Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 13 of 241|Showing 601-650 of 12038
pomurski-muzej.si favicon

Pomurski muzej Murska Sobota

pomurski-muzej.si

44
OtherSloveniasmallHIGH

Pomurski muzej Murska Sobota is a regional museum dedicated to preserving and showcasing the cultural heritage of the Pomurje region in Slovenia. The website provides comprehensive information about exhibitions, events, educational programs, and digital collections, targeting a broad audience including families, schools, and cultural enthusiasts. The museum positions itself as a key cultural institution in the region with a focus on both physical and digital heritage preservation. Technically, the website is built on the WBCE CMS platform with modern web technologies such as Bootstrap, jQuery, and Revolution Slider. It is hosted under a reputable Slovenian registrar (Arnes) and uses HTTPS with a valid SSL configuration. The site is mobile-optimized and includes basic accessibility features. Google Analytics is used for visitor tracking, and a cookie consent banner with opt-in is implemented, indicating good privacy compliance. From a security perspective, the site enforces HTTPS and uses cookie consent mechanisms but lacks advanced security headers and does not publish explicit security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the HTML content. The WHOIS data aligns well with the website's claims, supporting legitimacy. Overall, the website is professional, trustworthy, and serves its cultural mission effectively. Strategic improvements in security headers, incident response transparency, and accessibility could enhance its security posture and compliance further.

20
43
17
60
62
65
-
museumculturalheritageeducationsloveniapomurje+2 more
jQueryBootstrapFont AwesomeRevolution Slider+3

Partner Domains:

visitmurskasobota.si
partner
www.prekmurjevsrcu.si
partner

+1 more partners

2025-11-01T04:02:17.004Z
poukz.hr favicon

Pučko otvoreno učilište Katarina Zrinska – Ozalj

poukz.hr

54
EducationCroatiasmallMEDIUM

Pučko otvoreno učilište Katarina Zrinska – Ozalj is a small educational institution based in Croatia, founded in 2022. The organization offers a variety of educational and creative programs targeting children, youth, retirees, and adults, focusing on lifelong learning and community engagement. The website reflects a local community-oriented business model with clear contact information and social media presence, positioning itself as a trusted local educational provider. Technically, the website employs modern front-end technologies including Bootstrap, jQuery, and various JavaScript libraries to provide a responsive and visually appealing user experience. While the site is mobile-optimized and well-structured, there is room for improvement in accessibility and SEO optimization. Hosting and domain registration are consistent with the business location, enhancing trustworthiness. From a security perspective, the website implements a cookie consent mechanism compliant with GDPR, but lacks visible advanced security headers and incident response information. No critical vulnerabilities or exposed sensitive data were detected in the provided content. The absence of terms of service and security policies suggests an opportunity to strengthen compliance and user trust. Overall, the website is functional, professional, and safe for general audiences. The risk level is low, but strategic improvements in security posture and privacy transparency would enhance the institution's digital maturity and trustworthiness.

15
40
2
60
62
75
100
educationcommunityworkshopscroatiapoukz+1 more
HTML5CSS3JavaScriptBootstrap+7
2025-11-01T04:01:11.504Z
azelija-eko.hr favicon

Azelija Eko d.o.o.

azelija-eko.hr

47
GovernmentCroatiasmallHIGH

Azelija Eko d.o.o. is a Croatian municipal service company specializing in waste management, recycling, cemetery services, public lighting maintenance, and chimney sweeping within the Ozalj region and surrounding municipalities. The company operates fixed and mobile recycling yards and provides essential environmental services to local residents and businesses. The website reflects a local government service provider with clear contact information and service descriptions, targeting the regional community. Technically, the website is built on Joomla CMS with a Bootstrap framework and uses common JavaScript libraries such as jQuery and Font Awesome for UI elements. The site includes image sliders and responsive design elements, indicating moderate digital maturity. Hosting is provided by CARNET, a reputable Croatian academic network, which aligns with the local focus. From a security perspective, the site lacks visible security headers and explicit HTTPS enforcement in the provided data, which lowers its security posture. No privacy or cookie policies were found, indicating potential GDPR compliance gaps. The site does not use tracking or advertising technologies, which reduces privacy risks but also limits marketing insights. Overall, the website is functional and professional for its purpose but would benefit from enhanced security measures, privacy compliance improvements, and clearer policies to strengthen trust and regulatory adherence.

