Skip to main content

Transportation security reports

Browse 7,552 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155885
Websites
130
Industries
113
Countries
52
Avg Score
Page 11 of 152|Showing 501-550 of 7552
C

COREhub, S.R.L.

gorivo.com

49
TransportationCroatiasmallHIGH

Gorivo.com operates as a regional ride-sharing platform primarily serving Croatia and neighboring countries. It facilitates peer-to-peer transportation by allowing users to offer and request rides, focusing on routes within Croatia and nearby European nations. The platform has been active since 2003, indicating a mature presence in its niche market. The website's business model centers on connecting drivers and passengers, providing a cost-effective and community-driven transportation alternative. Its market position is niche but stable, targeting individuals seeking carpooling options in the region. Technically, the website is built on ASP.NET WebForms with supporting libraries such as jQuery and Bootstrap, reflecting a legacy but functional technology stack. The site includes standard web fonts, UI components, and Google Adsense for monetization. Performance and mobile optimization are basic, with room for modernization. The site employs cookie consent mechanisms and basic privacy compliance features, though lacks advanced SEO and accessibility optimizations. From a security perspective, the site uses HTTPS and has domain transfer protections in place, but lacks advanced security headers and DNSSEC. No explicit security or incident response policies are published, which could be a gap in compliance and trust. Advertising practices involve multiple ad networks and tracking vendors, indicating moderate user tracking. The overall security posture is average, with recommendations to enhance headers, enable DNSSEC, and publish security policies. Overall, Gorivo.com presents a functional but basic digital presence with moderate trustworthiness and compliance. Strategic improvements in security, privacy transparency, and technical modernization would enhance its risk profile and user confidence.

20
65
17
55
72
75
20
ride-sharingtransportationcarpoolcroatiatravel
ASP.NET WebFormsjQueryBootstrapjQuery UI Datepicker+3
2025-11-01T08:57:14.468Z
akz.hr favicon

Hrvatski Telekom d.d.

akz.hr

52
TransportationCroatiamediumMEDIUM

The website www.akz.hr serves as the official online platform for the Zagreb Bus Station, providing extensive bus ticketing services across Croatia and neighboring countries. It offers users the ability to search for bus schedules, purchase tickets online up to 15 minutes before departure, and access real-time status updates for arrivals and departures. The platform supports mobile app integration, enhancing accessibility for travelers. The business is positioned as a key transportation service provider in the region, backed by Hrvatski Telekom d.d., a reputable Croatian telecommunications company. Technically, the website employs standard web technologies including HTML5, CSS3, and JavaScript, with integrations of Google Tag Manager and Google Analytics for marketing and analytics purposes. Hosting is managed by Hrvatski Telekom with Cloudflare DNS services, ensuring reliable domain resolution. The site demonstrates moderate performance and good mobile optimization, though accessibility features are basic. SEO practices are adequately implemented with proper meta tags and Open Graph data. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks explicit security headers such as Content Security Policy and HSTS, which are recommended for enhanced protection. Privacy compliance is limited due to the absence of a visible privacy policy and terms of service, representing a compliance gap especially under GDPR. No incident response or vulnerability disclosure information is provided. Overall, the website is trustworthy and professionally maintained, with a strong business credibility score. Strategic improvements in privacy policy publication, security header implementation, and comprehensive compliance documentation would elevate its security posture and user trust.

15
10
17
70
47
75
100
busticketstransportationonlineticketingzagrebbusstationtravel
HTML5CSS3JavaScriptGoogle Tag Manager+2
2025-11-01T08:56:59.436Z
jadrolinija.hr favicon

Jadrolinija

jadrolinija.hr

11
TransportationCroatialargeCRITICAL

Jadrolinija is Croatia's largest passenger shipping company, providing ferry and catamaran transport services connecting numerous local and international destinations. The company operates a comprehensive online platform offering schedule information, ticket purchasing, and prepaid travel card services, targeting both local residents and tourists. The website reflects a mature digital presence with consistent branding and a focus on user convenience. Technically, the website employs modern web technologies including jQuery, Plyr video player, and Swiper sliders, alongside Google Fonts and accessibility tools. It is hosted under a Croatian academic network registrar, indicating a stable and regionally appropriate hosting environment. The site is mobile-optimized and accessible, with good SEO practices and performance. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms compliant with GDPR. However, it lacks explicit published security policies, incident response plans, and vulnerability disclosure information. The use of third-party tracking pixels from Google, Meta, and TikTok indicates moderate user tracking, balanced by privacy controls. Overall, Jadrolinija's website is professional, trustworthy, and well-aligned with its business objectives. Strategic improvements in security transparency and incident readiness would enhance its security posture and user trust further.

