Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149319
Websites
130
Industries
113
Countries
52
Avg Score
Page 10 of 73|Showing 451-500 of 3618
pearldiver.io favicon

Blackpearl Group Limited

pearldiver.io

65
TechnologyNew ZealandmediumMEDIUM

Pearl Diver, operated by Blackpearl Group Limited, is a New Zealand-based B2B SaaS company specializing in intent data and prospect identification solutions for marketers and sales teams. The platform leverages real-time buyer signals beyond traditional ad platforms to improve targeting accuracy, reduce wasted ad spend, and increase conversion rates. The company is well-positioned in the marketing technology sector with a strong user base and positive market reputation, supported by numerous customer testimonials and G2 reviews. Technically, the website is built on Webflow CMS and integrates advanced marketing and analytics tools such as HubSpot, Microsoft Clarity, and Google Tag Manager. The site demonstrates excellent design quality, mobile optimization, and SEO practices, ensuring a smooth user experience and effective digital presence. Security-wise, the site enforces HTTPS and uses controlled third-party scripts, though it lacks some advanced security headers and a published security policy. The security posture is solid with no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with comprehensive privacy and cookie policies, including GDPR and CCPA considerations. However, the WHOIS data is privacy protected, limiting transparency on domain registration details, though this is common and justified for commercial SaaS providers. Overall, Pearl Diver presents a professional, trustworthy, and technically mature online presence with minor recommendations to enhance security headers and incident response transparency. The business is credible and well-aligned with its market claims, making it a reliable partner for marketers seeking intent data solutions.

60
68
17
60
57
75
100
intent-datamarketing-technologyb2bsaaslead-generation+2 more
WebflowGoogle FontsHubSpot (analytics, messaging, forms, ads pixel)Microsoft Clarity+3

Partner Domains:

pearldiver.blackpearl.com
partner
help.blackpearlmail.com
partner

+1 more partners

2025-10-26T13:17:39.287Z
teachers.org.uk favicon

National Education Union

teachers.org.uk

62
EducationUnited KingdomlargeMEDIUM

The National Education Union (NEU) is a prominent UK-based education union focused on advocating for better school funding, teacher pay, and member support. The website serves as a comprehensive platform offering campaigns, advice, training courses, and union publications targeted at education professionals and union members. The NEU positions itself as a leading union in the education sector with a large membership base and a strong advocacy role. Technically, the website is built on Drupal 10 with Commerce 2, leveraging modern web technologies and analytics tools such as Google Tag Manager and Microsoft Clarity. The site demonstrates good digital maturity with responsive design, accessibility features, and SEO optimization. Performance is moderate, with room for optimization. From a security perspective, the site employs HTTPS with strong SSL configuration and security headers. It includes a cookie consent mechanism aligned with GDPR requirements. No critical vulnerabilities or exposed sensitive data were detected. However, explicit security policies and incident response contacts are not publicly available, which could be improved. Overall, the NEU website is a professional, trustworthy, and well-maintained platform that effectively supports its business objectives. The risk profile is low, with recommendations focusing on enhancing transparency around security policies and incident response to further strengthen trust and compliance.

55
68
2
75
57
50
100
educationunionteachercampaignadvice+2 more
Drupal 10Commerce 2Google Tag ManagerMicrosoft Clarity+2
2025-10-26T13:17:24.255Z
oeec.biz favicon

