Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 1033 of 1064|Showing 51601-51650 of 53176
kystverket.no favicon

Kystverket

kystverket.no

60
GovernmentNorwaylargeMEDIUM

Kystverket is a Norwegian government agency responsible for maritime safety, navigation, and environmental protection along the Norwegian coast. The website serves as a portal for digital maritime services, including navigation aids, real-time ship tracking, and environmental alerts. It targets maritime professionals, coastal communities, and the general public interested in maritime affairs. The agency holds a strong national position as the authoritative maritime body in Norway. Technically, the website leverages Microsoft Azure infrastructure, ASP.NET Core framework, and integrates advanced analytics and consent management tools such as Microsoft Application Insights, Google Tag Manager, and Cookie Information. The site uses Episerver CMS and Cloudflare for CDN services. Despite a rich technical stack, the site suffers from critical SSL/TLS misconfigurations, lacking a valid certificate and disabling all TLS protocols, which severely impacts security posture. Security-wise, while the site implements HSTS with preload and includes no known major vulnerabilities like Heartbleed or POODLE, the absence of a valid SSL certificate and TLS support is a critical flaw. Cookie consent and privacy policies are comprehensive and GDPR compliant, reflecting good privacy practices. Contact information and social media presence enhance trust and transparency. Overall, the site is professionally designed with good content quality and user experience but requires urgent remediation of SSL/TLS issues to ensure secure communications. Strategic recommendations include fixing the SSL certificate, enabling modern TLS protocols, and improving OCSP stapling and session resumption. These steps will significantly enhance the security posture and user trust.

30
25
25
80
100
90
85
governmentmaritimenorwaynavigationenvironment+4 more
Microsoft AzureASP.NET CorePower BICloudflare+3
2025-06-15T13:19:43.146Z
dsa.no favicon

Direktoratet for strålevern og atomsikkerhet

dsa.no

74
GovernmentNorwaymediumMEDIUM

Direktoratet for strålevern og atomsikkerhet (DSA) is a Norwegian government directorate responsible for radiation protection and nuclear safety. The organization operates as a national authority providing regulatory oversight, monitoring radioactive emissions, and disseminating information to the public and relevant sectors such as veterinary and medical fields. The website serves as an official communication channel offering news, regulatory information, publications, and contact resources. It targets Norwegian citizens, government agencies, and professional sectors involved with radiation safety. Technically, the website is built on the Enonic CMS platform, hosted on Fastly CDN, and employs modern web technologies including jQuery and Google Tag Manager. The site supports TLS 1.3 and 1.2 with strong cipher suites, ensuring secure communications. However, performance is suboptimal with a slow load time and a large page size. Accessibility and SEO optimizations are well implemented, and the site is mobile responsive. From a security perspective, the site enforces HTTPS with valid certificates and implements SPF and DMARC email authentication policies with strict reject rules, reducing email spoofing risks. The absence of HSTS and DNSSEC are notable gaps. No critical vulnerabilities or exposed sensitive data were detected. Privacy and cookie policies are present and GDPR compliant, with a consent mechanism implemented. Overall, the website demonstrates a strong security posture and credible business presence consistent with a government agency. Recommendations include enabling HSTS, DNSSEC, and OCSP stapling to further harden security. Performance improvements would enhance user experience. The domain registration data aligns well with the organization's identity, supporting high trustworthiness.

75
25
25
80
87
85
100
governmentradiationnuclearsafetynorwaypublicservice+1 more
jQueryGoogle Tag ManagerPiwik PRO analyticsTLS 1.3+1
2025-06-15T13:19:43.026Z
adwcatholicschools.org favicon

Archdiocese of Washington

adwcatholicschools.org

40
EducationUnited StatesmediumHIGH

The Archdiocese of Washington Catholic Schools website serves as a comprehensive informational portal for a network of 90 Catholic educational institutions ranging from preschool to high school across Washington D.C. and surrounding Maryland counties. The site effectively communicates the organization's mission, educational offerings, and community engagement, targeting families seeking faith-based education. The business model is non-profit and education-focused, with a medium-sized regional presence and a well-established brand identity. Technically, the website is built on WordPress with common libraries such as jQuery and FontAwesome, and integrates marketing and analytics tools including Google Analytics, Facebook Pixel, and LiveChat. However, the site suffers from slow load times and lacks a valid SSL certificate, which critically impacts security and user trust. SEO and mobile optimization are handled well, but accessibility features are basic. From a security perspective, the absence of HTTPS and modern TLS protocols is a major vulnerability. No security headers or consent mechanisms for cookies are present, exposing the site to potential data privacy compliance issues, especially under GDPR. Contact information is clearly provided, but no dedicated security or incident response policies are visible. Overall, while the website is content-rich and professionally presented, the lack of fundamental security measures and privacy compliance mechanisms poses significant risks. Strategic improvements in SSL deployment, security headers, and privacy policies are essential to enhance trust and protect user data.

