Skip to main content

E-commerce security reports

Browse 3,261 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 11 of 66|Showing 501-550 of 3261
covet.pics favicon

Space Squirrel Ltd.

covet.pics

57
E-commerceN/asmallMEDIUM

Covet.pics is a specialized Shopify app developed by Space Squirrel Ltd. that offers merchants customizable, shoppable galleries integrating Instagram feeds, user-generated content, and product galleries to enhance e-commerce conversion rates. The website positions itself as a niche solution within the Shopify ecosystem, targeting store owners seeking to improve visual merchandising and customer engagement through galleries. The business model is subscription-based with tiered pricing plans, reflecting a SaaS approach tailored for small to medium-sized e-commerce businesses. Technically, the website is built on Webflow CMS and leverages modern web technologies including Google Analytics, Google Tag Manager, and Google reCAPTCHA for analytics and security. Hosting and DNS services are provided via Cloudflare and Webflow, ensuring good performance and availability. The site is mobile optimized and demonstrates good SEO practices, although accessibility features are basic. No major technical debt or vulnerabilities were detected in the frontend code. From a security perspective, the site enforces HTTPS and uses reCAPTCHA to protect forms, but lacks explicit security headers and published security or incident response policies. The domain registration is consistent and trustworthy, with no privacy protection masking ownership, and domain age aligns with the business founding date. However, the absence of privacy and cookie policies and lack of GDPR compliance indicators represent compliance gaps. Overall, the security posture is moderate but could be improved with additional policies and technical controls. The overall risk assessment is low to moderate, with no signs of malicious activity or suspicious content. Strategic recommendations include implementing privacy and cookie policies with consent mechanisms, enabling DNSSEC, adding security headers, and publishing incident response contacts to enhance trust and compliance. These improvements will strengthen the security posture and regulatory compliance, supporting business credibility and customer confidence.

30
35
2
60
72
80
100
shopifye-commercegalleryinstagramusergeneratedcontent+1 more
WebflowGoogle AnalyticsGoogle Tag ManagerGoogle reCAPTCHA+1
2025-10-23T19:14:43.272Z
logbase.io favicon

Logbase

logbase.io

63
E-commerceN/amediumMEDIUM

Logbase is a technology company specializing in developing Shopify apps designed to help e-commerce businesses grow by increasing sales, improving customer engagement, and streamlining logistics. Their product suite includes apps for upselling, shipping rate calculation, local delivery scheduling, appointment booking, volume discounts, and preorder management. The company targets Shopify store owners and e-commerce businesses, positioning itself as a popular and trusted app provider with a substantial customer base and positive user reviews. Technically, Logbase's website is built on the Webflow platform, leveraging modern web technologies such as Google Fonts, jQuery, and integration with third-party services like Tawk.to for live chat and Google Analytics for tracking. The site is well-optimized for performance, mobile responsiveness, and SEO, providing an excellent user experience with clear navigation and professional design. From a security perspective, the website enforces HTTPS and includes domain verification mechanisms for Google and Facebook, indicating a baseline of security hygiene. However, it lacks explicit security headers and published security policies or incident response contacts, which are areas for improvement. The absence of a cookie consent mechanism also suggests partial GDPR compliance. Overall, Logbase presents a low-risk profile with strong business credibility and technical maturity. The main limitation is the lack of publicly available WHOIS data due to privacy protection, which slightly reduces domain trust verification. Strategic recommendations include enhancing security transparency, implementing cookie consent, and publishing incident response information to further strengthen trust and compliance.

60
53
2
70
62
75
100
shopifye-commercesaasappsupsell+5 more
WebflowGoogle FontsjQuery 3.5.1Tawk.to live chat+2
2025-10-23T13:56:11.495Z
cartloom.com favicon

