Skip to main content

High-risk security reports

Browse 43,717 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149318
Websites
130
Industries
113
Countries
52
Avg Score
Page 122 of 875|Showing 6051-6100 of 43717
kbv.de favicon

Kassenärztliche Bundesvereinigung

kbv.de

46
HealthcareGermanylargeHIGH

The website www.kbv.de represents the Kassenärztliche Bundesvereinigung (KBV), the umbrella organization for 17 statutory health insurance physician associations in Germany. It serves as a central platform organizing ambulatory healthcare and representing the interests of contracted physicians and psychotherapists at the federal level. The site targets healthcare professionals and stakeholders within the German healthcare system. The business model is non-profit and focused on healthcare governance and support services. The organization holds a strong national market position as a key healthcare body in Germany. Technically, the website is hosted on Akamai CDN infrastructure, uses modern web technologies including HTML5, CSS3, JavaScript, and Bootstrap for responsive design. The site demonstrates good mobile optimization, accessibility, and SEO practices. Cookie consent is managed via a custom script from a subdomain. However, no explicit CMS or analytics services were detected. From a security perspective, the site uses HTTPS and shows no visible vulnerabilities or exposed sensitive data. However, it lacks explicit security headers and does not provide a public security policy or incident response contacts. Privacy compliance is weak due to the absence of visible privacy and cookie policies. Contact information is not directly available on the homepage, which may impact user trust and compliance. Overall, the site is professional, trustworthy, and well-structured but would benefit from enhanced privacy disclosures, security headers, and clearer contact information to improve compliance and user confidence.

-
-
-
70
57
60
100
healthcaregovernmentstatutoryhealthinsurancephysiciansgermany
HTML5CSS3JavaScriptAkamai CDN (akam.net nameservers)+1

Partner Domains:

karriere.kbv.de
partner
2025-10-24T17:04:34.113Z
116117-termine.de favicon

Kassenärztliche Bundesvereinigung (KBV)

116117-termine.de

34
HealthcareGermanylargeHIGH

The website www.116117-termine.de serves as the official appointment booking platform for statutory health insured patients in Germany, operated under the auspices of the Kassenärztliche Bundesvereinigung (KBV). It provides a trusted and user-friendly service for booking, viewing, and canceling medical appointments with general practitioners and specialists. The platform is recognized as a Stiftung Warentest Testsieger in 2021, underscoring its market credibility and user trust. The target audience is primarily German statutory health insured patients seeking quick and reliable access to healthcare appointments. Technically, the website is built on the TYPO3 CMS framework, leveraging modern web technologies including JavaScript and CSS. It integrates Matomo analytics with a clear cookie consent mechanism, ensuring compliance with GDPR and privacy best practices. The site demonstrates good mobile optimization, accessibility, and SEO practices, contributing to a positive user experience. Hosting appears to be managed by kv.digital GmbH, a technology partner closely affiliated with the KBV. From a security perspective, the site enforces HTTPS and employs cookie consent for tracking, minimizing privacy risks. However, explicit security headers such as Content Security Policy and HSTS are not evident, and no formal security or incident response policies are published. No vulnerabilities or exposed sensitive data were detected in the analysis. The WHOIS data is limited but does not raise concerns, and the domain appears legitimate and consistent with the official nature of the service. Overall, the website presents a professional, secure, and privacy-conscious platform that effectively supports its public healthcare mission. Strategic improvements could include publishing a security policy, adding security headers, and providing clearer contact information for incident response. These enhancements would further strengthen trust and compliance in an increasingly regulated digital environment.