15
43
25
40
50
80
100
educationcatholicschoolsnon-profitwordpress+1 more
WordPressjQueryFontAwesomeGoogle Tag Manager+3

Partner Domains:

adw.org
partner39
blackstudentfund.org
partnerpending

+3 more partners

2025-06-15T13:17:06.361Z
rotundasoftware.com favicon

Rotunda Software LLC

rotundasoftware.com

53
TechnologyN/asmallMEDIUM

Rotunda Software LLC is a small, self-funded technology company specializing in innovative volunteer management software solutions. Their products, including Volunteer Scheduler Pro and Ministry Scheduler Pro, serve non-profit organizations and volunteer-based groups, positioning them as a niche player in the volunteer management software market. The company emphasizes a fully remote, collaborative culture and showcases client testimonials and partnerships with reputable organizations such as The Salvation Army. Technically, the website employs modern JavaScript libraries, Google Analytics, and Google Tag Manager, hosted likely on AWS infrastructure. However, the site lacks a valid SSL certificate, resulting in insecure HTTP connections, which is a significant security concern. Privacy policies and terms of service are present on related domains but not directly on the main site, and no cookie consent mechanism is implemented. Overall, the security posture is basic with room for improvement in SSL/TLS configuration and security headers. The domain is mature and well-registered, supporting the legitimacy of the business. Strategic recommendations include implementing HTTPS, enhancing security headers, and improving privacy compliance to strengthen trust and security.

65
25
25
50
50
85
100
volunteeringsoftwarenon-profittechnologyremotework+1 more
JavaScriptjQueryGoogle AnalyticsGoogle Tag Manager+2

Partner Domains:

ministryschedulerpro.com
partnerpending
volunteerschedulerpro.com
partnerpending
2025-06-15T13:14:28.226Z
donaora.it favicon

Fondazione Bambino Gesù ETS

donaora.it

39
Non-profitItalymediumHIGH

The website donaora.it serves as a fundraising platform for Fondazione Bambino Gesù ETS, a non-profit organization focused on pediatric healthcare support in Italy. The site aims to facilitate donations to support scientific research, medical care, and assistance to children and their families. The business model revolves around charitable giving and donor engagement, targeting individuals interested in supporting pediatric health causes. The organization is mature, with a domain age of 17 years, aligning with its founding date in 2007. Technically, the website employs basic modern web technologies such as Google Tag Manager and Google Fonts, with integration of GestPay for payment processing. However, the site suffers from significant performance issues, including a very slow load time and large page size. Mobile optimization and accessibility are basic, and SEO practices are minimal. The absence of a valid SSL certificate and HTTPS support is a critical flaw, exposing users to security risks. From a security perspective, the website lacks essential protections such as HTTPS, HSTS, DMARC, DNSSEC, and domain protection locks. The presence of exposed sensitive tokens or API keys in the HTML source is a severe vulnerability that could lead to exploitation. No privacy, cookie, or terms of service policies are present, indicating poor privacy compliance. The WHOIS data confirms the domain is mature and consistent with the organization's profile but highlights a high expiry risk and lack of domain locks. Overall, the website's risk profile is elevated due to critical security shortcomings and poor privacy compliance. Strategic improvements in SSL implementation, security headers, privacy policies, and domain management are urgently recommended to enhance trustworthiness and protect donor data.

