Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 157 of 251|Showing 7801-7850 of 12548
realdomus.cz favicon

REALDOMUS s.r.o.

realdomus.cz

10
Real EstateCzech RepublicmediumCRITICAL

REALDOMUS s.r.o. is a professional real estate agency operating primarily in České Budějovice, Prague, and surrounding regions in the Czech Republic. The company offers comprehensive real estate services including property sales, rentals, legal and financial advisory, supported by a team of 19 professionals with over 14 years of experience. Their market position is strengthened by membership in the Realitní komora and a strong portfolio of client testimonials, reflecting high customer satisfaction and trust. Technically, the website employs a modern technology stack including Bootstrap, jQuery, Google Maps API, and various marketing and analytics tools such as Google Analytics, Facebook Pixel, and Hotjar. The site is mobile-optimized, well-structured, and provides a good user experience with clear navigation and professional design. Privacy and cookie policies are implemented with consent mechanisms, indicating compliance with GDPR requirements. From a security perspective, the website uses HTTPS and implements Google reCAPTCHA to protect forms from bots. However, explicit security headers are not clearly detected, and no public security or incident response policies are available. The absence of WHOIS data reduces domain trustworthiness, but the website content and business information appear legitimate and professional. Overall, REALDOMUS presents a credible and professional online presence with good technical and privacy practices. The main risk lies in the lack of WHOIS transparency and limited public security policy disclosures. Strategic improvements in security headers and incident response visibility would enhance trust and compliance.

-
-
-
-
-
-
-
realestatepropertysalespropertyrentalczechrepubliceskbudjovice+6 more
jQuery 3.3.1Bootstrap 4Slick CarouselMagnific Popup+7
2025-07-28T22:50:12.244Z
getrockerbox.com favicon

Rockerbox

getrockerbox.com

11
TechnologyN/aenterpriseCRITICAL

Rockerbox is an enterprise-grade marketing measurement platform that unifies Multi-Touch Attribution, Marketing Mix Modeling, and Incrementality Testing into a single solution. Positioned as a leader in marketing analytics, it serves large, data-driven companies and marketing teams seeking comprehensive insights to optimize their marketing spend. The platform emphasizes data centralization, unbiased measurement, and expert professional services, and is SOC2 Type 2 certified, reflecting a strong commitment to security and compliance. The recent acquisition by DoubleVerify further strengthens its market position. Technically, the website is built on HubSpot CMS and integrates modern analytics and marketing tools such as Google Tag Manager, Facebook Pixel, and Reddit Pixel. The site is well-optimized for performance, mobile responsiveness, and accessibility, with a professional design and clear navigation. Security best practices are observed, including HTTPS enforcement and cookie consent mechanisms, though explicit security headers and incident response contacts could be improved. The security posture is solid with SOC2 compliance and no visible vulnerabilities or exposed sensitive data. Privacy compliance is good, with a comprehensive privacy policy and cookie consent banner. However, the WHOIS data for the domain is missing or unavailable, which is unusual for an enterprise site and warrants further verification. Overall, the site demonstrates high professionalism, trustworthiness, and technical maturity.

-
-
-
-
-
-
-
marketingattributionanalyticsmeasurementsaas+3 more
HubSpot CMSGoogle Tag ManagerGoogle Analytics (gtag.js)Facebook Pixel+6

Partner Domains:

doubleverify.com
parent
2025-07-28T21:45:25.079Z
thealchemygroup.co favicon

Alchemy Advertising FZCO

thealchemygroup.co

63
MediaIndiamediumMEDIUM

Alchemy Advertising FZCO operates the Alchemy Group, a tech-first digital marketing agency founded in 2015, specializing in influencer marketing, digital media monetization, video content, digital audio, and localization solutions. The company targets brands and businesses seeking innovative marketing strategies leveraging technology and new-age channels. The group includes subsidiaries such as AndBeyond.Media, WORD, and LIT, each focusing on specific marketing and talent management services. The website presents a professional image with clear branding, client logos, and leadership profiles, supporting its market position as a medium-sized agency in the media sector primarily operating in India and the UAE. Technically, the website uses modern web technologies including HTML5, CSS3, JavaScript, jQuery, and integrates analytics tools like Google Analytics and Facebook Pixel. The site is moderately optimized for performance and mobile devices, with basic accessibility and SEO features. However, there is room for improvement in security headers and explicit security policy disclosures. The WHOIS data is fully redacted, which is common for marketing agencies but limits transparency. From a security perspective, the site uses HTTPS and secure forms but lacks visible security headers and detailed security or incident response policies. No vulnerabilities or exposed sensitive data were detected in the HTML content. Privacy compliance is basic with a privacy policy and cookie consent banner present, but GDPR-specific details are minimal. Overall, the security posture is moderate with recommendations to enhance header security and transparency. The overall risk is low given the professional presentation and lack of suspicious content, but the lack of WHOIS transparency and security header implementation are areas to address. Strategic recommendations include improving security headers, enhancing privacy and security disclosures, and conducting regular security audits to maintain trust and compliance.

