Skip to main content

High-risk security reports

Browse 43,626 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149092
Websites
130
Industries
113
Countries
52
Avg Score
Page 121 of 873|Showing 6001-6050 of 43626
S

Robot Challenge Screen

sefeaimpact.it

36
OtherItalysmallHIGH

The website sefeaimpact.it currently serves a robot challenge screen implementing a proof-of-work captcha mechanism to verify visitors. This indicates the presence of a Web Application Firewall (WAF) or security layer blocking direct access to the actual website content. Due to this, no business-related content, contact information, or policies are accessible for analysis. The domain is registered since 2016 with DNSSEC enabled, suggesting a legitimate registration, but the lack of accessible content limits further trust evaluation. Technically, the site uses custom JavaScript with Web Workers and cryptographic hashing to implement the captcha challenge. The hosting leverages AWS Cloudfront CDN for content delivery. However, no SEO, accessibility, or privacy compliance features are present on the challenge page. Security headers and HTTPS configuration details are not visible in the provided data. The security posture shows some strengths in DNSSEC and captcha usage but lacks visible security headers and privacy compliance mechanisms. The site does not expose forms or inputs, reducing attack surface but also limiting user interaction. Overall, the site is currently inaccessible for normal users without passing the challenge, which impacts usability and trust. Given these factors, the overall risk is moderate due to the blocking mechanism, but the lack of transparency and policies is a concern. Strategic recommendations include implementing visible security headers, publishing privacy and cookie policies, providing contact and incident response information, and improving user experience post-challenge.

20
25
2
85
72
60
-
securitycaptcharobotchallengeblockedwaf
JavaScriptWeb WorkersSHA1 hashingCrypto API
2025-10-24T16:05:31.214Z
fin4coop.it favicon

Consorzio Cooperativo Finanziario per lo Sviluppo

fin4coop.it

40
FinanceItalysmallHIGH

FIN4COOP is a cooperative financial intermediary operating nationally in Italy, focusing on providing financial services and support to cooperative members. The website serves as an information portal offering details on financial activities, brochures, membership procedures, financial statements, and news updates. The company targets cooperative organizations and mutual societies, positioning itself as a niche player in the cooperative finance sector with strategic partnerships and a cooperative business model. The website is professionally designed, consistent in branding, and includes trust signals such as privacy compliance and social media presence. Technically, the website is built on WordPress with a modern tech stack including jQuery, Google Maps API, and Google Analytics integrated with consent management. The site shows moderate performance and good mobile optimization. SEO practices are well implemented with proper meta tags and structured data. However, a visible PHP warning indicates a plugin issue that should be resolved to improve security and user experience. From a security perspective, the site uses HTTPS with excellent SSL configuration and employs a cookie consent mechanism via Iubenda. No critical vulnerabilities were detected, but the absence of security headers and the PHP warning reduce the security posture score. No incident response or security policy pages were found, suggesting room for improvement in transparency and preparedness. Overall, the website is trustworthy and professional with a good balance of content quality, technical implementation, and privacy compliance. Addressing the minor security issues and enhancing security headers would further strengthen the site's security and user trust.

15
68
2
70
-
65
20
financecooperativemutualitalyprivacy+2 more
WordPressPHPjQueryGoogle Maps API+6

Partner Domains:

wikisoftware.it
partner
webevolutodemo.cedac.com
partner
2025-10-24T16:05:16.175Z
nroa-cnoa.be favicon

ORDRE DES ARCHITECTES - ORDE VAN ARCHITECTEN FCGOA

nroa-cnoa.be

44
GovernmentBelgiumsmallHIGH

The website represents the National Council of the Order of Architects (NROA) in Belgium, a governmental regulatory body overseeing architects. It provides information about the council's assignments, composition, and offers a service to find architects via an external API. The site is multilingual, targeting Dutch, French, and German-speaking audiences in Belgium. The business model is regulatory and service-oriented, focusing on governance and professional oversight within the architecture sector. The organization is relatively new online, with domain registration in 2023, consistent with the website's recent content updates. Technically, the website is built on WordPress with Elementor and uses modern SEO and cookie consent plugins. Hosting is provided by OVH, a reputable provider. The site is mobile-optimized, has good SEO practices, and uses Google Analytics with consent-based loading. Performance is moderate, and accessibility is basic but functional. Security posture is good with HTTPS enforced and cookie consent implemented, though some security headers are not explicitly detected. Security-wise, no critical vulnerabilities or exposed sensitive data were found. The site lacks explicit security policies or incident response contacts, which could be improved. Privacy compliance is good with a clear cookie policy and consent mechanism. Business credibility is supported by consistent branding, structured data, and trust signals such as official logos and partner links. Overall, the website is professional, secure, and compliant with GDPR requirements, serving its role as a national architectural regulatory authority effectively.

