Skip to main content

United States security reports

Browse 10,774 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157370
Websites
130
Industries
113
Countries
52
Avg Score
Page 211 of 216|Showing 10501-10550 of 10774
curotec.com favicon

Curotec

curotec.com

49
TechnologyUnited StatesmediumHIGH

Curotec is a medium-sized technology company specializing in software development services including SaaS, web, mobile, AI/ML, and e-commerce development. Positioned as a trusted and top-rated development agency, it serves SaaS and enterprise teams with flexible engagement models such as project delivery, staff augmentation, and support retainers. The company boasts multiple industry recognitions and partnerships, including official Laravel and Vue.js partnerships, enhancing its market credibility. Technically, the website is built on a modern tech stack featuring Laravel, React, Vue.js, Python, Node.js, and AWS, hosted on an Nginx server with Cloudflare DNS. The site uses WordPress CMS with Elementor for content management and includes advanced SEO and accessibility features. However, performance metrics are not available, though the site is mobile-optimized and well-structured. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability impacting user trust and data security. While SPF and DMARC records are properly configured, the absence of HTTPS and security headers like HSTS reduces the overall security posture. Privacy and cookie policies are present with consent mechanisms, indicating good compliance with GDPR and related regulations. Overall, Curotec's website is professional and content-rich, supporting its business credibility. The critical security issue of missing SSL must be addressed promptly to improve trust and protect user data. Strategic improvements in SSL configuration and security headers will enhance the site's security and compliance standing.

15
25
25
50
50
85
100
saassoftwaredevelopmentstaffaugmentationaimlwebdevelopment+2 more
LaravelPHPVue.jsNuxt+15
2025-06-14T21:49:28.468Z
kirschbaumdevelopment.com favicon

Kirschbaum Development

kirschbaumdevelopment.com

49
TechnologyUnited StatessmallHIGH

Kirschbaum Development is a small technology company specializing in web application development, staff augmentation, training, and technical leadership services. They primarily focus on Laravel, Vue.js, Angular, Drupal, and Wordpress frameworks, serving a diverse client base including Fortune 50 companies and smaller organizations. Their market position is strengthened by partnerships with Laravel and endorsements from industry leaders. The website presents a professional and consistent brand image with comprehensive service offerings and client testimonials. Technically, the website leverages modern web technologies including Laravel and Vue.js frameworks, hosted on AWS CloudFront CDN. The site includes Google Tag Manager for analytics and marketing purposes. While the site is mobile optimized and SEO friendly, performance metrics are unavailable. Accessibility is basic but functional. From a security perspective, the site lacks a valid SSL certificate and does not serve content over HTTPS, which is a critical vulnerability. No advanced security headers or mechanisms such as HSTS or OCSP stapling are implemented. Cookie consent mechanisms are absent, indicating limited privacy compliance. The site uses secure cookies with CSRF tokens but overall security posture is weak. Overall, the website is professional and credible but requires urgent improvements in SSL/TLS implementation and privacy compliance to enhance security and user trust.

15
43
25
50
50
85
100
laravelwebdevelopmentstaffaugmentationtechnicalleadershiptraining+2 more
LaravelVue.jsFilamentAngular+5
2025-06-14T21:49:28.404Z
guidewire.com favicon

Guidewire Software, Inc.

