Manifest position 976 · CrUX rank bucket 1000
https://ara.xhopen.com
Coverage complete
Coverage-complete representative audit of five public paths/templates. Not covered: authenticated account areas, payment/subscription completion, destructive account actions, and media playback to completion because they require credentials, external commitments, or prolonged explicit content interaction.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | Dark/light captures match and root colorScheme is normal with a hard-coded dark class. F01 medium: The interface imposes one dark palette instead of following the user color-scheme preference. |
respect-user-preferencesrespects-reduced-motion | issues | high | Eight 2-second infinite animations remain running under reduce. F02 medium: Animations continue when reduced motion is requested. |
respect-user-preferencesrespects-contrast | pass | high | Forced-colors capture retains visible text, controls, borders, and underlined links. |
implement-natural-interactionsview-transitions | issues | medium | MPA routes have no authored cross-document transition treatment. F03 low: Cross-document navigation changes state abruptly and does not guide attention. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No parallax, scrollytelling, or scroll-linked animation exists on the representative templates. |
implement-natural-interactionsphysical-gestures | pass | high | Primary interactions are native links, buttons, scrolling, and media controls; no custom pointermove/swipe surface was observed. |
provide-guided-navigationscroll-state-aware-chrome | pass | high | Persistent header/sidebar and active category state keep location and primary navigation visible during long listings. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip or edge-sensitive anchored popover appeared in representative flows. |
provide-guided-navigationdirects-attention | issues | medium | Cross-document category/detail changes lack directional or transition cues. F03 low: Cross-document navigation changes state abruptly and does not guide attention. |
maximize-content-reduce-noiseno-intrusive-interruptions | issues | high | Consent layer covers primary content on all tested entry routes. F05 high: A consent interstitial obscures the primary content on every tested entry route. |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | Blocking consent UI is a plain DIV without dialog/aria-modal semantics. F06 high: The blocking consent surface is an unlabelled custom div rather than a semantic modal. |
maximize-content-reduce-noisereduced-chrome | issues | high | Navigation/promotional chrome dominates narrow viewport and clips primary cards. F07 medium: Navigation and promotional chrome crowd the content, especially in the narrow view. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | issues | high | Both home and detail report 664 px horizontal overflow at 360 px. F08 critical: The site serves a 1024 px desktop canvas into a 360 px viewport. |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | No container rules were found despite reused components in constrained regions. F09 medium: Reusable card and navigation components do not adapt to their available container. |
adapt-to-the-form-factorinput-modality-aware | issues | high | Focused link has no outline and 53 visible targets are below 24 px. F10 high: Keyboard focus and touch target support are inadequate. |
support-core-task-successclear-purpose-and-primary-action | pass | high | H1, descriptive localized metadata, content cards, category links, and signup CTA make purpose and next action clear. |
support-core-task-successprimary-flow-completion | pass | high | Consent offers accept/reject, content cards use real detail hrefs, and signup presents Google, X, email, terms, and login paths. |
support-core-task-successclear-system-state-and-recovery | pass | high | Unknown URL returns real HTTP 404 and renders localized recovery content plus homepage/content links. |
be-fast-and-stablegood-core-web-vitals | issues | high | Mobile Lighthouse LCP is 4.4 s; trace result varies by condition. F11 high: Lab loading performance misses the good LCP range. |
be-fast-and-stablevisual-stability | pass | high | Layout observers recorded CLS 0 with no shifts on desktop and mobile during the capture window. |
be-fast-and-stableefficient-main-thread | issues | high | Trace TBT 145.15 ms and layout captures include tasks up to 157 ms. F12 medium: Startup JavaScript creates user-visible main-thread blocking. |
be-fast-and-stableefficient-resource-delivery | issues | high | Four parser styles are VeryHigh; Lighthouse flags render-blocking/cache savings. F13 medium: The critical path contains excessive parser-inserted styles and weak cache opportunities. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | 62 scripts transfer 1.03 MB; Lighthouse reports unused JS/CSS. F14 medium: The page ships a large script surface with measurable unused code. |
be-inclusivenames-roles-labels | issues | high | Lighthouse identifies an unnamed card button; consent lacks dialog semantics. F15 high: Some controls have no accessible name. |
be-inclusivesufficient-contrast | issues | high | Measured failures include 1.75:1, 2.15:1, and 3.29:1 text. F16 high: Important text does not meet WCAG contrast minimums. |
be-inclusivestructure-and-focus | issues | high | No visible focus outline; list semantics fail; signup begins with H3. F17 high: Focus treatment and list semantics are not robust. |
be-inclusivelegible-text | pass | high | Arabic body and headings are comfortably sized, RTL-aligned, unclipped on desktop, and remain visible in forced colors. |
be-inclusivezoom-reflow-targets-and-media | issues | high | Mobile Lighthouse fails viewport/targets; detail overflows and video has no tracks. F18 high: Mobile scaling, reflow, target sizes, and media alternatives are incomplete. |
follow-best-practicesno-console-errors | pass | high | Lighthouse best-practices score is 1.0 and its console-error audit passes. |
follow-best-practicessound-document-and-assets | issues | high | Doctype/UTF-8 are valid, but 29 images lack dimensions and 13 are oversized. F19 medium: Image markup and delivery are inefficient. |
