Manifest position 976 · CrUX rank bucket 1000

https://ara.xhopen.com

Coverage complete

Coverage-complete representative audit of five public paths/templates. Not covered: authenticated account areas, payment/subscription completion, destructive account actions, and media playback to completion because they require credentials, external commitments, or prolonged explicit content interaction.

Attempts
1 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighDark/light captures match and root colorScheme is normal with a hard-coded dark class.
F01 medium: The interface imposes one dark palette instead of following the user color-scheme preference.
respect-user-preferences
respects-reduced-motion
issueshighEight 2-second infinite animations remain running under reduce.
F02 medium: Animations continue when reduced motion is requested.
respect-user-preferences
respects-contrast
passhighForced-colors capture retains visible text, controls, borders, and underlined links.
implement-natural-interactions
view-transitions
issuesmediumMPA routes have no authored cross-document transition treatment.
F03 low: Cross-document navigation changes state abruptly and does not guide attention.
implement-natural-interactions
scroll-driven-animations
not-applicablehighNo parallax, scrollytelling, or scroll-linked animation exists on the representative templates.
implement-natural-interactions
physical-gestures
passhighPrimary interactions are native links, buttons, scrolling, and media controls; no custom pointermove/swipe surface was observed.
provide-guided-navigation
scroll-state-aware-chrome
passhighPersistent header/sidebar and active category state keep location and primary navigation visible during long listings.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip or edge-sensitive anchored popover appeared in representative flows.
provide-guided-navigation
directs-attention
issuesmediumCross-document category/detail changes lack directional or transition cues.
F03 low: Cross-document navigation changes state abruptly and does not guide attention.
maximize-content-reduce-noise
no-intrusive-interruptions
issueshighConsent layer covers primary content on all tested entry routes.
F05 high: A consent interstitial obscures the primary content on every tested entry route.
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighBlocking consent UI is a plain DIV without dialog/aria-modal semantics.
F06 high: The blocking consent surface is an unlabelled custom div rather than a semantic modal.
maximize-content-reduce-noise
reduced-chrome
issueshighNavigation/promotional chrome dominates narrow viewport and clips primary cards.
F07 medium: Navigation and promotional chrome crowd the content, especially in the narrow view.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
issueshighBoth home and detail report 664 px horizontal overflow at 360 px.
F08 critical: The site serves a 1024 px desktop canvas into a 360 px viewport.
adapt-to-the-form-factor
component-level-responsiveness
issueshighNo container rules were found despite reused components in constrained regions.
F09 medium: Reusable card and navigation components do not adapt to their available container.
adapt-to-the-form-factor
input-modality-aware
issueshighFocused link has no outline and 53 visible targets are below 24 px.
F10 high: Keyboard focus and touch target support are inadequate.
support-core-task-success
clear-purpose-and-primary-action
passhighH1, descriptive localized metadata, content cards, category links, and signup CTA make purpose and next action clear.
support-core-task-success
primary-flow-completion
passhighConsent offers accept/reject, content cards use real detail hrefs, and signup presents Google, X, email, terms, and login paths.
support-core-task-success
clear-system-state-and-recovery
passhighUnknown URL returns real HTTP 404 and renders localized recovery content plus homepage/content links.
be-fast-and-stable
good-core-web-vitals
issueshighMobile Lighthouse LCP is 4.4 s; trace result varies by condition.
F11 high: Lab loading performance misses the good LCP range.
be-fast-and-stable
visual-stability
passhighLayout observers recorded CLS 0 with no shifts on desktop and mobile during the capture window.
be-fast-and-stable
efficient-main-thread
issueshighTrace TBT 145.15 ms and layout captures include tasks up to 157 ms.
F12 medium: Startup JavaScript creates user-visible main-thread blocking.
be-fast-and-stable
efficient-resource-delivery
issueshighFour parser styles are VeryHigh; Lighthouse flags render-blocking/cache savings.
F13 medium: The critical path contains excessive parser-inserted styles and weak cache opportunities.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshigh62 scripts transfer 1.03 MB; Lighthouse reports unused JS/CSS.
F14 medium: The page ships a large script surface with measurable unused code.
be-inclusive
names-roles-labels
issueshighLighthouse identifies an unnamed card button; consent lacks dialog semantics.
F15 high: Some controls have no accessible name.
be-inclusive
sufficient-contrast
issueshighMeasured failures include 1.75:1, 2.15:1, and 3.29:1 text.
F16 high: Important text does not meet WCAG contrast minimums.
be-inclusive
structure-and-focus
issueshighNo visible focus outline; list semantics fail; signup begins with H3.
F17 high: Focus treatment and list semantics are not robust.
be-inclusive
legible-text
passhighArabic body and headings are comfortably sized, RTL-aligned, unclipped on desktop, and remain visible in forced colors.
be-inclusive
zoom-reflow-targets-and-media
issueshighMobile Lighthouse fails viewport/targets; detail overflows and video has no tracks.
F18 high: Mobile scaling, reflow, target sizes, and media alternatives are incomplete.
follow-best-practices
no-console-errors
passhighLighthouse best-practices score is 1.0 and its console-error audit passes.
follow-best-practices
sound-document-and-assets