20
10
2
85
85
85
20
municipalwastemanagementrecyclingenvironmentcroatia+2 more
jQueryBootstrapFont AwesomeJoomla CMS+3
2025-11-01T04:00:51.396Z
czp.hr favicon

Centar za poduzetništvo d.o.o.

czp.hr

43
GovernmentCroatiasmallHIGH

Centar za poduzetništvo d.o.o. is a regional entrepreneurial support center serving the Dubrovnik-Neretva County in Croatia. The organization focuses on providing a range of services including education, business consulting, credit programs, and assistance with EU funding projects. Their website reflects a government-affiliated entity aimed at fostering entrepreneurship and small business growth in the region. The target audience primarily consists of local entrepreneurs and small business owners seeking support and resources. Technically, the website employs a modern technology stack featuring jQuery, Bootstrap, FontAwesome, and various plugins for enhanced user experience and accessibility. The site is mobile-optimized, uses HTTPS with strong SSL configuration, and integrates Google Analytics and UserWay accessibility tools, indicating a mature digital infrastructure. The website content is well-structured, professionally designed, and includes clear navigation and relevant business information. From a security perspective, the site enforces HTTPS and obfuscates email addresses to reduce spam. However, it lacks explicit security policies and incident response contact details. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with GDPR-aligned privacy and cookie policies and a consent mechanism in place. The website demonstrates a good security posture but could improve by adding formal security documentation and security headers. Overall, the website is trustworthy, professional, and serves its business purpose effectively. The domain registration data aligns with the website's claims, reinforcing legitimacy. Strategic recommendations include enhancing security transparency, publishing incident response information, and maintaining regular security audits to sustain trust and compliance.

20
10
17
70
62
80
-
entrepreneurshipeducationgovernmentbusinesssupporteuprojects+1 more
jQueryBootstrapFontAwesomeOwl Carousel+3
2025-11-01T04:00:20.755Z
likaceste.hr favicon

Lika ceste d.o.o.

likaceste.hr

45
TransportationCroatiamediumHIGH

Lika ceste d.o.o. is a Croatian company specializing in the maintenance, protection, reconstruction, and construction of roads and related infrastructure, primarily serving the Gospić region. The company positions itself as a regional service provider focused on public roadways, offering key services such as road maintenance and winter services. The website reflects a medium-sized enterprise with a clear focus on transportation infrastructure, targeting local government entities and public road users. Technically, the website is built on WordPress using Bootstrap for responsive design, enhanced with several JavaScript libraries including jQuery, Owl Carousel, and Google Maps API. SEO is supported by the Yoast SEO plugin, and user interaction is facilitated through Contact Form 7 with Google reCAPTCHA v3 for spam protection. The site demonstrates moderate performance and good mobile optimization, though accessibility features are basic. From a security perspective, the site uses HTTPS and includes a cookie consent mechanism compliant with GDPR. However, it lacks explicit security headers and published security policies or incident response information. No vulnerability disclosure or security.txt files are present, indicating room for improvement in transparency and security maturity. Overall, the website is professional and trustworthy with moderate tracking and analytics usage. It is safe for general audiences and does not contain adult or questionable content. The domain registration data aligns well with the business identity, supporting legitimacy. Strategic improvements in security headers, incident response policies, and accessibility would enhance the site's security posture and compliance.

