Skip to main content

United States security reports

Browse 10,659 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155884
Websites
130
Industries
113
Countries
52
Avg Score
Page 4 of 214|Showing 151-200 of 10659
aplu.org favicon

Association of Public and Land-grant Universities (APLU)

aplu.org

59
EducationUnited StateslargeMEDIUM

The Association of Public and Land-grant Universities (APLU) is a well-established non-profit organization dedicated to advancing public higher education in North America. The website serves as a comprehensive platform for public and land-grant university leaders, offering advocacy, collaborative initiatives, research promotion, and community engagement resources. The organization has a strong market position as the oldest higher education association in North America, with a clear focus on policy, student success, and innovation. Technically, the website is built on WordPress with modern plugins and libraries such as Yoast SEO, jQuery, and Kadence Blocks, ensuring good SEO, accessibility, and mobile responsiveness. The site loads with moderate performance and includes multimedia content such as videos and image sliders, enhancing user engagement. From a security perspective, the site enforces HTTPS with strong security headers and no visible vulnerabilities or exposed sensitive data. However, it lacks a visible cookie consent mechanism and a dedicated terms of service page, which are recommended for full privacy compliance. The WHOIS data is unavailable due to privacy protection, which is common for non-profits but limits domain registration transparency. Overall, the website is professional, trustworthy, and well-maintained, with minor improvements recommended in privacy compliance and legal disclosures to enhance user trust and regulatory adherence.

39
70
100
80
53
30
17
educationpublicuniversitiesland-grantuniversitieshighereducationnon-profit+3 more
WordPressYoast SEO pluginjQueryKadence Blocks+3
2026-07-11T07:22:21.697Z
N

Newark Public Library

npl.org

57
GovernmentUnited StatesmediumMEDIUM

The Newark Public Library website serves as a comprehensive digital portal for the Newark community, offering access to a wide range of library services including book lending, digital collections, educational programs, and community resources. The site is well-positioned as a key public institution in Newark, New Jersey, targeting a broad audience including students, researchers, and general community members. The business model is typical of a public library, relying on public funding and donations to support its operations and services. Technically, the website is built on WordPress and leverages modern web technologies such as JavaScript, Google Analytics, HubSpot, and Facebook Pixel for analytics and marketing. The site demonstrates good SEO practices, mobile optimization, and basic accessibility features, although there is room for improvement in security headers and accessibility compliance. Performance is moderate, with asynchronous loading of scripts to enhance user experience. From a security perspective, the site enforces HTTPS and uses some security best practices but lacks several important HTTP security headers such as Content-Security-Policy, X-Frame-Options, and X-Content-Type-Options, which could expose it to certain web-based attacks. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is basic, with a privacy policy and cookie consent mechanism present, though GDPR compliance indicators are limited. Overall, the website is trustworthy and professional, with no signs of malicious activity or suspicious content. The WHOIS data is unavailable or privacy protected, which is common for public institutions and does not detract from the site's legitimacy. Strategic recommendations include enhancing security headers, improving accessibility compliance, and maintaining transparency in privacy practices to further strengthen trust and security posture.

100
50
85
47
2
40
50
libraryeducationcommunitypublicservicenon-profit+3 more
WordPressPHPJavaScriptGoogle Analytics+4
2026-07-11T07:22:16.164Z
A

American Educational Research Association

aera.net

69
EducationUnited StateslargeMEDIUM

The American Educational Research Association (AERA) is a well-established professional organization focused on advancing educational research and its practical application. Founded in 1916, it serves a large international membership of over 25,000 education professionals, researchers, and students. The website reflects a mature digital presence with comprehensive content about events, publications, policy advocacy, and professional development. The organization positions itself as a leader in the education research sector with a strong emphasis on scholarly inquiry and dissemination of research findings. Technically, the website is built on the DNN CMS platform with the NOAH framework and uses a variety of modern web technologies including Bootstrap, jQuery, Font Awesome, and multiple analytics and tracking tools such as Google Analytics and Facebook Pixel. The site is mobile-optimized and provides a good user experience with clear navigation and professional design. However, some technical improvements are recommended, including the implementation of security headers and cookie consent mechanisms to enhance privacy compliance. From a security perspective, the site uses HTTPS and secure form submissions but lacks visible security headers and published security policies or incident response information. The absence of WHOIS data for the domain is a notable anomaly that slightly reduces trust but does not undermine the overall legitimacy given the professional content and branding. No critical vulnerabilities or adult content were detected, and the site is accessible without WAF or blocking mechanisms. Overall, the site demonstrates a strong business credibility and a good security posture with room for improvement in privacy compliance and technical security best practices. Strategic recommendations include enhancing security headers, publishing security and incident response policies, and implementing GDPR-compliant cookie consent to strengthen trust and compli…

100
80
85
72
55
65
17
educationresearchprofessionalassociationconferencemembership+2 more
JavaScriptjQueryBootstrapFont Awesome+5
2026-07-11T07:21:53.821Z
T

Transportation Security Administration

tsa.gov

57
GovernmentUnited StatesenterpriseMEDIUM

The website www.tsa.gov represents the Transportation Security Administration, a U.S. government agency responsible for transportation security. However, the website content is currently inaccessible due to a Web Application Firewall or security mechanism blocking access, resulting in an 'Access Denied' page. This prevents any direct analysis of the site's content, metadata, or technical infrastructure. The domain WHOIS data is incomplete, lacking registrar, creation, and nameserver information, which is unusual but may be due to registry restrictions for government domains. Technically, no information about the technology stack, hosting, or security headers could be obtained. The lack of accessible content also means no privacy, cookie, or security policies could be reviewed. From a security perspective, the site appears to have strong perimeter defenses (WAF), but the inability to access content limits assessment of internal security posture or compliance. Overall, the site is a critical government resource with an enterprise-level scope. The blocking of content impacts the ability to evaluate its digital maturity and security posture fully. Strategic recommendations include ensuring authorized access for security assessments, publishing clear privacy and security policies, and improving transparency of WHOIS data where possible.

