Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 149 of 166|Showing 7401-7450 of 8294
veevaconnect.com favicon

Veeva Systems

veevaconnect.com

74
TechnologyN/aenterpriseMEDIUM

Veeva Connect is a digital engagement platform likely operated by Veeva Systems, targeting enterprise clients in the life sciences or pharmaceutical sectors. The website serves as a portal or interface for their SaaS offerings, leveraging modern web technologies such as React and AWS CloudFront CDN for content delivery. The platform integrates third-party services like Wistia for video and Google Maps API for location services. From a technical perspective, the website demonstrates a solid security posture with HTTPS enforced, strong security headers including a nonce-based Content Security Policy, and no evident vulnerabilities. However, the site lacks visible privacy and cookie policies, contact information, and terms of service, which are important for compliance and user trust. The content on the landing page is minimal, suggesting the site is a single-page application requiring user authentication or further navigation to access substantive content. The domain registration is consistent and trustworthy, with a mature domain age of 5 years, registered through a reputable registrar without privacy protection, aligning with the business's founding date. No suspicious patterns or vulnerabilities were detected in the DNS or SSL configurations. Overall, the site is technically sound but could improve transparency and compliance aspects. Strategic recommendations include implementing comprehensive privacy and cookie policies with consent mechanisms, publishing contact information and incident response channels, enabling HSTS preload, and adding a vulnerability disclosure policy to enhance security culture and trustworthiness.

80
40
25
60
92
80
100
technologydigitalengagemententerprisesaassecurity+1 more
JavaScriptReact (implied by react-main div)CloudFront CDNWistia video API+3
2025-06-16T16:31:30.295Z
burgenlandenergie.at favicon

Burgenland Energie

burgenlandenergie.at

40
EnergyAustrialargeHIGH

Burgenland Energie is a regional energy provider based in Austria, specializing in renewable energy solutions such as photovoltaic systems, battery storage, heat pumps, and e-mobility services. The company targets private customers and municipalities within the Burgenland region, emphasizing energy independence and sustainability. Their market position is that of a trusted regional leader in renewable energy, supported by a comprehensive portfolio of products and services tailored to modern energy needs. Technically, the website is built on modern frameworks including React and Next.js, hosted on AWS infrastructure with Amazon S3 and CloudFront for content delivery. The site demonstrates strong digital maturity with fast performance, mobile optimization, and good SEO practices. Integration with marketing and analytics tools like Google Tag Manager and Zoho CRM is implemented with user privacy in mind, including cookie consent mechanisms. From a security perspective, the site enforces HTTPS with a valid SSL certificate and uses AWS KMS for server-side encryption. OCSP stapling is enabled, but HTTP security headers like HSTS are not fully implemented, representing an area for improvement. No critical vulnerabilities or exposed sensitive data were detected. Privacy policies and terms of service are present and comprehensive, supporting GDPR compliance. Overall, the website presents a professional, trustworthy, and secure digital presence aligned with the company's business objectives. Strategic recommendations include enhancing HTTP security headers, continuous monitoring of third-party scripts, and maintaining strong privacy compliance to further strengthen user trust and security posture.

15
18
25
50
82
85
100
energyrenewablephotovoltaicbatteriesheatpumps+3 more
ReactNext.jsAmazon S3CloudFront+3

Partner Domains:

befunkt.at
partner37
fcbe.at
partner38

+2 more partners

2025-06-16T16:23:11.551Z
integritycounts.ca favicon

IntegrityCounts

integritycounts.ca

65
OtherN/asmallMEDIUM

IntegrityCounts operates a confidential and anonymous ethics reporting system aimed at organizations requiring secure ethics reporting solutions. The website is minimalistic, built using React and hosted on Microsoft Azure, indicating a modern but basic technical infrastructure. The site lacks visible content beyond the root container and does not provide privacy, cookie, or terms of service policies, nor contact information, which limits user engagement and trust. From a security perspective, the website enforces HTTPS with a valid SSL certificate and implements several important security headers such as Content-Security-Policy and X-Frame-Options. However, the absence of enabled HSTS, support for deprecated TLS 1.1, and lack of OCSP stapling reduce the overall security posture. No vulnerabilities or exposed sensitive data were detected, but the security configuration could be improved to meet best practices. Overall, the website presents a moderate risk profile due to limited content, lack of compliance documentation, and partial security best practices. The domain registration and DNS setup are consistent with a legitimate business presence, but the absence of contact details and policies impacts credibility and privacy compliance. Strategic improvements in transparency, security hardening, and user engagement are recommended to enhance trust and compliance.