35
25
2
85
62
75
-
transportationroadmaintenancecroatiawordpressbootstrap+3 more
jQueryBootstrapGoogle Maps APIGoogle Analytics+6
2025-11-01T03:50:39.628Z
zzpudnz.hr favicon

Zavod za prostorno uređenje Dubrovačko-neretvanske županije

zzpudnz.hr

65
GovernmentCroatiamediumMEDIUM

The website zzpudnz.hr is the official online portal for the Zavod za prostorno uređenje Dubrovačko-neretvanske županije, a governmental spatial planning institute serving the Dubrovnik-Neretva County in Croatia. It provides comprehensive spatial planning documentation, project information, and news updates relevant to local government officials, urban planners, and the public. The site is well-structured, professionally designed, and offers extensive archives of news and legal documents related to spatial planning. The target audience includes government entities, municipalities, and citizens interested in regional planning and development. Technically, the website is built on the DotNetNuke (DNN) CMS platform, utilizing modern JavaScript libraries such as jQuery, Vue.js, and Bootstrap for responsive design and user experience. The site is mobile optimized and includes accessibility features. Security best practices are observed with HTTPS enforced, appropriate security headers, and secure form handling. Google Analytics is used for visitor tracking, with a cookie consent mechanism in place to comply with GDPR requirements. From a security perspective, the site shows a mature posture with no detected vulnerabilities or exposed sensitive data. However, there is no explicit public security policy or vulnerability disclosure page, and incident response contact information is not provided. The WHOIS data confirms the domain's legitimacy, consistent with the Croatian governmental entity it represents, and the domain age aligns with the institution's operational history. Overall, zzpudnz.hr is a credible, secure, and professionally maintained governmental website that effectively serves its informational and public service role. Strategic recommendations include publishing a dedicated security policy, adding vulnerability disclosure information, and providing clear incident response contacts to enhance transparency and trust.

40
68
17
70
67
75
100
governmentspatialplanningcroatiaurbanplanningpublicservice
jQueryjQuery UIBootstrapVue.js+3
2025-11-01T03:47:13.997Z
E

Exabytes Network Sdn Bhd

eth.ai

55
TechnologyMalaysiasmallMEDIUM

PUNKS.MY is a Malaysia-based NFT project that offers a unique collection of 1000 iconic Malaysian figures as digital collectibles on the Ethereum blockchain. The project emphasizes on-chain SVG storage for permanence and has historical significance with public billboard exposure during the NFT craze. The website integrates with Metamask for wallet connection and links to reputable platforms such as OpenSea and Etherscan for marketplace and contract transparency. The business targets NFT collectors and crypto enthusiasts within Malaysia and operates as a small niche player in the NFT space. Technically, the website uses a modern JavaScript stack including ethers.js, jQuery, Bootstrap, and various UI plugins. Hosting is supported by Cloudflare DNS and nameservers, ensuring good SSL configuration and moderate performance. However, mobile optimization and accessibility are basic, and SEO practices are minimal. The site lacks a CMS and appears custom-built. From a security perspective, HTTPS is enforced, and the site uses nonce-based Metamask signature challenges for authentication. However, no explicit security headers (CSP, HSTS, etc.) are detected, and there are no published privacy or cookie policies, which are compliance gaps. Google Analytics is used without visible cookie consent mechanisms, indicating moderate user tracking but poor privacy compliance. No contact or incident response information is provided, limiting transparency. Overall, the website is functional and professional with moderate trustworthiness but has room for improvement in privacy compliance, security hardening, and user transparency. Strategic recommendations include publishing privacy and cookie policies, adding security headers, improving mobile and accessibility features, and providing clear contact and incident response channels.