15
68
17
70
100
55
100
digitalmarketinginfluencermarketingmediaagencyvideocontenttalentmanagement+2 more
HTML5CSS3JavaScriptjQuery+3

Partner Domains:

andbeyond.media
subsidiary
whatstheword.co
subsidiary

+1 more partners

2025-07-28T20:36:04.451Z
art4fans.com favicon

Art4Fans

art4fans.com

67
E-commerceCanadasmallMEDIUM

Art4Fans is a niche e-commerce retailer specializing in official gaming and entertainment artwork and posters. Founded in 2023 and operating primarily from Canada, the company offers unique printed creations on various materials such as canvas, wood, metal, and museum-grade paper. The website targets gaming and cinema fans seeking high-quality, authentic artwork with fast international shipping. The business leverages Shopify as its e-commerce platform, integrating multiple marketing and analytics tools to enhance customer experience and business insights. The site demonstrates good content quality, professional design, and consistent branding, supporting a positive market position within its niche. Technically, the website is built on a modern Shopify infrastructure with standard third-party libraries and apps, delivering moderate performance and good mobile optimization. Security posture is solid with HTTPS enforced and domain registration protections, though minor improvements such as enabling DNSSEC and publishing explicit security policies are recommended. Privacy compliance is well addressed with visible privacy and cookie policies and consent mechanisms. Overall, Art4Fans presents a trustworthy and professional online presence with room for enhanced security transparency and technical hardening.

75
85
2
55
57
80
100
e-commercegamingartworkpostersshopify+3 more
ShopifyjQueryFlickityFancybox+7

Partner Domains:

art4fans-2016.myshopify.com
service
judge.me
partner
2025-07-28T20:31:55.133Z
R

RevPAR Collective, Inc.

stashrewards.com

68
HospitalityUnited StatesmediumMEDIUM

Stash Rewards operates a loyalty program focused on independent and boutique hotels, offering travelers the ability to earn points redeemable for free nights at unique properties across North America and the Caribbean. The company positions itself as a top-rated loyalty program for discerning travelers who prefer authentic, non-chain hotel experiences. The website is professionally designed with clear navigation, mobile optimization, and integrated social media and marketing tools, reflecting a mature digital presence. Technically, the site leverages modern web technologies including React, Google Analytics, Facebook Pixel, and Sentry for error tracking. The use of HTTPS and cookie consent mechanisms indicates attention to security and privacy compliance, although explicit security headers and incident response policies are not evident. The absence of WHOIS data for the domain is a notable anomaly that impacts trustworthiness, though the website content and business information appear legitimate and professional. Security posture is generally good with encrypted communications and monitoring tools, but could be improved by publishing security policies, implementing security headers, and establishing a vulnerability disclosure program. Overall, the site presents a trustworthy and user-friendly platform for its target audience, but domain registration transparency should be addressed to enhance credibility.

60
68
2
85
67
85
100
loyaltyboutiquehotelstravelrewardsindependenthotels+1 more
Google Tag ManagerGoogle Analytics (gtag.js)Facebook PixelRaven.js (Sentry for error tracking)+3
2025-07-28T20:28:28.680Z
npca.org favicon

National Parks Conservation Association

npca.org

68
Non-profitUnited StateslargeMEDIUM

The National Parks Conservation Association (NPCA) is a well-established non-profit organization dedicated to protecting and enhancing America's National Park System. Their website reflects a strong commitment to advocacy, education, and public engagement with a professional and consistent brand presence. The organization targets a broad audience including national park visitors, environmental advocates, and the general public. NPCA operates primarily through fundraising, advocacy campaigns, and educational outreach, positioning itself as a leading voice in national park conservation. Technically, the website employs a modern technology stack including JavaScript frameworks, SVG graphics, and integrates multiple analytics and advertising services such as Google Analytics, Facebook Pixel, and Quantcast. The site is mobile-optimized, accessible, and SEO-friendly, though some opportunities exist to enhance security headers and incident response transparency. Privacy compliance is robust with clear policies and cookie consent mechanisms in place. Security posture is generally strong with HTTPS enforced and CSRF protections on forms, but lacks explicit security policy disclosures and incident response contacts. No critical vulnerabilities or exposed sensitive data were detected. The absence of WHOIS data limits domain registration trust analysis, but the presence of multiple trust indicators and professional content supports legitimacy. Overall, NPCA's website demonstrates a mature digital presence with strong business credibility and good security hygiene. Strategic improvements in security policy transparency and WHOIS data availability would further enhance trust and compliance.