82
85
70
100
30
50
17
governmentsecuritytransportationtsablocked
2026-07-11T07:21:31.662Z
A

American Academy of Orthopaedic Surgeons

aaos.org

65
HealthcareUnited StateslargeMEDIUM

The American Academy of Orthopaedic Surgeons (AAOS) is a leading professional association dedicated to advancing orthopaedic education, advocacy, and patient care. Their website serves as a comprehensive resource hub for orthopaedic surgeons, allied health professionals, and the public, offering educational programs, clinical guidelines, publications, and advocacy tools. The organization holds a strong market position as an authoritative source in musculoskeletal care and orthopaedics, supported by a large membership base and corporate partnerships. Technically, the website employs a modern technology stack including Google Analytics, Microsoft Application Insights, Marketo, HubSpot, and various marketing and tracking tools, integrated with responsive design frameworks to ensure good performance and accessibility. The site demonstrates good SEO practices and mobile optimization, with a professional and consistent branding approach. From a security perspective, the site enforces HTTPS and uses multiple security best practices, though explicit security headers and a dedicated security policy page are absent. Privacy compliance is well addressed with clear privacy and cookie policies, including GDPR compliance and consent mechanisms. The WHOIS data is privacy protected, which is typical for organizations of this nature, and does not raise legitimacy concerns. Overall, the AAOS website presents a low-risk profile with strong business credibility and technical maturity. Strategic recommendations include enhancing security header implementation, publishing a security policy and incident response information, and establishing a vulnerability disclosure program to further strengthen trust and compliance.

-
85
100
80
-
85
17
healthcareorthopaedicseducationprofessionalassociationmedical+1 more
Google AnalyticsGoogle Tag ManagerMicrosoft Application InsightsMarketo+8

Partner Domains:

ams.aaos.org
partner
registryapps.net
partner

+1 more partners

2026-07-11T07:21:20.533Z
mmwr.com favicon

Montgomery McCracken Walker & Rhoads LLP

mmwr.com

68
OtherUnited StatesmediumMEDIUM

Montgomery McCracken Walker & Rhoads LLP is a regional law firm serving clients primarily in Pennsylvania, New York, New Jersey, and Delaware. The firm offers a multidisciplinary approach with key legal services including bankruptcy, business litigation, intellectual property, labor and employment, and general litigation. The website positions the firm as a trusted advisor with recognized attorneys, including 24 lawyers named in Best Lawyers in America 2026. The target audience includes businesses and individuals seeking legal counsel in the firm's geographic focus areas. Technically, the website is built on WordPress with a modern plugin ecosystem, including SEO frameworks, live search, event calendars, and marketing integrations. The site is mobile optimized, accessible, and SEO friendly, with good performance metrics. Security posture is solid with HTTPS enforced and reCAPTCHA implemented on forms, though it lacks some security headers and published security policies. Privacy compliance is well addressed with a clear privacy policy and cookie consent mechanism. However, the WHOIS data for the domain is missing or not found, which raises concerns about domain registration legitimacy. Overall, the website is professional and trustworthy in appearance but would benefit from improved transparency on domain registration and enhanced security headers.

37
100
75
75
70
47
68
lawfirmlegalservicesprofessionalserviceswordpresscompliance+2 more
WordPressPHPjQueryGoogle reCAPTCHA v3+7
2026-07-11T07:20:23.871Z
genesys.com favicon

Genesys

genesys.com

78
TechnologyUnited StatesenterpriseLOW

Genesys is a leading enterprise technology company specializing in omnichannel customer experience and contact center solutions. Trusted by over 10,000 companies worldwide, Genesys offers AI-powered cloud-based platforms designed to enhance customer engagement and operational efficiency. The company positions itself as a market leader with a comprehensive suite of services tailored for large organizations seeking advanced customer experience management. The website reflects a mature digital presence with professional branding and clear communication of its offerings. Technically, the website employs modern web technologies including Bootstrap 5, jQuery, and personalization tools like Intellimize. It is built on WordPress CMS and leverages CDNs for performance optimization. The site demonstrates excellent mobile responsiveness, accessibility, and SEO practices, indicating a high level of digital maturity and user experience focus. From a security perspective, Genesys maintains strong practices including HTTPS enforcement, comprehensive security headers, and adherence to recognized frameworks such as ISO 27001 and SOC 2. The presence of detailed privacy, cookie, and security policies, along with incident response contacts, underscores a robust security posture. No significant vulnerabilities or exposed sensitive data were detected. Overall, Genesys presents a low-risk profile with a professional and trustworthy online presence. The only notable gap is the absence of publicly available WHOIS registration data, which may be due to privacy protection but does not detract from the company's legitimacy given its enterprise stature and compliance indicators.