15
15
17
50
50
45
100
non-profithealthcarefundraisingdonationpediatriccare+1 more
Google Tag ManagerGoogle FontsGestPay payment JavaScript
2025-06-15T13:11:26.316Z
supresencia.com favicon

Iglesia Cristiana El Lugar de Su Presencia

supresencia.com

39
Non-profitColombiamediumHIGH

Iglesia Cristiana El Lugar de Su Presencia is a medium-sized non-profit religious organization based in Bogotá, Colombia. The website serves as the official digital presence for the church, providing information about services, community groups, children's ministry, radio broadcasting, and donation options. The target audience is primarily Spanish-speaking Christians in Colombia. The organization maintains a multimedia presence including live streaming and social media engagement, supported by several subsidiary domains related to radio, media production, and community outreach. Technically, the website is built on Drupal 7 with common web technologies such as jQuery and Bootstrap, hosted on AWS infrastructure. However, the site lacks a valid SSL certificate and proper HTTPS configuration, which is a critical security shortfall. Privacy policies exist but lack comprehensive GDPR compliance and cookie consent mechanisms. Security headers are partially implemented but TLS protocols and modern security features are missing, exposing the site to potential risks. Overall, the website is functional and professionally presented but requires urgent improvements in security and privacy compliance to enhance trust and protect user data.

40
-
-
65
-
85
100
iglesiacristianabogotreligiousnon-profit+4 more
Drupal 7jQuery 2.1BootstrapArt Revolution Slider+4

Partner Domains:

supresenciaradio.com
subsidiarypending
coffeenjesus.com
subsidiarypending

+1 more partners

2025-06-15T13:07:58.053Z
E

ETTINGER GmbH

ettinger.de

28
ManufacturingGermanymediumHIGH

ETTINGER GmbH is a well-established German family-owned company specializing in fastening technology and electromechanical components, serving industrial and trade customers through a comprehensive B2B online shop. The company offers a wide range of over 25,000 products, including custom manufacturing and special procurement services, with a focus on quality and fast delivery. The website reflects a mature digital presence with professional design, clear navigation, and rich content tailored to its target audience of manufacturers and industrial clients. Technically, the site is built on the Shopware CMS platform, leveraging modern technologies like Algolia for search and Google Tag Manager for analytics. However, a critical security gap exists as the site lacks a valid SSL/TLS certificate, exposing users to potential risks and undermining trust. Security headers are partially implemented but ineffective without HTTPS. Privacy and cookie policies are present and compliant with GDPR, including consent mechanisms. The domain registration is consistent and legitimate, with no privacy protection or suspicious patterns, supporting the company's credibility. Overall, while the business and content aspects are strong, immediate attention is required to secure the website with HTTPS to protect user data and enhance trust.

60
-
-
50
-
70
40
b2be-commercemanufacturingelectromechanicsfasteningtechnology+1 more
Apache 2.4.62Debian LinuxShopware CMShtmx.js+4

Partner Domains:

portal.ettinger.de
service
katalog.ettinger.de
service
2025-06-15T13:07:57.644Z
dmdiocese.org favicon

Diocese of Des Moines

dmdiocese.org

40
Non-profitUnited StatesmediumHIGH

The Diocese of Des Moines website serves as the official online presence for the Catholic Diocese in southwest Iowa, providing comprehensive information about its ministries, schools, events, and community services. The site targets the local Catholic community and families interested in faith formation and education. It offers key services such as Catholic schooling, mental health ministry, worship schedules, and charitable giving opportunities. The organization maintains a consistent brand and provides clear contact information, enhancing its credibility as a regional non-profit religious entity. Technically, the website is built on an ASP.NET framework with modern JavaScript libraries like jQuery and uses Google Tag Manager for analytics. The site employs asynchronous script loading and lazy loading for images, indicating a focus on performance and user experience. However, performance data is missing, and the site is rated as slow based on available indicators. Mobile optimization and SEO practices are good, but accessibility is basic. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability. While several security headers are present, the absence of HTTPS and weak SSL configuration significantly reduce the site's security posture. There are no visible privacy policies, cookie consent mechanisms, or incident response contacts, indicating compliance gaps with GDPR and other privacy regulations. Overall, the website is functional and professional but requires urgent improvements in security and privacy compliance to protect users and enhance trust. Strategic recommendations include implementing a valid SSL certificate, enabling modern TLS, adding privacy and cookie policies, and establishing incident response protocols.

