Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 150 of 248|Showing 7451-7500 of 12372
I

Institut pro testování a certifikaci, a.s., Zlín

nlfnorm.cz

42
GovernmentCzech RepublicsmallHIGH

The website nlfnorm.cz serves as an official information system for the introduction of products to the market in the Czech Republic. It is operated by the Institut pro testování a certifikaci, a.s., Zlín, a recognized testing and certification institute. The site provides access to harmonized standards databases, terminological dictionaries, and legislative updates relevant to product compliance and market entry. Its target audience includes regulatory bodies, manufacturers, certification authorities, and professionals involved in product compliance. The business model is primarily informational, supporting regulatory compliance and market transparency. From a technical perspective, the website employs a traditional technology stack including jQuery, jQuery UI, and Google Analytics for tracking. The site appears to be custom-built or uses an unknown CMS, with moderate performance and basic mobile optimization. SEO and accessibility features are present but could be improved. The site uses HTTPS and includes a cookie consent banner, indicating some level of privacy compliance. Security posture is moderate; while HTTPS is used and cookie consent is implemented, no explicit security headers were detected in the provided data. There are no visible forms or input fields that might expose vulnerabilities, but the absence of privacy and security policies and contact information for incident response reduces overall security maturity. No WAF or blocking mechanisms were detected, and the domain registration is consistent with the business history, supporting legitimacy. Overall, the website is professional, trustworthy, and serves its informational purpose well. However, improvements in privacy policy publication, security headers implementation, and contact information transparency would enhance compliance and security posture. The site is safe for general audiences with no adult or questionable content.

15
25
17
70
62
75
-
governmentnormscertificationproductregulationczechrepublic+2 more
jQuery 1.12.4jQuery UI 1.10.3Chosen jQuery pluginGoogle Analytics+3
2025-07-10T16:05:41.459Z
D

DLC Websites

whatarecookies.com

58
TechnologyN/asmallMEDIUM

WhatAreCookies.com is an educational website focused on providing detailed information about computer cookies, their usage, security implications, and browser cookie management. The site targets general internet users seeking to understand cookies and offers tools such as cookie checkers and guides on enabling, deleting, and viewing cookies. The business model appears to be advertising-supported, primarily through Google Adsense, with additional marketing tools like AddThis for social sharing. The website has been operational since at least 2002, as indicated by copyright notices, but domain registration data is missing or unavailable, which raises concerns about domain legitimacy. Technically, the website uses standard web technologies including HTML, CSS, and JavaScript, with integrations for Google Adsense, Google Analytics, and AddThis. The site is moderately optimized for mobile devices and SEO, with a clear navigation structure and good content quality. However, there is no evidence of a CMS or modern frameworks, and performance is moderate. Accessibility features are basic. From a security perspective, the site lacks visible security headers and there is no confirmation of HTTPS usage from the provided data. The cookie consent banner is implemented, requesting user consent for cookies and non-personalized advertising, which is a positive privacy compliance indicator. However, the absence of privacy policy and terms of service pages, as well as missing WHOIS registration data, reduce the overall trustworthiness and security posture. No incident response or vulnerability disclosure information is provided. Overall, the website is a useful educational resource with moderate technical maturity and basic privacy compliance. The main risk lies in the unclear domain registration status, which should be investigated further. Strategic recommendations include securing the domain registration, implementing HTTPS and security headers, publishing privacy and terms policies, and enhancing accessibility and security practices.

30
65
2
60
72
70
100
cookiescomputercookiescookieinformationcookieconsentprivacy+1 more
HTMLCSSJavaScriptGoogle Adsense+2
2025-07-10T16:05:16.414Z
bmedia.cz favicon

B Media Solutions s.r.o.

bmedia.cz

44
TechnologyCzech RepublicsmallHIGH

B Media Solutions s.r.o. is a small Czech technology company specializing in custom eCommerce solutions, custom web development, and comprehensive internet marketing services. Their website is bilingual, targeting both Czech and English-speaking clients, and showcases client logos to establish credibility. The business model focuses on delivering tailored eShops and web solutions to businesses, positioning itself as a niche provider within the Czech market. Technically, the website employs standard web technologies including HTML5, CSS, JavaScript, and jQuery 3.6.1. The site is moderately optimized for performance and mobile devices but lacks advanced accessibility features and modern frameworks. No CMS or hosting provider information is discernible from the content. SEO and metadata are basic but present. From a security perspective, the site lacks visible security headers and privacy-related policies such as GDPR compliance or cookie consent mechanisms. WHOIS data is missing, which raises concerns about domain registration transparency. No forms or data collection mechanisms are present on the homepage, reducing immediate data exposure risks. Overall, the security posture is moderate but could be significantly improved by implementing HTTPS, security headers, and privacy policies. The overall risk is moderate with no critical vulnerabilities detected in the visible content. Strategic recommendations include improving security configurations, adding privacy and cookie policies, and enhancing mobile and accessibility features to increase trust and compliance.