-
-
-
-
-
-
-
transportationferrycroatiatravelticketing+5 more
jQuery 3.5.1Plyr video player 3.7.8Google Fonts (Plus Jakarta Sans)Swiper.js slider+2
2025-11-01T08:43:14.722Z
revijahak.hr favicon

Hrvatski autoklub

revijahak.hr

61
TransportationCroatiamediumMEDIUM

Revija HAK is an online magazine operated by Hrvatski autoklub, focusing on automotive news, traffic safety, and vehicle maintenance primarily for the Croatian market. The website serves as a content hub for drivers and HAK members, offering news articles, educational tests, and links to official HAK services including membership and webshop. The site is well-branded and professionally designed, targeting Croatian drivers and automotive enthusiasts with relevant and timely content. Technically, the website is built on WordPress with common plugins such as Yoast SEO for search optimization, Advanced Ads for advertising management, and Eightshift GDPR for cookie consent compliance. It uses Cloudflare DNS and is hosted via the Croatian registrar cyber_Folks d.o.o. The site is mobile-optimized and features a clear navigation structure with categorized content sections. Performance is moderate with standard modern web technologies. From a security perspective, the site enforces HTTPS and implements GDPR cookie consent with a detailed modal allowing users to select cookie preferences. However, explicit security headers are not detected, and there is no published security policy or incident response information. No vulnerabilities or exposed sensitive data were found in the HTML content. The WHOIS data is consistent with the business entity and geographic location, supporting legitimacy. Overall, the website presents a low-risk profile with good business credibility and technical implementation. Recommendations include publishing privacy and security policies, adding security headers, and establishing a vulnerability disclosure process to enhance trust and compliance.

35
10
17
88
67
90
100
automobilipromethakilanovimagazinsavjeti+2 more
jQueryYoast SEO pluginAdvanced Ads pluginEightshift GDPR plugin

Partner Domains:

hak.hr
partner
map.hak.hr
partner

+2 more partners

2025-11-01T08:19:03.866Z
skypicker.com favicon

Kiwi.com

skypicker.com

70
TransportationCzech RepubliclargeMEDIUM

Kiwi.com is a prominent online travel agency specializing in providing cheap flights, hotels, and car rental services globally. The platform offers a user-friendly interface with advanced search capabilities including flexible dates and map-based destination exploration. It is trusted by millions and provides additional services such as disruption protection and 24/7 customer support. The website demonstrates a mature digital presence with consistent branding and comprehensive content tailored for travelers seeking affordable travel options. Technically, Kiwi.com employs modern web technologies including React and Tailwind CSS, supported by Google Tag Manager and Forter for analytics and fraud prevention respectively. The site is optimized for performance and mobile responsiveness, ensuring a seamless user experience across devices. Security best practices are observed with HTTPS enforcement and presence of key security headers, although explicit incident response and vulnerability disclosure information are not publicly available. From a security and compliance perspective, Kiwi.com maintains a comprehensive privacy policy and cookie consent mechanism aligned with GDPR requirements. However, the WHOIS data for the domain is not publicly available, which slightly impacts trust but is common for commercial entities using privacy protection services. Overall, the site presents a strong security posture with room for improvement in transparency around incident response and vulnerability management. The overall risk assessment is moderate to low, with recommendations focusing on enhancing security transparency and providing clear contact channels for security incidents. Kiwi.com’s strategic position as a leading travel booking platform is supported by its technical infrastructure and user-centric design, making it a reliable choice for consumers worldwide.

