Skip to main content

High-risk security reports

Browse 46,362 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155885
Websites
130
Industries
113
Countries
52
Avg Score
Page 12 of 928|Showing 551-600 of 46362
spinningdrum.co.uk favicon

Spinningdrum | Brand & Online Communications

spinningdrum.co.uk

44
OtherUnited KingdomsmallHIGH

Spinningdrum is a UK-based brand and online communications consultancy established in 2005, specializing in building brands through integrated brand and business strategies. The company targets businesses seeking to enhance their brand presence and digital communications, offering services such as brand strategy, identity, marketing communications, and optimisation. Their market position is that of an experienced, small consultancy with a professional online presence and a clear focus on brand effectiveness. Technically, the website is built on WordPress using the Avada theme and several popular plugins including LayerSlider, Yoast SEO, and Contact Form 7. The site is hosted by a reputable UK provider (LCN) and employs HTTPS with good SSL configuration. Performance is moderate with good mobile optimization and basic accessibility features. SEO is well supported by meta tags and structured data. From a security perspective, the site uses HTTPS and secure form submissions but lacks visible security headers and does not provide explicit security or incident response policies. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is limited due to the absence of privacy and cookie policies and no consent mechanism. Overall, the website is professional and trustworthy with a strong business credibility score. However, improvements in privacy compliance and security headers are recommended to enhance trust and regulatory adherence.

30
35
17
70
37
60
20
brandingmarketingcommunicationsconsultancydigital+2 more
jQueryLayerSliderYoast SEOSlider Revolution+2
2026-07-25T07:23:12.936Z
atomeducation.co.uk favicon

ATOM Education Ltd.

atomeducation.co.uk

42
EducationUnited KingdomsmallHIGH

ATOM Education Ltd. is a specialist recruitment agency established in 2006, focusing on staffing solutions for institutional and educational workplaces, including the prison sector, young offender institutions, and secure training centers. The company offers both permanent and temporary recruitment services, targeting clients and candidates within these niche sectors. The website reflects a professional and consistent brand presence with clear navigation and relevant content tailored to its audience. The domain age and WHOIS data corroborate the company's longstanding market presence in the UK education sector. Technically, the website is built on WordPress using common plugins such as Contact Form 7 and Email Subscribers, with UIkit as the front-end framework. The site is hosted by GoDaddy and employs HTTPS, ensuring secure communication. Performance and mobile optimization are moderate to good, though accessibility and SEO could be improved. The absence of advanced security headers and privacy policies indicates room for enhancement in security and compliance. From a security perspective, the site uses HTTPS and standard WordPress security practices but lacks explicit security headers and visible privacy or cookie policies, which are critical for GDPR compliance. No vulnerabilities or exposed sensitive data were detected in the provided content. The lack of incident response or security contact information suggests limited formal security posture documentation. Overall, the website is functional, professional, and trustworthy for its business domain but would benefit from improved privacy compliance, enhanced security headers, and clearer contact information to strengthen user trust and regulatory adherence.

20
50
2
85
47
60
-
recruitmenteducationprisonsectorstaffinginstitutional+1 more
jQueryWordPressKingComposerUIkit+2
2026-07-25T07:22:40.315Z
twist-id.co.uk favicon

Digital Spirit

twist-id.co.uk

44
Non-profitN/asmallHIGH

Digital Spirit is a Christian web and graphic design agency specializing in serving churches, charities, and the education sector. Their market position is niche, focusing on non-profit organizations with tailored digital solutions. The website content is professional and consistent with their stated mission, featuring clear contact information and social media presence. However, the domain www.twist-id.co.uk queried is invalid and not registered, indicating a possible misconfiguration or error in domain usage. Technically, the website uses the Foundation framework and jQuery, with Typekit fonts for styling. The site is moderately optimized for mobile and performance but lacks advanced SEO and accessibility features. No CMS or hosting provider information is evident. Security posture is weak due to missing HTTPS confirmation and absence of security headers. Privacy compliance is minimal with only a basic privacy policy available in PDF format on a related domain, and no cookie consent mechanism. Security evaluation reveals no immediate vulnerabilities but highlights the need for HTTPS enforcement, security headers, and improved privacy practices. The lack of WHOIS data for the queried domain reduces trust in that domain, though the actual website domain digital-spirit.co.uk appears legitimate. Overall, the site is functional and professional but requires improvements in security and privacy compliance to enhance trust and protection.