65
53
2
82
77
80
100
nationalparksconservationnon-profitadvocacyenvironment+1 more
JavaScriptSVGGoogle AnalyticsFacebook Pixel+7

Partner Domains:

support.npca.org
partner
act.npca.org
partner

+1 more partners

2025-07-28T19:25:47.888Z
friendsofkww.org favicon

Friends of Katahdin Woods and Waters

friendsofkww.org

61
Non-profitUnited StatessmallMEDIUM

Friends of Katahdin Woods and Waters is a small non-profit organization dedicated to the preservation, protection, and promotion of the Katahdin Woods and Waters National Monument. The organization focuses on conservation efforts, educational youth programs, community events, and fundraising through memberships and donations. Their market position is regional with a clear mission to engage the local and broader community in outdoor and conservation activities. Technically, the website is built on WordPress using the Organic Nonprofit theme and WooCommerce for donation processing. It employs modern web technologies including jQuery, Google Analytics, and Facebook Pixel for tracking. The site is mobile optimized with good SEO practices but lacks some advanced accessibility features and security headers. From a security perspective, the site uses HTTPS with a good SSL configuration and secure forms. However, it lacks visible security headers and does not provide privacy or cookie policies, which are important for compliance and user trust. No vulnerabilities or exposed sensitive data were detected in the HTML content. Overall, the website is professional and trustworthy with clear contact information and social media presence. The lack of WHOIS data limits domain registration insights, but the privacy protection is justified for a non-profit. Recommendations include adding privacy and cookie policies, implementing security headers, and publishing incident response or vulnerability disclosure information to enhance security posture and compliance.

80
35
2
80
85
90
40
non-profitconservationeducationcommunityoutdoors+1 more
WordPressWooCommercejQueryGoogle Analytics+1
2025-07-28T19:25:32.830Z
mooiwerkbreda.nl favicon

MOOIWERK

mooiwerkbreda.nl

62
Non-profitNetherlandssmallMEDIUM

MOOIWERK is a community-oriented platform dedicated to facilitating volunteer work and supporting volunteer organizations and sports associations in Breda, Netherlands. The website targets local residents interested in volunteering opportunities and community engagement. The business model appears to be non-profit or community service focused, aiming to connect volunteers with organizations in the Breda area. The platform is relatively young, with domain registration dating back to 2018, and maintains a consistent brand presence with good content quality and user experience. Technically, the website is built on WordPress using the Astra theme and leverages popular plugins such as Yoast SEO, Elementor, and LearnDash LMS. It integrates multiple marketing and analytics tools including Google Tag Manager, Facebook Pixel, Hotjar, and ActiveCampaign, indicating a moderate level of digital maturity. The site is hosted by team.blue nl B.V. and employs HTTPS with DNSSEC enabled, reflecting a solid baseline security posture. Mobile optimization and SEO practices are good, though accessibility features are basic. From a security perspective, the site benefits from HTTPS, DNSSEC, and Google reCAPTCHA to mitigate automated abuse. However, it lacks explicit security headers and does not publish privacy or cookie policies, which are critical for GDPR compliance. There is no visible incident response or vulnerability disclosure information, which could be improved to enhance trust and security readiness. No critical vulnerabilities or suspicious patterns were detected. Overall, the website is functional and trustworthy for its community service purpose but requires improvements in privacy compliance and security transparency. Strategic recommendations include publishing comprehensive privacy and cookie policies, implementing security headers, and establishing incident response contacts to strengthen compliance and user trust.

15
60
17
75
85
70
100
volunteerbredacommunitynon-profitsports+1 more
WordPressYoast SEO pluginElementorGoogle reCAPTCHA+6
2025-07-28T19:24:27.520Z
smithsonianstore.com favicon