Cartloom

cartloom.com

66
E-commerceUnited StatessmallMEDIUM

Cartloom is a specialized ecommerce platform founded in 2007, offering easy-to-integrate shopping cart solutions and hosted storefronts for selling physical and digital products. The company targets website owners and online sellers seeking quick ecommerce enablement with minimal technical overhead. Cartloom maintains a niche market position with a focus on simplicity, digital goods delivery, and integration with major payment processors such as PayPal, Stripe, and AuthorizeNet. The website demonstrates strong branding consistency, professional design, and clear navigation, supporting a positive user experience. Technically, Cartloom employs modern frontend technologies including AlpineJS and uses privacy-conscious analytics via Fathom. The site is mobile-optimized and performs well, with good SEO and accessibility features. However, there is no detected CMS or explicit hosting provider information. The domain is well aged and consistent with the business history, registered since 2007 with no privacy protection, indicating transparency. From a security perspective, the site enforces HTTPS and has domain transfer protections but lacks DNSSEC and security headers such as Content-Security-Policy or X-Frame-Options. No explicit security or incident response policies are published, and no vulnerability disclosure or security.txt files are found. Privacy compliance is basic; a privacy policy and terms of service exist but lack explicit GDPR compliance statements and no cookie consent mechanism is present. Contact information is not explicitly provided on the site, which may impact user trust. Overall, Cartloom presents a professional and trustworthy ecommerce platform with solid technical foundations and a clear business model. To enhance security posture and privacy compliance, the company should implement security headers, cookie consent, GDPR statements, and publish incident response and vulnerability disclosure policies. Adding clear contact information would further improve business credibility and user trust.

40
53
2
85
77
85
100
ecommerceshoppingcartdigitalgoodsonlinestorepayments+3 more
AlpineJSFathom AnalyticsSVG graphicsCustom CSS

Partner Domains:

paypal.com
partner
stripe.com
partner

+2 more partners

2025-10-23T11:57:11.015Z
olirecords.com favicon

OLI Records

olirecords.com

74
E-commerceUnited KingdomsmallMEDIUM

OLI Records is an independent record label with a digital presence focused on selling music records and merchandise through an e-commerce platform powered by Shopify. The website showcases a curated catalogue of artists and releases, targeting music enthusiasts and vinyl collectors. The business has a consistent brand identity and a clear market niche in independent music. Technically, the website leverages modern e-commerce technologies including Shopify's Dawn theme, integrates marketing and analytics tools such as Mailchimp and Google Analytics, and is hosted on Shopify's infrastructure with Cloudflare DNS. The site is well-optimized for performance, mobile responsiveness, and accessibility. Security posture is solid with HTTPS enforced and standard security headers likely in place, though DNSSEC is not enabled and explicit security policies are absent. Privacy compliance is addressed with a cookie consent banner and a privacy policy, indicating GDPR awareness. However, direct contact information such as emails or phone numbers is not publicly listed, relying on a contact form instead. Overall, the website is professional, trustworthy, and well-maintained, with minor areas for improvement in security transparency and contact accessibility.

75
85
17
75
75
80
100
musicrecordsindependentlabele-commercevinyl+1 more
ShopifyJavaScriptCloudflare DNSReqwest (XHR library)+5

Partner Domains:

onelittleindierecords.com
partner
2025-10-23T09:14:49.165Z
feedr.co.uk favicon

GoDaddy Operating Company, LLC

feedr.co.uk

73
E-commerceUnited StatesenterpriseMEDIUM

The website is a domain sales landing page hosted by GoDaddy, offering the domain feedr.co.uk for sale. It leverages GoDaddy's trusted brand and domain brokerage services to facilitate secure and straightforward domain acquisitions. The platform targets businesses and individuals seeking premium domain names, providing options such as buy now and lease to own. The site integrates partner services like Afternic and Trustpilot to enhance trust and customer confidence. Technically, the site is built using modern web technologies including React and Next.js, hosted on GoDaddy's infrastructure. It demonstrates good performance, mobile optimization, and basic accessibility features. The presence of secure HTTPS and secure payment messaging indicates a mature digital infrastructure, although explicit security headers are not detected. From a security perspective, the site shows a strong posture with HTTPS enforcement and no visible vulnerabilities or exposed sensitive data. However, it lacks explicit security policies and incident response information, which could be improved to enhance compliance and user trust. Privacy and cookie policies are present but basic, with GDPR compliance implied but not explicitly detailed. Overall, the site is legitimate and trustworthy, operated by a well-known domain registrar. The lack of WHOIS data for the subdomain is expected and does not detract from legitimacy. Strategic recommendations include enhancing security headers, expanding privacy and security policy disclosures, and improving accessibility and SEO metadata to further strengthen the platform's professionalism and compliance.