15
25
2
65
72
85
20
ecommercecustomwebsolutionsinternetmarketingczechrepublicbusinessservices
HTML5CSSJavaScriptjQuery 3.6.1
2025-07-10T13:47:35.232Z
laix.lu favicon

LAIX (Luxembourg Architectes Ingénieurs-conseils eXport)

laix.lu

47
OtherLuxembourgsmallHIGH

LAIX is a professional platform dedicated to showcasing architectural, engineering, and urbanism projects by Luxembourg architects and consulting engineers, primarily members of the Ordre des Architectes et Ingénieurs Conseils (OAI). The website serves as a promotional and informational hub for these professionals, highlighting their projects both within Luxembourg and internationally. The platform targets industry professionals, potential clients, and partners interested in Luxembourgish architectural and engineering expertise. Technically, the website is built on Drupal 8 CMS, incorporating modern web technologies such as JavaScript, CSS, and external services like Google Analytics and AddToAny for social sharing. The site is mobile-optimized and accessible, with a moderate performance profile. However, some SEO and privacy compliance aspects could be improved. From a security perspective, the site uses HTTPS and anonymizes IP addresses in Google Analytics, but lacks visible security headers and formal security or incident response policies. No critical vulnerabilities or blocking mechanisms were detected, indicating a generally secure posture but with room for enhancement in security best practices and compliance documentation. Overall, the website is professional and trustworthy, with comprehensive project content and clear contact information. The absence of privacy and cookie policies, as well as security policies, represents compliance gaps that should be addressed to improve user trust and regulatory adherence.

40
10
17
60
62
75
40
architectureengineeringluxembourgprojectsoai+1 more
Drupal 8Google AnalyticsAddToAny sharingJavaScript+1

Partner Domains:

oai.lu
partner
architectour.lu
partner

+3 more partners

2025-07-10T11:32:55.152Z
panopto.com favicon

Panopto

panopto.com

68
TechnologyN/aenterpriseMEDIUM

Panopto is an enterprise-grade SaaS company specializing in AI-powered video tools designed to enhance knowledge sharing across teams and educational campuses. Their platform enables secure video creation, sharing, and management, targeting businesses and educational institutions. The website reflects a mature digital presence with comprehensive content, strong branding, and integration of advanced marketing and analytics technologies. The company positions itself as a leader in video knowledge management solutions with a focus on AI enhancements. Technically, the website is built on WordPress with modern SEO practices, including structured data and responsive design. It integrates multiple marketing and analytics tools such as Marketo, Google Tag Manager, and Visual Website Optimizer, indicating a sophisticated approach to user engagement and conversion tracking. Performance and accessibility are good, supporting a positive user experience across devices. From a security perspective, the site enforces HTTPS and implements key security headers, demonstrating adherence to best practices. However, explicit security policies, incident response details, and vulnerability disclosure mechanisms are not publicly available, representing areas for improvement. The absence of WHOIS registration data reduces transparency but does not detract significantly from the overall trustworthiness given the professional site presentation. Overall, Panopto's website is a well-executed digital asset supporting its business objectives, with strong content quality and technical implementation. Strategic enhancements in security transparency and domain registration disclosure would further strengthen trust and compliance posture.

75
58
17
80
57
75
100
videoaiknowledgesharingenterpriseeducation+2 more
WordPressYoast SEOGoogle Tag ManagerMarketo+4
2025-07-10T11:32:10.002Z
frs-systems.de favicon

FRS Systems GmbH

frs-systems.de

64
TransportationGermanymediumMEDIUM

FRS Systems GmbH is a German company specializing in highly flexible ticketing software solutions tailored for the ferry and passenger vessel industry. Their flagship product, flexWays, offers comprehensive features including sales and distribution, booking management, inventory control, route planning, capacity management, and boarding administration. The company positions itself as an innovative and reliable software provider with a medium-sized workforce and a history dating back to 1992. The website is professionally designed, mobile-optimized, and provides clear contact information, enhancing its credibility. Technically, the website is built on the TYPO3 CMS platform, leveraging modern web technologies such as JavaScript, CSS, and SVG graphics. Hosting and DNS services are managed via Cloudflare, providing robust SSL encryption and potential security benefits. The site demonstrates good performance and accessibility standards, although no advanced analytics or tracking scripts were detected in the provided content. From a security perspective, the website enforces HTTPS and benefits from Cloudflare's DNS services, but lacks visible security headers and explicit security policies. There is no cookie consent mechanism or terms of service present, which are important for GDPR compliance and legal clarity. Incident response contacts and vulnerability disclosure information are also absent, representing areas for improvement. Overall, the website is trustworthy and professional, with a strong business focus and solid technical foundation. However, enhancements in privacy compliance, security policy transparency, and incident response readiness would further strengthen its security posture and regulatory adherence.

