Skip to main content

Germany security reports

Browse 14,812 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 290 of 297|Showing 14451-14500 of 14812
anqa-itsecurity.de favicon

Anqa IT-Security GmbH

anqa-itsecurity.de

39
TechnologyGermanymediumHIGH

Anqa IT-Security GmbH is a German-based Managed Security Service Provider specializing in comprehensive IT security solutions including UTM firewalls, pentesting, endpoint protection, dark web monitoring, and cyber security awareness trainings. The company serves over 7,000 businesses and partners with more than 500 IT system houses, positioning itself as a trusted and experienced player in the German IT security market. Their offerings are designed to be flexible with monthly cancellable contracts and include a free managed service component, enhancing customer value and operational reliability. Technically, the website is built on WordPress with modern plugins for SEO and GDPR compliance, but suffers from slow load times and lacks a valid SSL certificate, which critically impacts security posture. The absence of HTTPS and security headers represents a significant vulnerability that should be addressed immediately. Privacy compliance is strong, with clear cookie consent mechanisms and a comprehensive privacy policy. Business credibility is supported by certifications such as ISO27001 and TÜV, testimonials, and a professional online presence. Overall, while the business model and content quality are excellent, the technical security shortcomings reduce the overall risk rating and require urgent remediation.

15
18
22
75
50
80
20
it-securitymanagedservicecybersecurityawarenessutmfirewallpentesting+4 more
WordPressYoast SEO pluginjQuerySwiper.js+4

Partner Domains:

network-box.com
partnerpending
enginsight.com
partnerpending

+2 more partners

2025-06-14T21:55:38.694Z
ivymayhem.io favicon

ivy.mayhem GmbH

ivymayhem.io

51
TechnologyGermanysmallMEDIUM

ivy.mayhem GmbH is a Germany-based digital product and service studio specializing in SaaS platform development. Founded in 2016, the company develops and operates multiple SaaS products such as eniston, releasesapp, deftform, and others, serving a diverse clientele from startups to large corporations. The company recently expanded by acquiring stella.projects, a full-service web development agency, enhancing its service offerings. The website presents a professional and modern design with clear navigation and responsive layout, targeting technology-focused businesses and entrepreneurs. Technically, the site uses modern frontend technologies including Alpine.js and Tailwind CSS, hosted with Cloudflare DNS and agenturserver.de mail services. However, the website lacks a valid SSL certificate, resulting in no HTTPS support, which is a significant security concern. Security best practices such as HSTS, security headers, and OCSP stapling are absent, reducing the overall security posture. Privacy compliance is addressed with a comprehensive privacy policy and GDPR compliance statements, but no cookie consent mechanism is implemented. The site uses minimal user tracking via Fathom Analytics, respecting user privacy. Overall, the website is functional and professional but requires urgent improvements in SSL configuration and security headers to enhance trust and security.

50
43
25
55
85
80
40
saasdigitalproductstechnologygdpriso27001+2 more
JavaScript (ES Modules)Tailwind CSS (inferred from class names)Cloudflare DNS and nameserversVideo embedding with HTML5 video tag+1

Partner Domains:

stella-projects.de
subsidiarypending
2025-06-14T21:52:20.578Z
gft.com favicon

GFT Technologies SE

gft.com

63
TechnologyGermanylargeMEDIUM

GFT Technologies SE is a global technology company specializing in digital transformation and IT modernization services, primarily serving the banking, insurance, and manufacturing sectors. The company leverages advanced technologies such as cloud computing, AI, blockchain, and IoT to deliver innovative solutions that help enterprises stay competitive. Their strong partner ecosystem includes major cloud providers and fintech innovators, reinforcing their market position. Technically, the website is built on modern frameworks like Vue.js and managed via Magnolia CMS, with integrations for analytics and consent management tools such as Google Tag Manager, Microsoft Clarity, and Cookiebot. While the site is mobile-optimized and well-structured for SEO and accessibility, performance metrics were not available. The hosting is supported by Fastly CDN, ensuring global content delivery. From a security perspective, the site implements several best practices including a Content Security Policy, secure cookie flags, and security headers. However, the SSL certificate is invalid or missing, and modern TLS protocols are not supported, which significantly impacts the security posture. No explicit security policy or incident response information is publicly available, and no vulnerability disclosure or security.txt file was found. Overall, the website presents a professional and trustworthy image with comprehensive privacy and cookie policies, but the lack of valid SSL and modern TLS support are critical issues that should be addressed promptly to improve security and user trust.

85
25
25
85
50
85
100
digitaltransformationcloudaiblockchainfinancialservices+2 more
JavaScriptVue.jsGoogle Tag ManagerCookiebot+4
2025-06-14T21:35:59.120Z
exaroton.com favicon

Aternos GmbH

exaroton.com

66
TechnologyGermanymediumMEDIUM

exaroton.com is a specialized service offering high-end, on-demand Minecraft game servers with a unique pay-per-use pricing model. The platform targets Minecraft players and server administrators who desire flexible, customizable, and cost-efficient server hosting. The service is backed by Aternos GmbH, a German company, and integrates features such as DDOS protection, automatic backups, and API access to enhance user experience and operational control. The website demonstrates a professional design with clear navigation and comprehensive content tailored to its niche audience. Technically, the site employs modern web technologies including JavaScript, HTML5, and CSS3, with DNS and CDN services provided by Cloudflare. The platform supports both Minecraft Java and Bedrock editions, offering a wide range of server software and modpacks. Despite good SEO and accessibility practices, the website suffers from a critical security flaw: the absence of a valid SSL certificate and HTTPS support, which severely impacts its security posture. Security-wise, the site has implemented SPF and DMARC DNS records with a strict reject policy, uses Google MX servers for email, and has no subdomain takeover vulnerabilities. However, the lack of HTTPS, TLS protocols, HSTS, and OCSP stapling exposes users to potential risks. Privacy compliance is strong, with a comprehensive privacy policy and terms of service hosted on the parent company domain. Analytics usage is moderate and privacy-conscious, utilizing Matomo. Overall, exaroton.com presents a strong business and technical foundation but must urgently address its SSL/TLS deficiencies to ensure user trust and data security. Strategic improvements in security configuration will elevate the platform's credibility and protect its user base effectively.

50
43
25
87
100
85
100
minecraftgameserversondemandhostingcloudgamingddosprotection+1 more
JavaScriptHTML5CSS3Cloudflare DNS+6

Partner Domains:

aternos.org
parent67
2025-06-14T21:31:50.152Z
D

DZ BANK AG Deutsche Zentral-Genossenschaftsbank

vr-bankenportal.de

40
FinanceGermanyenterpriseHIGH

The VR-BankenPortal website is a secure login portal designed for cooperative banks affiliated with DZ BANK AG, one of Germany's leading cooperative central banks. It provides customers and members with access to online banking services, including account management and password reset functionalities. The portal is clearly branded with DZ BANK's identity and targets banking customers within the cooperative banking sector in Germany. The business model focuses on providing secure digital access to banking services rather than direct customer engagement or marketing. From a technical perspective, the website employs modern TLS protocols (TLS 1.3 and 1.2) and is hosted on Google Cloud infrastructure. However, the site exhibits slow load times and lacks advanced security headers and cookie consent mechanisms. The absence of structured data and analytics scripts suggests a minimalistic approach focused solely on secure login functionality. Mobile optimization and accessibility are basic, indicating room for improvement in user experience. Security posture is adequate but not robust. HTTPS is enforced with a valid certificate, but critical security enhancements such as HSTS, OCSP stapling, DMARC records, and security headers are missing. The login form posts credentials securely to a DZ BANK domain, reducing phishing risk. No vulnerabilities or exposed sensitive data were detected, but the lack of certain security best practices lowers the overall security score. Overall, the website is functional and trustworthy for its intended purpose but would benefit from performance optimization, enhanced security configurations, and improved privacy compliance measures. Strategic improvements in these areas would strengthen user trust and regulatory adherence.

