Skip to main content

N/a security reports

Browse 30,780 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157367
Websites
130
Industries
113
Countries
52
Avg Score
Page 121 of 616|Showing 6001-6050 of 30780
exastaging.com favicon

Exasol

exastaging.com

69
TechnologyN/amediumMEDIUM

Exasol is a technology company specializing in a high-performance analytics engine designed to modernize data warehouses, accelerate analytics, optimize cloud costs, and enable governed AI/ML workloads. The company targets data professionals including database masters, data scientists, and analytics accelerators, positioning itself as a scalable and cost-effective solution provider in the analytics and AI space. The website reflects a mature digital presence with comprehensive content, customer stories, and industry-specific solutions, indicating a medium-sized enterprise with a strong market position. Technically, the website is built on WordPress hosted on AWS infrastructure, utilizing modern web technologies such as Google Tag Manager, Cookiebot for consent management, and Plyr for video playback. The site is well-optimized for performance, mobile responsiveness, accessibility, and SEO, with structured data enhancing search visibility. Security practices include HTTPS enforcement and cookie consent mechanisms, though some security headers and vulnerability disclosure information could be improved. The security posture is solid with no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR consent mechanisms. Business credibility is supported by professional content, customer testimonials, and consistent branding. WHOIS data confirms domain legitimacy and appropriate registration history. Overall, Exasol's website demonstrates a strong digital maturity and security posture suitable for its business model. Strategic recommendations include enabling DNSSEC, adding security headers, publishing vulnerability disclosure policies, and providing incident response contacts to further enhance trust and security readiness.

90
68
17
60
42
85
100
analyticsaimldatawarehousetechnology+3 more
Google Tag ManagerCookiebotYouTube iframe APIPlyr video player+3
2025-10-19T02:21:01.529Z
membershipoperator.com favicon

Operator

membershipoperator.com

51
MediaN/asmallMEDIUM

Operator is a newly established subscription-based newsletter and resource platform focused on helping individuals build and operate membership businesses with purpose and excellence. The website positions itself as a trusted resource for subscription business operators, offering curated content and insights to its target audience. The business model revolves around subscription and content delivery, with a clear focus on media and business sectors. Technically, the website employs modern JavaScript frameworks, including React, and integrates third-party services such as Stripe for payments and Sentry for error monitoring. Hosting and DNS services appear to be managed via Google Cloud and Squarespace Domains, respectively. The site demonstrates good mobile optimization and a professional design, though some accessibility features are basic. Security posture is solid with HTTPS enabled and domain status protections in place; however, DNSSEC is not enabled, and no explicit security policies or incident response information are published. Privacy compliance is limited due to the absence of privacy and cookie policies, which is a notable gap for a subscription-based service. Overall, the website is accessible without WAF or blocking mechanisms, and content is safe and business-focused.

15
35
2
40
57
80
100
businessmediasubscriptionmembershipnewsletter
JavaScriptReact (implied by jsx-runtime.js)Day.jsStripe (payment integration)+2
2025-10-19T00:04:15.671Z
E

Emerson Electric Co.

greenleegear.com

60
RetailN/amediumMEDIUM

Greenleegear.com is an e-commerce website specializing in branded apparel and accessories for the Greenlee and RIDGID brands, both associated with Emerson Electric Co. The site targets professionals and enthusiasts in related industries, offering a range of products including men's, women's, and youth apparel, as well as accessories and co-branded merchandise. The business model is retail-focused, leveraging brand recognition and parent company support to position itself in a niche market. The website demonstrates consistent branding and a professional presentation with clear navigation and mobile optimization. Technically, the site uses a modern JavaScript library (jQuery 3.6.0), Google Fonts, and custom navigation scripts to deliver a responsive user experience. Hosting and domain registration are managed through CSC Corporate Domains, Inc., with HTTPS enabled ensuring basic transport security. However, the site lacks advanced security headers and DNSSEC, which are recommended for enhanced protection. The absence of privacy and cookie policies indicates a gap in compliance with data protection regulations. From a security perspective, the website maintains a moderate posture with HTTPS and domain status protections but falls short on explicit security policies and headers. No vulnerabilities or malware indicators were detected in the content. The lack of privacy and cookie policies, as well as limited contact information, reduces trust and compliance scores. Overall, the site is functional and professional but would benefit from improved security and privacy practices. The overall risk assessment is moderate with no critical issues detected. Strategic recommendations include implementing DNSSEC, adding comprehensive privacy and cookie policies, enhancing security headers, and improving transparency with contact and incident response information to strengthen trust and compliance.