guidewire.com

68
TechnologyUnited StatesenterpriseMEDIUM

Guidewire Software, Inc. is a leading enterprise technology company specializing in Property and Casualty (P&C) insurance software and cloud platforms. Founded in 2001 and headquartered in the United States, Guidewire offers a comprehensive suite of products including InsuranceSuite for policy administration, claims management, and billing, as well as InsuranceNow, a cloud-based platform designed for rapid deployment. The company serves a global market with customers in over 40 countries and maintains a strong presence through partnerships, professional services, and an extensive marketplace ecosystem. Guidewire is recognized as a market leader with multiple industry awards and a robust social media presence. Technically, Guidewire's website leverages modern web technologies such as Next.js and React, hosted on Vercel, and managed via Sitecore CMS. The site demonstrates good mobile optimization, accessibility, and SEO practices, providing a professional and user-friendly experience. The use of Marketo forms and integration with marketing and analytics tools like Google Tag Manager and Cookiebot indicates a mature digital marketing infrastructure. From a security perspective, the site employs several security headers and enforces HTTPS, although the SSL certificate is currently invalid, which is a critical issue. The absence of full HSTS enforcement and OCSP stapling are areas for improvement. The company provides clear security and privacy policies, including incident response contact information, reflecting a responsible security posture. No major vulnerabilities or exposed sensitive data were detected. Overall, Guidewire presents a strong business and technical profile with excellent content quality and business credibility. The primary risk lies in the SSL certificate status, which should be promptly addressed to maintain trust and security. Strategic recommendations include enhancing SSL management, fully enabling HSTS, and continuing to strengthen privacy compliance and security best practices.

45
43
25
50
100
85
100
insurancesoftwaretechnologypcinsurancecloudplatform+2 more
Next.jsReactJavaScriptjQuery+3
2025-06-14T21:41:56.327Z
helpspot.com favicon

UserScape, Inc.

helpspot.com

45
TechnologyUnited StatessmallHIGH

HelpSpot, operated by UserScape, Inc., is a specialized help desk software provider focused on transforming chaotic email support into an efficient, unified system. Established in 2005, the company targets businesses and organizations that require streamlined customer support solutions. Their offerings include email ticketing, automation, reporting, and self-service portals, available as both cloud-hosted and on-premise deployments. The website demonstrates strong branding, comprehensive content, and a professional user experience, positioning HelpSpot as an affordable and customizable alternative in the help desk software market. Technically, the site uses modern web technologies such as Alpine.js, Livewire, and Cloudflare CDN, hosted on AWS infrastructure. However, the absence of a valid SSL certificate and HTTPS implementation significantly impacts the security posture. Security headers are present, but critical TLS protocols and encryption are missing, exposing the site to potential risks. Privacy compliance is supported by a comprehensive privacy policy and terms of service, though cookie consent mechanisms are not evident. Overall, while the business and technical maturity are solid, the lack of HTTPS is a critical vulnerability that must be addressed to ensure trust and security.

50
43
25
50
50
85
40
helpdeskcustomersupportemailsupporthelpdesksoftwareautomation+2 more
Alpine.jsLivewireCloudflareAWS (hosting)+4
2025-06-14T21:35:13.688Z
M

My Health Toolkit, LLC

myhealthtoolkit.com

49
HealthcareUnited StatesmediumHIGH

My Health Toolkit, LLC operates a healthcare benefits management platform targeting members of various Blue Cross and Blue Shield plans across multiple states in the United States. The platform offers services such as claims status checking, digital ID card management, coverage confirmation, provider search, and medical spending account management. It serves as a centralized portal for eligible members to manage their health insurance benefits efficiently. Technically, the website relies on the Dojo Toolkit 1.13.0 for frontend functionality and integrates Google Analytics and Google Tag Manager for user tracking and analytics. The site is hosted on infrastructure associated with Level3. However, the website suffers from slow load times and basic mobile optimization. SEO and accessibility features are present but minimal. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, exposing users to significant risks. No security headers or advanced security configurations are implemented. Privacy and cookie policies are absent, and no GDPR compliance indicators are present. These deficiencies represent critical vulnerabilities and compliance gaps that must be addressed to protect user data and build trust. Overall, while the business model and service offerings are clear and well-targeted, the technical and security posture of the website is weak. Immediate remediation of SSL/TLS issues and implementation of privacy policies are recommended to improve security and compliance. Enhancements in performance and mobile responsiveness would also benefit user experience and trust.

