Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

150016
Websites
130
Industries
113
Countries
52
Avg Score
Page 153 of 778|Showing 7601-7650 of 38857
tpopsite.com favicon

E-commerce + Print on Demand

tpopsite.com

69
E-commerceFrancemediumMEDIUM

TPOP is a French-based e-commerce platform specializing in print-on-demand services with a strong emphasis on eco-friendly and local production. The platform enables entrepreneurs and small to medium-sized businesses to quickly create online stores without upfront inventory costs, integrating easily with popular marketplaces and CMS platforms like Shopify, Etsy, and WooCommerce. The website demonstrates a mature digital presence with multilingual support, rich multimedia content, and a user-friendly interface designed for rapid store setup and product customization. Technically, the site employs modern web technologies including Bootstrap, Weglot for translations, and analytics tools such as Google Analytics and Gleap for user feedback. Security posture is solid with HTTPS enforced and cookie consent mechanisms in place, though explicit HTTP security headers are not evident in the provided data. The absence of WHOIS registration details is a notable gap, reducing domain trustworthiness, but the presence of customer testimonials, Trustpilot ratings, and active social media accounts support the legitimacy of the business. Overall, TPOP presents as a professional and trustworthy e-commerce solution with room for improvement in transparency of security policies and contact information.

45
68
2
87
75
90
100
e-commerceprintondemandeco-friendlyonlinestoreshopify+2 more
JavaScriptGoogle AnalyticsGoogle Tag ManagerWeglot translation+4

Partner Domains:

apps.shopify.com
partner
www.tpop.fr
sister

+2 more partners

2025-10-20T20:24:06.444Z
usbr.gov favicon

Bureau of Reclamation

usbr.gov

69
GovernmentUnited StatesenterpriseMEDIUM

The Bureau of Reclamation is a longstanding U.S. government agency under the Department of the Interior, responsible for managing water and power resources primarily in the Western United States. The website serves as a comprehensive portal for information on dams, powerplants, water projects, environmental resources, and public recreation. It targets government entities, water resource managers, researchers, and the general public. The agency operates with an enterprise-level scale and maintains a strong market position as the primary federal water management authority in its region. Technically, the website employs a modern technology stack including HTML5, CSS3, JavaScript, jQuery, and analytics tools such as Google Tag Manager and DigitalGov Universal-Federated-Analytics. The site is mobile-optimized, accessible, and well-structured with clear navigation and good SEO practices. Hosting appears to be government-managed, ensuring reliability and compliance with federal standards. From a security perspective, the site enforces HTTPS and publishes a vulnerability disclosure policy, indicating a proactive security posture. However, explicit security headers are not clearly present, and there is no cookie consent mechanism, which could be improved for privacy compliance. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data confirms the domain's legitimacy as a government entity with consistent registration information. Overall, the website is professional, trustworthy, and provides valuable public services. Strategic improvements in privacy compliance and security header implementation would enhance its security posture and regulatory adherence.

45
53
35
85
67
85
100
governmentwatermanagementhydropowerdamspublicservices+2 more
HTML5CSS3JavaScriptjQuery+4
2025-10-20T20:23:36.354Z
ovh.co.uk favicon

OVHcloud

ovh.co.uk

72
TechnologyFrancelargeMEDIUM

OVHcloud is a prominent European cloud computing and web hosting provider offering a broad portfolio of infrastructure and platform services including dedicated servers, VPS, bare metal servers, and cloud storage. The company targets businesses and developers seeking scalable and secure cloud solutions, positioning itself as a competitive player in the global cloud market. The website demonstrates a mature digital presence with multiple language versions and comprehensive service offerings. Technically, the site employs modern web technologies, custom analytics, and error monitoring tools, with good mobile optimization and accessibility features. Security posture is strong with HTTPS enforcement and certifications such as ISO 27001 and SecNumCloud, although explicit security headers and incident response details are not fully visible. The absence of WHOIS data is a notable anomaly but does not detract significantly from the overall legitimacy given the brand recognition and content quality. Strategic recommendations include enhancing security header implementation, publishing vulnerability disclosure policies, and improving transparency on data retention. Overall, OVHcloud's website reflects a professional, secure, and business-focused cloud service provider with room for incremental security and compliance improvements.

