Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 123 of 166|Showing 6101-6150 of 8294
T

TCS Velocorner

velocorner.ch

75
RetailSwitzerlandmediumMEDIUM

Velocorner.ch is a leading Swiss online marketplace specializing in bicycles, e-bikes, and related accessories. It operates under the reputable Touring Club Schweiz (TCS) brand, offering a trusted platform for both private sellers and dealers. The website provides a comprehensive catalog of over 37,000 bikes and accessories, supported by personal customer service via chat, email, and phone. Its market position as the #1 bike marketplace in Switzerland is reinforced by buyer and seller protection mechanisms and secure transaction processes. Technically, the website is built on modern web technologies including Next.js and React, ensuring fast performance and excellent mobile optimization. It integrates popular analytics and marketing tools such as Google Analytics, Google Tag Manager, and Facebook Pixel, while maintaining GDPR compliance through clear privacy and cookie policies. The site employs HTTPS with strong security headers, reflecting a mature security posture. Security-wise, Velocorner demonstrates good practices with no detected vulnerabilities or exposed sensitive data. However, it lacks a dedicated security policy or incident response page, which could enhance transparency and preparedness. The WHOIS data confirms the legitimacy of the domain, with consistent registrant information matching the business claims. Overall, Velocorner.ch presents a professional, secure, and user-friendly platform with strong business credibility. Strategic improvements could include publishing explicit security policies and incident response contacts to further strengthen trust and compliance.

95
68
17
75
75
80
100
bicyclee-bikemarketplaceswitzerlandretail+2 more
Next.jsReactApollo GraphQLChatra live chat+3

Partner Domains:

tcs.ch
partner
2025-07-05T20:17:12.710Z
C

City and County of San Francisco

sf.gov

57
GovernmentUnited StateslargeMEDIUM

The City and County of San Francisco operates SF.gov as its official government portal, providing residents, businesses, and visitors with access to a wide range of public services and information. The website features comprehensive content including services like job search, marriage licensing, birth certificate requests, and contact information for city staff. It also prominently displays profiles of elected officials, reinforcing its authoritative position as a government resource. The site targets a broad audience including local citizens, government employees, and businesses operating within San Francisco. Technically, SF.gov is built on modern web technologies including React and Next.js, with a CMS likely based on Wagtail. The site demonstrates excellent mobile optimization, accessibility, and SEO practices. It integrates Google Tag Manager and Google Analytics for user tracking and performance monitoring. The website is served over HTTPS with strong security headers, indicating a robust security posture. However, it lacks a visible cookie consent mechanism and explicit security or incident response policies, which are areas for improvement. From a security perspective, the site follows best practices such as enforcing HTTPS, implementing security headers, and avoiding exposure of sensitive data. No vulnerabilities or suspicious domains were detected. The WHOIS data is limited, showing no registrar or creation date, but this is typical for government domains using privacy protection. The domain's legitimacy is supported by consistent branding and official content. Overall, SF.gov presents a secure, professional, and trustworthy online presence for the San Francisco government. Strategically, the site should enhance privacy compliance by implementing a cookie consent banner and publishing clear security policies and incident response contacts. Adding a vulnerability disclosure or security.txt file would further improve transparency and trust. Regular audits of third-party scripts and tracking tools are recommended to maintain security and privacy standards. These steps will strengthen the site's compliance posture and user trust while maintaining its role as a critical public service platform.

20
53
17
85
67
30
100
governmentpublicservicescityportalsanfranciscoofficial+1 more
ReactNext.jsGoogle Tag ManagerGoogle Analytics