-
-
-
70
62
40
20
healthcareappointmentbookingmedicalgermanypublicservice+3 more
TYPO3 CMSMatomo AnalyticsJavaScriptCSS

Partner Domains:

www.kbv.de
partner
www.kv.digital
partner
2025-10-24T17:04:29.052Z
W

Women In Architecture France

womeninarchitecture.fr

36
OtherFrancesmallHIGH

Women In Architecture France is a small non-profit association dedicated to promoting gender equity in the architecture profession, primarily in France and Europe. Founded in 2018 by three architects, the organization focuses on advocacy, research, awards, and international collaboration to enhance the visibility and professional equality of women architects. The website serves as an informational platform showcasing the founders, their mission, and related activities. Technically, the website is built on an older version of WordPress with the Enfold theme and uses common web technologies such as jQuery and LayerSlider. The site is accessible, mobile-optimized, and uses HTTPS, but lacks modern security headers and up-to-date software versions, which could pose security risks. No analytics or tracking scripts are present, indicating minimal user tracking. From a security perspective, the site has a good SSL configuration but lacks important security headers and privacy compliance documentation such as privacy and cookie policies. The absence of WHOIS data for the domain is a concern for trust and legitimacy verification. No contact emails or phone numbers are provided, limiting direct communication channels. Overall, the website is professional and content-rich for its niche but requires improvements in security practices, privacy compliance, and transparency to enhance trustworthiness and reduce risk.

15
10
17
70
62
45
-
architecturewomenequalitynon-profitfrance+1 more
WordPress 4.9.28jQuery 1.12.4LayerSlider 6.7.1Google Fonts (Open Sans)+1
2025-10-24T16:59:24.694Z
atlasestateagents.co.uk favicon

Atlas Estate Agents

atlasestateagents.co.uk

45
Real EstateUnited KingdomsmallHIGH

Atlas Estate Agents is a well-established real estate agency specializing in residential and commercial property sales, lettings, and management in Liverpool, UK. The company emphasizes competitive pricing, family business values, and customer service, positioning itself as a trusted local market player since 1965. Their website provides property search functionality, valuation requests, and detailed service information targeting buyers, sellers, landlords, and tenants in the Liverpool area. Technically, the website employs a modern tech stack including jQuery, Bootstrap, Google Maps API, Google reCAPTCHA, Google Tag Manager, and Facebook Pixel. The site is mobile-optimized with good navigation and SEO practices, though some accessibility features are basic. Security measures include HTTPS enforcement and spam protection via reCAPTCHA, but lack certain HTTP security headers and cookie consent mechanisms. From a security perspective, the site shows a moderate maturity level with no visible vulnerabilities or exposed sensitive data. However, the absence of security headers and formal privacy/cookie consent banners indicates room for improvement in compliance and defense-in-depth. The WHOIS lookup failed due to querying a subdomain rather than the registered domain, limiting domain trust verification. Overall, the site is professional and trustworthy but could enhance its security posture and privacy compliance. Strategically, the company should prioritize implementing security headers, cookie consent mechanisms, and publishing security policies to strengthen user trust and regulatory compliance. Additionally, clarifying domain registration details and improving accessibility would further enhance their digital maturity and risk management.

15
53
2
75
72
65
-
realestateestateagentslettingagentsliverpoolproperty+3 more
jQueryBootstrapGoogle Maps APIGoogle reCAPTCHA+4
2025-10-24T16:32:27.786Z
dlhsulawesitenggara.id favicon

Dinas Lingkungan Hidup Provinsi Sulawesi Tenggara

dlhsulawesitenggara.id

49
GovernmentIndonesiamediumHIGH

The website dlhsulawesitenggara.id serves as the official online presence of the Environmental Agency of Southeast Sulawesi Province, Indonesia. It provides public information including news, announcements, documents, and contact details relevant to environmental management in the region. The site targets residents and stakeholders within the province and operates as a government service platform. Technically, the website employs common web technologies such as Bootstrap, jQuery, and Font Awesome, hosted behind Cloudflare DNS services. The site demonstrates basic mobile optimization and moderate performance but lacks advanced SEO and accessibility features. Security-wise, HTTPS is enabled, but the absence of DNSSEC and security headers reduces the overall security posture. The WHOIS data presents inconsistencies, including a future domain creation date and a registrant organization that does not align with the government entity, which raises questions about domain ownership authenticity. No privacy, cookie, or terms of service policies are present, indicating compliance gaps. Overall, the website is functional and safe for general audiences but requires improvements in security, privacy compliance, and domain legitimacy to enhance trust and professionalism.

