Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 10 of 43|Showing 451-500 of 2124
G

Geoff Huston

potaroo.net

59
TechnologyN/asmallMEDIUM

The website potaroo.net is a personal technical resource maintained by Geoff Huston, a recognized figure in Internet infrastructure and network operations. The site offers a rich collection of ISP articles, technical papers, books, presentations, podcasts, and tools primarily targeting network engineers, researchers, and technology professionals. It is supported by APNIC sponsorship, indicating a degree of authority and trust within the Internet community. The business model is content publishing and knowledge sharing, with a niche market position focused on Internet technology education and research. Technically, the website employs a straightforward HTML/CSS/JavaScript stack with Google Analytics for visitor tracking. The site demonstrates moderate performance and basic mobile optimization and accessibility. However, there is no evidence of a modern CMS or advanced frameworks. SEO and accessibility features are basic but functional. Security-wise, HTTPS usage is implied but not explicitly confirmed, and no security headers were detected in the provided data. The site lacks privacy, cookie, and terms of service policies, which impacts compliance and user trust. No contact or incident response information is provided, limiting transparency. Overall, the security posture is moderate with room for improvement in headers, policies, and disclosure mechanisms. The WHOIS data is notably missing or inaccessible, which raises questions about domain registration legitimacy despite the active and professional content. No WAF or blocking mechanisms were detected, and the content is safe for general audiences with no adult or explicit material. Strategically, the site would benefit from enhanced privacy and security disclosures, improved mobile and accessibility features, and clarification or correction of WHOIS registration data to bolster trust and compliance.

15
35
25
60
95
75
100
internetnetworkingbgpdnstechnology+2 more
HTMLCSSJavaScriptGoogle Analytics (gtag.js)
2025-10-07T21:01:07.799Z
protonmail.com favicon

Proton AG

protonmail.com

71
TechnologySwitzerlandmediumMEDIUM

Proton AG operates Proton Mail, the world's largest secure email service with over 100 million users, headquartered in Switzerland. The company offers a suite of privacy-focused services including encrypted email, calendar, cloud storage, password manager, VPN, and more, targeting privacy-conscious individuals, journalists, activists, and businesses. Proton's business model is freemium, providing free secure email accounts supported by paid subscription plans with enhanced features. The company is well-positioned in the privacy technology market, emphasizing Swiss privacy laws and open-source transparency. Technically, Proton's website employs modern web technologies including React and Astro frameworks, delivering a fast, mobile-optimized, and accessible user experience. The infrastructure supports multiple platforms including web, desktop, and mobile apps. SEO and content quality are excellent, reflecting a mature digital presence. Security-wise, Proton demonstrates strong practices with HTTPS enforcement, comprehensive security headers, end-to-end and zero-access encryption, and independent audits. However, DNSSEC is not enabled, and explicit incident response contacts or vulnerability disclosure pages are not found, representing minor gaps. Overall, Proton Mail's website and business exhibit high trustworthiness, professionalism, and compliance with privacy regulations such as GDPR. The risk profile is low, with no detected vulnerabilities or suspicious indicators. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, and providing clearer incident response contacts to further enhance security posture and transparency.

65
53
17
80
72
90
100
encryptedemailprivacysecurecommunicationswisscompanytechnology+2 more
ReactAstroJavaScriptCSS+1

Partner Domains:

protonvpn.com
partner
simplelogin.io
partner

+2 more partners

2025-10-07T19:55:27.331Z
G

Global Multimedia Protocols Group

gmpg.org

43
OtherN/asmallHIGH

The Global Multimedia Protocols Group (GMPG) is a small, niche experimental organization focused on developing and promoting web protocols and conceptual frameworks such as the XHTML Friends Network (XFN) and XHTML Meta Data Profiles (XMDP). The website serves primarily as an informational resource to stimulate simplification and innovation in web technologies. The group operates with a non-commercial, experimental business model and targets audiences interested in web standards and conceptual simplification. Technically, the website is basic, built with simple HTML and CSS, lacking modern web technologies, mobile optimization, and accessibility features. There is no evidence of advanced CMS, analytics, or advertising technologies. The hosting provider is not explicitly identified beyond the registrar and name servers. Performance is likely moderate given the minimal content. From a security perspective, the site lacks critical security headers, privacy and cookie policies, and incident response information. DNSSEC is not enabled, and HTTPS status is unknown but assumed minimal. The domain registration is consistent and legitimate, with a long history dating back to 2003, aligning with the group's founding. No vulnerabilities or suspicious patterns were detected, but the security posture is basic and could be improved. Overall, the website presents low risk but also low maturity in security and privacy compliance. Strategic improvements in security headers, HTTPS enforcement, privacy policies, and contact transparency would enhance trust and compliance.

