Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 122 of 248|Showing 6051-6100 of 12372
werkenbijcbr.nl favicon

CBR

werkenbijcbr.nl

70
GovernmentNetherlandsmediumMEDIUM

CBR is a Dutch government agency focused on traffic safety and mobility, operating a professional recruitment website targeting a range of professionals including examiners, IT specialists, jurists, and project leaders. The site serves as a portal for job listings, job alerts, and information about working at CBR, positioning itself as a stable and innovative employer within the public sector. The website is well-branded, consistent, and provides clear navigation and relevant content for its target audience. Technically, the website employs modern frontend technology such as Elm, integrates analytics tools like Matomo and Google Analytics, and uses secure YouTube embeds. The site is mobile-optimized, accessible, and SEO-friendly, with a moderate performance profile. Cookie consent mechanisms and privacy policies are implemented in compliance with GDPR requirements. From a security perspective, the site enforces HTTPS and uses secure content delivery practices. However, it lacks explicit security headers and a published security or incident response policy. No vulnerabilities or exposed sensitive data were detected. The WHOIS data aligns with the website's government affiliation, supporting legitimacy and trustworthiness. Overall, the website presents a low-risk profile with strong business credibility and good privacy compliance. Strategic improvements include enhancing security headers, publishing a vulnerability disclosure policy, and providing clearer incident response contact information to further strengthen security posture and user trust.

75
83
2
70
75
70
100
governmentrecruitmenttrafficsafetynetherlandscareer+1 more
Elm (frontend framework)Matomo (analytics)Google Tag ManagerGoogle Analytics (gtag)+3
2025-07-28T01:33:22.147Z
A

Alex Martsinovich

distantprovince.by

53
TechnologyCanadasmallMEDIUM

The website distantprovince.by is a personal professional portfolio for Alex Martsinovich, a software engineer specializing in Elixir development. The site highlights his professional background, previous employers, open source contributions, and hobby projects. It targets potential employers, recruiters, and the software development community, serving primarily as a personal branding and job-seeking platform. The website is hosted on DigitalOcean and uses modern web technologies including HTML5, CSS, JavaScript, and PostHog analytics for user tracking. The site is well-structured, mobile-optimized, and fast-loading, with good SEO practices and consistent branding. From a security perspective, the site uses HTTPS with a good SSL configuration but lacks security headers such as Content-Security-Policy and X-Frame-Options. There are no forms or sensitive data collection points, reducing attack surface. However, the absence of privacy and cookie policies, as well as no visible consent mechanisms, indicates gaps in privacy compliance. No incident response or vulnerability disclosure information is provided. The WHOIS data is transparent and consistent with the website's professional nature, showing no suspicious patterns or privacy protection. Overall, the website presents a low-risk profile with good technical implementation and business credibility but requires improvements in privacy compliance and security best practices. Strategic recommendations include adding privacy and cookie policies, implementing security headers, and providing contact information for security incidents to enhance trust and compliance.

50
35
2
70
72
75
40
softwareengineerportfolioelixirdeveloperopensourceprofessional+1 more
HTML5CSSJavaScriptPostHog analytics
2025-07-28T00:25:10.397Z
hidde.blog favicon

hiddedevries.nl

hidde.blog

57
TechnologyNetherlandssmallMEDIUM

Hidde.blog is a personal blog operated by Hidde de Vries, focusing on web accessibility, web standards, front-end development, and tech ethics. The site serves a niche audience of developers and accessibility enthusiasts, providing insightful blog posts, speaking engagements, and contact opportunities. The business model is primarily personal branding and thought leadership within the technology sector, with a small but consistent audience. The website is well-positioned as a trusted source in its niche with clear author identity and no commercial distractions. Technically, the site is built using the Eleventy static site generator, leveraging modern web standards including custom fonts and SVG graphics. It is hosted with DNS managed by NS1 and uses HTTPS with a good SSL configuration. The site is fast, mobile-optimized, and accessible, with a clean and professional design. SEO practices are good, with proper meta tags and Open Graph data. From a security perspective, the site enforces HTTPS and has domain transfer protection. However, it lacks DNSSEC and security headers such as Content-Security-Policy. No forms or inputs on the homepage reduce attack surface, and analytics are privacy-focused (GoatCounter). There is no explicit security policy or incident response contact published. Privacy compliance is partial, with an accessibility statement but no explicit privacy or cookie policies. Overall, the site is low risk with a strong reputation and good technical hygiene. Recommendations include enabling DNSSEC, adding security headers, publishing privacy and security policies, and implementing cookie consent if cookies are used. These steps would enhance trust and compliance further.

