Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 105 of 166|Showing 5201-5250 of 8293
tickettailor.com favicon

Ticket Tailor

tickettailor.com

77
TechnologyN/amediumLOW

Ticket Tailor is a well-established online ticketing platform that simplifies the process of selling tickets for events of all sizes. The company targets event organizers ranging from individuals hosting small events to medium-sized businesses, offering a user-friendly platform with integrated payment processing and event management features. The website demonstrates a high level of professionalism with excellent design quality, clear navigation, and comprehensive privacy and cookie policies, reflecting a mature digital presence. Technically, the website leverages modern web technologies including React and Next.js, supported by integrations with Google Tag Manager, Intercom, and Cookiebot for analytics, marketing, and consent management. The site is optimized for performance and mobile responsiveness, ensuring a smooth user experience across devices. Security best practices are observed with HTTPS enforcement and multiple security headers, although explicit security policies and incident response information are not publicly available. The security posture is strong, with no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed through detailed policies and a robust cookie consent mechanism, aligning with GDPR requirements. However, the lack of publicly available WHOIS data due to privacy protection limits direct verification of domain ownership, though the overall trust indicators and third-party integrations support legitimacy. Overall, Ticket Tailor presents a secure, compliant, and professional online service with a strong market position in the event ticketing industry. Strategic recommendations include publishing explicit security and incident response policies, adding vulnerability disclosure mechanisms, and enhancing direct contact information for security concerns to further strengthen trust and compliance.

70
100
17
82
75
85
100
ticketingeventmanagementonlinesalesprivacycookieconsent+2 more
ReactNext.jsJavaScriptYouTube Player API+3

Partner Domains:

paypal.com
partner
linkedin.com
partner

+3 more partners

2025-07-22T06:28:25.051Z
xoxo.zone favicon

XOXO Zone

xoxo.zone

67
TechnologyIcelandsmallMEDIUM

XOXO Zone operates as a community-run Mastodon instance primarily serving attendees and speakers of the XOXO Festival, a cultural event held in Portland, Oregon. The platform facilitates social networking within the fediverse, leveraging the open-source Mastodon software. The website presents a niche social media service with a focused target audience, maintaining a small but active user base. The business model centers on community engagement rather than commercial monetization. Technically, the website is built on Mastodon version 4.4.1, utilizing React and modern JavaScript modules, hosted on DigitalOcean infrastructure with CDN support for media assets. The site demonstrates moderate performance and good mobile optimization, though accessibility and SEO optimizations are basic. The technical stack is modern and appropriate for a social networking platform of this scale. From a security perspective, the site enforces HTTPS and uses domain transfer protection, but lacks DNSSEC and several recommended security headers. No exposed sensitive data or vulnerable libraries were detected. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism or terms of service published. Contact information is limited to Mastodon user profiles and sign-in forms, with no direct company emails or phone numbers. Overall, XOXO Zone is a trustworthy and professionally maintained community platform with a clear niche focus. Security posture is adequate but could be improved with enhanced policies and technical controls. Privacy compliance requires attention to meet GDPR standards fully. Strategic recommendations include enabling DNSSEC, publishing terms of service, implementing cookie consent, and enhancing security headers to strengthen trust and compliance.

80
58
17
60
72
70
100
mastodonsocialnetworkcommunityxoxofestivalfediverse
Mastodon 4.4.1ReactJavaScript ES ModulesDigitalOcean Spaces CDN+1
2025-07-22T06:26:53.662Z
venmo.com favicon

Venmo

venmo.com

75
FinanceUnited StateslargeMEDIUM

Venmo is a well-established mobile payment platform founded in 2008 and currently operating as a subsidiary of PayPal Holdings, Inc. It offers peer-to-peer payment services, enabling users to manage balances, send and receive money, and split bills seamlessly. The website reflects Venmo's strong market position as a leading social payments app in the United States, targeting consumers who prefer mobile and social payment solutions. The business model focuses on facilitating easy and social financial transactions among friends and networks. Technically, the website is built using modern frameworks such as React and Gatsby, hosted on AWS infrastructure, and integrates analytics tools like Google Analytics and mParticle for data-driven insights. The site is optimized for performance, mobile responsiveness, and accessibility, providing an excellent user experience. SEO practices are well implemented with comprehensive meta tags and structured data. From a security perspective, Venmo enforces HTTPS, employs multiple security headers, and uses domain registration protections to safeguard its digital presence. However, DNSSEC is not enabled, and there is no public security.txt or explicit incident response contact information, which are areas for improvement. Privacy compliance is strong with clear policies and consent mechanisms, aligning with GDPR requirements. Overall, Venmo's website demonstrates a high level of professionalism, security, and compliance, supporting its credibility and trustworthiness in the financial technology sector. Strategic recommendations include enabling DNSSEC, publishing vulnerability disclosure information, and enhancing incident response transparency to further strengthen security posture.

