Skip to main content

United States security reports

Browse 10,271 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

148887
Websites
130
Industries
113
Countries
52
Avg Score
Page 92 of 206|Showing 4551-4600 of 10271
montanarealtors.org favicon

Montana Association of REALTORS®

montanarealtors.org

60
Real EstateUnited StatesmediumMEDIUM

The Montana Association of REALTORS® (MAR) is a professional membership organization serving real estate professionals in Montana. It focuses on enhancing member professionalism, advocating for private property rights, and supporting local communities. The website provides comprehensive resources including advocacy, education, legal updates, and member services. MAR maintains a strong market position as the state-level REALTOR® association with a clear focus on member engagement and professional development. Technically, the website uses a modern technology stack including jQuery, Foundation framework, Flickity carousel, and Google Tag Manager for analytics. The site is mobile optimized and offers good user experience with clear navigation and professional design. The CMS platform is Accrisoft Freedom, indicating a specialized association management system. From a security perspective, the site enforces HTTPS and uses secure external libraries but lacks visible security headers and cookie consent mechanisms, which are areas for improvement. WHOIS data is unavailable due to privacy protection, which is common for such organizations and does not detract from legitimacy. Overall, the site demonstrates a solid security posture but could enhance compliance and transparency. The overall risk is low with no suspicious content or vulnerabilities detected. Strategic recommendations include implementing security headers, adding cookie consent, and publishing security policies to improve trust and compliance.

30
53
2
75
62
80
100
realestateassociationprofessionalmontanarealtors+4 more
jQuery 3.5.1jQuery UI 1.12.1js-cookie 2.2.1Flickity carousel+5

Partner Domains:

realtor.com
partner
accrisoft.com
partner

+2 more partners

2025-07-28T22:47:04.893Z
wa.gov favicon

State of Washington

wa.gov

64
GovernmentUnited StatesenterpriseMEDIUM

WA.gov is the official website of the State of Washington, serving as a centralized portal for residents, businesses, families, seniors, and visitors to access government services, agencies, and helpful guides. The site is well-established with a domain age dating back to 1997, reflecting its long-standing role as a trusted government resource. It offers a broad range of services including contact directories, how-to guides, and a secure login portal for state services (SecureAccess Washington). The website targets a diverse audience with multilingual support and accessibility considerations. Technically, the site is built on Drupal 10 with modern front-end frameworks like Bootstrap 5.2, and integrates third-party tools such as Google Tag Manager, Yext Answers Search, and Qualtrics for analytics and user feedback. The site is mobile-optimized, accessible, and SEO-friendly, providing a professional and user-friendly experience. From a security perspective, the site uses HTTPS and has domain transfer protections in place. However, DNSSEC is not enabled, and there is a lack of explicit security policies or incident response information publicly available. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is moderate, with a clear privacy policy but no cookie consent mechanism. Overall, WA.gov demonstrates a strong business credibility and technical maturity appropriate for a government entity. Strategic recommendations include enabling DNSSEC, implementing security headers, adding cookie consent mechanisms, and publishing security and incident response policies to enhance trust and compliance.

50
53
2
75
72
75
100
governmentstateserviceswashingtonpublicservicesofficial
Drupal 10Bootstrap 5.2Google Tag ManagerYext Answers Search+3
2025-07-28T21:44:34.884Z
utah.gov favicon

State of Utah

utah.gov

61
GovernmentUnited StatesenterpriseMEDIUM

Utah.gov is the official website of the State of Utah, serving as a comprehensive portal for government services, information, and resources targeted at residents, businesses, visitors, and government employees. The site offers key services such as vehicle renewal, hunting and fishing licenses, driver license renewal, job listings, vital records, and local government information. It holds a strong market position as the authoritative source for Utah state government information. Technically, the website employs modern web standards including HTML5, CSS3, and JavaScript, with integrations such as Google Tag Manager and Qualtrics for analytics and user feedback. The Utah Design System Header framework is used for consistent UI/UX. The site is mobile-optimized, accessible, and SEO-friendly, though performance is moderate. From a security perspective, the site enforces HTTPS and uses secure forms with proper accessibility attributes. However, it lacks explicit security headers like Content-Security-Policy and does not have a visible cookie consent mechanism, which impacts privacy compliance. WHOIS data is unavailable or privacy protected, which is unusual for a government domain but does not detract from the site's legitimacy based on content and domain usage. Overall, Utah.gov demonstrates a high level of professionalism, trustworthiness, and user-centric design. Strategic improvements in security headers, privacy compliance, and transparency of domain registration would further enhance its security posture and user trust.

