Skip to main content

Transportation security reports

Browse 7,639 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 12 of 153|Showing 551-600 of 7639
tschudigroup.com favicon

Tschudi Shipping Company AS

tschudigroup.com

68
TransportationNorwaylargeMEDIUM

Tschudi Shipping Company AS is a well-established, family-owned Norwegian maritime and logistics group with a history dating back to 1883. The company offers a broad range of integrated services including shipping, ship management, transshipment, energy advisory, ocean industries support, offshore wind support, logistics, and financial services. With a strong Nordic and European presence and offices in 12 countries, Tschudi Group targets businesses requiring comprehensive maritime and logistics solutions. The website reflects a professional and consistent brand image, emphasizing their expertise and global reach. Technically, the website is built on the Webflow platform, utilizing modern web technologies such as jQuery, Google Analytics, and Google Tag Manager. The site is well-optimized for performance, mobile responsiveness, and accessibility, with clear navigation and rich content. Privacy and cookie policies are present with consent mechanisms, indicating good privacy compliance. However, explicit security headers are missing, and no public security policy or incident response information is available. From a security perspective, the site enforces HTTPS and anonymizes IPs in analytics, but the absence of WHOIS data for the domain raises concerns about domain registration legitimacy. No vulnerabilities or exposed sensitive data were detected, but improvements in security headers and transparency about security practices are recommended. Overall, the site demonstrates a solid security posture with room for enhancement. The overall risk assessment is moderate with a legitimacy score impacted by missing WHOIS data. Strategic recommendations include verifying domain registration, enhancing security headers, publishing security policies, and implementing vulnerability disclosure mechanisms to strengthen trust and compliance.

60
68
2
85
72
80
100
shippinglogisticsmaritimeenergyarctic+3 more
Webflow CMSjQuery 3.5.1Google AnalyticsGoogle Tag Manager+1

Partner Domains:

tschudilogistics.com
subsidiary
tschudienergy.com
subsidiary

+1 more partners

2025-11-01T12:55:37.728Z
vilatrans.com favicon

Vilatrans Empresa de Distribución y Logística

vilatrans.com

53
TransportationSpainmediumMEDIUM

Vilatrans Empresa de Distribución y Logística is a medium-sized Spanish logistics and distribution company with over 25 years of experience. The company specializes in full load transportation and associated logistics services, leveraging satellite tracking technology and holding necessary administrative authorizations for special transport across Spain. Their website reflects a professional and consistent brand presence, targeting businesses requiring reliable logistics solutions. Technically, the site is built on WordPress with the Divi theme and uses common plugins such as Yoast SEO and Contact Form 7, hosted on Amazon AWS infrastructure. The website is mobile-optimized and SEO-friendly, though accessibility features are basic. Security posture is adequate with HTTPS enabled and domain protections in place, but lacks DNSSEC and security headers, and does not publish explicit security or incident response policies. Privacy compliance is partial, with a cookie policy and consent mechanism present but no privacy policy page found. Overall, the domain registration data aligns well with the business claims, supporting legitimacy. The site is free from WAF blocking or content restrictions and contains no adult or questionable content.

35
50
17
85
62
75
20
logisticsdistributiontransportationspainwordpress+2 more
WordPress 4.9.4Divi ThemeYoast SEO pluginContact Form 7+3

Partner Domains:

hiemesa.com
partner
indianwebs.com
partner
2025-11-01T12:31:04.924Z
buzzattitrasporti.com favicon

Buzzatti

buzzattitrasporti.com

50
TransportationItalymediumMEDIUM

Buzzatti is a medium-sized Italian logistics company specializing in dry bulk logistics for food, animal feed, and technical products. The company positions itself as an international leader with over 50 years of experience, offering a range of services including road transport, intermodal transport, bonded warehousing, and rebulking. Their business model focuses on providing high-quality, efficient logistics solutions with a strong emphasis on environmental sustainability, as evidenced by their 80% reduction in CO2 emissions and a large fleet of owned vehicles. Technically, the website is built on WordPress using the Elementor page builder, incorporating modern web technologies such as jQuery and Slick Slider. The site is mobile-optimized and provides a good user experience with clear navigation and professional design. However, performance is moderate and accessibility features are basic. From a security perspective, the site uses HTTPS with a good SSL configuration and includes a cookie consent mechanism, indicating basic GDPR compliance. However, there is a lack of advanced security headers and no visible security or incident response policies, which could be improved to enhance trust and resilience. Overall, the website is professional and trustworthy, with clear business information and contact details. The absence of critical security issues and the presence of privacy policies support a positive risk assessment. Strategic improvements in security headers, incident response transparency, and performance optimization are recommended to further strengthen the company's digital posture.

