Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 139 of 261|Showing 6901-6950 of 13036
gwtf.it favicon

Andrea Contino

gwtf.it

55
OtherN/asmallMEDIUM

The website contino.com is a personal weblog operated by Andrea Contino, focusing on communication, gaming, technology, and lifestyle topics. It serves a niche audience interested in personal reflections and commentary on these subjects. The site has been active since 2009, supported by a domain registered since 1997, indicating a stable and long-term presence. The business model is non-commercial, with no advertising or paid content, emphasizing personal expression and community engagement. Technically, the website is built with standard HTML, CSS, and JavaScript, without reliance on major CMS platforms or frameworks. The site demonstrates good mobile optimization and SEO practices but lacks advanced accessibility features. Hosting and DNS services are managed by Porkbun LLC, with domain security measures such as clientDeleteProhibited and clientTransferProhibited status enabled, though DNSSEC is not implemented. From a security perspective, the site uses HTTPS (implied by URLs), but no explicit security headers or incident response policies are published. There is no privacy or cookie policy, which is a compliance gap especially under GDPR. No analytics or tracking technologies are detected, indicating minimal user tracking and good privacy by default. The domain registration data aligns well with the website content, supporting legitimacy and trustworthiness. Overall, the website is a well-maintained personal blog with good content quality and moderate technical implementation. Security and privacy compliance could be improved by adding relevant policies and security headers. The site poses low risk and is safe for general audiences.

65
35
17
75
72
65
40
blogtechnologygamingpersonallifestyle+1 more
HTML5CSS3JavaScript
2025-07-27T20:57:19.870Z
galaiko.rocks favicon

Nikita Galaiko

galaiko.rocks

46
OtherN/asmallHIGH

The website nikita.galaiko.rocks serves as a personal homepage for an individual named Nikita Galaiko. It primarily functions as a personal portfolio and contact point, sharing curated lists of interests such as vinyl records, restaurants, cocktails, movies, and blogrolls. The site targets a general audience interested in these personal interests and provides contact options via email and scheduling calls. The business model is informational and personal, with no commercial or corporate presence evident. Technically, the website is built with standard HTML5 and CSS3, utilizing custom fonts loaded via WOFF2. There is no evidence of a CMS or advanced frameworks. The site appears moderately optimized for performance and mobile devices, with basic accessibility and SEO features. No advanced analytics or tracking technologies are detected, indicating a privacy-conscious approach. From a security perspective, the site lacks visible HTTPS enforcement and security headers, which lowers its security posture. There are no published security policies, incident response contacts, or cookie consent mechanisms, which are typical for personal sites but represent areas for improvement. The WHOIS data is unavailable or privacy protected, which is common for personal domains and does not raise immediate concerns. No vulnerabilities or suspicious patterns were detected. Overall, the website is a safe, personal informational site with moderate technical quality but limited security and privacy compliance features. Strategic recommendations include implementing HTTPS, adding security headers, publishing privacy and security policies, and introducing cookie consent mechanisms to enhance trust and compliance.

15
53
2
70
75
80
-
personalportfoliocontactlistsvinyl+4 more
HTML5CSS3WOFF2 fonts
2025-07-27T20:56:34.260Z
C

Cody Schultz

codyschultz.com

53
MediaUnited StatessmallMEDIUM

Cody Schultz operates a personal brand website focused on photography, writing, and creative podcasting. The site serves as a portfolio and content hub targeting enthusiasts and professionals interested in landscape photography and creative philosophy. The business model centers on content creation, podcast hosting, and newsletter distribution, positioning itself as a niche media entity within the creative arts sector. The website is small scale and founded in 2016, consistent with the domain registration data. Technically, the website is built with standard HTML5 and CSS3, leveraging custom fonts and hosted likely on Squarespace infrastructure. The site demonstrates good mobile optimization, SEO metadata, and a clean, consistent design. However, no CMS or advanced frameworks are detected, indicating a simple static or lightly dynamic site. Performance is moderate with no evident technical debt but lacks advanced accessibility features. From a security perspective, the domain registration includes transfer and update prohibitions, enhancing domain security. However, DNSSEC is not enabled, and no security headers are detected in the provided data, representing areas for improvement. The site lacks privacy, cookie, and terms of service policies, which are critical for GDPR and general compliance. No contact information or incident response details are published, limiting transparency and trust. Overall, the website is professionally presented and trustworthy for its niche but requires enhancements in privacy compliance and security best practices to improve its risk posture and user trust. Strategic recommendations include adding privacy and cookie policies, enabling DNSSEC, implementing security headers, and publishing contact information for security incidents.

