Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157326
Websites
130
Industries
113
Countries
52
Avg Score
Page 148 of 153|Showing 7351-7400 of 7637
framforum.com favicon

Framsenteret Drift AS

framforum.com

40
Non-profitNorwaysmallHIGH

Framforum is a specialized online publication operated by Framsenteret Drift AS, focusing on climate, environment, and people in the High North, particularly the Arctic region. The website serves as a communication platform for research notes, profiles, retrospectives, and editorials related to Arctic environmental research, targeting researchers, journalists, and interested public. The business operates as a non-profit entity with a clear affiliation to the Fram Centre, a recognized research center in Norway. Technically, the website is built on WordPress, utilizing common web technologies such as jQuery, Font Awesome, and Google Fonts, with Matomo and Google Tag Manager for analytics. However, the site suffers from a critical security shortfall: it lacks a valid SSL certificate and does not serve content over HTTPS, which undermines user trust and data security. While HSTS is enabled, it is ineffective without proper SSL/TLS configuration. Privacy compliance is minimal, with a privacy policy present but no cookie consent mechanism or GDPR compliance indicators. Contact information is clearly provided, enhancing business credibility. Overall, the site is content-rich and professionally designed but requires urgent security improvements to protect users and enhance trust.

70
43
17
50
82
70
-
arcticclimateenvironmentresearchnon-profit+1 more
WordPressPHPjQueryMatomo Analytics+3

Partner Domains:

framsenteret.no
partner40
2025-06-15T13:19:42.681Z
rotundasoftware.com favicon

Rotunda Software LLC

rotundasoftware.com

53
TechnologyN/asmallMEDIUM

Rotunda Software LLC is a small, self-funded technology company specializing in innovative volunteer management software solutions. Their products, including Volunteer Scheduler Pro and Ministry Scheduler Pro, serve non-profit organizations and volunteer-based groups, positioning them as a niche player in the volunteer management software market. The company emphasizes a fully remote, collaborative culture and showcases client testimonials and partnerships with reputable organizations such as The Salvation Army. Technically, the website employs modern JavaScript libraries, Google Analytics, and Google Tag Manager, hosted likely on AWS infrastructure. However, the site lacks a valid SSL certificate, resulting in insecure HTTP connections, which is a significant security concern. Privacy policies and terms of service are present on related domains but not directly on the main site, and no cookie consent mechanism is implemented. Overall, the security posture is basic with room for improvement in SSL/TLS configuration and security headers. The domain is mature and well-registered, supporting the legitimacy of the business. Strategic recommendations include implementing HTTPS, enhancing security headers, and improving privacy compliance to strengthen trust and security.

65
25
25
50
50
85
100
volunteeringsoftwarenon-profittechnologyremotework+1 more
JavaScriptjQueryGoogle AnalyticsGoogle Tag Manager+2

Partner Domains:

ministryschedulerpro.com
partnerpending
volunteerschedulerpro.com
partnerpending
2025-06-15T13:14:28.226Z
framsenteret.no favicon

Framsenteret Drift AS

framsenteret.no

40
GovernmentNorwaymediumHIGH

Framsenteret Drift AS operates as a Norwegian Arctic research center focused on interdisciplinary climate and environmental research of high international standard. The organization collaborates with numerous research institutions and partners, positioning itself as a key player in Arctic research and policy support. The website serves as a platform for disseminating research findings, hosting events, and providing information about ongoing projects and collaborations. The target audience includes researchers, policymakers, environmental stakeholders, and the general public interested in Arctic issues. Technically, the website is built on WordPress with a modern tech stack including jQuery, Font Awesome, and Matomo analytics for privacy-conscious user tracking. The site is well-structured with good SEO metadata and accessibility features, though performance is slow with a load time exceeding 12 seconds. Mobile optimization is good, and navigation is clear and professional. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical vulnerability. No modern TLS protocols are enabled, and advanced security features like OCSP stapling and session resumption are missing. The site does implement HSTS but without HTTPS, this is ineffective. No explicit security or incident response policies are found, indicating gaps in security governance. Overall, the site is trustworthy and professionally maintained with strong business credibility and content quality. However, the lack of HTTPS and security policies significantly lowers its security posture and overall risk profile. Strategic improvements in SSL/TLS deployment and security governance are recommended to enhance trust and compliance.