65
25
25
50
50
75
100
healthcareinsurancebluecrossbenefitsmanagementhealthplan+3 more
Dojo Toolkit 1.13.0Google AnalyticsGoogle Tag ManagerSmartBanner.js+1
2025-06-14T20:53:29.658Z
scdhhs.gov favicon

South Carolina Department of Health and Human Services

scdhhs.gov

63
GovernmentUnited StateslargeMEDIUM

The South Carolina Department of Health and Human Services (SCDHHS) operates the Healthy Connections Medicaid program, providing health coverage to eligible residents of South Carolina. The website serves as a comprehensive portal for Medicaid members, providers, and partners, offering detailed information on eligibility, provider enrollment, claims, communications, and legal notices. The site is well-branded and consistent with government standards, targeting a broad audience including Medicaid recipients and healthcare providers. Technically, the site is built on Drupal 10 and utilizes modern monitoring and analytics tools such as New Relic and Google Tag Manager. However, the site currently lacks a valid SSL certificate, resulting in no HTTPS support, which is a critical security concern. Security headers like SPF and DMARC are configured, but DNSSEC and CAA are missing, and no advanced TLS protocols are enabled. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism detected. Contact information is clearly provided, enhancing business credibility. Overall, the site is functional and professional but requires urgent security improvements to protect user data and comply with best practices.

40
43
55
85
85
85
100
medicaidhealthcaregovernmentsouthcarolinamedicaideligibility+2 more
Drupal 10 CMSGoogle Tag ManagerNew Relic monitoringJavaScript libraries (various)+3
2025-06-14T20:53:29.582Z
scblueretailcenters.com favicon

BlueCross BlueShield of South Carolina

scblueretailcenters.com

51
HealthcareUnited StateslargeMEDIUM

BlueCross BlueShield of South Carolina operates SC Blue Retail Centers providing in-person health insurance services and resources to consumers in South Carolina. The company holds a strong market position as a South Carolina owned and operated health insurance carrier and offers a variety of services including plan enrollment, payment processing, and Medicare seminars. The website serves as a digital front for these retail centers, providing location details, contact information, and educational content. Technically, the website is built on Drupal 10 CMS and integrates marketing and tracking tools such as Google Tag Manager and ClickCease. However, the site suffers from slow performance and lacks a valid SSL certificate, resulting in no HTTPS support. Mobile optimization and SEO are adequate, but accessibility features are basic. From a security perspective, the absence of HTTPS and security headers significantly weakens the site's security posture. While SPF and DMARC email protections are properly configured, the lack of incident response contacts, security policies, and vulnerability disclosures indicates limited security maturity. Privacy compliance is minimal, with no cookie consent mechanism detected. Overall, the website is functional and professionally presented but requires urgent improvements in security infrastructure and privacy compliance to reduce risk and enhance user trust.

70
25
25
50
50
75
100
healthinsurancebluecrossblueshieldsouthcarolinaretailcentersmedicare+1 more
Drupal 10Google Tag ManagerMandrillClickCease+1

Partner Domains:

bluechoicesc.com
partnerpending
southcarolinablues.com
partneranalyzing...
2025-06-14T20:50:19.618Z
companionbenefitalternatives.com favicon

Companion Benefit Alternatives, Inc.

companionbenefitalternatives.com

53
HealthcareUnited StatesmediumMEDIUM

Companion Benefit Alternatives, Inc. operates as a behavioral health benefit administrator primarily serving health insurance plans in South Carolina. The company manages provider networks, preauthorization processes, and offers mental health coaching resources targeting both members and providers. Positioned as the administrator for the largest insurer in South Carolina, it serves over one million members, focusing on behavioral health treatment benefits. The website content is well-structured and professionally presented, targeting healthcare providers and insurance members with relevant resources and information. Technically, the website is built on Drupal 10 CMS and uses Google Tag Manager for analytics and marketing. Hosting is inferred to be via Level3 network infrastructure. Performance is moderate with good mobile optimization and basic accessibility features. SEO practices are adequate with proper meta tags and Open Graph data. However, the site lacks a valid SSL/TLS certificate, resulting in no HTTPS support, which is a critical security and trust issue. Security posture is weak due to the absence of valid SSL, no TLS protocols enabled, and missing security headers like HSTS. Email authentication is strong with SPF and DMARC policies properly configured. Privacy compliance is basic with a privacy policy present but no cookie consent mechanism. Contact information is not explicitly provided on the homepage or footer, limiting direct communication channels. Overall, the site demonstrates a moderate level of digital maturity with good content and business clarity but suffers from critical security shortcomings that impact trust and user safety. Strategic improvements in SSL deployment and privacy compliance are essential to enhance security and user confidence.

