Skip to main content

United States security reports

Browse 10,774 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157370
Websites
130
Industries
113
Countries
52
Avg Score
Page 208 of 216|Showing 10351-10400 of 10774
dmdiocese.org favicon

Diocese of Des Moines

dmdiocese.org

40
Non-profitUnited StatesmediumHIGH

The Diocese of Des Moines website serves as the official online presence for the Catholic Diocese in southwest Iowa, providing comprehensive information about its ministries, schools, events, and community services. The site targets the local Catholic community and families interested in faith formation and education. It offers key services such as Catholic schooling, mental health ministry, worship schedules, and charitable giving opportunities. The organization maintains a consistent brand and provides clear contact information, enhancing its credibility as a regional non-profit religious entity. Technically, the website is built on an ASP.NET framework with modern JavaScript libraries like jQuery and uses Google Tag Manager for analytics. The site employs asynchronous script loading and lazy loading for images, indicating a focus on performance and user experience. However, performance data is missing, and the site is rated as slow based on available indicators. Mobile optimization and SEO practices are good, but accessibility is basic. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability. While several security headers are present, the absence of HTTPS and weak SSL configuration significantly reduce the site's security posture. There are no visible privacy policies, cookie consent mechanisms, or incident response contacts, indicating compliance gaps with GDPR and other privacy regulations. Overall, the website is functional and professional but requires urgent improvements in security and privacy compliance to protect users and enhance trust. Strategic recommendations include implementing a valid SSL certificate, enabling modern TLS, adding privacy and cookie policies, and establishing incident response protocols.

70
-
5
50
-
85
100
educationnon-profitreligioncatholiccommunity+3 more
ASP.NETjQuery 3.7.1Google Tag ManagerGoogle Marketing Platform (gtag.js)+2

Partner Domains:

catholiccharitiesdm.org
partnerpending
catholicfoundationiowa.org
partnerpending
2025-06-15T13:07:50.206Z
abtassociates.com favicon

Abt Global

abtassociates.com

40
GovernmentUnited StateslargeHIGH

Abt Global is a well-established international consulting and social impact organization with over 60 years of history and a large workforce. The company focuses on leveraging data, innovation, and expertise across multiple sectors including health, environment, governance, and economic growth to improve lives worldwide. Their business model centers on providing consulting, technical assistance, and digital solutions to governments, organizations, and communities. The website reflects a professional and comprehensive digital presence with strong branding and relevant content targeting global development stakeholders. Technically, the website is built on Drupal 10 and uses modern JavaScript libraries and marketing/analytics tools such as Google Tag Manager, Google Analytics, LinkedIn Insight Tag, and HubSpot. However, the site suffers from slow load times and lacks a valid SSL certificate, resulting in no HTTPS support. Mobile optimization and SEO are good, but accessibility is basic. The hosting appears to be via Fastly CDN. From a security perspective, the absence of a valid SSL certificate and HTTPS is a critical vulnerability, severely impacting the security posture. No security headers or advanced TLS configurations are present, and no incident response or security policies are published. Cookie consent mechanisms are implemented, indicating GDPR awareness, but no terms of service or vulnerability disclosure pages are found. Overall, the security maturity is low and requires urgent improvements. The overall risk assessment highlights the critical need for SSL/TLS implementation to protect user data and improve trust. Strategic recommendations include securing the site with HTTPS, enabling security headers, optimizing performance, and publishing clear security and incident response policies. The business credibility and content quality are strong, but technical and security shortcomings reduce the overall trust score.