35
28
17
100
75
75
100
ticketingferrysoftwaretransportationbooking+2 more
TYPO3 CMSJavaScriptCSSSVG
2025-07-10T11:28:24.366Z
frs-syltfaehre.de favicon

FRS Syltfähre GmbH & Co. KG

frs-syltfaehre.de

67
TransportationGermanymediumMEDIUM

FRS Syltfähre GmbH & Co. KG is a well-established regional ferry operator providing car and passenger ferry services between Havneby on Rømø and List on Sylt. The company operates up to 32 daily departures, catering primarily to tourists and travelers seeking reliable and comfortable transportation across the North Sea. The website reflects a mature digital presence with a professional design, clear navigation, and comprehensive service information including booking, schedules, fares, and travel tips. The company is part of the larger FRS group, indicating a stable market position and operational backing. Technically, the website is built on TYPO3 CMS, leveraging modern web technologies and integrating analytics tools such as Microsoft Clarity, Google Tag Manager, and Hotjar for user behavior insights. Hosting and DNS are managed via Cloudflare, enhancing performance and security. Accessibility features and SEO best practices are well implemented, contributing to a positive user experience across devices. From a security perspective, the site enforces HTTPS and uses reputable third-party services, with no evident vulnerabilities or exposed sensitive data. Privacy and cookie policies are clearly presented with consent mechanisms, aligning with GDPR requirements. However, explicit security headers and incident response policies are not prominently disclosed, representing an area for improvement. Overall, the website demonstrates a strong security posture, good privacy compliance, and solid business credibility. The risk level is low, with recommendations focusing on enhancing security header implementation, publishing incident response information, and maintaining vigilance on third-party scripts.

55
40
17
97
65
75
100
ferrytransportationtravelbookingsylt+3 more
TYPO3 CMSJavaScriptCSSHTML5+3

Partner Domains:

www.frs.world
parent
www.frs-travel.de
partner

+1 more partners

2025-07-10T11:27:34.253Z
Y

Yahoo

yahooapis.com

72
TechnologyN/aenterpriseMEDIUM

Yahoo is a major global internet brand operating a portfolio of websites and applications including Yahoo, AOL, Engadget, Rivals, In The Know, and Makers. The analyzed page is a Finnish language consent management interface for GDPR compliance, allowing users to accept or reject cookies and manage privacy settings. The business model centers on advertising and content delivery, targeting general internet users with a broad range of digital services. The website demonstrates consistent branding and good content quality aligned with Yahoo's corporate identity. Technically, the site uses standard web technologies including JavaScript and CSS, with some proprietary Yahoo libraries such as YAHOO.i13n.Rapid for analytics. The page is moderately optimized for performance and mobile devices, though accessibility and SEO could be improved. Security measures include CSRF tokens in forms, but no explicit security headers were detected in the provided data. The SSL configuration could not be assessed from the data but is expected to be standard for Yahoo domains. From a security and compliance perspective, the site shows good GDPR compliance with clear privacy and cookie policies linked, and a consent mechanism implemented. No contact or incident response information was found on this page, which is typical for a consent layer. The domain WHOIS data for the subdomain is not separately registered, which is normal for subdomains under a large corporate domain. Overall, the site is trustworthy and safe, with no adult or malicious content detected. Strategically, Yahoo should enhance security headers and accessibility features, improve SEO metadata, and consider publishing clear security and incident response policies linked from consent pages to strengthen trust and compliance posture.