60
68
17
87
57
85
100
travelflightsbookingairfarecheapflights+1 more
ReactTailwind CSSGoogle Tag ManagerForter (fraud prevention)+2

Partner Domains:

cars.kiwi.com
subsidiary
sp.booking.com
partner

+2 more partners

2025-11-01T08:17:38.200Z
citroencl.cz favicon

LIPEX PLUS spol. s.r.o.

citroencl.cz

45
TransportationCzech RepublicsmallHIGH

LIPEX PLUS spol. s.r.o. operates the website citroencl.cz as a specialized Citroën dealership and service center located in Česká Lípa, Czech Republic. The company offers automotive sales, servicing, emission testing, and financing services primarily targeting Citroën vehicle owners in the local region. The website presents a professional and consistent brand image with clear contact details and social media presence, supporting its local market position. Technically, the website uses a traditional tech stack including jQuery, Bootstrap, and Google Analytics, with a responsive but basic mobile optimization. The site is moderately performant with clear navigation and SEO basics in place. However, there is no evidence of advanced CMS or modern frameworks, and accessibility features are minimal. From a security perspective, the site lacks visible security headers and does not provide privacy or cookie policies, indicating gaps in GDPR compliance and security best practices. No incident response or vulnerability disclosure information is present. The domain registration data is consistent and supports the legitimacy of the business. No WAF or blocking mechanisms were detected, and the site content is safe for general audiences. Overall, the website is functional and credible for its business purpose but would benefit from enhanced security measures, privacy compliance improvements, and modern technical upgrades to strengthen trust and regulatory adherence.

35
10
2
85
62
75
20
automotivecardealershipcarservicecitronczechrepublic+1 more
jQueryBootstrapGoogle AnalyticsjQuery Revolution Slider+1
2025-11-01T07:20:29.772Z
hondacl.cz favicon

LIPEX PLUS spol. s r.o.

hondacl.cz

43
TransportationCzech RepublicsmallHIGH

Honda Česká Lípa, operated by LIPEX PLUS spol. s r.o., is a small-sized authorized dealer and service provider specializing in Honda vehicles and garden machinery in the Czech Republic. The company offers a comprehensive range of automotive services including sales of new and used cars, authorized repairs, tire services, emission testing, and garden equipment sales. The website reflects a professional and consistent brand image with clear contact information and customer testimonials, positioning the company as a trusted local business with over 20 years of experience. Technically, the website employs modern frontend technologies such as Bootstrap, jQuery, and Google Analytics, ensuring a responsive and user-friendly experience. However, the absence of detected security headers and privacy policies indicates room for improvement in security and compliance. The site is accessible without any WAF or blocking mechanisms, but the lack of WHOIS data reduces domain trustworthiness and raises questions about domain registration transparency. From a security perspective, the site shows no immediate vulnerabilities or exposed sensitive data, but the missing privacy and cookie policies and lack of incident response information highlight compliance gaps, particularly with GDPR. The use of Google Analytics suggests moderate user tracking, but without clear privacy disclosures. Overall, the security posture is moderate but could be enhanced with standard best practices. Strategically, the company should prioritize establishing clear privacy and cookie policies, implement security headers, and verify domain registration details to improve trust and compliance. Enhancing incident response readiness and communicating data protection officer contacts would further strengthen their security culture and customer confidence.

20
10
2
85
62
75
20
automotivehondaautoserviscarsalesgardenmachinery+1 more
Google AnalyticsBootstrapjQueryFont Awesome+2
2025-11-01T07:20:24.760Z
formula1.com favicon

Formula 1®

formula1.com

69
TransportationN/alargeMEDIUM

Formula 1's official website serves as the primary digital platform for global fans and stakeholders of the Formula 1 racing series. It offers comprehensive content including news, race schedules, results, driver and team profiles, video highlights, and ticketing services. The site also supports subscription-based streaming via F1 TV, enhancing fan engagement with live and on-demand content. The platform is well-positioned as the authoritative source for Formula 1 information and entertainment, leveraging strong branding and partnerships with official entities such as the FIA. Technically, the website employs a modern technology stack including React with Next.js for server-side rendering, Brightcove for video delivery, and Cloudinary for media management. It integrates various analytics and monitoring tools such as Google Analytics and New Relic, and implements a consent management platform to comply with privacy regulations. The site is optimized for performance, mobile responsiveness, and accessibility, providing a seamless user experience across devices. From a security perspective, the website enforces HTTPS, utilizes robust security headers, and manages user consent effectively. However, there is no publicly available security policy or incident response contact information, and no vulnerability disclosure program is evident. The WHOIS data for the domain is unavailable, likely due to privacy or registry restrictions, but the website's official nature and consistent branding mitigate concerns about legitimacy. Overall, the website demonstrates a high level of professionalism, security, and compliance suitable for a major international sports brand. Strategic recommendations include publishing explicit security policies, establishing a vulnerability disclosure channel, and enhancing transparency around incident response to further strengthen trust and security posture.