75
18
5
50
-
80
100
globaldevelopmentsolutionsdata-drivensocialimpacthealthpolicyresearcheconomicpolicyanalysisclimatechangesolutions
Drupal 10JavaScriptjQueryGoogle Tag Manager+4
2025-06-15T13:07:49.673Z
goodness.inc favicon

Goodness, Inc.

goodness.inc

60
E-commerceUnited StatessmallMEDIUM

Goodness, Inc. is a user-first digital commerce partner specializing in helping direct-to-consumer (DTC) brands thrive in the digital economy. The company offers a comprehensive suite of services including DTC strategy, design, technology, and marketing activation, serving notable clients such as OREO, CLIF, and Papa & Barkley. Their market position is that of a specialized, boutique agency with a strong focus on delivering best-in-class digital experiences for modern brands. The business is US-based, relatively new (established in 2023), and operates with a small but professional team. Technically, the website is built on modern frameworks like Nuxt.js and Vue.js, leveraging Cloudflare for DNS and DigitalOcean for media hosting. The site integrates multiple marketing and analytics tools including Google Analytics, Google Tag Manager, HubSpot, and social media pixels. However, the site suffers from slow performance and lacks a valid SSL certificate, which is a critical security concern. Mobile optimization and accessibility are good, and SEO practices are well implemented. From a security perspective, the absence of a valid SSL certificate and disabled TLS protocols significantly weaken the site's security posture. While some security headers like HSTS and SPF are present, the lack of HTTPS and modern TLS support are critical vulnerabilities. The site does not implement a cookie consent mechanism, and its DMARC policy is set to 'none', indicating limited email protection. No explicit security policies or incident response contacts are found. Overall, the website presents a professional and trustworthy business with excellent content and branding but requires urgent security improvements to protect user data and enhance trust. The domain registration details are consistent and transparent, supporting the legitimacy of the business. Strategic recommendations include obtaining a valid SSL certificate, enabling modern TLS protocols, implementing cookie consent, and enhancing email security policies.

30
43
25
75
97
80
100
digitalcommercedtcecommerceagencybrandingtechnology+2 more
Nuxt.jsVue.jsGoogle Tag ManagerGoogle Analytics+5
2025-06-15T11:55:57.767Z
bkwld.com favicon

Goodness, Inc.

bkwld.com

55
E-commerceUnited StatesmediumMEDIUM

Goodness, Inc. is a well-established digital commerce agency specializing in user-first design and technology solutions for direct-to-consumer (DTC) brands. With over 20 years of domain maturity and a portfolio featuring prominent clients such as OREO, CLIF, and Papa & Barkley, the company positions itself as a strategic partner for modern brands seeking to thrive in the digital economy. Their services encompass DTC strategy, design, technology, and multi-brand website development, reflecting a comprehensive approach to digital commerce. Technically, the website leverages modern frameworks like Nuxt.js and Vue.js, supported by robust analytics and marketing tools including Google Analytics, HubSpot, and LinkedIn Insight. However, the site suffers from a critical security shortfall due to the absence of a valid SSL certificate and lack of HTTPS enforcement, which significantly impacts its security posture. Performance metrics indicate a slow loading time and large page size, suggesting opportunities for optimization. From a security perspective, the presence of SPF and DMARC records with a strict reject policy demonstrates good email security practices. Yet, the lack of TLS protocols, HSTS, and OCSP stapling, combined with no certificate transparency compliance, exposes the site to potential risks. Privacy compliance is strong, with clear privacy and cookie policies and consent mechanisms in place. Overall, Goodness, Inc. presents a credible and professional digital presence with excellent content quality and business credibility. The primary risk lies in its SSL/TLS configuration, which should be addressed promptly to enhance trust and security. Strategic recommendations include implementing a valid SSL certificate, enabling modern TLS protocols, and optimizing site performance to align with its high-quality brand image.