15
53
2
80
57
70
20
christianwebdesigngraphicdesignnon-profitcharity+1 more
jQueryFoundation frameworkTypekit fonts
2026-07-25T07:18:32.704Z
sasbah.org.uk favicon

Sussex Association for Spina Bifida and Hydrocephalus

sasbah.org.uk

42
Non-profitUnited KingdomsmallHIGH

Sussex Association for Spina Bifida and Hydrocephalus (SASBAH) is a UK-based non-profit organization dedicated to supporting individuals affected by Spina Bifida and Hydrocephalus in Sussex. The website serves as an informational and engagement platform targeting affected individuals, families, healthcare professionals, and donors. The organization has an established presence since 2004, reflecting stability and community trust. Technically, the website is built on WordPress using the Divi theme, hosted by ANS Group Ltd (UKFAST). It employs Google Analytics for visitor tracking and uses Google Fonts for typography. The site is mobile-optimized with moderate performance and basic accessibility features. However, it lacks some advanced SEO and accessibility optimizations. From a security perspective, the site enforces HTTPS and implements a cookie consent mechanism, indicating awareness of privacy regulations. However, it lacks several important security headers such as Content-Security-Policy and X-Frame-Options, which could improve protection against common web attacks. No signs of WAF or content blocking were detected, and no vulnerabilities were evident from the HTML content. Overall, the website presents a trustworthy and professional image consistent with a small non-profit organization. To enhance security and compliance, it is recommended to implement missing security headers and publish comprehensive privacy and terms of service policies. These improvements will strengthen user trust and regulatory compliance.

15
50
2
55
57
65
20
non-profithealthcaredisabilitysupportwordpressdivi+1 more
WordPressDivi ThemeGoogle FontsGoogle Analytics
2026-07-25T07:17:55.950Z
asgs.co.uk favicon

All Seasons Group Services

asgs.co.uk

42
OtherUnited KingdomsmallHIGH

All Seasons Group Services (ASGS) is a UK-based commercial cleaning company specializing in providing tailored cleaning services to both public and private sectors across South and South West England. Their offerings include commercial cleaning, build cleans, window cleaning, and event cleaning. The company emphasizes quality, reliability, and direct management involvement from their Director, positioning themselves as a leading regional service provider. The website is professionally designed with clear navigation and contact information, targeting commercial clients in the region. Technically, the website employs Bootstrap and jQuery frameworks, ensuring responsive design and moderate performance. However, there is no evidence of HTTPS enforcement or advanced security headers, and no analytics or tracking scripts are present. The site lacks cookie consent mechanisms despite having cookie and privacy policy pages, indicating partial privacy compliance. From a security perspective, the absence of HTTPS and security headers lowers the security posture. The WHOIS data is unavailable due to a domain naming rules error from the UK registry, which raises concerns about domain registration legitimacy. No incident response or vulnerability disclosure information is provided. Overall, the site appears safe and professional but requires improvements in security and privacy compliance. Strategically, ASGS should prioritize implementing HTTPS, adding security headers, and deploying cookie consent mechanisms to enhance trust and compliance. Addressing the WHOIS data anomaly or clarifying domain registration status would further improve legitimacy perception.

15
68
2
85
47
60
-
commercialcleaningcleaningservicesukbusinessservicesfacilitymanagement
BootstrapjQuery
2026-07-25T07:15:18.144Z
rossendalehospice.org favicon

Rossendale Hospice

rossendalehospice.org

45
Non-profitUnited KingdomsmallHIGH

Rossendale Hospice is a UK-based charitable organization dedicated to providing compassionate care and support to individuals in the Rossendale community facing life-limiting illnesses. The organization operates primarily through donations, fundraising events, and community engagement, offering services such as Hospice at Home, wellbeing centers, counselling, and complementary therapies. Their website reflects a well-established local charity with a strong focus on patient and family support as well as healthcare professional collaboration. Technically, the website is built on the Kentico CMS platform and leverages modern web technologies including jQuery, Bootstrap, Google Tag Manager, Facebook Pixel, and Hotjar for analytics and user experience enhancement. The site is mobile-optimized, accessible, and demonstrates good SEO practices. Performance is moderate, with room for optimization. From a security perspective, the site enforces HTTPS and includes cookie consent mechanisms, but lacks explicit security headers and published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the content. The absence of WHOIS data is a minor concern but does not significantly detract from the site's legitimacy given the professional presentation and charity registration details. Overall, Rossendale Hospice's website is a trustworthy and professional digital presence for a non-profit healthcare charity. Strategic improvements in security headers, transparency of security policies, and WHOIS data verification would further enhance trust and compliance.