70
25
25
50
50
75
100
behavioralhealthhealthinsurancementalhealthopioidaddictionprovidernetwork+2 more
Drupal 10Google Tag ManagerDrupal
2025-06-14T20:50:13.221Z
bcbssc.com favicon

BlueCross BlueShield of South Carolina

bcbssc.com

52
HealthcareUnited StateslargeMEDIUM

BlueCross BlueShield of South Carolina is a major regional health insurance provider offering a wide range of health insurance products including individual, family, Medicare, and group health plans. The company serves individuals, families, employers, healthcare providers, and agents primarily in South Carolina. The website reflects a well-structured and professionally branded digital presence consistent with its market position as an independent licensee of the Blue Cross Blue Shield Association. Key services include member management, provider resources, employer services, and agent support. The site integrates multiple external partners and resources to support its offerings. Technically, the website employs modern JavaScript frameworks such as Vue.js and Bootstrap Vue, hosted on IBM WebSphere Portal infrastructure with DNS hosted by Level3. Despite the modern tech stack, the site suffers from slow performance with a page load time exceeding 8 seconds and a large page size. Mobile optimization is good, and SEO practices are adequately implemented. However, the site lacks a valid SSL certificate and does not enable HTTPS, which is a critical security flaw. Security headers are absent, and no advanced TLS protocols or HSTS are configured, exposing the site to potential risks. From a security perspective, the site has strong email authentication with valid SPF and DMARC policies, but the absence of HTTPS and security headers significantly lowers its security posture. No vulnerability disclosure or incident response information is publicly available. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism detected. The site uses multiple analytics and marketing tools including Google Analytics, Adobe Launch, and Qualtrics, indicating moderate user tracking. Overall, the website is professionally designed and content-rich but requires urgent security improvements, especially regarding SSL/TLS implementation and security headers. Enhancing privacy compliance and adding explicit cookie consent would further improve trust. Strategic recommendations include immediate SSL certificate installation, enabling modern TLS protocols, implementing security headers, and publishing a vulnerability disclosure policy to strengthen security culture and compliance.

65
25
25
50
50
75
100
healthinsurancemedicaregrouphealthplansbluecrossblueshieldsouthcarolina+1 more
Vue.jsBootstrap VueAxiosAdobe Launch+5

Partner Domains:

benefitfocus.com
partneranalyzing...
express-scripts.com
partner74

+3 more partners

2025-06-14T20:50:13.007Z
endurance.com favicon

Newfold Digital Inc.

endurance.com

65
TechnologyUnited StatesenterpriseMEDIUM

Newfold Digital Inc. is a prominent enterprise-level technology company specializing in web presence solutions for small-to-medium businesses worldwide. Through a diverse portfolio of well-known brands such as Bluehost, HostGator, Network Solutions, and Web.com, the company offers comprehensive services including domain registration, hosting, website building, security, online marketing, and professional website design. Their market position is strong, supported by extensive product offerings and personalized customer support. Technically, the website is built on Adobe Experience Manager CMS and leverages modern technologies including Adobe Launch for analytics, OneTrust for cookie consent management, and AudioEye for accessibility compliance. Hosting and DNS services are protected by Cloudflare, ensuring resilience and performance. However, the site exhibits slow load times and lacks some advanced security configurations such as HSTS and DNSSEC. From a security perspective, the site maintains a valid SSL certificate, properly configured SPF and DMARC records, and no detected vulnerabilities or exposed sensitive data. Privacy compliance is robust with clear privacy and cookie policies, GDPR indicators, and a consent mechanism. Incident response readiness is indicated by an ethical hacking report link. Accessibility is enhanced through AudioEye integration, reflecting a commitment to inclusive design. Overall, Newfold Digital's website demonstrates a high level of professionalism, security, and compliance, though performance optimizations and enhanced security headers could further strengthen its posture. The company maintains a trustworthy online presence with clear business information and active social media engagement.