30
35
17
60
75
55
100
webaccessibilitywebstandardshtmlcssjavascript+2 more
EleventyJavaScriptCSSSVG
2025-07-28T00:24:52.244Z
fictionalbrandsarchive.com favicon

Fictional Brands Archive

fictionalbrandsarchive.com

49
MediaN/asmallHIGH

Fictional Brands Archive is a niche online platform dedicated to cataloging and researching fictional brands featured across various media including films, series, videogames, and animated content. The website offers a searchable and filterable database with detailed brand information such as sector, category, media type, genre, and touchpoints, catering primarily to researchers, fans, and content creators interested in fictional brand lore. The platform's market position is specialized within the media industry, focusing on content curation rather than commercial services. Technically, the website employs standard web technologies including HTML5, CSS, JavaScript, and jQuery, with Google Analytics integrated for visitor tracking. The site demonstrates moderate performance and basic mobile optimization, with a clear navigation structure and consistent branding. However, it lacks advanced SEO and accessibility features, and no CMS or hosting provider information is evident from the content. From a security perspective, the site uses HTTPS and includes no forms collecting sensitive data, which reduces exposure to common web vulnerabilities. Nevertheless, it lacks visible security headers and formal security policies, and no incident response or vulnerability disclosure information is provided. Privacy compliance is weak, with no privacy or cookie policies found, and no GDPR compliance indicators. The absence of contact information further limits trust and business credibility. Overall, the website is functional and content-rich but requires improvements in privacy, security policies, and contact transparency to enhance trustworthiness and compliance. Strategic recommendations include implementing comprehensive privacy and cookie policies, adding security headers, improving mobile and accessibility features, and providing clear contact and incident response information.

20
35
47
40
95
65
20
fictionalbrandsmediaarchivefilmbrandsvideogamebrandsseriesbrands+1 more
HTML5CSSJavaScriptjQuery+1
2025-07-28T00:21:17.092Z
P

PHP for People

phpforpeople.com

45
TechnologyN/asmallHIGH

PHP for People is a small-scale informational website focused on educating visitors about the PHP programming language, emphasizing its origins and ease of use. The site is created by Neatnik and inspired by a similar project, HTML for People. The domain is newly registered in October 2024, consistent with the site's 'coming soon' status, indicating an early-stage project rather than an established business. The website content is minimal but clear in its messaging, targeting developers and web enthusiasts interested in PHP. Technically, the website uses basic HTML and CSS without any detected frameworks or CMS. Hosting and DNS are managed via Porkbun LLC and DNS Kitchen respectively. The site lacks advanced technical features such as DNSSEC, security headers, or analytics tools. Performance and mobile optimization are basic but functional. There is no evidence of tracking, advertising, or user data collection mechanisms. From a security perspective, the site does not present critical vulnerabilities but lacks several best practices including DNSSEC, security headers, and published privacy or cookie policies. No contact or incident response information is provided, limiting transparency and trust. The domain registration is consistent and legitimate, with protective domain status flags in place. Overall, the security posture is basic and could be improved with standard measures. The overall risk is low given the informational nature and minimal data collection, but the lack of privacy and security policies, as well as contact information, reduces trustworthiness. Strategic recommendations include implementing security headers, enabling DNSSEC, publishing privacy and cookie policies, and adding contact and incident response details to enhance compliance and user trust.

15
50
2
60
65
75
40
phpprogrammingwebdevelopmenttechnologyinformational
HTML5CSS
2025-07-28T00:20:56.857Z
appleinsider.com favicon

Quiller Media, Inc.

