Skip to main content

High-risk security reports

Browse 46,362 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155885
Websites
130
Industries
113
Countries
52
Avg Score
Page 11 of 928|Showing 501-550 of 46362
F

Security Verification

fathomit.co.uk

48
OtherN/asmallHIGH

The website www.fathomit.co.uk currently serves a security verification page that employs Google reCAPTCHA v3 to prevent automated access. This indicates the site is protected by a Web Application Firewall or similar bot mitigation technology, effectively blocking direct content access. Due to this, no meaningful business content, contact information, or policies are accessible for analysis. The domain WHOIS lookup failed with an error stating the domain name contains too many parts and cannot be registered, suggesting the domain may be invalid or improperly configured. This severely limits the ability to assess the legitimacy or business operations behind the site. Technically, the site uses Bootstrap 5.3.3 for styling and Google reCAPTCHA for security verification. However, no security headers or HTTPS enforcement details are visible in the provided data. The site lacks privacy, cookie, or terms of service policies, and no contact or company information is present. SEO and accessibility features are minimal or absent, and the overall user experience is poor due to the blocking challenge. From a security perspective, while the use of reCAPTCHA is a positive measure against bots, the absence of visible HTTPS enforcement and security headers, combined with the domain registration issues, represent significant concerns. The lack of transparency and contact information further reduces trustworthiness. Overall, the site’s security posture is weak beyond the bot protection layer, and the domain’s legitimacy is questionable. Given these factors, the site poses a moderate to high risk for users attempting to access it, and the lack of accessible content prevents a full business or compliance evaluation. Strategic recommendations include resolving domain registration issues, implementing HTTPS and security headers, publishing privacy and cookie policies, and providing clear business contact information to improve trust and compliance.

15
50
2
70
62
60
100
securityverificationcaptchabotprotection
Bootstrap 5.3.3Google reCAPTCHA v3
2026-07-26T07:10:35.188Z
A

Security Verification

atlas-washrooms.co.uk

47
OtherN/asmallHIGH

The website www.atlas-washrooms.co.uk currently serves a security verification page employing Google reCAPTCHA v3, effectively blocking access to any substantive content. This indicates the site is protected by a security mechanism, likely to prevent automated access or abuse. Due to this, no business-related content, contact information, or policies are accessible for analysis. The WHOIS lookup for the domain failed with an error from Nominet UK citing domain naming rules violations, suggesting the domain may be improperly registered or invalid. This raises significant concerns about the legitimacy and operational status of the website. From a technical perspective, the site uses Bootstrap 5.3.3 for styling and Google reCAPTCHA for bot mitigation, but no other frameworks or CMS are detectable. The lack of visible security headers, privacy policies, or contact details further limits the assessment of the site's security posture and compliance. The absence of HTTPS information in the provided data is a critical gap. Security-wise, the presence of reCAPTCHA is a positive control against automated abuse, but the lack of other security best practices and the blocked content status reduce confidence in the site's overall security maturity. The domain's WHOIS failure and lack of registrant data further diminish trust. Overall, the site is currently inaccessible beyond a security challenge, with no publicly available business or compliance information. This results in a low trust and legitimacy score, and the site should be monitored or further investigated for proper registration and operational status.

15
50
2
70
57
60
100
securitycaptchaverificationblocked
Bootstrap 5.3.3Google reCAPTCHA v3
2026-07-26T07:10:19.381Z
D

Attention Required! | Cloudflare

duftonkellner.co.uk

45
OtherN/asmallHIGH

The website www.duftonkellner.co.uk is currently inaccessible due to a Cloudflare Web Application Firewall (WAF) block, which prevents any meaningful content or business information from being retrieved or analyzed. The domain WHOIS lookup failed with an error indicating the domain name contravenes Nominet UK naming rules, suggesting the domain is either invalid or unregistered. Consequently, no business, contact, or compliance information is available. The site only displays a Cloudflare block page, indicating a security mechanism is actively preventing access. From a technical perspective, the site is protected by Cloudflare, but no further details about hosting, CMS, or technology stack can be determined due to the block. No security headers, privacy policies, or forms are accessible, limiting the ability to assess security posture or privacy compliance. The lack of WHOIS data and domain registration issues further reduce trust and legitimacy. Security-wise, the presence of a Cloudflare block indicates some level of protection against attacks, but the inability to access the site content or metadata prevents a full security evaluation. There are no visible vulnerabilities or exposed data, but the domain's invalid status is a critical concern. Overall, the site scores very low on content quality, technical implementation, security posture, privacy compliance, and business credibility due to the block and domain issues. Strategically, it is recommended to resolve the domain registration issues and ensure the website is accessible without triggering WAF blocks for legitimate users. Publishing clear business and compliance information will improve trust and credibility. Enhancing technical SEO, accessibility, and security headers will further strengthen the site’s posture.