45
65
65
62
77
80
100
cloudhostingdedicatedserversvpsbaremetal+4 more
JavaScriptCSSHTML5Sentry (error tracking)+1
2025-10-20T20:22:00.722Z
A

Ayuntamiento de Zaragoza

zaragozaciudad.net

52
GovernmentSpainlargeMEDIUM

The website www.zaragozaciudad.net serves as an official municipal blog platform for the Ayuntamiento de Zaragoza, targeting local citizens with community engagement and information about city neighborhoods and municipal services. The site provides a directory of citizen blogs categorized by topics and neighborhoods, supporting local communication and participation. The business model is public sector focused, providing a platform for citizen interaction and municipal transparency. The website content is primarily in Spanish and reflects a government entity's communication channel. Technically, the website uses XHTML 1.0 and CSS 2.0 with JavaScript enhancements and integrates Google Analytics and Google Tag Manager for visitor tracking. The design is basic and somewhat dated, with limited mobile optimization and accessibility features. No modern CMS or advanced frameworks are detected. Performance is moderate, and SEO is basic with meta tags present but no advanced structured data or Open Graph tags. From a security perspective, the site uses HTTPS as inferred from script sources but lacks explicit security headers such as CSP or HSTS. No privacy or cookie policies are present, indicating GDPR compliance gaps. The WHOIS data is missing or unavailable, which is inconsistent with the active municipal content and raises concerns about domain legitimacy. No incident response or vulnerability disclosure information is published, and no security best practices beyond basic HTTPS are observed. Overall, the website is functional and serves its public sector purpose but has notable gaps in privacy compliance, security posture, and domain registration transparency. Strategic improvements in security headers, privacy policies, and WHOIS registration clarity are recommended to enhance trust and compliance.

30
35
2
60
62
65
100
municipalblogcommunityzaragozagovernment+1 more
HTML 1.0 XHTMLCSS 2.0JavaScriptGoogle Analytics+1
2025-10-20T20:21:45.512Z
T

Terrena

terciel.fr

53
OtherFrancelargeMEDIUM

Terciel is a digital platform associated with Terrena, a major French agricultural cooperative. The website serves primarily as a login portal for members to access their dashboards and related services. The platform is built on Drupal 10 and incorporates performance monitoring tools such as Boomerang. The site is designed with basic but consistent branding and provides clear contact information via phone for user support. However, it lacks visible privacy, cookie, or terms of service policies on the login page, which are important for compliance and user trust. From a technical perspective, the website uses modern CMS technology and includes some performance monitoring scripts. The site appears to be moderately optimized for mobile devices and accessibility but could benefit from enhanced SEO and accessibility features. Security posture is moderate; HTTPS is implied but no explicit security headers are detected, and no vulnerability disclosures or incident response information is provided. The WHOIS data for the domain is not publicly available, indicating privacy protection, which is common and justified for cooperative businesses. No suspicious patterns or legitimacy concerns are identified. Overall, the site is functional and trustworthy for its intended audience but would benefit from improved privacy compliance and security best practices. Strategic recommendations include implementing comprehensive privacy and cookie policies, adding security headers, providing incident response contacts, and enhancing accessibility and SEO to improve user experience and compliance.

20
25
2
60
75
70
100
logincooperativeagriculturedrupalterrena
Drupal 10JavaScriptCSSBoomerang Real User Monitoring
2025-10-20T20:06:56.691Z
studoflow.com favicon

Studo GmbH

studoflow.com

78
EducationAustriasmallLOW

Studo GmbH is a European software company specializing in digital solutions for higher education institutions. Their flagship product, Studo Flow, is a SaaS platform designed to help universities digitize and simplify administrative processes through modular, configurable software components. The company targets small and emerging higher education institutions, offering a user-friendly and integrable platform that supports various administrative needs. Their market position is strong as a pioneer in European higher education SaaS solutions, supported by EU and Austrian funding agencies. Technically, the website is well-constructed with modern web technologies, including Cloudflare DNS and CDN services, and uses Piwik PRO for privacy-conscious analytics. The site is mobile-optimized, fast-loading, and SEO-friendly, reflecting a mature digital infrastructure. However, some security best practices such as DNSSEC and explicit security headers could be improved. From a security perspective, the company demonstrates a solid posture with HTTPS enforcement, GDPR compliance, and support for modern authorization frameworks like OAuth, SAML, and LDAP. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of a cookie consent mechanism and explicit incident response contacts are areas for enhancement. Overall, the website and company present a trustworthy and professional image with a high level of business credibility and technical maturity. Strategic improvements in security headers, DNSSEC, and privacy mechanisms would further strengthen their security and compliance stance.