30
43
25
70
50
85
100
digitalcommercedtcecommerceagencynuxtjsvuejs+4 more
Nuxt.jsVue.jsGoogle AnalyticsGoogle Tag Manager+5
2025-06-15T11:53:42.534Z
endsoftpatents.org favicon

Free Software Foundation

endsoftpatents.org

44
TechnologyUnited StatessmallHIGH

End Software Patents is a non-profit advocacy initiative operated by the Free Software Foundation, focused on abolishing software patents to protect developer freedom and promote free software principles. The website serves as an educational platform providing resources, campaigns, and calls to action for software developers and advocates. The site is positioned as a niche player within the technology and non-profit sectors, targeting developers and free software supporters globally. Technically, the website is built on WordPress using the Hestia theme and standard web technologies like Bootstrap and jQuery. While the site is mobile responsive and well-structured, it suffers from slow load times and lacks modern performance optimizations. Security posture is weak due to the absence of a valid SSL certificate and HTTPS support, exposing visitors to potential risks. Privacy compliance is minimal, with a privacy policy linked only via the parent organization's site and no cookie consent mechanisms. Business credibility is supported by the association with the Free Software Foundation, a reputable non-profit organization with a long domain registration history. Overall, the site is functional and informative but requires significant improvements in security and privacy to enhance trust and user safety.

55
43
25
60
50
80
40
softwarepatentsfreesoftwareadvocacynon-profittechnology
WordPressBootstrapjQueryHestia WordPress Theme+1
2025-06-15T11:42:52.735Z
A

Atom

threesixty.com

53
TechnologyUnited StateslargeMEDIUM

Atom.com operates a comprehensive online marketplace specializing in premium domain name sales, branding contests, and related services such as trademark filing and audience research. The website for ThreeSixty.com serves as a landing page for a high-value domain sale, offering multiple purchase options including buy now, installments, and escrow services. The platform targets businesses and entrepreneurs seeking brandable domain names and branding solutions, positioning itself as a trusted and established player in the domain marketplace industry since 2011. Technically, the website employs modern JavaScript frameworks and monitoring tools such as New Relic and Intercom, hosted on Amazon AWS infrastructure. While the site is mobile-optimized and features good navigation and content quality, it suffers from critical security shortcomings including the absence of a valid SSL certificate and missing security headers, which significantly impact its security posture. From a security perspective, the lack of HTTPS and security headers exposes users to potential risks and undermines trust. However, the presence of a purchase protection program, verified domain badges, and clear contact information contribute positively to business credibility. The domain registration data aligns well with the website's claims, indicating legitimacy. Overall, while the business model and content quality are strong, immediate remediation of security issues is essential to enhance user trust and compliance. Strategic improvements in SSL deployment, security headers, and privacy mechanisms will elevate the platform's security and privacy compliance, supporting its market position and customer confidence.

60
25
25
50
50
85
100
domainsalesbrandingnamingcontestspremiumdomainsaitools+1 more
JavaScriptNew Relic Browser AgentIntercomCloudflare Insights+3

Partner Domains:

atom.com
partner65
2025-06-15T09:18:27.404Z
personifycorp.com favicon

Personify

personifycorp.com

49
TechnologyUnited StateslargeHIGH

Personify is a mature technology company specializing in software solutions for associations, nonprofits, chambers of commerce, and event professionals. With over 25 years of industry leadership and a client base exceeding 30,000 organizations, Personify offers a comprehensive SaaS platform including association management, event management, and member engagement software. Their business model focuses on delivering purpose-driven software combined with client success services to empower organizations in building communities and revenue streams. The company maintains a strong market position supported by multiple subsidiary brands and a consistent, professional web presence. Technically, the website is built on WordPress with a modern tech stack including Yoast SEO, UberMenu, and integrations with marketing and analytics tools such as Google Tag Manager and Marketo. Hosting appears to be on Azure infrastructure. Despite good SEO and content quality, the website suffers from slow load times and lacks a valid SSL certificate, which critically impacts security and user trust. From a security perspective, the absence of HTTPS and modern TLS protocols is a significant vulnerability, exposing visitors to potential data interception risks. The site also lacks essential security headers and advanced SSL features like HSTS and OCSP stapling. Privacy compliance is reasonably addressed with a clear privacy policy and cookie consent mechanism, but no explicit security or incident response policies are found. Overall, while Personify demonstrates strong business credibility and digital marketing maturity, urgent improvements in SSL/TLS implementation and security hardening are necessary to protect users and enhance trust. Addressing these gaps will align the company’s technical posture with its market leadership and professional brand image.

