Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

150016
Websites
130
Industries
113
Countries
52
Avg Score
Page 165 of 1026|Showing 8201-8250 of 51300
one.store favicon

OneStore

one.store

65
TechnologyN/amediumMEDIUM

OneStore is a technology company specializing in AI-powered customer engagement and marketing solutions tailored for e-commerce businesses. Their platform offers a comprehensive suite of tools including abandoned cart recovery, social proof notifications, gamified popups, email and SMS marketing, and integrations with major e-commerce platforms such as Shopify, WooCommerce, and BigCommerce. The company has established a strong market presence with over 150,000 businesses using their services and more than 2,450 five-star reviews on the Shopify App Store, indicating high customer satisfaction and trust. Technically, the website employs a modern technology stack with JavaScript frameworks, analytics tools like Google Analytics and ProfitWell, and customer support integrations such as Crisp chat. The site is hosted behind Cloudflare, ensuring performance and security benefits. The website is well-optimized for mobile devices, accessible, and SEO-friendly, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS and uses domain status protections to prevent unauthorized transfers or updates. Cookie consent mechanisms are implemented in compliance with GDPR and CCPA regulations. However, there is no explicit security policy or incident response contact information published, and DNSSEC is not enabled, which could be improved to enhance security posture. Overall, OneStore presents a professional, trustworthy, and technically sound online presence with strong privacy compliance and business credibility. Strategic improvements in security transparency and DNS security would further strengthen their risk profile.

30
68
2
75
75
80
100
ecommercemarketingaicustomerengagementshopify+4 more
JavaScriptjQuerySwiper.jsGoogle Analytics+7
2025-10-24T15:53:53.131Z
caritas-beider-basel.ch favicon

Caritas beider Basel

caritas-beider-basel.ch

11
Non-profitSwitzerlandmediumCRITICAL

Caritas beider Basel is a regional non-profit organization focused on providing social and legal support services, integration assistance, and emergency aid to individuals in the Basel-Landschaft and Basel-Stadt regions of Switzerland. The organization operates multiple service locations and offers a wide range of programs including social counseling, legal advice related to social welfare, secondhand clothing stores, affordable meals, child sponsorships, and support for caregivers. Their market position is strong within the regional social services sector, supported by their ZEWO certification which attests to their trustworthy handling of donations. Technically, the website employs modern web technologies including JavaScript, Google Tag Manager, and SEOmatic for SEO management. The site is well-structured, mobile-optimized, and provides a good user experience with clear navigation and professional design. Privacy and cookie policies are implemented with consent mechanisms, reflecting good compliance with GDPR requirements. Analytics usage is extensive, leveraging Google Analytics and Tag Manager, with transparent cookie consent. From a security perspective, the site uses HTTPS and includes CSRF tokens, but explicit security headers are not clearly visible in the HTML content. No critical vulnerabilities or exposed sensitive data were detected. The domain WHOIS data aligns well with the organization's identity and location, indicating legitimacy and consistency. No WAF or blocking mechanisms interfere with content access. Overall, Caritas beider Basel presents a professional, trustworthy, and well-maintained online presence that supports its mission of social aid and community support. Strategic recommendations include enhancing security headers, publishing a formal security policy, and establishing a vulnerability disclosure process to further strengthen their security posture.

-
-
-
-
-
-
-
socialservicesnon-profitcharitysocialcounselinglegaladvice+4 more
JavaScriptGoogle Tag ManagerGoogle AnalyticsHTMX