75
68
2
83
77
90
100
consentprivacycookiegdpryahoo+1 more
JavaScriptCSSHTML5

Partner Domains:

aol.com
subsidiary
engadget.com
subsidiary

+3 more partners

2025-07-10T08:08:05.712Z
eceae.org favicon

European Coalition to End Animal Experiments (ECEAE)

eceae.org

48
Non-profitGermanysmallHIGH

The European Coalition to End Animal Experiments (ECEAE) is a well-established non-profit umbrella organization founded in 1990, representing 18 animal protection and scientific organizations across Europe. Their mission focuses on abolishing animal experiments and promoting humane, animal-free research methods. The organization holds a recognized position with official stakeholder status in several EU bodies, enhancing their influence in policy and advocacy. The website reflects this mission with clear, relevant content targeted at animal welfare advocates, researchers, and policymakers. Technically, the website is built on Joomla CMS with a modern and responsive design, delivering a good user experience across devices. The infrastructure is moderate in performance, with no blocking or WAF challenges detected. However, some security best practices such as DNSSEC and security headers are missing, and no cookie consent mechanism is implemented, which is a compliance gap given GDPR relevance. Security posture is adequate with HTTPS enabled and domain transfer protection, but lacks published security policies or incident response contacts. The WHOIS data is transparent and consistent with the organization's identity and location, supporting legitimacy. Overall, the site is professional and trustworthy but could improve privacy compliance and security hardening. Strategic recommendations include enabling DNSSEC, implementing security headers, adding cookie consent for GDPR compliance, and publishing security and incident response policies to enhance trust and compliance.

50
53
2
70
72
55
-
animalprotectionantivivisectionnon-animalresearcheuropeancoalitionanimalexperiments
JavaScriptCSSHTML5
2025-07-10T08:05:40.408Z
L

Luxembourg House of Cybersecurity

secin.lu

56
GovernmentLuxembourgsmallMEDIUM

The Luxembourg House of Cybersecurity (LHC) website represents a government-backed initiative focused on cybersecurity coordination and awareness within Luxembourg. The site primarily serves as an informational landing page announcing the transformation of SECURITYMADEIN.LU into LHC, targeting government entities and cybersecurity stakeholders. The business model is centered on providing a national cybersecurity hub and fostering community engagement in cybersecurity matters. Technically, the website is built using the Hugo static site generator, with basic CSS and JavaScript. The site is simple and moderately optimized for performance and mobile devices but lacks advanced SEO and accessibility features. No analytics or tracking technologies are detected, indicating a minimal digital footprint. From a security perspective, the site lacks visible security headers and published privacy or cookie policies, which are important for compliance and user trust. The absence of WHOIS data limits the ability to verify domain registration legitimacy, although the presence of official government links supports authenticity. No forms or user input fields reduce attack surface but also limit user engagement. Overall, the website is safe and professional but basic in content and technical sophistication. Strategic improvements in security headers, privacy compliance, and WHOIS transparency would enhance trust and compliance posture.

65
25
47
60
72
80
40
cybersecuritygovernmentluxembourgsecuritymadeinlhc
Hugo 0.107.0CSSJavaScript
2025-07-10T08:03:14.154Z
raisio.fi favicon

Raision Kaupunki

raisio.fi

63
GovernmentFinlandmediumMEDIUM

Raisio.fi is the official website of Raision Kaupunki, the municipal government of Raisio city in Finland. The site provides comprehensive information and services related to housing, environment, city planning, and public events targeted primarily at residents, immigrants, and tourists. The website is built on Drupal 10 and incorporates modern web technologies including Matomo analytics and CookieHub for cookie consent management. The site demonstrates good design quality, clear navigation, and mobile optimization, reflecting a mature digital presence for a local government entity. From a security perspective, the website enforces HTTPS and uses a consent management platform, but lacks DNSSEC and explicit security headers, which are recommended for enhanced security. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is partial, with cookie consent mechanisms present but no explicit privacy policy or terms of service pages found in the analyzed content. WHOIS data confirms the domain is legitimately registered to the city of Raisio with consistent registration details and a long domain age, supporting trustworthiness. Overall, Raisio.fi presents a secure and professional municipal website with room for improvement in privacy transparency and DNS security. The site is safe for general audiences and does not contain any adult or questionable content.

80
10
17
75
62
80
100
governmentmunicipalpublicservicesfinlanddrupal+2 more
Drupal 10Matomo AnalyticsCookieHubJavaScript+2
2025-07-10T08:02:23.415Z
ui.com favicon

Ubiquiti Inc.