50
35
2
60
57
60
100
nftethereummalaysiablockchaindigitalcollectibles+2 more
HTML5CSS3JavaScriptjQuery+7
2025-11-01T03:18:22.471Z
D

Duha - sdružení dětí a mládeže pro volný čas, přírodu a recesi

duha.cz

43
Non-profitCzech RepublicmediumHIGH

Duha is a Czech non-profit organization dedicated to providing leisure, nature, and recreational activities for children and youth. The organization operates through local branches across the country, offering camps, outdoor sports, cultural activities, and volunteer opportunities. Their focus on experiential pedagogy and community engagement positions them as a well-established entity in the youth non-profit sector. The website content is rich with event reports, news, and information about their programs, targeting children, youth, and volunteers. Technically, the website uses standard web technologies such as Bootstrap and jQuery, with a moderate level of mobile optimization and accessibility. However, there is no evidence of advanced CMS or hosting details. The site lacks privacy and cookie policies, and no security headers or HTTPS status information was detected from the provided data, indicating room for improvement in security and compliance. From a security perspective, the absence of WHOIS data reduces transparency, though this is likely due to privacy protection common among non-profits. No forms or sensitive data collection mechanisms were found, reducing immediate risk. The site does not display any signs of WAF or blocking mechanisms, and content is fully accessible. Social media presence and partner logos add to the trustworthiness of the organization. Overall, the website is functional and informative but requires enhancements in security posture, privacy compliance, and transparency to improve trust and protect user data. Strategic improvements in these areas will strengthen the organization's digital maturity and stakeholder confidence.

15
10
2
80
62
85
20
non-profityouthoutdoorcommunityeducation+1 more
BootstrapjQueryGoogle Fonts
2025-11-01T03:17:47.377Z
thelocal.se favicon

The Local Europe AB

thelocal.se

65
MediaSwedenmediumMEDIUM

The Local Sweden is a well-established online news media company providing English-language news and practical guides focused on Sweden. Founded in 2004, it targets expatriates and English-speaking residents, offering a broad range of content including politics, travel, jobs, and property. The business model combines advertising revenue with a membership program, supported by a professional and user-friendly website. The company maintains a consistent brand presence and strong trust indicators such as clear contact information and privacy compliance. Technically, the website leverages modern web technologies including Vue.js, Bootstrap, and integrates multiple third-party services for analytics, advertising, and membership management. The site is mobile-optimized and SEO-friendly, delivering a good user experience. Security posture is solid with HTTPS enforced, cookie consent mechanisms, and CSRF protections, though some HTTP security headers could be improved. No critical vulnerabilities or exposed sensitive data were detected. The absence of WHOIS data for the .se domain is noted but does not detract significantly from the overall legitimacy given the strong business presence and content quality. Overall, The Local Sweden presents a trustworthy and professional digital presence with room for minor security enhancements.

15
100
17
80
57
70
100
newsmediaswedenenglishmembership+5 more
Google Tag ManagerPiano (paywall and membership)Cxense (content recommendation)Consentmanager.net (cookie consent)+5

Partner Domains:

buy.tinypass.com
partner
thelocalhelp.zendesk.com
partner

+1 more partners

2025-11-01T03:16:01.444Z
berufundpflege-nrw.de favicon

Kuratorium Deutsche Altershilfe

berufundpflege-nrw.de

48
GovernmentGermanylargeHIGH

The website berufundpflege-nrw.de represents a government-supported non-profit program managed by Kuratorium Deutsche Altershilfe, aimed at improving the compatibility of professional work and caregiving responsibilities for employees in North Rhine-Westphalia, Germany. It offers a comprehensive web portal, qualification programs for workplace care guides, a digital care toolkit, and employer branding tools. The program targets companies seeking to support employees with caregiving duties and secure skilled workforce retention. The site is well-positioned regionally with strong institutional backing and partnerships. Technically, the website is built on WordPress with modern plugins such as Yoast SEO, Advanced Custom Fields Pro, and Borlabs Cookie for privacy compliance. It uses Bootstrap for responsive design and integrates Matomo Tag Manager for analytics, reflecting a mature digital infrastructure. The site is mobile-optimized, accessible, and SEO-friendly, though some security headers could be improved. From a security perspective, the site enforces HTTPS and cookie consent mechanisms, with no visible vulnerabilities or exposed sensitive data. However, it lacks explicit security policies, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for enhanced trust and compliance. The WHOIS data is minimal but consistent with the business profile, showing no suspicious patterns. Overall, berufundpflege-nrw.de is a professional, trustworthy, and well-maintained website serving a clear social and governmental mission. Strategic improvements in security headers and transparency around incident response would further strengthen its posture.