15
35
2
40
75
70
100
governmentenvironmentpublicserviceindonesiasulawesitenggara
BootstrapjQueryFont AwesomeGoogle Fonts (Roboto)+2
2025-10-24T16:12:25.848Z
iqsperrholz.org favicon

IQS Initiative Qualitätssperrholz

iqsperrholz.org

44
ManufacturingGermanysmallHIGH

The IQS Initiative Qualitätssperrholz is a voluntary association of companies within the wood import industry in Germany, focused on promoting fair competition and transparency in plywood product quality and labeling. The website serves as an informational platform to educate customers and industry participants about plywood standards and product declarations. The business model centers on collaboration among industry members to ensure consistent quality and compliance with relevant norms. The site is well-positioned within its niche, supported by a network of partner companies and the Gesamtverband Deutscher Holzhandel e.V., which provides organizational backing. Technically, the website is built on a modern WordPress CMS platform using Elementor and JetEngine plugins, with SEO optimization via Yoast and cookie consent managed by Borlabs Cookie. The site is mobile-optimized and performs moderately well, with a clean and professional design. Security posture is adequate with HTTPS enabled and domain transfer protection in place, though it lacks explicit security policies and vulnerability disclosures. Security-wise, the site benefits from SSL encryption and domain status protections but is missing critical compliance documents such as a privacy policy and terms of service, which impacts GDPR compliance and overall trust. No incident response or vulnerability disclosure mechanisms are present, which could be improved to enhance security readiness. Overall, the website is a credible and professional representation of the IQS initiative with good business credibility and technical implementation. Strategic improvements in privacy compliance and security transparency would further strengthen its position and trustworthiness.

25
73
2
55
62
60
-
woodplywoodqualityindustryinitiative+3 more
WordPress 6.8.3Elementor 3.32.4JetEngine pluginYoast SEO plugin+2
2025-10-24T16:10:50.588Z
S

Städte-Verlag E. v. Wagner & J. Mitterhuber GmbH

unser-stadtplan.de

48
OtherGermanymediumHIGH

Unser-stadtplan.de is a German website operated by Städte-Verlag E. v. Wagner & J. Mitterhuber GmbH, providing digital and printed city maps, district maps, and comprehensive business directories. The platform also features job listings, targeting local residents and businesses in Germany. The website content is primarily in German and focuses on delivering detailed geographic and commercial information to its users. The business model revolves around map publishing and local business promotion, positioning itself as a regional leader in city planning and local information services. Technically, the website uses standard web technologies including JavaScript and CSS with custom scripts for UI interactions and animations. The site shows moderate performance and basic mobile optimization but lacks advanced SEO and accessibility features. No CMS or major frameworks are detected. The hosting provider and SSL configuration details are not explicitly available, limiting a full technical assessment. From a security perspective, the site does not explicitly show HTTPS status or security headers in the provided data, indicating potential gaps in security best practices. No privacy or cookie consent banners are present, which is a compliance concern under GDPR. The site includes a privacy policy and contact form but lacks visible incident response or security policies. No vulnerabilities or exposed sensitive data were detected in the HTML content. Overall, the website is functional and provides valuable local information but would benefit from enhanced security measures, improved privacy compliance, and better technical modernization to strengthen trust and user experience.