75
35
17
85
72
85
100
formula1motorsportracingsportsf1tv+6 more
React (Next.js)Brightcove video platformCloudinary for media deliveryGoogle Tag Manager+5

Partner Domains:

www.fia.com
partner
f1store.formula1.com
subsidiary

+3 more partners

2025-11-01T06:14:34.009Z
cvs-mobile.com favicon

W.A.G. payment solutions, a.s.

cvs-mobile.com

52
TransportationCzech RepubliclargeMEDIUM

W.A.G. payment solutions, a.s., operating under the Eurowag brand, is a leading European provider of integrated mobility and payment solutions focused on the transportation sector. The company offers a comprehensive suite of services including fleet management telematics, fuel cards, toll payment solutions, tax refund services, and eMobility options. Their recent integration of CVS Mobile enhances their fleet management capabilities with advanced real-time tracking and route planning, positioning them strongly in the European transport market. The website reflects a mature digital presence with multi-language support and country-specific offerings, targeting fleet operators and logistics managers across Europe. Technically, the website is built on the Webflow platform, leveraging modern web technologies such as Google Tag Manager for analytics and tracking, and intl-tel-input for phone input handling. The site is well-optimized for mobile devices, accessible, and fast-loading, demonstrating a high level of digital maturity. The presence of comprehensive legal, privacy, and cookie policies indicates a strong commitment to compliance and user privacy. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms, though explicit security headers are not detected in the provided data. No vulnerabilities or exposed sensitive data were found in the content. The absence of WHOIS data limits domain registration trust analysis, but the website's professional presentation, regulatory disclosures, and trust signals support a strong security posture. Overall, the website presents a low-risk profile with robust business credibility and technical implementation. Strategic recommendations include enhancing security headers, publishing an incident response page, and adding a vulnerability disclosure policy to further strengthen security transparency and resilience.

-
-
-
85
57
85
100
fleetmanagementtransportationmobilitysolutionspaymentservicestelematics+4 more
Webflow CMSGoogle Tag ManagerIntl-Tel-Input JSjQuery 3.5.1+3

Partner Domains:

investors.eurowag.com
partner
mobileweb.cvs-mobile.com
subsidiary

+3 more partners

2025-11-01T06:09:23.039Z
gbox.pl favicon

W.A.G. payment solutions, a.s.

gbox.pl

65
TransportationCzech RepubliclargeMEDIUM

W.A.G. payment solutions, a.s. operates as a leading European provider of integrated mobility and payment solutions, primarily serving the transportation and fleet management sectors. Their website promotes the GBox telematics platform, offering real-time vehicle tracking, driver monitoring, and data analytics to optimize fleet operations and reduce costs. The company targets transport companies, fleet managers, and logistics operators with a comprehensive suite of telematics and payment services, supported by multiple digital portals and mobile applications. Technically, the website is built on the Webflow CMS platform, leveraging modern JavaScript libraries such as jQuery and intl-tel-input, and integrates Google Tag Manager and LiveChat for analytics and customer support. The site is well-optimized for mobile devices, accessibility, and SEO, with a fast loading performance and structured navigation. Privacy and cookie policies are clearly presented with consent mechanisms, reflecting good compliance with GDPR requirements. From a security perspective, the site enforces HTTPS, uses CAPTCHA on forms, and avoids exposing sensitive data. However, explicit security headers like CSP and HSTS are not detected, and no public vulnerability disclosure or incident response contacts are provided. The WHOIS data is unavailable publicly, which slightly reduces transparency but is common for corporate domains. Overall, the security posture is solid but could be enhanced with additional headers and disclosure practices. The overall risk assessment indicates a trustworthy and professional online presence with moderate to high credibility. Strategic recommendations include improving security header implementation, publishing a security.txt file, and enhancing incident response transparency to further strengthen trust and compliance.