15
43
10
70
62
60
40
governmentnon-profithealthcarework-lifebalancecaregiving+2 more
WordPressYoast SEO pluginjQueryBootstrap+3

Partner Domains:

berufundfamilie.de
partner
kda.de
parent
2025-11-01T03:15:05.614Z
jjcustomerconnect.com favicon

Johnson & Johnson Health Care System Inc.

jjcustomerconnect.com

61
HealthcareN/aenterpriseMEDIUM

Johnson & Johnson Customer Connect is a specialized order management platform designed for Johnson & Johnson's direct customers and distributors. The website serves as a portal to search for markets that have opted into this service, facilitating streamlined order processing within the healthcare sector. The platform is clearly targeted at B2B users within the Johnson & Johnson ecosystem, reflecting an enterprise-grade business model supported by a well-established parent company. Technically, the website employs a traditional web stack including Bootstrap for responsive design, jQuery for interactivity, and several UI enhancement libraries such as DataTables and Swiper. The site demonstrates basic mobile optimization and a moderate performance profile. However, there is no evidence of advanced CMS or analytics integration, suggesting a focused, internal-use application rather than a public-facing marketing site. From a security perspective, the domain is registered with appropriate safeguards such as clientTransferProhibited status and uses DNS servers consistent with Johnson & Johnson's infrastructure. However, the absence of visible HTTPS confirmation, security headers, and privacy or cookie policies indicates room for improvement in security posture and compliance. No contact or incident response information is publicly available, which may limit transparency and user trust. Overall, the website is functional and consistent with its business purpose but lacks several modern security and privacy best practices. Strategic improvements in HTTPS deployment, security headers, and policy disclosures would enhance trust and compliance, supporting the platform's role within a global healthcare enterprise.

70
50
2
70
57
80
100
healthcareordermanagementb2bjohnsonjohnsonbootstrap+1 more
HTML5CSS3BootstrapjQuery+4
2025-11-01T03:14:05.451Z
balloonsinuplasty.com favicon

Integra LifeSciences

balloonsinuplasty.com

67
HealthcareN/aenterpriseMEDIUM

Integra LifeSciences is a healthcare enterprise specializing in medical devices, particularly in the treatment of sinusitis through innovative solutions like Balloon Sinuplasty. The website serves both patients and healthcare professionals by providing educational content, treatment options, and surgeon locator services. The company positions itself as a trusted provider in the ENT medical device market with a focus on minimally invasive procedures. Technically, the website leverages modern web technologies including Bootstrap, jQuery, GSAP, and is hosted on Oracle Cloud Infrastructure with content delivery via Oracle's CDN. It integrates Google Analytics for user tracking and OneTrust for cookie consent management, reflecting a moderate level of digital maturity and privacy compliance. The site is mobile optimized and offers a good user experience, though accessibility features could be enhanced. From a security perspective, the site enforces HTTPS and uses cookie consent mechanisms but lacks explicit security headers such as CSP or HSTS, which are recommended for improved protection. No vulnerabilities or exposed sensitive data were detected in the content. The absence of WHOIS data for the domain is a concern, potentially indicating privacy protection or a recent registration, which slightly lowers the trust score. Overall, the website is professional, content-rich, and aligned with healthcare industry standards. Strategic improvements in security headers, accessibility, and WHOIS transparency would enhance trust and compliance. The risk level is moderate with no critical issues detected.