77
85
100
82
60
47
85
customerexperiencecontactcenteraicloudenterprisesoftware+1 more
JavaScriptBootstrap 5jQueryIntellimize (A/B testing and personalization)+1
2026-07-11T07:14:59.060Z
stannswarehouse.org favicon

St. Ann's Warehouse

stannswarehouse.org

58
OtherUnited StatesmediumMEDIUM

St. Ann's Warehouse is a well-established cultural arts organization based in Brooklyn, New York, specializing in theater productions and cultural events. The website reflects a medium-sized non-profit entity with a strong market position in the arts and culture sector. Their services include theater shows, membership programs, and facility rentals, targeting a general audience interested in performing arts. The domain has been registered since 2003, consistent with the organization's history and credibility. Technically, the website is built on WordPress with a modern tech stack including jQuery, Google Analytics, Facebook and TikTok pixels, and uses Cloudflare for DNS management. The site is mobile optimized and has good SEO practices, though performance is moderate. The presence of multiple marketing and tracking tools indicates a mature digital marketing approach but raises privacy compliance concerns. Security posture is adequate with HTTPS enabled and domain registration protections in place; however, the lack of DNSSEC, security headers, and published security policies indicates room for improvement. No critical vulnerabilities were detected, but privacy compliance is weak due to missing privacy and cookie policies. Overall, the website is professional and trustworthy but should enhance privacy compliance and security best practices to reduce risk and improve user trust.

32
75
80
100
65
35
2
theaterartsculturenon-profitevents+1 more
WordPressjQueryGoogle AnalyticsGoogle Tag Manager+5
2026-07-11T07:13:02.388Z
uks.com favicon

Updike, Kelly & Spellacy, P.C.

uks.com

52
OtherUnited StatesmediumMEDIUM

Updike, Kelly & Spellacy, P.C. is a well-established Connecticut law firm with a strong regional presence and affiliations that extend its reach nationally and internationally. The firm offers a broad range of legal services including business and corporate law, litigation, real estate, technology, and governmental affairs. Their website reflects a professional and client-focused approach, targeting businesses and individuals seeking legal expertise in Connecticut and beyond. Technically, the website employs a modern technology stack including Bootstrap, jQuery, and Google Analytics, ensuring a responsive and user-friendly experience. While performance is moderate and mobile optimization is good, there is room for improvement in accessibility and security headers implementation. The site uses asynchronous loading for analytics and marketing scripts, indicating a focus on performance and tracking. From a security perspective, the site uses HTTPS and integrates standard analytics and marketing tools but lacks visible security headers and cookie consent mechanisms, which are important for compliance and protection. The absence of WHOIS data for the domain is a notable concern, potentially impacting trustworthiness. No explicit security policies or incident response contacts are provided, which could be improved to enhance transparency and readiness. Overall, the website is professional and credible but would benefit from enhanced privacy compliance, security best practices, and domain registration transparency to strengthen its security posture and user trust.

80
40
70
67
17
53
15
lawfirmconnecticutlegalservicesbusinesslawlitigation+1 more
jQuery 2.2.2Modernizr 2.8.3Bootstrap CSS and JSFont Awesome 4.3.0+5

Partner Domains:

meritas.org
partner
2026-07-11T07:09:48.267Z
gkff.org favicon

George Kaiser Family Foundation

gkff.org

59
Non-profitUnited StateslargeMEDIUM

The George Kaiser Family Foundation (GKFF) is a well-established philanthropic organization focused on empowering children through education, strengthening family well-being, and revitalizing neighborhoods primarily in Tulsa, Oklahoma. The foundation operates multiple community programs targeting early childhood development, community well-being and justice, city vibrancy, and strong neighborhoods. Their website reflects a professional and consistent brand presence with comprehensive content aimed at community members, partners, and prospective grantees. Technically, the website is built on the Webflow platform, leveraging modern web technologies including Google Fonts, Google Analytics, and Finsweet attributes for enhanced user experience. The site is mobile-optimized, fast-loading, and accessible, with good SEO practices. However, some security best practices such as security headers and explicit incident response information are missing. From a security perspective, the site uses HTTPS with an excellent SSL configuration and does not expose sensitive data. There is no evidence of vulnerabilities or malicious content. Privacy compliance is generally good with a clear privacy policy and terms of use, though a cookie consent mechanism is absent. WHOIS data is unavailable due to privacy protection, which is typical and justified for a non-profit entity. Overall, the website demonstrates a strong security posture and business credibility with minor areas for improvement in privacy compliance and security transparency. The risk level is low, and the site is trustworthy for its intended audience.

