Manifest position 936 · CrUX rank bucket 1000
https://business.facebook.com
Coverage complete
Completed atomic audit of the public unauthenticated login gateway. Authenticated Business Suite, Ads Manager, account recovery, and credentialed destinations were excluded because no test account was provided.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | The dark-emulated capture retained the same white modal and light page palette as the default capture. F01 medium: The public login and consent surfaces do not adapt to dark color preference. |
respect-user-preferencesrespects-reduced-motion | pass | high | prefers-reduced-motion: reduce matched; no active animations or smooth scrolling were present, and the CSS inventory contained 32 reduced-motion rules. |
respect-user-preferencesrespects-contrast | issues | high | Lighthouse found “Allow all cookies” at 4.23:1 instead of the required 4.5:1. F02 low: The primary cookie acceptance control narrowly misses minimum text contrast. |
implement-natural-interactionsview-transitions | pass | medium | The audited gateway has no same-document route swap; the loaded consent state is stable and no jarring animated swap was observed. |
implement-natural-interactionsscroll-driven-animations | pass | high | No scroll-linked animation or parallax was present, so native scrolling is not blocked by main-thread visual effects. |
implement-natural-interactionsphysical-gestures | pass | medium | The gateway exposes ordinary buttons and document scrolling, with no custom swipe, drag, overscroll, or pointer-driven gesture that fights platform behavior. |
provide-guided-navigationscroll-state-aware-chrome | pass | medium | No sticky or affixed application chrome is used on this compact gateway, so there is no static scroll chrome obscuring content. |
provide-guided-navigationanchored-positioning | pass | medium | The visible consent modal remains contained at 360px with zero horizontal overflow; no detached tooltip or manually drifting anchored surface was observed. |
provide-guided-navigationdirects-attention | pass | high | Purpose copy leads directly to four clearly named authentication choices, while the modal presents two explicit consent actions. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | A modal consent wall obscures the core login page before user interaction. F03 high: A blocking cookie interstitial obscures the core login content immediately on load. |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | The overlay uses role=dialog but has no accessible name and no aria-modal; the menu trigger also lacks an accessible label. F04 medium: The consent overlay lacks complete modal semantics. |
maximize-content-reduce-noisereduced-chrome | pass | medium | Behind the consent layer, the gateway is content-focused: one purpose block, four account actions, and a compact footer without a persistent app frame. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | scrollWidth, clientWidth and innerWidth were all 360px; horizontalOverflowPx was 0 and viewport metadata was present. |
adapt-to-the-form-factorcomponent-level-responsiveness | pass | high | The CSSOM probe found 31 container rules, and the consent surface reflowed from a wide desktop panel to a single-column 360px layout. |
adapt-to-the-form-factorinput-modality-aware | issues | high | Twenty-eight actionable footer/locale links measured only 16px high. F05 medium: Many footer and locale links have undersized touch hit areas. |
support-core-task-successclear-purpose-and-primary-action | pass | high | The body states “Get started with business tools from Meta” and exposes Facebook, Instagram, account creation, and managed-account actions. |
support-core-task-successprimary-flow-completion | pass | medium | For the auditable public gateway, all four authentication handoff choices are present, named, focusable, and wired as actions; credentialed destinations were intentionally excluded. |
support-core-task-successclear-system-state-and-recovery | not-applicable | medium | The pre-authentication gateway contains no local data-entry or submit result state; credential errors and recovery occur beyond the unauthenticated scope. |
be-fast-and-stablegood-core-web-vitals | issues | high | Lighthouse LCP was 11.6s and FCP 9.7s; the independent trace LCP was 3.25s. F06 high: Cold-load paint performance is poor. |
be-fast-and-stablevisual-stability | pass | high | Both instruments reported CLS 0 with no observed shifts. |
be-fast-and-stableefficient-main-thread | pass | high | Trace found one 60.83ms long task and 10.83ms TBT; Lighthouse TBT was 32ms, both low. |
be-fast-and-stableefficient-resource-delivery | issues | high | 112 requests transferred 2.14MB; 21 stylesheets included numerous parser-inserted VeryHigh-priority render-blocking candidates. F07 high: The login gateway has a long, heavy critical-resource path. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | The gateway loaded 62 scripts (1.06MB) and 21 stylesheets (386KB) for a four-choice login surface. F08 medium: The simple gateway ships disproportionate script and stylesheet volume. |
be-inclusivenames-roles-labels | issues | high | Lighthouse found two unnamed focusable links; the custom probe counted five unlabeled interactives. F09 medium: Focusable links lack accessible names. |
be-inclusivesufficient-contrast | issues | high | The primary cookie acceptance control measured 4.23:1 against a 4.5:1 requirement. F02 low: The primary cookie acceptance control narrowly misses minimum text contrast. |
be-inclusivestructure-and-focus | issues | high | No H1 and no semantic landmarks were found; all detected headings were H2 elements inside consent content. F10 high: The page lacks a useful top-level heading and landmark structure. |
be-inclusivelegible-text | pass | high | Body copy wraps without clipping at 360px, remains readable, and the layout primitive found no overflow. |
be-inclusivezoom-reflow-targets-and-media | issues | high | User scaling is not disabled and reflow has no overflow, but 28 links are only 16px high. F11 medium: Interactive footer and language targets are too short for reliable touch use. |
follow-best-practicesno-console-errors | pass | high | Lighthouse errors-in-console passed, and the resource timing probe found no response status >=400. |