65
35
2
55
72
80
40
photographywritingpodcastcreativenewsletter+3 more
HTML5CSS3WOFF2 fontsSquarespace DNS+1
2025-07-27T20:56:24.189Z
L

Lars-Christian Simonsen

lars-christian.com

50
OtherNorwaysmallMEDIUM

Lars-Christian.com is a personal website and blog operated by Lars-Christian Simonsen from Oslo, Norway. The site features a collection of longer posts and shorter notes covering various personal interests, including reading and workout logs. The website targets a general audience interested in personal reflections and curated content. It operates as a small-scale personal publishing platform without commercial business operations or extensive user engagement features. Technically, the website is built with clean HTML and CSS, featuring responsive design and basic accessibility. It uses Atom feeds and supports Webmention for social interactions. Hosting is managed through Hover.com, with domain registration dating back to 2005, indicating a mature and stable online presence. However, no CMS or advanced frameworks are detected, reflecting a minimalist and self-managed technical infrastructure. From a security perspective, the website benefits from domain transfer protections but lacks DNSSEC and visible security headers. There is no evidence of HTTPS enforcement or cookie consent mechanisms, which limits privacy compliance. No forms or scripts that collect user data are present, reducing attack surface but also limiting interactivity. The site does not publish a security policy or incident response contacts, which is typical for personal blogs but could be improved for trust. Overall, the website is safe, trustworthy, and professionally maintained for a personal blog. Strategic recommendations include enabling DNSSEC, adding security headers, enforcing HTTPS, and implementing privacy compliance features such as cookie consent. These improvements would enhance security posture and user trust without compromising the site's simplicity.

15
53
2
65
72
80
40
personalblognotespostsreadinglogworkoutlog+1 more
HTML5CSS3Atom feedsWebmention
2025-07-27T20:56:19.178Z
L

Luke’s Wild Website

lkhrs.com

63
TechnologyUnited StatessmallMEDIUM

Luke’s Wild Website is a personal portfolio and blog site operated by Luke Harris, a developer and designer based in Chicago. The site serves as a platform for sharing blog posts, notes, and personal insights, targeting a general audience interested in technology and personal content. The website is built on the Ghost CMS platform, utilizing modern web technologies such as HTML5, CSS3, and JavaScript, with a clean and consistent design that supports good user experience and mobile optimization. However, the site lacks explicit contact information, privacy policies, and security headers, which impacts its overall trustworthiness and compliance posture. From a technical perspective, the website demonstrates moderate performance and good SEO optimization but lacks advanced security configurations such as HTTPS enforcement and security headers. The absence of WHOIS registration data raises concerns about domain legitimacy, although the site content appears genuine and updated recently. No advertising or analytics services are detected, indicating minimal user tracking and a privacy-conscious approach, albeit without formal policies. Security posture is currently weak due to missing HTTPS confirmation, lack of security headers, and no visible incident response or data protection policies. The site does not expose sensitive data or show signs of vulnerabilities but would benefit from implementing standard security best practices and publishing privacy and cookie policies to improve compliance and user trust. Overall, the website is functional and professional for a personal blog but requires improvements in security and compliance to enhance credibility and protect visitors.

65
50
2
70
75
85
100
blogpersonaltechnologydeveloperdesigner
HTML5CSS3JavaScriptGhost CMS
2025-07-27T20:56:14.170Z
I

Ivan Moreale

ivanmoreale.com

52
OtherN/asmallMEDIUM

Ivan Moreale's website is a personal portfolio showcasing graphic design services with a casual and informal tone. The site targets a general audience interested in creative design work, emphasizing personal branding rather than corporate presence. The business model appears to be freelance or individual service provision with a niche market position. The website is minimalistic, with limited content and contact information, primarily an email and Instagram link. Technically, the site is built with basic HTML, CSS, and JavaScript without any detected CMS or frameworks. Hosting is managed via Hover, a common domain and DNS provider. The site shows moderate performance and good mobile optimization but lacks advanced SEO and accessibility features. No analytics or tracking technologies are present, indicating minimal data collection. From a security perspective, the site lacks critical security headers and does not indicate HTTPS enforcement explicitly. DNSSEC is not enabled, and no privacy or cookie policies are published, which impacts compliance posture. The WHOIS data shows a stable domain registration with appropriate protections against unauthorized transfers, consistent with a legitimate personal brand site. No vulnerabilities or incident response information is available. Overall, the website presents a low-risk profile but would benefit from improved security practices, privacy compliance, and richer content to enhance trust and professionalism.