25
53
2
70
67
85
100
governmentutahofficialservicesstate+2 more
HTML5CSS3JavaScriptGoogle Tag Manager+2
2025-07-28T21:44:29.868Z
nvartscouncil.org favicon

Nevada Arts Council

nvartscouncil.org

51
GovernmentUnited StatesmediumMEDIUM

The Nevada Arts Council is a government-affiliated non-profit organization dedicated to promoting and supporting the arts and culture across the state of Nevada. Their website serves as a comprehensive resource for artists, educators, community members, and grant applicants, offering information on grants, programs, events, and educational initiatives. The organization positions itself as a key catalyst for artistic and cultural development within the state. Technically, the website is built on WordPress and leverages a variety of plugins and third-party services including Google Analytics, HubSpot, and Instagram Feed Pro to enhance functionality and user engagement. The site is mobile-optimized and includes SEO best practices such as structured data and meta tags, although some accessibility features could be improved. From a security perspective, the site uses HTTPS and employs standard tracking and marketing scripts. However, it lacks visible security headers and formal security or incident response policies. The WHOIS data is unavailable due to a malformed request, but the domain appears legitimate and privacy protection is justified given the nature of the organization. Overall, the website is professional, content-rich, and trustworthy, but could benefit from enhanced privacy compliance measures and improved security configurations to further strengthen its posture.

15
50
2
40
52
70
100
artsculturegrantseducationnevada+2 more
WordPress CMSjQueryGoogle Tag ManagerGoogle Analytics+5
2025-07-28T21:44:19.816Z
mt.gov favicon

State Information Technology Services Division

mt.gov

68
GovernmentUnited StateslargeMEDIUM

The website mt.gov serves as the official online portal for the State of Montana, providing a wide range of government services, resources, and information to residents, businesses, visitors, and government employees. It acts as a centralized hub for accessing employment opportunities, business registration, tax services, driver licensing, legislative and judicial information, and tourism-related content. The site is well-positioned as the authoritative digital presence for Montana state government, with a large user base and comprehensive service offerings. From a technical perspective, the site employs modern web technologies including Bootstrap, jQuery, and Google Tag Manager for analytics. The design is responsive and user-friendly, with clear navigation and consistent branding. Performance is moderate, and accessibility features are basic but present. The site uses HTTPS with a good SSL configuration, though DNSSEC is not enabled, which could be improved for enhanced DNS security. Security posture is solid with no visible vulnerabilities or exposed sensitive data. However, the absence of explicit privacy policies, terms of service, and incident response contacts represents a compliance gap. Cookie consent is implemented, indicating some attention to privacy regulations. The domain is a legitimate government .gov domain with a long registration history, enhancing trustworthiness. Overall, the website is a professional, secure, and credible government portal with room for improvement in privacy compliance and security documentation. Strategic enhancements in these areas would further strengthen user trust and regulatory adherence.

15
68
47
85
67
80
100
governmentmontanastateservicesofficial
Bootstrap 4.5.3Bootstrap 5.1.3jQuery 3.6.0Popper.js 1.16.1+5
2025-07-28T21:44:09.719Z
hawaii.gov favicon

State of Hawaiʻi

hawaii.gov

57
GovernmentUnited StatesenterpriseMEDIUM

The website portal.ehawaii.gov serves as the official digital gateway for the State of Hawaiʻi, providing comprehensive resources and services for government entities, residents, businesses, and visitors. It functions as a centralized hub for accessing government departments, online services such as business registration and driver records, and up-to-date news and alerts. The site is positioned as a trusted and authoritative source, reinforced by consistent branding with the state seal and multiple industry awards. From a technical perspective, the site employs modern web technologies including Google Analytics for traffic analysis, Freshchat for user engagement, and Siteimprove Analytics for quality assurance. The site demonstrates good mobile optimization, accessibility features, and SEO practices, contributing to a positive user experience. However, some improvements could be made in security headers and cookie consent mechanisms to enhance compliance and security posture. Security-wise, the site enforces HTTPS and avoids exposing sensitive data, but lacks explicit security headers and a published security policy or incident response contacts. The absence of a vulnerability disclosure program and cookie consent banner indicates areas for compliance enhancement, particularly with privacy regulations. Overall, the site maintains a strong security baseline appropriate for a government portal. The overall risk assessment is low, given the official nature, consistent branding, and absence of suspicious content or vulnerabilities. Strategic recommendations include implementing security headers, adding cookie consent for GDPR compliance, publishing security policies, and enhancing transparency with vulnerability disclosure mechanisms to further strengthen trust and compliance.