55
65
65
98
72
85
100
educationsaasuniversityadministrationdigitalizationhighereducation+1 more
JavaScriptCSSHTML5Cloudflare DNS+1

Partner Domains:

research-and-innovation.ec.europa.eu
partner
www.ffg.at
partner

+3 more partners

2025-10-20T20:05:41.355Z
gorilla-cafe.cz favicon

GORILLA CAFÉ

gorilla-cafe.cz

56
HospitalityCzech RepublicsmallMEDIUM

Gorilla Café is a small hospitality business based in the Czech Republic, specializing in serving high-quality specialty coffee and tea with an emphasis on exotic blends sourced from Uganda and sustainable fair trade practices. The café positions itself as a calm oasis for customers seeking a relaxing environment and cultural experiences such as travel talks. The business model focuses on onsite café services, event hosting, and promoting sustainability through donations to conservation efforts. Technically, the website is built on the Webnode platform and utilizes AWS Cloudfront CDN for content delivery. The site is moderately optimized for performance and mobile devices, with a clean design and clear navigation. However, it lacks advanced security headers and comprehensive privacy documentation, which are areas for improvement. Google Tag Manager is used for analytics, indicating moderate user tracking. From a security perspective, the site enforces HTTPS and implements a cookie consent banner, but it lacks visible security headers and a privacy policy, which impacts its compliance posture. The absence of WHOIS data reduces trust in domain legitimacy, although the website content and business information appear professional and trustworthy. Overall, the website scores moderately well in content quality and business credibility but should address privacy and security gaps to enhance trust and compliance. Verifying domain registration details and adding comprehensive privacy and security policies are recommended to improve the site's security posture and user confidence.

35
25
2
70
62
80
100
coffeecafspecialtycoffeefairtradeugandacoffee+5 more
HTML5CSS3JavaScriptCloudfront CDN+1
2025-10-20T20:02:55.746Z
padlet.com favicon

Padlet

padlet.com

70
EducationN/alargeMEDIUM

Padlet is a well-established SaaS company founded in 2004, specializing in visual collaboration tools for creative work and education. The platform serves a large global user base of 40 million, targeting educators, students, and creative professionals. Their business model is freemium with tiered subscription plans for individuals, teams, classrooms, and schools. The website reflects a mature market position with strong branding and user engagement through social media and positive reviews on multiple platforms. Technically, Padlet employs modern web technologies including Vue.js and Cloudflare services for DNS and CDN. The site is well optimized for performance, mobile responsiveness, and accessibility. Analytics are implemented via RudderStack, indicating a moderate level of user tracking. The website is professionally designed with clear navigation and comprehensive content. From a security perspective, Padlet enforces HTTPS, uses security headers, and maintains a clientTransferProhibited domain status, indicating good domain security practices. However, DNSSEC is not enabled, and there is no visible vulnerability disclosure or security.txt file. Privacy compliance is partially addressed with a comprehensive privacy policy, but lacks an explicit cookie consent mechanism. Contact information for security incidents or data protection officers is not publicly available. Overall, Padlet presents a high level of business credibility and technical maturity with minor gaps in privacy compliance and security transparency. Strategic recommendations include enabling DNSSEC, implementing cookie consent, publishing vulnerability disclosure information, and providing clearer contact channels for security and privacy matters.