15
50
17
60
72
75
-
webprotocolsxfnxmdpmetamemeticswebstandards+1 more
HTMLCSS
2025-10-07T12:26:14.428Z
on-res.com favicon

Computer Online AG

on-res.com

48
TransportationSwitzerlandsmallHIGH

The website on-res.com is operated by Computer Online AG, a Swiss company specializing in providing an online reservation and administration system tailored for aviation clubs, flight schools, and charter services. The platform offers real-time flight scheduling, digital flight logs approved by Swiss aviation authorities (BAZL), technical maintenance logs, and integration with Swiss accounting software (Comatic). The business model is that of an Application Service Provider (ASP), targeting niche aviation organizations primarily in Switzerland. The company has been established since 2002, indicating a mature presence in its market segment. Technically, the website employs basic web technologies including HTML, CSS, JavaScript, and jQuery 2.2.4. It supports multiple browsers and mobile devices such as iPads and iPhones, though mobile optimization is basic. The site lacks modern CMS frameworks and advanced SEO or accessibility features, reflecting a functional but dated technical infrastructure. From a security perspective, the domain is registered with a reputable registrar and has a long history, supporting legitimacy. However, the site lacks DNSSEC, security headers, and published privacy or cookie policies, which are notable compliance and security gaps. No WAF or blocking mechanisms are detected, and no analytics or tracking scripts are present, indicating minimal user tracking. Contact information is clearly provided, enhancing trust. Overall, the website scores moderately on content quality and business credibility but lower on technical implementation and privacy compliance. Strategic improvements in security headers, privacy documentation, and modernizing the technical stack would enhance the site's security posture and user trust.

15
35
17
70
67
70
40
flugplatzadministrationreservationssystemflugzeugonline-buchungssystem+5 more
HTMLCSSJavaScriptjQuery 2.2.4

Partner Domains:

comatic.ch
partner
2025-10-04T07:08:05.862Z
futuristica.com favicon

FUTURISTICA d.o.o.

futuristica.com

58
TechnologySloveniamediumMEDIUM

Futuristica d.o.o. is a Slovenian-based digital agency specializing in modern web development, creative web design, SEO, branding, marketing, and AI tool development. Established since 2012, the company serves a global clientele with a strong portfolio of diverse projects, positioning itself as an innovative and reliable partner in the technology sector. The website reflects a professional and consistent brand image, targeting businesses seeking digital growth solutions. Technically, the website leverages modern frameworks such as Next.js and React, with backend technologies including Golang and Laravel. Hosting and DNS are managed via reputable providers including Cloudflare, ensuring good performance and availability. The site is well optimized for mobile devices and SEO, with clear navigation and rich content. From a security perspective, the site uses HTTPS and has domain transfer protections in place, but lacks DNSSEC and important security headers. There is no visible privacy or cookie policy, which is a compliance gap especially under GDPR. Google Analytics is used without a consent mechanism, indicating moderate user tracking without explicit privacy compliance. Overall, the website is trustworthy and professional but would benefit from enhanced privacy compliance and security hardening to improve its risk posture and regulatory adherence.