35
35
2
70
37
60
100
Cloudflare
2026-07-26T07:09:47.607Z
I

www.indian-ocean.co.uk

indian-ocean.co.uk

47
OtherHIGH

The website www.indian-ocean.co.uk is currently inaccessible, presenting only a minimal HTML page with a 'local_rate_limited' message, indicating that access is blocked or rate limited, likely by a web application firewall or security mechanism. The WHOIS lookup for the domain failed due to a naming rules violation, suggesting the domain may be invalid or improperly registered. No business, contact, or policy information is available on the site, and no metadata or structured data was found to provide insights into the company's operations or services. From a technical perspective, the site lacks HTTPS, security headers, and any detectable modern web technologies or content, indicating a very low level of digital maturity. The absence of privacy and cookie policies further highlights compliance gaps. Security posture is weak due to missing SSL and headers, and the site is effectively non-functional for analysis. Overall, the domain's legitimacy is questionable given the WHOIS failure and the site's blocked state. The risk to users is low as no content is accessible, but the lack of transparency and security controls suggests the site is not currently operational or trustworthy. Strategic recommendations include resolving domain registration issues, implementing HTTPS and security headers, publishing privacy and cookie policies, and ensuring the site is accessible for proper business and security evaluation.

35
40
17
70
37
65
100
2026-07-26T07:08:43.968Z
L

Linaker Green Limited

linakergreen.com

40
TransportationUnited KingdomsmallHIGH

Linaker Green Limited is a small UK-based insurance brokerage firm specializing in commercial insurance for transportation and high-risk trades such as scaffolders and roofers. The company has a long history dating back to 1987 and is authorized by the Financial Conduct Authority, which adds credibility to its operations. The website provides basic information about the company, its history, and services but lacks modern design and mobile optimization. Technically, the website is built using basic HTML, CSS, and JavaScript without modern frameworks or CMS. There is no evidence of HTTPS or advanced security headers, which exposes the site to potential security risks. The absence of privacy and cookie policies indicates non-compliance with GDPR and other privacy regulations. No contact emails or phone numbers are explicitly provided, limiting direct communication channels. From a security perspective, the site lacks essential protections such as SSL/TLS encryption and security headers. The WHOIS data for the domain is missing or unavailable, which is a significant concern as it raises questions about the domain's legitimacy and registration status. While the website content appears professional and safe, these technical and registration issues reduce overall trustworthiness. Overall, the website presents a basic but functional online presence for Linaker Green Limited. However, critical improvements in security, privacy compliance, and domain registration transparency are necessary to enhance trust and protect both the business and its customers.

30
50
2
70
47
70
-
insurancebrokercommercialinsurancetransportationfca+1 more
JavaScriptHTMLCSS
2026-07-26T07:06:42.412Z
terrafix.co.uk favicon

Terrafix Limited

terrafix.co.uk

46
TechnologyUnited KingdommediumHIGH

Terrafix Limited is a UK-based company specializing in ICT and mobile data solutions primarily for emergency services such as the UK Ambulance Service, Security Services, and Police. Established in 1997, the company positions itself as a world leader in mobile data solutions, offering a broad range of services including hosted cloud environments, software services, communication systems, and 24/7 support. Their market position is reinforced by long-term contracts with government health departments and a focus on mission-critical infrastructure. The website reflects a professional and consistent brand image targeting emergency and security sectors. Technically, the website is built on WordPress with a modern technology stack including Bootstrap, jQuery, and various UI/UX enhancement libraries. It employs Google Analytics for user tracking and has implemented a cookie consent mechanism, indicating a moderate level of digital maturity. The site is mobile optimized with good SEO practices but lacks some accessibility features and formal privacy documentation. From a security perspective, the site uses HTTPS with no visible vulnerabilities or exposed sensitive data. However, it lacks published security policies, incident response plans, and vulnerability disclosure information, which are important for comprehensive security posture. The presence of BCI accreditation and clear contact information adds to trustworthiness. Overall, the security posture is good but could be improved with formal policy disclosures. The overall risk assessment is low with no critical issues detected. Strategic recommendations include publishing privacy and security policies, enhancing accessibility, and formalizing incident response and vulnerability disclosure processes to improve compliance and trust. The website quality and business credibility are high, supporting Terrafix's position as a reliable technology provider in the emergency services sector.