65
50
2
60
72
70
40
graphicdesignpersonalportfoliocreativefreelance
HTML5CSS3JavaScript
2025-07-27T20:55:58.615Z
elmikewalsh.com favicon

Mike Walsh

elmikewalsh.com

61
TechnologyChilesmallMEDIUM

The website elmikewalsh.com serves as a personal portfolio and blog for Mike Walsh, a front-end web designer, developer, and translator based in Villarrica, Chile. The site highlights his skills, writings, and professional presence with links to his GitHub, Medium, and Mastodon profiles. The business model is that of an individual professional showcasing services and content to a general audience interested in technology, politics, humor, and life. The site is well-structured, visually consistent, and optimized for mobile devices, reflecting a good level of digital maturity for a personal brand. Technically, the website is built using modern web standards including HTML5, CSS3, JavaScript, and JSON-LD structured data for SEO. It uses a static site generator (Publii), which contributes to fast loading times and good performance. The site is served over HTTPS with a valid SSL certificate, and minimal external scripts are used, primarily for analytics via Cloudflare Insights. Accessibility and SEO optimizations are present but could be enhanced further. From a security perspective, the site enforces HTTPS and does not expose sensitive data or use vulnerable libraries. However, it lacks explicit security headers and does not provide privacy, cookie, or terms of service policies, which are important for compliance and user trust. No contact information for security incidents or vulnerability disclosure mechanisms are present. The WHOIS data is unavailable or the domain is unregistered, which raises concerns about domain legitimacy and trustworthiness. Overall, the website is professional and safe for general audiences but would benefit from improved privacy compliance, clearer domain registration information, and enhanced security practices. Strategic recommendations include publishing privacy and cookie policies, adding security headers, providing contact channels for incident response, and implementing a vulnerability disclosure policy to strengthen trust and compliance.

50
50
2
65
75
70
100
front-endwebdesigndevelopmenttranslationblog+2 more
HTML5CSS3JavaScriptJSON-LD+1
2025-07-27T20:55:28.024Z
C

Chris Hannah

chrishannah.me

56
OtherN/asmallMEDIUM

The website chrishannah.me is a personal blog and portfolio site maintained by Chris Hannah. It features a variety of content including essays, technical articles, photography, and personal updates. The site targets a general audience interested in technology, programming, and personal storytelling. The business model is primarily content publishing for personal branding and sharing knowledge. The site is small-scale and has been active since 2016, with consistent content updates and a clear personal identity. Technically, the site is well-structured with modern HTML5 and CSS3 standards, uses JavaScript libraries such as Highlight.js for code syntax highlighting, and Lightbox.js for image display. Hosting is via Vercel DNS, indicating a modern and performant infrastructure. The site is mobile-optimized and has good navigation clarity, although accessibility features are basic. SEO optimization is present but could be improved. From a security perspective, the site enforces HTTPS with good SSL configuration and has domain transfer protections enabled. However, it lacks DNSSEC and security headers such as Content Security Policy or HSTS. There are no published privacy or cookie policies, nor a security.txt or vulnerability disclosure page, which are areas for improvement. Analytics are minimal and privacy-respecting, using Tinylytics with no aggressive tracking. Overall, the site is trustworthy and professional for a personal blog but has gaps in privacy compliance and security best practices. Strategic recommendations include adding privacy and cookie policies, implementing security headers, enabling DNSSEC, and publishing a vulnerability disclosure policy to enhance trust and compliance.

30
35
17
40
72
75
100
personalblogtechnologyprogrammingphotographyessays
HTML5CSS3JavaScriptHighlight.js+2
2025-07-27T20:54:41.543Z
liputenpo.org favicon

lipu tenpo

liputenpo.org

56
Non-profitGermanysmallMEDIUM

lipu tenpo is a registered association based in Germany that provides a cultural and educational platform primarily in the Toki Pona language. The website hosts a collection of articles and multimedia content licensed under CC BY-SA 4.0, targeting a general audience interested in this niche language and culture. The organization engages its community through Discord, Patreon, and Linktree, indicating active outreach and support mechanisms. The domain was registered in 2021, consistent with the association's founding timeline. Technically, the website is built with standard HTML5 and CSS3, utilizing Google Fonts and GoatCounter for lightweight, privacy-conscious analytics. The hosting is managed via Name.com, with no CMS or major frameworks detected, suggesting a custom or static site approach. The site is mobile-optimized with good navigation and SEO practices, though accessibility features are basic. Performance is moderate, with no blocking or WAF detected. From a security perspective, the site uses HTTPS and has domain transfer protections enabled, but lacks DNSSEC and security headers such as Content-Security-Policy or X-Frame-Options. There is no visible privacy or cookie policy, nor incident response or vulnerability disclosure information, which are areas for improvement. No sensitive data exposure or vulnerabilities were detected in the content. Overall, the security posture is moderate but could be enhanced with standard best practices. The overall risk assessment is low to moderate, with no critical issues found. Strategic recommendations include implementing DNSSEC, adding security headers, publishing privacy and cookie policies, and providing incident response contacts to improve compliance and trust. The site is trustworthy for its intended educational and cultural purpose but would benefit from enhanced security and privacy transparency.