20
35
17
60
75
75
100
webdevelopmentdigitalmarketingwebdesignseobranding+1 more
Next.jsReactGolangLaravel+3
2025-10-03T15:41:08.921Z
C

Carsten Röpkes | Straßen- und Tiefbau

carsten-roepkes.de

23
TransportationGermanysmallCRITICAL

Carsten Röpkes | Straßen- und Tiefbau is a small local construction business specializing in road and civil engineering services in the Ostfriesland region of Germany. The company offers a range of services including street and deep construction, paving with natural and concrete stones, driveway and terrace construction, and pipeline construction. The website serves as an informational portal targeting local customers and businesses seeking specialized construction and landscaping services. Technically, the website is built with basic HTML, CSS, and JavaScript, incorporating Google Analytics for visitor tracking. The site is hosted on servers associated with kasserver.com, consistent with the domain's WHOIS data. The website lacks modern CMS frameworks and shows basic mobile and accessibility optimization. SEO is reasonably addressed through meta tags and structured navigation. From a security perspective, the website lacks HTTPS, which is a critical vulnerability for user data protection and trust. No security headers are present, and there are no visible privacy or cookie policies, indicating non-compliance with GDPR requirements. The use of Google Analytics without a consent mechanism further highlights privacy compliance gaps. Contact information is clearly provided, but no incident response or security policies are disclosed. Overall, the website is functional and informative but requires significant improvements in security, privacy compliance, and technical modernization to enhance trustworthiness and protect user data. Strategic implementation of HTTPS, security headers, privacy policies, and consent mechanisms is recommended to align with best practices and regulatory requirements.

15
-
-
70
-
45
-
straenbautiefbaupflasterarbeitennatursteinrohrleitungsbau+2 more
HTMLCSSJavaScriptGoogle Analytics
2025-09-22T07:40:26.832Z
foxnet.fi favicon

Fox Holding Oy

foxnet.fi

33
TechnologyFinlandsmallHIGH

Foxnet, operated by Fox Holding Oy, is a Finnish small business specializing in accessible and user-friendly WordPress website development. The company is led by Sami Keijonen, who brings decades of experience and a strong focus on accessibility, UX, and project management. The website clearly communicates the services offered, including coding, auditing, training, and mentoring, targeting clients who value quality and accessibility in web development. The business model is service-based with hourly rates and project estimates, positioning Foxnet as a niche expert in the Finnish market. Technically, the website is built on WordPress with a modern tech stack including HTML, CSS, JavaScript, PHP, and React for block development. Hosting is provided by Shellit.org, a Finnish registrar and hosting provider. The site is well-structured, mobile-optimized, and accessible, reflecting the business's core values. However, there is room for improvement in security headers and privacy compliance. Security posture is solid with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. The absence of security headers and privacy/cookie policies represents compliance and security gaps that should be addressed. No incident response or vulnerability disclosure information is provided, which could be improved to enhance trust and readiness. Overall, Foxnet presents a professional, trustworthy, and technically competent web presence with strong business credibility. Strategic improvements in privacy compliance and security hardening would elevate the site's security posture and regulatory adherence.

15
10
2
60
-
75
20
wordpressaccessibilitywebdevelopmentfrontendmentoring
HTMLCSSJavaScriptPHP+1

Partner Domains:

meom.fi
partner
2025-09-07T08:03:59.883Z
C

colophon

colophon.info

62
OtherNetherlandssmallMEDIUM

Colophon is a small Amsterdam-based graphic design studio and type-design research initiative specializing in commissioned design work, research projects, free font distribution, and educational activities. The website serves as a detailed portfolio showcasing collaborations with cultural institutions, exhibitions, publications, and teaching engagements. The business targets design professionals, researchers, and cultural organizations with a niche focus on typography and graphic design research. Technically, the website is built with basic HTML and CSS, including a custom font-face. It lacks modern frameworks, CMS, or advanced hosting details. The site is moderately optimized for performance and mobile use but has basic accessibility and SEO features. No analytics or tracking scripts are detected, indicating minimal user tracking. From a security perspective, the site lacks visible HTTPS confirmation and security headers, and no privacy or cookie policies are present, which lowers its compliance posture. The WHOIS data is privacy protected, common for small creative businesses, but limits transparency. No forms or input fields reduce attack surface, but incident response and security policies are absent. Overall, the site is professional and trustworthy in content and business credibility but would benefit from improved security practices, privacy compliance, and technical modernization to enhance trust and resilience.