Partner Domains:

careers.sf.gov
partner
www.sfbos.org
partner

+1 more partners

2025-07-05T19:05:13.276Z
dy.dev favicon

Dynamic Yield

dy.dev

63
TechnologyN/aenterpriseMEDIUM

Dynamic Yield operates as an enterprise-grade technology company specializing in digital experience optimization through its Experience OS platform. The company targets developers and enterprise clients seeking to personalize digital interactions across multiple channels using API-first, cloud-native solutions. The website analyzed serves as a developer documentation portal, providing comprehensive guides and API references to facilitate integration and usage of their platform. The company holds MACH Alliance certification, underscoring its commitment to modern, modular, and API-driven architectures. Technically, the website is built on modern frameworks such as React and is hosted on the ReadMe.io platform, ensuring fast performance and good mobile optimization. The site employs HTTPS with excellent SSL configuration and shows no signs of exposed sensitive data or vulnerable libraries. However, some security best practices such as explicit security headers and visible cookie consent mechanisms are missing. Privacy policies and security information are referenced on the main corporate site but are not directly linked on this developer subdomain. From a security perspective, the site demonstrates a mature posture with enterprise-grade security claims and no detected vulnerabilities or blocking mechanisms. The absence of incident response contacts and vulnerability disclosure policies suggests areas for improvement. Overall, the site is trustworthy, professional, and well-aligned with the company's business model and market positioning. Strategically, the company should enhance transparency by adding direct links to privacy and terms of service pages, implement cookie consent mechanisms to comply with GDPR, and publish clear vulnerability disclosure and incident response information to strengthen trust and compliance.

65
50
2
70
52
85
100
developerdocumentationapipersonalizationexperienceoptimizationmachalliance+1 more
ReactReadMe.io platformJavaScriptCSS
2025-07-05T19:03:52.904Z
mattel.com favicon

Mattel

mattel.com

70
RetailN/aenterpriseMEDIUM

Mattel is a globally recognized enterprise specializing in the manufacturing and retail of toys and entertainment products, including iconic brands such as Barbie, Hot Wheels, and Fisher Price. The website analyzed is the corporate 'About' page, providing an overview of the company's mission to empower childhood wonder and potential. The site targets parents, children, and toy consumers, positioning Mattel as a leader in the retail toy industry. The business model focuses on product manufacturing, brand licensing, and entertainment content creation. Technically, the website employs modern web technologies including React and Next.js frameworks, with content management facilitated by Builder.io and e-commerce elements linked to Shopify. The site demonstrates good mobile optimization, accessibility, and SEO practices, although some performance optimizations could be enhanced. Google Tag Manager and UsableNet are used for analytics and accessibility enhancements respectively. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data in the HTML content. However, no explicit security headers were detected in the provided content, and no privacy or cookie policies were found, indicating areas for compliance improvement. No forms or direct contact information were identified, limiting data collection risks but also reducing transparency. Overall, the website reflects a professional and trustworthy corporate presence consistent with Mattel's brand reputation. The absence of WHOIS data for the subdomain is typical and does not detract from legitimacy. Strategic recommendations include implementing comprehensive privacy and cookie policies, adding security headers, and publishing a vulnerability disclosure policy to enhance security posture and regulatory compliance.

30
85
17
80
75
90
100
matteltoysbarbiehotwheelsfisherprice+2 more
ReactNext.jsGoogle Tag ManagerUsableNet
2025-07-05T17:55:06.096Z
tirebuyer.com favicon

Tirebuyer

tirebuyer.com

65
RetailUnited StateslargeMEDIUM

Tirebuyer operates as a large-scale e-commerce platform specializing in the sale of tires and wheels, targeting vehicle owners seeking convenient online shopping solutions. The company boasts a vast network of over 18,000 installers, positioning itself as a leading retailer in the automotive aftermarket sector. Their business model focuses on providing a wide selection of tire brands and wheels, coupled with financing options and local installer delivery services, enhancing customer convenience and market reach. Technically, the website leverages modern web technologies including React and Next.js frameworks, supported by robust CDN services from Akamai. The site demonstrates excellent performance, mobile responsiveness, and SEO optimization, reflecting a mature digital infrastructure. Integration of analytics and marketing tools such as Google Tag Manager, Microsoft Clarity, and Listrak indicates a data-driven approach to user engagement and marketing. From a security perspective, the site enforces HTTPS with strong SSL configurations and employs security headers like Content-Security-Policy and X-Frame-Options, indicating adherence to best practices. However, the absence of a publicly available security policy, vulnerability disclosure, or incident response contact points to areas for improvement in transparency and security communication. Overall, Tirebuyer presents a professional and trustworthy online presence with strong business credibility and technical maturity. The lack of WHOIS data is a notable anomaly but does not detract significantly from the site's legitimacy based on content and operational indicators. Strategic enhancements in security policy disclosure and incident response readiness would further strengthen their security posture and customer trust.