25
25
2
60
62
75
20
architecturegovernmentbelgiumregulatorynroa+3 more
WordPress 6.8.3Elementor 3.32.4Rank Math SEOComplianz GDPR/CCPA Cookie Consent+1

Partner Domains:

ordredesarchitectes.be
partner
architect.be
partner
2025-10-24T15:57:29.603Z
junge-erwachsene-mit-krebs.de favicon

Deutsche Stiftung für junge Erwachsene mit Krebs

junge-erwachsene-mit-krebs.de

46
HealthcareGermanymediumHIGH

The Deutsche Stiftung für junge Erwachsene mit Krebs is a specialized non-profit foundation dedicated to supporting young adults aged 18 to 39 diagnosed with cancer. The organization provides comprehensive information, support services, advocacy, and educational resources tailored to this demographic within Germany. Their market position is focused and niche, serving a critical healthcare segment with a strong emphasis on community engagement and scientific collaboration. The website reflects a mature digital presence with multilingual support and donation capabilities, indicating a well-established infrastructure. Technically, the website is built on WordPress with modern plugins such as Yoast SEO for optimization, GiveWP for donations, and WPML for multilingual content. The site demonstrates good mobile responsiveness, accessibility compliance (including BITV standards), and SEO best practices. Performance is moderate, with room for optimization, but overall the technical implementation supports the foundation's mission effectively. From a security perspective, the site enforces HTTPS and employs cookie consent management via Borlabs Cookie. While explicit security headers are not fully evident, no critical vulnerabilities or exposed sensitive data were found. The WHOIS data aligns well with the organization's identity, showing consistent registration and no privacy protection, which is appropriate for a non-profit entity. No incident response or vulnerability disclosure policies are publicly visible, suggesting an area for improvement. Overall, the website presents a low-risk profile with strong business credibility and compliance with privacy regulations. Strategic recommendations include enhancing security headers, formalizing incident response and vulnerability disclosure processes, and continuous monitoring of plugin security to maintain a robust security posture.

15
48
17
70
67
60
-
healthcarenon-profitcancersupportyoungadultsaccessibility+2 more
WordPressYoast SEO pluginGiveWP donation pluginWPML multilingual plugin+3
2025-10-24T15:55:33.980Z
schazo.ch favicon

Schazo AG

schazo.ch

45
TransportationSwitzerlandmediumHIGH

Schazo AG is a well-established regional delivery company based in Switzerland, specializing in early morning delivery of newspapers, magazines, and advertising materials across the Schaffhausen region and neighboring cantons. With over 30 years of experience and a workforce of approximately 150 employees, Schazo serves over 51,000 households, positioning itself as a key player in regional print media distribution. The company offers services including early delivery, advertising mail distribution, and comprehensive delivery solutions in partnership with local providers. Technically, the website is built on the webEdition CMS platform and utilizes jQuery and custom image fading scripts. The site demonstrates moderate performance and basic mobile optimization, with a clear navigation structure and consistent branding. SEO and accessibility features are basic but functional. The site includes a cookie consent mechanism compliant with GDPR requirements, and privacy and terms of service documents are available, though security policies and incident response information are absent. From a security perspective, the website uses HTTPS (assumed from modern standards though not explicitly confirmed in the HTML), but lacks visible security headers and explicit security policies. No vulnerabilities or exposed sensitive data were detected in the content. The cookie consent mechanism is implemented properly, enhancing privacy compliance. WHOIS data confirms the domain is consistent with the business profile, showing legitimacy and alignment with the company's claimed history and location. Overall, the website presents a professional and trustworthy image with good business credibility and privacy compliance. However, improvements in security headers, incident response transparency, and technical modernization could enhance the security posture and user trust further.