65
35
2
85
62
75
100
graphicdesigntypographytypedesignresearchamsterdam+4 more
HTMLCSSCustom font-face (LincolnMITRE-LM5x7)
2025-09-07T02:11:55.861Z
H

Hamilton Communications

hamilton.com

47
TelecommunicationsN/asmallHIGH

Hamilton Communications operates as a private Internet service provider with a long-established domain dating back to 1992. The company does not accept new customers and primarily provides services to existing clients. The website is minimalistic, serving mainly as an informational portal and a point of contact for abuse reporting. The business model is niche and focused on maintaining a private ISP service without public customer acquisition. The market position is limited but stable given the domain age and consistent branding. Technically, the website is built on basic HTML and CSS without modern frameworks or CMS platforms. Hosting is provided by Linode, a reputable provider, with multiple Linode nameservers configured. The site lacks mobile optimization and advanced SEO or accessibility features, indicating a low level of digital maturity. No analytics or tracking technologies are present, reflecting minimal data collection practices. From a security perspective, the domain benefits from transfer and update prohibitions, enhancing domain security. However, the absence of DNSSEC, security headers, and visible HTTPS enforcement reduces the overall security posture. No privacy or cookie policies are published, and no vulnerability disclosure or incident response policies are evident beyond a single abuse contact email. These gaps suggest room for improvement in compliance and security transparency. Overall, the website presents a low-risk profile due to its limited functionality and content but would benefit from enhanced security measures, privacy compliance, and technical modernization to improve trust and resilience against emerging threats.

15
50
2
75
85
75
20
ispinternetserviceproviderhamiltoncommunicationstelecommunications
HTMLCSS
2025-09-06T16:59:17.313Z
unstable.money favicon

Unstable Protocol

unstable.money

55
FinanceN/asmallMEDIUM

Unstable Protocol is a decentralized finance (DeFi) platform specializing in high-leverage yield strategies. It enables users to borrow the nUSD stablecoin against high-yield stable assets, allowing for yield looping and portfolio leverage enhancement. The platform targets DeFi users and cryptocurrency investors seeking advanced yield optimization. The website presents a professional and consistent brand image with clear calls to action and community engagement links, positioning itself as a niche player in the DeFi space backed by multiple investment firms. Technically, the website employs modern web technologies including JavaScript modules and CSS with responsive design, ensuring excellent mobile optimization and fast performance. However, no CMS or hosting provider details are evident. The site lacks explicit security headers and privacy-related policies, which are areas for improvement. No analytics or tracking scripts were detected, indicating minimal user tracking. From a security perspective, the site uses HTTPS, which is a strong baseline. The absence of security headers and formal privacy or cookie policies reduces the overall security posture. The WHOIS data is unavailable due to query failure or privacy protection, which is common in crypto projects but slightly reduces transparency. No contact information or incident response channels are provided, limiting user trust and support options. Overall, the site is functional, well-designed, and focused on its DeFi niche but would benefit from enhanced transparency, security policies, and contact information to improve trust and compliance.

30
50
2
40
72
75
100
defifinancecryptocurrencyblockchainstablecoin+2 more
JavaScriptCSSHTMLES Modules
2025-09-06T12:24:02.036Z
A

Admiral

slackpod.com

54
MediaN/asmallMEDIUM

The domain slackpod.com currently serves a 404 Not Found error page with informational content about Admiral's copyright access control and privacy consent services. Admiral operates this domain as a service provider for digital publishers, focusing on copyright compliance and GDPR privacy management. The website lacks active business content, contact information, or interactive features, indicating it is not a fully operational business site but rather a service endpoint or placeholder. Technically, the site is hosted on Google Cloud Platform in Europe and serves only static content (JavaScript, HTML, CSS) with no executable files or downloads. The domain is secured with HTTPS and frequent certificate rotation, but lacks DNSSEC and visible security headers. No tracking or analytics scripts are present, and privacy compliance is basic but present. The site does not implement a cookie consent mechanism despite mentioning cookie policies. From a security perspective, the domain follows good practices by enforcing encryption and avoiding executable content. However, the absence of security headers and formal vulnerability disclosure policies limits its security posture. The WHOIS data shows a consistent registration with a reputable registrar and no suspicious patterns, supporting domain legitimacy. Overall, the site is low in content quality and business credibility due to its 404 status and lack of contact details. The security posture is moderate but could be improved with additional headers and policies. The domain appears to be a service endpoint rather than a customer-facing business website, which explains the minimal content and limited business information.