90
18
25
70
87
80
100
bankinglogincooperativebanksfinancesecureportal
HTML5CSSTLS 1.3TLS 1.2

Partner Domains:

dzbank.de
partner40
2025-06-14T20:56:27.692Z
V

VRM

meine-vrm.de

40
MediaGermanylargeHIGH

VRM operates as a regional media company serving the Rhein-Main and Mittelhessen areas in Germany, offering a broad portfolio of newspapers, magazines, subscription services, advertising platforms, and travel packages. The website meine-vrm.de acts as a central hub linking to various VRM services and portals, targeting regional readers and subscribers. The business model focuses on media publication, subscription sales, and advertising revenue, positioning VRM as a leading regional media provider with a strong local presence and diversified service offerings. Technically, the website employs common web technologies such as jQuery, Foundation framework, and slick carousel for UI components, alongside Google Tag Manager and DoubleClick for analytics and advertising. Hosting is managed via Versatel nameservers. However, the site suffers from a lack of HTTPS support, with no valid SSL certificate installed, which significantly impacts security posture and user trust. Performance is suboptimal with a slow load time and a large number of resources. Security-wise, the absence of HTTPS, missing security headers, and lack of advanced TLS protocols represent critical vulnerabilities. While no active WAF or blocking mechanisms are detected, the site does not implement modern security best practices, exposing users to potential risks. Privacy compliance is well addressed with a comprehensive privacy policy, cookie consent banner, and GDPR adherence via consentmanager.net integration. Overall, VRM's website demonstrates solid business credibility and content quality but requires urgent security improvements, particularly SSL/TLS implementation, to protect user data and enhance trust. Strategic investments in security and performance optimization will strengthen VRM's digital maturity and safeguard its market position.

15
18
17
70
75
75
100
medianewssubscriptionregionalconsent+1 more
jQueryFoundation frameworkSlick carouselConsentmanager.net+3

Partner Domains:

vrm-abo.de
partner40
vrm-mediasales.de
partner40

+3 more partners

2025-06-14T20:55:13.510Z
P

Perbility

mein-check-in.de

40
TechnologyGermanysmallHIGH

The domain mein-check-in.de hosts a minimal website that immediately redirects visitors to an external recruiting solutions page at www.mein-helix.de. The site appears to represent a product or service named CHECK-IN by Perbility, targeting recruiting professionals or businesses. The business model is likely B2B software or service provision in the technology sector, specifically recruiting solutions. However, the website itself contains no substantive content, contact information, or legal disclosures, limiting insight into market position or company size. Technically, the site is hosted on an Apache server with DNS managed by noris.net. The SSL configuration is critically deficient, with no valid certificate and no TLS protocols enabled, resulting in an insecure HTTP-only connection despite the presence of HSTS headers. Security headers such as X-Frame-Options and X-Content-Type-Options are present, but the lack of HTTPS severely undermines security posture. Performance data is unavailable, but the immediate redirect and minimal content suggest a very lightweight site. Security posture is weak due to missing HTTPS and malformed DNS CAA records. No privacy, cookie, or terms policies are present, and no contact or incident response information is available. The site does not employ analytics or tracking technologies, indicating minimal user data collection. Overall, the site functions primarily as a redirect placeholder rather than a full-featured business website. Strategic recommendations include obtaining and properly configuring a valid SSL certificate to enable HTTPS, correcting DNS CAA records, implementing DMARC for email security, and publishing privacy and cookie policies to improve compliance and trust. Adding clear contact and business information would enhance credibility and user confidence.

