Skip to main content

France security reports

Browse 4,458 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 49 of 90|Showing 2401-2450 of 4458
C

Cdiscount

cdiscount.com

69
E-commerceFrancelargeMEDIUM

Cdiscount is a major French e-commerce platform offering a wide range of products including furniture, electronics, home improvement, garden, and sports goods. The website targets French consumers looking for affordable prices and convenient online shopping experiences. It provides services such as secure payment options, installment plans, free delivery over certain amounts, and a loyalty program. The platform also offers mobile plans and travel booking services, indicating a diversified e-commerce ecosystem. Technically, the website employs modern web technologies including React and jQuery, with a responsive design optimized for mobile and desktop users. The presence of JSON-LD structured data and comprehensive meta tags supports good SEO practices. Performance is moderate with extensive use of JavaScript and external resources. Accessibility features and SEO optimizations are well implemented. From a security perspective, the site enforces HTTPS with strong SSL configuration and includes security headers such as Content Security Policy and X-Frame-Options. No critical vulnerabilities or exposed sensitive data were detected in the HTML content. However, explicit security policies and incident response contacts are not prominently published, which could be improved to enhance transparency and trust. Overall, the website is professional, trustworthy, and compliant with GDPR, featuring clear privacy and cookie policies with consent mechanisms. The lack of WHOIS data reduces domain registration transparency but does not significantly impact the site's legitimacy given its established market presence. Strategic recommendations include publishing detailed security policies, incident response contacts, and vulnerability disclosure information to further strengthen security posture and user trust.

55
65
17
65
77
90
100
e-commerceretailshoppingconsumerelectronicsfrenchmarket+1 more
JavaScriptReactjQueryJSON-LD+1

Partner Domains:

order.cdiscount.com
service
clients.cdiscount.com
service

+3 more partners

2025-10-19T19:56:19.896Z
diximedical.com favicon

DIXI medical

diximedical.com

71
HealthcareFrancemediumMEDIUM

DIXI medical is a well-established French medical device company specializing in precision SEEG electrodes for epilepsy care, boasting over 50 years of expertise. The company positions itself as a global leader in the field, offering advanced intracerebral electrodes and related implantation accessories, alongside clinical support and educational programs. Their target audience primarily includes healthcare professionals such as neurosurgeons, neurologists, and researchers focused on epilepsy treatment. The website reflects a mature business model centered on manufacturing, direct sales, and knowledge dissemination through training and partnerships. Technically, the website is built on the Webflow platform, leveraging modern web technologies including GSAP for animations, Google Fonts, and Cloudflare services for security and performance. The site is well-optimized for mobile devices, fast loading, and incorporates accessibility and SEO best practices. Security measures include HTTPS, security headers, and a cookie consent mechanism compliant with GDPR standards. From a security perspective, the site demonstrates a strong posture with no detected vulnerabilities or exposed sensitive data. However, it lacks explicit security policies or incident response contacts, which could be areas for improvement. The WHOIS data corroborates the legitimacy of the domain, showing a long registration history consistent with the company's claimed experience and no privacy protection, indicating transparency. Overall, the website presents a professional, trustworthy, and compliant digital presence for DIXI medical, supporting its market position as a leader in SEEG electrode technology. Strategic recommendations include enabling DNSSEC, publishing formal security policies, and establishing a vulnerability disclosure program to further enhance trust and security maturity.

60
83
17
80
57
85
100
healthcaremedicaldevicesseegelectrodesepilepsycaremedicaltechnology+1 more
Webflow CMSGoogle Fonts (PT Sans, DM Sans, Source Sans 3)GSAP (GreenSock Animation Platform)Google Analytics+3
2025-10-19T19:54:44.204Z
V

Ville de Metz

metz.fr

61
GovernmentFrancelargeMEDIUM

The website metz.fr serves as the official digital portal for the Ville de Metz, providing residents and visitors with comprehensive information about city services, events, public policies, and cultural activities. It holds a strong market position as the authoritative source for municipal information in Metz, France. The site targets a broad audience including local citizens, tourists, and stakeholders interested in city governance and community engagement. Key services include news updates, event calendars, administrative procedures, and social support information. Technically, the website employs modern JavaScript libraries such as Swiper.js for UI components, Matomo for privacy-conscious analytics, and Google Custom Search for site search functionality. The cookie consent mechanism is implemented using tarteaucitron.js with high privacy settings, reflecting good compliance with GDPR. The site is mobile-optimized and presents a professional design with clear navigation, although accessibility features are basic. From a security perspective, the site enforces HTTPS and uses privacy-respecting analytics without setting cookies by default. However, no explicit security headers were detected in the HTML content, and there is no published security policy or incident response contact information. No vulnerabilities or exposed sensitive data were found. Overall, the security posture is good but could be improved by adding security headers and formalizing security policies. The overall risk assessment is low, with the site demonstrating strong legitimacy, consistent branding, and compliance with privacy regulations. Strategic recommendations include enhancing security transparency, improving accessibility, and publishing incident response and vulnerability disclosure information to further strengthen trust and security culture.