Offshore Energy

oeec.biz

65
EnergyUnited StatesmediumMEDIUM

Offshore Energy operates a professional event website promoting the Offshore Energy Exhibition & Conference scheduled for November 2025 in Amsterdam. The business focuses on organizing and hosting a major industry event targeting energy sector professionals, exhibitors, and visitors interested in offshore energy solutions. The website provides comprehensive event information, exhibitor details, ticketing options, and networking opportunities, positioning itself as a key player in the offshore energy event market. Technically, the website is built on WordPress with Elementor, leveraging modern web technologies including Google Analytics, Microsoft Clarity, and CookieYes for privacy compliance. The site demonstrates good SEO, accessibility, and mobile optimization, with a moderate performance profile. Security measures include HTTPS enforcement, Google reCAPTCHA, and a detailed cookie consent mechanism, although some security headers and policies are not explicitly published. The security posture is solid with no critical vulnerabilities detected in the HTML content. However, the absence of a published privacy policy, terms of service, security policy, and incident response contacts represents areas for improvement. The domain registration uses privacy protection, which is justified for this event business, and the domain age aligns with the event timeline. Overall, the website is trustworthy, professional, and compliant with cookie consent regulations but would benefit from enhanced transparency in privacy and security policies to strengthen user trust and regulatory compliance.

25
88
47
70
47
60
100
energyoffshoreconferenceexhibitionevent+3 more
WordPressElementorGoogle AnalyticsGoogle Tag Manager+5
2025-10-26T11:00:19.688Z
filmana.cz favicon

Elevup s.r.o.

filmana.cz

62
MediaCzech RepublicsmallMEDIUM

Filmana.cz is a Czech-Slovak streaming platform specializing in Christian films, series, and documentaries. Founded in 2023 and based in Zlín, Czech Republic, it operates under Elevup s.r.o. The platform targets audiences interested in faith-based media content, positioning itself as the first in the region with this niche focus. The business model is subscription-based streaming, supported by an independent foundation promoting Christian messages through film art. Technically, the website is built using modern frameworks such as Next.js and React, hosted on AWS infrastructure. It integrates standard analytics and marketing tools including Google Analytics, Microsoft Clarity, Google Tag Manager, and Facebook Pixel. The site implements a comprehensive cookie consent mechanism via Cookiebot, ensuring GDPR compliance in user tracking and data collection. From a security perspective, the site enforces HTTPS and uses cookie consent controls to manage user privacy. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not present. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data confirms domain registration consistency and legitimacy, matching the business's founding date and location. Overall, Filmana.cz presents a professional and trustworthy online presence with good content quality and technical implementation. To enhance security posture and compliance, it is recommended to publish detailed privacy and security policies, implement security.txt, and regularly audit third-party scripts. The platform is safe for general audiences with no adult or questionable content detected.

15
88
17
55
77
65
100
streamingchristianmediaczechslovak+4 more
Next.jsReactAWS DNSCookiebot+4
2025-10-26T09:46:23.053Z
healthpartnersplans.com favicon

Health Partners Plans

healthpartnersplans.com

62
HealthcareUnited StateslargeMEDIUM

Health Partners Plans, Inc. is a regional healthcare insurance provider offering Medicaid, CHIP, Medicare Advantage, and Individual and Family health plans. Affiliated with Jefferson Health and Thomas Jefferson University, it serves a broad audience including families, children, and seniors, focusing on whole-person health coverage. The website reflects a professional and consistent brand presence with clear navigation and relevant content tailored to its target audience. Technically, the site uses Adobe Experience Manager CMS and integrates multiple modern analytics and tracking tools such as Microsoft Clarity, Crazy Egg, Google Tag Manager, and Freshpaint, indicating a mature digital infrastructure. Mobile optimization and SEO practices are good, though accessibility could be improved. Security posture is solid with HTTPS enforced and no visible sensitive data exposure, but lacks some recommended security headers and explicit incident response information. Privacy compliance is partially addressed with a comprehensive privacy policy and terms of service, but no cookie consent mechanism was detected despite tracking scripts in use. WHOIS data is unavailable, which slightly reduces trust but the strong affiliation with known healthcare entities supports legitimacy. Overall, the website is professional, secure, and trustworthy with room for improvement in privacy and security transparency.