35
50
2
60
75
75
100
404copyrightprivacygdprdigitalpublishing+1 more
JavaScriptHTMLCSS
2025-09-06T11:09:36.957Z
S

See PrivacyGuardian.org

88lm.vip

46
OtherUnited StatessmallHIGH

The website 88lm.vip functions primarily as a login and registration portal for the '88联盟' platform, targeting Chinese-speaking users. It provides direct links to login and registration pages hosted on an external domain (pc.pg3we.com) and includes minimal contact information such as a QQ number and a Telegram handle. The business model appears to be centered around user access management rather than direct service delivery on this domain. The domain is newly registered in December 2024 with privacy protection, which obscures registrant details and creates some trust concerns due to mismatch with the website's language and content. Technically, the website uses basic HTML, CSS, and JavaScript, including third-party analytics and tracking scripts from 51.la. The site lacks advanced frameworks or CMS and shows basic mobile optimization and accessibility. Performance is moderate but SEO and content quality are minimal. Security posture is weak with no DNSSEC, no security headers, and no published privacy or cookie policies. The site uses HTTPS but links to external domains for critical functions like login and registration, which may pose security risks. From a security perspective, the site does not demonstrate mature security practices or compliance with privacy regulations such as GDPR. There are no incident response contacts or vulnerability disclosures. The use of privacy protection in WHOIS and the mismatch between registrant info and website content reduce trustworthiness. No adult or explicit content is detected, and the site is rated safe for general audiences. Overall, the website scores low on content quality, security, and privacy compliance, reflecting a minimalistic and early-stage online presence. Strategic improvements in transparency, security policies, and hosting critical services on the primary domain are recommended to enhance trust and compliance.

30
50
2
60
72
70
40
loginregistrationchineseanalyticsprivacyprotection
JavaScriptHTMLCSS
2025-09-04T18:44:41.275Z
hg-daigou.com favicon

货源通

hg-daigou.com

35
RetailChinasmallHIGH

货源通 is a Chinese wholesale and retail product information platform established in 2010, providing a user-driven marketplace for various product categories including shoes, bags, clothing, watches, and cosmetics. The platform operates as a non-commercial information publishing site where users must complete real-name authentication before posting. It targets a broad audience of suppliers and buyers seeking product sourcing information. The website is structured with multiple subdomains dedicated to specific product categories, indicating a comprehensive product offering. The business model focuses on free information dissemination rather than direct sales, positioning itself as a reference platform in the retail supply chain sector. Technically, the website uses a custom CMS with standard web technologies including JavaScript, jQuery 1.11, CSS, and HTML. It employs Baidu Analytics for user tracking and is hosted with GoDaddy as the registrar, using Alibaba DNS servers. The site is moderately optimized for performance and mobile use but lacks advanced accessibility and SEO features. Security-wise, HTTPS is enabled, but no advanced security headers or DNSSEC are implemented. The use of an outdated jQuery version presents potential vulnerabilities. Privacy compliance is limited, with no cookie consent mechanism and only a basic privacy policy present. Overall, the security posture is moderate with room for improvement in security headers, library updates, and privacy compliance. The domain registration is consistent and trustworthy, with no privacy protection masking registrant details. The site is fully accessible without WAF or blocking mechanisms. Strategic improvements in security and privacy policies would enhance trust and compliance. The platform serves as a useful resource for wholesale sourcing but should address technical and compliance gaps to strengthen its market position and user trust.

30
50
2
60
-
75
-
JavaScriptjQuery 1.11CSSHTML+1

Partner Domains:

xie.hg-daigou.com
subsidiary
bao.hg-daigou.com
subsidiary

+1 more partners

2025-09-04T16:38:15.666Z
lifescienceopenspace.com favicon

Klaster LifeScience Krakow

lifescienceopenspace.com

53
HealthcareN/asmallMEDIUM

The website 'LSOS Collaboration Platform' is managed by Klaster LifeScience Krakow and serves as an open collaboration platform aimed at promoting innovation and entrepreneurship in health and quality of life sectors. It targets innovators, entrepreneurs, and community members interested in life sciences. The platform offers services such as community connection, event participation, project collaboration, and partner discovery. The market position is niche, focusing on life sciences innovation. Technically, the website is built using modern JavaScript technologies including React and loads resources from the Innoloft platform. The site appears to have moderate performance and good mobile optimization but lacks visible accessibility features and comprehensive SEO optimization. The HTML snapshot shows minimal content with a loading spinner, indicating possible dynamic content loading or incomplete snapshot. From a security perspective, no HTTPS or security headers information is available in the provided data. There are no visible privacy, cookie, or terms of service policies, nor contact information for security or data protection. The WHOIS data is unavailable, which raises concerns about domain legitimacy and trustworthiness. No vulnerabilities or security best practices are evident from the data. Overall, the website shows a basic level of professionalism and technical implementation but lacks critical security and privacy compliance elements. The domain registration status is unclear, which impacts trust. Strategic improvements in security posture, privacy policies, and transparency are recommended to enhance credibility and user trust.

65
50
17
60
72
75
40
lifesciencescollaborationinnovationhealthcareentrepreneurship
JavaScriptReactCSSHTML
2025-08-04T12:28:31.923Z
itingnao.com favicon

听脑AI-录音转文字助手_免费在线会议纪要总结软件_让沟通更高效

itingnao.com

63
TechnologyChinasmallMEDIUM

The website itingnao.com presents a newly launched AI-powered transcription and meeting summarization service primarily targeting Chinese-speaking users. It offers real-time speech-to-text conversion with high accuracy, supporting various scenarios such as meetings, classrooms, and sales calls. The business appears to be a small technology service provider founded in 2024, leveraging modern web technologies including Next.js and React. Hosting is provided by Alibaba Cloud, a reputable provider. Technically, the site is well-structured with good mobile optimization and moderate performance. It integrates analytics tools like Microsoft Clarity and Baidu Analytics for user behavior tracking. However, the site lacks critical privacy and cookie policies, consent mechanisms, and explicit contact or security policy disclosures, which are important for compliance and user trust. Security posture is basic with HTTPS enabled but missing important security headers and incident response information. The WHOIS data is transparent and consistent with the business claims, indicating legitimacy despite the domain's recent registration. Overall, the site is functional and professional but requires improvements in privacy compliance and security best practices. Strategic recommendations include implementing comprehensive privacy and cookie policies with consent mechanisms, adding security headers, publishing incident response contacts, and enhancing transparency to build user trust and meet regulatory requirements.

15
50
10
70
100
85
100
aitranscriptionmeetingsummaryspeechtotextchineselanguage+1 more
ReactNext.jsJavaScriptCSS+1
2025-08-04T09:34:13.773Z
boluoyun.com favicon

上海云纯网络科技有限公司

boluoyun.com

44
TechnologyChinamediumHIGH

Boluoyun.com is a Chinese cloud hosting and VPS service provider specializing in Hong Kong, US, and domestic cloud servers. The company, Shanghai YunChun Network Technology Co., Ltd., founded in 2014, offers a range of cloud hosting products including VPS, cloud servers, CDN, and server rental services. The website targets general customers seeking reliable cloud hosting solutions with a focus on the Chinese and Hong Kong markets. The business positions itself as a professional and known service provider with 24/7 technical support and multiple trust indicators such as ICP licensing and customer case studies. Technically, the website uses basic HTML, CSS, and JavaScript without modern frameworks or CMS detected. The site is moderately performant but lacks advanced mobile optimization and accessibility features. SEO is basic with meta keywords and description but no structured data or Open Graph tags. The site uses Baidu Analytics for user tracking but lacks privacy and cookie policies, indicating poor privacy compliance. From a security perspective, the domain is registered with a reputable registrar and has a long registration period with clientTransferProhibited status, indicating domain security. However, the website lacks DNSSEC, HTTPS enforcement details, and security headers, which lowers its security posture. No incident response or vulnerability disclosure information is provided, and no forms are present to assess input security. Overall, the website is functional and moderately credible but requires improvements in security best practices, privacy compliance, and technical modernization to enhance trust and user experience. Strategic recommendations include enabling DNSSEC, enforcing HTTPS with HSTS, publishing privacy and cookie policies, adding security headers, and implementing vulnerability disclosure mechanisms.

15
50
2
60
72
70
20
cloudhostingvpshongkongvpsserverrentalidc+2 more
HTMLCSSJavaScript
2025-08-04T06:04:32.411Z