50
35
2
65
72
85
100
e-commerceretailapparelgreenleeridgid+1 more
jQuery 3.6.0Google FontsCustom CSShc-offcanvas-nav.js

Partner Domains:

ridgidgear.com
partner
emerson.com
parent
2025-10-19T00:04:10.661Z
strategy.com favicon

Strategy

strategy.com

66
FinanceN/amediumMEDIUM

Strategy.com is a specialized financial analytics platform focusing on providing real-time market data and metrics related to MicroStrategy (MSTR) stock and Bitcoin. The website offers detailed financial indicators such as price, returns, market capitalization, trading volume, and Bitcoin holdings, targeting investors and financial analysts interested in these assets. The platform also extends its offerings to merchandising and software products, indicating a diversified business model within the finance and technology sectors. The site is professionally designed with consistent branding and clear navigation, supporting a good user experience for its target audience. Technically, the website leverages modern web technologies including React, Next.js, and Material-UI, with content managed via Contentstack CMS. It integrates marketing and analytics tools such as Google Tag Manager and Marketo, and employs OneTrust for cookie consent management, reflecting a mature digital infrastructure. Performance is moderate with good mobile optimization and basic accessibility features. SEO practices are well implemented with proper meta tags and Open Graph data. From a security perspective, the site enforces HTTPS and includes important security headers, contributing to a strong security posture. However, it lacks explicit security policy documentation, incident response contacts, and vulnerability disclosure mechanisms, which are areas for improvement. Privacy compliance is well addressed with comprehensive privacy and cookie policies and GDPR compliance indicators. The absence of direct contact emails or phone numbers slightly reduces business credibility. Overall, the website presents a trustworthy and professional front for its niche financial analytics services. The main risk factor is the absence of WHOIS registration data, which reduces transparency about domain ownership and age. Strategic recommendations include enhancing security transparency, adding incident response information, and improving direct contact availability to strengthen trust and compliance further.

40
88
2
75
72
75
100
financemarketdatabitcoinmicrostrategyanalytics+1 more
ReactNext.jsMaterial-UIGoogle Tag Manager+2
2025-10-18T21:57:16.687Z
deaflympics.com favicon

International Committee of Sports for the Deaf

deaflympics.com

60
Non-profitN/asmallMEDIUM

The International Committee of Sports for the Deaf (ICSD) operates the Deaflympics.com website, serving as the official platform for deaf athletes competing internationally. The site provides comprehensive information about Deaflympics games, athletes, sports, countries, and news updates. It holds a recognized position in the international sports community, affiliated with the International Olympic Committee, and targets deaf athletes and sports enthusiasts globally. The business model is non-profit, focusing on event coordination and information dissemination. Technically, the website uses a modern tech stack including jQuery 3.6.0 and Bootstrap 5, hosted likely by 1&1 IONOS. The site is moderately performant, mobile-optimized, and has a consistent branding approach. However, accessibility and SEO optimizations are basic, and no CMS or advanced platforms are detected. From a security perspective, the site lacks DNSSEC and visible security headers, and no cookie consent mechanism is present, which impacts privacy compliance. The domain is well-established with consistent WHOIS data, indicating legitimacy. No WAF or blocking mechanisms are detected, and no critical vulnerabilities are visible in the provided content. Overall, the website is professional and trustworthy but would benefit from enhanced security headers, DNSSEC implementation, and privacy compliance improvements to strengthen its security posture and user trust.