40
53
2
70
77
75
100
healthcareinsurancemedicaidchipmedicare+2 more
jQueryGoogle Tag ManagerMicrosoft ClarityCrazy Egg+1

Partner Domains:

jefferson.edu
partner
jeffersonhealth.org
partner
2025-10-26T04:21:51.567Z
jeffersonhealthplans.com favicon

Jefferson Health Plans

jeffersonhealthplans.com

65
HealthcareUnited StatesmediumMEDIUM

Jefferson Health Plans is a regional healthcare insurance provider offering Medicare Advantage, Individual and Family plans, Medicaid, and CHIP plans. It operates under the umbrella of Health Partners Plans, Inc. and is affiliated with Jefferson Health and Thomas Jefferson University, providing a strong brand presence and community focus. The website presents comprehensive information about their products and services, targeting individuals and families seeking affordable health coverage in the region. Technically, the site is built on Adobe Experience Manager and uses modern analytics and tracking tools such as Crazy Egg, Microsoft Clarity, and Freshpaint, indicating a mature digital infrastructure. The site is mobile optimized and well-structured with good SEO practices. Security posture is generally good with HTTPS enforced, but lacks visible security headers and a cookie consent mechanism, which are areas for improvement. WHOIS data is unavailable, which reduces transparency and trust slightly, but the overall branding and external references support legitimacy. Privacy and terms of service pages are present, though GDPR compliance indicators are minimal. Overall, the site is professional, trustworthy, and serves its business purpose effectively.

40
53
2
85
77
85
100
healthcareinsurancemedicaremedicaidfamilyplans+2 more
jQueryGoogle Tag ManagerCrazy EggMicrosoft Clarity+1

Partner Domains:

healthpartnersplans.com
partner
jefferson.edu
partner

+2 more partners

2025-10-26T03:47:35.966Z
decathlon.com favicon

Decathlon

decathlon.com

66
RetailUnited StatesenterpriseMEDIUM

Decathlon America operates as an enterprise-level e-commerce retailer specializing in outdoor sports clothing and gear. The website targets outdoor enthusiasts and general consumers in the United States, offering a wide range of products including apparel, equipment, and accessories for activities such as camping, hiking, and running. The business model is focused on direct online sales through a Shopify-powered platform, leveraging a strong brand presence and multiple marketing tools to engage customers. Technically, the website is built on the Shopify platform using the Dawn theme, integrating various third-party services such as Klaviyo for email marketing, Dynamic Yield for personalization, and Microsoft Clarity for analytics. The site demonstrates good mobile optimization, SEO practices, and moderate performance. Security is managed primarily through Shopify's infrastructure, with HTTPS enforced and several security best practices observed, although explicit security headers and policies could be improved. From a security perspective, the site shows a mature posture with no visible vulnerabilities or exposed sensitive data. However, the absence of explicit privacy, cookie, and terms of service pages in the provided content, as well as missing WHOIS registration data, slightly reduce trust and compliance confidence. The extensive use of tracking and marketing scripts indicates a high level of user data collection, which should be balanced with transparent privacy practices. Overall, Decathlon America's website is professional, secure, and well-positioned in the retail market, but would benefit from enhanced privacy compliance documentation and clearer contact information to improve user trust and regulatory adherence.

60
58
2
85
57
85
100
e-commerceretailsportsoutdoorshopify+3 more
ShopifyJavaScriptKlaviyoDynamic Yield+7
2025-10-26T02:31:26.493Z
em-lyon.com favicon

emlyon business school

em-lyon.com

64
EducationFrancelargeMEDIUM

emlyon business school is a prestigious and long-established European business school founded in 1872, offering a wide range of business education programs including Grande Ecole, Bachelors, Masters, MSc, MBA, and executive education. The school holds triple accreditation (EQUIS, AACSB, AMBA), underscoring its high academic standards and global recognition. It serves a diverse international student body across multiple campuses in Lyon, Shanghai, Paris, and Mumbai. The website reflects a mature digital presence with a modern Drupal CMS, responsive design, and comprehensive content tailored to prospective students and professionals. Technically, the website employs modern web technologies including Bootstrap for responsive design, Google Tag Manager for analytics and marketing, and Didomi for GDPR-compliant cookie consent management. The site is well-optimized for SEO and accessibility, with clear navigation and structured data enhancing search engine understanding. Security posture is strong with HTTPS enforced and domain locking status flags, though DNSSEC is not enabled, representing an area for improvement. From a security and compliance perspective, the site demonstrates good privacy practices with explicit privacy and cookie policies, consent mechanisms, and no detected vulnerabilities or suspicious domains. However, explicit security policies and incident response contacts are not published, which could be enhanced to improve transparency and trust. Overall, the site is safe, professional, and trustworthy, serving its educational mission effectively.