-
83
2
70
-
65
100
logisticstransportdrybulkfoodanimalfeed+5 more
WordPressElementorjQuerySlick Slider+1

Partner Domains:

buzzattitrasporti.com
partner
2025-11-01T12:23:33.609Z
rovalcomponents.com favicon

Specialized Bicycle Components

rovalcomponents.com

71
TransportationUnited StateslargeMEDIUM

Specialized Bicycle Components operates a comprehensive e-commerce platform focused on bicycles, bike wheels, components, and cycling gear. The company targets a broad audience ranging from professional cyclists to casual riders and commuters. Their market position is strong, supported by a professional website that showcases a wide product range and emphasizes quality and innovation. The website is well-designed, mobile-optimized, and provides clear navigation and rich content, enhancing user experience. Technically, the website leverages modern web technologies including React and Next.js, and integrates third-party marketing and analytics tools such as Klaviyo, Monetate, Affirm, and Klarna. The site employs HTTPS with strong security headers, indicating a good security posture. However, the absence of WHOIS data limits the ability to fully verify domain registration legitimacy. Privacy and cookie policies are present and indicate GDPR compliance, though explicit contact details and security policies are limited. Overall, the website demonstrates a mature digital infrastructure and a solid security foundation, with room for improvement in transparency of domain registration and explicit security incident response information. The risk profile is low given the professional nature of the business and the absence of vulnerabilities or suspicious content.

65
73
17
75
82
75
100
bikescyclinge-commercesportsoutdoor
ReactNext.jsJavaScriptCSS+6

Partner Domains:

affirm.com
partner
klarna.com
partner

+1 more partners

2025-11-01T12:08:16.953Z
zps-online.de favicon

Zweckverband Personennahverkehr Saarland (ZPS)

zps-online.de

10
TransportationGermanymediumCRITICAL

Zweckverband Personennahverkehr Saarland (ZPS) operates as a regional public transportation authority in Saarland, Germany, focusing on coordinating and planning local passenger transport services including rail and bus networks. The website serves residents and commuters in the region, providing information on transport tasks, schedules, and news. The organization positions itself as a key regional player in public transport management with a medium-sized operational scale. Technically, the website is built on WordPress using Elementor and Yoast SEO plugins, indicating a modern and maintainable infrastructure. It employs Matomo analytics for privacy-conscious user tracking and Borlabs Cookie for GDPR-compliant cookie management. The site is mobile-optimized and accessible, with good SEO practices and structured navigation. From a security perspective, the site uses HTTPS with good SSL configuration and cookie consent mechanisms. However, explicit security headers are not clearly detected, and no public security or incident response policies are found. No vulnerabilities or suspicious content are evident, and the site maintains a good security posture overall. Overall, the website is professional, trustworthy, and compliant with privacy regulations, serving its public sector transportation role effectively. Strategic improvements in security headers and incident response transparency could further enhance its security maturity and stakeholder trust.

-
-
-
-
-
-
-
publictransportsaarlandbusrailtransportation+4 more
WordPressElementorYoast SEOjQuery+3
2025-11-01T10:51:28.948Z
rolph.de favicon