50
15
25
70
97
80
100
redirectminimalcontentsecurityheadersnossltechnology
Apache
2025-06-14T20:54:41.397Z
vr-payment.de favicon

VR Payment GmbH

vr-payment.de

40
FinanceGermanymediumHIGH

VR Payment GmbH is a specialized payment solutions provider serving the Volksbanken Raiffeisenbanken network and their merchants. The company offers a broad range of services including card readers, terminals, cashless payment methods, e-commerce payment integration, and value-added services such as digital receipt management and mobile payment solutions. The website reflects a professional and consistent brand presence targeting merchants, banks, and resellers within the financial and payment technology sectors in Germany. The company maintains a medium-sized market presence with a focus on innovation and customer-centric payment solutions. Technically, the website is built on the Contao CMS platform and leverages modern JavaScript libraries such as jQuery, jQuery UI, and Swipe.js for UI interactions. It uses Matomo for analytics and Usercentrics for consent management, indicating a mature approach to user privacy and data tracking. However, the website suffers from a critical security deficiency due to an invalid or missing SSL certificate and lack of enabled TLS protocols, which severely undermines HTTPS security and user trust. From a security perspective, while the site has HSTS enabled with preload and a valid SPF record, the absence of a valid SSL certificate and TLS support is a major vulnerability. No incident response or explicit security policy information is found, and no vulnerability disclosure or security.txt file is present. Privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanism. Contact information is readily available through multiple channels including email, phone, and detailed contact forms. Overall, the website is content-rich, professionally designed, and privacy-conscious but critically impaired by its SSL/TLS configuration issues. Immediate remediation of the SSL certificate and enabling modern TLS protocols is essential to restore security posture and trustworthiness.

85
18
25
70
100
80
20
paymentfinancee-commerceposgdpr+3 more
jQueryjQuery UISwipe.jsMatomo Analytics+2

Partner Domains:

vr-pay-ecommerce.de
partnerpending
vr-payment-webportalpos.de
partnerpending

+1 more partners

2025-06-14T20:54:15.707Z
vrm-mediasales.de favicon

VRM Holding GmbH & Co. KG

vrm-mediasales.de

40
MediaGermanymediumHIGH

VRM Media Sales is a regional media sales company operating primarily in the Rhein-Main and Mittelhessen regions of Germany. They specialize in developing tailored advertising solutions and media campaigns for local businesses, leveraging print and online media channels. The company positions itself as a competent partner for marketing strategies, offering services such as campaign planning, mediamix consulting, and corporate publishing. Their website reflects a medium-sized enterprise with a professional digital presence, targeting businesses seeking regional advertising opportunities. Technically, the site uses JavaScript, Google Analytics, Google Tag Manager, and a consent management platform, hosted on Versatel infrastructure and built on the ecomaXL CMS platform. However, the website suffers from a lack of a valid SSL certificate and HTTPS support, which significantly impacts its security posture. Other security best practices such as DNSSEC, DMARC, and security headers are missing, exposing the site to potential risks. Privacy compliance is well addressed with a comprehensive privacy policy, cookie consent mechanism, and GDPR notices. Overall, the website is content-rich and professionally designed but requires urgent security improvements to protect user data and enhance trust.

70
18
25
70
100
75
-
mediaadvertisingmarketingregionalgerman
JavaScriptGoogle AnalyticsGoogle Tag ManagerConsentmanager.net
2025-06-14T20:53:07.864Z
A