15
53
2
75
62
60
100
governmenthawaiiofficialportalservices+3 more
Google AnalyticsFreshchatSiteimprove AnalyticsFont Awesome+2

Partner Domains:

governor.hawaii.gov
partner
hidot.hawaii.gov
partner

+3 more partners

2025-07-28T21:44:04.641Z
azarts.gov favicon

Arizona Commission on the Arts

azarts.gov

44
GovernmentUnited StatesmediumHIGH

The Arizona Commission on the Arts is a state government agency dedicated to supporting and promoting the arts across Arizona. It provides grants, programs, and services to artists, arts organizations, schools, and communities to foster cultural development and arts education. The agency holds a strong market position as the official state arts agency with a clear mission to enhance quality of life and economic growth through the arts. The website reflects this mission with comprehensive content, clear navigation, and active community engagement through events and social media. Technically, the website is built on WordPress with a modern tech stack including Bootstrap, jQuery, and SEO plugins like Yoast. It is hosted on Google Cloud infrastructure, uses HTTPS, and integrates analytics tools such as Google Analytics and Siteimprove. The site demonstrates good mobile optimization and accessibility features, though some improvements in cookie consent and DNS security could be made. From a security perspective, the site enforces HTTPS and has domain transfer protections but lacks DNSSEC and explicit public security policies or incident response contacts. No critical vulnerabilities or blocking mechanisms were detected. Privacy compliance is basic with a privacy policy present but no cookie consent mechanism. The WHOIS data shows a long-established domain with privacy protection justified for a government entity. Overall, the site is professional, trustworthy, and well-maintained with minor areas for improvement in privacy compliance and DNS security. Strategic recommendations include enabling DNSSEC, implementing cookie consent, publishing security policies, and adding vulnerability disclosure information to enhance trust and compliance.

15
53
2
60
62
75
-
artsgovernmenteducationgrantsarizona+2 more
jQueryBootstrapGoogle AnalyticsYoast SEO+5
2025-07-28T21:43:49.600Z
alaska.gov favicon

State of Alaska

alaska.gov

66
GovernmentUnited StateslargeMEDIUM

The State of Alaska's official website serves as a comprehensive portal for residents, businesses, visitors, and state employees, providing access to a wide range of government services and information. It is well-structured with clear navigation and covers multiple departments and agencies, reflecting its role as a central government resource. The website's market position is authoritative as the official state government domain, with a large audience and extensive service offerings. Technically, the site uses a legacy but stable technology stack including jQuery and Bootstrap, hosted with reliable DNS providers. It is mobile optimized and accessible, though performance is moderate. Google Analytics is used for visitor tracking, but there is no visible cookie consent mechanism or explicit privacy policy, indicating room for improvement in privacy compliance. From a security perspective, the site uses HTTPS and has domain transfer protections, but lacks DNSSEC and security headers. No vulnerabilities or exposed sensitive data were detected. The absence of a published security policy or incident response contact reduces transparency. Overall, the security posture is solid but could be enhanced with modern best practices. The website is safe for general audiences, contains no adult or questionable content, and maintains a high level of trustworthiness consistent with its government status. Strategic improvements in privacy and security disclosures would further strengthen its compliance and user trust.

80
35
17
70
67
80
100
governmentalaskastatepublicservicesresident+3 more
jQuery 2.2.4Bootstrap 3.3.6Google AnalyticsLine Awesome Font Awesome icons
2025-07-28T21:43:39.558Z
T

T-Mobile US

t-mobile.com

67
TelecommunicationsUnited StatesenterpriseMEDIUM

T-Mobile US is a leading telecommunications company providing wireless services, devices, and related products to consumers and businesses primarily in the United States and Puerto Rico. The company offers a broad range of plans including unlimited phone plans, prepaid options, business plans, and home internet services. Their market position is strong, supported by competitive pricing and a well-recognized brand. The website reflects a mature digital presence with comprehensive content, clear navigation, and extensive customer engagement features. Technically, the website leverages a modern technology stack including Adobe Experience Manager as the CMS, Adobe Launch for tag management, Google Analytics, LivePerson chat, and various SDKs for payment and fraud detection. The site is optimized for performance and mobile responsiveness, with good accessibility and SEO practices in place. Security is robust with HTTPS enforced, multiple security headers, and advanced fraud detection mechanisms. While the WHOIS data is unavailable due to registry restrictions, the website's trustworthiness is supported by official branding, verified contact information, and consistent domain usage. Privacy and cookie policies are comprehensive and GDPR compliant, though explicit security policies and incident response details are not publicly disclosed. Overall, the site demonstrates a high level of professionalism and security maturity. Strategically, T-Mobile should consider publishing explicit security and incident response policies and establishing a vulnerability disclosure program to enhance transparency and trust. Continued investment in privacy compliance and security best practices will further strengthen their market position and customer confidence.

