Skip to main content

United States security reports

Browse 10,271 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

148885
Websites
130
Industries
113
Countries
52
Avg Score
Page 87 of 206|Showing 4301-4350 of 10271
wolfordshop.com favicon

Wolford Official Website

wolfordshop.com

62
RetailUnited StatesmediumMEDIUM

Wolford is a premium fashion brand specializing in women's hosiery, lingerie, bodywear, and ready-to-wear apparel. The website serves as the official online shop for the US market, offering a wide range of products with a focus on quality and style. The brand maintains a strong market position in the retail and e-commerce sectors, targeting a mature female audience interested in elegant and designer hosiery and apparel. The site features comprehensive product categories, promotional sales, and a user-friendly shopping experience. Technically, the website is built on Salesforce Commerce Cloud, leveraging modern web technologies including Google Tag Manager, reCAPTCHA, and accessibility tools to ensure a secure and inclusive user experience. The site is mobile-optimized and SEO-friendly, with good performance and accessibility standards. Security posture is strong with HTTPS enforcement, security headers, and bot protection, though explicit security policies and incident response contacts are not publicly available. Privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanism. The absence of WHOIS data is a notable anomaly but does not detract significantly from the overall legitimacy and professionalism of the site. Overall, Wolford's website demonstrates a mature digital presence with strong business credibility and security practices.

45
53
2
55
82
80
100
e-commercefashionhosierylingerieretail+3 more
Google Tag ManagerGoogle reCAPTCHAUsercentrics Consent ManagementEqualWeb Accessibility+2
2025-07-30T15:59:56.451Z
28stone.com favicon

28Stone Consulting

28stone.com

54
FinanceUnited StatesmediumMEDIUM

28Stone Consulting is a specialized software consulting company focused on delivering cutting-edge custom software solutions for the financial services industry, including sell-side, buy-side, market venues, and brokers. Founded in 2011 and headquartered in New York, the company has established itself as a trusted partner to leading financial institutions, demonstrated by its extensive client portfolio and industry awards. Their key services include software development for capital markets, legacy system modernization, and electronic trading platform development. The company leverages modern technologies such as React, Next.js, OpenFin, and Cloud9 to deliver scalable and innovative solutions. Technically, the website reflects a mature digital infrastructure with a modern tech stack, good performance, and mobile optimization. The use of asynchronous scripts and integration with analytics and marketing tools like Google Analytics and HubSpot indicates a data-driven approach to user engagement. However, some security headers are missing, and DNSSEC is not enabled, suggesting areas for improvement in security hardening. From a security perspective, the site enforces HTTPS and employs domain transfer protection, but lacks published security policies, incident response contacts, and vulnerability disclosure mechanisms. Privacy compliance is weak, with no visible privacy or cookie policies, which could expose the company to regulatory risks. Overall, the security posture is solid but could benefit from enhanced transparency and technical controls. The overall risk assessment is moderate to low, with no critical vulnerabilities detected. Strategic recommendations include implementing comprehensive privacy and cookie policies, enabling DNSSEC, adding security headers, and publishing security and incident response information to enhance trust and compliance. These steps will strengthen the company's security culture and regulatory posture while maintaining its strong market position.

65
35
2
70
100
80
-
financetechnologysoftwareconsultingcapitalmarketscustomsoftware+2 more
ReactNext.jsOpenFinCloud9+3

Partner Domains:

28stone.bamboohr.com
partner
2025-07-30T15:59:52.235Z
rmhcdemo.com favicon

Ronald McDonald House Charities

rmhcdemo.com

48
Non-profitUnited StatesmediumHIGH

The website rmhcdemo.com serves as a demo platform for a Ronald McDonald House Charities chapter, focusing on providing support and housing for families with sick children. It presents a professional and consistent brand image aligned with the RMHC mission, targeting families, donors, and volunteers. The site offers information on key services such as housing, scholarships, fundraising, and family rooms, positioning itself as a medium-sized non-profit organization with a clear community focus. The domain age and registration details support the legitimacy of the demo site, with no privacy protection used and domain locked against unauthorized changes. Technically, the site is built on WordPress using common plugins like WPBakery Page Builder and Yoast SEO, with good mobile optimization and accessibility features. The performance is moderate, and SEO practices are adequately implemented. Security posture is reasonable with HTTPS enforced and no exposed sensitive data, but lacks DNSSEC and security headers, which are recommended for improvement. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism detected. Overall, the security posture is adequate for a demo non-profit site but could benefit from enhanced DNS security and security headers. The site does not expose critical vulnerabilities or sensitive data. Business credibility is high due to clear branding, trust indicators like Charity Navigator and BBB logos, and consistent content quality. No adult or explicit content is present, making it safe for general audiences. Strategic recommendations include enabling DNSSEC, implementing security headers, adding a cookie consent mechanism, and providing clearer contact information to enhance trust and compliance. These improvements will strengthen the site's security and privacy posture while maintaining its professional and trustworthy image.

30
53
2
85
42
75
20
non-profitcharityhealthcarefamilysupportwordpress+1 more
WordPressPHPjQueryMediaElement.js+4

Partner Domains:

rmhc.org
partner
hesterdesigns.com
partner
2025-07-30T12:04:28.894Z
autofrywebstore.com favicon

AutoFry

autofrywebstore.com

61
E-commerceUnited StatessmallMEDIUM

AutoFry operates a specialized e-commerce platform focused on ventless automated fryers and related commercial kitchen equipment. The company positions itself as a leader in this niche market, offering a range of products including fryers, ovens, oil filtration systems, and accessories. The website targets commercial kitchen operators and food service businesses, providing direct sales through a Shopify-based online store. The business appears established with a domain age consistent with its founding year of 2014. Technically, the website leverages modern e-commerce technologies including Shopify, jQuery, Google Fonts, and Google Analytics. Hosting is likely on Google Cloud Platform, ensuring reliable performance and scalability. The site is mobile-optimized with good SEO practices and clear navigation, enhancing user experience. From a security perspective, the site enforces HTTPS and uses domain status locks to prevent unauthorized transfers or updates. It employs hCaptcha for form protection and integrates standard Shopify security features. However, DNSSEC is not enabled and some advanced security headers are missing, representing areas for improvement. Privacy compliance is basic with a privacy policy and terms of service present but lacking a cookie consent mechanism. Overall, the website is professional, trustworthy, and safe for general audiences. It demonstrates a solid business and technical foundation with room for enhanced security and privacy practices. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, adding cookie consent, and strengthening security headers to improve compliance and trust.

75
35
2
55
65
75
100
ecommerceshopifyventlessfryerkitchenequipmentcommercialcooking+1 more
ShopifyjQueryGoogle FontsGoogle Tag Manager+3

Partner Domains:

mtiproducts.com
partner
autofry.com
partner

+1 more partners

2025-07-30T10:55:46.270Z
peacock.com favicon

NBCUNIVERSAL MEDIA

peacock.com

67
MediaUnited StatesenterpriseMEDIUM

NBCUniversal Media is a leading global media and entertainment company specializing in the development, production, and marketing of entertainment, news, and information to a worldwide audience. As a subsidiary of Comcast Corporation, NBCUniversal operates multiple subsidiaries including Peacock streaming service, Universal Pictures, and NBC Sports, positioning itself as a dominant player in the media industry. The website reflects a mature digital presence with professional design, rich multimedia content, and consistent branding aligned with its corporate identity. Technically, the site is built on Drupal 10, leveraging modern analytics and consent management tools, indicating a high level of digital maturity. Security posture is strong with HTTPS enforcement, security headers, and cookie consent mechanisms, though explicit security policies and incident response contacts are not publicly disclosed. Overall, the site demonstrates a high level of professionalism and trustworthiness, though the lack of WHOIS data limits domain registration transparency. Strategic recommendations include publishing detailed security and incident response information and establishing a vulnerability disclosure program to enhance trust and compliance.