Rolph

rolph.de

55
TransportationGermanymediumMEDIUM

Rolph.de is a regional public transport information portal dedicated to mobility in Rheinland-Pfalz, Germany. It provides news, updates, and resources related to local public transportation, including bus networks and the Deutschlandticket. The website targets residents and travelers in the region seeking reliable and up-to-date transit information. The platform appears to be affiliated with regional transport authorities or government entities, supported by references to official ministries and verified Facebook domain ownership. Technically, the website is built on TYPO3 CMS, leveraging modern JavaScript libraries such as jQuery and Slick Carousel for UI components. It integrates common marketing and analytics tools including Google Tag Manager, Google Analytics, Facebook Pixel, and advertising networks like DoubleClick and The Trade Desk. The site implements a GDPR-compliant cookie consent mechanism and is mobile-optimized with good accessibility features. From a security perspective, the site enforces HTTPS and uses cookie consent opt-in mechanisms, but lacks explicit security headers and published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the analyzed content. The domain registration data is consistent and appropriate for a public service website, enhancing trustworthiness. Overall, Rolph.de presents a professional, secure, and privacy-conscious platform serving the transportation sector in Rheinland-Pfalz. Strategic improvements could include adding explicit security headers, publishing terms of service and security policies, and providing direct contact information to enhance transparency and user trust.

30
95
17
70
52
70
20
publictransportrheinland-pfalzmobilitynewstypo3+2 more
TYPO3 CMSjQuerySlick CarouselGoogle Tag Manager+5
2025-11-01T10:51:23.937Z
vrn.de favicon

Verkehrsverbund Rhein-Neckar GmbH

vrn.de

49
TransportationGermanymediumHIGH

Verkehrsverbund Rhein-Neckar GmbH operates as a regional public transportation authority in the Rhein-Neckar area of Germany, providing comprehensive services including bus, train, and tram schedules, ticketing, and mobility solutions such as carsharing and e-scooters. The website serves as a central portal for journey planning, traffic updates, and customer service, targeting commuters and general public users in the region. The business model is focused on facilitating public transport and mobility services within a defined geographic area, positioning VRN as a key regional transport provider. Technically, the website is built on the Imperia CMS platform and leverages modern web technologies including jQuery, Leaflet for maps, and Foundation for responsive design. It integrates Matomo analytics with user consent, demonstrating a mature approach to data privacy. Accessibility features such as skip links and visual assistance tools are implemented, enhancing usability for diverse users. Performance is moderate with good mobile optimization and SEO practices. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms, but lacks explicit security policy documentation and incident response contacts. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data is limited but consistent with a legitimate regional transport entity. Overall, the site demonstrates a solid security posture with room for improvement in transparency and security policy communication. The overall risk is low given the nature of the business and the absence of suspicious indicators. Strategic recommendations include publishing a dedicated security policy, providing incident response contact details, enhancing HTTP security headers, and considering a vulnerability disclosure policy to further strengthen trust and compliance.

-
-
-
70
77
60
100
vrnpublictransportbustraintram+5 more
jQueryjQuery UILeafletSelect2+4
2025-11-01T10:51:13.916Z
erixx.de favicon

erixx GmbH

erixx.de

56
TransportationGermanymediumMEDIUM

erixx GmbH is a regional passenger rail service provider operating in Niedersachsen and northern Germany, focusing on routes through Harz, Heide, and Wendland. The company is positioned as a trusted regional transportation operator with a clear business model centered on passenger rail services. The website provides comprehensive travel information, live schedules, ticketing options, and customer support, targeting regional train passengers. The parent company is Netinera, a known transportation group, which adds to erixx's market credibility. Technically, the website employs modern web technologies including HTML5, CSS3, JavaScript, and integrates a Progressive Web App manifest for enhanced user experience. Hosting and DNS are managed via Cloudflare, ensuring reliable performance and security. The site is mobile-optimized, accessible, and SEO-friendly, with embedded third-party widgets for timetable and route planning. From a security perspective, the website enforces HTTPS and follows several best practices, though explicit security headers like X-Frame-Options and X-Content-Type-Options are not clearly visible in the HTML. No vulnerabilities or exposed sensitive data were detected. However, the absence of a published security policy or incident response contact limits transparency in security governance. Overall, the website is professional, trustworthy, and compliant with GDPR, featuring clear privacy and cookie policies. The risk profile is low with no signs of malicious activity or content safety concerns. Strategic recommendations include enhancing security header implementation, publishing a security.txt file, and providing explicit incident response contacts to improve security posture and trust.