15
53
2
70
57
60
20
charityhospicehealthcarenon-profitfundraising+3 more
jQueryBootstrapKentico CMSGoogle Tag Manager+8
2026-07-25T07:12:40.626Z
P

Pro-Creative Diagnostics

casaexperts.com

40
HealthcareN/asmallHIGH

Pro-Creative Diagnostics is a small healthcare-focused company specializing in the development and commercialization of the Sperminator®, a device designed to improve the accuracy and reproducibility of semen analysis, particularly for IVF applications. Founded in 2012, the company targets medical professionals and research institutions with a niche product validated against standard manual methods. The website content reflects this specialized focus but is basic in design and technical sophistication. Technically, the website employs older JavaScript libraries such as jQuery 1.7.2 and a simple slider plugin, with no detected CMS or advanced frameworks. The site lacks HTTPS enforcement and security headers, which are critical for protecting user data and establishing trust. Mobile optimization and accessibility are minimal, and no privacy or cookie policies are present, indicating low digital maturity. From a security perspective, the absence of HTTPS and outdated libraries expose the site to potential vulnerabilities. The lack of WHOIS registration data is a significant concern, suggesting possible domain registration issues or privacy obfuscation that reduces trustworthiness. No incident response or security policies are published, and contact information is limited to a single phone number and email address. Overall, the website presents a professional but basic online presence with notable security and compliance gaps. Strategic improvements in security posture, privacy compliance, and domain legitimacy verification are recommended to enhance trust and protect business operations.

30
50
17
60
52
60
-
medicaldiagnosticssemenanalysishealthcareivf
jQuery 1.7.2easySlider 1.5HTMLCSS
2026-07-25T07:12:35.363Z
ducatimondo.co.uk favicon

Ducati Mondo

ducatimondo.co.uk

44
RetailUnited KingdomsmallHIGH

Ducati Mondo operates as a specialized e-commerce retailer focused on supplying OEM and aftermarket parts for Ducati and other Italian motorcycle brands within the UK market. The website presents a comprehensive catalog of motorcycle parts, organized by model and part type, targeting motorcycle enthusiasts and owners seeking specific spares. The business positions itself as a leading UK supplier in this niche, leveraging an online Magento platform to facilitate sales and customer account management. Technically, the website employs a Magento CMS with integrations of Google Analytics, Google Tag Manager, and Hotjar for analytics and user behavior tracking. The site uses HTTPS, ensuring encrypted communications, but lacks visible advanced security headers and formal privacy or cookie policies, indicating room for improvement in privacy compliance and security hardening. The site shows moderate performance and basic mobile optimization, with good navigation clarity and professional design. From a security perspective, the site benefits from HTTPS and secure cookie settings but lacks comprehensive security headers and incident response contact information. The absence of privacy and cookie policies reduces GDPR compliance confidence. The WHOIS lookup failed due to domain naming rules violations, limiting trust in domain registration legitimacy, although the website content and structure suggest a legitimate small business. Overall, Ducati Mondo presents a functional and professional e-commerce presence with moderate technical maturity and security posture. Strategic improvements in privacy compliance, security headers, and domain registration transparency would enhance trust and reduce risk exposure.

20
68
2
85
47
45
20
motorcycleducatimotorcyclepartse-commerceuk+2 more
Google AnalyticsGoogle Tag ManagerHotjarjQuery (implied by typical Magento JS)+1
2026-07-25T07:12:03.855Z
trafficsurveypartners.co.uk favicon

