Skip to main content

Government security reports

Browse 7,671 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 149 of 154|Showing 7401-7450 of 7671
M

Mölndals stad

molndal.se

54
GovernmentSwedenmediumMEDIUM

Mölndals stad operates as the official municipal government website for the city of Mölndal, Sweden. It provides residents and visitors with comprehensive information about municipal services, events, job opportunities, and contact channels. The website serves as a central hub for public communication and e-services, reflecting a medium-sized government entity with a clear focus on accessibility and user engagement. The site is well-branded and consistent with municipal identity, targeting local citizens and stakeholders. Technically, the website leverages a modern technology stack including SiteVision CMS, React, and multiple analytics platforms such as Piwik PRO and Vizzit. The infrastructure supports responsive design, accessibility features, and performance optimizations suitable for a government portal. The use of nonce attributes in scripts and secure cookie flags indicates attention to security best practices. From a security perspective, the site enforces HTTPS, employs cookie consent mechanisms, and integrates analytics with privacy compliance in mind. However, it lacks explicit published security policies or incident response information, which could be improved to enhance transparency and readiness. No critical vulnerabilities or blocking mechanisms were detected, and the WHOIS data confirms the legitimacy and consistency of the domain registration. Overall, Mölndals stad's website demonstrates a solid digital presence with good content quality, technical implementation, and privacy compliance. Strategic enhancements in security policy publication and incident response communication would further strengthen its security posture and user trust.

75
15
-
85
-
75
100
governmentmunicipalitypublicservicesswedenmlndal+3 more
JavaScriptjQueryReact 18.3.1SiteVision CMS+3
2025-06-18T08:55:47.851Z
uppsala.se favicon

Uppsala kommun

uppsala.se

48
GovernmentSwedenlargeHIGH

Uppsala kommun operates as the official municipal government website for the city of Uppsala, Sweden. It provides comprehensive information about municipal services including education, social care, culture, traffic, building permits, and political governance. The site targets residents, businesses, and visitors, offering resources such as job listings, event information, and contact channels. The business model is public sector service provision, with a strong emphasis on transparency and accessibility. Technically, the website is built on the EPiServer CMS Falcon platform, utilizing Bootstrap 3.3.7 and jQuery for frontend components. It integrates Matomo analytics for user tracking and employs modern web standards including responsive design and accessibility features. The site is served over HTTPS with a good security posture, including cookie consent mechanisms and no detected vulnerabilities. Security-wise, the site demonstrates good practices such as HTTPS enforcement, cookie consent, and no exposed sensitive data. However, it lacks explicit published security policies or incident response contacts. No critical vulnerabilities or suspicious patterns were found, and WHOIS data confirms the legitimacy and consistency of the domain registration. Overall, the website is professional, trustworthy, and well-maintained, suitable for its role as a municipal information portal. Strategic improvements could include enhanced security headers and publishing formal security and incident response policies to further strengthen trust and compliance.

30
-
-
98
-
70
100
municipalitygovernmentpublicservicesuppsalasweden+3 more
Bootstrap 3.3.7jQueryRequireJSMatomo Analytics+1

Partner Domains:

kubikuppsala.se
partner
destinationuppsala.se
partner
2025-06-18T08:55:47.171Z
skatteverket.se favicon

Skatteverket

skatteverket.se

57
GovernmentSwedenenterpriseMEDIUM

Skatteverket is the official Swedish Tax Agency responsible for tax collection, population registration, and related public services. The website serves a broad audience including private individuals, companies, associations, and public actors. It provides comprehensive information, e-services, and guidance related to taxation and population matters. The agency holds a strong national position as a government authority with monopoly over these services in Sweden. Technically, the website is built on the SiteVision CMS platform, utilizing jQuery and Matomo analytics for privacy-conscious user tracking. The site is well-optimized for mobile devices and accessibility, with good SEO practices and a moderate performance profile. Security is robust with HTTPS enforced, secure login via SSO, and a cookie consent mechanism, although some security headers are not explicitly detected. The security posture is strong with no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies, and GDPR compliance indicators. Contact information is provided primarily via phone, with no direct email addresses listed on the main page. The domain registration details align perfectly with the official agency, confirming legitimacy and trustworthiness. Overall, the website demonstrates a mature digital presence with good security and privacy practices, serving as a reliable portal for Swedish tax and population services.