30
58
17
87
72
85
100
telecommunicationswirelessmobileinternetconsumer+4 more
Adobe Launch (Tag Manager)Google Analytics (gtag.js)LivePerson chatCookielaw.org cookie consent+6

Partner Domains:

prepaid.t-mobile.com
subsidiary
metrobyt-mobile.com
subsidiary

+1 more partners

2025-07-28T21:40:07.884Z
A

Applied Materials

appliedmaterials.com

72
TechnologyUnited StatesenterpriseMEDIUM

Applied Materials is a global leader in materials engineering solutions, primarily serving the semiconductor and advanced display industries. The company partners strategically with customers across Europe and worldwide to deliver innovative technologies and services that enable next-generation microchips and devices. Their business model focuses on B2B technology and manufacturing solutions, positioning them as a market leader with a comprehensive product and service portfolio including semiconductor technologies, display solutions, automation software, and supply chain services. The website reflects a mature enterprise with consistent branding and professional content. Technically, the website is built on Adobe Experience Manager, leveraging modern web technologies and performance monitoring tools. It is well-optimized for mobile and accessibility, with strong SEO practices. Security posture is robust with HTTPS, Content Security Policy, and cookie consent mechanisms, although additional security headers and a public security policy could enhance trust further. No critical vulnerabilities or suspicious content were detected. The WHOIS data is unavailable publicly, likely due to privacy protection, which is common for large enterprises. Overall, the website demonstrates high professionalism, security awareness, and compliance with privacy regulations, making it a trustworthy digital presence for Applied Materials. Strategic recommendations include enhancing security headers, publishing a dedicated security policy and incident response contacts, and implementing a vulnerability disclosure program to further strengthen security posture and stakeholder trust.

70
73
2
85
77
85
100
materialsengineeringsemiconductordisplayautomationsoftwarecorporateresponsibility+2 more
Adobe Experience Manager (AEM)Adobe Launch (Tag Manager)Font AwesomeCustom Elements polyfill+3

Partner Domains:

appliedsmartfactory.com
partner
ir.appliedmaterials.com
related

+1 more partners

2025-07-28T21:39:17.683Z
B

Bread Financial

breadfinancial.com

69
FinanceUnited StateslargeMEDIUM

Bread Financial is a large financial services company specializing in credit cards, personal loans, savings products, and payment solutions. The company positions itself as a tech-forward organization offering simple and competitive financial products for both personal and business customers. Their website demonstrates a strong market presence with multiple branded credit card programs and partnerships with well-known brands such as American Express, AAA, NFL, Victoria’s Secret, and Ulta Beauty. The company leverages Adobe Experience Manager as its CMS and integrates advanced marketing and analytics tools from Adobe and other providers to optimize user experience and engagement. Security posture is generally strong with HTTPS enforcement and privacy compliance, though explicit security policies and incident response contacts are not published. The absence of WHOIS data reduces transparency but does not detract significantly from the overall legitimacy based on website content and external references. Strategic recommendations include enhancing security header implementation, publishing vulnerability disclosure and incident response information, and improving WHOIS transparency to strengthen trust and compliance.

55
58
2
100
72
85
100
financecreditcardsloanssavingspaymentsolutions+1 more
Adobe TargetAdobe Launch (Adobe DTM)jQueryOneTrust Cookie Consent+2

Partner Domains:

comenity.net
partner
mysavings.breadfinancial.com
subsidiary

+3 more partners

2025-07-28T21:38:57.593Z
merck.com favicon

Merck & Co., Inc.

merck.com

70
HealthcareUnited StatesenterpriseMEDIUM

Merck & Co., Inc. is a leading research-intensive biopharmaceutical company with a long history of developing important medicines and vaccines to address global health threats. The website targets patients, investors, researchers, and healthcare professionals, providing comprehensive information on research, products, clinical trials, sustainability, and investor relations. The company positions itself as a premier player in the healthcare industry with a strong focus on innovation and patient support. Technically, the website is built on WordPress with modern SEO and performance optimizations, including lazy loading, responsive design, and Google Tag Manager integration. The site demonstrates good digital maturity with excellent mobile optimization and accessibility features, although explicit security headers are not visibly configured in the HTML source. From a security perspective, the site enforces HTTPS and provides privacy and cookie policies with consent mechanisms, indicating good privacy compliance. However, there is no visible security policy or incident response contact information, and WHOIS data for the domain is unavailable, which slightly reduces trustworthiness. No vulnerabilities or suspicious content were detected. Overall, the website is professional, trustworthy, and well-maintained, supporting Merck's reputation as a major healthcare entity. Strategic improvements in security header implementation and transparency around security policies would further enhance the site's security posture and user trust.