55
25
25
70
67
80
100
webhostingdomainswebsitebuilderonlinemarketingsecurity+3 more
Adobe LaunchjQueryMaterial IconsAudioEye Accessibility+5

Partner Domains:

register.com
subsidiarypending
web.com
subsidiarypending

+1 more partners

2025-06-14T20:41:28.787Z
ctdems.org favicon

Connecticut Democratic Party

ctdems.org

59
GovernmentUnited StatesmediumMEDIUM

The Connecticut Democratic Party website serves as the official online presence for the state-level Democratic Party organization. It focuses on voter engagement, volunteer recruitment, fundraising, and disseminating party information. The site targets Connecticut residents interested in Democratic politics and activism, providing resources such as voter registration links, event calendars, and donation portals. The party positions itself as a key political actor within the state, aiming to mobilize support and fight GOP extremism. Technically, the website is built on WordPress with a modern but somewhat heavy tech stack including jQuery, DataTables, and Google services. However, performance is slow with a large page size and long load times. Security posture is weak due to the absence of a valid SSL certificate, lack of HTTPS, and missing security headers, exposing users to potential risks. Privacy compliance is minimal with no cookie consent mechanism despite tracking scripts. Contact information and social media presence are clearly provided, enhancing business credibility. Overall, the site is functional and content-rich but requires urgent security and privacy improvements to protect users and enhance trust.

15
43
25
70
100
80
100
politicaldemocraticpartyconnecticutactivismvoterregistration+1 more
WordPressjQueryDataTablesGoogle Fonts+4

Partner Domains:

ct.gov
partnerpending
mobilize.us
partner60
2025-06-14T20:34:07.578Z
forgood.org favicon

For Good

forgood.org

70
Non-profitUnited StatesmediumMEDIUM

For Good is a well-established 501(c)(3) non-profit organization operating a technology-enabled donor-advised fund platform that facilitates charitable giving for individuals and companies. Founded in 2001 by tech executives from AOL, Yahoo!, and Cisco, it has positioned itself as a leader in digital philanthropic innovation, partnering with major platforms such as YouTube, Walmart, and Patagonia. The website clearly communicates its mission, services, and impact, targeting donors, nonprofits, and corporate partners. The business model centers on enabling donors to support charities efficiently and transparently through a secure online platform. Technically, the website is built on Webflow CMS, leveraging modern web technologies and hosting infrastructure with CDN support. It employs Google Tag Manager and Analytics for tracking and performance monitoring. The site is mobile-optimized and accessible, with good SEO practices and a moderate page load time. Security-wise, the site uses HTTPS with TLS 1.3 and 1.2, has valid SPF and DMARC records, and avoids known SSL vulnerabilities. However, it lacks some advanced security features such as HSTS, DNSSEC, OCSP stapling, and Certificate Transparency compliance, which are recommended for enhanced protection. Privacy compliance is partially addressed with a comprehensive privacy policy and terms of service, but no explicit cookie consent mechanism was detected, which may impact GDPR compliance. Contact information is clearly provided, including email, phone, and physical address, along with active social media profiles, enhancing business credibility and trustworthiness. Overall, the site demonstrates a strong professional presence with room for security and privacy improvements.

60
43
25
75
77
80
100
non-profitdonor-advisedfundphilanthropycharitygivingplatform+1 more
WebflowGoogle Tag ManagerGoogle AnalyticsMandrill (email)+3

Partner Domains:

ppe-hosted.com
partnerpending
zendesk.com
partner71

+1 more partners

2025-06-14T20:31:13.081Z
B

Bonterra LLC

donortrends.com

64
Non-profitUnited StateslargeMEDIUM

Bonterra LLC is a leading provider of nonprofit software solutions designed to empower social impact organizations including foundations, corporations, government agencies, and nonprofits. Their product suite covers fundraising, case management, corporate social responsibility, grant management, and volunteer management, positioning them as the second-largest social good software company globally. The website reflects a mature digital presence with strong branding, comprehensive content, and clear navigation targeting a broad social good ecosystem. Technically, the site is built on WordPress with modern JavaScript frameworks like React and uses various marketing and analytics tools such as Google Tag Manager and Marketo. However, performance is currently slow, and there is room for optimization. Accessibility and SEO practices are well implemented, supporting a good user experience. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability impacting trust and data protection. While SPF, DMARC, and HSTS headers are configured, the absence of HTTPS severely undermines the security posture. Privacy compliance is strong with clear privacy and cookie policies and consent mechanisms. Overall, Bonterra's website is professional and content-rich but requires urgent security improvements to protect user data and maintain trust. Strategic recommendations include immediate SSL deployment, enabling TLS 1.2/1.3, and enhancing security configurations to align with best practices.