70
-
5
50
-
85
100
educationnon-profitreligioncatholiccommunity+3 more
ASP.NETjQuery 3.7.1Google Tag ManagerGoogle Marketing Platform (gtag.js)+2

Partner Domains:

catholiccharitiesdm.org
partnerpending
catholicfoundationiowa.org
partnerpending
2025-06-15T13:07:50.206Z
abtassociates.com favicon

Abt Global

abtassociates.com

40
GovernmentUnited StateslargeHIGH

Abt Global is a well-established international consulting and social impact organization with over 60 years of history and a large workforce. The company focuses on leveraging data, innovation, and expertise across multiple sectors including health, environment, governance, and economic growth to improve lives worldwide. Their business model centers on providing consulting, technical assistance, and digital solutions to governments, organizations, and communities. The website reflects a professional and comprehensive digital presence with strong branding and relevant content targeting global development stakeholders. Technically, the website is built on Drupal 10 and uses modern JavaScript libraries and marketing/analytics tools such as Google Tag Manager, Google Analytics, LinkedIn Insight Tag, and HubSpot. However, the site suffers from slow load times and lacks a valid SSL certificate, resulting in no HTTPS support. Mobile optimization and SEO are good, but accessibility is basic. The hosting appears to be via Fastly CDN. From a security perspective, the absence of a valid SSL certificate and HTTPS is a critical vulnerability, severely impacting the security posture. No security headers or advanced TLS configurations are present, and no incident response or security policies are published. Cookie consent mechanisms are implemented, indicating GDPR awareness, but no terms of service or vulnerability disclosure pages are found. Overall, the security maturity is low and requires urgent improvements. The overall risk assessment highlights the critical need for SSL/TLS implementation to protect user data and improve trust. Strategic recommendations include securing the site with HTTPS, enabling security headers, optimizing performance, and publishing clear security and incident response policies. The business credibility and content quality are strong, but technical and security shortcomings reduce the overall trust score.

75
18
5
50
-
80
100
globaldevelopmentsolutionsdata-drivensocialimpacthealthpolicyresearcheconomicpolicyanalysisclimatechangesolutions
Drupal 10JavaScriptjQueryGoogle Tag Manager+4
2025-06-15T13:07:49.673Z
ospedalebambinogesu.it favicon

Ospedale Pediatrico Bambino Gesù

ospedalebambinogesu.it

36
HealthcareItalylargeHIGH

Ospedale Pediatrico Bambino Gesù is a leading pediatric hospital and research center in Europe, providing specialized healthcare services for children and adolescents primarily in Italy but also internationally. The website serves as a comprehensive portal offering information about the hospital, research projects, patient services including online appointment booking, and donation opportunities. The institution is well-positioned in the healthcare sector with strong trust indicators such as certifications and a professional digital presence. Technically, the website employs modern web technologies including Bootstrap, jQuery, Handlebars.js, and integrates Google Analytics and Tag Manager for tracking and marketing. Hosting is via Amazon CloudFront CDN, and authentication services use Amazon Cognito. However, the site currently lacks a valid SSL certificate and HTTPS support, which is a critical security gap. Cookie consent is managed through Cookiebot, indicating compliance with GDPR requirements. From a security perspective, the absence of HTTPS and related security headers significantly lowers the security posture. No incident response or vulnerability disclosure information is published. DNS security features like DNSSEC and DMARC are missing. Despite these issues, the site does not show signs of active vulnerabilities or malicious content. Overall, the website is professionally designed and content-rich but requires urgent security improvements to protect user data and enhance trust. Strategic recommendations include deploying a valid SSL certificate, enabling HSTS, implementing DNS security records, and publishing security policies and incident response contacts.

15
-
5
50
-
75
100
healthcarepediatrichospitalresearchitaly+1 more
BootstrapjQueryHandlebars.jsGoogle Analytics+4

Partner Domains:

donaora.it
partnerpending
2025-06-15T13:07:46.336Z
goodness.inc favicon

Goodness, Inc.

goodness.inc

60
E-commerceUnited StatessmallMEDIUM

Goodness, Inc. is a user-first digital commerce partner specializing in helping direct-to-consumer (DTC) brands thrive in the digital economy. The company offers a comprehensive suite of services including DTC strategy, design, technology, and marketing activation, serving notable clients such as OREO, CLIF, and Papa & Barkley. Their market position is that of a specialized, boutique agency with a strong focus on delivering best-in-class digital experiences for modern brands. The business is US-based, relatively new (established in 2023), and operates with a small but professional team. Technically, the website is built on modern frameworks like Nuxt.js and Vue.js, leveraging Cloudflare for DNS and DigitalOcean for media hosting. The site integrates multiple marketing and analytics tools including Google Analytics, Google Tag Manager, HubSpot, and social media pixels. However, the site suffers from slow performance and lacks a valid SSL certificate, which is a critical security concern. Mobile optimization and accessibility are good, and SEO practices are well implemented. From a security perspective, the absence of a valid SSL certificate and disabled TLS protocols significantly weaken the site's security posture. While some security headers like HSTS and SPF are present, the lack of HTTPS and modern TLS support are critical vulnerabilities. The site does not implement a cookie consent mechanism, and its DMARC policy is set to 'none', indicating limited email protection. No explicit security policies or incident response contacts are found. Overall, the website presents a professional and trustworthy business with excellent content and branding but requires urgent security improvements to protect user data and enhance trust. The domain registration details are consistent and transparent, supporting the legitimacy of the business. Strategic recommendations include obtaining a valid SSL certificate, enabling modern TLS protocols, implementing cookie consent, and enhancing email security policies.