70
85
49
100
2
53
30
philanthropycommunitydevelopmenteducationnon-profittulsa+1 more
Webflow CMSGoogle FontsGoogle Analytics (gtag.js)Finsweet Attributes (richtext, cmsslider)+1
2026-07-11T07:09:15.020Z
postschell.com favicon

Post & Schell, P.C.

postschell.com

61
OtherUnited StateslargeMEDIUM

Post & Schell, P.C. is a well-established law firm providing legal services and strategic counseling primarily to highly regulated industries and their stakeholders across the United States. The firm operates multiple offices in key regional locations including Pennsylvania, New Jersey, Delaware, West Virginia, and Washington, DC. Their core services include litigation, regulatory compliance, business and transactional law, and dispute resolution. The website reflects a mature and professional business with a strong market position and a broad sector focus including energy, healthcare, insurance, financial services, and government sectors. Technically, the website is built on modern web technologies such as Bootstrap, jQuery, and Owl Carousel, ensuring a responsive and accessible user experience. The site is well-structured with comprehensive metadata, Open Graph tags, and JSON-LD structured data that enhance SEO and social media integration. The presence of SOC 2 Type II certification indicates a commitment to information security standards. However, some security headers are missing, and there is no explicit cookie consent mechanism, which could be improved for enhanced privacy compliance. From a security perspective, the site uses HTTPS and secure form practices, but lacks visible security policy or incident response contact information. The WHOIS data for the domain is not publicly available, which raises some questions about domain registration transparency, but the professional content and external trust signals mitigate concerns. Overall, the website demonstrates a strong security posture with room for improvement in privacy and security policy disclosures. Strategically, the firm should focus on enhancing privacy compliance by implementing cookie consent banners and publishing clear security and incident response policies. Improving WHOIS transparency or clarifying domain registration details would also strengthen trust. The website’s design, content qua…

75
55
57
100
15
53
47
legallawfirmattorneysregulatorycompliancelitigation+4 more
Bootstrap 4.3.1jQuery 3.4.1Popper.jsOwl Carousel 2+2
2026-07-11T07:08:47.299Z
vassar.edu favicon

Vassar College

vassar.edu

69
EducationUnited StatesmediumMEDIUM

Vassar College is a well-established liberal arts college in the Northeastern United States, offering a broad range of academic programs and a vibrant campus life. The website reflects a professional and comprehensive digital presence, targeting prospective and current students, families, alumni, and employees. The institution positions itself as a top liberal arts college with a strong emphasis on academic rigor and community engagement. Technically, the website is built on Drupal 11 with modern web technologies including Google Tag Manager for analytics and Monsido for heatmaps. The site is mobile-optimized, accessible, and SEO-friendly, providing a positive user experience. The use of HTTPS and cookie consent mechanisms indicates attention to security and privacy compliance. Security posture is solid with HTTPS and no visible vulnerabilities, though the site could improve by adding explicit security headers and publishing a security policy or incident response contacts. The absence of WHOIS data is typical for .edu domains and does not detract from the legitimacy of the institution. Overall, the website demonstrates a mature digital infrastructure suitable for an educational institution. Recommendations include enhancing security headers, publishing a vulnerability disclosure policy, and providing clearer contact information for security incidents to strengthen trust and compliance further.

67
70
100
80
40
25
83
educationliberalartscollegeuniversityhighereducation+3 more
Drupal 11Google Tag ManagerMonsido heatmapsVimeo Player+1
2026-07-11T07:08:30.571Z
idacorpinc.com favicon

IDACORP, Inc.

idacorpinc.com

68
EnergyUnited StateslargeMEDIUM

IDACORP, Inc. operates as a large, established energy company primarily through its fully integrated electric utility, Idaho Power Company. Founded in 1916, the company focuses on providing reliable, affordable, and clean hydropower energy to a broad customer base. The website emphasizes investor relations, corporate responsibility, and a long-term strategy toward 100% clean energy by 2045. The company maintains a strong market position with NYSE listing and transparent financial reporting. The target audience includes investors, shareholders, customers, and the general public interested in energy services. Technically, the website is built on an ASP.NET WebForms platform with integration of Q4 Inc. investor relations tools and Google services such as reCAPTCHA and fonts. The site demonstrates good mobile optimization, accessibility, and SEO practices, although performance is moderate. Security measures include HTTPS enforcement, anti-CSRF tokens, and invisible reCAPTCHA on forms, but could be improved with additional security headers and published security policies. Security posture is solid with no visible vulnerabilities or exposed sensitive data. Privacy compliance is supported by a comprehensive privacy policy and cookie consent mechanisms, though a dedicated cookie policy page is not explicitly found. The absence of WHOIS data for the domain is a notable anomaly, potentially indicating privacy protection or data source issues, but the website content and branding strongly indicate legitimacy. Overall, the website is professional, trustworthy, and well-maintained, serving its business and investor communication needs effectively. Strategic recommendations include enhancing security headers, publishing incident response contacts, and clarifying cookie policies to further strengthen compliance and trust.