50
68
17
75
52
65
100
educationbusinessschoolmanagementmbaexecutiveeducation+2 more
Drupal CMSBootstrapGoogle Tag ManagerDidomi Consent Management+3
2025-10-26T01:27:41.153Z
breezy.hr favicon

Breezy HR, Inc.

breezy.hr

62
TechnologyUnited StatesmediumMEDIUM

Breezy HR, Inc. is a well-established technology company specializing in modern hiring software and applicant tracking systems designed to streamline recruitment processes for businesses. With a strong market position supported by over 17,000 customers and recognition from Gartner and G2, Breezy HR offers a comprehensive SaaS platform that covers job advertising, candidate management, offer management, and performance review cycles. The company operates under the parent organization Learning Technologies Group plc and is headquartered in Raleigh, North Carolina. Technically, the website is built on a modern Webflow CMS platform, leveraging a robust tech stack including AWS hosting, multiple analytics and marketing tools, and video hosting via Wistia. The site demonstrates excellent performance, mobile optimization, and SEO practices, providing a professional and user-friendly experience. Security measures include HTTPS enforcement, Content Security Policy headers, and ISO/IEC 27001 certification, reflecting a mature security posture. Privacy compliance is well addressed with clear privacy and cookie policies, including consent mechanisms and GDPR adherence. Contact information is transparent and consistent across the site and structured data. No critical vulnerabilities or blocking mechanisms were detected, indicating a trustworthy and accessible online presence. Overall, Breezy HR presents a secure, professional, and credible digital footprint suitable for its business domain.

25
43
17
70
77
75
100
hrsoftwareapplicanttrackingsystemrecruitmenthiringsaas+1 more
WebflowGoogle Tag ManagerMicrosoft ClarityCustomer.io+9

Partner Domains:

ltgplc.com
parent
2025-10-26T01:22:11.376Z
dpharmconference.com favicon

The Conference Forum

dpharmconference.com

57
HealthcareN/amediumMEDIUM

DPHARM Conference is a well-established annual event focused on modernizing clinical research and clinical trial operations. It targets senior clinical operations executives, R&D professionals, patient advocates, and technologists, providing a platform for thought leadership and innovation in the pharmaceutical industry. The conference is organized by The Conference Forum, a recognized entity in the healthcare events sector with a domain age consistent with its claimed history. The website presents professional content, including detailed speaker profiles, sponsors, and event information, reflecting a strong market position in healthcare conference organization. Technically, the website employs a modern technology stack including jQuery, Bootstrap, and various JavaScript libraries for UI and analytics. It is hosted on Amazon AWS with CloudFront CDN, ensuring reliable performance and moderate loading speeds. The site is mobile optimized and uses HTTPS with good SSL configuration, though DNSSEC is not enabled. Analytics and tracking tools such as Google Analytics, Microsoft Clarity, and LinkedIn Insight Tag are used, indicating moderate user tracking. From a security perspective, the site follows several best practices including HTTPS enforcement and form protection via Google reCAPTCHA. However, it lacks published privacy and cookie policies, incident response contacts, and vulnerability disclosure information, which are important for compliance and trust. No critical vulnerabilities or suspicious content were detected. Overall, the security posture is good but could be improved with enhanced transparency and policy disclosures. The overall risk assessment is low, with the site appearing trustworthy and professional. Strategic recommendations include publishing comprehensive privacy and cookie policies with consent mechanisms, enabling DNSSEC, and providing clear incident response and vulnerability disclosure channels to enhance compliance and user trust.