85
15
-
83
-
90
100
governmenttaxswedenprivacycookie-consent+2 more
jQuerySiteVision CMSMatomo Analytics
2025-06-18T08:55:47.150Z
S

Stockholms stad

stockholm.se

58
GovernmentSwedenlargeMEDIUM

Stockholms stad operates an official municipal website serving over 960,000 residents and approximately 40,000 employees. The website provides comprehensive access to city services, including education, family support, cultural activities, traffic information, and business resources. It targets residents, businesses, and visitors, positioning itself as the authoritative digital portal for Stockholm city government. The site is well-branded, professionally designed, and offers clear navigation and accessibility features. Technically, the website employs modern web technologies including JavaScript, SVG icons, React components, and Piwik PRO analytics. The presence of Episerver CMS is inferred from script paths. The site is mobile-optimized and demonstrates good SEO and accessibility practices. Performance is moderate, with asynchronous script loading and structured content. From a security perspective, the site enforces HTTPS, uses cookie consent mechanisms with granular controls, and avoids exposing sensitive data. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not found. Security headers are not explicitly detected in the HTML content, suggesting room for improvement. Overall, the website is trustworthy, professionally maintained, and compliant with GDPR requirements. The domain registration data aligns with the official city ownership, reinforcing legitimacy. No blocking or WAF interference was detected, allowing full content access and analysis.

95
15
-
92
-
75
100
governmentmunicipalstockholmpublicservicessweden+1 more
JavaScriptSVG iconsPiwik PRO analyticsReact (react-components.js)+2
2025-06-18T08:55:47.082Z
jekabpils.lv favicon

Jēkabpils novada pašvaldība

jekabpils.lv

49
GovernmentLatviamediumHIGH

Jēkabpils novada pašvaldība is the official municipal government entity for the Jēkabpils region in Latvia. The website serves as a comprehensive portal providing residents, businesses, and visitors with access to government services, news, projects, and contact information. It positions itself as a central hub for local governance and community engagement. The site includes detailed navigation, multiple service categories, and links to partner organizations and social media channels, reflecting a mature digital presence for a government entity. Technically, the website is built on the Drupal CMS platform, utilizing standard web technologies such as Bootstrap and jQuery. It is mobile-optimized and includes accessibility features, cookie consent mechanisms, and Google Analytics for user tracking. The performance is moderate, with room for optimization. Security practices include HTTPS enforcement and cookie consent, but lack explicit security headers and incident response disclosures. From a security perspective, the site demonstrates a reasonable posture with no critical vulnerabilities detected in the HTML content. However, improvements are recommended in implementing security headers and publishing formal security policies. Privacy compliance is strong, with GDPR-aligned cookie consent and a comprehensive privacy policy in Latvian. Contact information is clearly presented, enhancing trust and transparency. Overall, the website is a well-structured, professional government portal with good content quality and compliance. The domain registration details align with the municipal government entity, supporting legitimacy. Strategic recommendations include enhancing security headers, formalizing incident response information, and continuous monitoring of third-party scripts to maintain security and trust.

50
-
5
85
-
70
100
governmentmunicipalitypublicserviceslatviadrupal+3 more
Drupal CMSGoogle AnalyticsBootstrapjQuery

Partner Domains:

jekabpilsudens.lv
partner
jekabpils-siltums.lv
partner

+3 more partners

2025-06-18T08:51:56.870Z
public-i.tv favicon

Public-i Group Ltd

public-i.tv

61
GovernmentUnited KingdommediumMEDIUM

Public-i Group Ltd is a well-established provider specializing in live streaming, remote and hybrid meetings, audio-visual solutions, and event webcasting primarily for local government entities in the United Kingdom. With over two decades of experience since its founding in 2000, Public-i has positioned itself as a market leader offering comprehensive, scalable, and integrated solutions that enhance meeting accessibility, transparency, and engagement. Their product suite includes Connect Webcasting, HybridLink, SpaceManager, CameraControl, and Connect Remote, all designed to streamline meeting management and digital audience reach. Technically, the website is built on a modern WordPress platform utilizing popular plugins and libraries such as WPBakery Page Builder, jQuery, Google reCAPTCHA, and Cookiebot for consent management. The site demonstrates good performance, mobile optimization, and accessibility features, reflecting a mature digital infrastructure. Security measures include HTTPS enforcement, reCAPTCHA integration, and comprehensive cookie consent mechanisms, contributing to a strong security posture. The security evaluation reveals a robust implementation of best practices, including secure forms, no exposed sensitive data, and use of recognized certifications like ISO 9001 and Cyber Essentials. However, the absence of a public incident response page and security.txt file suggests areas for improvement in transparency and vulnerability management. Overall, Public-i presents a professional, trustworthy, and compliant online presence with clear contact channels, detailed policies, and strong trust indicators. The domain registration details align well with the business claims, reinforcing legitimacy. Strategic recommendations include enhancing vulnerability disclosure, publishing incident response procedures, and continuous monitoring of third-party integrations to maintain security and compliance.