100
85
70
57
17
68
65
energyinvestorrelationshydropowercorporateutilities+1 more
ASP.NET WebFormsjQueryGoogle reCAPTCHAQ4 Inc. widgets and APIs+1

Partner Domains:

www.idahopower.com
partner
2026-07-11T07:08:19.477Z
plasticsurgery.org favicon

American Society of Plastic Surgeons

plasticsurgery.org

61
HealthcareUnited StateslargeMEDIUM

The American Society of Plastic Surgeons (ASPS) operates a comprehensive and professionally designed website focused on educating patients and medical professionals about cosmetic and reconstructive plastic surgery. The site offers extensive resources including procedure information, before and after galleries, patient safety guides, and community engagement tools. ASPS holds a strong market position as a leading professional society in the healthcare sector, targeting both patients seeking plastic surgery and surgeons themselves. Technically, the website employs a modern technology stack including RequireJS, jQuery, Bootstrap, and various analytics and marketing tools such as Marketo, Facebook Pixel, and Microsoft Clarity. The site is mobile optimized, accessible, and SEO-friendly, delivering a good user experience with moderate performance. Security posture is solid with HTTPS enforced and no visible vulnerabilities, though security headers and explicit incident response policies could be improved. The WHOIS data is incomplete due to a malformed query, limiting domain registration verification. Despite this, the website's professional presentation, comprehensive content, and active social media presence strongly indicate legitimacy. Privacy and cookie policies are present with consent mechanisms, supporting GDPR compliance. Overall, the site is a trustworthy and authoritative resource in the plastic surgery domain, with recommendations to enhance security headers, incident response transparency, and WHOIS data availability to further strengthen trust and compliance.

67
75
75
100
68
15
2
plasticsurgerycosmeticsurgeryreconstructivesurgerymedicalsocietypatientsafety+1 more
RequireJSjQuery 1.12.4Bootstrap 3.3.7OwlCarousel 2.1.6+7

Partner Domains:

www.thepsf.org
partner
journals.lww.com
partner
2026-07-11T07:03:31.157Z
intrexon.com favicon

Precigen

intrexon.com

61
HealthcareUnited StatesmediumMEDIUM

Precigen is a commercial-stage biopharmaceutical company specializing in precision medicines targeting difficult-to-treat diseases with high unmet patient needs. The company has achieved FDA approval for its product PAPZIMEOS, positioning it as a significant player in the healthcare and biotechnology sector. The website reflects a professional and consistent brand image, targeting healthcare professionals, patients, and investors. The business model focuses on developing and commercializing innovative therapies with a clear pipeline and investor relations presence. Technically, the website is built on WordPress with common plugins such as Yoast SEO and jQuery libraries, hosted likely via GoDaddy infrastructure. The site is mobile optimized and performs moderately well, with good SEO practices implemented. Analytics are handled via Google Analytics, and cookie consent is managed through OneTrust, indicating a basic level of privacy compliance. From a security perspective, the site uses HTTPS and has implemented cookie consent mechanisms. However, there is no evidence of advanced security headers or published security policies, incident response contacts, or vulnerability disclosure mechanisms. The WHOIS data is transparent and consistent with the company's profile, enhancing trustworthiness. Overall, the security posture is adequate but could be improved with additional security best practices. The overall risk assessment is moderate with no critical issues detected. Strategic recommendations include enabling DNSSEC, publishing privacy and security policies, implementing security headers, and establishing clear incident response contacts to enhance compliance and trust.

85
85
100
47
15
17
58
biopharmaceuticalprecisionmedicinehealthcarefdaapprovedinvestors+2 more
WordPressjQueryYoast SEO pluginDataTables

Partner Domains:

papzimeos.com
partner
investors.precigen.com
related
2026-07-11T07:01:01.189Z
B

Blackstone Mortgage Trust

blackstonemortgagetrust.com

71
Real EstateUnited StateslargeMEDIUM

Blackstone Mortgage Trust (BXMT) is a publicly traded commercial mortgage REIT specializing in real estate credit investments across North America, Europe, and Australia. Managed by Blackstone Inc., the largest owner of commercial real estate globally, BXMT leverages significant data, resources, and a global platform to underwrite complex transactions and partner with leading sponsors. The website presents comprehensive investor information, financial disclosures, and market positioning that reflect a mature and professional business entity. Technically, the website is built on WordPress with modern SEO and accessibility practices, integrating advanced analytics and monitoring tools such as New Relic and Google Tag Manager. The site is well-optimized for performance and mobile responsiveness, with a clear navigation structure and consistent branding. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms compliant with GDPR. While explicit security policies and incident response contacts are not published, the use of monitoring tools and privacy policies indicates a reasonable security posture. The absence of WHOIS registration data is a concern but is mitigated by the strong brand presence and external references to Blackstone domains. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance suitable for its investor audience. Strategic recommendations include publishing explicit security policies, incident response contacts, and improving WHOIS transparency to enhance trust further.

70
32
85
100
80
17
100
realestatereitfinanceinvestorrelationsmortgagetrust+1 more
WordPressYoast SEOBrightcove video playerNew Relic monitoring+2

Partner Domains:

www.blackstone.com
parent
ir.blackstonemortgagetrust.com
subsidiary
2026-07-10T07:13:22.515Z
onegas.com favicon