appleinsider.com

73
MediaUnited StatesmediumMEDIUM

AppleInsider.com is a well-established media website operated by Quiller Media, Inc., focusing on Apple-related news, rumors, reviews, prices, and deals. Founded in 1998, it serves a dedicated audience of Apple enthusiasts and consumers seeking timely and comprehensive information about Apple products and services. The site offers a broad range of content including news articles, product reviews, price guides, deals, forums, podcasts, and videos, positioning itself as a leading source in the Apple media niche. Technically, the website employs modern web technologies including JavaScript, CSS, and HTML5, with integrations of Google Tag Manager, Microsoft Clarity, and header bidding ad technologies such as Prebid.js and Google Ad Manager. Hosting and DNS services are provided via Cloudflare, ensuring fast content delivery and robust infrastructure. The site is mobile-optimized with responsive design and accessibility considerations, delivering a high-quality user experience. From a security perspective, the site enforces HTTPS with a strong SSL configuration and employs domain transfer protection. However, DNSSEC is not enabled, and explicit security policies or incident response contacts are not published. The site uses advertising and tracking technologies but lacks a visible cookie consent mechanism, which may impact privacy compliance. No vulnerabilities or exposed sensitive data were detected in the analysis. Overall, AppleInsider.com demonstrates a high level of professionalism, content quality, and technical maturity. The domain registration data aligns with the business claims, supporting legitimacy. Strategic recommendations include enabling DNSSEC, publishing a dedicated security policy and incident response contact, and implementing a cookie consent mechanism to enhance privacy compliance and user trust.

90
65
2
85
75
80
100
appletechnologynewsreviewsdeals+1 more
JavaScriptCSSHTML5Google Tag Manager+4
2025-07-28T00:18:25.829Z
fabrykajabo.li favicon

Fabryka jaboli

fabrykajabo.li

59
OtherPolandsmallMEDIUM

Fabryka jaboli is a small personal and community-focused website primarily hosting various self-maintained services by an individual named Nomza. The site offers a blog, IRC, federated social instance, and links to member pages, targeting a Polish-speaking general audience interested in niche community services. The business model is informal and self-hosted, with no commercial or enterprise positioning. Technically, the website is built with basic HTML, CSS, and JavaScript without any detected CMS or advanced frameworks. Hosting appears to be provided by Hetzner, inferred from footer text. The site has moderate performance and basic mobile optimization but lacks advanced SEO and accessibility features. From a security perspective, the site lacks critical security headers, privacy policies, cookie consent mechanisms, and contact information for incident response or data protection. No analytics or tracking scripts were detected, indicating minimal user tracking. The domain uses privacy protection for WHOIS data, which is appropriate for a small personal site. No vulnerabilities or suspicious patterns were identified, but security posture is minimal. Overall, the website is safe for general audiences but lacks formal compliance and security best practices. Strategic improvements in privacy, security headers, and contact transparency would enhance trust and compliance.

15
40
17
85
75
85
100
personalcommunityblogfederatedirc+1 more
HTML5CSSJavaScript

Partner Domains:

mandarynki.eu
partner
demae.party
partner
2025-07-27T23:11:36.227Z
fufexan.net favicon

~fufexan.net

fufexan.net

49
OtherN/asmallHIGH

The website fufexan.net is a minimal personal site owned by an individual named Mihai, primarily serving as a small blog or informational page related to the Nix community. It contains very limited content, mainly a greeting and a brief FAQ. The site uses the Zola static site generator and is hosted with Cloudflare DNS services, with HTTPS enabled but lacking advanced security headers or DNSSEC. There are no forms, contact details, or business-related information, indicating it is not a commercial or organizational site. From a security perspective, the site benefits from HTTPS and domain status protections but lacks DNSSEC and security headers, which are recommended for improved security posture. No privacy, cookie, or terms of service policies are present, which limits compliance with GDPR or other privacy regulations. No analytics or advertising technologies are detected, suggesting minimal user tracking. Overall, the site is safe for general audiences with no adult or questionable content. The domain registration is consistent with the site's nature and age, showing no suspicious patterns. The lack of business information and policies limits the site's credibility and compliance but is understandable given its personal nature. Strategic improvements include adding basic privacy and cookie policies, enabling DNSSEC, and implementing security headers to enhance security and trust.

15
50
2
65
75
85
40
personalblognixtechnology
HTML5CSSZola v0.16.1Cloudflare DNS
2025-07-27T22:08:07.663Z
G

ivy is gay!