45
50
17
85
57
85
100
fleetmanagementtelematicstransportgboxeurowag+4 more
Webflow CMSGoogle Tag ManagerLiveChatintl-tel-input+1

Partner Domains:

selfcare.eurowag.com
service
office.eurowag.com
service

+3 more partners

2025-11-01T06:09:18.026Z
ocrk.pl favicon

W.A.G. payment solutions, a.s.

ocrk.pl

63
TransportationCzech RepubliclargeMEDIUM

W.A.G. payment solutions, a.s. operates a professional website focused on providing integrated mobility and payment solutions for the European transport sector. The site highlights expert services in driver work time management, compliance, and financial settlements, targeting transport companies and fleet managers. The company positions itself as a leading provider with a broad portfolio including fuel cards, toll services, telematics, and financial services. The website is well-structured, multilingual, and rich in content, reflecting a mature digital presence. Technically, the site leverages modern web technologies including Webflow CMS, JavaScript libraries like jQuery and intl-tel-input, and integrates Google Tag Manager and LiveChat for analytics and customer support. The site is mobile-optimized and accessible, with cookie consent mechanisms and GDPR-compliant privacy policies. Security measures include HTTPS and CAPTCHA on forms, though explicit security headers and incident response information are not evident. The security posture is solid but could be improved by adding security headers and publishing vulnerability disclosure information. The absence of WHOIS data reduces trust slightly but the professional presentation and consistent business information mitigate concerns. Overall, the site demonstrates a strong business and technical foundation with room for enhanced security transparency. Strategic recommendations include implementing security headers, publishing a security.txt file, providing incident response contacts, and improving WHOIS transparency to enhance trust and compliance.

45
50
2
85
57
85
100
transportfleetmanagementdriversettlementfinancialservicesfuelcards+4 more
JavaScriptjQuery 3.5.1intl-tel-inputLiveChat+2

Partner Domains:

investors.eurowag.com
partner
webeye.eu
partner

+3 more partners

2025-11-01T06:09:13.013Z
webeye.eu favicon

W.A.G. payment solutions, a.s.

webeye.eu

64
TransportationCzech RepubliclargeMEDIUM

W.A.G. payment solutions, a.s., operating under the brand Eurowag, is a leading provider of integrated mobility and payment solutions tailored for the European transportation sector. The company offers a comprehensive suite of services including fleet management, toll payment solutions, fuel cards, tax refunds, and financial services, targeting commercial fleet operators and logistics companies. Their market position is strong, supported by a large-scale operation and a broad geographic presence across multiple European countries. Technically, the website is built on modern web technologies including Webflow CMS, jQuery, and Google Tag Manager, hosted on a performant CDN infrastructure. The site is well-optimized for mobile devices, accessibility, and SEO, reflecting a mature digital presence. The integration of multiple login portals and partner platforms indicates a complex and well-managed technical ecosystem. From a security perspective, the website enforces HTTPS and implements cookie consent mechanisms, demonstrating compliance with privacy regulations such as GDPR. However, explicit security headers are not visibly configured, and there is no public incident response or vulnerability disclosure policy, which are areas for improvement. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website presents a professional and trustworthy front for a large enterprise in the transportation and payment services industry. The lack of WHOIS data reduces transparency but does not detract significantly from the site's legitimacy. Strategic recommendations include enhancing security headers, publishing incident response contacts, and formalizing vulnerability disclosure policies to strengthen trust and compliance.

45
50
17
85
47
85
100
fleetmanagementtelematicstollservicespaymentsolutionstransportation+3 more
jQuery 3.5.1intl-tel-inputGoogle Tag ManagerWebflow CMS+1

Partner Domains:

investors.eurowag.com
subsidiary
panel.ocrk.pl
partner

+3 more partners

2025-11-01T06:09:07.997Z
insa.de favicon

Nahverkehrsservice Sachsen-Anhalt GmbH

insa.de

57
TransportationGermanymediumMEDIUM

Nahverkehrsservice Sachsen-Anhalt GmbH operates the INSA platform, a regional public transportation service providing comprehensive timetable information and ticketing solutions for Sachsen-Anhalt and the Mitteldeutschen Verkehrsverbund (MDV). The website serves as a digital hub for users seeking mobility information, ticket purchases, and related services such as the INSA app and RufBus ordering. Positioned as a key regional mobility facilitator, INSA leverages modern web technologies and complies with GDPR regulations to ensure user privacy and data protection. Technically, the website is built on TYPO3 CMS, integrating JavaScript libraries such as ReadSpeaker for accessibility and Cookiebot for consent management. The infrastructure is hosted with professional DNS providers and employs HTTPS with good SSL configuration, ensuring secure communications. The site demonstrates good mobile optimization, accessibility, and SEO practices, providing a user-friendly experience. From a security perspective, the site enforces HTTPS, uses cookie consent mechanisms, and avoids exposing sensitive data. However, it lacks explicit published security policies or incident response contacts, which could be improved to enhance trust and readiness. Analytics usage is moderate with Piwik (Matomo), respecting privacy with clear retention policies. Overall, the website is trustworthy, professionally maintained, and compliant with privacy laws. Strategic recommendations include publishing a security.txt file, incident response contacts, and expanding security policy disclosures to strengthen the security posture and user trust.