15
43
25
50
50
80
100
technologyassociationmanagementeventmanagementmemberengagementsaas+1 more
WordPressYoast SEOUberMenuGoogle Tag Manager+6

Partner Domains:

memberclicks.com
subsidiaryanalyzing...
wildapricot.com
subsidiary52

+1 more partners

2025-06-15T09:14:04.271Z
trustly.one favicon

Trustly, Inc.

trustly.one

53
FinanceUnited StateslargeMEDIUM

Trustly, Inc. is a leading Pay by Bank payment service provider leveraging a proprietary Open Banking technology stack to deliver guaranteed payments, risk management, and consumer insights. The company targets businesses across financial services, gaming, retail, and subscription sectors, offering a global network with over 110 million consumers in 30+ countries. Their business model focuses on enabling faster, more secure, and cost-effective bank payments compared to traditional card payments. The website reflects a mature digital presence with excellent content quality and professional branding, supported by modern marketing and analytics tools such as HubSpot, Google Tag Manager, and Weglot for multilingual support. Technically, the site is built on Webflow CMS and hosted on Amazon AWS, utilizing various JavaScript libraries and integrations. However, the site suffers from slow load times and lacks a valid SSL certificate, resulting in a critical security deficiency. Accessibility and mobile optimization are good, and SEO practices are well implemented. The absence of HTTPS and security headers significantly impacts the site's security posture, exposing users to potential risks. From a security perspective, the lack of HTTPS and essential security headers, combined with no evidence of incident response or vulnerability disclosure policies, indicates a need for urgent improvements. Privacy and cookie policies are present and comprehensive, supporting GDPR compliance. The WHOIS data shows the domain is privacy-protected but consistent with the company's US presence and age, supporting legitimacy. Overall, while Trustly's business and website demonstrate strong market positioning and professional quality, the critical absence of SSL/TLS encryption and security best practices poses a significant risk. Immediate remediation of these issues is recommended to enhance user trust and secure sensitive transactions.

65
43
25
50
50
85
100
openbankingpaymentsfinancetechnologypaybybank+1 more
jQueryWebflowHubSpotGoogle Tag Manager+3

Partner Domains:

trustly.com
partneranalyzing...
2025-06-15T09:07:58.015Z
disneyprivacycenter.com favicon

The Walt Disney Company

disneyprivacycenter.com

50
MediaUnited StatesenterpriseMEDIUM

The Walt Disney Company Privacy Center website serves as a comprehensive resource for privacy-related information, focusing on transparency and user control over personal data across its digital platforms. The site targets global consumers engaging with Disney's media and entertainment services, providing detailed privacy policies, cookie consent mechanisms, and information tailored for parents and children. The business is a large enterprise with a mature domain and strong brand presence, supported by multiple subsidiary brands such as ABC, ESPN, Marvel, and Hulu. Technically, the website is built on WordPress, leveraging technologies such as Apache, jQuery, Adobe Launch, and OneTrust for cookie consent management. Hosting is via Amazon CloudFront, indicating a scalable and reliable infrastructure. SEO and accessibility features are implemented at a good level, with comprehensive metadata and structured data enhancing search visibility. From a security perspective, the site suffers from a critical issue: the absence of a valid SSL certificate and lack of HTTPS support, severely impacting the security posture and user trust. While some security headers like HSTS are present, they are insufficiently configured. No explicit security policies or incident response contacts are published, and no vulnerability disclosure mechanisms are evident. Overall, the website is professionally designed and content-rich but requires urgent remediation of its SSL/TLS configuration to ensure secure communications and compliance with modern security standards. Strategic improvements in security transparency and incident response readiness would further enhance trust and compliance.