25
83
25
85
77
85
20
livestreaminghybridmeetingsremotemeetingsaudiovisuallocalgovernment+2 more
WordPressWPBakery Page BuilderjQueryGoogle reCAPTCHA+3
2025-06-18T08:21:25.135Z
gov.je favicon

States of Jersey

gov.je

71
GovernmentJerseylargeMEDIUM

The Government of Jersey website serves as the official digital portal for the States of Jersey, providing comprehensive information and public services to residents and visitors of the island. It offers a wide range of services including tax filing, job listings, consultations, news updates, and access to government departments. The site is well-positioned as the authoritative source for government-related information in Jersey, targeting a broad audience that includes citizens, businesses, and tourists. Technically, the website leverages a mature infrastructure based on Microsoft SharePoint, enhanced with modern web technologies such as jQuery, Bootstrap, and Google Tag Manager. It integrates multiple third-party services for analytics, cookie consent management, and performance monitoring. The site demonstrates good mobile optimization, accessibility features, and SEO practices, reflecting a solid digital maturity. From a security perspective, the site enforces HTTPS, employs CSRF protection, and uses a cookie consent mechanism compliant with GDPR. However, it lacks publicly available dedicated security policies or incident response information, which could be improved to enhance transparency and trust. No critical vulnerabilities or security issues were detected in the content analyzed. Overall, the website presents a trustworthy and professional government portal with strong compliance to privacy and accessibility standards. Strategic recommendations include publishing explicit security and incident response policies, implementing a vulnerability disclosure program, and enhancing security headers to further strengthen the security posture.

85
88
25
58
62
65
100
governmentpublicservicesjerseytaxconsultations+3 more
jQuery 3.4.1Google Tag ManagerCookiebotTypekit Fonts

Partner Domains:

blog.gov.je
partner
id.gov.je
partner

+3 more partners

2025-06-18T08:18:11.728Z
B

Bank of England

bankofengland.co.uk

54
GovernmentUnited KingdomlargeMEDIUM

The Bank of England website serves as the official digital presence of the UK's central bank, providing comprehensive information on monetary policy, financial stability, banknotes, and regulatory functions. It targets a broad audience including UK residents, financial institutions, researchers, and policymakers. The site offers authoritative content with a clear mission to promote monetary and financial stability in the UK. The business model is government-centric, focusing on public service and regulatory oversight, positioning the Bank of England as a key institution in the UK's financial ecosystem. Technically, the website employs modern web technologies including JavaScript, CSS, service workers, and integrates with Akamai CDN for hosting and performance optimization. It uses Google Tag Manager and Akamai mPulse for analytics and performance monitoring. The site is well optimized for mobile devices, accessible, and SEO-friendly, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS, uses service workers for caching, and implements cookie consent mechanisms. However, explicit security headers and a published security policy or incident response contacts are absent. No vulnerabilities or exposed sensitive data were detected. The WHOIS data confirms the legitimacy and consistency of the domain registration with the Bank of England's identity. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance with privacy regulations. Strategic recommendations include enhancing security headers, publishing a security policy, and adding vulnerability disclosure information to further strengthen security posture and transparency.

30
63
-
80
-
70
100
bankingcentralbankfinancegovernmentmonetarypolicy+3 more
JavaScriptCSSHTML5Service Workers+3

Partner Domains:

bankunderground.co.uk
partner
2025-06-18T08:07:10.426Z
villagaiety.com favicon

VillaGaiety

villagaiety.com

55
GovernmentIsle of ManmediumMEDIUM

VillaGaiety is a government-operated entertainment venue management organization based on the Isle of Man, managing premier cultural sites such as the Villa Marina and Gaiety Theatre. The website serves as a comprehensive portal for event information, ticketing, venue hire, and visitor information, targeting local residents and visitors interested in arts and entertainment. The business model revolves around event hosting, ticket sales, and venue services, positioning VillaGaiety as a leading cultural institution on the island. Technically, the website employs a mature technology stack including jQuery, Google Tag Manager, Facebook Pixel, and integrates with the Ticketsolve platform for ticketing. The site is moderately performant, mobile-optimized, and includes accessibility features, though some improvements could be made. SEO practices are good with proper meta tags and structured navigation. From a security perspective, the site uses HTTPS and implements cookie consent mechanisms, but lacks explicit security headers and documented security policies. No vulnerabilities or exposed sensitive data were detected in the HTML content. Privacy compliance is well addressed with clear privacy and cookie policies, and GDPR compliance indicators are present. Overall, the website is professional, trustworthy, and well-aligned with its government affiliation. Recommendations include enhancing security headers, documenting security policies, and improving accessibility compliance to further strengthen the security posture and user experience.