follow-best-practicessound-document-and-assets | issues | high | HTML5 doctype, UTF-8 and viewport are present, but 8 of 9 images omit intrinsic dimensions and 8 use PNG. F12 low: Most consent illustrations omit intrinsic dimensions and use legacy PNG delivery. |
follow-best-practicesbrowser-platform-hygiene | pass | medium | The page produced no console errors, no failing timed resources, and no permission prompt on load; HTTPS passed. |
be-discoverabletitle-and-description | issues | high | A descriptive title exists, but meta description is absent. F13 medium: The public gateway has no meta description. |
be-discoverablecrawlable-and-mobile-friendly | pass | high | Robots and crawlable-anchor audits passed; real href links and viewport metadata are present. |
be-discoverablecanonical-and-indexing-signals | issues | high | The 200 public page has locale choices but no canonical or hreflang links. F14 low: Localized login URLs have no canonical or hreflang signals. |
be-discoverablestructured-and-shareable-metadata | issues | high | No Open Graph, Twitter Card or JSON-LD metadata was present. F15 low: The public organization/login page has no share-preview or structured entity metadata. |
be-private-and-securesecure-transport-and-headers | issues | high | HTTPS, HSTS, nosniff and CSP are present and no client secret was found, but Referrer-Policy is absent and CSP allows inline styles. F16 low: The response omits Referrer-Policy and permits inline styles in CSP. |
be-private-and-securedata-minimisation-and-third-parties | pass | high | Before a consent choice, CDP found zero cookies and no known tracker domains; external requests were confined to Meta-operated facebook.com/fbcdn.net origins. |
be-private-and-securein-context-permissions-and-modern-auth | pass | high | No browser permission prompt appeared; authentication offers Facebook, Instagram and a managed Meta account rather than exposing a local password form. |
be-private-and-securedefensive-browser-policies | issues | high | HSTS, DENY framing and Permissions-Policy are present, but Referrer-Policy is missing. F16 low: The response omits Referrer-Policy and permits inline styles in CSP. |
be-resilientprogressive-enhancement | issues | high | Only 11% of rendered content words were available in raw HTML without JavaScript. F17 high: Most meaningful gateway content is unavailable without JavaScript. |
be-resilientresilient-runtime-behaviour | pass | high | The modal stays within a 360px viewport with zero horizontal overflow, no console errors, and no failing resource status observed. |
be-resilientoffline-and-installable | not-applicable | high | The audited surface is an online authentication gateway to account-bound business services; offline task completion is not meaningful. |
be-resilientnetwork-and-http-failure-states | issues | high | When script execution is unavailable, only 11% of normal content survives and the primary rendered gateway is not preserved. F18 medium: The JavaScript-disabled/network-degraded state loses most of the primary experience. |
be-internationalisedlang-dir-and-logical-properties | pass | medium | The document declares lang=en and exposes multiple clearly named locale choices; no forced LTR dir attribute conflicts with language selection. |
be-internationalisedlocale-aware-data | not-applicable | high | The gateway displays no locale-sensitive date, number, currency, duration, address, or calendar data to format. |
be-internationalisedtime-zone-correctness | not-applicable | high | The gateway presents no times, events, schedules, or recurring intervals. |
be-trustworthyno-dark-patterns | issues | high | The mandatory full-screen consent detour blocks all authentication actions before they can be used. F19 high: Consent blocks the account task before the user can proceed. |
be-trustworthyhumane-error-handling | not-applicable | high | document.forms was empty and the public gateway exposes no local editable fields or validation state. |
be-trustworthytrustworthy-input-assistance | not-applicable | high | The DOM contains no public input fields requiring autocomplete or input assistance. |
be-trustworthysafe-commercial-and-account-flows | issues | high | All account actions are blocked until the separate consent overlay is handled. F20 medium: The authentication entry is gated behind a separate full-screen consent decision. |
be-sustainableoptimised-assets | issues | high | Eight legacy PNG images lack dimensions; responsive sources are missing on five and below-fold consent images load eagerly. F21 medium: Consent artwork is delivered inefficiently. |
be-sustainableno-wasteful-work | issues | high | Initial load performs 112 requests including 62 scripts and fetches offscreen consent illustrations. F22 medium: The gateway performs substantial work unrelated to its visible task. |
be-sustainablethird-party-and-media-budget | issues | high | Meta CDN and related-origin traffic accounts for 101 requests and 2.08MB of 2.14MB transferred. F23 medium: Related-origin CDN traffic dominates the page budget. |
be-agent-readystructured-agent-capabilities | not-applicable | high | No WebMCP capabilities are exposed, but the public gateway has no safe domain action beyond handing off to credentialed authentication. |
be-agent-readyon-device-inference | not-applicable | high | The gateway performs no inference, summarisation, translation, or generative task. |
be-memory-efficientno-leak-under-repeated-interaction | pass | medium | After repeated disclosure clicks, node count fell by 1,022 and retained self-size changed by only +38,219 bytes, with no Detached constructor in the top post-interaction list. |
be-memory-efficientbounded-footprint | issues | medium | The baseline heap held 1,368,314 V8 nodes and 53.1MB self-size for a 716-element login gateway. F24 medium: The baseline JavaScript heap is large for a pre-authentication gateway. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | medium | Node/edge counts decreased after repetition and no Detached constructor appeared in the post-interaction top constructors. |
Provenance
Canonical report: results/atomic/reports/0936-business_facebook_com.json
Report SHA-256: 06f1585e4f5f55e59315e1d27750adba86129227d60ae1dbe3a2a80fd32eda45
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/business_facebook_com/2026-07-28T12-10-58-253Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/business_facebook_com/2026-07-28T12-10-58-253Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.