Partner Domains:

caritas-shop.ch
partner
zewo.ch
partner

+2 more partners

2025-10-24T15:50:28.378Z
hev.ch favicon

État de Vaud - Direction générale de l’enseignement supérieur (DGES)

hev.ch

63
EducationSwitzerlandmediumMEDIUM

The Direction générale de l’enseignement supérieur (DGES) is a governmental entity under the Canton of Vaud, Switzerland, responsible for the strategic oversight and policy development of higher education institutions within the canton. It supports education, research, and innovation, focusing on optimizing conditions for universities and specialized schools. The website serves as an official communication channel providing detailed information on missions, projects, legal frameworks, and contact points for stakeholders including students, academic institutions, and government partners. Technically, the website is built on TYPO3 CMS with modern frameworks like Bootstrap, and integrates analytics tools such as Matomo, Mouseflow, and Google Tag Manager. The site demonstrates good mobile optimization, accessibility, and SEO practices, reflecting a mature digital infrastructure suitable for a public sector organization. From a security perspective, the site enforces HTTPS and uses some security headers, though explicit security policies and incident response contacts are not published. No vulnerabilities or suspicious content were detected. Privacy compliance is basic, with cookie consent mechanisms and a privacy policy present, but GDPR compliance is not explicitly stated. Overall, the website is trustworthy, professional, and well-maintained, with a strong alignment between domain registration and organizational identity. Strategic recommendations include enhancing security header implementation, publishing security and incident response policies, and improving privacy compliance transparency.

35
50
17
70
67
85
100
educationgovernmenthighereducationswitzerlandpolicy+2 more
TYPO3 CMSBootstrapMatomo AnalyticsGoogle Tag Manager+1
2025-10-24T15:34:53.331Z
benz-sport.de favicon

Gotthilf Benz Turngerätefabrik GmbH + Co KG

benz-sport.de

57
RetailGermanymediumMEDIUM

Gotthilf Benz Turngerätefabrik GmbH + Co KG operates a professional e-commerce platform specializing in sports equipment manufacturing and retail. The company targets a broad audience in Germany and neighboring countries, offering a wide range of sports products with a focus on quality and service. The website is well-branded, consistent, and provides clear contact and business information, reinforcing its market position as a trusted sports equipment provider. Technically, the website leverages Prestashop CMS with modern integrations such as Google Tag Manager, Facebook Pixel, and PayPal SDK, indicating a mature digital infrastructure. The site is mobile-optimized and includes SEO best practices, although some accessibility features could be enhanced. Performance is moderate, suitable for the business scale. Security posture is solid with HTTPS enforced and GDPR compliance mechanisms in place, including cookie consent and privacy policy. However, explicit security headers could be improved. No critical vulnerabilities or suspicious activities were detected. The WHOIS data aligns well with the business identity, supporting legitimacy. Overall, the website presents a low-risk profile with good privacy compliance and business credibility. Strategic improvements in security headers and accessibility would further strengthen its posture.

20
80
17
70
95
70
20
sportse-commercegermanyretailmanufacturing+2 more
Google Tag ManagerFacebook PixelPayPal SDKjQuery UI Autocomplete+4

Partner Domains:

benz-sport.com
partner
benz-sport.at
partner
2025-10-24T15:34:18.169Z
arag.de favicon

ARAG Allgemeine Versicherungs-AG

arag.de

68
FinanceGermanylargeMEDIUM

ARAG Allgemeine Versicherungs-AG is Germany's largest family-owned insurance company, offering a broad portfolio of insurance products including legal protection, health, liability, travel, home, pet, and commercial insurance. The website reflects a mature, well-established business with over 90 years of market presence and a strong customer base exceeding 12 million. The company emphasizes tailored insurance solutions and customer service accessibility through multiple channels including online portals, live chat, and local advisors. The site is professionally designed, mobile-optimized, and rich in content relevant to its target audience of private and commercial insurance customers in Germany. Technical infrastructure incorporates modern web technologies, consent management, and analytics tools, indicating a digitally mature organization. Security posture is strong with HTTPS, consent mechanisms, and reputable third-party integrations, though explicit security policies and vulnerability disclosure mechanisms are not publicly detailed. Overall, ARAG's website demonstrates high professionalism, trustworthiness, and compliance with privacy regulations, supporting its market leadership and customer trust.