Smithsonian Store

smithsonianstore.com

68
RetailUnited StateslargeMEDIUM

The Smithsonian Store website serves as the official e-commerce platform for the Smithsonian Institution, offering a wide range of museum-inspired products including jewelry, apparel, books, toys, and home decor. The site targets general consumers interested in educational and cultural merchandise, leveraging the strong Smithsonian brand to position itself as a trusted retailer in the museum gift market. The business model is primarily retail e-commerce, supported by a large-scale, professionally managed online storefront hosted on BigCommerce. Technically, the website employs a modern technology stack including BigCommerce Stencil framework, Google Analytics 4, Microsoft Clarity, and Facebook Pixel for analytics and marketing. It uses lazy loading for images, Typekit fonts, and integrates multiple third-party scripts for enhanced user experience and tracking. The site is well optimized for mobile devices, accessibility, and SEO, with fast loading times and clear navigation. From a security perspective, the site enforces HTTPS, implements key security headers, and shows no signs of exposed sensitive data or vulnerabilities. Privacy compliance is strong with clear privacy and cookie policies, including consent mechanisms and GDPR considerations. However, no explicit security policy or incident response information is publicly available. The WHOIS data is unavailable, likely due to privacy protection, but the website's branding and infrastructure strongly indicate legitimacy. Overall, the Smithsonian Store website demonstrates a high level of professionalism, security, and compliance suitable for a large institutional retailer. Strategic recommendations include maintaining regular security audits of third-party scripts, enhancing CSP reporting, and potentially publishing more detailed security and incident response policies to further build trust.

55
73
2
55
95
80
100
museume-commerceretailgiftssmithsonian+5 more
BigCommerceGoogle Analytics 4Microsoft ClarityFacebook Pixel+5

Partner Domains:

subscribe.smithsonianmag.com
partner
2025-07-28T19:23:47.287Z
S

Smithsonian Enterprises

smithsonian.com

61
MediaUnited StateslargeMEDIUM

Smithsonian.com serves as the digital platform for Smithsonian Enterprises, offering a blend of retail shopping, award-winning editorial content, original television series, and travel experiences worldwide. The website targets a general audience interested in culture, education, and travel, leveraging the strong brand recognition of the Smithsonian Institution. The domain has been registered since 2001, reflecting a mature and established online presence consistent with the Smithsonian's reputation. Technically, the website employs a modern technology stack including Cloudflare for DNS and CDN services, Google Analytics, Facebook Pixel, Hotjar, and Google Tag Manager for analytics and marketing. The site demonstrates good mobile optimization and a professional design, although some SEO and accessibility features appear basic. Performance is moderate, with room for improvement in technical modernization and security hardening. From a security perspective, the site enforces HTTPS and uses domain status locks to prevent unauthorized changes. However, DNSSEC is not enabled, and no explicit security headers or incident response policies are visible in the provided content. The absence of privacy and cookie policies, as well as a consent mechanism, indicates gaps in privacy compliance. No vulnerabilities or exposed sensitive data were detected, but improvements in security transparency and compliance documentation are recommended. Overall, Smithsonian.com is a credible and professionally maintained website with a strong brand and business model. To enhance trust and compliance, it should publish clear privacy and cookie policies, implement consent mechanisms, enable DNSSEC, and adopt security best practices such as security headers and incident response disclosures.

25
68
17
55
65
80
100
cultureeducationmediaretailtravel+1 more
Cloudflare DNS and CDNGoogle AnalyticsGoogle Tag ManagerFacebook Pixel+3
2025-07-28T19:23:42.271Z
pointsoflight.org favicon

Points of Light

pointsoflight.org

65
Non-profitUnited StateslargeMEDIUM

Points of Light is a well-established non-profit organization founded in 1990, dedicated to increasing volunteerism and civic engagement globally. The organization serves a broad audience including nonprofits, corporations, and individual volunteers, providing resources, events, and corporate partnership programs to maximize social impact. Their market position is strong as a leading entity in volunteer mobilization with a large global footprint. Technically, the website is built on WordPress and leverages modern analytics and marketing tools such as Google Analytics, Hotjar, and HubSpot, indicating a mature digital infrastructure. The site is mobile-optimized, accessible, and SEO-friendly, supporting a positive user experience. From a security perspective, the site enforces HTTPS, employs multiple security headers, and does not expose sensitive data. However, it lacks a publicly available security policy or vulnerability disclosure page, which are recommended for transparency and incident readiness. Overall, the website presents a low risk profile with strong trust indicators and professional presentation. Strategic improvements in security transparency and incident response communication would further enhance their security posture and stakeholder confidence.