40
88
17
60
65
80
100
mediaentertainmentnewscorporatenbcuniversal+4 more
Drupal 10FontAwesomeGoogle Tag ManagerDatadog RUM+1

Partner Domains:

corporate.comcast.com
parent
peacocktv.com
subsidiary

+1 more partners

2025-07-30T09:48:19.079Z
jurassicworld.com favicon

Universal Pictures

jurassicworld.com

64
MediaUnited StateslargeMEDIUM

Jurassic World Rebirth's official website serves as a comprehensive platform for movie promotion, providing users with showtimes, ticket purchasing options, trailers, cast information, and galleries. The site is professionally designed and targets moviegoers and fans of the Jurassic World franchise, positioning itself as a key marketing tool for Universal Pictures and its parent company NBCUniversal. Technically, the site employs a modern tech stack including JavaScript frameworks, Google Tag Manager, and multiple advertising and analytics pixels, hosted on AWS Cloudfront for performance and reliability. Privacy compliance is robust, with clear privacy and cookie policies managed via OneTrust, reflecting adherence to GDPR and other regulations. Security posture is strong, with HTTPS enforced and appropriate security headers in place, although no explicit security or incident response policies are publicly disclosed. The WHOIS data is unavailable, which is unusual but likely due to privacy protection or proxy registration, slightly impacting business credibility. Overall, the site is trustworthy, secure, and professionally maintained, effectively supporting the movie's marketing and audience engagement objectives.

15
88
17
60
65
80
100
movieentertainmentjurassicworldshowtimestickets+2 more
JavaScriptGoogle Tag ManagerTikTok PixelAmazon Ads+4

Partner Domains:

www.nbcuniversal.com
parent
www.powster.com
partner
2025-07-30T09:48:09.028Z
M

Motion Tactic

motiontactic.com

58
TechnologyUnited StatessmallMEDIUM

Motion Tactic is a boutique custom web design agency founded in 2017, specializing in delivering compelling, user-friendly websites and SEO services tailored for innovative B2B companies. The company emphasizes strategic partnerships, an in-house US-based team, and a client-focused approach to drive tangible ROI. Their market position is strengthened by a strong portfolio, client testimonials, and Clutch Gold verification, positioning them as a trusted partner in the B2B technology sector. Technically, the website is built on WordPress with a modern tech stack including jQuery, Google Analytics, Hotjar, and HubSpot integrations. The site is mobile-optimized, accessible, and SEO-friendly, although performance is moderate. The domain is registered with NameCheap since 2017, consistent with the company's founding date, and uses HTTPS with a clientTransferProhibited status, indicating good domain security practices. Security posture is solid with HTTPS enforced but lacks visible security headers and published privacy or cookie policies, which are compliance gaps. The site uses multiple third-party tracking scripts, indicating moderate user tracking. No incident response or vulnerability disclosure information is provided. Overall, the site is professional and trustworthy but could improve privacy compliance and security hardening. The overall risk is moderate with recommendations to implement DNSSEC, publish privacy and cookie policies, add security headers, and provide incident response contacts to enhance trust and compliance.

50
35
47
85
52
70
40
webdesignb2bseocustomwordpressdigitalmarketing+1 more
WordPressjQueryGoogle AnalyticsGoogle Tag Manager+4
2025-07-29T17:14:16.795Z
staud.clothing favicon

STAUD

staud.clothing

65
E-commerceUnited StatesmediumMEDIUM

STAUD is a Los Angeles-based women's fashion brand specializing in modern clothing, handbags, footwear, and swimwear. Founded in 2015, it targets modern women seeking stylish and design-forward apparel and accessories. The company operates a direct-to-consumer e-commerce model primarily through its Shopify-powered website, positioning itself as a niche fashion retailer with a focus on quality and design. The website is professionally designed with consistent branding and good content quality, supporting a positive user experience and clear navigation. Social media integration and structured data enhance its digital presence. Technically, the site leverages a mature e-commerce infrastructure with Shopify as the CMS and hosting platform. It integrates multiple third-party marketing, analytics, and fraud prevention tools such as Google Analytics, Klaviyo, Hotjar, Rakuten Advertising, and Signifyd. The site is mobile-optimized and performs moderately well, though accessibility features are basic. Security posture is solid with HTTPS enforced and domain registration protected by privacy services, though explicit security headers and policies are not fully evident. From a security and compliance perspective, the site lacks visible privacy and cookie policies and does not present a security or incident response policy publicly. While no critical vulnerabilities or suspicious patterns were detected, the absence of these policies suggests room for improvement in privacy compliance and transparency. The domain WHOIS data shows a privacy-protected registration consistent with the business's US location and founding date, supporting legitimacy. Overall, STAUD's website is a credible, professionally managed e-commerce platform with strong business credibility and technical implementation. Enhancements in privacy policy publication, cookie consent mechanisms, and security policy transparency would further strengthen its compliance and trustworthiness.