Axel-Bourjau-Stiftung

axel-bourjau-stiftung.de

40
Non-profitGermanysmallHIGH

The Axel-Bourjau-Stiftung website represents a small regional non-profit foundation focused on supporting children and youth work through cultural, educational, and social projects in Büchen, Germany. The foundation was established in 2005 and primarily serves local communities, churches, and schools. The website content is well-structured and provides clear information about the foundation's mission, projects, and history, targeting local stakeholders and potential supporters. Technically, the website uses Bootstrap and jQuery for frontend development and is hosted with GoDaddy services. The site performance is moderate with a page load time of approximately 3.3 seconds and basic mobile responsiveness. However, the site lacks a valid SSL certificate, resulting in no HTTPS support, which significantly impacts security posture and user trust. From a security perspective, the absence of HTTPS, security headers, and cookie consent mechanisms are critical vulnerabilities. No forms or direct contact emails are present on the homepage, limiting direct user engagement. The site does not implement modern security best practices such as HSTS or OCSP stapling. Privacy compliance is minimal, with a privacy policy page present but no cookie consent or GDPR indicators. Overall, the website is functional and informative but requires urgent security improvements, especially enabling HTTPS and implementing privacy compliance features, to enhance trustworthiness and protect user data.

15
18
25
65
100
85
50
non-profitfoundationsocialcultureeducation+1 more
BootstrapjQuery
2025-06-14T20:34:33.642Z
M

Miles & More GmbH

swiss-shop.com

51
E-commerceGermanylargeMEDIUM

The Worldshop is a comprehensive e-commerce platform operated by Miles & More GmbH, serving as the sales channel for Europe's leading loyalty program. It offers a wide range of premium products from over 400 brands, including exclusive SWISS branded items, targeting loyalty program members and general consumers. The platform integrates miles earning and redemption with flexible payment options, including Cash & Miles, and maintains a presence both online and at airport stores. Technically, the website employs a modern JavaScript stack with Apache Wicket as the framework, leveraging various libraries for UI components, lazy loading, and analytics. However, performance is moderate to slow due to large page size and resource count. Mobile optimization and accessibility are well addressed, ensuring a good user experience across devices. From a security perspective, the site lacks a valid SSL certificate and does not implement modern TLS protocols or security headers like HSTS, which poses significant risks. Privacy compliance is strong with clear policies and consent mechanisms. The site integrates multiple trusted payment and shipping partners, enhancing business credibility. Overall, while the business and content aspects are strong and professional, critical security issues related to SSL must be addressed to improve trust and protect user data. Strategic improvements in security posture and performance optimization are recommended.

15
40
25
50
50
80
100
e-commerceloyaltyprogramretailaviationloyalty+1 more
jQueryApache WicketMaterial Design ComponentsLazyLoad+6

Partner Domains:

miles-and-more.com
partner59
2025-06-14T20:30:21.761Z
D

dbc - digital business creators gmbh

dbc-gmbh.com

65
TechnologyGermanymediumMEDIUM

dbc - digital business creators gmbh is a full-service digital agency based in Germany, specializing in application development, content management, cloud services, and AI applications. The company serves a diverse range of industries including technology, financial services, insurance, pharma, and marketing. Their market position is supported by a portfolio of notable clients and a commitment to delivering tailored digital solutions from concept to long-term maintenance. Technically, the website is built on modern frameworks such as React and Next.js, with a CMS likely based on Strapi. The site employs TLS 1.3 for secure communications and integrates Lottie animations for enhanced user experience. However, performance is currently slow, and some advanced security features like HSTS and OCSP stapling are not enabled. From a security perspective, the site has a valid SSL certificate and no critical vulnerabilities were detected. However, improvements are recommended in email security (DMARC), certificate transparency, and enabling additional security headers. Privacy compliance is well addressed with a comprehensive privacy policy and cookie policy, though no explicit consent mechanism was found. Overall, the website demonstrates a strong business credibility and professional presentation, but could benefit from technical and security enhancements to improve performance and harden defenses. Strategic recommendations include implementing advanced security headers, optimizing site performance, and enhancing privacy controls to maintain trust and compliance.

30
25
25
85
92
75
100
digitalagencyappdevelopmentcontentmanagementcloudservicesaiapplications+1 more
ReactNext.jsLottie animationsTLS 1.3+3
2025-06-14T20:26:48.556Z