65
58
2
87
75
85
100
educationcollaborationvisual-thinkingsaascreative-tools
JavaScriptVue.jsCloudflare DNSRudderStack analytics
2025-10-20T20:02:30.686Z
bioracer.com favicon

Bioracer Official Store

bioracer.com

60
RetailBelgiummediumMEDIUM

Bioracer is a premium sportswear company specializing in custom bike clothing and accessories, targeting cyclists, triathletes, and athletes across multiple sports disciplines including skating and skiing. The company emphasizes performance, aerodynamics, and comfort, leveraging real-world racing data and wind tunnel testing. Their market position is strong within the niche of high-performance sports apparel, supported by endorsements and medals from professional athletes. The website is multilingual, professionally designed, and integrates e-commerce capabilities with a dedicated webshop and design-your-own apparel service. Technically, the website is built on WordPress using modern themes and plugins, with integrations for marketing and analytics tools such as HubSpot, Mailchimp, Google Tag Manager, and Facebook Pixel. The site demonstrates good performance, mobile optimization, and SEO practices. Security posture is solid with HTTPS enforced and cookie consent implemented, though explicit security headers and policies could be improved. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website presents a trustworthy and professional digital presence with comprehensive content and strong branding. The lack of WHOIS data for the subdomain is expected and does not detract from legitimacy. Strategic recommendations include enhancing security headers, publishing a security policy, and adding vulnerability disclosure information to further strengthen trust and compliance.

15
80
2
100
95
80
20
cyclingsportswearcustomclothingtriathlonathletics+5 more
WordPressPHPJavaScriptjQuery+6

Partner Domains:

shop.bioracer.com
partner
design.bioracer.com
partner
2025-10-20T20:01:25.490Z
botoxmusic.cz favicon

Musicus agency s.r.o.

botoxmusic.cz

43
MediaCzech RepublicsmallHIGH

Botoxmusic.cz represents a Czech multi-genre music band named Botox, active since 2018. The website serves as a digital hub for the band’s activities including concert announcements, music streaming links, and merchandise sales via an e-shop. The band targets a general audience interested in music and live performances, maintaining a consistent brand presence across social media platforms and partner collaborations. The business model revolves around live events, digital music distribution, and merchandise sales, positioning the band as a small but active player in the Czech music scene. Technically, the website is built using HTML5, CSS3, JavaScript, and AngularJS framework, with multimedia integration such as YouTube video embeds and a swiper slider for featured content. The site is mobile optimized with good navigation and content relevance, though some modern accessibility features could be improved. No CMS or hosting provider details were detected. Performance is moderate with no critical technical issues observed. From a security perspective, the site uses HTTPS but lacks visible security headers and privacy/cookie policies, indicating room for compliance and security posture enhancement. No WHOIS data was found, which reduces domain trustworthiness, but the website content and contact information appear legitimate and professional. No tracking or analytics scripts were detected, suggesting minimal user tracking. Overall, the website is functional and professional for its purpose but would benefit from improved privacy compliance, security headers, and domain registration transparency to enhance trust and security posture.

25
10
2
40
72
80
40
musicbandconcertsmediaentertainment+1 more
HTML5CSS3JavaScriptSwiper.js (slider)+2

Partner Domains:

www.sennheiser.cz
partner
kytary.cz
partner
2025-10-20T19:25:59.351Z
werthers-original.co.uk favicon

Storck

werthers-original.co.uk

65
RetailUnited KingdomlargeMEDIUM

Werther’s Original is a well-established confectionery brand owned by Storck, specializing in caramel and toffee products. The website serves as a brand and product showcase with rich multimedia content, product catalogs, recipes, and brand storytelling aimed at a general consumer audience in the UK. The business model focuses on retail and brand marketing within the confectionery sector, supported by a large parent company with multiple related brands. Technically, the site is built on TYPO3 CMS with modern JavaScript frameworks and includes Piwik PRO analytics with GDPR-compliant cookie consent mechanisms. The site is mobile-optimized and offers a good user experience with clear navigation and professional design. Security posture is moderate; while HTTPS is implied, explicit security headers are not detected, and no dedicated security or incident response policies are published. WHOIS data is unavailable due to domain registration errors, which slightly reduces trust but does not undermine the legitimacy of the brand given the strong corporate backing. Overall, the site is professional, trustworthy, and compliant with privacy regulations, though improvements in security transparency and WHOIS clarity are recommended.