50
85
30
82
82
85
100
paymentsmobilepaymentssocialpaymentsfinancepeer-to-peer+1 more
ReactGatsbyGoogle AnalyticsmParticle+1

Partner Domains:

paypal.com
parent
2025-07-22T06:25:12.580Z
go-scale.com favicon

Insight Partners

go-scale.com

63
OtherUnited StatesenterpriseMEDIUM

The website go-scale.com serves as a community engagement platform branded as GO, associated with Insight Partners, a global private equity and venture capital firm. It provides a networking platform for members related to Insight Partners' ecosystem. The site is professionally designed, with clear branding and social media integration linking to official Insight Partners profiles. The business model centers on investment management combined with community networking services, targeting investors and portfolio companies. The domain is appropriately aged and registered without privacy protection, indicating transparency and legitimacy. Technically, the site leverages modern web technologies including React, Mapbox for mapping, and Hivebrite as the community platform. It integrates multiple analytics and monitoring tools such as Google Analytics, Amplitude, Datadog, and Sentry, indicating a mature digital infrastructure. Hosting is via AWS Cloudfront CDN, supporting performance and scalability. Mobile optimization is good, though accessibility and SEO optimizations are basic. From a security perspective, the site enforces HTTPS with a valid SSL certificate and domain registration protections. However, DNSSEC is not enabled, and no explicit security headers are detected in the HTML content. There is no visible privacy policy, cookie consent mechanism, or terms of service on the main page, which are critical for GDPR compliance and user trust. Incident response and vulnerability disclosure information are also absent. Overall, the website is trustworthy and professional but would benefit from enhanced privacy compliance and security best practices. Strategic improvements in publishing privacy and cookie policies, enabling DNSSEC, and adding security headers would strengthen the security posture and regulatory compliance, thereby improving user trust and reducing risk.

80
35
17
60
62
75
100
communityinvestmentprivateequityventurecapitalnetworking+1 more
ReactMapboxGoogle AnalyticsGoogle Tag Manager+5

Partner Domains:

insightpartners.com
parent
hivebrite.io
partner
2025-07-22T04:08:20.826Z
S

SAP

cloud.sap

73
TechnologyUnited StatesenterpriseMEDIUM

SAP is a global leader in enterprise software and cloud technology platforms, offering a comprehensive Business Technology Platform that integrates data management, analytics, AI, IoT, blockchain, and application development services. The platform targets enterprises seeking to connect processes, experiences, and data to drive digital transformation. The website reflects SAP's strong market position and enterprise focus with professional content and extensive service offerings. Technically, the website employs modern frameworks including SAP UI5, React, and jQuery, hosted likely on a robust infrastructure with Adobe Experience Manager as the CMS. The site is mobile-optimized, accessible, and SEO-friendly, demonstrating digital maturity and a commitment to user experience. From a security perspective, the site enforces HTTPS, implements key security headers, and uses consent management for privacy compliance. Certifications such as ISO 27001 and SOC 2 are indicated, reinforcing trust. No critical vulnerabilities or exposed sensitive data were detected, though explicit vulnerability disclosure and incident response contacts are not found. Overall, the site presents a low-risk profile with strong business credibility and security posture. Minor improvements could include publishing a vulnerability disclosure policy and incident response contacts to enhance transparency and trust.