80
43
25
60
97
80
100
nonprofitsoftwaresocialimpactfundraisingcasemanagement+3 more
ReactGSAPSplide.jsMax Mega Menu+4

Partner Domains:

etosoftware.com
partner51
cybergrants.com
partner61

+3 more partners

2025-06-14T20:31:11.416Z
S

Streets For All

sfareportcard.com

55
TransportationUnited StatessmallMEDIUM

Streets For All operates as a focused non-profit advocacy organization dedicated to advancing sustainable and equitable transportation policies in California. Their website serves as a comprehensive platform to assess and report on the performance of state legislators regarding transportation legislation, providing transparency and accountability to the public and stakeholders. The organization positions itself as a key influencer in California's transportation policy landscape, emphasizing legislative sponsorship, support, and public engagement. Technically, the website employs modern web technologies including React and Material-UI, hosted on DigitalOcean infrastructure. While the site offers rich content and a professional design, performance issues such as slow load times and lack of some security headers are noted. The site uses Umami for privacy-focused analytics, indicating a moderate approach to user tracking. From a security perspective, the site benefits from a valid SSL certificate but lacks advanced security headers and DNS protections like DNSSEC and DMARC. Privacy compliance is weak due to the absence of privacy and cookie policies and no visible consent mechanisms. Contact information is limited to an email address, with no phone or physical address provided. Overall, the website is a credible and professional resource for transportation policy advocacy but would benefit from enhanced security practices and privacy compliance to strengthen trust and protect users. Performance optimizations and clearer privacy disclosures are recommended to improve user experience and regulatory adherence.

15
40
25
50
52
75
100
transportationcaliforniamobilitylegislationadvocacy+2 more
Material-UI (Mui components)Typekit fontsCloud Umami analyticsReact+1
2025-06-14T20:26:37.347Z
B

Bonterra

cybergrants.com

61
Non-profitUnited StateslargeMEDIUM

Bonterra is a purpose-built software company specializing in corporate social responsibility (CSR) solutions that empower organizations to enhance their philanthropic programs. Founded in 2021, Bonterra has quickly established itself as the second-largest social good software company globally, serving nonprofits, foundations, corporations, and government entities. Their key offerings include grant management, employee engagement, volunteer management, and fundraising software, all designed to maximize social impact and streamline administrative workflows. Technically, the website is built on a WordPress CMS platform with a modern tech stack including React, Bootstrap, and GSAP for animations. The site integrates multiple marketing and analytics tools such as Marketo, Microsoft Clarity, Facebook Pixel, and Google Tag Manager, reflecting a mature digital marketing strategy. However, performance is currently slow, and while mobile optimization and accessibility are good, there is room for improvement in loading speed. From a security perspective, the site lacks a valid SSL certificate and does not enforce HTTPS, which is a critical vulnerability. Other security best practices like HSTS, OCSP stapling, and modern TLS protocols are missing, significantly lowering the security posture. Privacy and cookie policies are present and include consent mechanisms, indicating good privacy compliance. Contact information is limited to a physical address without explicit phone or email contacts publicly visible. Overall, Bonterra's website demonstrates strong business credibility and content quality but requires urgent security improvements to protect user data and enhance trust. Strategic recommendations include obtaining a valid SSL certificate, enabling HTTPS and modern TLS protocols, and implementing additional security headers and mechanisms to improve the security score and user confidence.