15
53
17
60
90
70
100
deaflympicsdeafsportsinternationalsportsicsddeafathletes+1 more
jQuery 3.6.0Bootstrap 5
2025-10-18T21:56:31.596Z
Y

YunoHost

yunohost.org

65
TechnologyN/asmallMEDIUM

YunoHost is an open-source, volunteer-driven non-profit project founded in 2012 that provides an easy-to-use system for self-hosting digital services on personal or organizational servers. It targets individuals, small organizations, and associations seeking to control their own digital infrastructure with minimal technical knowledge. The platform offers a variety of applications including mail hosting, cloud storage, social networks, and more, emphasizing privacy, decentralization, and digital sovereignty. The website reflects a consistent brand and community-oriented approach with multilingual support and active donation campaigns. Technically, the website is built with modern web standards including HTML5, CSS3, and JavaScript, using fonts like Source Sans 3 and icon sets such as Font Awesome. It is hosted by OVH sas, a reputable provider, and the domain is well-established since 2012. The site is mobile-optimized, accessible, and SEO-friendly, though performance is moderate. No CMS or major frameworks are explicitly detected. The site lacks advanced security headers and DNSSEC is not enabled, representing areas for improvement. From a security perspective, the site uses HTTPS and has domain status protections against unauthorized transfers or deletions. However, it lacks explicit security headers and cookie consent mechanisms, and no vulnerability disclosure or incident response contacts are published. No sensitive data exposure or vulnerabilities are evident in the content. The overall security posture is moderate but could be enhanced by adopting best practices such as enabling DNSSEC, adding security headers, and publishing clear privacy and security policies. Overall, YunoHost presents a trustworthy and professional presence consistent with its open-source community-driven mission. The site is safe, free of adult or questionable content, and provides clear information about its services and community. Strategic recommendations include improving privacy compliance, enhancing security configurations, and publishing vulnerability disclosure information to strengthen trust and security culture.

90
50
25
70
85
85
40
open-sourceself-hostingprivacydecentralizationnon-profit+1 more
HTML5CSS3JavaScriptFont Awesome+1
2025-10-18T21:54:31.336Z
eventschedule.com favicon

Event Schedule

eventschedule.com

60
TechnologyN/asmallMEDIUM

Event Schedule is a specialized SaaS platform focused on enabling talent, vendors, venues, and event curators to create, promote, and share custom event calendars. The platform integrates features such as ticket sales, QR check-ins, AI-powered tools, translations, and team collaboration, positioning itself as a niche player in the event management technology space. The website demonstrates a professional and consistent brand presence with clear messaging targeting event organizers and participants. Technically, the site is built on WordPress with Elementor and related plugins, leveraging modern web technologies and SEO best practices. Performance and mobile optimization are good, though accessibility could be improved. Security posture is solid with HTTPS enforced and no visible vulnerabilities, but lacks some security headers and cookie consent mechanisms. The absence of WHOIS data for the domain raises concerns about domain legitimacy and registration transparency, which impacts overall trust. Social media presence and privacy policies are well established, but incident response and security policies are not publicly disclosed. Overall, the site is functional and professional but would benefit from enhanced security practices and domain registration transparency.

25
58
2
90
65
65
100
eventmanagementcalendarticketingaitoolsteamcollaboration+1 more
WordPressElementorJet EngineRank Math SEO+3

Partner Domains:

invoiceninja.com
partner
blog.eventschedule.com
subsidiary
2025-10-18T21:54:06.282Z
I

Invoice Ninja

invoicing.co

57
TechnologyN/asmallMEDIUM

Invoice Ninja operates as a SaaS platform specializing in invoicing and billing solutions primarily targeting freelancers and small businesses. The website serves as a web application built with Flutter Web technology, integrating modern authentication methods such as Google, Apple, and Microsoft OAuth. The platform offers key services including online invoicing, payment processing, and PDF invoice generation. The market position is that of a niche invoicing software provider with a small business scale and moderate brand consistency. From a technical perspective, the site leverages a modern tech stack with Flutter, OAuth libraries, and client-side PDF rendering. Hosting appears to be via Cloudflare, with analytics implemented through Google Tag Manager and Cloudflare Insights. Performance and mobile optimization are moderate to good, though SEO and accessibility features are basic. The site uses service workers for offline capabilities and update management. Security posture shows some strengths such as HTTPS usage (inferred), OAuth authentication, and service worker management. However, no security headers are detected, and no visible privacy or cookie policies are present, indicating gaps in compliance and security best practices. No contact information or incident response channels are provided, limiting transparency and trust. Overall, the website is functional and moderately secure but lacks comprehensive privacy compliance and visible business contact details. Strategic improvements in security headers, privacy disclosures, and contact transparency would enhance trust and compliance. The risk level is moderate with no critical vulnerabilities detected in the static content analyzed.