20
53
2
70
62
75
-
schazoschaffhausenfrhzustellungliefergebietlieferdienste+2 more
jQuerywandaImageFader
2025-10-24T15:55:13.932Z
junges-krebsportal.de favicon

Deutsche Stiftung für junge Erwachsene mit Krebs

junges-krebsportal.de

49
HealthcareGermanysmallHIGH

The Deutsche Stiftung für junge Erwachsene mit Krebs operates the Junges Krebsportal, a specialized online platform providing young cancer patients in Germany with direct access to expert advice and support. The portal offers multiple communication channels including online chats, telephone consultations, and in-person meetings, complemented by a Tandem-Beratung program where affected individuals support each other. The foundation is supported by recognized partners and foundations, reinforcing its credibility in the healthcare non-profit sector. Technically, the website is built using modern web standards including HTML5, CSS3, JavaScript, and the UIkit framework, hosted on a reputable German hosting provider. The site is mobile-optimized with good SEO practices and clear navigation, although accessibility features are basic. No major performance or technical issues were detected. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks visible security headers and explicit security or incident response policies. Privacy compliance is good with a comprehensive privacy policy, but no cookie consent mechanism is evident. No analytics or tracking scripts were detected, indicating a privacy-conscious approach. Overall, the website presents a trustworthy, professional, and focused service with a strong business credibility score. Security posture is solid but could be improved with additional headers and policies. The absence of cookie consent mechanisms and incident response information are notable gaps. The domain WHOIS data is limited but consistent with the business purpose. No WAF or blocking mechanisms interfere with content access.

15
28
17
80
77
70
20
healthcarecancernon-profitpatientsupportyoungadults+1 more
HTML5CSS3JavaScriptjQuery

Partner Domains:

junge-erwachsene-mit-krebs.de
partner
metzler-stiftung.de
partner

+1 more partners

2025-10-24T15:34:07.999Z
finanzen-mit-daniel-jung.de favicon

Sparkassen- und Giroverband Hessen-Thüringen (SGVHT)

finanzen-mit-daniel-jung.de

47
FinanceGermanymediumHIGH

The website 'finanzen-mit-daniel-jung.de' is an educational platform focused on financial literacy, primarily targeting students and educators in the Hessen and Thüringen regions of Germany. It is operated under the auspices of the Sparkassen- und Giroverband Hessen-Thüringen, a reputable financial association. The site offers a series of well-structured, easy-to-understand videos and learning materials to enhance financial knowledge. The partnership with Sparkassen and the inclusion of the Sparkassen-SchulService platform reinforce its credibility and regional relevance. Technically, the website employs modern web technologies including HTML5, CSS3, JavaScript, and integrates Google Tag Manager and Matomo for analytics, alongside a GDPR-compliant cookie consent mechanism. The site is hosted on servers indicated by the nameservers 'your-server.de' and related domains, suggesting a professional hosting environment. The site is mobile-optimized and demonstrates good SEO and accessibility practices, though some improvements in accessibility and security headers could be made. From a security perspective, the site uses HTTPS with strong SSL configuration and implements cookie consent for privacy compliance. No critical vulnerabilities or exposed sensitive data were detected. Privacy policies and terms of service are comprehensive and clearly presented, with a designated data protection officer contact provided. The site does not employ a vulnerability disclosure policy, which could be considered for future enhancement. Overall, the website presents a low-risk profile with strong business credibility and compliance posture. It effectively serves its educational mission with professional content and transparent governance. Strategic recommendations include enhancing HTTP security headers, formalizing a vulnerability disclosure process, and improving accessibility features to further strengthen the site's security and user experience.

15
45
17
70
100
45
-
financeeducationfinancialliteracysparkassevideos+2 more
HTML5CSS3JavaScriptGoogle Tag Manager+2

Partner Domains:

sparkassen-schulservice.de
partner
sfg-ht.de
partner
2025-10-24T15:33:02.574Z
helvetiarockt.ch favicon