85
25
25
50
72
85
100
ethicsreportinganonymousconfidentialsecurity+1 more
ReactJavaScript
2025-06-16T16:20:12.116Z
pinterest.info favicon

Pinterest

pinterest.info

40
TechnologyUnited StatesenterpriseHIGH

Pinterest is a leading visual discovery and social media platform that enables users to explore and save creative ideas across various categories such as recipes, home decor, fashion, and more. The platform serves a broad audience including individual users, content creators, and businesses seeking advertising opportunities. Pinterest operates on an advertising-based business model with integrated e-commerce features, positioning itself as a key player in the technology and social media industry. The website demonstrates a high level of digital maturity with a modern tech stack primarily based on React and extensive use of cloud services and CDNs for content delivery. The design and user experience are professional and optimized for both desktop and mobile users, ensuring accessibility and SEO best practices are followed. Security-wise, the site implements several important HTTP security headers and a comprehensive content security policy, but it currently suffers from an invalid or missing SSL certificate and lacks support for modern TLS protocols, which significantly impacts its security posture. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms in place. Overall, Pinterest's website is trustworthy and professional, but immediate attention is required to resolve SSL and TLS issues to enhance security and user trust.

80
25
17
65
-
90
100
socialmediavisualdiscoveryadvertisinge-commercetechnology
ReactJavaScript ES6+WebAssemblyAmazon S3+4
2025-06-16T11:09:36.584Z
J

Johnson & Johnson Vision

amo-inc.com

59
HealthcareUnited StatesenterpriseMEDIUM

Johnson & Johnson Vision operates a professional website focused on refractive surgery and related eye health products. The company is a recognized leader in the ophthalmology healthcare sector, offering advanced surgical technologies such as iLASIK and femtosecond lasers. The website targets eye health professionals, providing detailed product information, educational resources, and access to ordering and support services. The business is positioned as a market leader with a strong brand presence and extensive industry experience under the Johnson & Johnson umbrella. Technically, the website leverages modern web frameworks including Next.js and React, integrates advanced analytics and marketing tools such as Google Tag Manager, Optimizely, and WalkMe, and employs robust cookie consent management via OneTrust. The site is well-optimized for mobile devices and accessibility, with good SEO practices and performance metrics. From a security perspective, the site enforces HTTPS, uses security headers, and integrates Google reCAPTCHA Enterprise to protect forms. Privacy compliance is strong, with clear privacy and cookie policies and user consent mechanisms. However, there is no explicit security policy or incident response contact information published, which could be improved. Overall, the website demonstrates a mature digital presence with strong business credibility and security posture. Strategic recommendations include publishing a dedicated security policy, providing incident response contacts, and considering a vulnerability disclosure program to enhance transparency and trust.

70
63
5
70
-
80
100
refractivesurgeryhealthcareophthalmologymedicaldevicesprivacy+2 more
ReactNext.jsGoogle Tag ManagerGoogle reCAPTCHA Enterprise+3