ui.com

77
TechnologyUnited StatesenterpriseLOW

Ubiquiti Inc. is a well-established enterprise technology company specializing in networking hardware and software solutions, particularly under the UniFi brand. The company targets enterprise customers and IT professionals with a comprehensive portfolio of products designed to unify networking and security management through an advanced software interface. The website reflects a mature digital presence with a professional design, clear navigation, and mobile optimization, supporting a strong market position in the technology and telecommunications sectors. Technically, the website leverages modern web technologies including React and JavaScript, hosted on Amazon AWS infrastructure, ensuring fast performance and scalability. The site employs best practices in SEO, accessibility, and user experience, with comprehensive metadata and structured data supporting search engine visibility. Analytics and marketing tools are integrated responsibly with user consent mechanisms in place. From a security perspective, the site enforces HTTPS, implements key security headers, and avoids exposing sensitive data. However, DNSSEC is not enabled, which is a recommended enhancement for DNS security. The absence of a public security policy or incident response contact is noted as an area for improvement. Overall, the security posture is strong with no critical vulnerabilities detected. The domain WHOIS data confirms the legitimacy of the website, showing a long registration history consistent with the company's founding date and no use of privacy protection, which aligns with the public nature of the business. The website is free from WAF or blocking mechanisms, allowing full content access and analysis. Strategic recommendations include enabling DNSSEC, publishing a security policy and incident response contacts, and maintaining regular audits of third-party scripts to sustain security and compliance standards.

70
88
2
82
100
85
100
enterprisenetworkingtechnologysecuritysoftwarehardware+2 more
ReactJavaScriptCSSHTML5
2025-07-10T07:00:09.859Z
tech.lgbt favicon

tech.lgbt Moderators

tech.lgbt

60
TechnologyIcelandsmallMEDIUM

tech.lgbt operates as a niche Mastodon instance providing a federated social networking platform primarily for LGBTQIA+ individuals and allies interested in technology and academic topics. The platform fosters community engagement through posts, hashtags, and news aggregation from across the fediverse, positioning itself as a trusted space for marginalized identities within the tech sector. The website's content and user base reflect a focused community with approximately 2.7K active users, indicating a small but engaged audience. The business model centers on community-driven social networking without commercial advertising or tracking, emphasizing privacy and inclusivity. From a technical perspective, the site leverages modern web technologies including React and JavaScript ES modules, hosted on DigitalOcean with domain registration via NameCheap. The platform runs Mastodon version 4.4.0-alpha.5+glitch, indicating active maintenance and use of open-source social networking software. The website demonstrates good mobile optimization and basic accessibility features, though SEO and performance optimizations are moderate. The absence of cookie consent mechanisms and some security headers suggests areas for improvement in compliance and security hardening. Security posture is solid with HTTPS enforced and no exposed sensitive data detected. However, the lack of DNSSEC and security headers such as CSP or HSTS represents potential vulnerabilities. The WHOIS data shows privacy protection for the domain registrant, which is justified given the community nature of the platform. No incident response or vulnerability disclosure policies are publicly available, which could be enhanced to improve trust and security readiness. Overall, tech.lgbt presents a professional, trustworthy, and community-focused platform with a strong emphasis on privacy and inclusivity. Strategic recommendations include enabling DNSSEC, implementing comprehensive security headers, adding cookie consent and vulnerability disclosure policies, and providing clearer contact information for security incidents. These steps would enhance compliance, security posture, and user trust, supporting sustainable growth and resilience in the federated social networking space.

75
58
17
65
95
55
40
mastodonlgbtqiatechnologysocialnetworkfediverse
Mastodon 4.4.0-alpha.5+glitchReactJavaScript ES ModulesCSS+2
2025-07-10T05:47:50.953Z
cwi.nl favicon

Centrum Wiskunde & Informatica (CWI)

cwi.nl

73
EducationNetherlandsmediumMEDIUM

Centrum Wiskunde & Informatica (CWI) is the national research institute for mathematics and computer science in the Netherlands. It conducts pioneering fundamental research in key areas such as algorithms, data and intelligent systems, cryptography and security, and quantum computing. The institute collaborates closely with Dutch universities and industry partners, providing education and knowledge transfer through semester programmes and joint research initiatives. CWI is positioned as a leading academic and research entity within the Dutch and international scientific community. The website infrastructure is modern and professionally implemented, utilizing JavaScript, CSS, MathJax for mathematical rendering, and Piwik/Matomo for analytics. The site is mobile-optimized, accessible, and SEO-friendly, with clear navigation and consistent branding. Privacy and cookie policies are present with consent mechanisms, reflecting good compliance with GDPR requirements. However, explicit security policies and incident response information are not published. Security posture is strong with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. The site could improve by adding security headers and publishing a vulnerability disclosure or security.txt file. WHOIS data confirms the legitimacy of the domain, matching the institutional identity and country. Overall, the website is trustworthy, professional, and serves its academic audience effectively.