55
33
2
70
47
60
100
regionaltraintransportationpublictransitgermanyniedersachsen+3 more
HTML5CSS3JavaScriptCloudflare DNS+2

Partner Domains:

www.netinera.de
parent
www.lnvg.de
partner

+2 more partners

2025-11-01T10:50:58.881Z
der-enno.de favicon

metronom Eisenbahngesellschaft mbH

der-enno.de

52
TransportationGermanymediumMEDIUM

The website www.der-enno.de represents a regional rail transport service operated by metronom Eisenbahngesellschaft mbH, serving the Hannover region and surrounding areas in Lower Saxony, Germany. It provides comprehensive travel planning tools, live timetable data, customer support, and career opportunities, positioning itself as a key regional transportation provider. The site is well-branded, professionally designed, and targets commuters and regional travelers with localized German content and an English alternative. Technically, the site employs modern web technologies including a Progressive Web App (PWA) framework, service workers, and integrates third-party public transport widgets from fahrplaner.vbn.de. Hosting and DNS are managed via Cloudflare, ensuring robust performance and security. The site is mobile-optimized with good accessibility and SEO practices. From a security perspective, the site enforces HTTPS, uses standard security headers, and avoids exposing sensitive data. However, it lacks a dedicated security policy or incident response contact information, and does not publish a vulnerability disclosure policy. Privacy compliance is strong with clear GDPR-aligned privacy and cookie policies and consent mechanisms. Overall, the website demonstrates a mature digital presence with strong business credibility and technical implementation. The security posture is good but could be enhanced with additional transparency and security headers. The risk level is low, with no detected vulnerabilities or suspicious content.

20
33
2
70
47
60
100
regionalrailtransportationpublictransittravelplanningcareer+4 more
JavaScriptHafas public transport widgetService Worker (PWA)Cloudflare DNS and likely CDN+2

Partner Domains:

www.der-enno.com
partner
www.ich-will-zu-metronom.de
partner

+3 more partners

2025-11-01T10:50:53.864Z
inelo.pl favicon

W.A.G. payment solutions, a.s.

inelo.pl

65
TransportationCzech RepubliclargeMEDIUM

Eurowag, incorporating Inelo, is a leading European provider of integrated mobility and payment solutions tailored for the road transport sector. Their offerings include advanced telematics, seamless payment services such as fuel cards and mobile payments, and comprehensive compliance and driver management solutions. The company targets transport companies and fleet managers, aiming to optimize fleet efficiency and regulatory adherence across multiple European markets. The website reflects a mature digital presence with multilingual support and extensive service descriptions. Technically, the website is built on Webflow CMS, leveraging modern JavaScript libraries and integrations such as Google Tag Manager and LiveChat for analytics and customer engagement. The site is well-optimized for mobile devices, features accessibility considerations, and employs security best practices including HTTPS and CAPTCHA on forms. The technical infrastructure suggests a robust and scalable platform suitable for enterprise operations. From a security perspective, the site demonstrates a strong posture with encrypted communications, secure form handling, and no visible vulnerabilities or exposed sensitive data. However, explicit security headers could be more clearly implemented, and incident response contact details are not publicly provided. Privacy compliance is well addressed with comprehensive privacy and cookie policies, including GDPR adherence and user consent mechanisms. Overall, the website and business exhibit high professionalism, trustworthiness, and operational maturity. The lack of public WHOIS data is consistent with privacy protection practices common among large enterprises. Strategic recommendations include enhancing security header implementation, publishing vulnerability disclosure policies, and providing clearer incident response contacts to further strengthen trust and security readiness.

45
50
17
85
47
85
100
transportationfleetmanagementtelematicspaymentservicescompliance+2 more
Webflow CMSjQuery 3.5.1Google Tag ManagerLiveChat+2

Partner Domains:

investors.eurowag.com
partner
selfcare.eurowag.com
service

+3 more partners

2025-11-01T10:27:42.637Z
firexgo.com favicon

fireTMS.com Sp. z o.o.