45
73
2
85
77
75
100
araginsurancelegalprotectionhealthinsuranceliabilityinsurance+3 more
Google Tag ManagerUsercentrics Consent ManagementVisual Website Optimizer (VWO)RealPerson Chat+3

Partner Domains:

arag-karriere.de
partner
2025-10-24T15:34:13.157Z
mein-fahrtwind.de favicon

Sparkassen- und Giroverband Hessen-Thüringen (SGVHT)

mein-fahrtwind.de

55
FinanceGermanylargeMEDIUM

Mein Fahrtwind is a promotional website operated by the Sparkassen- und Giroverband Hessen-Thüringen (SGVHT), a public financial association in Germany. The site hosts a contest offering participants the chance to win one of eight electric scooters, targeting residents of Hessen, Thüringen, and parts of Rheinland-Pfalz. The website is professionally designed with comprehensive legal and privacy documentation, reflecting a strong commitment to GDPR compliance and user data protection. The contest employs a double opt-in mechanism to ensure participant consent and data accuracy. Technically, the site uses modern web technologies including Google Tag Manager, Matomo analytics, Adobe Typekit fonts, and a cookie consent management system. Hosting is managed via DomainControl, indicating a professional infrastructure. The site is mobile-optimized and accessible, with good SEO practices. Security measures include HTTPS and IP masking in analytics, though HTTP security headers are not explicitly detected. From a security perspective, the site demonstrates good practices with no visible vulnerabilities or exposed sensitive data. Privacy policies are detailed and transparent, including a named data protection officer contact. No incident response or vulnerability disclosure policies are found, which could be areas for improvement. Overall, the site presents a low risk profile with strong compliance and trust indicators. Strategically, the site effectively supports the SGVHT's marketing and public engagement goals, leveraging digital tools to promote sustainable mobility. The integration of multiple marketing and tracking tools is balanced with user privacy considerations, positioning the organization as responsible and trustworthy in its digital presence.

15
85
2
65
100
70
20
sparkassengewinnspielmobilitte-schwalbehessen+4 more
HTML5CSS3JavaScriptGoogle Tag Manager+5
2025-10-24T15:33:17.753Z
finanzen-mit-daniel-jung.de favicon

Sparkassen- und Giroverband Hessen-Thüringen (SGVHT)

finanzen-mit-daniel-jung.de

47
FinanceGermanymediumHIGH

The website 'finanzen-mit-daniel-jung.de' is an educational platform focused on financial literacy, primarily targeting students and educators in the Hessen and Thüringen regions of Germany. It is operated under the auspices of the Sparkassen- und Giroverband Hessen-Thüringen, a reputable financial association. The site offers a series of well-structured, easy-to-understand videos and learning materials to enhance financial knowledge. The partnership with Sparkassen and the inclusion of the Sparkassen-SchulService platform reinforce its credibility and regional relevance. Technically, the website employs modern web technologies including HTML5, CSS3, JavaScript, and integrates Google Tag Manager and Matomo for analytics, alongside a GDPR-compliant cookie consent mechanism. The site is hosted on servers indicated by the nameservers 'your-server.de' and related domains, suggesting a professional hosting environment. The site is mobile-optimized and demonstrates good SEO and accessibility practices, though some improvements in accessibility and security headers could be made. From a security perspective, the site uses HTTPS with strong SSL configuration and implements cookie consent for privacy compliance. No critical vulnerabilities or exposed sensitive data were detected. Privacy policies and terms of service are comprehensive and clearly presented, with a designated data protection officer contact provided. The site does not employ a vulnerability disclosure policy, which could be considered for future enhancement. Overall, the website presents a low-risk profile with strong business credibility and compliance posture. It effectively serves its educational mission with professional content and transparent governance. Strategic recommendations include enhancing HTTP security headers, formalizing a vulnerability disclosure process, and improving accessibility features to further strengthen the site's security and user experience.