15
35
2
60
95
70
100
educationculturenon-profittokiponacommunity
HTML5CSS3Google FontsGoatCounter analytics
2025-07-27T19:50:06.230Z
A

Anna Kudriavtsev

ap5.dev

59
TechnologyN/asmallMEDIUM

The website ap5.dev is a personal professional portfolio and blog belonging to Anna Kudriavtsev, focusing on computing systems design and software development with an emphasis on correctness and maintainability. The site positions itself as a personal brand rather than a commercial business, targeting a general audience interested in technology and software development. The business model is primarily informational and portfolio-based, with links to a resume and GitHub repository. Technically, the website uses standard modern web technologies including HTML5, CSS3, and JavaScript, with external resources such as Google Fonts and a chat widget from cactus.chat. The site is moderately optimized for mobile and SEO, with good design quality and clear navigation. However, no CMS or hosting provider details are evident, and performance is moderate. From a security perspective, the site uses HTTPS and does not expose forms or sensitive data, but lacks explicit security headers and formal privacy or cookie policies. No vulnerability disclosure or incident response information is provided. The domain registration is privacy protected, which is appropriate for a personal site. Overall, the security posture is adequate but could be improved with additional headers and compliance documentation. The overall risk is low given the nature of the site, but strategic recommendations include implementing privacy and cookie policies, adding security headers, and providing vulnerability disclosure information to enhance trust and compliance.

15
35
2
70
95
80
100
personalportfoliotechnologyblogprofessional
HTML5CSS3JavaScript
2025-07-27T19:49:45.994Z
P

Pontus Henriksson

pontushenriksson.com

55
TechnologyN/asmallMEDIUM

The website pontushenriksson.com represents a personal portfolio for an individual web developer and programmer named Pontus Henriksson. The site is currently under development with a legacy site linked for reference. The business model is focused on showcasing skills and previous work to attract freelance or contract opportunities. The target audience includes potential clients or employers seeking web development and design services. The website is hosted on Cloudflare Pages and uses basic modern web technologies such as HTML5, CSS3, and JavaScript. The design is responsive and user-friendly, though content is minimal and lacks comprehensive business or contact information. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and security headers, which are recommended to enhance protection. No privacy, cookie, or terms of service policies are present, indicating limited compliance with GDPR or other privacy regulations. No contact emails, phone numbers, or social media links are provided, reducing business credibility and user trust. Analytics are implemented via Cloudflare Pages Analytics with minimal user tracking. Overall, the website is safe with no adult or questionable content detected. The domain registration is consistent with the website's new status and shows no suspicious patterns. The security posture is moderate but can be improved by adding security headers and privacy policies. The site’s technical implementation is adequate for a personal portfolio but lacks advanced SEO and accessibility features. Strategic recommendations include implementing privacy and cookie policies, adding security headers, providing clear contact information, enabling DNSSEC, and enhancing SEO and accessibility to improve user trust and compliance.

40
50
2
40
75
70
100
portfoliowebdeveloperprogrammerpersonalwebsitecloudflare
HTML5CSS3JavaScript
2025-07-27T19:45:11.043Z
is-a.dev favicon

is-a.dev - Free subdomains for developers

is-a.dev

61
TechnologyN/asmallMEDIUM

The website is-a.dev offers a free subdomain registration service targeted primarily at developers. It enables users to obtain free `.is-a.dev` subdomains by following instructions hosted on a GitHub repository. The service is positioned as a niche developer tool with a small-scale operation founded in 2020. The website content is clear, relevant, and professionally presented with consistent branding and a focus on developer engagement through GitHub and Discord communities. From a technical perspective, the site uses modern web technologies including HTML5, CSS3, JavaScript, and is hosted behind Cloudflare, ensuring fast performance and good mobile optimization. The presence of Carbon Ads and Cloudflare Insights indicates minimal advertising and analytics usage, with a low level of user tracking. SEO and accessibility are adequately addressed, though accessibility is basic. Security posture is solid with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. However, the site lacks explicit security headers and formal privacy or cookie policies, which are important for compliance and trust. Incident response is partially addressed via a GitHub abuse reporting mechanism, but no dedicated security contact or vulnerability disclosure policy is present. Overall, the website is trustworthy and functional with a good balance of usability and security for its scope. The main risks relate to privacy compliance and formal security governance, which could be improved to enhance user trust and regulatory adherence.

25
50
2
70
75
85
100
developersubdomainfreegithubcloudflare+1 more
HTML5CSS3JavaScriptCloudflare+1
2025-07-27T19:44:35.831Z
refact0r.dev favicon

refact0r

refact0r.dev

58
TechnologyN/asmallMEDIUM

The website refact0r.dev is a personal portfolio and blog belonging to a student interested in computer science, web development, and design. It serves as a platform to showcase projects, share blog content, and present personal interests. The site is built using modern web technologies including SvelteKit, and it demonstrates good design quality, mobile optimization, and user experience. However, it lacks formal business information, contact details, and compliance documentation such as privacy or cookie policies. From a technical perspective, the site uses a modern JavaScript framework (SvelteKit) and includes minimal analytics via umami, indicating a lightweight and privacy-conscious approach. The performance appears fast, and the site is mobile responsive. However, no security headers were detected in the provided data, and there is no evidence of HTTPS enforcement or advanced security practices. Security posture is moderate but could be improved by implementing standard security headers, privacy policies, and incident response information. The absence of contact information and compliance documents reduces trust and business credibility. No vulnerabilities or suspicious content were detected, and the domain registration uses privacy protection, which is appropriate for a personal site. Overall, the site is a well-designed personal portfolio with room for improvement in security, privacy compliance, and business transparency. Strategic recommendations include adding privacy and cookie policies, implementing security headers, providing contact information, and considering a vulnerability disclosure policy to enhance trust and compliance.