issueshighDoctype/UTF-8 are valid, but 29 images lack dimensions and 13 are oversized.
F19 medium: Image markup and delivery are inefficient.
follow-best-practices
browser-platform-hygiene
passhighLighthouse best-practices is 1.0; no on-load permission prompts, paste prevention, deprecated API, or console issue was observed.
be-discoverable
title-and-description
passhighHome, signup, and detail have localized descriptive titles and meta descriptions.
be-discoverable
crawlable-and-mobile-friendly
passhighLighthouse SEO is 1.0; links are real hrefs, viewport meta exists, and robots permits public routes.
be-discoverable
canonical-and-indexing-signals
issueshighCanonical/status are sound, but /sitemap.xml is empty and robots has no Sitemap directive.
F20 medium: The large public catalog does not expose a discoverable sitemap from the audited host.
be-discoverable
structured-and-shareable-metadata
issueshighDetail has Open Graph metadata but no VideoObject JSON-LD.
F21 medium: The media-detail template lacks structured video metadata.
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS/HSTS/frame controls exist, but CSP is frame-only and cookies/header flags are incomplete.
F22 high: Transport is HTTPS, but CSP and cookie protections are incomplete.
be-private-and-secure
data-minimisation-and-third-parties
issueshigh118 third-party requests transfer 1.63 MB across 15 origins before a core action.
F24 high: The default page load has a large third-party and tracking-shaped footprint.
be-private-and-secure
in-context-permissions-and-modern-auth
issuesmediumNo prompt fires on load, but signup has no passkey/WebAuthn path.
F25 medium: Account creation offers federated and email paths but no phishing-resistant passkey path.
be-private-and-secure
defensive-browser-policies
issueshighHSTS lifetime is one day; CSP, Referrer-Policy, nosniff and Permissions-Policy coverage are weak.
F23 high: Browser-enforced defenses are too narrow for a script-heavy site.
be-resilient
progressive-enhancement
issueshighRaw HTML carries essential metadata but only 54% of rendered content tokens.
F26 medium: A substantial share of rendered content is absent without JavaScript.
be-resilient
resilient-runtime-behaviour
passhighRepresentative home, category, signup, detail, and 404 templates render stable UI without cut-off overlay chrome on desktop or uncaught runtime errors.
be-resilient
offline-and-installable
passhighA valid manifest is linked and an active service worker is registered; its script contains cache and offline handling paths.
be-resilient
network-and-http-failure-states
passhighA real 404 response renders localized explanation and recovery content; service worker contains offline handling.
be-internationalised
lang-dir-and-logical-properties
passhighDocument declares lang=ar and dir=rtl; navigation, text alignment, and mirrored layout render RTL across templates.
be-internationalised
locale-aware-data
passhighDurations, view counts, labels, and the full account/navigation surface are localized, with explicit links to many locale variants.
be-internationalised
time-zone-correctness
not-applicablehighNo date scheduling, recurring events, time-zone conversion, or absolute event time appears in the audited content/signup flows.
be-trustworthy
no-dark-patterns
passhighConsent presents equally prominent accept and reject choices and links privacy policy; no preselected upsell or confirmshaming appeared.
be-trustworthy
humane-error-handling
not-applicablehighNo required data-entry form or validation state is exposed before the user explicitly chooses email signup; search has no required constraints.
be-trustworthy
trustworthy-input-assistance
not-applicablehighThe audited surface exposes only search (where stored autofill is not required) before account-provider selection; no address/payment/sign-in fields are present.
be-trustworthy
safe-commercial-and-account-flows
passhighSignup clearly labels Google, X, email and existing-login paths, with terms and privacy links visible; no hidden pricing/continuity appeared.
be-sustainable
optimised-assets
issueshigh13 images are oversized, 15 use legacy formats, and 8 below-fold images are not lazy.
F19 medium: Image markup and delivery are inefficient.
be-sustainable
no-wasteful-work
issueshigh145 requests/62 scripts and startup long tasks occur before content selection.
F27 medium: Default loading performs disproportionate background and third-party work.
be-sustainable
third-party-and-media-budget
issueshigh118 third-party requests account for 1.63 MB of a 1.82 MB load.
F24 high: The default page load has a large third-party and tracking-shaped footprint.
be-agent-ready
structured-agent-capabilities
not-applicablehighNo transaction/productivity tool surface needs agent actions; this is a public media catalog.
be-agent-ready
on-device-inference
not-applicablehighNo summarization, generation, or local inference task is part of the representative journeys.
be-memory-efficient
no-leak-under-repeated-interaction
passmediumAfter ten repeated full-list scroll cycles, heap self size decreased from 36,867,093 to 36,769,729 bytes; node count changed only +242 (0.04%).
be-memory-efficient
bounded-footprint
passmediumSingle-state heap is 36.9 MB with 684,036 nodes in the snapshot graph; runtime DOM is 1,799 elements and used JS heap is 22.6 MB, proportionate to a media listing.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passlowRepeated interaction did not produce material node/edge growth: +242 nodes and +1,124 edges with lower self size. No unbounded accumulation signal appeared.

Provenance

Canonical report: results/atomic/reports/0976-ara_xhopen_com.json
Report SHA-256: 9ec9a0601a1bfd03b1b595383bf8fec8230dc530dd03dfa9eca5408033141387
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/ara_xhopen_com/2026-07-24T06-10-37-735Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/ara_xhopen_com/2026-07-24T06-10-37-735Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.