Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149091
Websites
130
Industries
113
Countries
52
Avg Score
Page 1013 of 1021|Showing 50601-50650 of 51023
nyetimber.com favicon

Nyetimber Limited

nyetimber.com

45
wine productionUnited KingdommediumHIGH

The website exhibits a critically weak security posture with multiple severe vulnerabilities that expose it to significant risks including data breaches, compliance violations, and service interruptions. The absence of HTTPS encryption, flagged as critical across SSL/TLS, GDPR, and NIS2 compliance areas, is the most alarming issue, leaving all data transmissions vulnerable to interception and manipulation. Key security headers critical for protecting against common web attacks are missing, increasing the risk of clickjacking, content injection, and cross-site scripting attacks. GDPR compliance is poor, notably lacking a cookie consent mechanism and potentially non-compliant privacy policies, which could result in regulatory penalties and damage to customer trust. NIS2 directives are largely unmet, with no documented security policies, incident response plans, or information security frameworks, exposing the business to operational risks and regulatory enforcement. Email security is moderately better but still incomplete, with missing DKIM records and weak DMARC enforcement that could facilitate phishing attacks. DNS security is fairly strong, but the absence of DNSSEC and CAA records leaves some attack vectors open. Network security within the infrastructure is solid, providing a good foundation to build upon. Immediate attention is required to address critical encryption and compliance gaps to protect the business, customers, and reputation.

15
33
5
70
-
85
100
winesparkling wineEnglish wineonline shopgift+3 more
WooCommerceWordPressYoast SEOGoogle Tag Manager+15
2025-06-13T18:10:49.987Z
turassist.com favicon

Tur Assist

turassist.com

47
Assistance ServicesTurkeylargeHIGH

The website's overall security posture is critically weak, with multiple severe vulnerabilities primarily due to the absence of HTTPS encryption and inadequate security headers. The lack of HTTPS not only exposes sensitive data in transit but also results in non-compliance with GDPR and NIS2 regulations, posing significant legal and reputational risks. Key security headers such as Content-Security-Policy and X-Frame-Options are missing, increasing susceptibility to cross-site scripting and clickjacking attacks. Additionally, the absence of a privacy policy, cookie policy, and consent mechanisms indicates poor GDPR adherence, further risking regulatory penalties. The organization lacks foundational information security documentation, incident response procedures, and business continuity planning, undermining its ability to effectively manage and recover from security incidents. While email and network security appear strong, these do not compensate for the critical gaps in web and data protection. Immediate remediation is essential to protect customer data, maintain trust, and ensure compliance with legal frameworks. Overall, the current security posture exposes the business to high risk of data breaches, regulatory fines, and operational disruptions.

35
-
5
100
-
85
100
AssistanceInsuranceAutomotiveHealthLifestyle+1 more
Google Tag ManagerFacebook PixeljQueryTermsFeed Cookie Consent+2

Partner Domains:

rsotoekspertiz.com
partnerpending
rsboyasizonarim.com
partnerpending

+3 more partners

2025-06-13T18:10:49.882Z
mfo.org favicon

Multinational Force and Observers

mfo.org

45
International peacekeeping and securityEgypt/Israel (operational zones)mediumHIGH

The website currently exhibits critical vulnerabilities that severely compromise its security posture, most notably the complete absence of HTTPS encryption, which exposes all data transmissions to interception and manipulation. The lack of fundamental security headers such as Content-Security-Policy further increases the risk of cross-site scripting and other client-side attacks. Additionally, non-compliance with GDPR regulations due to missing privacy and cookie policies, as well as absence of cookie consent mechanisms, presents significant legal and reputational risks. Deficiencies in security governance, including missing information security frameworks, incident response procedures, and vulnerability disclosure policies, weaken the organization's ability to detect and respond to cyber threats effectively. Email security measures are partially implemented but require enforcement improvements to prevent phishing and spoofing attacks. DNS configurations lack advanced protections like DNSSEC, which could lead to domain hijacking risks. Overall, the combined technical and compliance gaps place the business at high risk of data breaches, regulatory penalties, and operational disruption.

60
-
-
85
-
85
90
peacekeepingsecurityinternational treatySinaiMFO+3 more
Vimeo (video provider)Mapbox GL JS (map library)Google Tag ManagerVue.js (implied by vue-ssr-id and nuxt-progress)+6
2025-06-13T18:10:49.864Z
peugeot.com favicon

Peugeot

peugeot.com

47
automotivenot determinablelargeHIGH

The website's overall security posture is critically weak, primarily due to the absence of HTTPS encryption, exposing all data in transit to interception and undermining user trust and regulatory compliance. Multiple critical and high-severity issues related to missing essential security headers such as Content-Security-Policy and X-Frame-Options further increase the risk of cross-site scripting and clickjacking attacks. The lack of GDPR compliance artifacts, including privacy policies, cookie consent mechanisms, and third-party privacy transparency, poses significant legal and reputational risks. From a regulatory perspective, the absence of a structured information security framework, incident response, and business continuity plans indicates unpreparedness for security incidents, risking operational disruptions. While network security and email security controls are strong, these positives do not offset fundamental web security deficiencies. DNS security is moderately addressed but can be improved by enabling DNSSEC and configuring CAA records. Immediate remediation is necessary to protect customer data, maintain compliance, and secure business operations. Without urgent action, the organization faces elevated risks of data breaches, regulatory penalties, and customer trust erosion.