30
50
2
60
75
75
100
portfolioblogpersonaltechnologystudent
HTML5CSS3JavaScriptSvelteKit
2025-07-27T19:44:15.778Z
O

Offenciv Security

terminaate.site

51
TechnologyRussiasmallMEDIUM

The website terminaate.site is a personal portfolio of a young web developer from Russia specializing in React and Next.js, with interests in backend and DevOps. The site serves as a showcase of skills and projects, targeting potential collaborators or clients interested in modern web development technologies. The technical infrastructure is modern, leveraging popular JavaScript frameworks, bundlers, and backend tools, hosted with Cloudflare DNS and employing HTTPS. The site is well-designed with good navigation and mobile optimization, though it lacks formal privacy and cookie policies, as well as contact information, which limits its professional completeness. From a security perspective, the site uses HTTPS and modern frameworks but lacks security headers and formal security policies. The WHOIS data raises concerns due to an inconsistent domain creation date set in the future and a registrant organization name that does not clearly align with the personal portfolio branding. No WAF or blocking mechanisms are detected, and the site includes minimal user tracking via Umami analytics. Overall, the security posture is moderate but could be improved with better compliance and security practices. The overall risk is moderate with no critical vulnerabilities detected, but the lack of privacy compliance and contact information, combined with suspicious WHOIS data, suggests caution. Strategic improvements in security headers, privacy policies, and domain registration accuracy are recommended to enhance trust and compliance.

30
35
2
40
72
60
100
terminaateterminatereactreactjstermi+10 more
JavaScriptTypeScriptHTML5CSS3+16
2025-07-27T19:43:30.288Z
A

meowem weowe me oe wmewoe mweweowemweowmewoewme ewemweowmewoemw eo wemwemwmemwmewoewmem wmewoewmewoemw eowmemweowemweow memwemw memwm ewoewmem weowme woemweowme woewo emwme mwem wmemmewoe meow emwo emweo wmewoe mweowme wemwewoemweo mmewow memwowem weowmewoeweow memwemwmewo me mwmewmeo

aprl.cat

58
TechnologyUnited KingdomsmallMEDIUM

The website aprl.cat is a personal site belonging to an individual named April, a 20-year-old from the UK with interests in programming, music, skateboarding, and cats. The site serves as a personal blog and portfolio showcasing her hobbies, technical skills, and social media presence. It targets a general audience interested in personal tech and music culture. The site is small-scale and non-commercial, with no evident business operations or monetization. Technically, the site is custom-built with vanilla HTML, CSS, and JavaScript, hosted behind Cloudflare DNS and CDN services. It integrates WebSocket connections to the Lanyard API for real-time Discord presence updates. The site lacks a CMS and advanced frameworks but uses modern programming languages and tools in the background as described by the owner. Security posture is moderate with domain transfer protections but lacks DNSSEC and security headers. Privacy and cookie policies are absent, reducing compliance. WHOIS data shows inconsistencies, notably a domain creation date in the future, which raises questions about domain legitimacy. Overall, the site is functional and moderately secure but would benefit from improved security headers, privacy compliance, and WHOIS data accuracy.

50
35
2
70
75
70
100
personalprogrammingmusicskateboardingcats+3 more
HTML5CSS3JavaScriptCloudflare DNS+8
2025-07-27T19:43:25.249Z
G

garnix.dev

garnix.dev

49
TechnologyN/asmallHIGH

The website garnix.dev is a personal blog and content sharing platform maintained by an individual named Emilia. It primarily offers blog posts, music recommendations, and personal content, targeting a general audience interested in technology and related community topics. The site is small in scale and operates as a niche personal blog without commercial business infrastructure or formal corporate presence. Technically, the site is built with standard HTML, CSS, and JavaScript, featuring a simple but consistent design and basic mobile optimization. It uses a fetch API call to an external HTTPS endpoint for form submissions, indicating some level of modern web technology usage. However, there is no evidence of advanced frameworks, CMS, or hosting provider details. SEO and accessibility features are basic, and no structured metadata or Open Graph tags are present. From a security perspective, the site uses HTTPS for external requests but lacks visible security headers and formal security policies. The contact form is minimal and lacks CSRF protection or input validation beyond a non-empty check. No privacy, cookie, or terms of service policies are published, which limits compliance with GDPR and other privacy regulations. The domain uses WHOIS privacy protection, which is common for personal sites and justified here. No suspicious or malicious indicators were found. Overall, the site is safe and trustworthy for general audiences but would benefit from improved security practices, privacy disclosures, and business contact information to enhance credibility and compliance. The AI score reflects a functional but basic personal website with room for improvement in security and privacy compliance.