20
35
17
60
67
75
100
conferenceclinicaltrialspharmaceuticalhealthcarerd+2 more
jQueryBootstrap 3.4.1Slick CarouselPhotoSwipe+5

Partner Domains:

theconferenceforum.org
partner
clinicaltrialsoperations.org
partner
2025-10-26T00:10:24.154Z
patientsaspartners.org favicon

The Conference Forum

patientsaspartners.org

59
HealthcareN/asmallMEDIUM

Patients as Partners in Clinical Research and Patient Access is a specialized platform operated by The Conference Forum, focusing on elevating the patient voice within clinical research and healthcare access. The website offers a range of services including conferences, editorial content, podcasts, and webinars aimed at healthcare professionals, patient advocates, and industry stakeholders. The platform positions itself as a niche leader in patient engagement communication within the healthcare sector, with a business model centered on content and event marketing. Founded in 2018, the organization maintains a consistent and professional brand presence with good content quality and user experience. Technically, the website employs a modern technology stack including jQuery, Bootstrap, Slick Carousel, Select2, and integrates multiple analytics and tracking tools such as Google Analytics, Microsoft Clarity, and LinkedIn Insight Tag. Hosting is provided by Bluehost Inc., and the site is secured with HTTPS and Google reCAPTCHA v3 for form protection. Mobile optimization and SEO practices are good, though accessibility features are basic. Performance is moderate, with opportunities for improvement in security headers and DNS security. From a security perspective, the site enforces HTTPS and uses CAPTCHA to protect forms, but lacks DNSSEC and important security headers like Content-Security-Policy. There is no published security policy or incident response contact, and no cookie consent mechanism is present, which may impact GDPR compliance. No vulnerabilities or exposed sensitive data were detected in the HTML content. The WHOIS data is consistent with the business age and domain registration details, indicating a legitimate and stable online presence. Overall, the website is professional and trustworthy with moderate security posture and privacy compliance. Strategic improvements in security headers, DNSSEC, and privacy mechanisms would enhance the site's security and compliance standing. The absence of direct contact emails or phone numbers limits immediate user contact options, relying instead on subscription forms. The site is safe for general audiences with no adult or explicit content detected.

20
53
17
60
77
70
100
healthcareclinicalresearchpatientengagementeventspodcasts+2 more
jQueryBootstrap 3.4.1Slick CarouselSelect2+6

Partner Domains:

theconferenceforum.org
parent
patientsaspartnersconference.com
partner

+1 more partners

2025-10-25T23:26:37.430Z
clinicaltrialsoperations.org favicon

The Conference Forum

clinicaltrialsoperations.org

61
HealthcareN/asmallMEDIUM

The Conference Forum operates the clinicaltrialsoperations.org website, providing specialized content including articles, podcasts, webcasts, and events focused on modernizing clinical trial operations and accelerating therapeutic development. The business targets pharmaceutical, biotech, and clinical research professionals, positioning itself as a niche content and event provider within the healthcare sector. The website is relatively new, consistent with the domain registration date in late 2023, and reflects a small but professional operation with a clear focus on clinical trial innovation and partnerships. Technically, the website employs a modern but standard technology stack including jQuery, Bootstrap, Select2, and integrates multiple third-party analytics and tracking services such as Google Analytics, Microsoft Clarity, and LinkedIn Insight. Hosting is via Amazon AWS infrastructure with Cloudfront CDN, ensuring reasonable performance and availability. The site is mobile-optimized with good SEO and accessibility basics, though some improvements could be made in accessibility and security headers. From a security perspective, the site enforces HTTPS and uses Google reCAPTCHA v3 to protect forms, but lacks DNSSEC and explicit security headers, which are recommended for enhanced protection. No sensitive data exposure or vulnerabilities were detected in the HTML content. Privacy compliance is partial; a privacy policy is present on the parent domain, but no explicit cookie consent mechanism is implemented, which may pose GDPR compliance risks. Overall, the website presents a trustworthy and professional front for its niche audience, with moderate technical maturity and a solid business foundation. Strategic improvements in security hardening and privacy compliance would enhance its posture and trustworthiness.