Partner Domains:

productcomplaintcenter.jnj.com
service
jjvisionmedicalaffairs.com
service

+1 more partners

2025-06-15T22:26:26.899Z
nhm.ac.uk favicon

The Natural History Museum

nhm.ac.uk

40
EducationUnited KingdomlargeHIGH

The Natural History Museum website serves as a comprehensive digital portal for one of the UK's leading educational and cultural institutions. It offers extensive information on exhibitions, scientific research, educational resources, and visitor services, targeting a broad audience including the general public, educators, and researchers. The site is well-branded, professionally designed, and provides clear navigation and rich content relevant to its mission. Technically, the website leverages modern web technologies such as React with Next.js and Adobe Experience Manager as its CMS, hosted on Microsoft Azure. While the site is mobile-optimized and accessible, performance is currently hindered by an invalid SSL certificate and lack of enabled TLS protocols, which also impacts the security posture. Security-wise, the site implements some security headers like HSTS and X-Frame-Options but lacks a valid SSL certificate and proper TLS support, which are critical for secure communications. Privacy and cookie policies are comprehensive and GDPR compliant, with a clear consent mechanism in place. Social media integration and tracking tools like Google Tag Manager and Adobe DTM are used responsibly with privacy considerations. Overall, the website is trustworthy and professional but requires urgent remediation of SSL and TLS issues to ensure secure user interactions and improve its security score. Strategic improvements in SSL management and security best practices will enhance user trust and compliance.

45
-
5
50
-
85
100
museumeducationsciencenaturalhistoryuk+1 more
React (Next.js)Adobe Experience Manager (AEM)Google Tag ManagerAdobe DTM (Dynamic Tag Management)+3
2025-06-15T22:12:49.186Z
B

Burgenland Energie

bewag.at

40
EnergyAustriamediumHIGH

Burgenland Energie is a regional energy provider based in Austria, specializing in renewable energy solutions such as photovoltaic systems, battery storage, heat pumps, and e-mobility services. The company targets private customers, municipalities, and businesses within the Burgenland region, emphasizing energy independence and sustainability. Their digital presence includes a professional website with comprehensive product information, customer portals, and active social media channels. Technically, the website is built using modern web technologies including React and Next.js, hosted on AWS infrastructure with CloudFront and S3. While the site is mobile-optimized and well-structured for SEO and accessibility, performance metrics indicate slow loading times, which could be improved. The use of Google Tag Manager and Zoho CRM scripts indicates integration with marketing and customer relationship management tools. From a security perspective, the website lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability that undermines user trust and data security. Other security best practices such as HSTS, OCSP stapling, and session resumption are also missing. Privacy compliance is well addressed with clear privacy and cookie policies and a consent mechanism in place. Overall, the website presents a trustworthy and professional business with strong content and user experience but requires urgent improvements in SSL/TLS configuration to enhance security posture and protect user data effectively.

-
-
-
50
-
50
100
energyrenewableenergyphotovoltaicbatteriesheatpumps+4 more
ReactNext.jsAmazon S3AWS KMS encryption+2

Partner Domains:

befunkt.at
partnerpending
fcbe.at
partnerpending

+3 more partners

2025-06-15T22:07:39.279Z
peschkedesign.at favicon

Peschke

peschkedesign.at

31
TechnologyAustriamediumHIGH

Peschke Design GmbH is a well-established design agency based in Vienna, Austria, specializing in product design, UX/UI, app development, 3D visualization, and industrial design. With over 50 years of experience and a strong portfolio of reputable clients such as Carl Zeiss AG, ENGEL AUSTRIA GmbH, and Austrian Airlines, the company positions itself as a trusted partner for digital transformation and innovative design solutions. Their business model focuses on delivering comprehensive design and development services tailored to client needs, supported by a professional and content-rich website that targets businesses seeking high-quality design expertise. Technically, the website is built on WordPress, hosted on WP Engine, and uses Cloudflare as a CDN and proxy. It employs modern web technologies including React, jQuery, and Swiper.js, and supports multilingual content via WPML. SEO and accessibility are well addressed with Yoast SEO and adherence to WCAG guidelines. However, performance metrics are not available, though mobile optimization and navigation clarity are good. From a security perspective, the site lacks a valid SSL certificate and does not serve content over HTTPS, which is a critical vulnerability. No TLS protocols are enabled, and security headers are minimal. While cookies are set with secure and HttpOnly flags, the absence of HTTPS exposes users to potential interception risks. Privacy compliance is strong with GDPR-aligned policies and a cookie consent mechanism. No explicit security or incident response policies are published. Overall, the website demonstrates high professionalism and business credibility but suffers from a critical security misconfiguration regarding SSL/TLS. Addressing this would significantly improve the security posture and trustworthiness of the site.