65
83
2
80
100
70
100
researchmathematicscomputerscienceeducationcryptography+3 more
JavaScriptCSSMathJaxPiwik/Matomo analytics

Partner Domains:

nwo.nl
partner
2025-07-10T05:46:10.563Z
K

Kevin Brown-Silva

kevin-brown.com

56
TechnologyN/asmallMEDIUM

Kevin Brown-Silva's website serves as a professional portfolio showcasing his software development expertise and contributions to open source projects. The site highlights his skills in technologies such as Python, Django, JavaScript, and jQuery, and provides links to his GitHub, Stack Overflow, LinkedIn, and Twitter profiles, establishing a credible online presence. The business model is personal branding and professional networking, targeting technology professionals and potential employers or collaborators. Technically, the website is built with standard web technologies including HTML, CSS, and JavaScript, with references to frameworks like Django REST framework and jQuery. Hosting and DNS are managed via Cloudflare, ensuring good SSL configuration and domain security. The site is moderately optimized for performance and mobile devices but lacks advanced SEO and accessibility features. From a security perspective, the website benefits from HTTPS and domain transfer protection but lacks critical security headers and formal privacy or cookie policies. No forms or data collection mechanisms are present, reducing attack surface but also limiting user engagement features. The absence of vulnerability disclosure or incident response information indicates room for improvement in security maturity. Overall, the website is a safe, professional, and trustworthy personal portfolio with good business credibility but limited privacy compliance and security best practices. Strategic enhancements in privacy policies, security headers, and incident response readiness would strengthen the site's security posture and compliance.

15
35
2
70
75
75
100
softwaredevelopmentportfoliotechnologyopensourceprofessional
HTMLCSSJavaScriptjQuery+1
2025-07-10T04:38:39.812Z
conostix.com favicon

Conostix S.A.

conostix.com

56
TechnologyLuxembourgsmallMEDIUM

Conostix S.A. is a small Luxembourg-based technology company specializing in security and system services, with a focus on security management consultancy, tailored open source software solutions, and customer care. Founded in 2001, the company positions itself as a niche provider for enterprises requiring advanced security expertise. The website content reflects this business focus but is basic in design and technical sophistication. Technically, the website is a simple HTML and CSS implementation with no detected CMS or advanced frameworks. There is no evidence of HTTPS enforcement or security headers, and mobile optimization is poor. The site lacks privacy and cookie policies, contact information, and incident response details, indicating limited digital maturity and compliance readiness. From a security perspective, the domain is well-established with consistent WHOIS data and clientTransferProhibited status, supporting legitimacy. However, the absence of HTTPS and security headers, as well as missing privacy compliance elements, represent vulnerabilities and compliance gaps. No forms or data collection mechanisms were found, reducing immediate data exposure risks. Overall, the website presents a moderate risk profile with room for significant improvements in security posture, privacy compliance, and technical modernization. Strategic recommendations include implementing HTTPS, adding privacy and cookie policies, improving mobile responsiveness, and enhancing security headers and incident response capabilities.

30
35
2
75
85
65
100
securityconsultingopensourceluxembourgtechnology
HTMLCSS
2025-07-10T04:35:21.381Z
ekokvarner.hr favicon

Eko Kvarner

ekokvarner.hr

41
Non-profitCroatiasmallHIGH

Eko Kvarner is a Croatian non-profit environmental organization focused on promoting sustainable energy, climate change awareness, and ecological protection in the Kvarner region. The website serves as an information hub providing news, activities, projects, and educational resources to local communities and stakeholders interested in environmental issues. The organization appears well-established with a domain registered since 2012 and clear contact information including physical address, phone numbers, and email. The site content is primarily in Croatian and targets regional audiences. Technically, the website uses an older CMS platform called Galaksija and relies on legacy JavaScript libraries such as jQuery and Fancybox. While the site is accessible and contains meaningful content, it loads some external scripts over unsecured HTTP, which introduces mixed content risks. The site lacks modern security headers and advanced privacy or cookie consent mechanisms, indicating room for improvement in security and compliance maturity. Hosting is provided by Totohost, a Croatian hosting provider, and the domain registrar is CARNET, a reputable Croatian academic network. From a security perspective, the site uses HTTPS but does not implement additional security headers or content security policies. No incident response or security policy pages are found, and no vulnerability disclosure or security.txt files are present. The WHOIS data is consistent with the website's business profile and geographic location, supporting legitimacy. No suspicious or malicious indicators were detected. Overall, the website is functional and provides valuable content for its target audience but would benefit from technical modernization, improved security practices, and enhanced privacy compliance to strengthen trust and resilience against threats.

