Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 174 of 800|Showing 8651-8700 of 39983
washubears.com favicon

Washington University in St. Louis

washubears.com

64
EducationUnited StateslargeMEDIUM

Washington University in St. Louis operates an official athletics website providing comprehensive information about its NCAA Division III sports teams, schedules, rosters, news, and athletics department resources. The site targets students, athletes, alumni, and sports fans, serving as a central hub for university sports engagement. The business model is focused on supporting university athletics and community involvement, positioning itself as a trusted source for sports information within the education sector. Technically, the website leverages a modern JavaScript stack including jQuery, RequireJS, Knockout.js, and integrates with Google Tag Manager and Google Analytics for tracking. It is hosted on Cloudfront CDN with DNS managed by Rackspace. The site is mobile optimized, accessible, and uses the Sidearm Sports CMS platform, reflecting a mature digital infrastructure suitable for its audience and purpose. From a security perspective, the site enforces HTTPS and employs standard domain protections but lacks DNSSEC and some advanced security headers like Content Security Policy. No WAF or blocking mechanisms were detected, and no critical vulnerabilities were found in the visible content. Privacy compliance is partial, with a privacy policy present but no explicit cookie consent mechanism despite active tracking scripts. Overall, the website demonstrates a solid security posture and business credibility with room for improvement in privacy compliance and DNS security. Strategic recommendations include enabling DNSSEC, implementing a cookie consent banner, adding security headers, and publishing a vulnerability disclosure policy to enhance trust and compliance.

65
70
2
60
62
75
100
universityathleticssportseducationncaa+2 more
JavaScriptjQueryRequireJSGoogle Tag Manager+5
2025-10-21T03:45:39.831Z
W

WilldooIT Pty Ltd

willdooit.com

73
TechnologyAustraliamediumMEDIUM

WilldooIT Pty Ltd is a well-established Australian company specializing in Odoo ERP software solutions tailored for diverse industries including timber, food distribution, manufacturing, and renewables. With over 15 years of experience and multiple industry awards such as the Odoo APAC Partner of the Year, WilldooIT holds a strong market position as a trusted ERP partner in Australia and New Zealand. Their business model focuses on B2B consulting, implementation, custom development, and ongoing support services, targeting medium-sized enterprises seeking to streamline operations and improve productivity through ERP technology. Technically, the website is built on the Odoo CMS platform, hosted on Amazon Web Services, and incorporates modern web technologies including JavaScript, FontAwesome, Google Tag Manager, and Hotjar for analytics and user behavior tracking. The site demonstrates good performance, mobile optimization, and SEO practices, reflecting a mature digital infrastructure. However, there is room for improvement in security headers and DNSSEC implementation. From a security perspective, the website enforces HTTPS and includes CSRF tokens, indicating attention to secure session management. No critical vulnerabilities or exposed sensitive data were detected. Privacy and cookie policies are present with consent mechanisms, though explicit GDPR compliance indicators are limited. The absence of a published security policy or incident response contact is noted as an area for enhancement. Overall, WilldooIT presents a professional, trustworthy online presence with strong business credibility and a solid technical foundation. The security posture is good but could benefit from additional hardening measures. The website content is safe for general audiences, and the company provides clear contact information and transparent policies. Strategic recommendations include enabling DNSSEC, adding security headers, publishing a security policy, and enhancing GDPR compliance to further strengthen trust and security.

70
68
17
90
65
85
100
erpodoobusinesssoftwareaustralianbusinesstechnologypartner+3 more
OdooJavaScriptFontAwesomeGoogle Tag Manager+1

Partner Domains:

pnors.com
partner
2025-10-21T03:44:24.662Z
msa.fr favicon

MSA

msa.fr

63
GovernmentFrancelargeMEDIUM

The website www.msa.fr/lfp represents the official online portal of the MSA (Mutualité Sociale Agricole), the French agricultural social security organization. It provides comprehensive social protection services including health insurance, family benefits, retirement pensions, and work accident coverage for agricultural workers and employers in France. The portal targets individuals, exploitants, employers, partners, and elected representatives within the agricultural sector. The business model is that of a government social security entity, serving a large user base with essential social services. The website is professionally designed with clear navigation and multiple service sections tailored to different user groups. Technically, the site is built on the Liferay CMS platform, utilizing modern JavaScript libraries such as YUI, jQuery, Bootstrap, and Clay components. It incorporates a secure login mechanism via OpenID Connect and includes a cookie consent banner, indicating attention to privacy compliance. The site is mobile-optimized and accessible, with good SEO practices evident from meta tags and structured navigation. From a security perspective, the site enforces HTTPS and uses secure authentication flows. While explicit security headers and policies are not visible in the HTML, the overall posture appears strong with no evident vulnerabilities or exposed sensitive data. However, the absence of a published security policy, incident response contacts, and vulnerability disclosure mechanisms suggests room for improvement in transparency and security communication. Overall, the website is a trustworthy and authoritative source for agricultural social security services in France. The lack of WHOIS data limits domain registration trust analysis but does not detract from the site's legitimacy given its government affiliation and professional presentation. Strategic recommendations include publishing privacy and security policies, adding security.txt for vulnerability reporting, and enhancing contact information for security incidents to strengthen trust and compliance.

70
25
2
85
67
70
100
socialsecurityagriculturefrancegovernmenthealth+3 more
JavaScriptYUI 3.18.1Liferay PortalClay CSS/JS+3
2025-10-21T03:43:59.607Z
gambleaware.org favicon

GambleAware

gambleaware.org

11
Non-profitUnited KingdommediumCRITICAL

GambleAware is a UK-based non-profit organization dedicated to providing free, confidential advice and support for individuals affected by gambling harms, including their family and friends. The website offers a comprehensive range of services such as a gambling harms assessment, support tools including a dedicated app, live chat, and a helpline. It also provides research publications and a service finder to locate local support. The organization partners with GamCare to deliver live support services, reinforcing its position as a leading entity in gambling harm prevention in Great Britain. Technically, the website employs modern JavaScript libraries and frameworks, including jQuery, Google Tag Manager, Cookiebot for consent management, and Gleap for user feedback. The site is well-optimized for mobile devices, features fast loading times, and includes accessibility considerations. The use of HTTPS and secure third-party integrations indicates a strong digital maturity. From a security perspective, the site enforces HTTPS and integrates consent management to comply with privacy regulations. While explicit security headers are not fully visible in the HTML, the overall posture is strong with no exposed sensitive data or vulnerable libraries detected. However, the absence of publicly available incident response or vulnerability disclosure policies suggests room for improvement. Overall, GambleAware presents a trustworthy, professional, and user-centric platform with a high level of content quality and security. The lack of WHOIS data due to privacy protection is justified given the sensitive nature of the services offered. Strategic recommendations include enhancing transparency around security policies and publishing a security.txt file to facilitate vulnerability reporting.

-
-
-
-
-
-
-
gamblingsupportnon-profitaddictionhelp+2 more
JavaScriptjQueryGoogle Tag ManagerCookiebot+3

Partner Domains:

www.gamcare.org.uk
partner
2025-10-21T03:41:54.360Z
mediaguru.cz favicon

MediaGuru.cz

mediaguru.cz

9
MediaCzech RepublicmediumCRITICAL

MediaGuru.cz is a Czech online media platform focused on delivering news, insights, and information related to media, advertising, and marketing. The website targets professionals in the media and marketing sectors as well as the general public interested in these topics. It offers a variety of content including articles, interviews, event listings, and video showcases of advertising campaigns. The platform maintains a consistent brand presence and integrates social media channels to engage its audience. Technically, the website employs modern JavaScript libraries and tracking tools such as Google Analytics, Google Tag Manager, Microsoft Application Insights, and Gemius for audience measurement. It uses Azure CDN for content delivery, ensuring moderate performance and good mobile optimization. The site is served over HTTPS, enhancing security, though some security headers are not explicitly detected in the HTML source. From a security perspective, the site enforces HTTPS and includes a default cookie consent mechanism denying ad and analytics storage until user consent. However, it lacks visible privacy and cookie policies, terms of service, and security.txt files, which are important for compliance and transparency. The absence of WHOIS data for the domain reduces trustworthiness and transparency, although the website content and technical setup appear professional and legitimate. Overall, MediaGuru.cz presents as a credible and professional media news platform with room for improvement in privacy disclosures, security headers, and domain registration transparency. Strategic recommendations include publishing comprehensive privacy and cookie policies, implementing security headers, and clarifying domain registration details to enhance trust and compliance.