gayest.dev

64
TechnologyN/asmallMEDIUM

The website gayest.dev is a personal developer portfolio site belonging to an individual named Ivy, who identifies with she/her pronouns. The site showcases several open-source projects primarily related to software development and fediverse services, including custom init systems, CI detection tools, and Lua-based utilities. It also highlights several related fediverse and git hosting services operated or affiliated with the owner. The site targets developers and fediverse users, positioning itself as a niche personal brand within the technology community. The business model is primarily personal branding and project showcasing without commercial transactions evident. Technically, the site is built with straightforward HTML and CSS, with no detected CMS or advanced frameworks. The site is moderately optimized for performance and mobile use but lacks advanced accessibility and SEO features. The technology stack is simple and appropriate for a personal portfolio, with links to related projects and services hosted on various domains. No analytics or advertising technologies are detected, indicating a privacy-conscious approach. From a security perspective, the site uses HTTPS as indicated by the URL, but no security headers were detected in the provided data. The only form present uses the GET method, which is not ideal for protecting user input. There are no privacy, cookie, or terms of service policies, nor any incident response or vulnerability disclosure information. The domain registration uses privacy protection, which is reasonable for a personal site. No suspicious patterns or vulnerabilities were identified, but security posture is basic and could be improved. Overall, the site is safe, with no adult or explicit content, and presents a moderate level of trustworthiness. The lack of formal policies and security best practices limits its compliance and security maturity. Strategic recommendations include adding privacy and cookie policies, improving form security, implementing security headers, and providing vulnerability disclosure and incident response information to enhance trust and compliance.

65
50
2
70
75
85
100
developerportfoliofediverseopensourcepersonal
HTML5CSSLua (project related)Fediverse software (implied)

Partner Domains:

fediring.net
partner
jadetopaz.straw.page
partner

+2 more partners

2025-07-27T22:07:07.399Z
oddbotout.com favicon

Martin Magni

oddbotout.com

45
TechnologyN/asmallHIGH

Odd Bot Out is an indie mobile puzzle game developed and promoted by Martin Magni. The website serves as a promotional platform linking to the iOS and Android app stores and features embedded video content and positive press reviews. The business operates in the technology sector, specifically mobile gaming, targeting casual gamers interested in physics-based puzzles. The site is small-scale and focused on a single product with no indication of a larger corporate structure. Technically, the website is built with basic HTML and CSS, uses Google Fonts, and embeds YouTube videos. It is mobile-optimized and provides a straightforward user experience. However, there is no evidence of advanced frameworks or CMS usage. SEO and accessibility are basic but adequate for the site's scope. From a security perspective, the site lacks visible HTTPS confirmation and security headers, and no privacy or cookie policies are present. The WHOIS data is missing or unavailable, which raises concerns about domain legitimacy and trustworthiness. No contact information or incident response details are provided, limiting transparency and user trust. Overall, the site is functional and content-rich for its purpose but has notable gaps in security, privacy compliance, and domain registration transparency. Strategic improvements in these areas would enhance trust and compliance.

15
35
2
70
62
70
40
mobilegamepuzzleindierobotphysics+3 more
HTML5CSSGoogle Fonts (Ubuntu)YouTube iframe embed
2025-07-27T22:02:59.930Z
mekorama.com favicon

Martin Magni

mekorama.com

48
OtherN/asmallHIGH

Mekorama is an indie mobile puzzle game developed by Martin Magni, offering a unique experience with mechanical dioramas and user-generated content via QR codes. The game is available across multiple platforms including iOS, Android, Nintendo Switch, PlayStation, Xbox, and web browsers, positioning it as a niche but well-regarded title in the indie gaming market. The website provides rich content about the game, including links to app stores, console versions, and social media channels, but lacks formal business contact details and privacy-related policies. Technically, the website uses standard web technologies such as HTML5, CSS, and JavaScript, with Google Adsense for monetization and Google Fonts for typography. The site is mobile-optimized and has good SEO practices but lacks advanced security headers and explicit privacy or cookie policies. No forms are present, reducing attack surface but also limiting user interaction on the site. From a security perspective, the site uses HTTPS, but no additional security headers were detected in the provided data. The absence of privacy and cookie policies indicates potential compliance gaps with GDPR and other privacy regulations. The WHOIS data is unavailable, which reduces trust slightly but is not uncommon for small indie projects. No vulnerabilities or malicious content were detected, and the content is safe for general audiences. Overall, Mekorama's website is professionally presented with good content quality and business credibility for an indie game. However, improvements in privacy compliance, security headers, and WHOIS transparency are recommended to enhance trust and regulatory adherence.