25
43
25
50
50
85
100
privacycookieconsentmediaentertainmentdataprotection+2 more
ApachejQueryOneTrustAdobe Launch+3
2025-06-15T09:00:39.625Z
nidaschool.org favicon

Nida School

nidaschool.org

49
EducationUnited StatessmallHIGH

Nida School is a small, non-profit educational organization focused on translation studies, particularly Bible translation. The website presents the institution's mission to build capacities in translation through research and training, targeting students and professionals in this niche. The business model is educational and non-profit, with a market position as a specialized institution in translation studies. The website content is well-structured and professionally designed, with consistent branding and relevant services highlighted, such as MA programs and symposia. Technically, the website is built on the Squarespace platform, utilizing standard web technologies including Typekit fonts and embedded social media widgets. However, the site suffers from a lack of a valid SSL certificate, resulting in no HTTPS support, which critically impacts security posture. Performance metrics are missing or indicate slow loading, and accessibility features are basic. SEO is reasonably well implemented with proper meta tags and Open Graph data. From a security perspective, the absence of HTTPS and HSTS, along with disabled modern TLS protocols, represent significant vulnerabilities. Security headers are partially present but insufficient. No privacy or cookie policies are found, and no incident response or vulnerability disclosure mechanisms are in place. The domain is mature and registered with privacy protection, which is justified for this type of organization. Social media presence is active, but no direct company contact emails or phone numbers are provided on the site. Overall, the website is functional and informative but requires urgent improvements in security configuration, privacy compliance, and contact transparency to enhance trustworthiness and protect user data. Strategic recommendations include obtaining a valid SSL certificate, enabling HTTPS and HSTS, publishing privacy and cookie policies, and providing clear contact information.

35
25
25
50
50
85
100
educationtranslationnon-profitbibletranslationtraining
SquarespaceTypekit fontsYouTube embedTwitter widgets+1
2025-06-15T08:40:41.153Z
goodmorningamerica.com favicon

ABC News

goodmorningamerica.com

51
MediaUnited StatesenterpriseMEDIUM

GoodMorningAmerica.com is the official website for Good Morning America, a flagship morning news and lifestyle program under ABC News, owned by The Walt Disney Company. The site offers a rich mix of news, entertainment, lifestyle content, and affiliate e-commerce deals, targeting a broad audience interested in current events, culture, wellness, and shopping. The website is professionally designed with consistent branding and a strong social media presence, reflecting its position as a major media enterprise in the United States. Technically, the site leverages modern web technologies including React, AWS CloudFront CDN, and tag management tools like Google Tag Manager and Ensighten. The site is mobile-optimized and SEO-friendly, with comprehensive metadata and structured content. However, the SSL/TLS configuration is currently invalid, with no valid certificate and no modern TLS protocols enabled, which poses a significant security risk and impacts user trust. From a security perspective, while the site does not exhibit common vulnerabilities such as Heartbleed or POODLE, the lack of a valid SSL certificate and absence of security headers like HSTS reduce its security posture. Privacy policies and terms of service are comprehensive and hosted on Disney domains, indicating good privacy compliance. Contact information is limited to a web form, with no direct emails or phone numbers publicly listed. Overall, the website is a high-quality, authoritative media platform with excellent content and business credibility. The primary risk lies in its SSL/TLS misconfiguration, which should be addressed promptly to ensure secure user connections and maintain trust. Strategic improvements in security configuration and enhanced accessibility features would further strengthen the site’s digital maturity and user confidence.

15
43
17
50
50
85
100
newsmediaentertainmentlifestylee-commerce+6 more
nginxReactJavaScriptAWS CloudFront CDN+4
2025-06-15T08:38:50.770Z
jobforward.org favicon

JobForward

jobforward.org

54
GovernmentUnited StatesmediumMEDIUM

JobForward is a workforce development organization formed in 2025 by the merger of the Institute for American Apprenticeships and Training Funding Partners. It provides consulting, apprenticeship program design, grant writing, and workforce planning services targeting employers, workforce boards, educators, and job seekers. The organization manages significant workforce funding and operates nationally with a focus on registered apprenticeship programs and workforce solutions. Technically, the website is built on WordPress with modern plugins and Google Tag Manager for analytics, hosted likely on GoDaddy with Cloudflare CDN. However, the site lacks a valid SSL certificate and proper HTTPS configuration, which is a critical security concern. Privacy compliance is partial with a privacy policy present but no cookie policy or terms of service. Contact information is clearly provided including phone numbers, physical addresses, and a contact form. Social media presence on LinkedIn and Facebook supports business credibility. WHOIS data aligns well with the business claims, showing a consistent and legitimate registration. Overall, the website is professional and functional but requires urgent improvements in security and privacy compliance to enhance trust and protect users.