ONE Gas

onegas.com

67
EnergyUnited StateslargeMEDIUM

ONE Gas is a large, publicly traded natural gas distribution company serving over 2.3 million customers across Kansas, Oklahoma, and Texas. It operates through three main divisions: Kansas Gas Service, Oklahoma Natural Gas, and Texas Gas Service. The company is headquartered in Tulsa, Oklahoma, and holds a strong market position as the largest natural gas distributor in Kansas and Oklahoma and the third largest in Texas. The website provides comprehensive investor relations, corporate governance, and customer service information, reflecting a mature and professional business presence. Technically, the website is built on ASP.NET WebForms with modern JavaScript libraries and integrates Google Analytics and OneTrust for privacy compliance. The site is mobile optimized, accessible, and uses HTTPS with a Content Security Policy, indicating a solid digital infrastructure. However, some security headers could be enhanced for improved protection. From a security perspective, the site demonstrates good practices including HTTPS enforcement and cookie consent mechanisms. No critical vulnerabilities or exposed sensitive data were detected. The absence of WHOIS data is a concern but likely due to privacy protection or technical reasons, not necessarily indicating malicious intent. Overall, the security posture is strong but could benefit from publishing incident response and vulnerability disclosure policies. The overall risk assessment is moderate to low, with the main recommendation being to improve transparency around domain registration and enhance security headers. The website is trustworthy, professionally maintained, and compliant with privacy regulations, making it a reliable source for customers and investors alike.

70
75
52
100
65
88
2
energynaturalgasinvestorscorporateutility+3 more
ASP.NET WebFormsjQuerySlick CarouselGoogle Analytics+2

Partner Domains:

kansasgasservice.com
subsidiary
oklahomanaturalgas.com
subsidiary

+2 more partners

2026-07-10T07:13:11.844Z
O

Owens Corning

owenscorning.com

68
ManufacturingUnited StatesenterpriseMEDIUM

Owens Corning is a leading global manufacturer specializing in roofing, insulation, composite materials, and doors. The company serves building professionals, contractors, and consumers with a broad portfolio of building and remodeling solutions. Their market position is strong, supported by comprehensive corporate governance, sustainability initiatives, and investor relations transparency. The website reflects a mature enterprise with consistent branding and professional content. Technically, the website employs modern web technologies including React, Adobe DTM for tag management, and Osano for consent management, indicating a high level of digital maturity. The site is mobile optimized, accessible, and SEO-friendly, with good performance metrics. Analytics and marketing tools are used responsibly with visible cookie consent mechanisms. From a security perspective, the site enforces HTTPS and uses cookie consent banners to comply with privacy regulations. While explicit security headers are not fully visible in the HTML, no vulnerabilities or exposed sensitive data were detected. The absence of a public security policy or vulnerability disclosure page is noted as an area for improvement. Overall, the website presents a low risk profile with strong business credibility and privacy compliance. The lack of WHOIS data slightly reduces trust but is mitigated by the professional presentation and extensive corporate information. Strategic recommendations include enhancing security header implementation, publishing a security policy, and establishing a vulnerability disclosure process.

72
85
100
80
70
17
53
roofinginsulationcompositesbuildingmaterialscorporate+3 more
Adobe DTMOsano Consent ManagementReactFontAwesome+3

Partner Domains:

newsroom.owenscorning.com
partner
investor.owenscorning.com
partner

+2 more partners

2026-07-10T07:13:01.164Z
naiop.org favicon

Commercial Real Estate Development Association

naiop.org

62
Real EstateUnited StateslargeMEDIUM

The Commercial Real Estate Development Association (CREDA) is a leading professional organization dedicated to advancing commercial real estate development across North America. The association provides a comprehensive suite of services including industry education, advocacy on legislative priorities, research publications, and networking opportunities through events and chapters. CREDA targets commercial real estate professionals such as developers, owners, investors, and industry stakeholders, positioning itself as a key resource and thought leader in the sector. Technically, the CREDA website is built on the EPiServer CMS platform and leverages modern web technologies including jQuery, Google Analytics, Microsoft Application Insights, and various UI libraries for a responsive and user-friendly experience. The site demonstrates good mobile optimization and SEO practices, although some accessibility features could be enhanced. Performance is moderate with room for optimization. From a security perspective, the website enforces HTTPS and employs CAPTCHA on forms to mitigate abuse. However, no explicit security headers were detected in the provided data, and there is no visible incident response or vulnerability disclosure information. Privacy compliance is well addressed with a comprehensive privacy policy, cookie consent mechanisms, and GDPR considerations. The WHOIS data is unavailable or privacy-protected, which is common for organizations of this nature. Overall, CREDA presents a professional, trustworthy, and content-rich online presence with a solid technical foundation. Strategic improvements in security headers, incident response transparency, and accessibility would further strengthen its security posture and user trust.

27
100
78
75
30
17
85
commercialrealestatedevelopmentassociationeducationadvocacy+2 more
EPiServer CMSjQueryGoogle AnalyticsMicrosoft Application Insights+4
2026-07-10T07:12:39.921Z
shelbyenergy.com favicon

Shelby Energy Cooperative

shelbyenergy.com

66
EnergyUnited StatesmediumMEDIUM

Shelby Energy Cooperative is a regional electric utility cooperative serving Shelbyville, Kentucky, and surrounding areas. The organization focuses on providing safe, reliable, and cost-effective energy solutions to its members, including residential and business customers. Key services include energy provision, account management via SmartHub, energy audits, renewable energy programs, and electric vehicle resources. The cooperative positions itself as a trusted community energy provider with a strong local presence and customer service focus. Technically, the website is built on the Drupal CMS platform, utilizing modern web technologies such as FontAwesome, Google Tag Manager, and GTranslate for multilingual support. The site demonstrates good mobile optimization, accessibility features, and SEO practices, although performance is moderate. The infrastructure appears stable and professionally maintained. From a security perspective, the website enforces HTTPS and avoids exposing sensitive data. However, it lacks several security headers and does not provide explicit security policies or incident response information. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism detected. The absence of WHOIS data reduces domain trustworthiness, though the website content and external partnerships suggest legitimacy. Overall, Shelby Energy Cooperative's digital presence is professional and functional, supporting its business objectives effectively. Strategic improvements in security headers, privacy compliance, and domain registration transparency would enhance trust and security posture.