80
68
2
85
52
85
100
healthcarepharmaceuticalresearchbiopharmaceuticalclinicaltrials+3 more
WordPressYoast SEO pluginGoogle Tag ManagerTiny Slider+3

Partner Domains:

merck-animal-health.com
subsidiary
merckhelps.com
partner

+3 more partners

2025-07-28T21:38:47.540Z
alloy.co favicon

Alloy

alloy.co

65
FinanceUnited StatesmediumMEDIUM

Alloy is a mature and reputable identity and fraud prevention platform focused on serving financial institutions and fintech companies. Established in 2010, Alloy offers a comprehensive suite of services including identity verification, AML monitoring, fraud prevention, credit underwriting, and embedded finance risk management. The company is well-positioned in the fintech and financial services market, trusted by over 700 top-tier clients including banks and credit unions. Their business model is primarily B2B SaaS, leveraging a broad network of data partners to deliver robust risk intelligence solutions. Technically, Alloy employs a modern and well-integrated technology stack with extensive use of marketing, analytics, and tracking tools such as Google Tag Manager, Marketo, Hotjar, and Clearbit. The website is hosted behind Cloudflare DNS, ensuring reliable performance and security. The site is well-optimized for mobile and accessibility, with excellent design quality and user experience. SEO practices are solid, supported by comprehensive metadata and structured data. From a security perspective, Alloy demonstrates good practices including HTTPS enforcement, domain transfer protections, and use of reputable third-party security and analytics services. However, there is room for improvement by enabling DNSSEC and publishing explicit incident response and vulnerability disclosure policies. Privacy compliance is strong with clear privacy and cookie policies, including consent mechanisms aligned with GDPR requirements. Overall, Alloy presents a high level of business credibility, technical maturity, and security posture. The website content is safe and professional, targeting a general audience within the financial sector. No critical security issues or blocking mechanisms were detected, supporting a high trustworthiness rating.

45
53
17
85
75
60
100
identityverificationfraudpreventionamlmonitoringcreditunderwritingfinancialservices+3 more
Google Tag ManagerMarketoHotjarSumo+6

Partner Domains:

mastercard.com
partner
lexisnexis.com
partner

+3 more partners

2025-07-28T21:38:07.126Z
mevo.com favicon

Mevo Inc.

mevo.com

62
TechnologyUnited StatessmallMEDIUM

Mevo Inc., a subsidiary of Logitech, specializes in wireless multi-camera live streaming solutions targeting content creators and professional streamers. Their product portfolio includes hardware like Mevo Core and Mevo Pro, complemented by multiple streaming and camera control applications. The company positions itself as a niche leader offering affordable, easy-to-use live streaming technology with strong integration to popular platforms such as Twitch, YouTube, and Facebook. The website reflects a professional and consistent brand image with excellent content quality and user experience. Technically, the website is built on modern web technologies including React and Next.js, hosted on AWS infrastructure. It demonstrates good performance, mobile optimization, and accessibility features. The site integrates third-party services for analytics and marketing, such as Tealium and Mailchimp, while maintaining GDPR compliance through comprehensive privacy and cookie policies linked to the parent company Logitech. From a security perspective, the site enforces HTTPS and domain registration protections but lacks DNSSEC and explicit security headers. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data confirms a long-standing domain registration consistent with the business history, enhancing trustworthiness. Overall, Mevo.com presents a secure, professional, and user-friendly digital presence aligned with its business goals. Strategic improvements in DNS security and publishing a formal security policy could further enhance its security posture.

30
68
2
65
62
85
100
livestreamingmulti-camerawirelesscameravideoproductionstreamingapps+3 more
ReactNext.jsAWS DNSYouTube iframe API+1

Partner Domains:

logitech.com
parent
2025-07-28T20:35:29.152Z
capublicnotice.com favicon

iPublish® Media Solutions

capublicnotice.com

58
MediaUnited StatesmediumMEDIUM

The website www.capublicnotice.com operates as a specialized platform providing access to legal public notices and classifieds primarily for California counties. It aggregates various types of legal notices including court filings, summons, name changes, bids, auctions, and government publications. The platform targets residents, legal professionals, and government entities seeking official public notices. The business is positioned as a niche regional media service under the parent company iPublish® Media Solutions, leveraging a searchable database and alert system to serve its audience. Technically, the website employs a modern technology stack including jQuery, Bootstrap 5, Select2, Google Maps API, and Google Tag Manager for analytics. The site is mobile optimized with good navigation and SEO practices, though accessibility features are basic. Security is robust with HTTPS enforced and use of reCAPTCHA, but lacks some security headers and a formal vulnerability disclosure mechanism. From a security perspective, the site demonstrates good practices such as secure forms and bot protection, but the absence of security headers and cookie consent mechanisms are areas for improvement. The WHOIS data is notably missing or inaccessible, which raises concerns about domain registration transparency despite the legitimate business presence. No adult or inappropriate content is present, making the site safe for general audiences. Overall, the site is functional, professional, and serves a clear business purpose, but improvements in privacy compliance and domain registration transparency would enhance trust and security posture.