15
-
-
50
-
50
100
designuxuiproductdesignindustrialdesign+5 more
WordPressWP EngineCloudflareGoogle Tag Manager+8
2025-06-15T22:05:14.403Z
aplaceformom.com favicon

A Place for Mom

aplaceformom.com

40
HealthcareUnited StateslargeHIGH

A Place for Mom is a leading senior living referral service that connects families with assisted living, memory care, independent living, home care, nursing homes, and other senior care options. The company operates a large network of communities and home care providers, offering personalized support through expert advisors at no cost to families. Their market position is strong, supported by extensive consumer reviews, award recognitions, and a broad geographic presence across major US cities. Technically, the website is built on modern frameworks such as Next.js and React, leveraging AWS CloudFront for content delivery and integrating advanced analytics and marketing tools like Segment, Optimizely, and Drift. The site demonstrates good mobile optimization, accessibility, and SEO practices, providing a professional and user-friendly experience. However, the security posture is currently weak due to the absence of a valid SSL certificate and lack of HTTPS support, which is a critical vulnerability. While security headers are properly configured, the lack of TLS protocols and OCSP stapling reduces overall security. Privacy compliance is well addressed with comprehensive policies and consent mechanisms. Overall, the website presents a trustworthy and professional front for its business but requires urgent improvements in SSL/TLS implementation to ensure secure user interactions and maintain trust. Strategic recommendations include immediate SSL certificate installation, enabling modern TLS protocols, and enhancing DNS security measures.

95
18
-
50
-
85
100
seniorlivingassistedlivingmemorycarenursinghomeshomecare+3 more
Next.jsReactSegment AnalyticsOptimizely+3
2025-06-15T22:04:04.687Z
C

CME Group Inc.

cmegroup.com

40
FinanceUnited StatesenterpriseHIGH

CME Group Inc. operates as a leading global derivatives marketplace, offering a diverse range of futures and options products for risk management across multiple asset classes including agriculture, energy, equity indices, FX, interest rates, and metals. The company serves a broad audience of traders, investors, and financial institutions, providing comprehensive market data, clearing services, and technology solutions. The website reflects a mature, enterprise-level organization with consistent branding and high-quality content tailored to its professional audience. Technically, the website leverages modern technologies such as React, jQuery, and Adobe Experience Manager, hosted via Akamai CDN, and integrates various marketing and analytics tools including Google Tag Manager, Evergage, and OneTrust for cookie consent. The site is well-optimized for mobile and accessibility, with good SEO practices evident in meta tags and structured data. From a security perspective, while the site employs important security headers and cookie protections, the SSL/TLS configuration appears incomplete or misreported in the provided data, lacking valid certificates and modern protocol support. This represents a significant security concern that should be addressed promptly to ensure secure communications and user trust. Overall, CME Group's website is professional, content-rich, and business credible, but requires immediate attention to its SSL/TLS implementation to align with best security practices and maintain its high trustworthiness in the financial sector.

45
33
2
50
-
85
100
financederivativesfuturesoptionsriskmanagement+3 more
ApachejQueryReactAkamai CDN+7
2025-06-15T22:03:46.584Z
insighttsi.com favicon