20
58
17
60
77
75
100
clinicaltrialspharmaceuticalrdclinicaloperationshealthcare+3 more
jQueryBootstrap 3.4.1Slick CarouselSelect2+5

Partner Domains:

theconferenceforum.org
parent
dpharmconference.com
partner

+3 more partners

2025-10-25T23:26:32.419Z
clinicaltrialaccess.com favicon

The Conference Forum

clinicaltrialaccess.com

58
HealthcareN/asmallMEDIUM

The website clinicaltrialaccess.com is a specialized platform operated by The Conference Forum, focusing on community-based clinical trials. It offers a range of services including events, editorial content, podcasts, webinars, and marketing services aimed at healthcare professionals, clinical trial sites, and pharmaceutical stakeholders. The platform positions itself as a niche content and event marketing provider within the healthcare and clinical research sector. Technically, the site employs a modern tech stack with popular JavaScript libraries and analytics tools, hosted on Amazon AWS infrastructure with CDN support. The design is professional, mobile-optimized, and provides a good user experience with clear navigation and relevant content. Security posture is solid with HTTPS enforced and use of reCAPTCHA, though improvements such as enabling DNSSEC and adding security headers are recommended. Privacy compliance is partial, with a privacy policy present but lacking cookie consent mechanisms. Overall, the domain registration is consistent with the business launch timeline and shows no suspicious indicators. The site is safe for general audiences and does not contain adult or explicit content.

20
53
2
60
77
75
100
clinicaltrialshealthcareeventspodcastswebinars+2 more
jQueryBootstrap 3.4.1Slick CarouselSelect2+6

Partner Domains:

theconferenceforum.org
parent
partnershipswithsites.com
partner

+3 more partners

2025-10-25T23:26:22.394Z
cmo360.org favicon

The Conference Forum

cmo360.org

59
HealthcareUnited StatessmallMEDIUM

The Conference Forum operates the cmo360.org website, a specialized platform supporting biotech Chief Medical Officers and R&D leadership throughout the drug development cycle. The site offers a variety of content including editorial articles, podcasts, webinars, and conferences, targeting biotech professionals and industry leaders. The business model centers on content marketing and event organization within the healthcare and biotech sectors, positioning itself as a niche leader with a focused audience. Technically, the website employs a modern tech stack including jQuery, Bootstrap, and various analytics and tracking tools such as Google Tag Manager, Microsoft Clarity, and LinkedIn Insight. Hosting is via Amazon AWS infrastructure with Cloudfront CDN, ensuring moderate performance and good mobile optimization. Security posture is solid with HTTPS enforced and use of reCAPTCHA, but lacks DNSSEC and security headers, which are recommended for enhancement. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism or GDPR-specific indicators. Contact information is limited to a subscription/contact form without direct emails or phone numbers. Overall, the website is professional, trustworthy, and well-aligned with its business goals.

20
53
2
60
77
75
100
biotechcmordleadershiphealthcareconferences+3 more
jQueryBootstrap 3.4.1Slick CarouselSelect2+6

Partner Domains:

theconferenceforum.org
parent
cmosummit360.com
partner
2025-10-25T23:26:17.382Z
acond.cz favicon

ACOND a.s.