20
53
17
70
67
65
100
legalnoticespublicnoticescaliforniaclassifiedsgovernment+1 more
jQueryjQuery UIBootstrap 5Select2+6
2025-07-28T20:35:24.113Z
loebschool.org favicon

The Nackey S. Loeb School of Communications

loebschool.org

55
Non-profitUnited StatessmallMEDIUM

The Nackey S. Loeb School of Communications is a well-established non-profit organization founded in 1999, dedicated to promoting and defending the First Amendment through education, free classes, workshops, and events. The organization targets students, journalists, nonprofits, and the general public interested in communications and constitutional rights. Their business model focuses on providing free and affordable educational services, private trainings, and hosting annual events such as the First Amendment Award. The website reflects a consistent brand and professional presence with clear contact information and social media integration. Technically, the website is built on the Squarespace platform, leveraging modern web technologies including Google reCAPTCHA Enterprise for form security and Typekit fonts for typography. The site is mobile-optimized and performs moderately well, with good SEO practices and accessibility features. However, there is room for improvement in security configurations, such as enabling DNSSEC and HSTS headers to enhance domain and transport security. From a security perspective, the site uses HTTPS with a valid certificate and employs domain locking to prevent unauthorized transfers. The presence of Google reCAPTCHA Enterprise adds protection against automated abuse. Nonetheless, the absence of a published privacy policy, terms of service, incident response, or vulnerability disclosure pages indicates gaps in compliance and transparency. These should be addressed to improve trust and regulatory adherence. Overall, the website is trustworthy, safe for general audiences, and professionally managed. The domain registration data aligns well with the organization's identity and history, supporting legitimacy. Strategic recommendations include publishing comprehensive privacy and security policies, enhancing DNS and transport security, and establishing clear incident response protocols to strengthen the security posture and compliance.

35
35
17
35
62
75
100
non-profiteducationfirstamendmentjournalismcommunications+3 more
Squarespace CMSGoogle reCAPTCHA EnterpriseTypekit FontsGoogle Fonts+3
2025-07-28T20:35:19.086Z
ghx.com favicon

Global Healthcare Exchange (GHX)

ghx.com

75
HealthcareUnited StatesenterpriseMEDIUM

Global Healthcare Exchange (GHX) is a leading enterprise in healthcare supply chain management, providing cloud-based automation and data analytics solutions to healthcare providers, suppliers, and government entities. Their platform enhances operational efficiency, reduces costs, and improves patient outcomes by streamlining procure-to-pay and order-to-cash processes. GHX positions itself as a trusted partner with over 20 years of experience and a broad network of trading partners. Technically, the website employs modern frameworks such as Bootstrap and jQuery, integrates advanced consent management via Osano, and uses multiple analytics and marketing tools including Google Tag Manager and Marketo. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital presence. Security-wise, the site enforces HTTPS and consent mechanisms but lacks visible security headers and a public incident response or vulnerability disclosure policy. The WHOIS data is unavailable, which slightly impacts trust but is mitigated by strong branding, customer testimonials, and professional content. Overall, GHX demonstrates a robust business and technical foundation with room for security policy enhancements.

65
68
25
83
82
90
100
healthcaresupplychainscmautomationvendorcredentialing+4 more
Bootstrap 5jQuery 3.6.0Font Awesome 4.7.0Revolution Slider+4

Partner Domains:

ghx.my.site.com
partner
app.lumere.com
partner

+3 more partners

2025-07-28T20:35:13.911Z
fluentco.com favicon

Fluent, Inc.

fluentco.com

61
TechnologyUnited StateslargeMEDIUM

Fluent, Inc. is a well-established technology company specializing in commerce media solutions that leverage AI-powered targeting and personalization to maximize monetization and customer engagement. The company serves brands, partners, and advertisers with a comprehensive platform designed to deliver performance-driven advertising and monetization across the customer journey. Their market position is strong, supported by proprietary technology and a large identity graph, with a focus on delivering measurable business outcomes. Technically, the website is built on WordPress with integrations of modern marketing and analytics tools such as HubSpot, Google Tag Manager, LinkedIn Insight Tag, Hotjar, and Optimizely, indicating a mature digital infrastructure. The site is mobile-optimized, accessible, and SEO-friendly, providing an excellent user experience. Security-wise, the site enforces HTTPS, uses domain status protections, and implements cookie consent mechanisms, though it lacks DNSSEC and explicit security policy or incident response pages. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance with privacy regulations, making it a credible and reliable digital presence for Fluent, Inc.