40
35
47
85
62
85
100
healthcaremedicaldevicessinusitisballoonsinuplastypatienteducation+1 more
BootstrapjQueryGSAPOracle Cloud CDN+3
2025-11-01T03:13:25.347Z
anthromedics.org favicon

Anthromedics

anthromedics.org

46
HealthcareN/asmallHIGH

Anthromedics.org is a specialized healthcare website focused on Anthroposophic Medicine, offering editorially supervised content including practice recommendations, basic concepts, and access to the Der Merkurstab journal. The platform targets healthcare professionals and individuals interested in this niche medical field, providing multilingual content in English, German, and Spanish. The business model revolves around content subscription and educational resources, supported by partnerships with recognized Anthroposophic organizations. Technically, the website employs a Symfony-based framework with JavaScript libraries such as jQuery and Bootstrap, and uses Piwik (Matomo) for analytics. The site is mobile-optimized with moderate performance and basic accessibility features. Security posture is solid with HTTPS enforced and CSRF protection on forms, though it lacks some security headers and cookie consent mechanisms. The WHOIS data is unavailable or malformed, limiting domain trust verification, but the website's professional presentation, affiliations, and content quality support its legitimacy. No blocking or WAF challenges were detected, and the site is fully accessible. Overall, the website is well-positioned within its niche, with good content quality and technical implementation. Security and privacy compliance could be improved by adding security headers and cookie consent. The absence of direct contact emails or phone numbers suggests reliance on contact forms for communication.

50
85
53
20
2
15
62
anthroposophicmedicinehealthcaremedicaljournaleducationsubscription+1 more
JavaScriptjQueryBootstrapPiwik (Matomo) Analytics

Partner Domains:

www.medsektion-goetheanum.org
partner
www.gaed.de
partner

+2 more partners

2025-11-01T02:59:12.125Z
kostal-drives-technology.com favicon

Leopold Kostal GmbH & Co. KG

kostal-drives-technology.com

64
EnergyGermanylargeMEDIUM

KOSTAL Drives Technology is a well-established industrial technology company specializing in frequency converters and motor control solutions. With a heritage spanning over 100 years, the company holds a strong market position as a leader in energy-efficient and sensorless motor control technologies. Their product portfolio targets diverse industrial sectors including machinery, water treatment, renewable energy, logistics, and building technology. The website reflects a professional and comprehensive digital presence, supporting global operations with multiple languages and extensive product information. Technically, the website is built on TYPO3 CMS and incorporates modern web technologies such as Bootstrap, Swiper.js, and Google Tag Manager. It demonstrates good performance, mobile optimization, and accessibility features. Privacy compliance is robust, featuring a consent management platform (Usercentrics) and clear GDPR-aligned policies. Security posture is strong with HTTPS enforcement and secure form handling, though some security headers could be explicitly improved. The WHOIS data is unavailable or not found, which is unusual but the website's content, branding, and external references to the Kostal group domains support its legitimacy. No WAF or blocking mechanisms were detected, allowing full content access and analysis. Overall, the site is trustworthy, professional, and well-maintained, with minor recommendations for enhanced security headers and vulnerability disclosure practices.

85
65
2
40
62
70
100
frequencyconvertersmotorcontrolindustrialautomationenergyefficiencysensorlesscontrol+4 more
TYPO3 CMSBootstrapSwiper.jsGoogle Tag Manager+3

Partner Domains:

www.kostal.com
parent
kostalgroup.speakup.report
service

+3 more partners

2025-11-01T02:47:01.316Z
C

Cia Proc. de Dados do Estado de S Paulo - Prodesp

sp.gov.br

58
GovernmentBrazilenterpriseMEDIUM

The website www.sp.gov.br is the official digital portal for the Government of the State of São Paulo, Brazil, managed by the Companhia de Processamento de Dados do Estado de São Paulo (Prodesp). It serves as a comprehensive platform providing institutional information, public services, news updates, and communication channels to residents, government employees, and visitors. The site demonstrates a mature digital presence with consistent branding and a clear focus on accessibility and transparency. Technically, the site leverages modern web technologies including jQuery, Bootstrap, FontAwesome, and Slick Carousel, integrated within an IBM WebSphere Portal framework. It employs Google Tag Manager and Microsoft Clarity for analytics and user behavior tracking. The site is mobile-optimized and includes accessibility features such as VLibras for sign language support, reflecting a commitment to inclusive design. From a security perspective, the website enforces HTTPS and provides clear incident response contacts including a CSIRT email. While explicit security headers were not fully visible in the HTML, the overall posture is strong with no exposed sensitive data or vulnerable libraries detected. Privacy and cookie policies are comprehensive and GDPR-compliant, supporting user data protection and transparency. Overall, the website is trustworthy, professionally maintained, and aligned with the expectations for a government portal. It effectively balances user experience, accessibility, and security, making it a reliable resource for its audience.