35
-
5
100
-
85
100
peugeotautomotivedigital landing pagemulti language
Google AnalyticsAdobe Helix RUMAB Tasty (mentioned as third party script)Google Tag Manager+2

Partner Domains:

stellantis.com
subsidiarypending
ingenico.com
paymentpending

+1 more partners

2025-06-13T18:10:49.858Z
wyser-search.com favicon

Wyser

wyser-search.com

47
recruitment and human resourcesmultiple including Brazil, Bulgaria, Chile, China, France, Hungary, Italy, Poland, Portugal, Romania, Serbia, Spain, TurkeymediumHIGH

The website's current security posture is critically weak, with multiple severe vulnerabilities exposing it to significant risk. The absence of HTTPS encryption is a fundamental flaw, affecting data confidentiality and trust, and violates GDPR and NIS2 requirements. Key security headers such as Strict-Transport-Security and Content-Security-Policy are missing, increasing exposure to common web attacks like XSS and protocol downgrade attacks. GDPR compliance is notably poor, lacking essential elements like a cookie policy and consent mechanisms, which can lead to regulatory fines and reputational damage. The absence of documented information security frameworks, security policies, and incident response procedures indicates immature organizational security governance. While email security and network security are relatively strong, this does not compensate for the critical gaps in web application and data protection. Immediate remediation is necessary to protect customer data, maintain regulatory compliance, and preserve business reputation. Without swift action, the organization risks data breaches, regulatory penalties, and loss of customer trust.

30
18
-
90
-
85
100
recruitmentsearch and selectionsenior managementhuman resourcesglobal+4 more
WordPressYoast SEO pluginWP RocketElementor+10

Partner Domains:

gigroupholding.com
subsidiarypending
2025-06-13T18:10:49.545Z
insidesystems.com favicon

Inside Systems A/S

insidesystems.com

50
Information TechnologyDenmarkmediumHIGH

The website's overall security posture is critically weak, primarily due to the absence of HTTPS encryption, which exposes all data in transit to interception and manipulation. Key security headers are missing, increasing the risk of cross-site scripting, clickjacking, and other web-based attacks. GDPR compliance is severely lacking, with no cookie policy or consent banner, potentially leading to regulatory penalties and loss of customer trust. The absence of an information security framework, incident response procedures, and security policy documentation further exacerbates the organization's vulnerability to cyber threats and operational disruptions. While email and network security are strong, these isolated strengths do not mitigate the critical risks posed by the core deficiencies. The low scores in NIS2 compliance indicate the organization is unprepared to meet mandatory cybersecurity standards, risking legal and financial consequences. Immediate remediation is necessary to protect sensitive data, maintain regulatory compliance, and uphold the company's reputation. Failure to address these issues may result in data breaches, regulatory fines, and significant business disruption.

25
18
10
100
-
85
100
IT hardwarerefurbished ITITADsustainabilitysecure data erasure+1 more
WordPressWooCommercejQueryFlatsome Theme+12

Partner Domains:

sustainableelectronics.org
partnerpending
co2neutralwebsite.com
partnerpending

+1 more partners

2025-06-13T18:10:49.540Z
optimat.be favicon

OptimaT

optimat.be

46
industrial supplyBelgiummediumHIGH

The website's security posture is currently at high risk, with multiple critical and high-severity issues that directly impact business operations and regulatory compliance. Notably, the absence of HTTPS encryption exposes sensitive data to interception, undermining user trust and violating legal requirements such as GDPR and NIS2. Missing key security headers (Strict-Transport-Security, X-Frame-Options, Content-Security-Policy) increases vulnerability to common web attacks. The lack of GDPR compliance elements, including privacy and cookie policies and consent mechanisms, poses significant legal and reputational risks, especially for EU customers. Additionally, the organization lacks foundational information security frameworks, incident response procedures, and business continuity plans, indicating immature security governance. Although email security and network security show moderate to good standing, critical gaps in SSL/TLS and GDPR compliance drastically overshadow these positives. Immediate remediation is essential to protect customer data, maintain regulatory compliance, and secure business operations. The overall security readiness score reflects urgent need for comprehensive security improvements and policy implementations.

55
-
5
85
-
85
100
industrial supplyISO9001ISO14001custom manufacturingprofessional services+2 more
Google Tag ManagerGoogle Analytics (gtag)Google Maps APIOwl Carousel v2+7

Partner Domains:

jobtoolz.com
servicepending
2025-06-13T18:10:49.509Z
flyprivate.com favicon

FlyPrivate

flyprivate.com

50
private aviationUSmediumHIGH

The website’s current security posture exhibits significant vulnerabilities that expose the business to substantial risks, particularly due to the absence of HTTPS encryption which is flagged as critical across multiple compliance frameworks including GDPR, NIS2, and SSL/TLS standards. Key security controls such as Content-Security-Policy and X-Frame-Options headers are missing, increasing the risk of web-based attacks like clickjacking and cross-site scripting. Compliance with GDPR is severely lacking, with no cookie policy or consent mechanism in place, potentially exposing the business to regulatory fines and reputational damage. Additionally, the absence of documented security policies, incident response procedures, and vulnerability disclosure mechanisms under NIS2 requirements indicates immature information security governance. While email and network security are strong points, foundational gaps in encryption and security headers undermine overall defenses. The DNS configuration is moderately healthy but could be improved with DNSSEC and CAA records. Immediate remediation is needed to protect customer data, ensure regulatory compliance, and safeguard business continuity. Without prompt action, the business faces operational disruptions, legal penalties, and loss of customer trust.

30
18
5
100
-
85
100
private jetcharterbusiness flightspersonal flightsaviation+2 more
WordPressJetpackGutenbergGoDaddy Styles+7
2025-06-13T18:10:49.493Z