Insight Technology Solutions, LLC

insighttsi.com

40
GovernmentUnited StatesmediumHIGH

Insight Technology Solutions, LLC is a well-established Federal contractor headquartered in the National Capital Region, with over 20 years of experience delivering management consulting, business operations, and engineering solutions to Federal agencies. The company holds multiple government contract vehicles and certifications such as ISO 9001:2015, ISO/IEC 20000-1:2018, and CMMI Maturity Level 3, demonstrating a commitment to quality and compliance. Their target audience primarily includes U.S. government agencies, particularly in sectors like maritime, IT, and cybersecurity services. Technically, the website is built on the Wix platform utilizing modern JavaScript frameworks like React and includes various Wix apps for enhanced functionality. While the site is moderately optimized for performance and basic mobile responsiveness, there is room for improvement in accessibility and SEO practices. The hosting is managed by Wix, with standard security headers present, but the SSL certificate is currently invalid, which poses a significant security risk. From a security perspective, the site implements some best practices such as HSTS and secure cookie attributes but lacks a valid SSL certificate and comprehensive security headers. No vulnerabilities or exposed sensitive data were detected, but the absence of a cookie consent mechanism and privacy compliance indicators suggests partial adherence to privacy regulations. Overall, the website presents a professional and trustworthy image with clear business information and contact details. However, critical security improvements, especially regarding SSL certification and privacy compliance, are necessary to enhance trust and protect user data effectively.

35
-
5
50
-
85
100
federalcontractorgovernmentservicesmaritimeengineeringitservicescybersecurity+3 more
Wix platformJavaScriptReactWix Pro Gallery+4
2025-06-15T22:00:50.765Z
f-secure.com favicon

F-Secure Corporation

f-secure.com

40
TechnologyFinlandlargeHIGH

F-Secure Corporation is a well-established Finnish cybersecurity company with over 35 years of experience and a global user base exceeding 30 million. The company offers a comprehensive suite of cybersecurity products including antivirus, VPN, identity protection, and scam protection, targeting both consumers and service providers. Their business model is subscription-based, emphasizing digital security and privacy. The website is professionally designed, multilingual, and rich in content, reflecting a mature digital presence. Technically, the site uses modern frameworks like Next.js and is hosted on Netlify, with good mobile optimization and SEO practices. However, the current SSL/TLS configuration is invalid or missing, which is a critical security concern that needs immediate remediation. Security headers are properly set, but the lack of valid HTTPS reduces the overall security posture. The site complies with GDPR and provides comprehensive privacy and cookie policies. Overall, the domain registration and WHOIS data align well with the company's identity, supporting high legitimacy and trust. Strategic recommendations include renewing SSL certificates, enabling modern TLS protocols, and enhancing security best practices to improve trust and compliance.

-
-
-
50
-
90
100
cybersecurityprivacyvpnantivirusidentityprotection+3 more
Next.jsReactNetlify hostingGoogle Tag Manager+1

Partner Domains:

vodafone.com
partner71
virginmedia.com
partner61

+2 more partners

2025-06-15T22:00:43.295Z
blue-tomato.com favicon

Blue Tomato

blue-tomato.com

71
RetailGermanylargeMEDIUM

Blue Tomato is a well-established European e-commerce and retail company specializing in boardsport and lifestyle products including snowboarding, skateboarding, surfing, freeski, and streetwear. With over 30 years of experience and more than 70 physical shops across Europe, the company offers a comprehensive product range from over 500 brands, supported by community engagement and specialized services such as snowboard schools and rental shops. The website is professionally designed, highly localized, and optimized for performance and user experience across devices. Technically, the website employs modern web technologies including React and Preact frameworks, utilizes Cloudflare for hosting and security, and integrates advanced analytics and consent management tools. The site demonstrates good SEO and accessibility practices, ensuring broad reach and compliance with relevant regulations. From a security perspective, the site uses a valid SSL certificate but lacks modern TLS protocol support and some security headers like HSTS and OCSP stapling. No critical vulnerabilities were detected, but improvements are recommended to enhance security posture. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Overall, Blue Tomato presents a low-risk profile with strong business credibility, good technical infrastructure, and adequate security measures. Strategic recommendations include enhancing SSL/TLS configurations, enabling additional security headers, and implementing domain protection locks to further secure the domain registration.

-
43
30
55
100
70
100
e-commerceboardsportlifestyleretailsnowboard+4 more
ReactPreactCloudflareConsentManager+4

Partner Domains:

zumiez.com
partnerpending
puresurfcamps.com
partnerpending
2025-06-15T21:59:08.026Z