Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 157 of 166|Showing 7801-7850 of 8294
featuredcustomers.com favicon

Featured Customers

featuredcustomers.com

64
TechnologyN/AmediumMEDIUM

Featured Customers operates as an online platform specializing in providing reviews, testimonials, and case studies for B2B and SaaS software and services. The platform targets B2B buyers and SaaS users seeking customer insights to inform purchasing decisions. The business model revolves around aggregating and showcasing customer feedback to enhance software selection processes. The company appears to be medium-sized within the technology sector, with a moderate market position focused on niche B2B software review services. Technically, the website is built using React and served via an nginx server hosted on DigitalOcean. It employs Google Fonts and Font Awesome for styling and icons, along with third-party tools such as UserWay for accessibility and Factors.ai for tracking. Performance is fast, but mobile optimization and SEO are basic. The absence of a CMS and limited metadata suggest a relatively simple technical infrastructure. From a security perspective, the site implements some security headers like X-Frame-Options and Content-Security-Policy to prevent clickjacking and framing attacks. However, the SSL configuration is weak, with no modern TLS protocols enabled, which poses a significant risk to secure communications. There are no visible privacy, cookie, or terms of service policies, nor GDPR compliance mechanisms, indicating gaps in regulatory adherence and user data protection. No incident response or vulnerability disclosure information is available. Overall, the website presents moderate trustworthiness but requires significant improvements in security posture, privacy compliance, and transparency. Strategic enhancements in SSL configuration, policy publication, and accessibility would strengthen the platform's reliability and user confidence.

50
25
25
90
80
85
90
B2BSaaSSoftware ReviewsCustomer TestimonialsCase Studies+1 more
ReactnginxGoogle FontsFont Awesome+2
2025-06-14T12:40:50.039Z
mongodb.com favicon

MongoDB, Inc.

mongodb.com

91
TechnologyUnited StatesenterpriseLOW

MongoDB, Inc. is a leading provider of modern, flexible, and AI-ready database solutions designed to help developers and enterprises build scalable applications. Positioned as a market leader in cloud database management systems, MongoDB offers a comprehensive suite of services including MongoDB Atlas, self-managed enterprise solutions, and developer tools. The company targets a broad audience ranging from startups and AI innovators to large enterprises across various sectors such as technology, financial services, healthcare, retail, automotive, and telecommunications. Their business model combines SaaS offerings with self-managed deployments, emphasizing flexibility and performance. Technically, MongoDB's website leverages modern web technologies including Next.js and React, hosted on AWS CloudFront CDN, and managed via Contentstack CMS. The site demonstrates fast performance, good mobile optimization, and strong SEO practices. Security-wise, MongoDB employs a valid SSL certificate but currently lacks modern TLS protocol support and HSTS enforcement, which are recommended for enhanced security. The site includes comprehensive legal and security policies, including a vulnerability disclosure policy, but lacks a visible cookie consent mechanism. Overall, MongoDB maintains a strong security posture with no detected vulnerabilities in SSL/TLS configurations and provides clear trust signals through customer case studies and industry recognitions. The company’s digital maturity is high, with a well-structured, professional website that supports its market leadership. Strategic improvements in security protocols and privacy compliance mechanisms would further strengthen their risk management and user trust.

-
-
-
100
80
85
100
databaseclouddeveloperAIenterprise+4 more
Next.jsReactSource Code Pro fontEuclid Circular A font+2

Partner Domains:

cloud.mongodb.com
service
support.mongodb.com
service

+1 more partners

2025-06-14T12:17:27.850Z
nifty.com favicon

NIFTY Corporation

nifty.com

82
TelecommunicationsJapanlargeLOW

NIFTY Corporation operates as a major Japanese internet service provider offering a wide range of broadband, mobile SIM, security, and media services primarily targeting Japanese consumers. The company maintains a strong market position with a comprehensive portfolio including @nifty光 broadband, NifMo mobile SIM, and various security and lifestyle services. Their digital presence is built on modern web technologies such as Next.js and is hosted via Amazon CloudFront, ensuring fast content delivery and good mobile optimization. However, the website currently lacks a valid SSL certificate, which is a critical security concern that undermines user trust and data protection. Security headers are partially implemented, but the absence of DNSSEC, CAA records, and HSTS reduces domain and transport security. The site uses multiple advertising and tracking services, with moderate user tracking and basic privacy compliance. Contact information is limited to a phone number with no visible email addresses or contact forms on the main page. Overall, the website is professionally designed with good content relevance and navigation clarity but requires urgent security improvements to protect users and enhance trust.

55
-
-
70
100
85
100
ISPInternet Service ProviderJapanTelecommunicationsSecurity+3 more
Next.jsReactJavaScriptAmazon CloudFront+1

Partner Domains:

lifemedia.jp
partnerpending
nojima.co.jp
partnerpending

+3 more partners

2025-06-14T12:17:00.411Z
whitedog.app favicon

Portal

whitedog.app

53
technologysmallMEDIUM

The website's overall security posture is currently weak, with critical and high-severity issues spanning multiple key areas including email authentication, security headers, GDPR compliance, and incident response readiness. The absence of fundamental security headers such as Strict-Transport-Security and X-Frame-Options increases the risk of man-in-the-middle attacks and clickjacking. Significant GDPR compliance gaps, like missing privacy and cookie policies and lack of consent mechanisms, could expose the business to regulatory fines and reputational damage. The lack of a formal information security framework, incident response procedures, and security policy documentation indicates immature organizational security governance, raising operational risk in the event of a breach. Email security is critically deficient, lacking SPF, DMARC, and DKIM configurations, which heightens exposure to phishing and spoofing attacks. SSL/TLS configuration weaknesses and missing DNSSEC further reduce trustworthiness and increase vulnerability to network attacks. While network security posture scores well, the overall security gaps must be urgently addressed to protect business assets, customer data, and regulatory compliance. Immediate remediation will safeguard the company’s reputation, reduce breach risk, and ensure compliance with evolving cybersecurity regulations like NIS2.

30
40
25
35
65
85
100
React

Partner Domains:

stripe.com
payment69
2025-06-14T08:49:10.723Z
everyday.com.au favicon

Everyday Rewards

everyday.com.au

66
loyalty programAustralialargeMEDIUM

The website demonstrates a strong foundation in network security and SSL/TLS implementation, scoring 100 in these areas, which ensures encrypted communication and robust network defenses. However, significant gaps exist in security headers, GDPR compliance, and adherence to the NIS2 directive, with scores ranging from 25 to 35 out of 100, exposing the business to regulatory, reputational, and operational risks. The absence of critical security headers like Content-Security-Policy and X-Frame-Options increases vulnerability to cross-site scripting and clickjacking attacks. Lack of privacy policies, cookie consent mechanisms, and third-party privacy disclosures pose serious compliance issues under GDPR, potentially resulting in fines and legal consequences. Deficiencies in information security frameworks, incident response plans, and business continuity preparations further heighten the risk of prolonged service disruptions and inadequate breach management. While email security and DNS health are relatively strong, enabling DNSSEC and configuring CAA records would enhance domain integrity and prevent abuse. Addressing these weaknesses promptly will protect customer trust, ensure regulatory compliance, and reduce the likelihood of costly security incidents.

35
25
25
85
100
85
100
loyaltyrewardsretailAustraliaWoolworths
ReactNext.jsJavaScriptAEM (Adobe Experience Manager)+2

Partner Domains:

bigw.com.au
subsidiaryanalyzing...
originenergy.com.au
partneranalyzing...

+1 more partners

2025-06-13T21:58:14.151Z