Traffic Survey Partners Ltd

trafficsurveypartners.co.uk

47
TransportationUnited KingdomsmallHIGH

Traffic Survey Partners Ltd is a UK-based specialist provider of traffic and transport data collection services, targeting local authorities, transport consultants, and private developers across the UK and Ireland. Their offerings include ANPR surveys, classified junction counts, automatic traffic counts, drone surveys, pedestrian and cycle crossing surveys, and queue length and signal timing surveys. The company is positioned as a trusted supplier, evidenced by their approvals on Coupa, Avetta, and Ariba platforms. The website reflects a professional and consistent brand image with clear contact channels and service descriptions. Technically, the website is built on WordPress using Elementor and Elementor Pro, incorporating modern web technologies such as Google reCAPTCHA v3 for form security and Complianz for GDPR cookie consent management. The site is mobile-optimized with good SEO and accessibility basics, hosted likely on a European provider. Performance is moderate with room for improvement in security headers and accessibility. Security posture is generally good with HTTPS enforced and secure form handling, but lacks some recommended security headers and a published security policy or incident response contacts. The WHOIS data for the domain is unavailable due to a domain registration error indicating the domain name violates Nominet UK naming rules, which raises concerns about domain legitimacy or configuration. Despite this, the website content and business information appear credible and professional. Overall, the website presents a trustworthy and professional front for a niche transport data service provider but should address domain registration issues, enhance security headers, and publish privacy and security policies to improve trust and compliance.

15
65
17
70
27
65
40
transporttrafficsurveyanprautomatictrafficcountsdronesurveys+7 more
WordPressElementorElementor ProjQuery+2
2026-07-25T07:11:58.589Z
clpsafety.co.uk favicon

CLP Safety & Training Ltd

clpsafety.co.uk

39
OtherUnited KingdomsmallHIGH

CLP Safety & Training Ltd is a UK-based health and safety consultancy firm established since 1995, specializing in supporting SMEs across diverse industries such as construction, retail, leisure, and engineering. The company offers tailored consultancy services including regulatory compliance, SSIP accreditation support, and assistance with Pre-Qualification Questionnaires, positioning itself as an experienced and trusted partner with long-term client relationships. The website reflects a professional business model focused on consultancy and training services for small and medium enterprises. Technically, the website is built on WordPress 6.7 using the Flatsome theme and Contact Form 7 plugin, with Google Fonts integration. The site is hosted likely by 20i Ltd, a UK-based hosting and registrar provider. The website demonstrates moderate performance and good mobile optimization, though accessibility and SEO optimizations are basic. No advanced analytics or tracking tools are detected, indicating a minimal user tracking approach. From a security perspective, the site uses HTTPS and standard WordPress security practices but lacks visible security headers and formal security or incident response policies. There are no detected vulnerabilities or exposed sensitive data, but the absence of privacy and cookie policies indicates compliance gaps with GDPR and related regulations. Contact information is clearly provided, but no dedicated security contact channels or certifications are presented. Overall, the website is safe, professional, and credible with a moderate security posture and some compliance shortcomings. Strategic improvements in privacy compliance, security headers, and incident response documentation would enhance trust and security maturity.

20
35
2
70
47
65
-
healthsafetyconsultancytrainingsmesupportukbusiness
WordPress 6.7PHPjQuery (commented out but referenced)Google Web Fonts+2
2026-07-25T07:11:21.792Z
R

RED Engineering

redengineers.co.uk

42
EnergyUnited KingdommediumHIGH

RED Engineering is a UK-based engineering services company specializing in delivering projects that enhance safety in hazardous environments. Founded in 2023, the company focuses on supporting clients in construction, maintenance, and decommissioning within the energy sector. Their website highlights a trusted partnership approach, client satisfaction, and recognized certifications such as SGS and Cyber Essentials. The company targets industrial clients requiring high-quality engineering solutions and testing facilities. Technically, the website is built on WordPress using modern plugins and frameworks like WPBakery, Bootstrap, and jQuery. The hosting is provided by Zen Internet Limited, a reputable UK hosting provider. The site demonstrates moderate performance and good mobile optimization but lacks some advanced accessibility and SEO features. From a security perspective, the site enforces HTTPS and displays certifications indicating a commitment to quality and safety. However, it lacks visible security headers and does not provide privacy or cookie policies, which are important for GDPR compliance. No incident response or vulnerability disclosure information is available, which could be improved to enhance trust. Overall, the website presents a professional and trustworthy image with solid business credibility. The main risks relate to privacy compliance and security best practices, which should be addressed to improve the security posture and regulatory adherence.

15
35
2
70
47
65
20
engineeringhazardousenvironmentsconstructionmaintenancedecommissioning+3 more
WordPressBootstrapjQueryOwl Carousel+4
2026-07-25T07:10:50.195Z