15
80
2
70
57
80
100
commercemediaaitargetingadvertisingmonetizationprivacy+2 more
jQueryHubSpot FormsGoogle Tag ManagerLinkedIn Insight Tag+4

Partner Domains:

investors.fluentco.com
subsidiary
2025-07-28T20:35:03.603Z
plusqa.com favicon

PLUS QA

plusqa.com

56
TechnologyUnited StatesmediumMEDIUM

PLUS QA is a Portland, Oregon-based quality assurance software testing company specializing in onshore testing services. Established in 2008, the company offers a broad range of QA services including functionality, compatibility, accessibility, usability, managed testing, API, payment, automation, and localization testing. Their client base includes notable companies such as Airbnb, Dropbox, Nike, Giphy, and Discord, positioning them as a reputable player in the QA testing market. The company emphasizes the use of real devices in a secure environment and employs US-based professional testers to ensure quality and timely delivery. Technically, the website is built on the Webflow platform and leverages modern technologies such as Google Tag Manager, Google Analytics, Uploadcare, and Botpoison CAPTCHA for spam protection. The site is mobile-optimized, fast-loading, and includes accessibility features. Privacy compliance is addressed through a cookie consent banner integrated with Google Consent Mode, allowing granular user control over data collection. From a security perspective, the site uses HTTPS and implements form validation and bot protection. However, it lacks explicit security headers, a published security policy, and incident response contact information. The absence of WHOIS registration data for the domain is a notable concern, potentially indicating domain registration issues or privacy protection, which slightly impacts trustworthiness. Overall, PLUS QA presents a professional and trustworthy digital presence with strong business credibility and technical maturity. Strategic improvements in security transparency and domain registration verification are recommended to enhance trust and compliance.

30
68
2
45
72
50
100
qatestingaccessibilitytestingonshoretestingsoftwarequalityassurancewebandmobiletesting
Google Tag ManagerGoogle Analytics (gtag.js)jQuery 3.5.1Webflow CMS+4
2025-07-28T20:34:43.269Z
N

National Newspaper Association

nnaweb.org

48
MediaUnited StatesmediumHIGH

The National Newspaper Association (NNA) is a well-established non-profit organization dedicated to supporting and advocating for community newspapers across the United States. Founded in 1885, it offers a broad range of services including government relations, education, industry news, postal consulting, and events such as conventions and webinars. The website reflects a mature digital presence with consistent branding and a clear focus on its target audience of community newspaper publishers, journalists, advertisers, and policy officials. Technically, the website employs a mix of legacy and modern technologies including jQuery, Bootstrap, and Google Analytics. It is hosted via GoDaddy with domain privacy protection enabled. The site is mobile optimized and provides a good user experience, though some technical improvements such as updating outdated libraries and enabling DNSSEC could enhance security and performance. From a security perspective, the site uses HTTPS and domain status protections but lacks DNSSEC and security headers, which are recommended best practices. Privacy compliance is weak due to the absence of explicit privacy and cookie policies, which poses a risk in jurisdictions with strict data protection laws. No incident response or vulnerability disclosure information is provided. Overall, the website is trustworthy and professional, serving a niche non-profit media sector effectively. Strategic improvements in privacy compliance and security hardening would strengthen its posture and user trust.

20
35
2
70
62
75
40
communitynewspapersjournalismnon-profitmediaassociationeducation+4 more
jQuery 1.11.1jQuery UI 1.11.2Google Analytics (gtag.js)Bootstrap 4.3.1+3

Partner Domains:

nnafoundation.org
partner
nnanewslink.creativecirclemedia.com
partner

+3 more partners

2025-07-28T20:34:38.244Z
tfff.org favicon

The Ford Family Foundation

tfff.org

68
Non-profitUnited StatesmediumMEDIUM

The Ford Family Foundation is a well-established non-profit organization dedicated to supporting rural communities in Oregon and Siskiyou County, California. Their primary services include providing grants to organizations serving children, families, and rural communities, as well as scholarships for students facing obstacles to higher education. The foundation also offers research, community building resources, and distributes free SelectBooks to enrich lives. The website reflects a strong market position as a regional leader in rural community development and education support. Technically, the website is built on WordPress using the Divi theme, leveraging modern web technologies such as Google Fonts, jQuery, and Google Tag Manager for analytics. The site is mobile-optimized, accessible, and SEO-friendly, with good performance metrics. Security measures include HTTPS enforcement, security headers, and use of reCAPTCHA on forms, indicating a mature security posture. Security-wise, the site demonstrates good practices with no visible vulnerabilities or exposed sensitive data. However, it lacks a dedicated security policy or vulnerability disclosure page, and incident response contacts are not publicly listed. Privacy compliance is strong, with clear privacy and cookie policies and GDPR adherence. Contact information is primarily via contact forms and social media, with no explicit company emails or phone numbers publicly listed. Overall, the website is professional, trustworthy, and well-maintained, supporting the foundation's mission effectively. Recommendations include publishing a formal security policy, adding vulnerability disclosure information, and enhancing transparency around incident response to further strengthen trust and security posture.