65
58
5
70
-
60
100
entertainmenttheatrecinemaculturearts+4 more
jQueryjQuery UIGoogle Tag ManagerGoogle Analytics+3

Partner Domains:

villagaiety.ticketsolve.com
partner
jobtrain.co.uk
partner
2025-06-18T08:07:09.722Z
capita.com favicon

Capita plc

capita.com

58
GovernmentUnited KingdomenterpriseMEDIUM

Capita plc is a leading international business process outsourcing and customer experience professional services company, primarily serving government and private sectors in the UK and Europe. The company offers a broad range of services including consulting, digital transformation, workforce development, and technology-enabled business process services. Their market position is strong, with a focus on delivering innovative solutions to improve operational efficiency and customer engagement. Technically, the website is built on Drupal CMS and integrates multiple modern marketing and analytics tools such as Google Analytics, Facebook Pixel, LinkedIn Insight Tag, and Pardot. The site is well-optimized for mobile devices, accessible, and demonstrates good SEO practices. Performance is moderate, with extensive use of third-party scripts. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms compliant with GDPR. While explicit security headers are not fully visible, no critical vulnerabilities or exposed sensitive data were detected. The absence of a public incident response or vulnerability disclosure page is noted. Overall, the website reflects a mature digital presence with strong business credibility and compliance posture. The domain registration details align with the company's UK base, supporting legitimacy. Strategic recommendations include enhancing security header implementation, publishing incident response contacts, and adding a security.txt file to improve transparency and vulnerability management.

40
60
13
80
-
85
100
businessprocessoutsourcingcustomerexperiencegovernmentservicesdigitaltransformationconsulting+2 more
Google Tag ManagerGoogle AnalyticsFacebook PixelLinkedIn Insight Tag+8
2025-06-18T08:07:09.466Z
د

دائرة التنمية الاقتصادية - عجمان

ajmanded.ae

46
GovernmentUnited Arab EmirateslargeHIGH

The Ajman Economic Development Department (AjmanDED) website serves as the official government portal for economic development activities in the Emirate of Ajman, UAE. It provides comprehensive services including business licensing, consumer protection, investment facilitation, and public information dissemination. The site targets investors, businesses, and consumers within Ajman, positioning itself as a key enabler of economic growth and regulatory compliance in the region. The business model is government-driven, focusing on service delivery and regulatory oversight. Technically, the website employs a modern technology stack with popular JavaScript libraries such as jQuery, Bootstrap, RequireJS, and others, ensuring a responsive and accessible user experience. The platform is built on ASP.NET Web Forms, indicating a mature and stable backend infrastructure. Accessibility and mobile optimization are well addressed, with additional features like voice search and accessibility widgets enhancing usability. From a security perspective, the site enforces HTTPS, integrates Google reCAPTCHA for form protection, and uses anti-forgery tokens to secure form submissions. However, there is room for improvement in security headers and publishing explicit security policies or incident response contacts. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance with basic privacy and cookie regulations. It effectively supports its business objectives while maintaining a secure and user-friendly environment.

-
28
-
85
-
70
100
governmenteconomicdevelopmentinvestmentconsumerprotectionbusinessservices+2 more
jQuery 3.7.1Bootstrap BundleRequireJSMoment.js+7
2025-06-18T08:07:09.001Z
I