25
83
2
40
62
60
100
publictransportfahrplanauskunftticketsinsasachsen-anhalt+3 more
TYPO3 CMSJavaScriptReadSpeakerCookiebot

Partner Domains:

www.nasa.de
partner
www.mein-takt.de
partner

+2 more partners

2025-11-01T05:43:37.332Z
nasa.de favicon

Nahverkehrsservice Sachsen-Anhalt GmbH

nasa.de

64
TransportationGermanymediumMEDIUM

Nahverkehrsservice Sachsen-Anhalt GmbH (NASA GmbH) is a regional public transportation authority responsible for planning, ordering, and financing local rail passenger transport in the German state of Sachsen-Anhalt. The company also operates the INSA timetable information system, serving public transport users and stakeholders in the region. The website reflects a professional and consistent brand presence, targeting primarily German-speaking users interested in regional mobility services. The business model focuses on public sector transportation planning and service provision, positioning NASA GmbH as an essential regional player in transportation infrastructure and information services. Technically, the website is built on the TYPO3 CMS platform, integrating modern web technologies such as jQuery, ReadSpeaker for accessibility, and Cookiebot for GDPR-compliant cookie management. Hosting is managed via DomainControl nameservers, and the site demonstrates good mobile optimization, accessibility, and SEO practices. Analytics are conducted using Piwik (Matomo), indicating a privacy-conscious approach to user data collection. From a security perspective, the site enforces HTTPS and implements a comprehensive cookie consent mechanism. However, explicit security headers like Content-Security-Policy and X-Frame-Options are not evident, and no public security policy or incident response contacts are published. No vulnerabilities or exposed sensitive data were detected in the analyzed content. The domain registration appears legitimate and consistent with the business's regional focus. Overall, the website presents a low-risk profile with strong privacy compliance and good technical implementation. Strategic improvements could include publishing a formal security policy, adding security headers, and establishing a vulnerability disclosure process to enhance trust and security posture further.

25
83
17
65
67
70
100
publictransportregionalmobilitysachsen-anhalttypo3cookieconsent+2 more
TYPO3 CMSjQueryReadSpeakerCookiebot

Partner Domains:

fahrgastforum.de
partner
insa.de
partner

+1 more partners

2025-11-01T05:29:46.229Z
deutschebahn.com favicon

Deutsche Bahn AG

deutschebahn.com

71
TransportationGermanyenterpriseMEDIUM

Deutsche Bahn AG operates as Germany's leading railway company, offering comprehensive passenger and freight transportation services, infrastructure management, and innovative mobility solutions. The website reflects a mature digital presence with a professional design, clear navigation, and extensive content covering corporate information, sustainability, digitalization, and business units. The company targets a broad audience including customers, investors, and partners, positioning itself as a key player in the European transportation sector. Technically, the site leverages modern technologies such as CoreMedia CMS, Matomo analytics, and Usercentrics for consent management, ensuring compliance with GDPR and providing a good user experience across devices. The security posture is strong with HTTPS enforcement and security headers, although explicit security policies and incident response contacts are not published. Overall, the website is trustworthy and professionally maintained, though the WHOIS data for the queried domain variant is missing, which warrants verification. The site does not exhibit any adult or questionable content and maintains good privacy compliance. Strategic recommendations include publishing detailed security policies, incident response information, and vulnerability disclosure mechanisms to enhance transparency and trust.