60
73
17
60
57
70
100
fashione-commerceretailwomensclothinghandbags+3 more
ShopifyGoogle AnalyticsKlaviyoHotjar+10

Partner Domains:

global-e.com
partner
rakutenadvertising.io
partner

+2 more partners

2025-07-29T17:12:06.237Z
covidmoneytracker.org favicon

Committee for Responsible Federal Budget

covidmoneytracker.org

55
GovernmentUnited StatessmallMEDIUM

The COVID Money Tracker website is an informational platform operated by the Committee for Responsible Federal Budget, a non-profit organization focused on tracking and visualizing the trillions of dollars spent by the U.S. federal government in response to the COVID-19 pandemic. The site provides interactive data visualizations and detailed tables to help policymakers, researchers, and the public understand federal spending, tax cuts, loans, grants, and subsidies related to COVID relief efforts. The platform positions itself as a niche government transparency tool with a clear mission to enhance fiscal accountability. Technically, the website is built on Drupal 10 CMS and incorporates modern web technologies including Google Tag Manager for analytics and tracking. The site is mobile-optimized, accessible, and SEO-friendly, offering a good user experience with clear navigation and professional design. Performance is moderate, with no major technical issues detected in the provided content. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks several recommended security headers such as Content-Security-Policy and X-Frame-Options, which could enhance protection against common web attacks. Privacy compliance is limited, with no visible privacy or cookie policies and no GDPR compliance indicators. Contact information and incident response channels are not evident, which could hinder user trust and security reporting. Overall, the website is a credible and trustworthy source for COVID-19 federal spending data, but it would benefit from improved privacy disclosures, enhanced security headers, and clearer contact information to strengthen its security posture and compliance. The domain WHOIS data is unavailable or privacy-protected, which is typical for non-profit organizations but limits external verification of registrant details.

40
35
47
60
62
75
40
covid-19federalspendingdatavisualizationgovernmenttransparencynon-profit
Drupal 10Google Tag ManagerUnderscore.js

Partner Domains:

www.crfb.org
partner
2025-07-29T17:10:35.758Z
jllt.com favicon

JLL Technologies

jllt.com

75
Real EstateUnited StatesenterpriseMEDIUM

JLL Technologies is a leading provider of commercial real estate technology solutions, offering software, data, and expertise to optimize property acquisition, management, and experience. Positioned as a market leader, JLLT serves enterprise clients globally with integrated workplace management systems, facilities management platforms, AI-powered workplace experience tools, and data analytics services. The website reflects a mature digital presence with professional design, comprehensive content, and strong branding aligned with its parent company JLL. Technically, the site leverages WordPress CMS with modern frameworks like Bootstrap, integrates advanced analytics and marketing tools such as Microsoft Clarity, Google Tag Manager, and Drift live chat, and employs Cloudinary for optimized media delivery. Security posture is strong with HTTPS, security headers, and secure form handling, though public security policies and incident response contacts are not published. Overall, the site is trustworthy, well-optimized for SEO and accessibility, and compliant with privacy regulations including GDPR. The lack of WHOIS data suggests privacy protection, which is justified for this enterprise business. Strategic recommendations include publishing security policies and incident response information to enhance transparency and trust.

75
68
17
85
82
85
100
commercialrealestatetechnologyfacilitiesmanagementaidataanalytics+2 more
WordPressGravity FormsjQueryBootstrap 4.3.1+5

Partner Domains:

us.jll.com
partner
spark.jllt.com
partner
2025-07-29T17:09:40.448Z
corelogic.com favicon