55
35
2
73
47
70
-
ictmobiledatasolutionsemergencyservicessecurityukambulanceservice+4 more
WordPress 7.0.2PHP (implied by WordPress)Google Analytics (MonsterInsights plugin)jQuery 3.7.1+8
2026-07-26T07:05:54.873Z
iwhc.com favicon

Irish World Heritage Centre

iwhc.com

48
HospitalityUnited KingdomsmallHIGH

The Irish World Heritage Centre (IWHC) is a well-established cultural and community venue based in Manchester, UK, serving the Irish community and broader audiences with event hosting, cultural activities, and hospitality services. The website reflects a professional and consistent brand presence, offering clear information about services such as venue hire, events, a bar, cafe, and retail shop. The domain age and WHOIS data support the legitimacy and stability of the organization. Technically, the website is built on WordPress with modern frameworks like Bootstrap and uses common plugins for navigation, forms, and analytics. The site is mobile-optimized and SEO-friendly, though performance is moderate. Security posture is adequate with HTTPS enforced but lacks advanced security headers and DNSSEC, which are recommended for enhanced protection. Privacy compliance is basic, with privacy and cookie policies present but no active consent mechanism. Overall, the security posture is moderate with no critical vulnerabilities detected, but improvements in security headers, privacy compliance, and incident response documentation would strengthen the site. The website is safe for general audiences, with no adult or explicit content. Contact information is comprehensive and clearly presented, supporting business credibility. Strategic recommendations include enhancing security headers, enabling DNSSEC, implementing cookie consent mechanisms, and publishing detailed security and incident response policies to improve trust and compliance.

25
68
2
70
47
70
20
irishheritagecommunitycentreeventsvenuemanchesterculture+1 more
WordPressBootstrap 4.3.1jQuery 3.7.1WPBakery Page Builder+3
2026-07-26T07:02:23.414Z
bxplant.com favicon

BX Plant Ltd

bxplant.com

40
ManufacturingUnited KingdomsmallHIGH

BX Plant Ltd is a UK-based manufacturer specializing in the design and production of sprayers for bitumen emulsion and concrete cure materials. The company offers a range of hand operated and motorised sprayers, along with spare parts and worldwide shipping services. Their market position is that of a niche manufacturer with an international export footprint, targeting industrial and commercial customers in need of specialized spraying equipment. The website content is professional and consistent with the business focus, providing clear contact information and product details. Technically, the website is built on Joomla CMS using the T3 framework and Bootstrap for responsive design. It employs common web technologies such as jQuery and FontAwesome. The site demonstrates moderate performance and good mobile optimization but lacks advanced SEO and accessibility features. No analytics or tracking scripts were detected, indicating minimal user tracking. From a security perspective, the site lacks visible security headers and privacy or cookie policies, which are important for compliance and user trust. The WHOIS data for the domain is missing, which raises concerns about domain legitimacy despite the professional website content. No WAF or blocking mechanisms were detected, and the site is fully accessible. Overall, the website presents a moderate risk profile with room for improvement in security posture and privacy compliance. Strategic recommendations include implementing security headers, adding privacy and cookie policies, verifying domain registration details, and enhancing SEO and accessibility features to improve trust and compliance.

20
35
2
85
47
70
-
manufacturingbitumensprayersconcretecureindustrialequipmentukbusiness
Joomla CMSBootstrap CSSjQueryFontAwesome

Partner Domains:

tudorfreight.com
partner
2026-07-26T07:01:46.392Z
M

www.mep.com

mep.com

42
OtherN/asmallHIGH

The website at www.mep.com currently presents minimal content, primarily consisting of embedded consent management scripts from ConsentManager. There is no visible business information, metadata, or user-facing content to describe the company, its services, or contact details. The domain WHOIS query returned no registration data, indicating the domain may be unregistered, parked, or protected, which raises significant trust concerns. The lack of privacy policy, terms of service, or contact information further limits the ability to assess the business credibility or compliance posture. Technically, the site uses JavaScript and a third-party consent management platform to handle cookie and privacy consent, but no other modern frameworks, CMS, or analytics services are detected. The website appears to have basic mobile optimization and accessibility but lacks SEO metadata and security headers. HTTPS status cannot be confirmed from the provided data. From a security perspective, the site lacks visible security best practices such as security headers and published policies. The absence of WHOIS data and business information suggests a low trust level and potential risk. No adult or explicit content is detected, and the site is rated safe for general audiences. Overall, the website is of low quality, with poor content and minimal technical sophistication. The domain registration status and lack of transparency significantly reduce trustworthiness. Strategic recommendations include registering the domain properly, publishing comprehensive privacy and security policies, adding contact information, implementing HTTPS with strong security headers, and improving website content and structure to build credibility.