50
43
25
50
50
85
100
workforcedevelopmentapprenticeshipfundingtrainingjobseekers+3 more
PHP 8.0WordPress 6.8.1jQueryGoogle Tag Manager+9

Partner Domains:

pluckvermont.com
partnerpending
2025-06-15T08:37:39.576Z
persado.com favicon

Persado

persado.com

40
FinanceUnited StatesenterpriseHIGH

Persado is an enterprise AI marketing platform specializing in generating, optimizing, and personalizing marketing language at scale, primarily targeting banks and financial institutions. The company positions itself as a market leader with strong endorsements from major U.S. banks and credit card issuers. Their platform integrates compliance, performance, and personalization features, supported by multi-agent AI workflows and domain-specific models tailored for the financial sector. The website reflects a mature digital presence with comprehensive content, strong branding, and customer testimonials. Technically, the site is built on WordPress with modern themes and plugins, leveraging WP Engine hosting and Cloudflare CDN. It employs standard marketing and analytics tools such as Google Analytics, Google Tag Manager, Drift, Pardot, and Zapier. SEO and accessibility practices are well implemented, and the site is mobile optimized. However, a critical security shortfall is the absence of a valid SSL/TLS certificate, resulting in no HTTPS encryption, which severely impacts the security posture. Security headers are properly configured, and the company demonstrates adherence to recognized security frameworks including ISO 27001 and SOC II type 2. Privacy compliance is strong with clear privacy and cookie policies and consent mechanisms. Despite the strong compliance and governance messaging, the lack of HTTPS is a major vulnerability that undermines user trust and data protection. Overall, Persado presents a professional and credible business with advanced AI-driven marketing solutions for finance, but must urgently address its SSL/TLS certificate issues to ensure secure communications and maintain enterprise-grade security standards.

70
33
5
50
-
85
100
aimarketingfinancecomplianceenterprise+3 more
WordPressKadence ThemeKadence BlocksjQuery+7
2025-06-15T08:35:24.146Z
tfpgroup.com favicon

TFP Group Inc.

tfpgroup.com

40
GovernmentUnited StatessmallHIGH

TFP Group Inc. is a specialized consulting firm focused on workforce development and training grant funding, operating nationally in the United States with over 25 years of experience. The company serves businesses and organizations seeking to develop talent pipelines and secure training incentives, working closely with government agencies across multiple states. Their website reflects a professional presence with clear service descriptions and contact information, targeting clients in workforce development sectors. Technically, the website is built on a modern WordPress platform using Elementor and related plugins, hosted behind Cloudflare with caching mechanisms. However, the site suffers from critical security shortcomings, notably the absence of a valid SSL certificate and disabled TLS protocols, which severely impact secure communications and user trust. Performance is rated slow, and SEO and accessibility features are basic. Security posture is weak due to missing HTTPS, lack of DMARC and DNSSEC, and no incident response or vulnerability disclosure information. Privacy compliance is minimal, with no privacy or cookie policies found. Business credibility is supported by clear contact details and a consistent brand message but is undermined by security and compliance gaps. Overall, the site is functional and informative but requires urgent security improvements and privacy policy implementations to enhance trust and compliance.

60
-
5
50
-
75
100
workforcedevelopmenttraininggrantsconsultinggovernmentnon-profit
PHP 8.0WordPress 6.8.1ElementorEssential Addons for Elementor+4

Partner Domains:

jobforward.org
partnerpending
2025-06-15T08:35:24.124Z