30
68
2
60
72
75
100
governmentmunicipalcitypublicservicesculture+2 more
JavaScriptMatomo AnalyticsSwiper.jsGoogle Custom Search Engine+1

Partner Domains:

eurometropolemetz.eu
partner
moselle.fr
partner

+3 more partners

2025-10-19T19:51:43.777Z
d-k.io favicon

DK

d-k.io

62
MediaFrancesmallMEDIUM

DK is a French company specializing in carbon measurement and management solutions tailored for the communication, media, and advertising sectors. Their platform offers harmonized and standardized carbon footprint measurement tools, including an API for automated calculations, targeting advertisers, agencies, publishers, and media companies. The company positions itself as a market reference in France with notable media clients and a strong emphasis on sustainability and environmental impact reduction. Technically, the website is well-built with modern technologies such as Matomo analytics and Google Tag Manager, hosted by OVH SAS. It demonstrates excellent mobile optimization, accessibility, and SEO practices. However, it lacks explicit privacy and cookie policies, which are important for GDPR compliance. Security posture is good with HTTPS enforced and no visible vulnerabilities, but the absence of security headers and incident response information are areas for improvement. Overall, the website is professional, trustworthy, and content-rich, reflecting a credible business with a clear mission. The domain registration data aligns well with the business claims, enhancing legitimacy. Privacy compliance and security transparency could be strengthened to improve user trust and regulatory adherence.

15
35
17
75
95
80
100
carbonmeasurementmediaadvertisingsustainabilityenvironment+3 more
Matomo AnalyticsGoogle Tag ManagerJavaScriptCSS+1
2025-10-19T19:51:13.550Z
groupem6.fr favicon

Groupe M6

groupem6.fr

67
MediaFrancelargeMEDIUM

Groupe M6 is a prominent French media group operating multiple TV channels, radio stations, and a streaming platform. The corporate website reflects a mature media business with a broad audience reach and diversified content offerings including news, sports, films, and original series. The site is professionally designed, well-branded, and provides comprehensive investor and governance information, indicating a transparent and established organization. Technically, the website is built on WordPress with modern SEO and analytics tools such as Yoast SEO and Matomo, demonstrating a commitment to digital maturity and privacy-conscious analytics. The site is mobile-optimized and accessible, with a cookie consent mechanism compliant with GDPR, reflecting good privacy practices. Security posture is solid with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. However, the absence of explicit security policies, incident response contacts, or vulnerability disclosure mechanisms suggests room for improvement in transparency and security maturity. Overall, the website presents a low-risk profile with strong business credibility and compliance. The lack of WHOIS data is likely due to privacy protection norms in France and does not detract from the site's legitimacy. Strategic recommendations include enhancing security headers, publishing security policies, and adding vulnerability disclosure information to further strengthen trust and security culture.

95
40
2
70
75
70
100
mediacorporatebroadcastingstreaminggdpr+2 more
WordPressYoast SEOMatomo AnalyticsVimeo video embedding+2

Partner Domains:

www.6play.fr
subsidiary
pro.m6.fr
subsidiary

+3 more partners

2025-10-19T19:50:58.519Z
genosafe.com favicon

GenoSafe

genosafe.com

59
HealthcareFrancemediumMEDIUM

GenoSafe is a specialized Contract Research Organization (CRO) based in France, with over 20 years of experience providing analytical services for innovative therapeutics including gene and cell therapies, vaccines, and DNA/RNA-based products. The company supports clients across all stages of development from preclinical to clinical phases, focusing on quality control and regulatory compliance. Their market position is that of a trusted mid-sized healthcare CRO with a professional digital presence and clear service offerings. Technically, the website is built on WordPress with modern SEO and analytics tools such as Yoast SEO and Matomo. It employs hCaptcha for bot protection and provides a GDPR-compliant cookie consent mechanism. The site is mobile-optimized, accessible, and well-structured, reflecting a mature digital infrastructure. From a security perspective, the site uses HTTPS with good SSL configuration but lacks some advanced security headers and published security policies. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with clear cookie consent and a comprehensive privacy policy. However, incident response and vulnerability disclosure information are absent. Overall, GenoSafe presents a low-risk profile with a professional and trustworthy online presence. Strategic improvements in security policy transparency and enhanced security headers would further strengthen their posture.