70
25
17
60
82
85
-
researchclimateenvironmentarcticnorway+2 more
WordPressjQueryFont AwesomeMatomo Analytics+2

Partner Domains:

framforum.com
partnerpending
ifram.no
partnerpending

+3 more partners

2025-06-15T13:10:49.353Z
dln.com.hk favicon

DLN

dln.com.hk

31
Real EstateHong KonglargeHIGH

DLN is a well-established architectural and engineering firm founded in 1972 in Hong Kong, recognized for its high-profile projects across Asia and globally. The company specializes in designing skyscrapers and complex building complexes, shaping urban landscapes with a strong market reputation. The website reflects a professional business presence with consistent branding and relevant content targeting clients in the real estate and construction sectors. Technically, the website is built on a custom PHP platform running on an Apache server with older software versions. It uses common web technologies such as jQuery and Bootstrap for frontend responsiveness and styling. However, the website lacks modern security implementations, notably missing HTTPS support and valid SSL certificates, which significantly impacts its security posture. Performance data is unavailable, but the site appears to have basic mobile optimization and SEO practices. From a security perspective, the absence of HTTPS and security headers exposes users to risks such as data interception and man-in-the-middle attacks. No privacy, cookie, or terms of service policies are present, indicating poor privacy compliance. No contact information or incident response channels are provided, limiting user trust and regulatory compliance. The WHOIS data aligns well with the business claims, showing a consistent and legitimate domain registration. Overall, the website demonstrates moderate business credibility and good content quality but suffers from critical security shortcomings and lack of privacy compliance. Strategic improvements in SSL implementation, privacy policies, and security best practices are essential to enhance trust and protect users.

15
-
-
50
-
50
100
architectureengineeringrealestatehongkongconstruction+1 more
PHP 7.3.1Apache 2.4.6OpenSSL 1.0.2k-fipsjQuery 3.5.1+5
2025-06-15T13:07:58.820Z
I

Identity Protection Service

dnsspy.io

58
TechnologyUnited KingdomsmallMEDIUM

DNS Spy is a specialized technology company offering DNS monitoring, alerting, and backup services primarily targeting organizations and individuals responsible for DNS management. The company provides a SaaS platform that enables users to monitor DNS changes, receive alerts, validate DNS configurations, and maintain DNS backups with advanced features such as AXFR zone transfer support. The website content is professionally presented with clear navigation and relevant information about the services offered. The technical infrastructure leverages modern frontend technologies including Bootstrap, Font Awesome, jQuery, and Laravel Livewire, hosted behind Cloudflare with domain registration via Amazon Registrar. However, the website currently lacks a valid SSL/TLS certificate and does not enforce HTTPS, which is a critical security vulnerability. Additionally, security headers and advanced TLS features are missing, reducing the overall security posture. Privacy compliance is partial, with a privacy policy present but no cookie policy or consent mechanism detected. Contact information is available via email and contact forms, supporting user engagement. The domain registration is mature and consistent with the business, enhancing trustworthiness. Overall, DNS Spy demonstrates a solid business and technical foundation but requires urgent improvements in security practices to protect users and data effectively.

60
43
25
55
85
80
100
dnsmonitoringdnssecuritydnsbackupdnsalertstechnology+1 more
BootstrapFont AwesomejQueryGoogle Analytics+2
2025-06-15T12:00:02.540Z
atm.cat favicon

Generalitat de Catalunya

atm.cat

66
TransportationSpainmediumMEDIUM

Autoritat del Transport Metropolità (ATM) is a public consortium under the Generalitat de Catalunya, managing integrated transport tariffs and mobility projects in the Barcelona metropolitan area. The website serves as an official portal providing comprehensive information about transport tariffs, mobility plans, transparency, and customer support. It targets residents and public transport users in Catalonia, offering multilingual content and links to related government services. The business model is public sector focused, emphasizing transparency and service delivery rather than commercial revenue. Technically, the website is built on the Liferay CMS platform with modern web technologies including React and Bootstrap. While the site is content-rich and accessible, performance is hindered by a high load time and large page size. The site is mobile optimized and includes accessibility features. SEO and metadata are well implemented, including Open Graph tags. Security posture is adequate with HTTPS enforced, valid SSL certificates, and email authentication via DMARC and SPF. However, advanced security headers like HSTS and DNSSEC are missing, and domain protection locks are not enabled, which could be improved. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with clear cookie and privacy policies and consent mechanisms. Overall, the site is trustworthy and professionally maintained, reflecting its governmental nature. Recommendations include enhancing security headers, enabling DNSSEC, improving performance, and adding explicit security and incident response policies to further strengthen trust and compliance.