80
83
2
60
62
60
100
werthersoriginalconfectionerycaramelretailbrand+4 more
TYPO3 CMSJavaScriptRequireJSPiwik PRO Tag Manager

Partner Domains:

www.bendicks.co.uk
partner
www.toffifee.com
partner

+1 more partners

2025-10-20T19:22:18.658Z
meyerweb.com favicon

Eric A. and Kathryn S. Meyer

meyerweb.com

45
TechnologyN/asmallHIGH

meyerweb.com is a well-established personal and professional website belonging to Eric A. Meyer, a recognized expert in CSS and web development, and his wife Kathryn, a doctor of nursing. The site primarily serves as a blog and resource hub for web developers and CSS enthusiasts, featuring detailed technical articles, tools, and personal writings. The business model is centered on content sharing and community engagement, targeting a niche audience of web professionals and learners. The site has a consistent brand identity and a strong reputation within its niche, supported by a domain age of over two decades. Technically, the site uses a combination of hand-authored HTML and WordPress for the blog section, with some static site generation for book content. The technology stack is modern and standards-compliant, with good mobile optimization and accessibility features. However, performance is moderate and could benefit from further optimization. SEO practices are good, with proper meta tags and structured navigation. From a security perspective, the site benefits from a long-standing domain with clientTransferProhibited status, indicating protection against unauthorized transfers. However, there is no evidence of DNSSEC, security headers, or explicit SSL configuration details, which suggests room for improvement. The absence of privacy and cookie policies is a compliance gap, especially for GDPR. No contact or incident response information is provided, limiting transparency in security matters. Overall, meyerweb.com is a trustworthy and authoritative site with excellent content quality and business credibility. The main risks relate to privacy compliance and security best practices, which if addressed, would enhance the site's security posture and user trust. Strategic recommendations include implementing privacy and cookie policies, enabling DNSSEC, adding security headers, and providing clear contact and vulnerability disclosure information.

15
35
17
85
62
70
-
csswebdevelopmentblogtechnologypersonalsite+1 more
HTML5CSS3JavaScript
2025-10-20T19:21:03.482Z
pinterest.com.mx favicon

Pinterest

pinterest.com.mx

74
TechnologyMexicolargeMEDIUM

Pinterest is a globally recognized technology company specializing in visual discovery and social media services. The platform enables users to find and share ideas related to recipes, home decor, fashion, and more, targeting a broad general audience. The Mexican localized site (mx.pinterest.com) reflects the company's commitment to regional markets with tailored content and language support. Pinterest operates primarily on an advertising and e-commerce integrated business model, leveraging its large user base and visual content to connect users with products and services. Technically, the website employs a modern tech stack including React, JavaScript, and WebAssembly, hosted on Amazon AWS infrastructure. It integrates multiple third-party services for fonts, analytics, advertising, and security, such as Google Fonts, Amazon Advertising, Facebook Pixel, and Arkose Labs for bot mitigation. The site demonstrates excellent performance, mobile optimization, and accessibility standards, ensuring a smooth user experience. From a security perspective, Pinterest enforces HTTPS with strong SSL configurations and implements comprehensive security headers including a strict Content Security Policy. The use of reCAPTCHA and Arkose Labs indicates proactive measures against automated abuse. Privacy and cookie policies are comprehensive and GDPR compliant, reflecting a mature privacy posture. No critical vulnerabilities or suspicious indicators were detected in the analyzed content. Overall, Pinterest's Mexican site exhibits a high level of professionalism, security, and compliance, supporting its position as a trusted and established platform. The absence of WHOIS data for the subdomain is typical and does not detract from legitimacy, as it is managed under the main pinterest.com domain. Strategic recommendations include maintaining regular security audits, enhancing transparency around vulnerability disclosures, and continuing to optimize privacy compliance.

80
53
10
85
82
90
100
socialmediavisualdiscoverye-commerceadvertisingrecipes+2 more
ReactJavaScriptWebAssemblyAmazon S3+3

Partner Domains:

pinterest.com
parent
amazon-adsystem.com
partner

+2 more partners

2025-10-20T19:20:13.293Z