25
35
2
70
75
85
100
invoicingbillingsaasflutteroauth+2 more
Flutter WebGoogle Tag Managerpdf.jsApple OAuth+2
2025-10-18T21:54:01.270Z
T

Threadless

threadless.com

73
E-commerceN/amediumMEDIUM

Threadless is an established e-commerce platform specializing in artist-designed apparel, accessories, and home decor. It operates a global marketplace that empowers independent artists to sell their designs on a variety of products, including t-shirts, hoodies, bags, and wall art. The platform also supports community engagement through design challenges and artist shops, fostering a vibrant creative ecosystem. The website is professionally designed with a clear focus on user experience and mobile optimization, supporting a broad consumer audience interested in unique, artist-driven merchandise. Technically, the site leverages modern web technologies such as jQuery, Google Tag Manager, Facebook Pixel, and lazy loading for images, ensuring efficient content delivery and robust marketing analytics. The presence of security headers and enforced HTTPS indicates a strong security posture, although some improvements in content security policy and public security policies could enhance protection. Privacy compliance is well addressed with comprehensive privacy and cookie policies, including consent mechanisms aligned with GDPR requirements. Security-wise, the site demonstrates good practices with no visible vulnerabilities or exposed sensitive data. However, the absence of publicly available incident response contacts and vulnerability disclosure policies suggests areas for improvement in transparency and readiness. The WHOIS data for the domain is unavailable, which is a minor concern but common for privacy-conscious businesses. Overall, the site presents a low risk profile with strong trust signals and a professional e-commerce presence. Strategically, Threadless should focus on enhancing its public security documentation and consider publishing vulnerability disclosure and incident response information to build further trust. Continuous monitoring of third-party scripts and regular security audits will help maintain a secure environment. The platform's strong community and artist support position it well for sustained growth in the niche of artist-driven e-commerce.

55
83
17
100
65
80
100
e-commerceartistmarketplaceapparelprint-on-demandcommunity+3 more
jQueryGoogle Tag ManagerFacebook PixelHandlebars.js+2
2025-10-18T21:52:20.795Z
mastodon.energy favicon

mastodon.energy

mastodon.energy

60
EnergyN/asmallMEDIUM

mastodon.energy operates as a specialized Mastodon instance dedicated to professionals and academics involved in energy transition policy, infrastructure, technology, journalism, and science. It serves a niche community within the broader fediverse, providing a platform for discussion and networking in the energy sector. The website presents itself with a clear focus on this audience and offers federated social networking services without commercial advertising or tracking. Technically, the site runs Mastodon version 4.3.9, leveraging modern web technologies including React and WebSocket streaming APIs, hosted likely on DigitalOcean infrastructure. The site is mobile optimized and provides a good user experience with clear navigation and relevant content. Security-wise, the site enforces HTTPS and avoids exposing sensitive data, but lacks some security headers and formal security policies. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism or terms of service page. WHOIS data is privacy protected, which is common for community servers but limits transparency. Overall, mastodon.energy is a legitimate, well-maintained community platform with moderate security and privacy posture, suitable for its professional audience.