30
35
2
70
62
70
40
mobilegamepuzzleindiegameuser-generatedcontentvr+1 more
HTML5CSSJavaScriptGoogle Adsense+1
2025-07-27T22:02:54.907Z
mattrutherford.co.uk favicon

Matt Rutherford

mattrutherford.co.uk

58
OtherN/asmallMEDIUM

Matt Rutherford operates a personal brand website focused on sharing weekly insights and tips related to career growth, personal development, and clarity in work and life. The site offers a newsletter subscription, blog articles, and various tools and resources aimed at individuals seeking to improve their professional and personal lives. The business model centers on content publishing and coaching services, positioning Matt Rutherford as a thought leader in this niche. The website is professionally designed, well-branded, and consistently updated with relevant content, targeting a general audience interested in self-improvement and career success. Technically, the website is built on the Ghost CMS platform, leveraging modern web technologies including JavaScript, CSS, and HTML5. It integrates third-party services such as Plausible Analytics for privacy-focused tracking and Ghostboard for engagement metrics. The site demonstrates good performance, mobile optimization, and SEO practices, although some security headers are missing. The use of structured data (JSON-LD) enhances search engine understanding and visibility. From a security perspective, the site enforces HTTPS and uses secure forms for newsletter subscription. However, it lacks explicit privacy and cookie policies, security.txt files, and incident response contact information, which are important for compliance and trust. No vulnerabilities or exposed sensitive data were detected in the analyzed content. The WHOIS lookup for the domain failed due to a naming rules error, which is unusual but the site is live and functional, indicating legitimacy despite the lack of WHOIS transparency. Overall, the website presents a low-risk profile with strong content quality and business credibility but would benefit from enhanced privacy compliance and security best practices to improve trust and regulatory adherence.

15
35
17
60
95
60
100
careerpersonaldevelopmentnewsletterblogcoaching
Ghost CMSJavaScriptCSSHTML5+4
2025-07-27T20:57:55.687Z
lmika.org favicon

Leon Mika

lmika.org

55
TechnologyAustraliasmallMEDIUM

The website lmika.org is a personal blog and portfolio site for Leon Mika, a software developer and occasional music writer based in Melbourne, Australia. The site features blog posts, photos, and links to various technology and personal interest sites. It is built using the Hugo static site generator and hosted on the Micro.blog platform, indicating a modern and lightweight technical infrastructure. The site includes JavaScript enhancements such as a service worker and lightbox functionality for images, and uses minimal third-party analytics via tinylytics.app. From a security perspective, the site uses HTTPS and registers a service worker, but lacks advanced security headers and does not have visible privacy or cookie policies, nor contact information for security incidents or data protection officers. The domain is privacy protected via Contact Privacy Inc., which is typical for personal sites, and the domain age aligns with the site's content history. No vulnerabilities or suspicious patterns were detected in the content or technical setup. Overall, the site presents a good level of content quality, technical implementation, and business credibility for a personal blog, but falls short on privacy compliance and security best practices. There is no evidence of adult or unsafe content, and the site is fully accessible without WAF or blocking mechanisms.

15
35
25
70
65
55
100
personalblogsoftwaredevelopmenttechnologymusicphotography+2 more
Hugo 0.117.0JavaScriptCSSHTML5+2
2025-07-27T20:57:40.350Z
heydingus.net favicon

Jarrod Blundy

heydingus.net

51
OtherUnited StatessmallMEDIUM

HeyDingus is a personal blog operated by Jarrod Blundy, focusing on technology, outdoor activities, and curated internet content. The site serves a niche audience of technology enthusiasts and outdoor lovers, offering blog posts, shortcuts, and digital products. The business model is primarily content-driven with monetization through tips, affiliate marketing, and a small store. The website is well-branded, professionally designed, and regularly updated, reflecting a small but engaged community presence. Technically, the website is hosted on Blot.im, leveraging a simple but effective tech stack including HTML5, CSS, JavaScript, and integrations with Micro.blog and Carbon Ads. The site is mobile-optimized and performs well, with fast loading times and good SEO practices. Accessibility is basic but functional. The site uses HTTPS with a strong SSL configuration, though it lacks DNSSEC and some recommended security headers. From a security perspective, the site demonstrates good baseline practices such as HTTPS enforcement and domain transfer/update protections. However, it lacks explicit privacy and cookie policies, security.txt files, and vulnerability disclosure mechanisms, which are important for compliance and transparency. No critical vulnerabilities or exposed sensitive data were detected. The domain registration is consistent with the website content and shows no suspicious patterns. Overall, HeyDingus is a trustworthy, well-maintained personal blog with solid technical foundations but could improve its privacy compliance and security posture by adding formal policies and security headers. The risk level is low, but enhancements in compliance and security best practices are recommended to maintain trust and meet evolving standards.