Isle of Man Post Office

iompost.com

56
GovernmentIsle of ManmediumMEDIUM

The Isle of Man Post Office website serves as the official digital presence for the government postal service of the Isle of Man. It offers a comprehensive range of services including online postage, mail receiving and sending, foreign currency exchange, business mailing solutions, and retail products such as stamps and coins. The site targets both individual residents and businesses within the Isle of Man and surrounding regions, positioning itself as the primary postal and related services provider in the territory. The business model is government-operated, focusing on providing essential postal and financial services with a strong emphasis on customer convenience and digital accessibility. Technically, the website employs a modern technology stack including jQuery, the Foundation CSS framework, Google reCAPTCHA v3 for bot protection, and integrates Google Fonts and jQuery UI for enhanced user experience. The site demonstrates good mobile optimization and basic accessibility features, with a moderate performance profile. SEO practices are adequately implemented with proper meta tags and structured navigation. From a security perspective, the site uses HTTPS (implied by external Google reCAPTCHA and Google Fonts usage over HTTPS), includes CSRF tokens in forms, and implements a cookie consent mechanism compliant with GDPR. However, explicit HTTP security headers are not detected in the provided data, and no published security policy or incident response contacts are found. There are no visible vulnerabilities or exposed sensitive data. The site integrates tracking and marketing tools such as Google Analytics and Facebook Pixel, with moderate user tracking levels and good privacy compliance. Overall, the website is professionally designed, trustworthy, and well-aligned with the official government postal service branding. The domain registration data matches the website content and business claims, indicating legitimacy. Strategic recommendations include enhancing security headers, publishing a security policy, and adding a vulnerability disclosure mechanism to further strengthen security posture and user trust.

70
43
-
70
-
80
100
postalgovernmentisleofmanonlinepostageforeigncurrency+2 more
jQueryFoundation CSS FrameworkGoogle reCAPTCHA v3Google Fonts+2

Partner Domains:

onlinepostage.iompost.com
partner
www.iomstamps.com
partner
2025-06-18T08:07:08.643Z
aluksne.lv favicon

Alūksnes novads

aluksne.lv

59
GovernmentLatviamediumMEDIUM

Alūksnes novads is the official municipal government entity for the Alūksnes region in Latvia, providing a comprehensive digital portal for residents and stakeholders. The website offers detailed information about municipal governance, public services, cultural events, education, tourism, and community news. It serves as a key communication channel between the local government and the public, supporting transparency and civic engagement. The site is well-positioned as the authoritative source for local government information in the region. Technically, the website is built on WordPress CMS with a modern technology stack including jQuery, Google Analytics, and various plugins for enhanced functionality such as event calendars, photo galleries, and accessibility tools. The site demonstrates good digital maturity with SEO optimization, mobile responsiveness, and accessibility features. Hosting appears to be on Microsoft Azure, inferred from cookie data, ensuring reliable infrastructure. From a security perspective, the website enforces HTTPS and implements cookie consent mechanisms compliant with GDPR. While explicit security headers are not fully confirmed, no critical vulnerabilities or exposed sensitive data were detected. The absence of a public security policy or incident response contact is noted, suggesting room for improvement in transparency and readiness. Overall, the site maintains a solid security posture appropriate for a government entity. The overall risk assessment is low, with the website demonstrating professionalism, compliance, and trustworthiness. Strategic recommendations include enhancing security headers, publishing a vulnerability disclosure policy, and improving incident response visibility to further strengthen security and user trust.

15
25
25
100
57
70
100
governmentmunicipalitypublicserviceslatviaalksnesnovads+5 more
WordPressPHPjQueryGoogle Analytics+7

Partner Domains:

aluksnesmakslasskola.lv
partner
aluksnesezers.lv
partner

+1 more partners

2025-06-17T21:33:41.233Z
innsbrucktermine.at favicon

Stadt Innsbruck

innsbrucktermine.at

40
GovernmentAustriamediumHIGH

Innsbrucktermine.at is the official event portal for the city of Innsbruck, Austria, managed by Innsbruck Marketing GmbH. The platform offers comprehensive listings of cultural, family, sports, and diverse events, targeting residents and visitors interested in the vibrant local scene. The business model focuses on providing free event submissions with editorial oversight, ensuring quality and relevance. The site is well-positioned as a trusted government-related resource with strong branding and clear contact information. Technically, the website employs modern technologies including nginx, TLS 1.3, Bulma CSS framework, and JavaScript libraries such as Splide.js and Litepicker. It is hosted on servers associated with kasserver.com and uses Matomo for analytics, reflecting a mature digital infrastructure. The site is mobile-optimized, accessible, and SEO-friendly, with structured data enhancing search engine visibility. From a security perspective, the site demonstrates good practices with HTTPS enforced, HSTS enabled with preload, and multiple security headers including CSP, X-Frame-Options, and X-XSS-Protection. No vulnerabilities or exposed sensitive data were detected. However, OCSP stapling is not enabled, and the content security policy could be tightened by removing 'unsafe-inline' and 'unsafe-eval'. The absence of a visible cookie consent mechanism is a compliance gap given EU regulations. Overall, the website presents a low risk profile with strong business credibility and technical robustness. Strategic recommendations include implementing a visible cookie consent banner to enhance privacy compliance, enabling OCSP stapling for improved SSL performance, and refining the CSP for better security. These steps will further strengthen trust and regulatory adherence.