75
53
17
70
72
75
40
mastodonfediverseenergysocialnetworkprofessional+1 more
Mastodon 4.3.9JavaScriptReact (implied by chunked JS and SPA behavior)DigitalOcean Spaces (CDN for media)+1
2025-10-18T21:52:00.580Z
brid.gy favicon

Bridgy

brid.gy

63
TechnologyN/asmallMEDIUM

Bridgy is a specialized technology service that connects websites to social media platforms, enabling functionalities such as likes, reposts, mentions, and cross-posting. The service targets website owners and social media users seeking to integrate their web presence with social media interactions. The business operates as a small, niche player with an open-source approach, evidenced by its GitHub presence and transparent service offerings. The website is well-branded and consistent, with a clear focus on social media integration technology. Technically, the website employs standard web technologies including HTML5, CSS with Bootstrap for responsive design, and JavaScript. Hosting appears to be managed via Google Cloud DNS infrastructure. The site is mobile-optimized and structured for good SEO, though accessibility features are basic. Performance is moderate, with no major technical issues detected in the provided content. From a security perspective, the site uses HTTPS and has domain transfer protections in place. However, DNSSEC is not enabled, and no security headers were detected in the provided data, indicating room for improvement. The absence of privacy, cookie, and terms of service policies reduces privacy compliance scores. No contact information or incident response details are provided, limiting transparency. No vulnerabilities or suspicious content were found. Overall, Bridgy presents a trustworthy and professional web service with a solid technical foundation but could enhance its security posture and privacy compliance by adding relevant policies, security headers, and contact information. The risk level is low, but improvements in these areas would strengthen user trust and regulatory compliance.

75
50
2
40
95
70
100
socialmediaintegrationwebmentionopensourcetechnology
HTML5CSS (Bootstrap)JavaScript
2025-10-18T21:51:50.562Z
cyberplace.social favicon

Cyberplace

cyberplace.social

67
TechnologyN/asmallMEDIUM

Cyberplace.social is an independent Mastodon social media server focused on cybersecurity, fandom, video games, and technology communities. It operates within the fediverse, providing a decentralized platform for users interested in these topics. The site is administered by a known individual, Kevin Beaumont (@GossiTheDog), and maintains an active user base of approximately 937 monthly active users. The platform leverages Mastodon version 4.4.7 and modern web technologies such as React and ES modules, ensuring a contemporary user experience with mobile optimization and good navigation clarity. From a technical perspective, the site demonstrates moderate performance and basic SEO and accessibility features. It uses HTTPS, but no explicit security headers were detected in the provided data, suggesting room for improvement in security hardening. Privacy compliance is partial, with a privacy policy present but lacking cookie consent mechanisms and terms of service pages. No contact emails or phone numbers are publicly listed, which is common for federated social platforms prioritizing user privacy. The security posture is adequate but could be enhanced by implementing recommended security headers, publishing security policies, and improving privacy compliance. The WHOIS data is privacy protected, which is typical for social media platforms, and does not raise immediate legitimacy concerns given the known administrator and active community. Overall, Cyberplace.social presents as a legitimate, niche social media platform with a focus on cybersecurity and related interests, but with opportunities to strengthen its security and privacy posture.

80
58
47
85
72
75
40
socialmediamastodoncybersecuritytechnologyfandom+1 more
Mastodon 4.4.7ReactJavaScript ES ModulesCSS+1
2025-10-18T21:51:25.505Z
bootstrapmade.com favicon

BootstrapMade

bootstrapmade.com

68
TechnologyN/asmallMEDIUM

BootstrapMade is a specialized provider of free and premium Bootstrap templates and themes, catering primarily to web developers, startups, and businesses seeking professional and responsive website designs. Established in 2013, the company has built a strong market presence with over 9 million downloads and a broad portfolio of templates across multiple industries. Their business model revolves around offering both free templates with footer credits and premium templates with advanced features and dedicated support, supplemented by a visual Bootstrap Template Builder for premium users. Technically, the website is built on modern web standards using Bootstrap 5, HTML5, CSS3, and JavaScript, hosted and protected by Cloudflare infrastructure. The site demonstrates excellent mobile optimization, fast performance, and good SEO practices. Analytics and tracking are implemented via Google Tag Manager and Cloudflare Insights, reflecting a moderate level of user tracking balanced with privacy considerations. From a security perspective, the site enforces HTTPS and uses Cloudflare DNS and hosting, providing a solid SSL configuration. However, explicit security headers such as Content-Security-Policy and X-Frame-Options are not visibly implemented, and no public security policy or incident response contacts are provided. Forms use secure POST methods, and no sensitive data exposure or vulnerabilities were detected in the HTML content. Overall, BootstrapMade presents a trustworthy and professional online presence with high-quality content and technical maturity. The absence of direct contact emails or phone numbers is mitigated by a contact form. Privacy and cookie policies are present with consent mechanisms, supporting GDPR compliance. Recommendations include enhancing security headers, publishing a security policy, and adding vulnerability disclosure information to further strengthen trust and security posture.