65
25
25
50
92
70
100
transportpublicsectormobilitygovernmentcatalonia+2 more
Liferay PortaljQueryBootstrapFont Awesome+9
2025-06-15T09:59:21.656Z
migachain.com favicon

Migastone International Srl

migachain.com

37
TechnologySan MarinosmallHIGH

Migachain.com is a specialized technology service offering blockchain notarization and IPFS file storage via an API webservice. The company behind it, Migastone International Srl, is based in San Marino and has expertise in mobile app development, positioning Migachain as a niche player in blockchain notarization services. The website content is professionally structured, targeting developers and professionals needing secure document notarization and decentralized file storage. The business model is subscription-based with clear pricing plans and affiliate programs. Technically, the website is built on the Kartra platform using Bootstrap and standard web technologies. However, performance metrics are lacking, and the SSL/TLS configuration is critically deficient, with no valid certificate or modern TLS protocols enabled. This severely impacts the security posture and trustworthiness of the site. Privacy and cookie policies exist but are basic, with limited GDPR compliance indicators. Contact information is limited to a physical address and contact form, with no direct emails or phone numbers provided. Security-wise, the site lacks a valid SSL certificate, modern TLS support, and advanced security headers. No incident response or vulnerability disclosure policies are found. While the site uses some security headers like HSTS and X-Content-Type-Options, the absence of HTTPS is a critical vulnerability. The overall risk is moderate to high due to these security gaps. Strategically, the company should prioritize obtaining and maintaining a valid SSL certificate and enabling modern TLS protocols to secure user data and improve trust. Enhancing privacy compliance and publishing clear security policies would further strengthen the security posture and business credibility.

35
58
25
50
50
75
-
blockchainethereumnotarizationipfsapi+1 more
LiteSpeed serverBootstrap CSSFont AwesomeGoogle Fonts+3
2025-06-15T08:49:07.210Z
unibo.it favicon

ALMA MATER STUDIORUM - Università di Bologna

unibo.it

39
EducationItalylargeHIGH

The Università di Bologna (University of Bologna) is a historic and prestigious public university based in Italy, recognized as the oldest university in the Western world. The website serves as a comprehensive portal offering extensive academic programs, research information, student services, and community engagement resources. It targets students, researchers, academic staff, and the general public, positioning itself as a leading institution in higher education. The business model focuses on education, research, and societal contribution, with a large organizational size and a strong market position in the education sector. Technically, the website is built on the Plone CMS platform, served by an Nginx server on Ubuntu, and utilizes modern web technologies including jQuery, Leaflet.js for maps, Splide.js for carousels, and Font Awesome for icons. Analytics are handled primarily via Matomo and Contentsquare, indicating a moderate level of user tracking with privacy compliance measures in place. The site is well-structured, mobile-optimized, accessible, and SEO-friendly, providing an excellent user experience. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical vulnerability. Other security headers like X-Frame-Options and X-Content-Type-Options are present, but the absence of HTTPS and modern TLS protocols significantly lowers the security posture. No WAF or content blocking mechanisms are detected, and no immediate vulnerabilities or exposed sensitive data are found. Overall, the site is highly credible and professional, with strong business legitimacy and comprehensive content. However, the lack of proper SSL/TLS configuration poses a significant risk that should be addressed promptly to protect user data and maintain trust.

40
-
-
50
-
85
100
educationuniversityresearchacademicitaly+1 more
nginxPlone CMSjQueryLeaflet.js+4
2025-06-15T08:35:29.115Z
interperformances.com favicon

Interperformances

interperformances.com

24
OtherN/asmallCRITICAL

Interperformances.com is a mature and established sports agency specializing in basketball player management, contract negotiation, marketing, and post-career planning. The website targets professional basketball players, agents, coaches, and teams globally. The business model is focused on athlete representation and sports management services. The company has a consistent brand presence and active social media engagement, supporting its market position as a recognized agency in the basketball sports sector. Technically, the website employs a variety of modern front-end libraries such as jQuery, Bootstrap, and Slick Carousel, hosted behind Cloudflare DNS services. However, the site suffers from slow load times and lacks HTTPS support, which is a significant technical and security deficiency. Mobile optimization is good, but accessibility and SEO optimizations are basic. From a security perspective, the absence of a valid SSL certificate and HTTPS support is a critical vulnerability that exposes users to risks such as data interception. The lack of security headers, HSTS, and OCSP stapling further weakens the security posture. No privacy or cookie policies are present, indicating poor compliance with data protection regulations. Incident response and vulnerability disclosure mechanisms are also missing. Overall, the website presents moderate business credibility but requires urgent improvements in security and privacy compliance to protect users and enhance trust. Strategic recommendations include implementing HTTPS, adding security headers, publishing privacy and cookie policies, and establishing incident response contacts.