80
43
25
85
50
85
100
csrgrantmanagementemployeeengagementnonprofitsoftwaresocialgood+2 more
ReactWordPressBootstrapGSAP+9

Partner Domains:

etosoftware.com
partnerpending
etosoftwareau.com
partnerpending

+3 more partners

2025-06-14T20:25:31.791Z
B

Bonterra LLC

networkforgood.org

57
Non-profitUnited StateslargeMEDIUM

Bonterra LLC operates Network for Good, a leading fundraising software platform tailored for small to medium-sized nonprofits. The company has a strong market position as the second-largest social good software provider globally, offering a comprehensive suite of tools including donor and volunteer management, peer-to-peer fundraising, and coaching services. Bonterra's business model focuses on SaaS solutions for nonprofit organizations, foundations, corporations, and government entities, supported by a robust ecosystem of subsidiaries and partner products. The website content is professionally crafted, targeting nonprofit organizations seeking efficient fundraising and engagement solutions. Technically, the website is built on WordPress hosted on WP Engine with Cloudflare CDN, utilizing modern JavaScript frameworks like React and libraries such as GSAP and Splide.js for UI enhancements. SEO and accessibility are well implemented, with extensive use of structured data and meta tags. However, performance metrics are not explicitly provided, though mobile optimization and user experience appear strong. From a security perspective, while the site employs several security headers and policies, it suffers from a critical issue: the SSL certificate is invalid or missing, and no modern TLS protocols are enabled. This severely impacts the security posture and user trust. Other security best practices like CSP and permissions policies are in place, but the lack of proper SSL/TLS undermines these efforts. Overall, the site is content-rich, professionally designed, and business credible but requires urgent remediation of SSL/TLS issues to ensure secure user interactions and compliance with modern security standards.

80
43
25
60
50
80
100
nonprofitfundraisingsoftwaredonormanagementvolunteermanagement+2 more
ReactWordPressBootstrapGSAP+6

Partner Domains:

bonterratech.com
parentpending
forgood.org
subsidiarypending

+3 more partners

2025-06-14T20:25:31.731Z
rollworks.com favicon

RollWorks

rollworks.com

58
TechnologyUnited StatesenterpriseMEDIUM

RollWorks is a B2B marketing technology company specializing in account-based marketing (ABM) and account-based advertising solutions. Positioned as a leading ABM platform, RollWorks offers AI-driven targeting and engagement tools designed to help marketers grow revenue by focusing on high-value accounts. The company operates as a division of NextRoll, Inc., serving primarily enterprise clients in the technology and business services sectors. Their platform integrates multiple marketing and analytics technologies, including Marketo, Google Tag Manager, and AdRoll, to provide comprehensive marketing automation and measurement capabilities. Technically, the website is built on WordPress with Elementor and Yoast SEO plugins, hosted behind Cloudflare CDN. The site demonstrates good SEO optimization, mobile responsiveness, and professional design quality. However, the SSL/TLS configuration is currently invalid or missing, which is a critical security vulnerability that undermines user trust and data protection. The site uses multiple third-party marketing and tracking tools, indicating extensive user tracking and data collection practices. From a security perspective, while some best practices like SPF and DMARC email policies are in place, the lack of a valid SSL certificate and disabled TLS protocols represent significant risks. The site also lacks advanced security headers and mechanisms such as OCSP stapling and session resumption. Privacy policies and terms of service are hosted on the parent company domain, and while privacy compliance is generally good, no explicit cookie consent mechanism was detected on the homepage. Overall, RollWorks presents a professional and trustworthy business front with strong market positioning and comprehensive marketing solutions. However, the critical SSL/TLS issues must be addressed immediately to ensure secure communications and maintain compliance with industry standards. Strategic improvements in security posture and privacy transparency will enhance trust and reduce risk exposure.