15
28
2
85
95
75
20
mapscityplansbusinessdirectoryjoblistingsgerman+1 more
JavaScriptCSSHTML5
2025-10-24T16:09:29.656Z
R

revsci.net

revsci.net

42
OtherN/asmallHIGH

The website revsci.net currently hosts extremely minimal content, consisting solely of a small JavaScript snippet that loads an external accessibility script. There is no metadata, no business information, no contact details, and no policies present on the site. The domain is newly registered in August 2023 via DropCatch.com, a domain drop-catching registrar, suggesting the site is either in early development or speculative. The lack of content and business information prevents any meaningful assessment of the company's market position or services. From a technical perspective, the site uses basic JavaScript but lacks modern web development best practices such as SEO metadata, accessibility features, or performance optimizations. There is no evidence of HTTPS or security headers, which poses a significant security risk. No analytics or advertising technologies are detected, indicating minimal digital maturity. Security posture is weak due to the absence of HTTPS, security headers, privacy policies, and contact information for incident response. The domain registration is legitimate but does not align with any visible business claims, reducing trustworthiness. No vulnerabilities or malicious indicators are detected, but the site is not production-ready. Overall, the site scores very low on content quality, security, privacy compliance, and business credibility. Strategic recommendations include enabling HTTPS, adding comprehensive privacy and cookie policies, publishing contact and security incident response information, and developing meaningful website content to establish trust and legitimacy.

15
40
17
60
72
70
40
JavaScript
2025-10-24T16:09:07.482Z
amnesty-intern.de favicon

Fachkommission Internet – Amnesty International

amnesty-intern.de

43
Non-profitGermanysmallHIGH

The Fachkommission Internet (FK Internet) website serves as an informational and support platform for the German section of Amnesty International, focusing on IT-related services such as webhosting, email, cloud storage, and intranet support. The organization operates as a small, volunteer-driven non-profit entity providing specialized IT assistance to Amnesty International groups and districts in Germany. The website is built on WordPress and leverages a variety of plugins and modern web technologies to deliver content and services effectively. Hosting is provided by Manitu, a reputable German hosting provider, which aligns with the organization's regional focus. From a technical perspective, the site demonstrates a moderate level of digital maturity with a modern tech stack, responsive design, and active content updates. However, there is room for improvement in areas such as security headers implementation and cookie consent mechanisms to enhance GDPR compliance. The absence of explicit terms of service and vulnerability disclosure pages suggests potential gaps in formal security and compliance documentation. Security posture is generally good, with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. The site does not exhibit signs of malicious activity or phishing. Privacy compliance is supported by the presence of a privacy policy, though cookie consent mechanisms are lacking. Contact information is available primarily via email and contact forms, but no phone numbers or physical addresses are prominently displayed. Overall, FK Internet presents a trustworthy and professional online presence consistent with its non-profit mission. Strategic recommendations include enhancing privacy compliance with cookie consent, implementing security headers, and publishing formal security policies to strengthen trust and compliance further.

35
28
2
55
62
65
20
non-profitamnestyinternationalitsupportwebhostingemailservices+2 more
WordPress 6.8.3jQueryLeaflet.jsFontAwesome Pro+5

Partner Domains:

amnesty-international.de
partner
amnesty-intern.de
partner
2025-10-24T16:06:21.545Z
S

Robot Challenge Screen

sefeaimpact.it

36
OtherItalysmallHIGH

The website sefeaimpact.it currently serves a robot challenge screen implementing a proof-of-work captcha mechanism to verify visitors. This indicates the presence of a Web Application Firewall (WAF) or security layer blocking direct access to the actual website content. Due to this, no business-related content, contact information, or policies are accessible for analysis. The domain is registered since 2016 with DNSSEC enabled, suggesting a legitimate registration, but the lack of accessible content limits further trust evaluation. Technically, the site uses custom JavaScript with Web Workers and cryptographic hashing to implement the captcha challenge. The hosting leverages AWS Cloudfront CDN for content delivery. However, no SEO, accessibility, or privacy compliance features are present on the challenge page. Security headers and HTTPS configuration details are not visible in the provided data. The security posture shows some strengths in DNSSEC and captcha usage but lacks visible security headers and privacy compliance mechanisms. The site does not expose forms or inputs, reducing attack surface but also limiting user interaction. Overall, the site is currently inaccessible for normal users without passing the challenge, which impacts usability and trust. Given these factors, the overall risk is moderate due to the blocking mechanism, but the lack of transparency and policies is a concern. Strategic recommendations include implementing visible security headers, publishing privacy and cookie policies, providing contact and incident response information, and improving user experience post-challenge.

