unnamed focusable links; the custom probe counted five unlabeled interactives.
F09 medium: Focusable links lack accessible names.
be-inclusive
sufficient-contrast
issueshighThe primary cookie acceptance control measured 4.23:1 against a 4.5:1 requirement.
F02 low: The primary cookie acceptance control narrowly misses minimum text contrast.
be-inclusive
structure-and-focus
issueshighNo H1 and no semantic landmarks were found; all detected headings were H2 elements inside consent content.
F10 high: The page lacks a useful top-level heading and landmark structure.
be-inclusive
legible-text
passhighBody copy wraps without clipping at 360px, remains readable, and the layout primitive found no overflow.
be-inclusive
zoom-reflow-targets-and-media
issueshighUser scaling is not disabled and reflow has no overflow, but 28 links are only 16px high.
F11 medium: Interactive footer and language targets are too short for reliable touch use.
follow-best-practices
no-console-errors
passhighLighthouse errors-in-console passed, and the resource timing probe found no response status >=400.
follow-best-practices
sound-document-and-assets
issueshighHTML5 doctype, UTF-8 and viewport are present, but 8 of 9 images omit intrinsic dimensions and 8 use PNG.
F12 low: Most consent illustrations omit intrinsic dimensions and use legacy PNG delivery.
follow-best-practices
browser-platform-hygiene
passmediumThe page produced no console errors, no failing timed resources, and no permission prompt on load; HTTPS passed.
be-discoverable
title-and-description
issueshighA descriptive title exists, but meta description is absent.
F13 medium: The public gateway has no meta description.
be-discoverable
crawlable-and-mobile-friendly
passhighRobots and crawlable-anchor audits passed; real href links and viewport metadata are present.
be-discoverable
canonical-and-indexing-signals
issueshighThe 200 public page has locale choices but no canonical or hreflang links.
F14 low: Localized login URLs have no canonical or hreflang signals.
be-discoverable
structured-and-shareable-metadata
issueshighNo Open Graph, Twitter Card or JSON-LD metadata was present.
F15 low: The public organization/login page has no share-preview or structured entity metadata.
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS, HSTS, nosniff and CSP are present and no client secret was found, but Referrer-Policy is absent and CSP allows inline styles.
F16 low: The response omits Referrer-Policy and permits inline styles in CSP.
be-private-and-secure
data-minimisation-and-third-parties
passhighBefore a consent choice, CDP found zero cookies and no known tracker domains; external requests were confined to Meta-operated facebook.com/fbcdn.net origins.
be-private-and-secure
in-context-permissions-and-modern-auth
passhighNo browser permission prompt appeared; authentication offers Facebook, Instagram and a managed Meta account rather than exposing a local password form.
be-private-and-secure
defensive-browser-policies
issueshighHSTS, DENY framing and Permissions-Policy are present, but Referrer-Policy is missing.
F16 low: The response omits Referrer-Policy and permits inline styles in CSP.
be-resilient
progressive-enhancement
issueshighOnly 11% of rendered content words were available in raw HTML without JavaScript.
F17 high: Most meaningful gateway content is unavailable without JavaScript.
be-resilient
resilient-runtime-behaviour
passhighThe modal stays within a 360px viewport with zero horizontal overflow, no console errors, and no failing resource status observed.
be-resilient
offline-and-installable
not-applicablehighThe audited surface is an online authentication gateway to account-bound business services; offline task completion is not meaningful.
be-resilient
network-and-http-failure-states
issueshighWhen script execution is unavailable, only 11% of normal content survives and the primary rendered gateway is not preserved.
F18 medium: The JavaScript-disabled/network-degraded state loses most of the primary experience.
be-internationalised
lang-dir-and-logical-properties
passmediumThe document declares lang=en and exposes multiple clearly named locale choices; no forced LTR dir attribute conflicts with language selection.
be-internationalised
locale-aware-data
not-applicablehighThe gateway displays no locale-sensitive date, number, currency, duration, address, or calendar data to format.
be-internationalised
time-zone-correctness
not-applicablehighThe gateway presents no times, events, schedules, or recurring intervals.
be-trustworthy
no-dark-patterns
issueshighThe mandatory full-screen consent detour blocks all authentication actions before they can be used.
F19 high: Consent blocks the account task before the user can proceed.
be-trustworthy
humane-error-handling
not-applicablehighdocument.forms was empty and the public gateway exposes no local editable fields or validation state.
be-trustworthy
trustworthy-input-assistance
not-applicablehighThe DOM contains no public input fields requiring autocomplete or input assistance.
be-trustworthy
safe-commercial-and-account-flows
issueshighAll account actions are blocked until the separate consent overlay is handled.
F20 medium: The authentication entry is gated behind a separate full-screen consent decision.
be-sustainable
optimised-assets
issueshighEight legacy PNG images lack dimensions; responsive sources are missing on five and below-fold consent images load eagerly.
F21 medium: Consent artwork is delivered inefficiently.
be-sustainable
no-wasteful-work
issueshighInitial load performs 112 requests including 62 scripts and fetches offscreen consent illustrations.
F22 medium: The gateway performs substantial work unrelated to its visible task.
be-sustainable
third-party-and-media-budget
issueshighMeta CDN and related-origin traffic accounts for 101 requests and 2.08MB of 2.14MB transferred.
F23 medium: Related-origin CDN traffic dominates the page budget.
be-agent-ready
structured-agent-capabilities
not-applicablehighNo WebMCP capabilities are exposed, but the public gateway has no safe domain action beyond handing off to credentialed authentication.
be-agent-ready
on-device-inference
not-applicablehighThe gateway performs no inference, summarisation, translation, or generative task.
be-memory-efficient
no-leak-under-repeated-interaction
passmediumAfter repeated disclosure clicks, node count fell by 1,022 and retained self-size changed by only +38,219 bytes, with no Detached constructor in the top post-interaction list.
be-memory-efficient
bounded-footprint
issuesmediumThe baseline heap held 1,368,314 V8 nodes and 53.1MB self-size for a 716-element login gateway.
F24 medium: The baseline JavaScript heap is large for a pre-authentication gateway.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumNode/edge counts decreased after repetition and no Detached constructor appeared in the post-interaction top constructors.

Provenance

Canonical report: results/atomic/reports/0936-business_facebook_com.json
Report SHA-256: 06f1585e4f5f55e59315e1d27750adba86129227d60ae1dbe3a2a80fd32eda45
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/business_facebook_com/2026-07-28T12-10-58-253Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/business_facebook_com/2026-07-28T12-10-58-253Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.