15
25
17
85
62
60
-
environmentenergynon-profitcroatiasustainability+1 more
jQueryjQuery UIFancyboxCSS+1
2025-07-10T03:34:04.514Z
restena.lu favicon

Fondation Restena

restena.lu

72
EducationLuxembourgmediumMEDIUM

Fondation Restena is a Luxembourg-based non-profit foundation that manages telecommunication infrastructure and services for the research, education, culture, health, and administration sectors in Luxembourg. It operates the national research and education network, manages the .lu domain registry, and provides a range of services including email, hosting, network connectivity, and IT security. The foundation is well-established, with origins dating back to 1989 and formal foundation status since 2000. Their market position is strong as a key national infrastructure provider with a focus on public and academic institutions. Technically, the website is built on Drupal 8, featuring modern web technologies and good mobile optimization. The site is well-structured with clear navigation and professional design. Security posture is strong, supported by ISO 27001 certification and secure form handling, although some security headers are not visibly implemented. Privacy compliance is partial, with a privacy policy present but lacking a cookie consent mechanism. Overall, the security posture is robust with dedicated incident response services (CSIRT) and ongoing certification efforts. No major vulnerabilities or suspicious patterns were detected. The domain WHOIS data aligns well with the website content, confirming legitimacy and consistency. Strategic recommendations include enhancing privacy compliance with cookie consent, adding security headers, and publishing a vulnerability disclosure policy to further strengthen trust and security culture.

70
28
59
60
90
85
100
educationresearchnetworksecuritydomainregistry+2 more
Drupal 8JavaScriptCSS
2025-07-10T03:32:28.909Z
aaa.lu favicon

Association d'assurance accident

aaa.lu

57
GovernmentLuxembourgmediumMEDIUM

The Association d'assurance accident (AAA) website serves as the official online presence for the Luxembourg governmental accident insurance association. It provides comprehensive information on accident insurance, workplace safety, indemnifications, and related public services. The site targets residents, workers, and employers in Luxembourg, offering resources, contact points, and regulatory information. The organization holds ISO9001:2015 certification, reinforcing its commitment to quality and trustworthiness. Technically, the website is built on Adobe Experience Manager CMS, leveraging modern web technologies including RequireJS and Adobe Dynamic Tag Manager for analytics and marketing. The site is well-structured, mobile-optimized, and accessible, with clear navigation and professional design. Cookie consent and privacy policies are implemented in compliance with GDPR. Security posture is moderate with HTTPS usage inferred, but no explicit security headers were detected in the provided data. No vulnerabilities or exposed sensitive data were found. The absence of WHOIS data limits domain registration trust analysis, but the domain's public.lu TLD and content strongly indicate an official government entity. Overall, the website is a reliable and professional government resource with good content quality and privacy compliance. Recommendations include enhancing security headers, publishing explicit security policies, and improving WHOIS data transparency where possible.

40
10
2
65
72
85
100
governmentinsuranceaccidentworkplacesafetyluxembourg+1 more
HTML5CSSJavaScriptRequireJS+2
2025-07-10T02:25:11.889Z
accessibilite.lu favicon

Le Gouvernement du Grand-Duché du Luxembourg

accessibilite.lu

54
GovernmentLuxembourgmediumMEDIUM

The website accessibilite.lu is an official government portal of Luxembourg dedicated to providing information on accessibility across digital platforms, infrastructure, and products/services. It serves as a public service resource aimed at residents and stakeholders interested in accessibility issues within Luxembourg. The site is branded consistently with Luxembourg government identity and offers navigation in French with an option for German. Technically, the site uses standard HTML5, CSS, and JavaScript, including Adobe Launch for analytics, indicating a moderate level of digital maturity. The site is mobile optimized and accessible, though content quality is basic with limited depth on the landing page. Security posture is adequate with HTTPS implied, but lacks visible security headers and formal security policies. Privacy compliance is weak due to absence of privacy and cookie policies or consent mechanisms. No contact or incident response information is provided, limiting user engagement and trust channels. Overall, the domain registration and DNS configuration align with official Luxembourg government infrastructure, confirming legitimacy and trustworthiness. Strategic improvements in privacy compliance, security headers, and contact transparency would enhance the site's security and user trust.