25
68
17
70
75
80
100
non-profitvolunteeringcivicengagementcommunityservice
WordPressjQueryGoogle Tag ManagerGoogle Analytics+5

Partner Domains:

guidestar.org
partner
charitynavigator.org
partner

+1 more partners

2025-07-28T19:21:31.482Z
hrc.org favicon

Human Rights Campaign

hrc.org

66
Non-profitN/alargeMEDIUM

Human Rights Campaign (HRC) is a leading non-profit organization dedicated to advocating for LGBTQ+ equality and inclusion since 1980. The website serves as a hub for community engagement, education, policy advocacy, and fundraising. It targets LGBTQ+ individuals and allies, offering resources, campaigns, and calls to action such as volunteering and donations. The organization enjoys a strong market position as a prominent voice in LGBTQ+ rights advocacy in the United States. Technically, the website employs a modern technology stack including Google Tag Manager, Hotjar, Yotpo, and multiple advertising pixels, indicating a mature digital marketing and analytics infrastructure. The site is well optimized for performance, mobile responsiveness, and accessibility, with comprehensive SEO and metadata implementation. From a security perspective, the site uses HTTPS with good SSL configuration and implements cookie consent mechanisms aligned with GDPR compliance. However, explicit security headers are not detected, and there is no public security policy or incident response information available. The WHOIS data is privacy protected, which is common for non-profits but limits domain registration transparency. Overall, the website presents a professional, trustworthy, and secure platform for its advocacy mission. Strategic recommendations include enhancing security headers, publishing security and incident response policies, and providing clearer contact information for security and privacy inquiries to further strengthen trust and compliance.

50
65
2
87
67
75
100
lgbtqequalitynon-profitadvocacydonate+2 more
Google Tag ManagerGoogle OptimizeHotjarYotpo+5

Partner Domains:

shop.hrc.org
service
give.hrc.org
service

+1 more partners

2025-07-28T19:21:21.389Z
owletcare.com favicon

Owlet US

owletcare.com

76
HealthcareUnited StatesmediumLOW

Owlet US operates a well-established e-commerce platform specializing in FDA-cleared smart baby monitors, including the Dream Sock®, Dream Duo 2, and Owlet Cam 2. The company targets parents and caregivers seeking advanced infant monitoring solutions that provide live health readings and HD video for peace of mind. Owlet holds a strong market position as an innovator in infant healthcare technology with a focus on safety and reliability. The website is professionally designed, mobile-optimized, and leverages Shopify's robust platform and third-party marketing tools such as Klaviyo and Bazaarvoice to enhance customer engagement and sales. Technically, the website is built on Shopify with modern web technologies including jQuery and video media elements. It uses Cloudflare DNS and Shopify CDN for hosting, ensuring fast performance and good availability. SEO and accessibility features are well implemented, and the site includes structured data for enhanced search engine understanding. Privacy and cookie policies are present with consent mechanisms, reflecting good compliance with GDPR and related regulations. From a security perspective, the site enforces HTTPS with strong domain registration protections and no visible vulnerabilities or exposed sensitive data. However, DNSSEC is not enabled, and there is no publicly available security policy or incident response information, which could be improved. The domain registration is consistent with the business claims, showing a mature and legitimate online presence. Overall, Owlet US presents a low-risk profile with a strong security posture, good privacy compliance, and a professional e-commerce presence. Strategic recommendations include enabling DNSSEC, publishing a security policy, and adding vulnerability disclosure information to further enhance trust and security transparency.

75
73
20
100
75
80
100
e-commercehealthcarebabymonitorfda-clearedshopify+2 more
ShopifyjQueryKlaviyoBazaarvoice+5

Partner Domains:

owletcare.myshopify.com
service
bazaarvoice.com
partner

+2 more partners

2025-07-28T19:02:01.961Z
P

Printing United Alliance

printing.org

75
ManufacturingUnited StateslargeMEDIUM

Printing United Alliance is a prominent trade association serving the printing industry in the United States. The organization provides a wide range of services including education, advocacy, industry events, and market research to support printing businesses and professionals. Their website reflects a mature digital presence with a focus on member engagement and industry resources. The site is well-branded and targets printing industry stakeholders effectively. Technically, the website employs a modern technology stack including Sitefinity CMS, various marketing automation and analytics tools such as Marketo, Microsoft Clarity, and Visual Website Optimizer. The site is mobile optimized and uses HTTPS with appropriate security headers, indicating a good level of technical maturity. Performance is moderate, with room for improvement in accessibility and SEO. From a security perspective, the site demonstrates good practices such as HTTPS enforcement and security headers. However, it lacks publicly available security policies, incident response information, and vulnerability disclosure mechanisms, which are recommended for transparency and trust. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website represents a legitimate and professional organization with a solid digital footprint. The absence of WHOIS data due to privacy protection is common for such entities and does not detract significantly from trustworthiness. Strategic recommendations include publishing security and incident response policies, improving accessibility, and establishing a vulnerability disclosure program to enhance security posture and stakeholder confidence.

80
73
17
85
82
85
100
printingtradeassociationprintingindustryeducationadvocacy+2 more
JavaScriptGoogle Tag ManagerMarketoMicrosoft Clarity+5
2025-07-28T17:39:03.519Z