30
35
2
75
67
65
100
governmentpublicservicessopaulobrazilofficialportal+2 more
jQueryBootstrapFontAwesomeSlick Carousel+2
2025-11-01T02:44:55.093Z
app-helper.com favicon

Kiwis & Brownies

app-helper.com

56
TechnologyN/asmallMEDIUM

The website www.app-helper.com/.adm/ represents a promotion builder platform named Prombu, developed by Kiwis & Brownies. It targets businesses and marketers seeking tools to create and manage promotional campaigns. The site provides user registration, login, and social login via Facebook integration. The business model appears to be SaaS-based, focusing on promotion creation services. The market position is niche with a small-scale operation and basic branding consistency. Technically, the site uses a standard web technology stack including jQuery, Bootstrap, Facebook SDK, Google Analytics, Google reCAPTCHA, and Klaro for cookie consent management. The site is moderately optimized for performance and mobile devices but lacks advanced SEO optimization and accessibility features. The presence of Google Adsense indicates monetization through advertising. From a security perspective, the site uses HTTPS and includes reCAPTCHA for form protection. However, it lacks visible security headers such as Content-Security-Policy and HSTS, which are recommended best practices. No explicit security or incident response policies are published, and WHOIS data is unavailable, raising concerns about domain legitimacy. Privacy and cookie policies are present and indicate GDPR compliance, but contact information is missing. Overall, the site is functional and provides basic business and privacy information but has gaps in security posture and domain transparency. The absence of WHOIS data and minimal security headers reduce trustworthiness. Strategic improvements in security headers, domain registration transparency, and enhanced privacy disclosures are recommended to strengthen the site's credibility and compliance.

30
85
2
55
47
65
100
promotionmarketingloginregistrationfacebook+2 more
jQueryBootstrapFacebook SDKGoogle Analytics+2
2025-11-01T02:40:14.154Z
spelpaus.se favicon

Abion AB

spelpaus.se

10
GovernmentSwedenmediumCRITICAL

Spelpaus.se is a Swedish government-backed online service that enables individuals to self-exclude from all licensed gambling operators in Sweden. The service is operated by Abion AB and closely affiliated with Spelinspektionen, the Swedish Gambling Authority. It provides a critical public health function by helping users control gambling addiction through a legally binding exclusion period verified by secure identity methods such as BankID and Freja eID+. The website is professionally designed, mobile-optimized, and offers multilingual support including Swedish, English, and Arabic. It includes educational content about gambling addiction and support for relatives of problem gamblers. Technically, the website uses a modern tech stack including Umbraco CMS, Bootstrap framework, and Matomo analytics for user tracking. The site is served over HTTPS with secure forms implementing anti-forgery tokens, ensuring a strong baseline security posture. However, DNSSEC is not enabled and security headers are not explicitly detected, representing areas for improvement. Privacy compliance is supported by clear GDPR documentation, although no cookie consent mechanism is present despite analytics usage. From a security perspective, the site demonstrates good practices such as secure identity verification and no visible vulnerabilities or exposed sensitive data. The domain registration is consistent and transparent, registered to Abion AB since 2015, aligning with the service's operational timeline. No WAF or blocking mechanisms interfere with content access. Overall, the site is trustworthy, safe, and serves an essential government function with a high level of professionalism. Strategically, the site would benefit from implementing cookie consent, publishing explicit security and incident response policies, enabling DNSSEC, and adding security headers to further enhance trust and compliance. These improvements would strengthen the security posture and privacy compliance, supporting the site's critical role in responsible gambling in Sweden.