90
18
25
55
52
85
40
eventsinnsbruckculturetourismfamily+2 more
nginxTLS 1.3JavaScriptSplide.js (slider)+5
2025-06-16T16:31:17.358Z
hscentre.org favicon

Human Security Centre

hscentre.org

35
GovernmentN/asmallLOW

The Human Security Centre is an independent foreign policy think tank specializing in human rights, international security policy, and democracy research. It operates primarily as a non-profit organization targeting policymakers, academics, and government officials. The website serves as a platform for publishing research, hosting events, and engaging with media. It maintains an active social media presence and provides evidence to parliamentary committees, enhancing its credibility and influence in its sector. Technically, the website is built on WordPress 4.7.2 with several plugins including Yoast SEO and Seamless Donations. It uses common web technologies such as jQuery and integrates analytics tools like Google Analytics and ClickTale for user tracking. The site demonstrates moderate performance and basic mobile optimization but uses outdated software versions that may expose it to security vulnerabilities. From a security perspective, the site lacks visible security headers and does not display privacy or cookie policies, which are critical for GDPR compliance. The absence of direct contact emails or phone numbers limits transparency. While HTTPS usage is implied, explicit SSL configuration details are missing. The overall security posture is moderate but requires improvements to align with best practices. Overall, the website is functional and professional but would benefit from enhanced privacy compliance, updated technical infrastructure, and improved security measures to strengthen trust and protect user data.

20
10
35
70
-
75
-
humanrightsinternationalsecuritythinktankresearchpolicy+1 more
WordPress 4.7.2Yoast SEO pluginGoogle Analytics (MonsterInsights)jQuery+2
2025-06-15T22:25:42.254Z
F

Finanzamt Geilenkirchen

finanzamt-geilenkirchen.de

39
GovernmentGermanymediumHIGH

The website finanzamt-geilenkirchen.de serves as the official online presence of the Finanzamt Geilenkirchen, a regional tax office under the Oberfinanzdirektion Nordrhein-Westfalen in Germany. It provides comprehensive tax-related information, contact details, online services such as appointment booking and electronic tax declaration (ELSTER), and current news updates. The site targets residents and businesses in the Nordrhein-Westfalen region, offering clear navigation and well-structured content tailored to public service needs. Technically, the website is built on the Drupal CMS platform, utilizing modern web technologies including Apache server, Matomo analytics for user tracking, and a robust Content Security Policy. The site demonstrates good mobile optimization and accessibility features, ensuring usability across devices and for users with disabilities. However, the SSL/TLS configuration is critically flawed, with no valid certificate and no TLS protocols enabled, which undermines secure HTTPS access. From a security perspective, the site implements several best practices such as strict security headers (X-Frame-Options, X-Content-Type-Options, CSP), HSTS with preload directive, and referrer policies. Despite these, the lack of a valid SSL certificate and HTTPS support is a major vulnerability that must be addressed urgently to protect user data and maintain trust. Overall, the website is professional, trustworthy, and compliant with GDPR, featuring clear privacy and cookie policies with consent mechanisms. The business credibility is high given its government affiliation, but the security posture is currently weak due to SSL issues. Strategic recommendations include immediate remediation of SSL/TLS configuration, enhancement of session security features, and continuous monitoring of security compliance.

85
-
-
50
-
50
100
governmenttaxfinancepublicservicenrw+1 more
ApacheDrupal CMSMatomo AnalyticsModernizr+3
2025-06-15T22:08:09.680Z
akwien.at favicon

Kammer für Arbeiter und Angestellte für Wien

akwien.at

40
GovernmentAustrialargeHIGH

The website akwien.at represents the Kammer für Arbeiter und Angestellte für Wien, a government-related non-profit organization advocating for workers' rights and social services in Vienna, Austria. The site offers comprehensive information and services including legal advice, consumer protection, educational resources, and digitalization funding. It targets employees and workers in Vienna, providing a rich content experience with clear navigation and strong branding. Technically, the site is built on a Gentics Portal CMS with a modern tech stack including jQuery, Bootstrap, Matomo Analytics, and Usercentrics for consent management. Hosting is provided by Anexia. While the site is mobile optimized and accessible, performance metrics indicate slow loading, and the SSL/TLS configuration is currently invalid, which is a critical security concern. Security posture is moderate with several security headers implemented, but the lack of a valid SSL certificate and disabled TLS protocols significantly reduce the security score. Privacy compliance is good, with a clear privacy policy and cookie consent mechanism in place. Business credibility is high due to consistent branding, official contact information, and alignment with WHOIS data. Overall, the site is a professional and trustworthy resource for workers in Vienna but requires urgent improvements in SSL/TLS configuration and performance optimization to enhance security and user experience.