65
68
17
88
80
80
100
technologyplatformcloudplatformenterprisesoftwareaianalytics+3 more
JavaScriptUI5ReactjQuery+1

Partner Domains:

partneredge.sap.com
partner
concur.com
subsidiary

+2 more partners

2025-07-22T03:02:41.382Z
nkt.cz favicon

NKT A/S

nkt.cz

51
EnergyCzech RepubliclargeMEDIUM

NKT A/S is a well-established company specializing in the manufacturing and supply of cables and cable accessories primarily for the energy sector. With a history dating back to 1891, NKT positions itself as a leading European supplier offering a comprehensive range of products including low, medium, and high voltage cables, as well as related services such as 24-hour cable service and cable laying via specialized vessels. The website reflects a mature digital presence with professional design, clear navigation, and multilingual support targeting energy sector professionals and partners. Technically, the website is built on modern frameworks such as Next.js and React, incorporating advanced features like consent management via Usercentrics and analytics through Google Tag Manager. The site is mobile-optimized and demonstrates good SEO and accessibility practices, although some security headers could be enhanced. The absence of WHOIS data due to privacy protection is noted but does not detract significantly from the site's legitimacy given the professional content and certifications displayed. From a security perspective, the site enforces HTTPS and employs consent mechanisms for privacy compliance, aligning with GDPR requirements. However, explicit incident response contacts and vulnerability disclosure mechanisms are not present, representing areas for improvement. Overall, the site maintains a strong security posture with no evident vulnerabilities or malicious content. The risk assessment indicates a low risk profile with recommendations to enhance security headers and publish incident response information to further bolster trust and compliance. The company’s digital maturity and business credibility are high, supporting its market position as a trusted energy sector partner.

30
10
2
40
67
75
100
energycablesmanufacturingcorporatecompliance+2 more
ReactNext.jsGoogle Tag ManagerUsercentrics CMP+2

Partner Domains:

www.europacable.eu
partner
www.ecovadis.com
partner

+2 more partners

2025-07-22T02:58:48.393Z
denns-biomarkt.de favicon

Denns BioMärkte

denns-biomarkt.de

69
RetailGermanylargeMEDIUM

Denns BioMärkte operates as a large-scale organic retail chain in Germany, offering a comprehensive range of organic products including food, fresh produce, bakery items, ecological drugstore goods, and natural cosmetics. The company is part of the BioMarkt Verbund, a recognized network of organic markets, and emphasizes certified organic products from reputable associations such as Bioland, Biokreis, Naturland, and Demeter. The website reflects a professional retail business model targeting general consumers interested in organic and ecological products. Technically, the website is built using modern frameworks like React and Gatsby, hosted on Microsoft Azure DNS infrastructure, and incorporates essential marketing and tracking tools such as Google Tag Manager and Facebook Pixel. The site includes a cookie consent mechanism via Cookiebot, indicating compliance efforts with GDPR regulations. Security-wise, while HTTPS is implied and cookie consent is implemented, the site lacks visible advanced security headers and formal security policies or incident response contacts. No blocking or WAF challenges were detected, allowing full content access. Overall, the website demonstrates a good balance of business credibility, technical implementation, and privacy compliance, with room for improvement in security policies and transparency.

15
83
17
85
100
70
100
organicbioretailgermanyecommerce+3 more
ReactGatsbyTailwind CSSCookiebot+2
2025-07-22T01:55:22.520Z
manor.ch favicon

Manor AG

manor.ch

75
RetailSwitzerlandlargeMEDIUM

Manor AG operates a leading retail and e-commerce platform in Switzerland, offering a broad assortment of products including fashion, beauty, household goods, multimedia, and more. The website manor.ch serves as a comprehensive online shop complemented by physical stores, loyalty programs, and customer services such as store locators and wishlists. The company has a strong market position as a well-established Swiss department store chain founded in 1902. Technically, the website leverages modern web technologies including React and Next.js frameworks, integrated with marketing and personalization tools like Dynamic Yield and Google Tag Manager. The site is well-optimized for performance, mobile responsiveness, and SEO, providing an excellent user experience. Privacy compliance is robust with clear cookie consent mechanisms and comprehensive privacy policies. From a security perspective, the site enforces HTTPS with strong SSL configurations and implements standard security headers. However, explicit security policies and incident response contacts are not publicly detailed, which could be improved. No vulnerabilities or suspicious activities were detected in the analysis. Overall, manor.ch presents a professional, trustworthy, and secure online presence aligned with its business stature. Strategic improvements in transparency around security policies and incident response would further enhance trust and compliance.