80
62
100
70
85
53
2
energycooperativeutilityrenewableenergyelectricvehicles+1 more
Drupal CMSFontAwesomeGoogle Tag ManagerGoogle Analytics+3

Partner Domains:

shelbyenergy.smarthub.coop
partner
coopwebbuilder3.com
partner
2026-07-10T07:12:34.641Z
foulston.com favicon

Foulston Siefkin LLP

foulston.com

76
OtherUnited StateslargeLOW

Foulston Siefkin LLP is the largest Kansas-based law firm, providing a broad range of legal services including corporate and business law, healthcare law, litigation, and employment law. The firm targets businesses and individuals seeking professional legal counsel, positioning itself as a leading regional legal service provider with a strong market presence in Kansas and surrounding areas. Their website reflects a professional and comprehensive approach, featuring detailed practice areas, attorney search capabilities, and client testimonials, supporting their market leadership claims. Technically, the website employs modern web technologies such as jQuery, Bootstrap, Owl Carousel, and integrates Google Tag Manager and CookieYes for analytics and privacy compliance. The site is mobile-optimized, accessible, and SEO-friendly, with structured data enhancing search engine understanding. Performance is moderate, with room for optimization. From a security perspective, the site uses HTTPS and cookie consent mechanisms effectively, but lacks visible security headers and explicit security or incident response policies. No vulnerabilities or exposed sensitive data were detected in the provided content. The absence of WHOIS data is a notable anomaly that warrants further investigation to confirm domain registration legitimacy. Overall, the website presents a low-risk profile with strong business credibility and privacy compliance, though improvements in security policy transparency and domain registration verification are recommended to enhance trust and security posture.

47
80
80
100
47
83
90
lawfirmlegalservicescorporatelawhealthcarelawlitigation+3 more
jQueryBootstrap 4.3.1Owl CarouselCookieYes Consent Management+1
2026-07-10T07:12:29.296Z
dol.gov favicon

U.S. Department of Labor

dol.gov

67
GovernmentUnited StatesenterpriseMEDIUM

The U.S. Department of Labor (DOL) is a federal government agency dedicated to promoting the welfare of job seekers, wage earners, and retirees in the United States. The website serves as a comprehensive portal for labor laws, workplace safety, unemployment insurance, apprenticeship programs, and disaster recovery assistance. It targets American workers, employers, and government entities, providing authoritative resources and regulatory information. The DOL maintains a strong market position as a key government institution with enterprise-level scale and reach. Technically, the website is built on Drupal 10 CMS, leveraging modern web technologies including Google Analytics, Google Tag Manager, and various accessibility and performance tools. The site demonstrates good mobile optimization, accessibility, and SEO practices, with asynchronous loading of analytics scripts to enhance performance. The design is professional, consistent, and user-friendly, reflecting the agency's authoritative brand. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks explicit security headers and a public vulnerability disclosure policy. Privacy compliance is strong with a comprehensive privacy policy and GDPR considerations, though a cookie consent mechanism is not evident. The WHOIS data is privacy protected or unavailable, typical for .gov domains, but the domain legitimacy is high given the official .gov TLD and consistent branding. Overall, the DOL website is a secure, credible, and well-maintained government resource. Strategic recommendations include enhancing security headers, publishing vulnerability disclosure information, implementing cookie consent, and providing incident response contacts to further strengthen trust and compliance.

85
80
100
67
30
58
25
governmentlaboremploymentworkplacesafetyunemployment+2 more
Drupal 10Google AnalyticsGoogle Tag ManagerFontAwesome+3
2026-07-10T07:12:23.950Z
americancentury.com favicon

American Century Investments®

americancentury.com

71
FinanceUnited StateslargeMEDIUM

American Century Investments® is a well-established investment management firm focused on serving institutional investors, professional investors, and wholesale clients. The company provides investment planning, management, and advisory services, with a notable emphasis on funding life-changing medical research. The website reflects a professional and consistent brand image, targeting a specialized financial audience with clear legal disclaimers and compliance with international privacy regulations such as GDPR. Technically, the website employs modern web technologies including JavaScript frameworks like Svelte, jQuery, and Adobe's Dynamic Tag Management for analytics and marketing. The site is mobile-optimized, accessible, and SEO-friendly, with a cookie consent mechanism that aligns with privacy best practices. External integrations include trusted analytics and search services. From a security perspective, the site enforces HTTPS, implements key security headers, and avoids exposing sensitive data. However, it lacks publicly visible security policies, incident response contacts, or vulnerability disclosure mechanisms, which are recommended for organizations in the financial sector. The absence of WHOIS data is a minor concern but does not detract significantly from the site's legitimacy given the professional presentation. Overall, the website demonstrates a strong digital maturity and security posture appropriate for its industry and audience. Strategic recommendations include publishing explicit security and incident response policies, providing clear security contact channels, and adding vulnerability disclosure information to enhance transparency and trust.