-
-
-
50
-
85
100
laborrightsworkerschamberaustriasocialservicesconsumerprotection+3 more
nginxjQueryBootstrapMatomo Analytics+8
2025-06-15T22:03:28.206Z
agenda-austria.at favicon

Agenda Austria

agenda-austria.at

35
GovernmentAustriamediumHIGH

Agenda Austria is an established independent think tank based in Austria, focusing on economic and socio-political research and analysis. The organization provides a variety of content including publications, graphics, podcasts, and events aimed at policymakers, academics, and the interested public. Their market position as the first independent think tank in Austria specializing in these areas is supported by a consistent and professional online presence. Technically, the website is built on WordPress with a modern tech stack including caching, SEO optimization, and consent management tools. The site is well-structured, mobile-optimized, and offers good user experience with clear navigation and rich content. However, the SSL/TLS configuration is currently inadequate, lacking a valid certificate and modern protocol support, which poses a security risk. Security-wise, the site implements several important HTTP security headers and uses reCAPTCHA for form protection, but the absence of valid HTTPS and modern TLS protocols significantly lowers its security posture. Privacy compliance is strong, with clear privacy and cookie policies and GDPR-compliant consent mechanisms. Overall, the website is trustworthy and professional but requires urgent improvements in SSL/TLS security to protect user data and enhance trust. Strategic recommendations include obtaining a valid SSL certificate, enabling modern TLS protocols, and enhancing domain security with DNSSEC and CAA records.

-
-
-
50
-
80
40
thinktankeconomicpolicyaustriapublicationsresearch+4 more
ApacheWordPressW3 Total CacheYoast SEO+7
2025-06-15T22:03:23.343Z
amstetten.at favicon

Stadtgemeinde Amstetten

amstetten.at

34
GovernmentAustriamediumHIGH

The website amstetten.at serves as the official online portal for the Stadtgemeinde Amstetten, a municipal government entity in Austria. It provides residents and visitors with comprehensive information about city administration, services, events, and public resources. The site targets local citizens and stakeholders, offering key services such as event announcements, service directories, job postings, and public transportation information. The business model is that of a government entity focused on public service delivery and community engagement. Technically, the website is built on the WordPress CMS platform, utilizing common plugins such as Yoast SEO for search optimization, WP Statistics for analytics, and Complianz for GDPR-compliant cookie management. The site employs Apache as the web server and includes JavaScript libraries like jQuery and RoyalSlider for interactive features. While the site is mobile-optimized and accessible, performance data is incomplete, and the site currently lacks a valid SSL certificate, resulting in no HTTPS support. From a security perspective, the absence of a valid SSL certificate is a critical vulnerability, exposing users to potential data interception risks. The site does not implement modern TLS protocols, HSTS, or OCSP stapling, which are essential for secure communications. However, no known vulnerabilities such as Heartbleed or POODLE were detected. Privacy compliance is strong, with a clear cookie consent mechanism and a comprehensive privacy policy aligned with GDPR requirements. Overall, the website is a well-structured and professionally maintained municipal portal with good content quality and user experience. The primary risk lies in the lack of HTTPS, which should be addressed urgently to protect user data and enhance trust. Strategic recommendations include implementing a valid SSL certificate, enabling modern security protocols, and enhancing security headers to improve the site's security posture and compliance.