50
68
17
65
75
80
100
bootstraptemplatesthemesfreepremium+4 more
Bootstrap 5HTML5CSS3JavaScript+4
2025-10-18T21:51:10.473Z
eupolicy.social favicon

eupolicy.social

eupolicy.social

61
GovernmentN/asmallMEDIUM

eupolicy.social is a niche Mastodon server dedicated to professionals and enthusiasts involved in EU policy. It operates as a community-driven platform providing a respectful and friendly environment for discussion related to EU policy matters. The server is administered by a small team of volunteers and funded through voluntary contributions, emphasizing its non-commercial and community-oriented nature. The website clearly communicates its purpose, rules, and administrative contacts, fostering trust and transparency within its user base. Technically, the site leverages the Mastodon open-source social networking platform (version 4.4.5) and modern web technologies including React and JavaScript ES modules. The platform supports federated social media participation via the ActivityPub protocol. The website demonstrates good mobile optimization and basic accessibility features, with a moderate performance profile. SEO practices are adequate with proper meta tags and Open Graph data. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data in its HTML content. However, it lacks explicit security headers such as Content Security Policy and HSTS, and does not provide a cookie consent mechanism, which are areas for improvement. The absence of WHOIS data due to privacy protection is justified given the community nature of the service, though it slightly reduces trustworthiness from a domain registration perspective. Overall, eupolicy.social presents a trustworthy, well-maintained community platform with a clear focus and good technical foundation. Strategic recommendations include enhancing security headers, implementing cookie consent for GDPR compliance, publishing a security policy, and improving accessibility to further strengthen its security posture and user trust.

75
58
17
80
52
85
40
mastodonsocialmediaeupolicyfederatedcommunity
Mastodon 4.4.5ReactJavaScript ES ModulesActivityPub protocol
2025-10-18T21:51:05.460Z
napec-portal.com favicon

WebPortal

napec-portal.com

47
OtherN/asmallHIGH

The website napec-portal.com serves as a login portal for NAPEC, presumably the Nigerian Association of Petroleum Explorationists or a related entity. The portal is designed for members or authorized users to access their profiles and services. The site is built using Angular 14 framework and incorporates Usercentrics for cookie consent management, indicating some attention to privacy compliance. However, the public-facing content is minimal, focusing solely on login functionality without detailed business or contact information. The domain is recently registered in April 2023, consistent with a new portal launch. From a technical perspective, the site uses modern web technologies including Angular and Bootstrap for styling. DNS is managed via Google Domains, and the domain registrar is Squarespace Domains II LLC. The site shows moderate performance and basic mobile optimization but lacks advanced SEO and accessibility features. No CMS or hosting provider details are explicitly found. Cookie consent is implemented via Usercentrics, but Google Analytics is present only in commented form, indicating limited active tracking. Security posture is moderate but could be improved. HTTPS is implied but no explicit security headers such as CSP, HSTS, or X-Frame-Options are detected in the HTML content. The login form lacks visible anti-CSRF tokens or advanced input security measures. No privacy policy, terms of service, or incident response contacts are published, which limits compliance and user trust. The domain registration is consistent and shows no suspicious patterns, but the lack of detailed business information and security policies reduces overall trustworthiness. Overall, the website is functional as a login portal but lacks comprehensive privacy, security, and business transparency features. Strategic improvements in security headers, privacy documentation, and contact information publication are recommended to enhance trust and compliance.

30
35
2
60
72
80
40
loginportalnapecusercentricsangular+1 more
Angular 14Usercentrics Consent ManagementBootstrap CSSSweetAlert2+1
2025-10-18T21:50:55.440Z