15
45
17
70
100
45
-
financeeducationfinancialliteracysparkassevideos+2 more
HTML5CSS3JavaScriptGoogle Tag Manager+2

Partner Domains:

sparkassen-schulservice.de
partner
sfg-ht.de
partner
2025-10-24T15:33:02.574Z
helvetiarockt.ch favicon

Helvetiarockt

helvetiarockt.ch

48
OtherSwitzerlandsmallHIGH

Helvetiarockt is a Swiss non-profit organization dedicated to empowering girls, women, intersex, non-binary, trans, and agender individuals through music workshops, sensitization events, and networking platforms. The organization positions itself as a niche player in the Swiss cultural and social empowerment sector, leveraging partnerships such as musicdirectory.ch and diversityroadmap.org to extend its reach and impact. The website is multilingual, supporting German, French, Italian, Romansh, and English, reflecting its inclusive and broad audience approach. Technically, the website is built on WordPress with modern integrations including Google Analytics, Google Tag Manager, and Elfsight widgets. It uses jQuery and GSAP for animations and interactive elements. The site demonstrates good mobile optimization and SEO practices, although some accessibility features could be enhanced. Performance is moderate, with deferred script loading to improve user experience. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks advanced security headers and explicit security or incident response policies. Privacy compliance is basic, with privacy and cookie policies present but no active consent mechanism. The site collects user data via newsletter subscription forms and uses tracking scripts moderately. Overall, Helvetiarockt presents a trustworthy and professional online presence with a clear mission and audience. Security and privacy practices are adequate but could be improved to meet higher compliance standards. The domain registration data aligns well with the organization's profile, supporting legitimacy. Strategic recommendations include enhancing security headers, implementing cookie consent, and publishing explicit security policies to strengthen trust and compliance.

15
53
2
85
70
75
-
empowermentmusicworkshopsdiversitynon-profitswitzerland
Google AnalyticsGoogle Tag ManagerjQueryGSAP TweenMax+3

Partner Domains:

musicdirectory.ch
partner
diversityroadmap.org
partner
2025-10-24T15:32:32.188Z
A

Avadis Vorsorge AG

avadis.ch

55
FinanceSwitzerlandmediumMEDIUM

Avadis Vorsorge AG is a Swiss financial services company specializing in pension fund management and investment solutions for institutional and private clients. The company offers a range of services including pension fund administration, private equity investments, real estate investments, and financial planning. With over 450 institutional clients and a strong presence in Switzerland, Avadis positions itself as a reliable and independent partner in the financial sector. The website reflects a professional and consistent brand image, targeting institutional investors and private individuals seeking investment opportunities and pension solutions. Technically, the website employs modern JavaScript frameworks, Google Analytics, and OneTrust for cookie consent, indicating a mature digital infrastructure. The site is mobile-optimized, accessible, and SEO-friendly, providing a good user experience. Security-wise, the site uses HTTPS with strong SSL configuration and appropriate security headers, but lacks publicly available security policies or incident response contacts. Privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanism. Overall, the website demonstrates a high level of professionalism and trustworthiness, with minor recommendations to enhance security transparency and incident response readiness.

40
88
2
80
62
85
-
financepensionskassenprivateequityinvestmentinstitutionelleanleger+3 more
JavaScriptGoogle AnalyticsGoogle Tag ManagerOneTrust Cookie Consent
2025-10-24T15:31:41.858Z
mediacampus-frankfurt.de favicon