20
-
5
85
-
80
-
sportsbasketballagencyplayersmanagement+2 more
jQueryBootstrapFont AwesomeSimple Line Icons+3

Partner Domains:

interferenza.net
partnerpending
2025-06-15T08:35:25.209Z
paddioinsurance.com favicon

Paddio Insurance

paddioinsurance.com

49
OtherUnited StatessmallHIGH

Paddio Insurance is a small insurance agency operating primarily in the United States, offering a broad range of insurance products including home, auto, renters, and specialty insurance lines. The company partners with major insurance carriers and provides customers with competitive quotes and personalized service. Their website reflects a professional and consistent brand image, targeting individuals and families seeking insurance coverage. The business model relies on partnerships and referral programs to expand its market reach. Technically, the website is built on a traditional stack using nginx, Bootstrap 3, jQuery, and integrates third-party marketing and analytics tools such as Google Analytics and Marketo Munchkin. Hosting is on AWS infrastructure. While the site is mobile responsive and SEO optimized with structured data, performance metrics are missing, and some accessibility features are basic. The site uses embedded forms for lead capture but lacks modern CMS indications. From a security perspective, the website has significant weaknesses. It lacks a valid SSL certificate and does not serve content over HTTPS, exposing users to potential interception risks. Security headers are minimal or absent, and no advanced SSL features like HSTS or OCSP stapling are enabled. Privacy compliance is partial, with a privacy policy and terms of use present but no cookie consent mechanism or GDPR compliance indicators. Contact information is clearly provided, but no incident response or security policy details are available. Overall, the website is functional and professional but requires urgent improvements in security posture, especially enabling HTTPS and implementing security headers. Privacy compliance should be enhanced with cookie policies and consent mechanisms. These steps will improve user trust, regulatory compliance, and reduce risk exposure.

15
43
25
50
50
85
100
insurancehomeinsuranceautoinsuranceinsurancequotesinsuranceagency+1 more
nginxPleskLinBootstrap 3jQuery+5

Partner Domains:

policygenius.com
partnerpending
ezlynx.com
partnerpending
2025-06-14T22:22:36.582Z
veteran.com favicon

Three Creeks Media, LLC

veteran.com

63
MediaUnited StatessmallMEDIUM

Veteran.com is a specialized media website operated by Three Creeks Media, LLC, providing comprehensive information and tools related to military pay, veteran benefits, and related financial resources. The site targets US military veterans, active duty members, reservists, and their families, offering calculators, discount listings, and educational content to assist users in navigating complex military and VA benefits. The business model relies heavily on content marketing, affiliate partnerships, and advertising revenue, positioning itself as a trusted resource within the veteran community. Technically, the website is built on WordPress and leverages common web technologies such as jQuery, Chart.js, and Font Awesome, with Cloudflare providing hosting and CDN services. SEO is enhanced through Yoast SEO, and Google Tag Manager is used for analytics and marketing tracking. However, performance data is missing, and the site exhibits slow loading characteristics. Mobile optimization is good, but accessibility features are basic. From a security perspective, the site has several critical issues: it lacks a valid SSL certificate and does not support modern TLS protocols, severely impacting secure communications. While some security headers are implemented, the ineffective HSTS configuration and malformed CAA DNS records further weaken the security posture. No cookie consent mechanism is present despite the use of tracking and advertising scripts, raising privacy compliance concerns. Overall, Veteran.com is a content-rich and professionally presented site with moderate trustworthiness and business credibility. However, its security and privacy compliance shortcomings present risks that should be addressed to protect user data and enhance user trust. Strategic improvements in SSL/TLS deployment, cookie consent implementation, and DNS record hygiene are recommended to elevate the site's security and compliance standing.

75
43
25
50
92
90
100
veteranmilitarybenefitsvaloansmilitarypaydiscounts+1 more
WordPressjQueryChart.jsFont Awesome+3

Partner Domains:

threecreeksmedia.com
parentpending
2025-06-14T22:10:58.364Z
lecepe.fr favicon

Ensae-Ensai Formation Continue (Cepe)