follow-best-practicesbrowser-platform-hygiene | pass | high | Lighthouse best-practices is 1.0; no on-load permission prompts, paste prevention, deprecated API, or console issue was observed. |
be-discoverabletitle-and-description | pass | high | Home, signup, and detail have localized descriptive titles and meta descriptions. |
be-discoverablecrawlable-and-mobile-friendly | pass | high | Lighthouse SEO is 1.0; links are real hrefs, viewport meta exists, and robots permits public routes. |
be-discoverablecanonical-and-indexing-signals | issues | high | Canonical/status are sound, but /sitemap.xml is empty and robots has no Sitemap directive. F20 medium: The large public catalog does not expose a discoverable sitemap from the audited host. |
be-discoverablestructured-and-shareable-metadata | issues | high | Detail has Open Graph metadata but no VideoObject JSON-LD. F21 medium: The media-detail template lacks structured video metadata. |
be-private-and-securesecure-transport-and-headers | issues | high | HTTPS/HSTS/frame controls exist, but CSP is frame-only and cookies/header flags are incomplete. F22 high: Transport is HTTPS, but CSP and cookie protections are incomplete. |
be-private-and-securedata-minimisation-and-third-parties | issues | high | 118 third-party requests transfer 1.63 MB across 15 origins before a core action. F24 high: The default page load has a large third-party and tracking-shaped footprint. |
be-private-and-securein-context-permissions-and-modern-auth | issues | medium | No prompt fires on load, but signup has no passkey/WebAuthn path. F25 medium: Account creation offers federated and email paths but no phishing-resistant passkey path. |
be-private-and-securedefensive-browser-policies | issues | high | HSTS lifetime is one day; CSP, Referrer-Policy, nosniff and Permissions-Policy coverage are weak. F23 high: Browser-enforced defenses are too narrow for a script-heavy site. |
be-resilientprogressive-enhancement | issues | high | Raw HTML carries essential metadata but only 54% of rendered content tokens. F26 medium: A substantial share of rendered content is absent without JavaScript. |
be-resilientresilient-runtime-behaviour | pass | high | Representative home, category, signup, detail, and 404 templates render stable UI without cut-off overlay chrome on desktop or uncaught runtime errors. |
be-resilientoffline-and-installable | pass | high | A valid manifest is linked and an active service worker is registered; its script contains cache and offline handling paths. |
be-resilientnetwork-and-http-failure-states | pass | high | A real 404 response renders localized explanation and recovery content; service worker contains offline handling. |
be-internationalisedlang-dir-and-logical-properties | pass | high | Document declares lang=ar and dir=rtl; navigation, text alignment, and mirrored layout render RTL across templates. |
be-internationalisedlocale-aware-data | pass | high | Durations, view counts, labels, and the full account/navigation surface are localized, with explicit links to many locale variants. |
be-internationalisedtime-zone-correctness | not-applicable | high | No date scheduling, recurring events, time-zone conversion, or absolute event time appears in the audited content/signup flows. |
be-trustworthyno-dark-patterns | pass | high | Consent presents equally prominent accept and reject choices and links privacy policy; no preselected upsell or confirmshaming appeared. |
be-trustworthyhumane-error-handling | not-applicable | high | No required data-entry form or validation state is exposed before the user explicitly chooses email signup; search has no required constraints. |
be-trustworthytrustworthy-input-assistance | not-applicable | high | The audited surface exposes only search (where stored autofill is not required) before account-provider selection; no address/payment/sign-in fields are present. |
be-trustworthysafe-commercial-and-account-flows | pass | high | Signup clearly labels Google, X, email and existing-login paths, with terms and privacy links visible; no hidden pricing/continuity appeared. |
be-sustainableoptimised-assets | issues | high | 13 images are oversized, 15 use legacy formats, and 8 below-fold images are not lazy. F19 medium: Image markup and delivery are inefficient. |
be-sustainableno-wasteful-work | issues | high | 145 requests/62 scripts and startup long tasks occur before content selection. F27 medium: Default loading performs disproportionate background and third-party work. |
be-sustainablethird-party-and-media-budget | issues | high | 118 third-party requests account for 1.63 MB of a 1.82 MB load. F24 high: The default page load has a large third-party and tracking-shaped footprint. |
be-agent-readystructured-agent-capabilities | not-applicable | high | No transaction/productivity tool surface needs agent actions; this is a public media catalog. |
be-agent-readyon-device-inference | not-applicable | high | No summarization, generation, or local inference task is part of the representative journeys. |
be-memory-efficientno-leak-under-repeated-interaction | pass | medium | After ten repeated full-list scroll cycles, heap self size decreased from 36,867,093 to 36,769,729 bytes; node count changed only +242 (0.04%). |
be-memory-efficientbounded-footprint | pass | medium | Single-state heap is 36.9 MB with 684,036 nodes in the snapshot graph; runtime DOM is 1,799 elements and used JS heap is 22.6 MB, proportionate to a media listing. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | low | Repeated interaction did not produce material node/edge growth: +242 nodes and +1,124 edges with lower self size. No unbounded accumulation signal appeared. |
Provenance
Canonical report: results/atomic/reports/0976-ara_xhopen_com.json
Report SHA-256: 9ec9a0601a1bfd03b1b595383bf8fec8230dc530dd03dfa9eca5408033141387
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/ara_xhopen_com/2026-07-24T06-10-37-735Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/ara_xhopen_com/2026-07-24T06-10-37-735Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.