Cotality

corelogic.com

68
Real EstateUnited StateslargeMEDIUM

Cotality is a business specializing in property data and intelligence solutions, serving a broad range of industries including banking, finance, energy, government, real estate, and telecommunications. Their website showcases a comprehensive suite of products designed to enhance workflows, provide accurate valuations, and deliver actionable insights for property-related decision-making. The company positions itself as a leader in property data analytics with a strong focus on innovation and customer-centric solutions. Technically, the website is built on modern web technologies including Webflow CMS, Google Tag Manager, and various JavaScript libraries for enhanced user experience and analytics. The site is well-structured, mobile-optimized, and integrates marketing and tracking tools such as Intellimize and HubSpot forms. Performance is moderate with good SEO and accessibility basics in place. From a security perspective, the site uses HTTPS and implements cookie consent mechanisms, but lacks explicit security headers and published security policies. No vulnerabilities or exposed sensitive data were detected in the provided content. The absence of WHOIS registration data is a notable concern, potentially indicating privacy protection or data unavailability, which impacts domain legitimacy assessment. Overall, the website presents a professional and trustworthy front for a large enterprise-level business in the real estate data sector. Strategic recommendations include publishing clear privacy and security policies, enhancing security headers, and verifying domain registration details to improve trust and compliance.

40
73
25
70
72
85
100
propertydatarealestateanalyticsbankingfinance+8 more
Google Tag ManagerIntellimizeHubSpot FormsFinsweet Attributes+3
2025-07-29T17:09:25.235Z
dolby.com favicon

Dolby Laboratories

dolby.com

70
TechnologyUnited StateslargeMEDIUM

Dolby Laboratories is a leading technology company specializing in audio, visual, and voice technologies for entertainment media including movies, TV, music, and gaming. The company is globally recognized for its premium technologies such as Dolby Atmos and Dolby Vision, which enhance immersive sound and stunning picture quality. The website reflects a strong market position with a professional and consistent brand presence targeting consumers, content creators, and device manufacturers. The business model centers on technology licensing and product innovation within the entertainment technology sector. Technically, the website employs a modern technology stack including JavaScript frameworks, Braze for marketing automation, Google Tag Manager, Hotjar for user behavior analytics, and Azure Application Insights for performance monitoring. The site is built on the EPiServer CMS platform, optimized for mobile devices, and demonstrates excellent performance and SEO practices. Accessibility features are present, supporting a broad user base. From a security perspective, the site enforces HTTPS with strong SSL configuration and implements key security headers. Cookie consent mechanisms and privacy policies indicate good privacy compliance aligned with GDPR. However, explicit security policies, incident response details, and vulnerability disclosure mechanisms are not publicly available, representing areas for improvement. Overall, the website is trustworthy, professionally maintained, and secure, with no signs of malicious activity or content safety concerns. The absence of WHOIS data is noted but likely due to privacy or registry policies rather than suspicious behavior. Strategic recommendations include publishing detailed security policies, vulnerability disclosure information, and data protection officer contacts to enhance transparency and trust.

20
88
20
75
85
85
100
audiovisualtechnologydolbyentertainment+3 more
JavaScriptBraze SDKGoogle Tag ManagerHotjar+2
2025-07-29T17:06:59.556Z
crfb.org favicon

Committee for a Responsible Federal Budget

crfb.org

50
GovernmentUnited StatesmediumMEDIUM

The Committee for a Responsible Federal Budget is a well-established nonpartisan, non-profit organization dedicated to educating the public and policymakers on fiscal policy issues. Their website reflects a professional and consistent brand presence, offering a variety of educational resources, interactive tools, and detailed fiscal policy analysis. The organization targets a broad audience including the general public, researchers, and government stakeholders. Technically, the site is built on Drupal 10, leveraging modern web technologies and analytics tools such as Google Analytics and Google Tag Manager, indicating a mature digital infrastructure. The site is mobile-optimized and accessible, with good SEO practices and clear navigation. From a security perspective, the website enforces HTTPS and includes some security headers, but lacks explicit advanced security policies such as Content Security Policy and a security.txt file. No vulnerabilities or exposed sensitive data were detected in the HTML content. Privacy compliance is basic; while a privacy policy is present, there is no cookie consent mechanism or detailed GDPR compliance information, which could be improved. Contact information including phone and physical address is clearly provided, enhancing business credibility. Overall, the website demonstrates a strong security posture and professional business credibility, though improvements in privacy compliance and security policy transparency are recommended. The absence of WHOIS data limits domain registration trust verification, but the website content and structure strongly support legitimacy and trustworthiness.

40
35
2
70
52
80
40
non-profitfiscalpolicygovernmenteducationnonpartisan+2 more
Drupal 10Google AnalyticsGoogle Tag Manager
2025-07-29T16:01:25.215Z