15
40
2
70
75
85
40
personalblogtechnologymusiccommunityprivacy
HTML5CSS3JavaScriptFetch API
2025-07-27T19:43:20.227Z
experiencegoldcoast.com favicon

Experience Gold Coast

experiencegoldcoast.com

70
HospitalityAustraliamediumMEDIUM

Experience Gold Coast operates a comprehensive tourism and education portal focused on promoting the Gold Coast region in Australia. The website offers rich content including attractions, events, accommodation, and student resources, positioning itself as a regional destination marketing organization. The business is relatively new, founded in 2022, and targets tourists, students, and locals interested in exploring the Gold Coast. The company leverages partnerships with local arts, education, and event organizations to enhance its offerings. Technically, the website is built on a modern stack including Sitecore CMS, Bootstrap 4, and hosted likely on Microsoft Azure infrastructure. It integrates multiple third-party analytics and marketing tools such as Microsoft Application Insights, Google Tag Manager, TikTok Pixel, and others, indicating a mature digital marketing approach. The site is mobile optimized and accessible with good SEO practices. From a security perspective, the website enforces HTTPS and uses domain status locks to protect domain integrity. However, it lacks DNSSEC and explicit security headers in the HTML content. Privacy compliance is weak due to the absence of visible privacy and cookie policies and consent mechanisms. No incident response or vulnerability disclosure policies are published. Extensive third-party tracking scripts raise privacy concerns. Overall, the website is professional and functional with good business credibility but requires improvements in privacy compliance and security hardening to reduce risk and enhance user trust.

80
70
17
70
82
60
100
experiencegoldcoastholidayspackagestourism+3 more
HTML5CSS3JavaScriptBootstrap 4+13

Partner Domains:

hota.com.au
partner
studygoldcoast.org.au
partner

+3 more partners

2025-07-27T18:39:06.466Z
kitsunes.dev favicon

KitsuDev

kitsunes.dev

48
TechnologyN/asmallHIGH

KitsuDev is a small-scale technology service provider specializing in hosting Forgejo instances and offering free static page hosting through its KitsuPage service. The website targets developers and small project owners who seek free and safe hosting solutions. The business model is primarily donation-supported, emphasizing community and small-scale operations. The site branding is consistent and content quality is good, focusing on clear messaging and developer-centric services. Technically, the website is built on Forgejo, a modern Git forge platform, with standard web technologies including JavaScript, HTML5, and CSS3. The site performs well with fast loading times and good mobile optimization. Accessibility is basic but functional. SEO practices are present but could be enhanced. The infrastructure appears modern and well-maintained, though hosting provider details are not explicitly disclosed. From a security perspective, the site enforces HTTPS and implements CSRF tokens, indicating a baseline security posture. However, it lacks explicit security headers such as Content Security Policy and HSTS, and does not provide privacy or cookie policies, which are important for compliance and user trust. No contact information or incident response channels are provided, limiting transparency. No vulnerabilities or exposed sensitive data were detected in the HTML content. Overall, the website presents a moderate risk profile with good technical foundations but gaps in privacy compliance and security best practices. Strategic improvements in policy publication, security headers, and contact transparency would enhance trust and compliance. The domain uses privacy protection, which is justified given the small-scale nature of the business. No suspicious patterns were found in WHOIS data or website content.

20
50
17
70
37
75
40
technologyhostingforgejoopensourcedeveloper
ForgejoJavaScriptHTML5CSS3
2025-07-27T18:37:45.409Z
C

The Catppuccin Webring

ctp-webr.ing

59
OtherN/asmallMEDIUM

The Catppuccin Webring is a community-driven website that aggregates links to various personal and developer websites themed around the Catppuccin aesthetic. It serves as a niche platform for enthusiasts and developers to connect and share their sites. The website is simple, primarily built with HTML and CSS, and uses the ringfairy framework to manage the webring functionality. There is no indication of commercial activity or a formal business entity behind the site. From a technical perspective, the site is lightweight and performs well with good mobile optimization and basic accessibility. However, it lacks advanced SEO features and does not implement security best practices such as HTTPS enforcement or security headers. No analytics or tracking technologies are present, indicating a privacy-conscious or minimalistic approach. Security posture is minimal; no security policies, incident response contacts, or vulnerability disclosures are provided. The absence of HTTPS confirmation and security headers lowers the security score. Privacy compliance is also lacking, with no privacy or cookie policies found. The site does not collect user data via forms or other means, reducing privacy risks but also limiting engagement. Overall, the site is safe and appropriate for general audiences, with no adult or explicit content detected. The lack of business information and policies suggests it is a hobbyist or community project rather than a commercial enterprise. Strategic recommendations include implementing HTTPS, adding privacy and cookie policies, and improving security headers to enhance trust and compliance.