mediacampus-frankfurt

mediacampus-frankfurt.de

66
EducationGermanymediumMEDIUM

Mediacampus Frankfurt is an established educational institution specializing in seminars, training, and educational programs for the book trade and media industry in Germany. The website presents a professional and well-structured platform offering a variety of courses, webinars, and training sessions targeting professionals, newcomers, and specialists in publishing and media sectors. The institution maintains a strong social media presence and provides detailed event information, enhancing its market position as a key player in media education. Technically, the website employs modern web technologies including JavaScript, Algolia Search for site search functionality, and Google Tag Manager for analytics, which is loaded conditionally upon cookie consent. The site is hosted on Anexia servers, uses HTTPS with good SSL configuration, and is optimized for mobile devices with good accessibility and SEO practices. However, some security headers are not explicitly detected, and no explicit security or incident response policies are published. From a security perspective, the site demonstrates good practices such as HTTPS enforcement and privacy-aware analytics loading. No vulnerabilities or exposed sensitive data were found in the provided content. The WHOIS data aligns with the business claims, showing consistent domain registration and hosting. Privacy and cookie policies are not explicitly found in the provided content, which is a compliance gap. Overall, the site is safe, professional, and trustworthy with room for improvement in privacy disclosures and security policy transparency.

40
83
2
85
77
60
100
educationseminarstrainingmediabooktrade+1 more
JavaScriptAlgolia SearchGoogle Tag ManagerSVG icons
2025-10-24T15:31:36.829Z
alalyonnaise.fr favicon

À la lyonnaise

alalyonnaise.fr

61
MediaFrancesmallMEDIUM

À la lyonnaise is a French lifestyle media company focusing on the city of Lyon, offering content related to food, shopping, cultural discoveries, and leisure activities. The website serves as a digital platform complementing their print magazine editions, targeting residents and visitors interested in Lyon's local culture and lifestyle. Their market position is that of a niche local media outlet with a consistent brand presence and active social media engagement. Technically, the website employs modern JavaScript libraries, Matomo and Google Analytics for tracking, and uses HTTPS with cookie consent mechanisms, indicating a moderate level of digital maturity. The site is mobile optimized and provides a good user experience with clear navigation and relevant content. Security-wise, the site uses HTTPS and cookie consent but lacks explicit security headers and public security policies, suggesting room for improvement in security posture. No critical vulnerabilities or blocking mechanisms were detected. Overall, the website is professional, trustworthy, and compliant with GDPR requirements, though it could enhance transparency around terms of service and incident response. Strategic recommendations include implementing security headers, publishing security policies, and improving SEO and accessibility compliance.

65
40
2
70
65
60
100
medialifestylefoodshoppingculture+2 more
JavaScriptjQueryMatomo AnalyticsGoogle Tag Manager+1
2025-10-24T15:31:26.742Z
visiterlyon.com favicon

Office du Tourisme et des Congrès de la métropole de Lyon

visiterlyon.com

69
HospitalityFrancelargeMEDIUM

The website www.visiterlyon.com serves as the official tourism portal for Lyon and its metropolitan area, operated by the Office du Tourisme et des Congrès de la métropole de Lyon. It provides comprehensive tourism information, online booking services for hotels, restaurants, leisure activities, and city passes such as the Lyon City Card. The site targets tourists, families, business travelers, and groups, positioning itself as an authoritative and trusted source for visiting Lyon. The content is rich, professionally presented, and available in multiple languages, enhancing accessibility and user experience. Technically, the website employs modern web technologies including Alpine.js for interactivity, Swiper.js for sliders, and MapLibre GL for mapping. It integrates Google Tag Manager and Google reCAPTCHA for analytics and security. The site is mobile-optimized, accessible, and SEO-friendly, with good performance metrics. Security best practices are observed with HTTPS enforcement, security headers, and secure forms, although explicit security policy and incident response information are not published. The security posture is strong with no detected vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies, GDPR adherence, and consent mechanisms. However, WHOIS data for the domain is missing or unavailable, which is unusual for an official entity and slightly impacts trustworthiness. Despite this, the website's certifications, social media presence, and comprehensive content support its legitimacy. Overall, the website is a high-quality, secure, and user-friendly platform for promoting tourism in Lyon. Strategic recommendations include publishing a dedicated security policy, incident response contacts, and a vulnerability disclosure policy to further enhance trust and transparency.