20
25
2
85
72
60
-
securitycaptcharobotchallengeblockedwaf
JavaScriptWeb WorkersSHA1 hashingCrypto API
2025-10-24T16:05:31.214Z
fin4coop.it favicon

Consorzio Cooperativo Finanziario per lo Sviluppo

fin4coop.it

40
FinanceItalysmallHIGH

FIN4COOP is a cooperative financial intermediary operating nationally in Italy, focusing on providing financial services and support to cooperative members. The website serves as an information portal offering details on financial activities, brochures, membership procedures, financial statements, and news updates. The company targets cooperative organizations and mutual societies, positioning itself as a niche player in the cooperative finance sector with strategic partnerships and a cooperative business model. The website is professionally designed, consistent in branding, and includes trust signals such as privacy compliance and social media presence. Technically, the website is built on WordPress with a modern tech stack including jQuery, Google Maps API, and Google Analytics integrated with consent management. The site shows moderate performance and good mobile optimization. SEO practices are well implemented with proper meta tags and structured data. However, a visible PHP warning indicates a plugin issue that should be resolved to improve security and user experience. From a security perspective, the site uses HTTPS with excellent SSL configuration and employs a cookie consent mechanism via Iubenda. No critical vulnerabilities were detected, but the absence of security headers and the PHP warning reduce the security posture score. No incident response or security policy pages were found, suggesting room for improvement in transparency and preparedness. Overall, the website is trustworthy and professional with a good balance of content quality, technical implementation, and privacy compliance. Addressing the minor security issues and enhancing security headers would further strengthen the site's security and user trust.

15
68
2
70
-
65
20
financecooperativemutualitalyprivacy+2 more
WordPressPHPjQueryGoogle Maps API+6

Partner Domains:

wikisoftware.it
partner
webevolutodemo.cedac.com
partner
2025-10-24T16:05:16.175Z
nroa-cnoa.be favicon

ORDRE DES ARCHITECTES - ORDE VAN ARCHITECTEN FCGOA

nroa-cnoa.be

44
GovernmentBelgiumsmallHIGH

The website represents the National Council of the Order of Architects (NROA) in Belgium, a governmental regulatory body overseeing architects. It provides information about the council's assignments, composition, and offers a service to find architects via an external API. The site is multilingual, targeting Dutch, French, and German-speaking audiences in Belgium. The business model is regulatory and service-oriented, focusing on governance and professional oversight within the architecture sector. The organization is relatively new online, with domain registration in 2023, consistent with the website's recent content updates. Technically, the website is built on WordPress with Elementor and uses modern SEO and cookie consent plugins. Hosting is provided by OVH, a reputable provider. The site is mobile-optimized, has good SEO practices, and uses Google Analytics with consent-based loading. Performance is moderate, and accessibility is basic but functional. Security posture is good with HTTPS enforced and cookie consent implemented, though some security headers are not explicitly detected. Security-wise, no critical vulnerabilities or exposed sensitive data were found. The site lacks explicit security policies or incident response contacts, which could be improved. Privacy compliance is good with a clear cookie policy and consent mechanism. Business credibility is supported by consistent branding, structured data, and trust signals such as official logos and partner links. Overall, the website is professional, secure, and compliant with GDPR requirements, serving its role as a national architectural regulatory authority effectively.

25
25
2
60
62
75
20
architecturegovernmentbelgiumregulatorynroa+3 more
WordPress 6.8.3Elementor 3.32.4Rank Math SEOComplianz GDPR/CCPA Cookie Consent+1

Partner Domains:

ordredesarchitectes.be
partner
architect.be
partner
2025-10-24T15:57:29.603Z