firexgo.com

70
TransportationPolandmediumMEDIUM

fireXgo is a freight exchange platform integrated into the fireTMS transport management system, designed to serve transport and forwarding companies by providing a unified tool for posting freights, finding transport orders, and managing transport operations comprehensively. The platform leverages the established fireTMS user base and infrastructure, offering real-time load monitoring and GPS telematics integration to enhance operational transparency and efficiency. The business targets freight forwarders and carriers, positioning itself as a secure and reliable marketplace with verified users and a large volume of daily orders. Technically, the website is built on a modern React and Next.js stack, hosted by OVH sas, and integrates Google services such as reCAPTCHA and Tag Manager for security and analytics. The site is mobile-optimized and provides a professional user experience with clear navigation and comprehensive content. However, some GDPR compliance aspects, such as cookie consent mechanisms, are missing. From a security perspective, fireXgo enforces HTTPS, uses user verification to reduce fraud risk, and integrates GPS telematics for real-time tracking. The absence of DNSSEC and explicit security headers suggests room for improvement in hardening the platform. No critical vulnerabilities or exposed sensitive data were detected. Overall, fireXgo presents a credible and professional service with strong business credibility and technical maturity. Strategic improvements in privacy compliance and security policies would further enhance trust and regulatory adherence.

30
85
47
70
69
75
100
freightexchangetransportmanagementfiretmslogisticssaas+2 more
ReactNext.jsGoogle reCAPTCHAGoogle Tag Manager

Partner Domains:

firetms.com
partner
2025-11-01T10:27:37.622Z
mvb.ch favicon

Migros Verteilbetrieb AG

mvb.ch

51
TransportationSwitzerlandlargeMEDIUM

Migros Verteilbetrieb AG is a leading logistics company within the Migros Group, specializing in storage, packaging, picking, and distribution of a wide range of products including food, textiles, and frozen goods. It operates multiple large distribution centers in Switzerland, serving hundreds of Migros stores and migrolino shops daily. The company is well-established with over 50 years of operational history, positioning itself as a key logistics partner in the Swiss retail sector. Technically, the website employs modern web technologies such as Bootstrap, jQuery, and OwlCarousel, and is built on the Umbraco CMS platform. The site is mobile-optimized, uses HTTPS, and includes cookie consent mechanisms compliant with GDPR. While the site lacks explicit security headers and detailed security policies, it demonstrates a solid baseline security posture with no evident vulnerabilities or exposed sensitive data. From a security perspective, the website benefits from HTTPS encryption and cookie consent but could improve by implementing additional HTTP security headers and publishing incident response or security policies. No WAF or blocking mechanisms were detected, and the domain registration data aligns well with the business identity, indicating high legitimacy. Overall, the website is professional, trustworthy, and well-suited for its business purpose. Strategic recommendations include enhancing security headers, improving accessibility, and publishing explicit security and incident response information to further strengthen trust and compliance.

15
65
2
70
72
80
20
logisticsmigrosdistributiontransportswitzerland+3 more
jQuery 3.6.0Bootstrap 4OwlCarouselFontAwesome 4.7+4

Partner Domains:

migros.ch
parent
migrolino.ch
partner

+1 more partners

2025-11-01T10:01:14.922Z
A

Auto Schmid AG

mercedes-benz-unterentfelden.ch

11
TransportationSwitzerlandmediumCRITICAL

Auto Schmid AG operates as an authorized Mercedes-Benz dealership in Switzerland, providing a comprehensive range of automotive services including new and used vehicle sales, leasing, financing, and after-sales services. The company benefits from strong brand association with Mercedes-Benz Schweiz AG, leveraging official product information and service offerings. The website targets car buyers and Mercedes-Benz customers in the Swiss market, offering a professional and user-friendly digital experience. Technically, the website is built on a modern stack including Vue.js and Web Components, hosted on Mercedes-Benz's OneWeb platform with Adobe Experience Manager as the CMS. It demonstrates good performance, mobile optimization, and accessibility. The site employs advanced analytics and marketing tools such as Google Analytics 360, Datadog RUM, and Salesforce marketing suites, with appropriate cookie consent mechanisms. From a security perspective, the site enforces HTTPS, uses strong security headers, and avoids exposing sensitive data. However, it lacks explicit security policy and incident response information, which could be improved. Privacy compliance is robust, with comprehensive privacy and cookie policies aligned with GDPR and Swiss data protection laws. Contact information is transparent and complete, including a named data protection officer. Overall, the website presents a trustworthy, professional, and secure online presence for Auto Schmid AG, supporting its business objectives effectively. Strategic enhancements in security transparency and incident response readiness would further strengthen its posture.