Helvetiarockt

helvetiarockt.ch

48
OtherSwitzerlandsmallHIGH

Helvetiarockt is a Swiss non-profit organization dedicated to empowering girls, women, intersex, non-binary, trans, and agender individuals through music workshops, sensitization events, and networking platforms. The organization positions itself as a niche player in the Swiss cultural and social empowerment sector, leveraging partnerships such as musicdirectory.ch and diversityroadmap.org to extend its reach and impact. The website is multilingual, supporting German, French, Italian, Romansh, and English, reflecting its inclusive and broad audience approach. Technically, the website is built on WordPress with modern integrations including Google Analytics, Google Tag Manager, and Elfsight widgets. It uses jQuery and GSAP for animations and interactive elements. The site demonstrates good mobile optimization and SEO practices, although some accessibility features could be enhanced. Performance is moderate, with deferred script loading to improve user experience. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks advanced security headers and explicit security or incident response policies. Privacy compliance is basic, with privacy and cookie policies present but no active consent mechanism. The site collects user data via newsletter subscription forms and uses tracking scripts moderately. Overall, Helvetiarockt presents a trustworthy and professional online presence with a clear mission and audience. Security and privacy practices are adequate but could be improved to meet higher compliance standards. The domain registration data aligns well with the organization's profile, supporting legitimacy. Strategic recommendations include enhancing security headers, implementing cookie consent, and publishing explicit security policies to strengthen trust and compliance.

15
53
2
85
70
75
-
empowermentmusicworkshopsdiversitynon-profitswitzerland
Google AnalyticsGoogle Tag ManagerjQueryGSAP TweenMax+3

Partner Domains:

musicdirectory.ch
partner
diversityroadmap.org
partner
2025-10-24T15:32:32.188Z
bluecommunity.ch favicon

blue-community.ch

bluecommunity.ch

48
Non-profitSwitzerlandsmallHIGH

Blue Community is a Swiss non-profit organization dedicated to advocating for water as a human right and promoting sustainable water management practices. The website serves as a community platform for municipalities, educational institutions, technical enterprises, church communities, and companies to demonstrate responsibility locally and globally. The organization positions itself as a niche player in the environmental non-profit sector with a focus on water resource protection and international partnerships. Technically, the website is built on WordPress using modern Gutenberg blocks, enhanced with Matomo analytics and Mautic marketing automation tools. It employs a cookie consent mechanism compliant with GDPR, ensuring user privacy and transparency. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS and uses cookie consent best practices but lacks explicit security headers and published security policies. No vulnerabilities or exposed sensitive data were detected. The WHOIS data confirms domain legitimacy and consistency with the organization's Swiss non-profit identity. Overall, the website presents a trustworthy, professional, and privacy-conscious platform with room for improvement in formal security documentation and incident response readiness.

15
65
2
70
72
75
-
waternon-profitcommunitysustainabilityswitzerland+2 more
WordPressPHPJavaScriptMatomo Analytics+1
2025-10-24T15:29:40.255Z
vlb.de favicon

MVB GmbH

vlb.de

46
MediaGermanymediumHIGH

MVB GmbH operates the VLB (Verzeichnis Lieferbarer Bücher), a central platform for automated exchange of product information in the German-speaking book industry. The website serves key stakeholders including bookstores, publishers, self-publishers, and service providers, offering services such as order clearing (IBU), reference databases, and subscription discounts. The platform holds a strong market position as an authoritative source in its sector. Technically, the website employs modern web technologies including Bootstrap, Owl Carousel, and Google Tag Manager, hosted on Anexia infrastructure. It features responsive design, good SEO, and accessibility standards, with a cookie consent mechanism ensuring privacy compliance. The site is well-structured and professionally designed, providing a positive user experience. From a security perspective, the site uses HTTPS with good SSL configuration and no visible vulnerabilities or exposed sensitive data. However, it lacks explicit security policy pages, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for enhanced security posture. Overall, the website is trustworthy, professionally maintained, and compliant with GDPR. The WHOIS data aligns with the business entity, reinforcing legitimacy. Strategic improvements in security transparency and incident response readiness would further strengthen the platform's reliability.

20
28
2
85
67
60
20
vlbbuchbranchemvbgmbhbuchhandelverlage+2 more
JavaScriptBootstrapFont AwesomeOwl Carousel+2