15
50
2
70
-
70
100
JavaScriptConsentManager CMP
2026-07-25T07:26:12.157Z
R

Rothschild & Co and Edmond de Rothschild

rothschild.com

42
FinanceN/alargeHIGH

The website www.rothschild.com serves as a simple landing page jointly operated by Edmond de Rothschild and Rothschild & Co, two established financial institutions. It primarily functions as a navigation portal directing visitors to the respective official websites of these entities. The site lacks substantive content, privacy policies, contact information, or security disclosures, indicating it is not a primary business site but rather a gateway or placeholder domain. From a technical perspective, the site is minimalistic, employing basic JavaScript for randomizing displayed partner order and simple HTML/CSS styling. There is no evidence of advanced CMS, analytics, or tracking technologies. The absence of security headers and unknown SSL status suggest limited security hardening on this domain. The WHOIS query returned no registration data, which is unusual for a major financial brand and raises questions about domain registration legitimacy or privacy protection. Security posture is weak due to missing HTTPS confirmation, lack of security headers, and absence of privacy or cookie policies. No contact or incident response information is provided, limiting transparency and compliance with data protection regulations. However, the content is safe, corporate, and free from any adult or questionable material. Overall, the site presents low risk but also low trustworthiness as a standalone domain. It is recommended to verify domain registration status and improve security and compliance disclosures if this domain is intended for public or client-facing use.

15
40
17
70
47
80
20
financecorporatelandingpagepartnerlinks
JavaScript

Partner Domains:

www.rothschildandco.com
partner
www.edmond-de-rothschild.com
partner
2026-07-25T07:25:51.156Z
A

403 Forbidden

allensmithsurveyors.com

36
OtherN/asmallHIGH

The domain www.allensmithsurveyors.com is currently inaccessible, returning a 403 Forbidden error page with no visible content or business information. The WHOIS lookup failed to retrieve any registration data, indicating the domain may be unregistered, expired, or otherwise inactive. The website lacks any metadata, structured data, or scripts that would provide insight into the business or technical infrastructure. The only external link directs users to a related domain path and a hosting provider's branding page, suggesting misconfiguration or placeholder content. Due to the lack of accessible content and registration data, the overall trustworthiness and credibility of the domain are very low. From a technical perspective, the site shows no evidence of modern web technologies, analytics, or security headers. The hosting provider appears to be zen.co.uk, but no further infrastructure details are available. The site is not mobile optimized and has poor accessibility and SEO characteristics due to the absence of content. Security posture is weak, primarily because the site is inaccessible and does not provide any security or privacy policies. The absence of HTTPS details and security headers further reduces confidence. No contact or incident response information is available, limiting the ability to assess compliance or readiness. Overall, the domain and website present significant risks due to lack of registration data, inaccessible content, and absence of business or security information. Strategic recommendations include resolving domain registration issues, publishing clear business and privacy information, and implementing proper security controls to improve trust and compliance.

15
50
2
70
47
60
20
403forbiddenaccessdeniedblockedinactivedomain+1 more
2026-07-25T07:25:24.664Z
csbinderysolutions.com favicon

CS Bindery Solutions

csbinderysolutions.com

43
ManufacturingUnited KingdomsmallHIGH

CS Bindery Solutions is a UK-based small manufacturing business specializing in the refurbishment, sale, and maintenance of post press machinery such as saddle stitchers, binders, folders, and guillotines. The company positions itself as a UK leader in this niche market, targeting businesses in the printing and post-press trade sectors. Their business model combines equipment refurbishment with repair services and spare parts supply, supported by a professional website that includes clear contact details and a newsletter signup. Technically, the website is built on WordPress 4.9.26 with several plugins for SEO, sliders, and forms. It uses Google Analytics and Google Tag Manager for tracking and includes multilingual support via Google Translate. The site is moderately optimized for performance and mobile use, with good SEO practices but basic accessibility features. The domain is registered with a UK registrar and shows consistent registration data aligned with the business claims. From a security perspective, the site uses HTTPS and domain registration protections but lacks DNSSEC and modern security headers. The WordPress and jQuery versions are outdated, posing potential security risks. There is no explicit security policy or incident response information available. Privacy compliance is basic, with a privacy and cookie policy present but no active cookie consent mechanism. Overall, the website is professional and trustworthy with good business credibility but would benefit from technical and security updates to improve its posture and compliance. Strategic improvements in CMS updates, security headers, and privacy mechanisms are recommended to enhance resilience and user trust.

15
68
2
85
-
75
20
refurbishedmachinerypostpressmachineryindustrialequipmentukbusinessmanufacturing
WordPress 4.9.26jQuery 1.12.4Google AnalyticsGoogle Tag Manager+5
2026-07-25T07:24:42.822Z