-
-
-
-
-
-
-
automotivemercedes-benzcardealershipleasingservice+2 more
Vue.jsWeb ComponentsGoogle Tag ManagerDatadog RUM+1

Partner Domains:

www.mercedes-benz.ch
partner
www.autoscout24.ch
partner
2025-11-01T09:44:18.364Z
db-bus-challenge.de favicon

DB Bus Challenge

db-bus-challenge.de

41
TransportationGermanysmallHIGH

The website 'DB Bus Challenge' is an interactive online game designed to engage users by simulating bus transportation challenges, likely related to Deutsche Bahn's bus services in Germany. The site targets a general audience interested in public transportation and casual gaming. The business model appears promotional, aiming to increase engagement and brand awareness rather than direct sales. The website is relatively small in scale with basic content and moderate branding consistency. Technically, the site uses a JavaScript-based frontend with RequireJS and jQuery, implementing device detection and responsive design for mobile optimization. Performance is moderate with basic SEO and accessibility features. No CMS or backend technologies are evident from the HTML content. Hosting details are limited but DNS servers indicate a standard hosting environment. From a security perspective, the site uses HTTPS but lacks visible security headers and formal privacy or cookie policies, which are critical for GDPR compliance given the European audience. No contact or incident response information is provided, limiting transparency and trust. No vulnerabilities or exposed sensitive data were detected in the static content. Overall security posture is average but could be improved with standard best practices. The overall risk is moderate with no critical issues detected. Strategic recommendations include adding privacy and cookie policies, improving security headers, providing clear contact and incident response information, and enhancing SEO and accessibility. These improvements would increase user trust, compliance, and security maturity.

25
25
2
60
72
60
20
gametransportationinteractivebusdeutschebahn+1 more
jQueryRequireJSJavaScript
2025-11-01T09:41:09.539Z
bahnshop.de favicon

cyber-Wear Heidelberg GmbH

bahnshop.de

53
TransportationGermanymediumMEDIUM

bahnshop.de is the official merchandise e-commerce platform for Deutsche Bahn, operated by cyber-Wear Heidelberg GmbH. The website offers a wide range of branded products including collectibles, travel accessories, family and kids items, and other merchandise targeted at Bahn fans, travelers, and families. It holds a strong market position as the official shop for Deutsche Bahn merchandise, leveraging the brand's reputation and customer base. The business model focuses on online retail with customer account management and a comprehensive product catalog. The site is well-branded, consistent, and professionally maintained with a medium-sized operational scale and a founding date around 2014. Technically, the website is built on the Shopware CMS platform, utilizing modern web technologies such as JavaScript, CSS3, and HTML5. It integrates Google Tag Manager and Google Analytics for marketing and analytics purposes, and PayPal Unified for payment processing. Hosting is managed via EuroDNS nameservers, indicating a stable and professional hosting environment. The site demonstrates good mobile optimization, accessibility, and SEO practices, with moderate performance. From a security perspective, the site enforces HTTPS, uses CSRF tokens on forms, and implements cookie consent mechanisms compliant with GDPR. Security headers are present but could be enhanced with additional policies like Content-Security-Policy. No vulnerabilities or exposed sensitive data were detected in the HTML content. However, the site lacks a published security.txt or explicit incident response contact information, which could improve transparency and security posture. Overall, bahnshop.de presents a low-risk profile with strong business credibility, good technical implementation, and solid privacy compliance. Strategic recommendations include publishing a security.txt file, enhancing security headers, and providing incident response contacts to further strengthen trust and security readiness.