50
58
2
85
67
80
100
e-commercetireswheelsautomotiveretail+1 more
ReactNext.jsGoogle Tag ManagerListrak+1
2025-07-05T16:52:56.215Z
cosmicjs.com favicon

Cosmic

cosmicjs.com

62
TechnologyN/amediumMEDIUM

Cosmic is a technology company specializing in a headless, API-first content management platform designed to empower developers and content teams to build and manage content-rich applications efficiently. Positioned as a leading SaaS provider in the headless CMS market, Cosmic offers a robust set of developer tools, AI-assisted content generation, and seamless integrations with popular frameworks. The website demonstrates a high level of professionalism, excellent design quality, and clear navigation, targeting developers and businesses seeking flexible content management solutions. Technically, the site leverages modern web technologies including React and Next.js, hosted on Vercel, ensuring fast performance and mobile optimization. The presence of Vercel Analytics indicates minimal user tracking with a focus on privacy compliance. Security best practices such as HTTPS enforcement and security headers are implemented, though the absence of a dedicated security policy and incident response information suggests room for improvement in transparency. The security posture is strong with no detected vulnerabilities or exposed sensitive data. However, the lack of WHOIS data for the domain cosmicjs.com raises concerns about domain registration legitimacy, which slightly impacts the overall trust score. Privacy and cookie policies are present and comprehensive, indicating good compliance with GDPR and related regulations. Overall, Cosmic presents a trustworthy and technically mature platform with a strong market position. Strategic recommendations include publishing detailed security and incident response policies, improving domain registration transparency, and enhancing business credibility through explicit contact information and certifications.

30
68
10
65
62
80
100
headlesscmsapi-firstcontentmanagementdevelopertoolssaas+2 more
ReactNext.jsJavaScriptGoogle Fonts+1
2025-07-05T16:47:34.044Z
allstate.com favicon

The Allstate Corporation

allstate.com

52
FinanceUnited StatesenterpriseMEDIUM

The Allstate Corporation operates a comprehensive insurance website offering a wide range of insurance products including auto, home, renters, life, business, and identity protection. The company is a well-established player in the insurance industry with a history dating back to 1931 and a strong market presence in the United States. The website serves consumers directly and through agents, providing online quotes, claims filing, and extensive resources. The site is professionally designed with clear navigation and mobile optimization, reflecting a mature digital presence. Technically, the website leverages modern web technologies such as React, service workers, and is hosted on Akamai's CDN infrastructure. It integrates Adobe Launch for marketing and analytics, and uses multiple tracking and performance monitoring tools. The site is fast, accessible, and SEO optimized, with robust privacy and cookie policies that comply with GDPR standards. Security best practices are observed with HTTPS enforcement and security headers, though explicit security policy and incident response information are not publicly detailed. The security posture is strong with no visible vulnerabilities or exposed sensitive data. However, the absence of a public vulnerability disclosure or security.txt file and incident response contacts suggests room for improvement in transparency. The WHOIS data for the domain is unavailable, which limits domain registration trust analysis, but the website content and branding strongly indicate legitimacy. Overall, the website is a high-quality, secure, and trustworthy platform for insurance services. Strategic recommendations include publishing explicit security policies, incident response contacts, and vulnerability disclosure information to enhance trust and compliance further.

-
58
17
75
-
80
100
insuranceautoinsurancehomeinsurancelifeinsurancebusinessinsurance+6 more
ReactJavaScriptService WorkersAdobe Launch+3