-
-
-
-
-
-
-
gamblingself-exclusionresponsiblegamblinggovernmentsweden+3 more
JavaScriptMatomo AnalyticsBootstrapUmbraco Forms

Partner Domains:

spelinspektionen.se
partner
2025-11-01T02:20:24.733Z
ibericode.com favicon

ibericode BV

ibericode.com

52
TechnologyN/asmallMEDIUM

ibericode BV is a small European company specializing in developing open-source software products for the web, primarily focusing on WordPress plugins such as Mailchimp for WordPress and Koko Analytics. The company has a significant market presence with over 73 million downloads and active use on more than 2.1 million websites, positioning it as a reputable niche player in the WordPress ecosystem. Their business model revolves around open-source software with premium plugin offerings, targeting web developers and WordPress site owners. Technically, the website employs modern web technologies including Bootstrap and JavaScript, with a clean and professional design optimized for mobile devices. The site uses self-hosted analytics to respect user privacy and demonstrates good SEO practices. However, some technical aspects such as security headers and cookie consent mechanisms are missing, indicating room for improvement in security and compliance. From a security perspective, the website shows no immediate vulnerabilities or exposed sensitive data, but lacks visible security headers and formal security policies. The absence of WHOIS data for the domain raises concerns about domain registration legitimacy, although the website content and business information appear trustworthy. Overall, the security posture is moderate but could be enhanced by implementing recommended best practices. The overall risk assessment suggests a generally trustworthy and professional website with minor security and compliance gaps. Strategic recommendations include improving security headers, adding cookie consent for GDPR compliance, publishing security policies, and clarifying domain registration details to enhance trust and security culture.

50
53
2
65
52
80
40
open-sourcewordpressanalyticsmailchimptechnology+1 more
BootstrapJavaScriptHTML5CSS3
2025-11-01T02:15:07.753Z
ifbls.org favicon

International Federation of Biomedical Laboratory Science (IFBLS)

ifbls.org

45
HealthcareCanadamediumHIGH

The International Federation of Biomedical Laboratory Science (IFBLS) is a well-established non-profit professional federation representing biomedical laboratory scientists globally. Founded in 1954 and with a domain registered since 2002, IFBLS serves over 240,000 professionals across 38 countries. The organization provides membership services, educational webinars, scientific publications, and international congresses to promote the profession and advance healthcare diagnostics. The website reflects a professional and consistent brand image targeted at biomedical laboratory science professionals worldwide. Technically, the website is built on Joomla CMS using standard web technologies including jQuery and Bootstrap. It integrates Google Analytics and Google Tag Manager for user tracking and AddThis for social sharing. The site is mobile optimized with a moderate performance profile. However, it lacks advanced SEO and accessibility features. Security-wise, the site uses HTTPS and domain transfer protections but lacks DNSSEC and security headers. There is no published privacy or cookie policy despite the use of tracking scripts, which is a compliance gap. The security posture is moderate with no critical vulnerabilities detected but improvements are needed in privacy compliance and security best practices. The site actively warns users about phishing attempts impersonating IFBLS, demonstrating awareness of security risks. Contact information is clearly provided, including email, phone, and physical address in Canada, along with active social media channels. Overall, IFBLS presents a credible and professional online presence with room for improvement in privacy compliance and security hardening. Strategic recommendations include implementing privacy and cookie policies, enabling DNSSEC, adding security headers, and establishing a vulnerability disclosure policy to enhance trust and compliance.

20
35
2
70
62
70
20
ifblsbiomedicallaboratorysciencehealthcareprofessionalassociationeducation+1 more
jQueryBootstrapGoogle AnalyticsGoogle Tag Manager+1

Partner Domains:

www.ifbls2026.jp
partner
idblse.editme.com
partner

+1 more partners

2025-11-01T01:49:31.196Z