lecepe.fr

40
EducationFrancemediumHIGH

Ensae-Ensai Formation Continue (Cepe) is a well-established continuing education center affiliated with the Groupe des écoles nationales d'économie et statistique (Genes) in France. It specializes in providing professional training and certification programs in statistics, data science, finance, and economics. The organization maintains strong partnerships with prestigious institutions such as Ensae Paris, Ensai, Crest, and Institut Polytechnique de Paris, positioning itself as a reputable education provider in its sector. The website reflects a professional and comprehensive approach to education, targeting professionals and learners seeking advanced skills and certifications in quantitative fields. Technically, the website employs modern web technologies including Bootstrap, jQuery, Font Awesome, and integrates third-party services like Google Analytics and Calendly for analytics and scheduling. Hosting is managed through Gandi, and the site uses a valid SSL certificate with strong key length, although some security enhancements such as HSTS and DNSSEC are absent. Performance is moderate to slow due to a large number of resources and page size, but mobile optimization and accessibility are adequately addressed. From a security perspective, the site uses HTTPS with a valid certificate and implements cookie consent mechanisms aligned with GDPR requirements. However, it lacks several security headers and DNS security features that could improve its security posture. No critical vulnerabilities or blocking mechanisms were detected, indicating a stable and secure environment for users. Privacy policies and terms of service are clearly available, enhancing compliance and user trust. Overall, the website demonstrates a strong business credibility and professional presence with room for technical and security improvements. Strategic recommendations include enhancing security headers, enabling DNSSEC and CAA, optimizing performance, and publishing incident response information to further strengthen trust and compliance.

20
-
17
50
82
85
100
educationtrainingdatasciencestatisticsfinance+3 more
BootstrapjQueryFont AwesomeGoogle Analytics+2

Partner Domains:

ensae.fr
partner40
ensai.fr
partner40

+3 more partners

2025-06-14T21:59:29.791Z
transdevna.com favicon

Transdev United States

transdevna.com

64
TransportationUnited StateslargeMEDIUM

Transdev United States operates as the largest private sector operator of multiple modes of transit in North America, providing services including bus, paratransit, rail, health solutions, microtransit, shuttle, autonomous mobility, fleet services, and ferry operations. The company targets public transportation clients and transit authorities, positioning itself as a leading integrator and operator in the transportation sector. The website reflects a large, well-established enterprise with a focus on safety, innovation, and sustainability. Technically, the site is built on WordPress with a modern tech stack including WPBakery Page Builder, jQuery, and Google services, hosted on WP Engine with Cloudflare CDN. Performance is fast, mobile optimization is good, and accessibility features are implemented via third-party tools. Security posture is strong with HTTPS, modern TLS protocols, CSP, and secure cookie settings, though improvements such as enabling HSTS and DNSSEC are recommended. Privacy compliance is addressed with a comprehensive privacy policy and cookie consent mechanism. Overall, the website is professional, trustworthy, and well-structured, supporting the company's market position and business model effectively.

30
43
25
50
57
75
100
transportationpublictransitmobilityaccessibilitysafety+1 more
WordPressWPBakery Page BuilderjQueryGoogle Fonts+6

Partner Domains:

transdevna.jobs
servicepending
2025-06-14T21:57:19.561Z
tny.app favicon

Chief Tools

tny.app

67
TechnologyNetherlandssmallMEDIUM

Tny.app is a technology-driven URL shortening service operated by Chief Tools, a Dutch company. The platform offers a range of subscription plans and add-ons targeting individuals and businesses who require fast, secure, and customizable link shortening solutions. The service integrates with popular automation platforms such as Make, Zapier, and IFTTT, enhancing its appeal to tech-savvy users and enterprises seeking workflow automation. The website is professionally designed with clear navigation and good content relevance, supporting a positive user experience. The business model is subscription-based with tiered offerings and additional paid features, positioning Tny.app as a competitive player in the niche URL management market. Technically, the website employs modern JavaScript frameworks like Alpine.js and uses Cloudflare for DNS and hosting infrastructure. While the SSL certificate is valid and HTTPS is enforced, the site lacks some advanced security headers and HSTS enforcement, which could improve its security posture. Performance is suboptimal with a relatively slow load time, likely due to a high number of resources. Accessibility and SEO are adequately addressed, though cookie consent mechanisms are missing despite GDPR compliance claims. From a security perspective, Tny.app demonstrates good baseline practices including SPF and DMARC email protections, valid SSL, and no detected vulnerabilities or subdomain takeover risks. However, the absence of a published security policy, vulnerability disclosure program, and data protection officer contact information indicates room for maturity improvement. Incident response contact is available via an abuse page with a dedicated email address. Overall, the security posture is solid but could benefit from enhanced transparency and additional security controls. The overall risk assessment is moderate with no critical issues detected. Strategic recommendations include enabling HSTS, implementing cookie consent, publishing security policies, and improving performance. These steps will enhance trust, compliance, and resilience, supporting Tny.app's growth and reputation in the competitive URL shortening market.

80
40
25
65
67
70
100
urlshortenerlinkmanagementprivacyautomationcustomdomains+1 more
Alpine.jsFont AwesomeGraphQLREST API+2

Partner Domains:

chief.app
parent68
2025-06-14T21:56:59.093Z