15
-
-
50
-
85
85
governmentmunicipalityaustriapublicservicesevents+3 more
WordPressPHPApachejQuery+7
2025-06-15T22:01:15.280Z
insighttsi.com favicon

Insight Technology Solutions, LLC

insighttsi.com

40
GovernmentUnited StatesmediumHIGH

Insight Technology Solutions, LLC is a well-established Federal contractor headquartered in the National Capital Region, with over 20 years of experience delivering management consulting, business operations, and engineering solutions to Federal agencies. The company holds multiple government contract vehicles and certifications such as ISO 9001:2015, ISO/IEC 20000-1:2018, and CMMI Maturity Level 3, demonstrating a commitment to quality and compliance. Their target audience primarily includes U.S. government agencies, particularly in sectors like maritime, IT, and cybersecurity services. Technically, the website is built on the Wix platform utilizing modern JavaScript frameworks like React and includes various Wix apps for enhanced functionality. While the site is moderately optimized for performance and basic mobile responsiveness, there is room for improvement in accessibility and SEO practices. The hosting is managed by Wix, with standard security headers present, but the SSL certificate is currently invalid, which poses a significant security risk. From a security perspective, the site implements some best practices such as HSTS and secure cookie attributes but lacks a valid SSL certificate and comprehensive security headers. No vulnerabilities or exposed sensitive data were detected, but the absence of a cookie consent mechanism and privacy compliance indicators suggests partial adherence to privacy regulations. Overall, the website presents a professional and trustworthy image with clear business information and contact details. However, critical security improvements, especially regarding SSL certification and privacy compliance, are necessary to enhance trust and protect user data effectively.

35
-
5
50
-
85
100
federalcontractorgovernmentservicesmaritimeengineeringitservicescybersecurity+3 more
Wix platformJavaScriptReactWix Pro Gallery+4
2025-06-15T22:00:50.765Z
A

Amt der Stadt Feldkirch

feldkirch.at

23
GovernmentAustriamediumCRITICAL

The website feldkirch.at serves as the official municipal portal for the city of Feldkirch, Austria, providing comprehensive information about city services, news, events, and administrative functions. It targets residents, visitors, and local businesses, offering a broad range of public services including housing, registry office, social services, education, culture, and urban development. The site also promotes local subsidiaries and partner organizations, enhancing community engagement and service delivery. Technically, the website is built on the TYPO3 CMS platform and served via an Apache web server. It employs JavaScript for interactive elements and uses Matomo for analytics, respecting user cookie consent. The site is well-structured, mobile-optimized, and accessible, with clear navigation and professional design. However, performance metrics are unavailable, limiting full technical assessment. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical vulnerability impacting user trust and data security. Security headers are partially implemented but modern TLS protocols and HSTS are missing. No explicit security policies or incident response contacts are provided. Privacy compliance is strong, with a clear cookie consent mechanism and GDPR-aligned privacy policy. Overall, the site is a professionally managed government portal with excellent content quality and business credibility but requires urgent improvements in SSL/TLS security to protect users and enhance trust. Strategic recommendations include immediate SSL certificate installation, enabling HTTPS, and enhancing security headers and protocols.

-
-
5
50
-
85
-
governmentmunicipalpublicservicesaustriafeldkirch+3 more
ApacheTYPO3 CMSJavaScriptMatomo Analytics+1
2025-06-15T21:59:50.744Z
uncitral.org favicon

United Nations Commission On International Trade Law

uncitral.org

50
GovernmentAustrialargeHIGH

The United Nations Commission On International Trade Law (UNCITRAL) operates as a key intergovernmental organization under the United Nations, focused on developing and harmonizing international trade law frameworks. The website serves as an authoritative resource for legal texts, working documents, technical assistance, and research related to international trade law, targeting governments, legal professionals, and trade stakeholders globally. The organization is well-established with a mature domain and consistent branding aligned with UN standards. Technically, the website is built on Drupal 7 with common web technologies such as jQuery and Bootstrap. While the site demonstrates good content quality, navigation, and mobile optimization, it suffers from critical security shortcomings, notably the absence of a valid SSL certificate and lack of HTTPS enforcement, which severely impacts its security posture. Performance metrics are unavailable, but the technical stack suggests potential modernization needs. Security-wise, the site implements some security headers but fails to provide a valid SSL/TLS configuration, exposing users to risks and undermining trust. Privacy compliance is minimal, with no visible cookie consent mechanisms and only a basic privacy policy linked externally. Contact information is not explicitly provided on the homepage, limiting direct communication channels. Overall, the site is credible and authoritative but requires urgent security improvements to protect users and maintain trust. Strategic recommendations include obtaining a valid SSL certificate, enabling HTTPS, enhancing privacy and cookie consent mechanisms, and modernizing the technical infrastructure to improve performance and security.

55
25
25
50
50
80
100
governmentinternationaltradelawunitednationslegal+1 more
Drupal 7jQuery 3.5.1Bootstrap 3.4.1Superfish menu+4
2025-06-15T21:55:59.942Z