15
25
2
60
82
75
100
governmentaccessibilityluxembourgpublicservicedigitalaccessibility
HTML5CSSJavaScriptAdobe Launch (Adobe DTM)
2025-07-10T02:24:56.474Z
skischool.shop favicon

Waldhart Software

skischool.shop

48
RetailAustriamediumHIGH

Waldhart Software operates a specialized online platform providing e-commerce and booking solutions tailored for ski schools and snow sports schools primarily in Alpine regions. The website serves as a reference showcase for nearly 300 live client online shops, demonstrating a strong market presence in the niche retail sector for winter sports education and services. The business model focuses on B2B SaaS offerings, enabling ski schools to manage online bookings and sales effectively. Technically, the website employs modern JavaScript frameworks, likely Vue.js with the Quasar UI framework, and integrates Google Maps APIs for location services. Hosting is managed via profiwebspace.at, with domain registration through InterNetX GmbH in Austria. The site is served over HTTPS, ensuring encrypted communications, but lacks DNSSEC and security headers, which are recommended for enhanced security. Security posture is moderate; while HTTPS and domain transfer protections are in place, the absence of security headers and privacy/cookie policies indicates room for improvement in compliance and security best practices. No forms or contact details were found in the analyzed content, limiting direct user engagement and incident response capabilities. Overall, the website is professional and well-structured, targeting ski schools and related businesses with a clear value proposition. However, to strengthen trust and compliance, the addition of privacy and cookie policies, security headers, and clear contact information is advised.

15
53
17
70
62
70
20
onlineshopskischulesnowboardschuleschneesportschulebooking+2 more
JavaScriptGoogle Maps APICSS
2025-07-10T01:10:44.692Z
F

Federal Public Planning Service Science Policy

belspo.be

61
GovernmentBelgiummediumMEDIUM

The Belgian Science Policy Office (BELSPO) operates as the Federal Public Planning Service Science Policy, providing coordination and support for scientific research and federal scientific institutions in Belgium. The website serves as an official government portal offering multilingual content in Dutch, French, and English, targeting government stakeholders, researchers, and the public interested in science policy. Key services include support for federal museums, participation in European and international scientific organizations, research funding, and management of the Belnet telematics network. Technically, the website uses basic HTML, CSS, and JavaScript without advanced frameworks or CMS detected. The site is moderately optimized for performance and mobile use but lacks advanced accessibility and SEO features. No analytics or tracking scripts were detected, indicating a privacy-conscious approach. Security headers and SSL configuration details are not visible in the provided data, suggesting room for improvement in security hardening. From a security perspective, the site shows no signs of vulnerabilities or exposed sensitive data but lacks explicit security policies, incident response contacts, and vulnerability disclosure mechanisms. Privacy and cookie policies are present, though cookie consent mechanisms are not implemented. WHOIS data is restricted by DNS Belgium policy, which is typical for government domains, and does not raise legitimacy concerns. Overall, the site is trustworthy and professional but could enhance its security posture and privacy compliance. The overall risk is low given the official nature and content safety, but strategic improvements in security headers, HTTPS enforcement, and transparency in incident response would strengthen the security and trust profile.

-
68
17
85
72
75
100
governmentsciencepolicybelgiumresearchfederal+1 more
HTML5CSSJavaScript
2025-07-10T00:05:01.136Z
guichet.lu favicon

Le Gouvernement du Grand-Duché de Luxembourg

guichet.lu

67
GovernmentLuxembourglargeMEDIUM

Guichet.public.lu is the official government portal of Luxembourg dedicated to providing citizens with easy access to a wide range of public services and administrative information. The website offers comprehensive coverage of topics such as financial aids, citizenship, family and education, taxation, immigration, inclusion, justice, housing, leisure, health, transport, and employment. It serves as a centralized digital gateway for Luxembourg residents to navigate government procedures efficiently. Technically, the site is built on Adobe Experience Manager (AEM), leveraging modern web technologies including SVG icons, JavaScript, and CSS for a responsive and accessible user experience. The presence of Adobe Dynamic Tag Manager indicates a mature approach to analytics and marketing tag management. The site is mobile-optimized and includes accessibility features, ensuring usability for a broad audience. From a security perspective, the website enforces HTTPS and integrates secure login mechanisms linking to official government authentication services. Cookie consent and privacy policies are clearly presented, reflecting compliance with GDPR requirements. While explicit security headers are not fully visible in the provided data, the overall posture appears strong with no evident vulnerabilities or exposed sensitive data. Overall, guichet.public.lu demonstrates a high level of professionalism, trustworthiness, and user-centric design, making it a reliable resource for Luxembourg citizens. The main limitation in the analysis is the absence of WHOIS data, which restricts domain registration trust assessment. Nonetheless, the official branding and domain extension support its legitimacy.

85
25
17
65
77
85
100
governmentcitizenspublicservicesluxembourgadministration+1 more
Adobe DTM (Adobe Dynamic Tag Manager)SVG iconsJavaScriptCSS+1
2025-07-10T00:02:29.608Z