30
83
2
70
52
60
40
e-commercetransportationmerchandisedeutschebahnshopware+2 more
Shopware CMSGoogle Tag ManagerGoogle AnalyticsPayPal Unified+3

Partner Domains:

mycybergroup.com
partner
2025-11-01T09:40:54.473Z
C

COREhub, S.R.L.

gorivo.com

49
TransportationCroatiasmallHIGH

Gorivo.com operates as a regional ride-sharing platform primarily serving Croatia and neighboring countries. It facilitates peer-to-peer transportation by allowing users to offer and request rides, focusing on routes within Croatia and nearby European nations. The platform has been active since 2003, indicating a mature presence in its niche market. The website's business model centers on connecting drivers and passengers, providing a cost-effective and community-driven transportation alternative. Its market position is niche but stable, targeting individuals seeking carpooling options in the region. Technically, the website is built on ASP.NET WebForms with supporting libraries such as jQuery and Bootstrap, reflecting a legacy but functional technology stack. The site includes standard web fonts, UI components, and Google Adsense for monetization. Performance and mobile optimization are basic, with room for modernization. The site employs cookie consent mechanisms and basic privacy compliance features, though lacks advanced SEO and accessibility optimizations. From a security perspective, the site uses HTTPS and has domain transfer protections in place, but lacks advanced security headers and DNSSEC. No explicit security or incident response policies are published, which could be a gap in compliance and trust. Advertising practices involve multiple ad networks and tracking vendors, indicating moderate user tracking. The overall security posture is average, with recommendations to enhance headers, enable DNSSEC, and publish security policies. Overall, Gorivo.com presents a functional but basic digital presence with moderate trustworthiness and compliance. Strategic improvements in security, privacy transparency, and technical modernization would enhance its risk profile and user confidence.

20
65
17
55
72
75
20
ride-sharingtransportationcarpoolcroatiatravel
ASP.NET WebFormsjQueryBootstrapjQuery UI Datepicker+3
2025-11-01T08:57:14.468Z
akz.hr favicon

Hrvatski Telekom d.d.

akz.hr

52
TransportationCroatiamediumMEDIUM

The website www.akz.hr serves as the official online platform for the Zagreb Bus Station, providing extensive bus ticketing services across Croatia and neighboring countries. It offers users the ability to search for bus schedules, purchase tickets online up to 15 minutes before departure, and access real-time status updates for arrivals and departures. The platform supports mobile app integration, enhancing accessibility for travelers. The business is positioned as a key transportation service provider in the region, backed by Hrvatski Telekom d.d., a reputable Croatian telecommunications company. Technically, the website employs standard web technologies including HTML5, CSS3, and JavaScript, with integrations of Google Tag Manager and Google Analytics for marketing and analytics purposes. Hosting is managed by Hrvatski Telekom with Cloudflare DNS services, ensuring reliable domain resolution. The site demonstrates moderate performance and good mobile optimization, though accessibility features are basic. SEO practices are adequately implemented with proper meta tags and Open Graph data. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks explicit security headers such as Content Security Policy and HSTS, which are recommended for enhanced protection. Privacy compliance is limited due to the absence of a visible privacy policy and terms of service, representing a compliance gap especially under GDPR. No incident response or vulnerability disclosure information is provided. Overall, the website is trustworthy and professionally maintained, with a strong business credibility score. Strategic improvements in privacy policy publication, security header implementation, and comprehensive compliance documentation would elevate its security posture and user trust.

15
10
17
70
47
75
100
busticketstransportationonlineticketingzagrebbusstationtravel
HTML5CSS3JavaScriptGoogle Tag Manager+2
2025-11-01T08:56:59.436Z
jadrolinija.hr favicon

Jadrolinija

jadrolinija.hr

11
TransportationCroatialargeCRITICAL

Jadrolinija is Croatia's largest passenger shipping company, providing ferry and catamaran transport services connecting numerous local and international destinations. The company operates a comprehensive online platform offering schedule information, ticket purchasing, and prepaid travel card services, targeting both local residents and tourists. The website reflects a mature digital presence with consistent branding and a focus on user convenience. Technically, the website employs modern web technologies including jQuery, Plyr video player, and Swiper sliders, alongside Google Fonts and accessibility tools. It is hosted under a Croatian academic network registrar, indicating a stable and regionally appropriate hosting environment. The site is mobile-optimized and accessible, with good SEO practices and performance. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms compliant with GDPR. However, it lacks explicit published security policies, incident response plans, and vulnerability disclosure information. The use of third-party tracking pixels from Google, Meta, and TikTok indicates moderate user tracking, balanced by privacy controls. Overall, Jadrolinija's website is professional, trustworthy, and well-aligned with its business objectives. Strategic improvements in security transparency and incident readiness would enhance its security posture and user trust further.