30
65
2
60
52
80
100
crogenetherapycelltherapyanalyticalserviceshealthcare+3 more
WordPressYoast SEO pluginMatomo analyticsjQuery+1
2025-10-19T19:33:49.978Z
b33.fr favicon

YOURLS — Your Own URL Shortener | https://b33.fr/

b33.fr

51
TechnologyFrancesmallMEDIUM

The website https://b33.fr/admin/ is an administrative login portal for a YOURLS (Your Own URL Shortener) instance, a self-hosted URL shortening service. The domain is registered with OVH in France since 2015, indicating a stable and legitimate presence. The site targets users who require URL shortening capabilities, likely webmasters or developers managing their own short URLs. The business model is niche and technology-focused, providing URL management services without public-facing commercial content on this page. Technically, the site uses YOURLS version 1.9.2 and jQuery 3.5.1, hosted on OVH infrastructure with HTTPS enabled and a valid SSL certificate. The site is basic in design and functionality, optimized for desktop login with minimal mobile optimization and accessibility features. No advanced SEO or analytics tools are detected, and no advertising or tracking scripts are present. From a security perspective, the site benefits from HTTPS and password-protected access but lacks important security headers and may expose the YOURLS version number, which could be a vulnerability if not updated. There is no evidence of privacy, cookie, or terms of service policies, which limits compliance with GDPR and other regulations. No contact or incident response information is provided, reducing transparency and trust. Overall, the site is functional for its purpose but lacks comprehensive security and privacy measures. The risk is moderate due to missing security headers and potential version exposure. Strategic improvements in security hardening, privacy compliance, and user trust signals are recommended.

25
15
17
60
67
65
100
urlshorteneryourlsadminlogintechnology
YOURLS 1.9.2jQuery 3.5.1
2025-10-19T19:33:19.919Z
jardin-botanique-bordeaux.fr favicon

Jardin Botanique de Bordeaux

jardin-botanique-bordeaux.fr

49
GovernmentFrancesmallHIGH

Jardin Botanique de Bordeaux is a public botanical garden institution located in Bordeaux, France, providing cultural, educational, and scientific services related to plant biodiversity and conservation. The website serves as an informational portal for visitors, researchers, and the general public, offering details on garden locations, events, exhibitions, and practical information. The institution is positioned as a local government-supported entity with a focus on public outreach and education. Technically, the website is built on Drupal 7 CMS with standard web technologies including jQuery and a cookie consent manager (Tarteaucitron). The site uses HTTPS and integrates AT Internet analytics for visitor tracking. While the site is functional and moderately optimized, there is room for improvement in mobile responsiveness, accessibility, and modern security headers. From a security perspective, the site enforces HTTPS and provides cookie consent mechanisms compliant with GDPR. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of explicit security policies and incident response contacts suggests an opportunity to enhance transparency and preparedness. Overall, the website is trustworthy, professionally maintained, and compliant with privacy regulations. Strategic improvements in security headers, CMS updates, and accessibility would further strengthen its posture and user experience.

35
10
2
40
62
60
100
botanicalgardencultureeducationpublicinstitutionbordeaux+1 more
Drupal 7jQueryTarteaucitron cookie managerAT Internet analytics
2025-10-19T19:33:14.910Z
budget-box.com favicon

Budgetbox

budget-box.com

75
TechnologyFrancemediumMEDIUM

Budgetbox is a French technology company specializing in omnichannel retail media platforms designed to engage consumers across all shopping journeys, both online and in-store. Established around 2021, it serves over 200 brands and partners with major retailers such as Carrefour, E.Leclerc, and Intermarché. The company offers tailored solutions for brands and distributors to activate retail media campaigns effectively. The website reflects a professional and consistent brand image with comprehensive business and privacy information, targeting retail and media sectors primarily in France. Technically, the website is built on WordPress with modern frameworks like Bootstrap and uses Matomo Analytics for privacy-conscious visitor tracking. It employs GDPR-compliant cookie management and integrates marketing tools such as Drift chat and Plezi. The site is mobile-optimized with good SEO practices, though some security headers could be enhanced. Performance is moderate, with a clean and user-friendly design. From a security perspective, the site enforces HTTPS and has implemented cookie consent mechanisms, but lacks explicit security headers like CSP or X-Frame-Options. No vulnerabilities or sensitive data exposures were detected in the content. The absence of WHOIS registration data is a concern but does not outweigh the professional presentation and detailed compliance documentation. Overall, Budgetbox presents a credible and trustworthy online presence with strong privacy compliance and a solid technical foundation. Strategic improvements in security headers and ongoing domain registration monitoring are recommended to maintain and enhance trust and security posture.