30
43
25
75
97
80
100
digitalcommercedtcecommerceagencybrandingtechnology+2 more
Nuxt.jsVue.jsGoogle Tag ManagerGoogle Analytics+5
2025-06-15T11:55:57.767Z
bkwld.com favicon

Goodness, Inc.

bkwld.com

55
E-commerceUnited StatesmediumMEDIUM

Goodness, Inc. is a well-established digital commerce agency specializing in user-first design and technology solutions for direct-to-consumer (DTC) brands. With over 20 years of domain maturity and a portfolio featuring prominent clients such as OREO, CLIF, and Papa & Barkley, the company positions itself as a strategic partner for modern brands seeking to thrive in the digital economy. Their services encompass DTC strategy, design, technology, and multi-brand website development, reflecting a comprehensive approach to digital commerce. Technically, the website leverages modern frameworks like Nuxt.js and Vue.js, supported by robust analytics and marketing tools including Google Analytics, HubSpot, and LinkedIn Insight. However, the site suffers from a critical security shortfall due to the absence of a valid SSL certificate and lack of HTTPS enforcement, which significantly impacts its security posture. Performance metrics indicate a slow loading time and large page size, suggesting opportunities for optimization. From a security perspective, the presence of SPF and DMARC records with a strict reject policy demonstrates good email security practices. Yet, the lack of TLS protocols, HSTS, and OCSP stapling, combined with no certificate transparency compliance, exposes the site to potential risks. Privacy compliance is strong, with clear privacy and cookie policies and consent mechanisms in place. Overall, Goodness, Inc. presents a credible and professional digital presence with excellent content quality and business credibility. The primary risk lies in its SSL/TLS configuration, which should be addressed promptly to enhance trust and security. Strategic recommendations include implementing a valid SSL certificate, enabling modern TLS protocols, and optimizing site performance to align with its high-quality brand image.

30
43
25
70
50
85
100
digitalcommercedtcecommerceagencynuxtjsvuejs+4 more
Nuxt.jsVue.jsGoogle AnalyticsGoogle Tag Manager+5
2025-06-15T11:53:42.534Z
katapult.io favicon

Krystal Hosting Ltd

katapult.io

63
TechnologyUnited KingdommediumMEDIUM

Katapult, operated by Krystal Hosting Ltd, is a cloud infrastructure provider focused on delivering high-speed, reliable, and scalable virtual infrastructure solutions tailored for developers and teams. The company emphasizes ease of use, transparency, and sustainability, positioning itself as a competitive player in the cloud technology sector with a strong commitment to renewable energy and certified business practices. The website presents a professional and comprehensive overview of its services, targeting technology professionals and businesses seeking cloud infrastructure with pay-as-you-go pricing. Technically, the website is built on modern frameworks such as Next.js and React, with good mobile optimization and accessibility features. However, the site suffers from a critical security shortfall due to the absence of a valid SSL certificate, resulting in no HTTPS support. This significantly impacts the security posture and user trust. Privacy and cookie policies are well implemented with consent mechanisms, and the site uses Google Tag Manager for analytics and marketing. Security-wise, while no major vulnerabilities or exposed sensitive data were detected, the lack of HTTPS and security headers is a major concern. No explicit security or incident response policies are published, and no vulnerability disclosure or security.txt files are present. The domain registration data is consistent and mature, supporting the legitimacy of the business. Overall, Katapult demonstrates strong business credibility and technical maturity but must urgently address its SSL/TLS configuration to improve security and trust. Strategic recommendations include installing a valid SSL certificate, enabling security headers, and publishing security policies to enhance compliance and incident readiness.

90
25
25
50
100
85
100
cloudvirtualmachinesinfrastructuredeveloperspubliccloud+2 more
Next.jsReactGoogle Tag ManagerSVG icons+1
2025-06-15T11:49:43.430Z