65
65
17
75
65
80
100
tourismlyontravelcultureevents+3 more
HTML5CSS3JavaScriptAlpine.js+4

Partner Domains:

boutique.visiterlyon.com
partner
pro.lyon-france.com
partner

+3 more partners

2025-10-24T15:31:21.732Z
nethinks.com favicon

NETHINKS GmbH

nethinks.com

56
TechnologyGermanymediumMEDIUM

NETHINKS GmbH is a well-established German IT and telecommunications service provider founded in 2004. The company specializes in network solutions, VoIP, web and mail hosting, and professional IT infrastructure consulting. Positioned as a manufacturer-neutral partner, NETHINKS serves business clients with tailored, future-proof communication and IT infrastructure solutions. Their market presence is reinforced by partnerships with major technology vendors and an ISO 27001 certification, underscoring their commitment to security and quality. Technically, the website is built on WordPress using WPBakery Page Builder and integrates Borlabs Cookie for GDPR-compliant cookie management. The site employs modern web technologies including jQuery and Google Tag Manager for analytics and marketing. Hosting and domain registration are managed by Vautron Rechenzentrum AG, a reputable provider. The website demonstrates good mobile optimization, SEO practices, and accessibility features, though some security headers are missing. From a security perspective, NETHINKS shows a mature posture with HTTPS enforced, cookie consent mechanisms, and ISO 27001 certification. However, there is room for improvement in publishing explicit incident response contacts and security.txt files. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with clear policies and consent management in place. Overall, NETHINKS GmbH presents a trustworthy and professional online presence with solid business credibility and technical implementation. The risk profile is low, but enhancing security headers and incident response transparency would further strengthen their security posture.

30
80
17
85
72
85
-
itservicestelecommunicationsnetworksolutionsvoipwebhosting+3 more
WordPressWPBakery Page BuilderBorlabs Cookie pluginjQuery+1
2025-10-24T15:31:11.681Z
vlb.de favicon

MVB GmbH

vlb.de

46
MediaGermanymediumHIGH

MVB GmbH operates the VLB (Verzeichnis Lieferbarer Bücher), a central platform for automated exchange of product information in the German-speaking book industry. The website serves key stakeholders including bookstores, publishers, self-publishers, and service providers, offering services such as order clearing (IBU), reference databases, and subscription discounts. The platform holds a strong market position as an authoritative source in its sector. Technically, the website employs modern web technologies including Bootstrap, Owl Carousel, and Google Tag Manager, hosted on Anexia infrastructure. It features responsive design, good SEO, and accessibility standards, with a cookie consent mechanism ensuring privacy compliance. The site is well-structured and professionally designed, providing a positive user experience. From a security perspective, the site uses HTTPS with good SSL configuration and no visible vulnerabilities or exposed sensitive data. However, it lacks explicit security policy pages, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for enhanced security posture. Overall, the website is trustworthy, professionally maintained, and compliant with GDPR. The WHOIS data aligns with the business entity, reinforcing legitimacy. Strategic improvements in security transparency and incident response readiness would further strengthen the platform's reliability.

20
28
2
85
67
60
20
vlbbuchbranchemvbgmbhbuchhandelverlage+2 more
JavaScriptBootstrapFont AwesomeOwl Carousel+2

Partner Domains:

vlbtix.de
partner
mvb-online.de
parent

+1 more partners

2025-10-24T15:28:29.779Z
nationalgeographic.es favicon

National Geographic España

nationalgeographic.es

55
MediaSpainlargeMEDIUM

National Geographic España operates as a prominent media brand delivering high-quality content focused on science, nature, history, and travel. The website serves a broad general audience with a mix of free and subscription-based content, supported by advertising partnerships and e-commerce through affiliated domains. The brand is well-established in Spain, leveraging multimedia content and digital subscriptions to maintain market relevance. Technically, the website employs a modern tech stack including advanced advertising technologies, consent management via Didomi, and multimedia delivery through JWPlayer. The site is mobile-optimized and uses HTTPS with appropriate security headers, reflecting a mature digital infrastructure. However, some areas such as explicit privacy policy publication and accessibility could be improved. Security posture is solid with HTTPS enforcement and consent mechanisms, but lacks visible vulnerability disclosure or incident response contacts. The absence of WHOIS data limits domain trust verification, though the website's professional presentation and branding strongly indicate legitimacy. Overall, the site presents a low-risk profile with good content quality and technical implementation, but should enhance transparency around privacy, contact information, and security disclosures to strengthen trust and compliance.