55
100
17
80
77
85
100
retailmediaomnichannelmarketinge-commerceprivacy+3 more
WordPressPHPjQueryBootstrap+4

Partner Domains:

content.communication-budget-box.com
partner
www.welcometothejungle.com
partner

+1 more partners

2025-10-19T19:32:17.369Z
O

Office franco-allemand pour la transition énergétique

energie-fr-de.eu

10
EnergyFrancesmallCRITICAL

The Office franco-allemand pour la transition énergétique (OFATE) is a bilateral platform established in 2006 by the French and German governments to facilitate information exchange and cooperation in the energy transition sector. The website serves as a comprehensive resource hub offering news, publications, event calendars, and membership information targeted at professionals and stakeholders involved in Franco-German energy initiatives. The site is well-structured, bilingual, and professionally branded, reflecting its governmental and non-profit nature. Technically, the website is built on the Contao Open Source CMS and employs a mix of legacy and modern web technologies including jQuery 1.11.3, Google reCAPTCHA v3, and cookie consent management via tarteaucitron.js. Hosting is provided by domainfactory GmbH, a reputable registrar and hosting provider. The site is HTTPS secured and implements GDPR-compliant cookie consent mechanisms, although some scripts use outdated libraries which could pose security risks. From a security perspective, the site enforces HTTPS and uses CAPTCHA to protect forms, but lacks explicit security headers and published incident response policies. The use of an outdated jQuery version is a notable vulnerability. No signs of WAF or blocking mechanisms were detected, and the site is fully accessible. Privacy policies and cookie policies are present and comprehensive, supporting GDPR compliance. Overall, the website presents a low-risk profile with good business credibility and technical maturity for its sector. Strategic improvements include updating legacy scripts, enhancing security headers, and publishing explicit security and incident response policies to further strengthen trust and compliance.

-
-
-
-
-
-
-
energytransitionfranco-germanrenewableenergywindenergy+6 more
jQuery 1.11.3Contao Open Source CMSGoogle reCAPTCHA v3tarteaucitron.js (cookie consent)+2

Partner Domains:

seanergy-forum.com
partner
photosol.fr
partner

+3 more partners

2025-10-19T12:30:30.049Z
syndicat-energies-renouvelables.fr favicon

Syndicat des énergies renouvelables

syndicat-energies-renouvelables.fr

10
EnergyFrancemediumCRITICAL

The Syndicat des énergies renouvelables is a professional trade association focused on the renewable energy sector in France. It serves as a key industry actor providing information, organizing events, publishing reports, and offering professional training to its members, which number over 530 companies including many SMEs and ETIs. The website reflects a well-established organization with a clear market position as a leading voice in the energy transition. The target audience includes energy professionals, companies, and stakeholders interested in renewable energy developments. Technically, the website is built on WordPress with a modern tech stack including Bootstrap 4, jQuery, and various plugins for SEO, sliders, and cookie consent management. The site is mobile-optimized and demonstrates good SEO practices with proper metadata and structured data. Performance is moderate, and accessibility is basic but adequate for the audience. From a security perspective, the site uses HTTPS with a good SSL configuration and implements cookie consent mechanisms. The login form for members uses secure POST methods with nonce tokens. However, additional security headers are not detected, and no explicit security or incident response policies are published. No critical vulnerabilities or exposed sensitive data were found in the HTML content. Overall, the website is professional, trustworthy, and compliant with GDPR requirements. The absence of WHOIS data reduces some trust but is mitigated by the site's content quality and transparency. Strategic recommendations include enhancing security headers, publishing security policies, and adding a vulnerability disclosure mechanism to improve security posture and trust further.