70
80
2
83
72
75
100
transportationrailwaycorporategermanymobility+2 more
CoreMedia CMSMatomo AnalyticsUsercentrics CMPPlyr video player+1

Partner Domains:

nachhaltigkeit.deutschebahn.com
subsidiary
lieferanten.deutschebahn.com
subsidiary

+3 more partners

2025-11-01T05:29:26.184Z
alex.info favicon

Regentalbahn GmbH

alex.info

57
TransportationGermanymediumMEDIUM

The website www.laenderbahn.com/alex/ represents the alex regional train service operated by Regentalbahn GmbH, a subsidiary of the Netinera group. It offers daily direct train connections between Germany and the Czech Republic, targeting commuters and travelers in this region. The site provides comprehensive travel information, ticket sales, real-time updates, and customer service resources. The business model focuses on regional transportation services with a strong emphasis on customer convenience and cross-border connectivity. Technically, the website is built on Craft CMS and employs modern JavaScript libraries and frameworks such as jQuery and Mmenu for mobile navigation. It integrates multiple analytics and tracking tools including Matomo, Google Tag Manager, Facebook Pixel, and Hotjar, all managed with a cookie consent mechanism to comply with privacy regulations. The site is mobile-optimized, accessible, and SEO-friendly, providing a good user experience. From a security perspective, the website enforces HTTPS and uses CSRF tokens to protect forms. While explicit HTTP security headers were not detected in the provided data, the site follows best practices in data protection and privacy compliance, including a comprehensive privacy policy and cookie management. No vulnerabilities or exposed sensitive data were found. However, the absence of WHOIS data for the domain raises concerns about domain registration legitimacy, although the website branding and content strongly indicate a legitimate business. Overall, the site is professional, trustworthy, and well-maintained, serving its target audience effectively. The main risk lies in the missing WHOIS registration data, which should be verified externally. Strategic recommendations include enhancing HTTP security headers, publishing a vulnerability disclosure policy, and providing explicit incident response contacts to further strengthen security posture.

20
68
2
70
47
70
100
alexbahnzuglaenderbahnausflug+7 more
JavaScriptjQueryFontAwesomeMatomo Analytics+3

Partner Domains:

www.netinera.de
parent
www.zugsammen.de
partner
2025-11-01T05:22:28.881Z
vogtlandbahn.de favicon

Regentalbahn GmbH

vogtlandbahn.de

57
TransportationGermanymediumMEDIUM

The website www.laenderbahn.com/vogtlandbahn/ represents the Vogtlandbahn, a regional passenger rail service operating in the Vogtland region of Germany. It is part of Regentalbahn GmbH and affiliated with the parent company Netinera. The site offers comprehensive information on train schedules, ticketing options, real-time departure data, and customer services, targeting regional travelers and commuters. The business model focuses on providing reliable and comfortable regional rail transport connecting multiple cities and towns. The website is professionally designed with consistent branding and clear navigation, supporting a positive user experience. From a technical perspective, the site employs modern web technologies including JavaScript libraries, Matomo analytics, Google Tag Manager, and Facebook Pixel for tracking and marketing. It is built on Craft CMS and demonstrates good mobile optimization and accessibility features. Security is well addressed with HTTPS enforcement, security headers, and CSRF protection, though there is room for improvement in publishing explicit security policies and incident response information. The security posture is strong with no evident vulnerabilities or exposed sensitive data. Privacy compliance is robust, featuring a comprehensive privacy policy and cookie consent mechanisms aligned with GDPR requirements. Contact information is clearly provided, including phone numbers and physical addresses, enhancing business credibility. Overall, the website is a trustworthy and professional digital presence for a regional transportation provider. However, the absence of WHOIS registration details introduces some uncertainty about domain legitimacy, warranting further verification. Strategic recommendations include publishing a dedicated security policy, establishing a vulnerability disclosure program, and enhancing incident response transparency to further strengthen trust and compliance.

20
68
2
70
47
70
100
vogtlandbahnregionaltransporttrainscheduleticketspublictransport+2 more
JavaScriptjQueryMmenu.jsMatomo Analytics+2

Partner Domains:

netinera.de
parent
zugsammen.de
partner
2025-11-01T05:21:57.189Z
der-metronom.de favicon