30
50
2
60
95
75
100
communitywebringdeveloperpersonalsitescatppuccin
HTML5CSS3
2025-07-27T18:37:40.207Z
U

Scrumpy System

uwu.gal

59
TechnologyUnited StatessmallMEDIUM

The website 'Scrumpy System' at uwu.gal represents a small technology-focused community comprising software engineers, community managers, and web developers. The site provides a professional and visually consistent experience with clear navigation and social media integration, targeting a general audience interested in technology and software development. The business model appears to be community and service-oriented without explicit commercial transactions or e-commerce features. The domain is relatively new, created in late 2022, aligning with the site's small-scale and emerging presence. Technically, the site employs modern web technologies including HTML5, CSS3, JavaScript, Google Fonts, and FontAwesome icons. Hosting and DNS are managed via Cloudflare, ensuring good SSL configuration and moderate performance. The site is mobile optimized and includes interactive elements such as clocks and a starmap iframe. However, accessibility features are basic, and SEO is adequately addressed through meta tags and Open Graph data. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and important security headers like Content-Security-Policy. There are no published privacy, cookie, or incident response policies, which limits compliance with GDPR and other regulations. No forms or data collection mechanisms are present on the main page, reducing immediate risk but also limiting user engagement features. Overall, the website is safe and professional but would benefit from enhanced privacy and security policies, improved transparency, and additional compliance measures. Strategic recommendations include enabling DNSSEC, publishing privacy and cookie policies, adding security headers, and establishing incident response and vulnerability disclosure protocols to strengthen trust and security posture.

50
35
2
70
75
70
100
technologysoftwareengineeringcommunitywebdevelopmentopensource
HTML5CSS3JavaScriptFontAwesome+3
2025-07-27T18:36:44.892Z
tokipona.org favicon

Toki Pona (official site)

tokipona.org

45
EducationN/asmallHIGH

The website tokipona.org serves as the official hub for the Toki Pona constructed language, created by Sonja Lang in 2001. It offers comprehensive educational resources including books, dictionaries, community links, and multimedia content. The site targets language learners, conlang enthusiasts, and educators globally, positioning itself as the authoritative source for Toki Pona with recognition from ISO 639-3 and university usage. The business model is primarily informational with commercial elements through book and merchandise sales. Technically, the site employs modern frontend technologies such as Bootstrap 5, jQuery, Chart.js, and Google Fonts, hosted by Vodien Internet Solutions. Performance and mobile optimization are good, though accessibility and SEO are basic. The site uses HTTPS and Google Analytics for tracking but lacks advanced security headers and privacy/cookie policies, indicating room for compliance improvement. Security posture is moderate with no visible vulnerabilities or exposed sensitive data, but the absence of security headers and vulnerability disclosure policies are notable gaps. The domain is well-established since 2001, registered with a reputable registrar, and shows no suspicious patterns, supporting legitimacy. Overall, the site is professional, content-rich, and trustworthy but should enhance privacy compliance and security best practices to improve user trust and regulatory adherence.

15
35
17
85
62
70
-
languageconstructedlanguagetokiponaeducationcommunity+2 more
HTML5CSS3Bootstrap 5.3.7jQuery 3.7.1+3
2025-07-27T18:34:08.883Z
P

Private by Design, LLC

starlightnet.work

47
TechnologyUnited StatessmallHIGH

The Starlight Network is a small, privacy-focused technology and community project operated by two individuals, Alexia and Nelson. The website serves as a platform for their blog posts, community engagement, and hosting of services that emphasize privacy, decentralization, and usability. The business model is community-supported, relying on donations via Liberapay, and targets technology enthusiasts interested in privacy and social interaction. The domain is newly registered in 2025 with protections to prevent unauthorized transfers or deletions, aligning with the privacy-centric ethos of the project. Technically, the website is built with basic HTML and CSS, with no detected CMS or advanced frameworks. The site is moderately optimized for performance and mobile use but lacks advanced SEO and accessibility features. No analytics or tracking scripts are present, indicating a minimal data collection approach. The hosting provider is not explicitly identified, but the domain registrar is Porkbun, known for privacy-friendly services. From a security perspective, the site lacks DNSSEC, security headers, and visible HTTPS enforcement details, which lowers its security posture. There is no published security policy or incident response information, and no cookie or privacy consent mechanisms are implemented. However, domain registration protections and the absence of suspicious content or vulnerabilities suggest a moderate security maturity level. Overall, the website is safe for general audiences, with no adult or questionable content detected. The site is professionally presented but could benefit from enhanced security measures, privacy compliance improvements, and clearer contact information to increase trust and credibility.