30
35
17
70
62
70
40
blogtechnologypersonaloutdoorsshortcuts+3 more
HTML5CSSJavaScriptBlot.im hosting+2
2025-07-27T20:57:14.842Z
F

fabiensauser.ch

fabiensauser.ch

71
OtherSwitzerlandsmallMEDIUM

The website fabiensauser.ch is a personal blog primarily in French, focusing on literature, technology, and personal reflections. It is built using the Hugo static site generator and contains a series of well-written blog posts with clear navigation and moderate mobile optimization. The site targets general internet users interested in thoughtful content rather than commercial services. There is no evidence of monetization or business operations beyond content publishing. Technically, the site uses a simple tech stack with Hugo and CSS, lacks advanced frameworks or analytics, and shows basic SEO and accessibility features. No forms or tracking scripts are present, indicating minimal data collection. However, there is no visible HTTPS/SSL confirmation or security headers, which reduces the security posture. Privacy and cookie policies are absent, limiting compliance with GDPR and related regulations. Security-wise, the site does not expose sensitive data or show signs of vulnerabilities but lacks formal security policies or incident response contacts. The domain uses privacy protection in WHOIS, typical for personal blogs, with no suspicious patterns detected. Overall, the site is safe and trustworthy for general audiences but could improve in security and privacy compliance. The overall risk is low given the non-commercial nature and limited data collection, but strategic improvements in HTTPS implementation, security headers, and privacy disclosures are recommended to enhance trust and compliance.

90
50
17
70
95
85
100
Hugo 0.127.0CSS
2025-07-27T20:56:59.779Z
corygibbons.com favicon

Cory Gibbons

corygibbons.com

59
TechnologyN/asmallMEDIUM

Cory Gibbons is an individual freelance developer and designer focused on creating fast, scalable, and enjoyable digital experiences. The website serves as a personal portfolio and contact point for limited freelance opportunities. The business model is straightforward, targeting clients seeking development and design services. The market position is that of a small-scale independent professional without broader corporate affiliations. Technically, the website is built using modern JavaScript frameworks, specifically React with React Router, and is hosted on Vercel, ensuring fast performance and good mobile optimization. The site uses module preloading and modern ES modules, indicating a contemporary tech stack. However, accessibility and SEO optimizations are basic, and no CMS or analytics tools are detected. From a security perspective, the site benefits from HTTPS and domain registrar protections but lacks DNSSEC and security headers, which are recommended for enhanced security. There are no privacy or cookie policies, which limits compliance with GDPR and related regulations. No incident response or vulnerability disclosure mechanisms are present, which could be improved to enhance trust and security posture. Overall, the website is professional and functional for its purpose but could benefit from improved privacy compliance and security best practices to increase trustworthiness and reduce risk.

30
50
2
50
72
90
100
portfoliofreelancedeveloperdesignertechnology
React RouterJavaScript ES ModulesCSSVercel DNS
2025-07-27T20:56:09.106Z
werd.io favicon

Ben Werdmuller

werd.io

57
MediaUnited StatessmallMEDIUM

Werd I/O is an independent media and blogging platform authored by Ben Werdmuller, focusing on topics at the intersection of technology, media, and democracy. The website operates on a reader-supported subscription model, providing thoughtful essays and articles to a general audience interested in societal and technological issues. The market position is niche but credible, with a small but engaged audience. The business is small-sized, US-based, and founded in 2013, reflecting a mature presence in independent digital media. Technically, the site is built on the Ghost CMS platform, leveraging modern web technologies including JavaScript, CSS, and Cloudflare DNS services. The site demonstrates good performance, mobile optimization, and SEO practices. However, accessibility is basic and could be improved. The technical infrastructure is modern and well-maintained, supporting a smooth user experience. From a security perspective, the site enforces HTTPS and uses clientTransferProhibited status on the domain, indicating domain transfer protection. However, DNSSEC is not enabled, and no security headers are detected, which are areas for improvement. There is no visible privacy or cookie policy, nor incident response or vulnerability disclosure information, which impacts compliance and trust. No critical vulnerabilities or exposed sensitive data were found. Overall, the website is trustworthy and professional but would benefit from enhanced privacy compliance and security best practices. Strategic recommendations include enabling DNSSEC, publishing privacy and cookie policies, adding security headers, and providing incident response contacts to improve user trust and regulatory compliance.