acond.cz

61
EnergyCzech RepublicmediumMEDIUM

ACOND a.s. is a leading Czech manufacturer specializing in heat pumps, air conditioning, and floor heating solutions. With over 12,000 installations, the company serves residential and commercial customers primarily in the Czech Republic and abroad. Their business model focuses on manufacturing, direct sales, installation, and servicing, supported by a strong partner network and comprehensive customer support. The website reflects a professional and trustworthy brand with clear communication of product offerings, warranties, and customer testimonials. Technically, the website is built on the Webflow platform, leveraging modern JavaScript libraries and analytics tools such as Google Analytics, Microsoft Clarity, and Adform. It employs a consent management platform (Usercentrics) to ensure GDPR compliance. The site is mobile-optimized, fast-loading, and well-structured, providing an excellent user experience. From a security perspective, the site uses HTTPS and integrates consent mechanisms for privacy compliance. However, it lacks visible security headers and does not publish an incident response or vulnerability disclosure policy, which are areas for improvement. The absence of WHOIS data limits domain legitimacy verification, but the overall digital footprint and business information suggest a legitimate and established entity. Overall, the website demonstrates a mature digital presence with strong content quality and privacy compliance, though it would benefit from enhanced security practices and transparent domain registration information.

30
45
2
75
72
80
100
heatpumpsairconditioningenergyczechrepublicmanufacturing+5 more
Webflow CMSjQuery 3.5.1Google Tag ManagerGoogle Analytics+4

Partner Domains:

acond.com
partner
route3.tecomat.com
partner

+1 more partners

2025-10-25T22:21:48.039Z
oceana.org favicon

Oceana

oceana.org

67
Non-profitUnited StateslargeMEDIUM

Oceana is a well-established non-profit organization dedicated to ocean conservation and advocacy, operating since 1995. It holds a strong market position as the largest international advocacy group focused solely on protecting the world's oceans. The website reflects a professional and consistent brand image, targeting a broad audience including environmental advocates and policymakers. The business model centers on advocacy, public education, and policy influence to drive ocean protection efforts. Technically, the website is built on WordPress with modern JavaScript libraries and integrates multiple analytics and tracking tools such as Google Tag Manager, Microsoft Clarity, and Facebook Pixel. Hosting and DNS services leverage Cloudflare, enhancing performance and security. The site is mobile-optimized with good SEO practices and basic accessibility features. From a security perspective, the site enforces HTTPS and employs domain transfer protection. However, DNSSEC is not enabled, and some advanced security headers are missing. No public security policy or incident response information is available, and no vulnerability disclosure program is evident. Overall, the security posture is solid but could be improved with additional headers and DNS security. The overall risk assessment is low, with no critical vulnerabilities or suspicious indicators detected. Strategic recommendations include enabling DNSSEC, implementing a Content-Security-Policy header, and publishing security and incident response policies to enhance transparency and trust.

45
58
17
85
62
80
100
non-profitoceanconservationenvironmentadvocacyenvironmentalprotection+1 more
WordPressPHPJavaScriptjQuery+4
2025-10-25T20:05:07.279Z
tattly.com favicon

Tattly Temporary Tattoos & Stickers

tattly.com

68
E-commerceN/asmallMEDIUM

Tattly Temporary Tattoos & Stickers operates a niche e-commerce platform specializing in high-quality, artistic temporary tattoos and stickers. Founded in 2011, the company has established a consistent brand presence with a well-structured Shopify-based website. The site targets a general audience interested in unique, non-permanent body art, offering a variety of collections and custom designs. The business model is retail-focused, leveraging online sales and subscription services via integrated tools like Recharge. Technically, the website employs modern e-commerce technologies including Shopify's Debut theme, multiple analytics and marketing integrations, and is hosted on reliable infrastructure with Amazon Registrar as the domain registrar. The site demonstrates good performance and mobile optimization, though accessibility features are basic. Security posture is solid with HTTPS enforced and domain status protections, but could be enhanced by enabling DNSSEC and implementing additional security headers. Privacy compliance is limited due to the absence of explicit privacy and cookie policies in the analyzed content. Overall, the website is professional, trustworthy, and safe for general audiences, with room for improvement in privacy transparency and security hardening.

75
58
17
75
57
80
100
temporarytattoosstickerse-commerceshopifymarketing+2 more
ShopifyJavaScriptGoogle Tag ManagerHotjar+5

Partner Domains:

tattly.myshopify.com
partner
2025-10-25T18:49:42.099Z