25
25
25
50
100
85
100
account-basedmarketingb2bmarketingabmplatformadvertisingmarketingtechnology
WordPressYoast SEOElementorjQuery+8

Partner Domains:

nextroll.com
parentpending
adroll.com
partner68

+1 more partners

2025-06-14T20:23:26.531Z
A

Asian Pacific Islander Forward Movement

apifm.org

53
Non-profitUnited StatesmediumMEDIUM

Asian Pacific Islander Forward Movement (APIFM) is a non-profit organization dedicated to cultivating healthy and vibrant Asian and Pacific Islander communities through engagement, education, and advocacy. The organization operates various community programs including food security initiatives, youth advocacy, and environmental sustainability projects. APIFM maintains an active digital presence with integrated social media feeds and regularly updated blog content, positioning itself as a community-centric entity within the non-profit sector in the United States. Technically, the website is built on WordPress with Elementor and several plugins for social media integration. Hosting is provided by DreamHost. While the site has good SEO metadata and structured data, performance metrics are lacking, and the site exhibits slow loading characteristics. Mobile optimization is good, but accessibility features are basic. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability exposing users to potential data interception. Security headers are minimal, and no incident response or security policies are published. Privacy compliance is limited, with no cookie consent mechanism detected and only a basic privacy policy present. Overall, APIFM's website serves its community well in content and engagement but requires urgent improvements in security infrastructure and privacy compliance to protect users and enhance trustworthiness.

15
43
25
50
100
85
75
non-profitcommunityasianpacificislanderenvironmentadvocacy+1 more
WordPress 6.8.1Elementor 3.28.4Elementor ProjQuery 3.7.1+7
2025-06-14T20:04:24.351Z
I

Investing in Place

investinginplace.org

49
GovernmentUnited StatessmallHIGH

Investing in Place is a small non-profit organization focused on leveraging public spaces in Los Angeles to improve quality of life for residents. The organization acts as an independent voice in local politics, advocating for better budgeting and planning of sidewalks, streets, and public spaces. Their key services include policy advocacy, public engagement, and research reporting. The website reflects a professional and consistent brand with clear messaging targeted at local stakeholders and community members. Technically, the website is built on WordPress using Elementor and WooCommerce plugins, hosted by DreamHost. While the site has a good design and user experience, it suffers from slow performance and lacks advanced SEO and accessibility features. The absence of a valid SSL certificate and modern TLS protocols is a significant security concern, exposing users to risks and undermining trust. Security posture is weak due to missing HTTPS, lack of security headers, and no evident privacy or cookie policies. Analytics are implemented via Google Analytics and Jetpack, but privacy compliance is poor with no GDPR indicators. Contact information is limited to an email address and a contact form, with no phone or physical address provided. Overall, the site is functional and informative but requires urgent improvements in security and privacy compliance to enhance trustworthiness and protect user data.

15
25
25
50
100
85
75
non-profitadvocacyurbanplanninglosangelespublicspace+3 more
WordPressWooCommerceElementorJetpack+4
2025-06-14T20:04:23.663Z
eurasiagroup.net favicon

Eurasia Group

eurasiagroup.net

64
MediaUnited StateslargeMEDIUM

Eurasia Group is a prominent global political risk consultancy headquartered in the United States with additional offices in Washington and London. The company specializes in providing political risk advisory, management consulting, thought leadership, speaking engagements, and event services to businesses and organizations navigating geopolitical uncertainties. Their market position is that of an established leader in the political risk and geopolitical analysis sector, supported by a strong digital presence and client engagement platforms. Technically, the website is built on a modern ASP.NET framework with extensive use of JavaScript libraries such as jQuery and UI components, hosted behind Cloudflare for performance and security. The site demonstrates good mobile optimization, fast loading times, and solid SEO practices. Integration with marketing and analytics tools like MailChimp, Hotjar, Facebook Pixel, and Twitter tracking indicates a mature digital marketing strategy. From a security perspective, the site employs HTTPS with TLS 1.3 and 1.2, uses secure and HttpOnly cookies, and has OCSP stapling enabled. However, it lacks some advanced security headers such as HSTS and Content-Security-Policy, which are recommended for enhanced protection. The site has well-defined privacy and cookie policies with consent mechanisms, indicating good privacy compliance. No critical vulnerabilities or exposed sensitive data were detected. Overall, Eurasia Group's website reflects a professional, secure, and privacy-conscious digital presence aligned with its business objectives. Strategic improvements in security headers and incident response transparency could further strengthen its security posture and trustworthiness.

15
58
25
50
62
85
100
politicalriskconsultinggeopoliticsmedianewsletter+2 more
ASP.NETjQueryjQuery UITypekit+8
2025-06-14T19:50:48.323Z