45
25
17
60
72
45
100
sciencenaturehistorytravelmedia+4 more
JavaScriptPrebid.jsGoogle Tag ManagerDidomi Consent SDK+5

Partner Domains:

tienda.rba.es
partner
historia.nationalgeographic.com.es
subsidiary

+2 more partners

2025-10-24T15:27:29.610Z
woa.de favicon

WOA

woa.de

50
MediaGermanysmallMEDIUM

WOA is a German advertising agency specializing in integrated communication services including web design, events, PR, and classical advertising. The company targets businesses seeking comprehensive marketing and communication solutions primarily in the German regions of Wiesbaden, Frankfurt, Hamburg, and central Hesse. Their website reflects a professional and consistent brand image with a clear presentation of services and client references. Technically, the website is built on Joomla CMS with Yootheme templates and uses modern web technologies such as UIkit, Google Tag Manager, and HubSpot integrations. The site is mobile optimized and includes standard SEO and accessibility features, though some accessibility aspects could be improved. Performance is moderate with no critical technical issues detected. From a security perspective, the site enforces HTTPS and includes cookie consent mechanisms compliant with GDPR. However, explicit security headers are missing, and no dedicated security or incident response policies are published. The site uses multiple third-party marketing and analytics tools, which are managed with user consent. No vulnerabilities or suspicious domains were detected. Overall, WOA presents a trustworthy and professional online presence with good privacy compliance and a solid technical foundation. Strategic improvements in security headers and incident response transparency would enhance their security posture further.

45
40
2
70
77
60
20
werbeagenturdesignagenturwebdesigneventpr+6 more
Joomla CMSYootheme templateGoogle Fonts (Roboto Condensed)Google Tag Manager+4

Partner Domains:

aeiforia.de
partner
bb-h.de
partner

+3 more partners

2025-10-24T14:47:02.167Z
hessenmetall.de favicon

Verband der Metall- und Elektro-Unternehmen Hessen (HESSENMETALL)

hessenmetall.de

51
ManufacturingGermanylargeMEDIUM

HESSENMETALL is a prominent industry association representing employers in the metal, electrical, and IT sectors in Hessen, Germany. The organization provides comprehensive services including labor relations, legal advice, workforce development, digital transformation support, and innovation facilitation. It holds a strong market position as a leading regional network for over 200,000 employment relationships in the region's M+E industry. The website reflects a professional and well-structured digital presence with member portals and extensive content tailored to its audience of employers and industry stakeholders. Technically, the site is built on the Contao CMS platform, utilizing modern JavaScript libraries such as jQuery and Swiper.js, and integrates analytics tools like Matomo and Google Tag Manager. Accessibility features are enhanced by the inclusion of eyeAble tools. The site is mobile-optimized and demonstrates good SEO practices with proper metadata and structured navigation. From a security perspective, the website enforces HTTPS and employs secure login forms with CSRF tokens. While explicit security headers are not fully visible in the HTML, the overall SSL configuration is good. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with clear privacy and cookie policies and consent mechanisms in place, aligning with GDPR requirements. Overall, the website presents a low-risk profile with a high degree of professionalism and trustworthiness. Strategic recommendations include enhancing security headers, increasing transparency around incident response contacts, and maintaining up-to-date CMS and third-party components to mitigate potential vulnerabilities.

65
28
17
80
72
60
-
industryassociationmanufacturingmetalelectricalit+6 more
Contao Open Source CMSjQuerySwiper.jsFont Awesome 4.7+3

Partner Domains:

hessenchemie.de
partner
2025-10-24T14:46:47.134Z