15
50
2
60
65
75
40
technologycommunityprivacydecentralizationblog
HTML5CSS3
2025-07-27T17:32:01.723Z
squeakable.dev favicon

(un)Squeakable Code

squeakable.dev

55
TechnologyN/asmallMEDIUM

The website squeakable.dev is a personal portfolio and blog site titled '(un)Squeakable Code'. It primarily serves as a space for the owner to share projects, blog posts, and links to related community sites. The content is minimal and informal, targeting a general audience interested in technology and personal projects. The site does not represent a commercial business entity and lacks formal business information or contact details. Technically, the site is a simple static HTML/CSS implementation without detectable CMS or advanced frameworks. There is no evidence of analytics, advertising, or tracking technologies. The site appears moderately optimized for mobile and accessibility but lacks advanced SEO features. No security headers or HTTPS status information was detected from the provided data, indicating potential areas for improvement in security posture. From a security perspective, the site does not provide privacy policies, cookie consent mechanisms, or incident response information. The WHOIS data is privacy protected, which is reasonable for a personal site. No vulnerabilities or suspicious patterns were identified, but the absence of security best practices and policies limits the overall security maturity. Overall, the site is low risk but would benefit from implementing HTTPS, security headers, privacy and cookie policies, and contact information to improve trust and compliance. The content is safe for general audiences with no adult or explicit material detected.

30
50
2
65
52
85
100
personalportfolioblogtechnologycommunity
HTML5CSS3
2025-07-27T17:31:56.704Z
catraxx.de favicon

CATRAXX

catraxx.de

38
TechnologyN/asmallHIGH

The website catraxx.de is a personal portfolio and hobbyist site belonging to an individual frontend developer and musician known as catraxx. The site showcases personal projects, music mixes, and shares insights into the author's development journey and interests. It targets frontend developers, musicians, and members of the Fediverse community, positioning itself as a niche personal brand with a focus on technology and electronic music. The business model is non-commercial, primarily serving as a creative outlet and community engagement platform. Technically, the site is built using modern static site generation technology (11ty), with a clean HTML5 and CSS3 codebase. Hosting appears to be with a German provider (kasserver.com), and the site is optimized for fast performance and good mobile experience. SEO and accessibility are basic but adequate. No CMS or analytics tools are detected, indicating a lightweight and privacy-conscious setup. From a security perspective, the site uses HTTPS as inferred from the Open Graph URL, but no explicit security headers are detected. There are no forms or data collection points, reducing attack surface. However, the absence of privacy and cookie policies, as well as lack of verified contact information, represents compliance and trust gaps. No vulnerabilities or suspicious patterns are found, but security best practices could be improved. Overall, the site is safe, professional, and trustworthy for its intended personal and community use. The main risks relate to privacy compliance and security hardening. Strategic recommendations include adding privacy and cookie policies, implementing security headers, and providing verified contact details to enhance credibility and compliance.

15
25
2
70
72
45
-
personalfrontenddevelopmentmusicfediverseportfolio+1 more
HTML5CSS311ty (Eleventy)VS Codium+1
2025-07-27T17:31:51.691Z
formfeelingfunction.com favicon

FormFeelingFunction®

formfeelingfunction.com

54
OtherN/asmallMEDIUM

FormFeelingFunction® is a newly established creative lab specializing in digital and analog product design, architectural and interior design websites, and branded merchandise. Led by Carl Barenbrug and Manu Moreale, the company emphasizes simplicity, taste, and purpose, targeting creative professionals and design enthusiasts. The business operates a small-scale e-commerce platform integrated via Shopify Buy Button, offering products such as apparel, wallpapers, and desk accessories. The website reflects a consistent and professional brand identity with good design quality and user experience. Technically, the website employs modern web standards including HTML5, CSS3, and JavaScript, with Shopify integration for commerce. Hosting is managed via Hover, and the site uses HTTPS for secure content delivery. However, there is a lack of advanced security headers and no DNSSEC enabled, which are areas for improvement. The site is mobile optimized and performs moderately well, though accessibility and SEO optimizations are basic. From a security perspective, the site lacks published privacy and cookie policies, which impacts GDPR compliance and user trust. No incident response or vulnerability disclosure information is provided. The domain is newly registered with Tucows Domains Inc., with protective domain status flags, indicating legitimate registration consistent with the business profile. No WAF or blocking mechanisms are detected, and content is safe for general audiences. Overall, the website scores moderately well in content quality and business credibility but requires enhancements in privacy compliance and security posture to improve trust and regulatory adherence.

65
50
2
55
72
75
40
creativedesigne-commerceshopifyart+1 more
Shopify Buy Button SDKCustom JavaScriptCSS3HTML5+2
2025-07-27T17:28:29.254Z