15
53
17
35
75
80
100
technologymediademocracyblogindependent+1 more
JavaScriptCSSGhost CMSCloudflare DNS
2025-07-27T20:56:03.830Z
P

Private by Design, LLC

skyhold.org

54
OtherUnited StatessmallMEDIUM

Skyhold.org is a personal website operated by C Jackdaw, a writer and witch, serving as a platform for creative expression, personal blogging, and resource sharing. The site targets a niche audience interested in writing, witchcraft, solarpunk, ADHD, and related topics. It is a small-scale, non-commercial site with regular content updates and a modest but consistent brand presence. The business entity behind the domain is Private by Design, LLC, a US-based organization, which aligns with the website's personal and creative nature. Technically, the site is hand-coded with standard HTML, CSS, and JavaScript, leveraging modern IndieWeb protocols such as IndieAuth and Webmention. Analytics are implemented via privacy-conscious services like GoatCounter and Tinylytics, reflecting a minimal user tracking approach. The site demonstrates good mobile optimization and basic accessibility but lacks advanced SEO and security headers. Hosting details are not explicit, but DNS indicates use of messagingengine.com name servers, possibly related to email hosting. From a security perspective, the site uses HTTPS and has domain status protections against unauthorized transfer or deletion. However, it lacks DNSSEC and common security headers, which are recommended to enhance security posture. No privacy or cookie policies are present, indicating compliance gaps. No forms or input fields are present, reducing attack surface but also limiting user interaction. Overall, the security posture is moderate but could be improved with standard best practices. The overall risk is low given the personal nature and limited business impact of the site. Strategic recommendations include enabling DNSSEC, adding security headers, publishing privacy and cookie policies, and considering a security.txt file for vulnerability disclosure. These steps would improve trust, compliance, and security without significant overhead.

15
50
2
55
72
65
100
personalblogcreativewitchcraftwriting+3 more
HTML5CSSJavaScriptGoatCounter analytics+4
2025-07-27T20:55:11.976Z
pcora.eu favicon

Pedro Corá

pcora.eu

41
TechnologyNetherlandssmallHIGH

The website pcora.eu serves as a personal professional profile for Pedro Corá, an IT Analyst based in the Netherlands. It primarily functions as a hub linking to various personal blogs, photoblogs, and social media profiles, emphasizing personal branding rather than commercial business operations. The site content is straightforward, professional, and targeted at a general audience interested in Pedro's IT expertise and personal content. Technically, the website uses standard HTML5 and CSS with FontAwesome icons and Open Graph metadata for social sharing. It is hosted on or uses services from omg.lol and cache.lol domains, indicating a lightweight, possibly static or semi-static site architecture. The site is moderately optimized for mobile and accessibility but lacks advanced SEO and security headers. From a security perspective, the site uses HTTPS, but no additional security headers were detected. There are no forms collecting sensitive data, reducing attack surface. However, the absence of privacy and cookie policies, security.txt, or vulnerability disclosure mechanisms indicates limited formal security and compliance posture. No WAF or blocking mechanisms were detected, and the site is fully accessible. Overall, the site is low risk with a moderate trust level, suitable for personal branding. Strategic improvements include adding privacy and cookie policies, implementing security headers, and enhancing SEO and accessibility to improve professionalism and compliance.

65
25
2
55
-
65
40
personalprofileitanalystblogphotoblogsocialmedia
HTML5CSSFontAwesome iconsOpen Graph meta tags
2025-07-27T20:54:46.621Z
bitwarden.com favicon

Bitwarden, Inc.

bitwarden.com

85
TechnologyUnited StatesenterpriseLOW

Bitwarden, Inc. operates a leading open source password management platform trusted by millions globally, serving individuals, families, businesses, and enterprises. Their product suite includes password management, secrets management, passwordless authentication, and developer tools, positioning them strongly in the cybersecurity technology market. The company emphasizes transparency, security, and compliance, supported by certifications such as SOC 2 and ISO 27001. Their business model is primarily SaaS with free and paid tiers, including self-hosting options for enterprises. Technically, Bitwarden employs a modern React-based web platform, leveraging Cloudflare for hosting and CDN services, and integrates analytics tools like Google Tag Manager and Plausible Analytics. The website demonstrates excellent performance, mobile optimization, accessibility, and SEO practices, reflecting a mature digital infrastructure. Security posture is robust, with enforced HTTPS, comprehensive security headers, a bug bounty program, and regular compliance audits. However, DNSSEC is not enabled, and a security.txt file is absent, representing areas for improvement. Privacy compliance is strong, with clear privacy and cookie policies and GDPR adherence. Contact information is available primarily via contact forms, with no explicit phone numbers or emails disclosed. Overall, Bitwarden presents a high-trust, professional, and secure online presence with minimal risk. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, and enhancing incident response transparency to further strengthen their security and compliance posture.