Partner Domains:

vlbtix.de
partner
mvb-online.de
parent

+1 more partners

2025-10-24T15:28:29.779Z
contao-themes-shop.de favicon

Preiss Werbe- und Internetagentur

contao-themes-shop.de

44
TechnologyGermanysmallHIGH

The website www.contao-themes-shop.de represents Preiss Werbe- und Internetagentur, a small German company specializing in providing professional Contao CMS themes, templates, and extensions. Their business model focuses on e-commerce sales of digital products tailored for Contao CMS users, alongside offering custom theme development and support services primarily targeting agencies and businesses seeking customizable web solutions. The site is well-structured, with clear navigation and comprehensive legal and privacy documentation, reflecting a professional and trustworthy online presence. Technically, the website is built on the Contao Open Source CMS platform, utilizing modern JavaScript libraries such as jQuery, AOS, and mmenu for enhanced user experience and mobile responsiveness. Hosting is provided via kasserver.com, consistent with the domain's nameservers. Performance is moderate with good mobile optimization and basic accessibility features. The site employs secure form handling with CSRF tokens but lacks explicit HTTP security headers. From a security perspective, the site uses HTTPS and secure form tokens, indicating a baseline security posture. However, the absence of security headers and a formal security policy or incident response contact reduces the overall security maturity. Privacy compliance is strong with a comprehensive GDPR-compliant privacy policy, though no cookie consent mechanism is detected. Business credibility is high due to clear contact information, official Contao partner certifications, and consistent branding. Overall, the website presents a low-risk profile with good business credibility and technical implementation. Strategic improvements in security headers, cookie consent, and incident response documentation would enhance the security posture and compliance further.

55
28
2
70
72
45
-
contaothemestemplatescmswebdesign+2 more
Contao Open Source CMSjQueryIsotope ProductsAOS (Animate On Scroll)+1
2025-10-24T15:28:14.746Z
nachhaltige-landbewirtschaftung.de favicon

INL – Privates Institut für Nachhaltige Landbewirtschaftung GmbH

nachhaltige-landbewirtschaftung.de

39
OtherGermanysmallHIGH

INL – Privates Institut für Nachhaltige Landbewirtschaftung GmbH is a specialized institute focused on measuring ecological sustainability in agriculture. With over 16 years of experience, the company offers consulting, certification, monitoring, and scientific services primarily targeting agricultural businesses, retailers, and environmental stakeholders in Germany. The website reflects a niche market position with a professional presentation and clear service offerings. Technically, the website is built on WordPress 6.8.2 with a modern plugin ecosystem including OpenLayers for mapping and WP Statistics for analytics. Hosting is provided by Cloudpit, and the site uses HTTPS with good SSL configuration. Mobile optimization and SEO are well addressed, though accessibility is basic. No major technical issues or vulnerabilities were detected in the visible content. From a security perspective, the site uses HTTPS and some security best practices but lacks explicit security headers and published security or incident response policies. No vulnerabilities or exposed sensitive data were found. Privacy compliance is supported by a privacy policy and cookie consent mechanism, aligning with GDPR requirements. Overall, the site presents a low risk profile with a good balance of content quality, technical implementation, and business credibility. Strategic improvements could focus on enhancing security headers, publishing incident response information, and adding direct contact details for security and data protection officers.

15
28
2
60
62
60
-
sustainabilityagricultureenvironmentconsultingcertification+1 more
WordPress 6.8.2jQuery 3.7.1OpenLayersCoBlocks plugin+3
2025-10-24T15:27:14.516Z
bangladesch.li favicon

Verein Hilfe für Bangladesch

bangladesch.li

47
Non-profitLiechtensteinsmallHIGH

Verein Hilfe für Bangladesch is a small non-profit organization dedicated to supporting educational and social development projects in Bangladesh. Their website provides information about ongoing and archived projects, encouraging donations and sponsorships. The organization targets donors and supporters interested in charitable aid for Bangladesh. The site is primarily in German and uses WordPress with WooCommerce for donation processing. Technically, the website is built on a modern WordPress platform with common plugins such as WooCommerce, Contact Form 7, and Yoast SEO. It uses HTTPS and external CDNs for performance. The site is moderately optimized for mobile and SEO, with good navigation and content quality. However, some accessibility features are basic, and performance is moderate. From a security perspective, the site enforces HTTPS and restricts ad and personalization tracking in Google Analytics, indicating some privacy awareness. However, it lacks important security headers and does not publish a security policy or incident response contacts. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is partial, with a privacy policy present but no cookie consent banner. Overall, the website is legitimate and trustworthy for a small non-profit, with room for improvement in security posture and privacy compliance. Strategic recommendations include implementing security headers, adding a cookie consent mechanism, publishing security policies, and maintaining up-to-date software to enhance trust and compliance.

15
58
2
65
72
85
-
non-profitcharityeducationbangladeshdonation+1 more
WordPressWooCommercejQueryYoast SEO+2
2025-10-24T14:51:36.510Z