-
-
-
-
-
-
-
transportationferrycroatiatravelticketing+5 more
jQuery 3.5.1Plyr video player 3.7.8Google Fonts (Plus Jakarta Sans)Swiper.js slider+2
2025-11-01T08:43:14.722Z
revijahak.hr favicon

Hrvatski autoklub

revijahak.hr

61
TransportationCroatiamediumMEDIUM

Revija HAK is an online magazine operated by Hrvatski autoklub, focusing on automotive news, traffic safety, and vehicle maintenance primarily for the Croatian market. The website serves as a content hub for drivers and HAK members, offering news articles, educational tests, and links to official HAK services including membership and webshop. The site is well-branded and professionally designed, targeting Croatian drivers and automotive enthusiasts with relevant and timely content. Technically, the website is built on WordPress with common plugins such as Yoast SEO for search optimization, Advanced Ads for advertising management, and Eightshift GDPR for cookie consent compliance. It uses Cloudflare DNS and is hosted via the Croatian registrar cyber_Folks d.o.o. The site is mobile-optimized and features a clear navigation structure with categorized content sections. Performance is moderate with standard modern web technologies. From a security perspective, the site enforces HTTPS and implements GDPR cookie consent with a detailed modal allowing users to select cookie preferences. However, explicit security headers are not detected, and there is no published security policy or incident response information. No vulnerabilities or exposed sensitive data were found in the HTML content. The WHOIS data is consistent with the business entity and geographic location, supporting legitimacy. Overall, the website presents a low-risk profile with good business credibility and technical implementation. Recommendations include publishing privacy and security policies, adding security headers, and establishing a vulnerability disclosure process to enhance trust and compliance.

35
10
17
88
67
90
100
automobilipromethakilanovimagazinsavjeti+2 more
jQueryYoast SEO pluginAdvanced Ads pluginEightshift GDPR plugin

Partner Domains:

hak.hr
partner
map.hak.hr
partner

+2 more partners

2025-11-01T08:19:03.866Z
skypicker.com favicon

Kiwi.com

skypicker.com

70
TransportationCzech RepubliclargeMEDIUM

Kiwi.com is a prominent online travel agency specializing in providing cheap flights, hotels, and car rental services globally. The platform offers a user-friendly interface with advanced search capabilities including flexible dates and map-based destination exploration. It is trusted by millions and provides additional services such as disruption protection and 24/7 customer support. The website demonstrates a mature digital presence with consistent branding and comprehensive content tailored for travelers seeking affordable travel options. Technically, Kiwi.com employs modern web technologies including React and Tailwind CSS, supported by Google Tag Manager and Forter for analytics and fraud prevention respectively. The site is optimized for performance and mobile responsiveness, ensuring a seamless user experience across devices. Security best practices are observed with HTTPS enforcement and presence of key security headers, although explicit incident response and vulnerability disclosure information are not publicly available. From a security and compliance perspective, Kiwi.com maintains a comprehensive privacy policy and cookie consent mechanism aligned with GDPR requirements. However, the WHOIS data for the domain is not publicly available, which slightly impacts trust but is common for commercial entities using privacy protection services. Overall, the site presents a strong security posture with room for improvement in transparency around incident response and vulnerability management. The overall risk assessment is moderate to low, with recommendations focusing on enhancing security transparency and providing clear contact channels for security incidents. Kiwi.com’s strategic position as a leading travel booking platform is supported by its technical infrastructure and user-centric design, making it a reliable choice for consumers worldwide.

60
68
17
87
57
85
100
travelflightsbookingairfarecheapflights+1 more
ReactTailwind CSSGoogle Tag ManagerForter (fraud prevention)+2

Partner Domains:

cars.kiwi.com
subsidiary
sp.booking.com
partner

+2 more partners

2025-11-01T08:17:38.200Z