95
80
75
82
72
85
100
passwordmanagersecurityopensourceenterprisecompliance+1 more
ReactJavaScriptCSSGoogle Tag Manager+2
2025-07-27T20:53:00.717Z
lipukule.org favicon

Private by Design, LLC

lipukule.org

58
OtherUnited StatessmallMEDIUM

Lipukule.org is a niche cultural and linguistic website dedicated to the toki pona language and related content. It provides articles and posts that explore various themes in toki pona, targeting enthusiasts and learners of this constructed language. The website operates under the ownership of Private by Design, LLC, a US-based entity, with domain registration consistent with the site's scale and focus. The business model centers on content publication and community engagement via Discord and Telegram channels, without evident commercial transactions or e-commerce features. Technically, the website is built using the modern SvelteKit framework with JavaScript and CSS, delivering a good user experience with responsive design and clear navigation. Performance is moderate, and accessibility is basic but functional. No major technical debt or outdated technologies were detected. However, the site lacks advanced SEO optimization and accessibility features. From a security perspective, the site uses HTTPS but lacks security headers and published security policies. No privacy or cookie policies are present, and no contact information is provided, which limits compliance with GDPR and other privacy regulations. No vulnerability disclosure or incident response information is available. The domain registration is transparent and consistent with the website's purpose, supporting legitimacy. Overall, the website is safe, with no adult or explicit content detected. The content quality and business credibility are good, but privacy compliance and security posture need improvement. Strategic recommendations include implementing privacy and cookie policies, adding security headers, publishing a vulnerability disclosure policy, and enhancing accessibility and SEO.

30
50
2
70
72
75
100
tokiponalanguageculturelipukulecommunity
SvelteKitJavaScriptCSS
2025-07-27T19:50:11.360Z
L

LIPUmanka

lipamanka.gay

56
OtherIcelandsmallMEDIUM

The website 'lipamanka.gay' is a personal site primarily focused on sharing essays, stories, and linguistic resources related to the creator's interests. It is a small-scale, niche site without commercial intent or business contact information. The site is hosted likely on GitHub Pages with domain registration through NameCheap, protected by privacy services. The technical infrastructure is basic, relying on standard HTML, CSS, and JavaScript, with minimal external dependencies. Analytics are implemented via GoatCounter, providing lightweight user tracking without aggressive data collection. From a security perspective, the site uses HTTPS and has domain transfer protection enabled, but lacks DNSSEC and security headers, which could be improved to enhance security posture. There are no privacy or cookie policies, nor terms of service, which limits compliance with GDPR and other privacy regulations. No contact or incident response information is provided, reducing transparency and trustworthiness from a security standpoint. Overall, the site is safe for general audiences, containing no adult or explicit content. The domain registration is recent and privacy protected, appropriate for a personal website. The lack of business information and policies limits the site's credibility and compliance maturity. Strategic improvements in security headers, privacy disclosures, and contact transparency would enhance trust and compliance.

15
40
2
70
95
70
100
personallinguisticsessaysstoriestokipona
HTML5CSSJavaScript
2025-07-27T19:49:51.004Z
unseen.ninja favicon

Private by Design, LLC

unseen.ninja

57
TechnologyUnited StatessmallMEDIUM

The website unseen.ninja is a personal portfolio site representing an individual or small entity focused on design and coding services. The site presents a modern, clean design with SVG-based branding and uses Vue.js framework for frontend interactivity. The content is minimal but relevant, targeting a general audience interested in design and code. The domain is newly registered in early 2024, consistent with the site's apparent purpose as a personal portfolio. Technically, the site employs modern web technologies including ES modules, web fonts, and SVG graphics. It is hosted under a reputable registrar Porkbun LLC, though the hosting provider is not explicitly identified. The site is mobile optimized and has basic accessibility features. SEO is basic but includes proper meta tags and Open Graph data. From a security perspective, the site uses HTTPS but lacks DNSSEC and visible security headers, which are recommended for enhanced security. No forms or data collection mechanisms are present, reducing attack surface but also limiting user interaction. No privacy or cookie policies are provided, which is a compliance gap. The WHOIS data is consistent and transparent, with no privacy protection, appropriate for this type of site. Overall, the site is low risk with moderate trustworthiness but would benefit from improved security headers, privacy compliance, and contact transparency to enhance credibility and user trust.

15
50
2
65
72
85
100
personalportfoliodesigncodetechnologyvuejs+1 more
JavaScript ES ModulesSVG graphicsCSSWeb fonts (woff2)
2025-07-27T19:45:57.757Z