35
88
17
85
100
90
100
retaile-commercefashionbeautyhousehold+3 more
ReactNext.jsDynamic YieldGoogle Tag Manager+1
2025-07-22T01:55:17.433Z
milagro.cz favicon

Milagro

milagro.cz

65
RetailCzech RepublicmediumMEDIUM

Milagro is an authorized e-commerce retailer specializing in Pandora jewelry, offering a wide range of products such as rings, earrings, necklaces, and bracelets. The website targets consumers primarily in the Czech Republic, providing services including product personalization and free shipping for orders above a certain threshold. The platform demonstrates a consistent brand identity and positions itself as a trusted authorized reseller within the retail jewelry market. Technically, the website is built using modern web technologies including Next.js and React, ensuring a responsive and user-friendly experience across devices. The site employs HTTPS with strong security headers, indicating a good security posture. However, the absence of WHOIS data and lack of visible cookie consent mechanisms suggest areas for improvement in domain transparency and privacy compliance. From a security perspective, the site follows best practices with HTTPS enforcement and security headers, but could enhance user trust by adding explicit privacy and cookie policies and implementing a security.txt file for vulnerability disclosures. Overall, the site is professional and secure, but the missing WHOIS information and privacy compliance gaps slightly reduce its trustworthiness. Strategic recommendations include improving GDPR compliance with visible cookie consent, enhancing domain transparency, and establishing a formal vulnerability disclosure process to strengthen security culture and user trust.

75
25
10
75
75
80
100
e-commercejewelrypandoraauthorizedresellerczechrepublic
Next.jsReactJavaScriptCSS+1
2025-07-22T01:51:44.669Z
cashmatters.org favicon

Cash Matters

cashmatters.org

68
FinanceN/asmallMEDIUM

Cash Matters is a non-profit advocacy platform dedicated to supporting and promoting the use of cash within the global payment industry. The website serves as a hub for news, studies, events, and resources that emphasize the importance of cash as a payment method, highlighting its role in privacy, inclusion, and financial freedom. The organization targets consumers, industry stakeholders, and policymakers, positioning itself as a credible voice in the payments landscape. Technically, the website is built using modern web technologies including React and Next.js, with Apollo GraphQL for data management and Amazon Cloudfront for content delivery. The site is well-optimized for performance and mobile devices, featuring a professional design and clear navigation. Analytics are implemented via Google Analytics and Google Tag Manager, with appropriate privacy and cookie policies in place, indicating a good level of digital maturity. From a security perspective, the site enforces HTTPS and follows several best practices, though explicit security headers like Content-Security-Policy and X-Frame-Options are not visibly set. No vulnerabilities or exposed sensitive data were detected. The lack of WHOIS data due to privacy protection is typical for non-profit organizations and does not detract from the site's legitimacy. Overall, the security posture is solid but could be improved with additional headers and a vulnerability disclosure policy. The overall risk assessment is low, with the site demonstrating professionalism, compliance with privacy regulations, and a clear mission. Strategic recommendations include enhancing security headers, publishing a vulnerability disclosure policy, and providing clearer contact information to improve trust and transparency.

65
68
2
55
95
75
100
cashpaymentsadvocacyfinancenon-profit+3 more
ReactNext.jsApollo GraphQLCloudfront CDN+1
2025-07-22T00:47:56.476Z
virginexperiencedays.co.uk favicon

Virgin Experience Days Ltd.

virginexperiencedays.co.uk

67
RetailUnited KingdomlargeMEDIUM

Virgin Experience Days Ltd. operates a UK-based e-commerce platform specializing in experience gifts, offering over 5,000 experiences ranging from supercars and spa days to dining and adventure activities. The company is positioned as a leading provider in the UK market with a broad target audience including families and gift buyers. The website demonstrates a mature digital infrastructure leveraging modern technologies such as Next.js, React, and marketing tools like Google Tag Manager and Klaviyo, indicating a well-developed digital presence. Security posture is generally good with HTTPS enforced and no exposed sensitive data, though the absence of security headers and explicit privacy and cookie policies suggests room for improvement in compliance and security best practices. Overall, the site is professional, trustworthy, and user-friendly, with a high-quality design and clear navigation. The WHOIS data could not be retrieved due to a query on the www subdomain, which is invalid for .uk domains, but the website content and branding strongly support legitimacy. Strategic recommendations include enhancing security headers, publishing comprehensive privacy and cookie policies, and providing clear contact and incident response information to strengthen trust and compliance.