-
-
-
-
-
-
-
renewableenergytradeassociationfranceprofessionalenergytransition+3 more
WordPressYoast SEOjQueryBootstrap 4+5

Partner Domains:

aqpv.fr
partner
flammeverte.org
partner

+3 more partners

2025-10-19T12:30:25.031Z
atmo-grandest.eu favicon

ATMO GrandEst

atmo-grandest.eu

59
EnergyFrancemediumMEDIUM

ATMO GrandEst operates as a regional environmental monitoring organization focused on air quality and pollen indices for the Grand Est region in France. The website provides detailed geographic and environmental data for numerous communes, serving residents and local authorities. The business model aligns with public service and environmental data dissemination, positioning ATMO GrandEst as a key regional authority in environmental monitoring. Technically, the website is built on Drupal 9 CMS, utilizing modern web fonts, icon libraries, and analytics tools such as Microsoft Clarity and Google Analytics. The site demonstrates moderate performance and good mobile optimization but lacks advanced SEO and accessibility features. Security practices include HTTPS usage and asynchronous loading of tracking scripts, though security headers and explicit privacy mechanisms are not evident. The security posture is moderate with no detected vulnerabilities or WAF blocking. However, the absence of visible privacy and cookie policies, as well as contact information, reduces privacy compliance and user trust. The WHOIS data is unavailable due to EURid privacy restrictions, which is typical for .eu domains, and does not raise immediate legitimacy concerns. Overall, the website is functional and serves its informational purpose but would benefit from enhanced privacy compliance, clearer contact channels, and improved security headers to strengthen trust and regulatory adherence.

25
28
17
75
77
85
100
environmentairqualitymonitoringfrancegrandest+1 more
Drupal 9Google FontsFontAwesomeMicrosoft Icon+2
2025-10-19T12:27:34.336Z
atmo-aura.fr favicon

Atmo Auvergne-Rhône-Alpes

atmo-aura.fr

58
GovernmentFrancemediumMEDIUM

Atmo Auvergne-Rhône-Alpes operates as a regional air quality observatory serving the Auvergne-Rhône-Alpes region in France. The organization provides comprehensive air pollution monitoring, forecasting, and public information services, positioning itself as a trusted regional authority in environmental data. Their offerings include real-time pollution indices, expert data services for businesses and authorities, and public engagement platforms such as Air Attitude and Air to Go. The website reflects a mature digital presence with modern technologies including Drupal 9 CMS, interactive mapping with Leaflet and Mapbox GL, and privacy-conscious analytics via Matomo. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms, demonstrating compliance with GDPR and privacy best practices. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of explicit HTTP security headers and incident response information suggests areas for improvement. The WHOIS data is unavailable, which slightly reduces domain trustworthiness, but the strong official branding and partner affiliations mitigate this concern. Overall, the website is professionally designed, accessible, and provides valuable environmental data to its target audience of citizens, public authorities, and businesses. The security posture is solid though could be enhanced with additional headers and documented policies. Strategic recommendations include improving security headers, publishing incident response contacts, and maintaining regular audits of third-party scripts to sustain trust and compliance.

25
68
17
65
52
55
100
airqualityenvironmentpublicserviceregionalmonitoringpollution+2 more
Drupal 9Leaflet.jsMapbox GLMatomo Analytics+1

Partner Domains:

atmo-france.org
partner
auvergnerhonealpes.fr
partner

+3 more partners

2025-10-19T12:27:19.186Z
easyence.com favicon

mediarithmics

easyence.com

66
TechnologyFrancemediumMEDIUM

mediarithmics is a technology company specializing in a holistic Customer Data Platform (CDP) designed for data-driven enterprises. Their platform integrates multiple data technologies to enable real-time marketing personalization, cookieless audience monetization, and data collaboration at scale. Positioned as a key player in the Retail and Media sectors, mediarithmics offers advanced capabilities such as identity resolution, compliance with stringent privacy standards, and flexible deployment options including Zero Copy CDP on existing datalakes. The website reflects a mature digital presence with professional design, clear navigation, and comprehensive business information targeting marketers, data scientists, and ad operations professionals. Technically, the website is built on Webflow CMS and integrates modern marketing and analytics tools including HubSpot, Google Tag Manager, and Didomi for consent management. The site is well-optimized for mobile and accessibility, with strong SEO practices. Security posture is robust with HTTPS enforced, ISO27001 certification, and use of reCAPTCHA to protect forms. Privacy compliance is evident with a comprehensive privacy policy, cookie consent mechanisms, and GDPR adherence. No critical security vulnerabilities or blocking mechanisms were detected, indicating a secure and accessible website. However, the WHOIS data is privacy protected or unavailable, which is typical for SaaS companies but limits domain registration transparency. Overall, mediarithmics demonstrates a strong security and compliance posture suitable for its business model and industry requirements.

60
50
17
70
72
75
100
cdpmarketingpersonalisationaudiencemonetisationdatacollaborationretailmedia+3 more
Webflow CMSHubSpot forms and analyticsGoogle Tag ManagerGoogle reCAPTCHA+2

Partner Domains:

welcometothejungle.com
partner
navigator.mediarithmics.com
service
2025-10-19T11:22:15.527Z