65
50
17
87
100
85
100
domainsalesgodaddypremiumdomaine-commercetrusted+1 more
React (Next.js)JavaScriptCSSWeb fonts (GDSherpa)+1

Partner Domains:

afternic.com
partner
trustpilot.com
partner

+1 more partners

2025-10-23T05:23:50.269Z
reservix.de favicon

Reservix GmbH

reservix.de

68
E-commerceGermanymediumMEDIUM

Reservix GmbH operates a well-established online ticketing platform primarily serving the German market. The website offers a broad range of event tickets including concerts, sports, musicals, and family events. The platform targets general consumers seeking convenient online ticket purchases and event information. The business model is e-commerce focused, with additional services such as voucher sales and event promotion. The company demonstrates consistent branding and maintains a professional online presence with good content quality and user experience. Technically, the website leverages modern JavaScript frameworks including React and Swiper.js for UI components, and integrates Google Tag Manager and Usercentrics for marketing and consent management. Hosting is provided via Amazon AWS, indicated by the DNS infrastructure. The site is mobile optimized and accessible, with good SEO practices and structured data for enhanced search engine visibility. From a security perspective, the site enforces HTTPS and uses a consent management platform to comply with GDPR. However, explicit security headers are not evident in the HTML content, and no published security or incident response policies were found. No vulnerabilities or exposed sensitive data were detected. The WHOIS data aligns with a legitimate business, showing no privacy protection and consistent domain registration. Overall, Reservix.de presents a secure, professional, and user-friendly ticketing portal with strong compliance and marketing practices. Strategic improvements could include publishing explicit security policies and enhancing HTTP security headers to further strengthen the security posture.

70
45
2
75
100
70
100
ticketingeventsconcertssportsecommerce+1 more
JavaScriptReactSwiper.jsGoogle Tag Manager+2
2025-10-23T03:02:35.009Z
whereisthebeastmaster.com favicon

candu123

whereisthebeastmaster.com

51
E-commerceFrancesmallMEDIUM

The website 'whereisthebeastmaster.com' operates as an e-commerce platform primarily focused on selling online gaming and gambling-related products under the brand 'Candu123'. It targets a mature audience interested in gaming and gambling, offering affiliate marketing and live chat support. The site is localized with Indonesian language content but claims a physical location in Paris, France. The business model revolves around online sales and affiliate links, with a modest market presence and a small-scale operation impression. Technically, the site employs a modern but basic technology stack including jQuery, Bootstrap, Font Awesome, and several UI libraries. It shows moderate performance and good mobile optimization but lacks advanced SEO and accessibility features. The site does not appear to use a known CMS and lacks clear hosting provider information. The design and user experience are functional but basic. From a security perspective, the site uses HTTPS but lacks critical security headers and published security policies. There is no visible privacy or cookie policy, and no incident response or vulnerability disclosure information is provided. The WHOIS data is privacy protected, reducing transparency and trust. The site uses multiple external domains for assets and affiliate links, some of which appear suspicious or unrelated, which may pose risks. Overall, the website presents moderate risks due to limited transparency, lack of security best practices, and gambling-related content which is regulated and sensitive. Strategic improvements in security posture, privacy compliance, and business transparency are recommended to enhance trust and compliance.

15
35
2
60
75
75
100
gaminggamblinge-commerceslotonline+1 more
jQuery 3.5.1Bootstrap 4.4.1Font Awesome 6.5.1Select2 4.1.0-beta.1+4

Partner Domains:

cutt.ly
partner
2025-10-22T20:46:33.858Z
worldscoutshops.com favicon

The Scout Association

worldscoutshops.com

60
E-commerceUnited KingdommediumMEDIUM

The website shop.scouts.org.uk/world-scout-shops serves as the official e-commerce platform for The Scout Association, offering a wide range of scouting merchandise including uniforms, badges, camping gear, and personalized items. The site targets Scouts, leaders, volunteers, and supporters, positioning itself as a trusted and official source for Scout-related products in the United Kingdom. The business model is primarily retail-focused, leveraging an online storefront to reach its audience effectively. Technically, the website is built using modern web technologies including Angular 17 and TypeScript, with rich interactive components such as carousels powered by Swiper.js. The site employs Google Tag Manager and cookie consent mechanisms to manage analytics and privacy compliance. The infrastructure appears well-maintained with HTTPS enforced and multiple security headers present, indicating a mature digital presence. From a security perspective, the site demonstrates good practices including secure forms, no visible vulnerabilities, and cookie consent management. However, the absence of explicit privacy policy and terms of service pages in the provided content suggests areas for improvement in compliance and transparency. No WHOIS data is available for the subdomain due to .uk domain naming rules, but the site’s branding and content strongly indicate legitimacy. Overall, the site presents a professional, secure, and user-friendly experience with a strong brand association to The Scout Association. Strategic recommendations include publishing comprehensive privacy and terms policies, enhancing contact transparency, and continuous monitoring of third-party scripts to maintain security posture.

35
35
2
80
75
70
100
scoutinge-commerceretailuniformsbadges+3 more
Angular 17TypeScriptSwiper.js carouselGoogle Tag Manager+1
2025-10-22T20:44:07.468Z
croissance-verte.net favicon

Candu123

croissance-verte.net

52
E-commerceFrancesmallMEDIUM

The website 'Candu123' operates as an online gaming agent platform primarily targeting users interested in gambling and gaming services. It offers products and services related to online gaming with claims of official PAGCOR licensing, positioning itself as a niche player in the online gaming e-commerce sector. The business appears small and relatively new, founded in 2019, with a physical address claimed in Paris, France. The website content is accessible and moderately structured but lacks comprehensive privacy and security policies, which impacts its trustworthiness. Technically, the site uses a modern but basic technology stack including Bootstrap, jQuery, and several popular JavaScript libraries for UI and interactivity. Hosting is supported by Cloudflare DNS, and HTTPS is enabled, but security headers and advanced security practices are missing. The site shows moderate performance and mobile optimization but has SEO and accessibility only at a basic level. From a security perspective, the site has some strengths such as HTTPS and Cloudflare DNS but lacks critical security headers and explicit data protection compliance. The absence of privacy and cookie policies, as well as incident response contacts, indicates compliance gaps. The use of multiple external and shortened URLs, some unrelated to the main domain, raises concerns about transparency and potential phishing risks. Overall, the website presents moderate risk with questionable content safety due to its gambling-related services and lack of robust privacy and security measures. Strategic improvements in security posture, privacy compliance, and clearer business information are recommended to enhance trust and reduce risk.

15
35
2
60
75
75
100
onlinegaminggamblinge-commercepagcorindonesia+1 more
jQueryBootstrap 4.4.1Font Awesome 6.5.1Select2 4.1.0-beta.1+4

Partner Domains:

cutt.ly
partner
whereisthebeastmaster.com
partner
2025-10-22T17:29:36.658Z
shopperapproved.com favicon

Shopper Approved

shopperapproved.com

65
E-commerceN/amediumMEDIUM

Shopper Approved is a professional ecommerce SaaS platform specializing in growth tools that enhance traffic, sales, and conversions through trust signals, user-generated content, and social proof. The company holds a strong market position as a highly rated review platform and is one of the few Google and Bing review partners worldwide. Their key services include store and product ratings, video reviews, reputation management, Q&A software, and website security solutions tailored for ecommerce businesses. Technically, the website is built on modern frameworks such as Bootstrap and integrates with HubSpot for forms and marketing automation. It employs Google Tag Manager and tracking pixels for analytics and retargeting, demonstrating a mature digital infrastructure. The site is mobile-optimized, accessible, and SEO-friendly, providing a high-quality user experience. From a security perspective, the site uses HTTPS and secure form handling but lacks explicit security headers and a public vulnerability disclosure policy. No WHOIS data was found, which is unusual and slightly reduces trust, but the overall professionalism and trust indicators on the site mitigate this concern. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Overall, Shopper Approved presents a low-risk profile with strong business credibility and technical maturity. Strategic improvements in security headers, incident response transparency, and WHOIS data visibility would further enhance trust and compliance.

45
68
2
85
47
85
100
ecommercereviewstrustsignalssocialproofconversionoptimization+2 more
Bootstrap 5Google Fonts (Roboto, Poppins)FontAwesomeHubSpot forms+3

Partner Domains:

marketplace.shopperapproved.com
partner
villageimpact.com
partner
2025-10-22T13:55:31.360Z