55
68
17
75
77
65
100
experiencegiftsuke-commerceadventurespa+3 more
Next.jsReactGoogle Tag ManagerKlaviyo+1
2025-07-21T22:06:27.144Z
upland.me favicon

Uplandme, Inc.

upland.me

69
TechnologyUnited StatesmediumMEDIUM

Uplandme, Inc. operates Upland, a blockchain-based virtual real estate game that enables users to buy, sell, and trade digital properties mapped to real-world locations. The platform leverages NFTs and an ERC-20 utility token ($SPARKLET) to create a player-driven open economy with real-world value. The company targets web3 gamers and virtual asset investors, positioning itself as a leader in the emerging metaverse and blockchain gaming space. The website is professionally designed, mobile-optimized, and provides comprehensive information about the business, team, investors, and token economy. Technically, the website is built on modern frameworks including React and Next.js, hosted with Cloudflare DNS and CDN services. It integrates analytics and marketing tools such as Google Tag Manager, Google Optimize, and HubSpot. The platform supports multiple access points including web, iOS, and Android apps. Performance and SEO optimizations are well implemented, with good accessibility features. From a security perspective, the site enforces HTTPS with strong SSL configuration and implements key security headers. The domain registration is consistent and legitimate, with no suspicious patterns. However, DNSSEC is not enabled, and there is no visible cookie consent mechanism or published security/incident response policies, which are areas for improvement. Overall, Upland demonstrates a mature digital presence with strong business credibility and technical infrastructure. Strategic recommendations include enabling DNSSEC, implementing cookie consent for privacy compliance, publishing security policies, and establishing a vulnerability disclosure program to enhance trust and security posture.

55
53
2
98
75
85
100
blockchaingamingnftvirtualrealestateweb3+3 more
ReactNext.jsCloudflare DNSERC-20 token integration+3

Partner Domains:

animocabrands.com
partner
gaingels.com
partner

+2 more partners

2025-07-21T20:09:53.302Z
devit.software favicon

DevIT Software

devit.software

67
TechnologyUkrainesmallMEDIUM

DevIT Software is a specialized IT company focused on software engineering services for the Shopify platform, including app and theme development. As an authorized Shopify partner, they have established a credible market position with over 6,000 app users and a strong presence on the Shopify App Store and Discord Marketplace. Their business model centers on B2B software solutions tailored for Shopify store owners and businesses seeking to enhance their e-commerce capabilities. Technically, the website leverages modern web technologies such as React and Next.js, with hosting and DNS services provided by Cloudflare. The site demonstrates good mobile optimization, SEO practices, and a professional design consistent with their branding. However, some accessibility features are basic, and performance is moderate. From a security perspective, the site uses HTTPS and has domain transfer protections in place, but lacks important security headers and explicit security policies. There is no visible privacy or cookie policy, nor incident response or vulnerability disclosure information, which are areas for improvement to enhance compliance and trust. Overall, the website is professional and trustworthy with a solid business foundation, but could benefit from enhanced privacy compliance and security best practices to reduce risk and improve user confidence.

15
83
17
85
75
80
100
shopifysoftwaredevelopmente-commerceauthorizedpartnerappdevelopment+1 more
ReactNext.jsPolaris UI (Shopify)Cloudflare DNS and registrar+1
2025-07-21T19:52:41.870Z
tribalfootball.com favicon

Tribal Football

tribalfootball.com

60
MediaN/amediumMEDIUM

Tribal Football operates as a specialized media platform delivering comprehensive football news, transfer rumors, and updates on teams and players worldwide. The website targets football fans and sports enthusiasts, providing timely and relevant content primarily focused on European football leagues and major competitions. The business model appears to be content publishing supported by advertising and possibly affiliate marketing, positioning Tribal Football as a recognized player in the football news media sector. Technically, the website is built using modern web technologies including React, Google Tag Manager, and performance monitoring tools like Lux. It demonstrates good mobile optimization, SEO practices, and moderate performance. The site uses HTTPS exclusively, ensuring secure data transmission, and integrates standard analytics tools for user behavior tracking. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data in its HTML content. However, it lacks explicit security headers and publicly available security policies or incident response information, which are areas for improvement. The absence of WHOIS data raises questions about domain registration legitimacy, though the website content and structure suggest a professional and trustworthy operation. Overall, Tribal Football presents a solid digital presence with good content quality and technical implementation. The main risks relate to domain registration transparency and the lack of detailed security and incident response disclosures. Addressing these gaps would enhance trust and compliance posture.

30
70
17
40
75
75
100
footballsportsnewstransfersmedia
ReactGoogle Tag ManagerGoogle AnalyticsLux (performance monitoring)+2
2025-07-17T17:39:15.522Z