Partner Domains:

allstateidentityprotection.com
subsidiary
answerfinancial.com
partner

+3 more partners

2025-07-05T15:37:55.951Z
cpr.org favicon

Colorado Public Radio

cpr.org

67
MediaUnited StatesmediumMEDIUM

Colorado Public Radio (CPR) is a well-established non-profit media organization providing news, classical music, indie music, and local radio programming primarily serving the Colorado region. The website demonstrates a strong market position as a trusted source for Colorado news and culture, offering multiple content streams including live radio, podcasts, and newsletters. CPR targets residents and listeners interested in regional news and cultural content, operating under a non-profit business model with a focus on public service broadcasting. Technically, the website is built using modern web technologies including React and Next.js, with integrations for various analytics and advertising platforms such as Google Analytics, Facebook Pixel, Chartbeat, and Pardot. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. The presence of cookie consent mechanisms and a comprehensive privacy policy indicates good privacy compliance. From a security perspective, CPR employs HTTPS with strong SSL configuration and multiple security headers, demonstrating adherence to best practices. However, there is no explicit security policy or incident response information publicly available, and WHOIS data is unavailable due to privacy protection, which is justified for this type of organization. No vulnerabilities or suspicious patterns were detected in the content or technical setup. Overall, CPR's website is professional, trustworthy, and well-maintained, with a high level of content quality and user experience. The main risks relate to the lack of publicly available security policies and incident response contacts, which could be improved to enhance transparency and trust. Strategic recommendations include publishing security policies, incident response contacts, and vulnerability disclosure information to strengthen security posture and stakeholder confidence.

50
58
17
80
65
80
100
newssportsisraelpalestinemilitary
ReactNext.jsTypekit FontsGoogle Tag Manager+6

Partner Domains:

donate.cpr.org
service
shop.cpr.org
service

+1 more partners

2025-07-05T12:12:40.939Z
stripchats.pro favicon

Privacy service provided by Withheld for Privacy ehf

stripchats.pro

62
MediaIcelandlargeMEDIUM

Stripchats.pro is an adult live webcam streaming platform launched in late 2023, offering free access to thousands of live adult webcam models and couples. The site targets an adult audience exclusively, with clear age verification and compliance badges such as RTA and ASACP. It supports interactive toys, private shows, and ticketed events, providing a comprehensive adult entertainment experience. The platform also facilitates model and studio registrations through partner domains, indicating a robust business model focused on live adult content and community engagement. Technically, the website leverages modern web technologies including React, Redux, Bootstrap, and integrates analytics and error tracking services like Amplitude and Sentry. Hosting and DNS services are managed via Cloudflare, ensuring good performance and security. Security posture is adequate with HTTPS enforced and client transfer protection on the domain, but could be improved by enabling DNSSEC and adding more security headers. Privacy compliance is well addressed with clear privacy and cookie policies, including consent mechanisms and GDPR indicators. Contact information is limited to a press email, with no dedicated security or incident response contacts published. Overall, the site presents a professional and functional adult entertainment platform with moderate security and privacy maturity.

30
73
17
65
52
80
100
adultlivewebcamadultentertainmentinteractivetoyscammodels+3 more
ReactReduxBootstrapCloudflare DNS+3

Partner Domains:

go.godkc.com
partner
stripcash.com
partner
2025-07-04T17:51:06.877Z
stripchat.ooo favicon

Digital Privacy Corporation

stripchat.ooo

61
MediaUnited StateslargeMEDIUM

Stripchat.ooo is an adult live webcam streaming platform operated by Digital Privacy Corporation, based in the US. The website offers free access to thousands of live adult webcam models and couples, with additional paid private shows and interactive toy integrations. It targets an adults-only audience and complies with US legal requirements for adult content. The platform is positioned as a large player in the adult live streaming market with a broad international model base and multiple language support. Technically, the site uses modern web technologies including React, Redux, Bootstrap, and integrates analytics and error tracking services such as Amplitude and Sentry. The hosting and DNS services are provided by Cloudflare, ensuring good performance and security. Security posture is strong with HTTPS enforced, content security policies, and domain transfer restrictions, though DNSSEC is not enabled. Privacy compliance is supported by a comprehensive privacy policy and cookie consent mechanism. However, incident response and vulnerability disclosure information are not explicitly provided. Overall, the site is professionally designed, mobile-optimized, and offers a good user experience with clear navigation and extensive content. The domain registration details align well with the business profile, indicating legitimacy and trustworthiness.

30
73
17
40
75
70
100
adultlivewebcamadultentertainmentstreamingcamgirls+2 more
ReactReduxBootstrapCloudflare DNS+3

Partner Domains:

go.godkc.com
partner
stripcash.com
partner
2025-07-04T17:50:06.660Z