metronom Eisenbahngesellschaft mbH

der-metronom.de

56
TransportationGermanymediumMEDIUM

metronom Eisenbahngesellschaft mbH operates regional passenger rail services connecting key northern German states including Niedersachsen, Hamburg, and Bremen. The company positions itself as a reliable regional transport provider with a focus on customer service, real-time travel information, and sustainable mobility. Their business model centers on providing scheduled train services, ticketing solutions, and substitute bus services during infrastructure works. The website reflects a medium-sized enterprise with consistent branding and a strong regional presence supported by partnerships with local transport authorities and the parent company Netinera. Technically, the website employs modern web technologies including Progressive Web App features, service workers, and integrates third-party widgets for travel planning. Hosting and DNS are managed via Cloudflare, ensuring good performance and security. The site is mobile-optimized, accessible, and SEO-friendly, with comprehensive metadata and structured content. From a security perspective, the site enforces HTTPS, uses standard security headers, and avoids exposing sensitive data. However, it lacks a dedicated security policy, incident response information, and vulnerability disclosure mechanisms, which are recommended for enhanced transparency and trust. Privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanisms aligned with GDPR. Overall, the website is professional, trustworthy, and well-suited for its audience. Strategic improvements in security transparency and incident response readiness would further strengthen its posture.

55
28
2
70
47
60
100
metronomregionalrailtransportationgermanypublictransit+3 more
JavaScriptCSSHTML5Service Worker (PWA)+2

Partner Domains:

www.netinera.de
parent
www.lnvg.de
partner

+3 more partners

2025-11-01T05:21:26.589Z
laenderbahn.com favicon

Die Länderbahn GmbH DLB

laenderbahn.com

59
TransportationGermanymediumMEDIUM

Die Länderbahn GmbH DLB is a well-established private railway company operating regional passenger transport services in Germany and the Czech Republic. With a history spanning over 130 years and multiple regional brands such as alex, trilex, and vogtlandbahn, the company holds a strong market position in the transportation sector. It is a subsidiary of NETINERA Deutschland GmbH, indicating a solid corporate backing. The website provides comprehensive information about the company’s services, history, and career opportunities, targeting both customers and potential employees. Technically, the website is built on a modern CMS platform (Craft CMS) and employs various analytics and marketing tools including Matomo, Google Tag Manager, Facebook Pixel, and Hotjar. The site is mobile-optimized with good SEO practices and a clear navigation structure. Security measures such as HTTPS and CSRF tokens are implemented, though some security headers and explicit incident response policies are absent. From a security and compliance perspective, the website includes a detailed privacy policy and cookie consent mechanism compliant with GDPR. However, the absence of WHOIS data for the domain raises questions about domain registration transparency, although the website content and branding strongly support legitimacy. No critical vulnerabilities or adult content were detected, and the site maintains a professional and trustworthy online presence. Overall, the website reflects a mature digital presence for a transportation company with good technical and privacy practices. Strategic improvements in security headers and public incident response information could further enhance trust and compliance.

20
68
17
70
47
70
100
lnderbahnwaldbahnalextrilexvogtlandbahn+10 more
JavaScriptjQueryMatomo AnalyticsGoogle Tag Manager+2

Partner Domains:

www.netinera.de
parent
www.alex.info
subsidiary

+3 more partners

2025-11-01T05:21:21.577Z
mobilotsin-niedersachsen.de favicon

Landesverkehrsgesellschaft Niedersachsen mbH (LNVG)

mobilotsin-niedersachsen.de

43
TransportationGermanymediumHIGH

MOBILOTSIN is a regional initiative under the Landesverkehrsgesellschaft Niedersachsen mbH (LNVG) focused on supporting municipalities and counties in Lower Saxony, Germany, with innovative mobility concepts and the traffic transition. The website presents a professional and consistent brand image, offering services such as consulting, qualification courses, and events. The target audience primarily includes local government entities and stakeholders involved in mobility management. The digital infrastructure is built on the ProcessWire CMS with modern JavaScript libraries enhancing user experience. The site is mobile-optimized and well-structured, providing clear navigation and relevant content including event listings and newsletter subscription. From a security perspective, the website uses HTTPS and does not expose sensitive data in the HTML content. However, there is no evidence of advanced security headers or published security policies, and no cookie consent mechanism is present, which could be improved for better compliance. No analytics or tracking scripts were detected, indicating minimal user tracking. Contact information is clearly provided, enhancing business credibility. WHOIS data shows consistent domain registration with no privacy protection, aligning with the website's governmental affiliation. Overall, the website demonstrates a solid technical foundation and business credibility with room for improvement in privacy compliance and security best practices. The content is safe and appropriate for a general audience, with no adult or questionable material detected.

45
28
2
65
52
70
-
mobilittniedersachsenberatungqualifizierungveranstaltungen+2 more
HTML5CSSJavaScriptOwl Carousel+1
2025-11-01T05:21:06.539Z