85
100
93
37
17
88
65
investmentfinanceinstitutionalinvestorsfinancialservicescookieconsent+1 more
JavaScriptjQueryAdobe DTM (Dynamic Tag Management)OneTrust Cookie Consent+3
2026-07-10T07:11:57.380Z
mastec.com favicon

MasTec, Inc.

mastec.com

72
EnergyUnited StatesenterpriseMEDIUM

MasTec, Inc. is a leading specialty contractor focused on engineering, designing, and constructing infrastructure projects primarily in the energy and telecommunications sectors. With a workforce of nearly 22,000 professionals and over 80 years of experience, MasTec holds a strong market position as a top infrastructure construction company in the United States. Their key services span civil infrastructure, communications, data centers, EV infrastructure, pipeline infrastructure, power delivery and generation, technology deployment, and water and wastewater solutions. The website reflects a professional corporate presence with comprehensive investor relations and sustainability reporting. Technically, the website employs modern front-end technologies including Bootstrap, Leaflet, Font Awesome, and Google Fonts. The site is mobile-optimized, accessible, and SEO-friendly, though performance is moderate. Security-wise, the site uses HTTPS and script integrity attributes but lacks visible security headers and explicit security or incident response policies. No vulnerabilities or malicious content were detected in the provided data. The WHOIS data is unavailable or protected, which introduces some uncertainty about domain registration details. However, the website's corporate content, investor relations, and contact information strongly support legitimacy. Privacy compliance is addressed with a clear privacy policy and cookie consent mechanism. Overall, the site demonstrates a mature digital presence suitable for an enterprise infrastructure contractor. Strategic recommendations include enhancing security posture by implementing security headers, publishing incident response and vulnerability disclosure policies, and verifying domain registration transparency to improve trustworthiness.

100
80
74
85
68
2
90
infrastructureconstructionenergycommunicationsrenewableenergy+3 more
BootstrapLeafletFont AwesomeGoogle Fonts

Partner Domains:

investors.mastec.com
partner
portal.mastec.com
service
2026-07-09T07:24:14.016Z
cityofedinburg.com favicon

City of Edinburg

cityofedinburg.com

63
GovernmentUnited StatesmediumMEDIUM

The City of Edinburg website serves as the official digital presence for the municipal government of Edinburg, Texas. It provides comprehensive information about city governance, departments, community programs, business resources, services, events, and news. The site targets residents, businesses, and visitors, offering easy access to essential city services and transparency portals. The website is well-branded with consistent use of official logos and social media links, reinforcing trust and authority. Technically, the site employs a modern technology stack including jQuery, Bootstrap, Tiny Slider, and the Revize CMS platform. It integrates accessibility tools such as the UserWay widget and supports mobile responsiveness. Performance is moderate with good SEO and accessibility features. The site uses HTTPS and includes Google Analytics for traffic monitoring. From a security perspective, the website enforces HTTPS and uses CAPTCHA on forms, but lacks explicit security headers like Content-Security-Policy and Strict-Transport-Security. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is basic with a privacy policy present but no cookie consent mechanism. WHOIS data for the domain is missing, which is unusual for a government domain and warrants further verification. Overall, the website is professional, trustworthy, and functional, but could improve security posture by adding security headers and enhancing privacy compliance. The missing WHOIS data is a concern that should be addressed to ensure domain legitimacy and trustworthiness.

70
80
100
47
75
17
35
governmentcityedinburgtexasmunicipal+4 more
jQuery 3.5.1Bootstrap 4.6Tiny SliderYouTube iframe API+3
2026-07-09T07:21:00.974Z
cardinalcapitalmanagement.com favicon

Cardinal Capital Management Inc.

cardinalcapitalmanagement.com

43
FinanceUnited StatessmallHIGH

Cardinal Capital Management Inc. is an independent, SEC registered investment advisory firm specializing in providing high-quality investment management services to individuals, trusts, and institutional investors. The firm emphasizes a fiduciary approach, ensuring clients' interests are prioritized. Their team boasts over 75 years of combined investment experience, managing diverse portfolios including U.S. Large Cap, Small Cap, Non-U.S. equity, and fixed income strategies. The company targets clients seeking personalized, valuation-oriented investment solutions. Technically, the website is built on WordPress using the Genesis Framework, enhanced with SEO and analytics plugins such as Yoast SEO and MonsterInsights for Google Analytics. The site demonstrates good mobile optimization, clear navigation, and moderate performance. However, some security best practices like security headers and cookie consent mechanisms are missing, which could be improved to enhance compliance and protection. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data in its HTML content. No critical vulnerabilities or malware indicators were found. The lack of WHOIS registration data is a notable concern, potentially impacting trustworthiness. The firm should consider publishing explicit security policies and incident response contacts to strengthen its security posture. Overall, Cardinal Capital Management presents a professional and trustworthy online presence with room for improvement in privacy compliance and security hardening. Addressing these areas will enhance client trust and regulatory adherence.

47
85
-
70
15
53
2
investmentfinanceadvisorysecregisteredwealthmanagement+1 more
WordPressYoast SEO pluginGoogle Analytics (MonsterInsights)jQuery+2
2026-07-09T07:16:40.177Z