30
65
25
80
75
85
100
non-profitgrantsscholarshipscommunityeducation+3 more
WordPressDivi ThemejQueryGoogle Fonts+2
2025-07-28T20:33:42.860Z
travelmediagroup.com favicon

Travel Media Group

travelmediagroup.com

58
HospitalityUnited StatesmediumMEDIUM

Travel Media Group is a specialized hospitality marketing agency focused on improving online marketing and reputation management for hotels and hotel management companies. With over 30 years of industry experience, they provide guest feedback solutions, social media content creation, and reputation management services powered by their proprietary OneView® platform. The company targets mid to large hotel brands and management companies, positioning itself as a trusted partner with a portfolio of elite hotel clients including Hilton, Marriott, and IHG. Technically, the website is built on WordPress with a modern tech stack including Divi theme, jQuery, and various marketing and analytics tools such as Pardot and Google Tag Manager. Privacy compliance is robust with a comprehensive privacy policy and cookie consent managed by OneTrust. Security posture is good with HTTPS and reCAPTCHA implemented, though explicit security policies and incident response contacts are not published. The absence of WHOIS data is a concern and reduces domain trustworthiness, but the professional presentation and client endorsements mitigate this risk. Overall, the website demonstrates a mature digital presence with strong business credibility and compliance, suitable for its B2B hospitality market.

15
53
2
65
62
85
100
hospitalityhotelmarketingreputationmanagementguestfeedbacksocialmedia+1 more
WordPressDivi ThemejQueryMediaElement.js+6

Partner Domains:

tmgoneview.com
partner
2025-07-28T20:33:17.390Z
R

RevPAR Collective, Inc.

stashrewards.com

68
HospitalityUnited StatesmediumMEDIUM

Stash Rewards operates a loyalty program focused on independent and boutique hotels, offering travelers the ability to earn points redeemable for free nights at unique properties across North America and the Caribbean. The company positions itself as a top-rated loyalty program for discerning travelers who prefer authentic, non-chain hotel experiences. The website is professionally designed with clear navigation, mobile optimization, and integrated social media and marketing tools, reflecting a mature digital presence. Technically, the site leverages modern web technologies including React, Google Analytics, Facebook Pixel, and Sentry for error tracking. The use of HTTPS and cookie consent mechanisms indicates attention to security and privacy compliance, although explicit security headers and incident response policies are not evident. The absence of WHOIS data for the domain is a notable anomaly that impacts trustworthiness, though the website content and business information appear legitimate and professional. Security posture is generally good with encrypted communications and monitoring tools, but could be improved by publishing security policies, implementing security headers, and establishing a vulnerability disclosure program. Overall, the site presents a trustworthy and user-friendly platform for its target audience, but domain registration transparency should be addressed to enhance credibility.

60
68
2
85
67
85
100
loyaltyboutiquehotelstravelrewardsindependenthotels+1 more
Google Tag ManagerGoogle Analytics (gtag.js)Facebook PixelRaven.js (Sentry for error tracking)+3
2025-07-28T20:28:28.680Z
delawarevalleyjournal.com favicon

InsideSources, LLC

delawarevalleyjournal.com

57
MediaUnited StatessmallMEDIUM

Delaware Valley Journal is a regional news publication operating under the InsideSources network, providing news, opinion, and analysis focused on politics, energy, technology, finance, and education. The website targets a general audience interested in Delaware Valley regional affairs and political commentary. Its business model relies on advertising revenue and newsletter subscriptions, positioning itself as a credible regional media outlet founded in 2020. Technically, the website is built on WordPress 6.1.1 with a modern tech stack including jQuery, Google Tag Manager, and multiple ad networks. Hosting appears to be supported by GoDaddy with Cloudflare DNS services. The site demonstrates moderate performance and good mobile optimization, with basic accessibility and SEO optimizations in place. From a security perspective, the site uses HTTPS and Cloudflare DNS but lacks DNSSEC and explicit security headers, which are recommended improvements. No sensitive data exposure or critical vulnerabilities were detected. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism despite use of tracking technologies. Contact information is limited to a contact form and social media links, with no direct emails or phone numbers published. Overall, the website is a legitimate, moderately secure, and professionally maintained regional news outlet with room for improvement in security hardening and privacy compliance to enhance trust and user protection.

15
58
17
40
75
75
100
newspoliticsenergytechnologyfinance+3 more
WordPress 6.1.1jQueryGoogle Tag ManagerGoogle Analytics+2

Partner Domains:

insidesources.com
parent
nhjournal.com
sister

+1 more partners

2025-07-28T19:27:56.480Z