-
-
-
-
-
-
-
mediamarketingadvertisingnewsczechrepublic+3 more
JavaScriptjQueryGoogle AnalyticsGoogle Tag Manager+2
2025-10-21T03:41:24.302Z
getbutton.io favicon

Chat Button for Your Website: WhatsApp, ChatGPT, Messenger | GetButton

getbutton.io

49
TechnologyMaltamediumHIGH

GetButton.io is a technology company providing an all-in-one chat button solution that integrates popular messaging platforms such as WhatsApp, Messenger, Instagram, and AI-powered chatbots including Custom ChatGPT. The service targets website owners and businesses aiming to enhance visitor engagement through seamless chat interactions. With over 736,000 websites trusting their solution, GetButton.io holds a strong market position in the customer engagement SaaS sector. The company was founded in 2019 and operates with a medium-sized business profile based in Malta. Technically, the website employs modern web technologies including HTML5, CSS3, JavaScript with Knockout.js for UI bindings, and leverages Cloudflare for DNS and CDN services. The site is mobile-optimized, SEO-friendly, and integrates third-party services such as CookieYes for GDPR-compliant cookie consent and FastSpring for payment processing. Analytics are conducted via Yandex Metrica, with extensive user tracking managed through cookies and device scanning. From a security perspective, the website enforces HTTPS, employs clientTransferProhibited domain status, and provides a granular cookie consent mechanism. However, DNSSEC is not enabled, and explicit security policies or incident response contacts are not published. No critical vulnerabilities or exposed sensitive data were detected in the analyzed content. Overall, GetButton.io presents a professional and trustworthy digital presence with good privacy compliance and security posture. The absence of explicit privacy policy and terms of service documents on the main page is a notable gap. Strategic recommendations include enabling DNSSEC, publishing comprehensive privacy and security policies, and adding vulnerability disclosure information to enhance transparency and trust.

15
83
17
70
52
75
-
chatmessagingwhatsappchatbotai+3 more
HTML5CSS3JavaScriptKnockout.js (data-bind attributes)+4
2025-10-21T03:40:54.243Z
cesaer.org favicon

CESAER

cesaer.org

68
EducationBelgiummediumMEDIUM

CESAER is a prominent non-profit association representing over 50 leading universities of science and technology across more than 25 European countries. The organization serves as a unified voice advocating for the interests of its members in European research and education policy arenas, including the European Research Area and European Education Area. Its key services include advocacy, networking, policy influence, organizing events, and publishing relevant materials to support its mission. The website reflects a professional and consistent brand image, targeting academic institutions, researchers, and policymakers in the science and technology education sector. Technically, the website employs modern web technologies such as HTML5, CSS3, JavaScript, and utilizes libraries like Slick Slider and a custom cookie consent mechanism (Brainlane Cookiewall). The site is mobile-optimized with good SEO practices and moderate performance. While no CMS or hosting provider is explicitly identified, the infrastructure appears stable and well-maintained. From a security perspective, the site enforces HTTPS and implements a granular cookie consent mechanism, demonstrating compliance with GDPR. However, it lacks explicit security headers and does not provide visible security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the HTML content. The WHOIS data is unavailable or privacy protected, which is common and justified for non-profit organizations, and no suspicious patterns were found. Overall, CESAER's website is a credible, secure, and well-maintained platform that effectively supports its mission. Strategic recommendations include enhancing security headers, publishing a security policy, and improving accessibility features to further strengthen its security posture and compliance.

70
68
2
75
72
75
100
educationuniversitiessciencetechnologyeurope+3 more
HTML5CSS3JavaScriptSlick Slider+1
2025-10-21T03:40:09.154Z
E

The Extensible Web Manifesto

extensiblewebmanifesto.org

71
TechnologyN/asmallMEDIUM

The Extensible Web Manifesto website serves as a platform to promote a new philosophy for web standards development, emphasizing low-level capabilities and iterative JavaScript-based feature development. It targets web developers, standards committees, and browser vendors, positioning itself as a thought leadership and advocacy initiative within the technology sector. The site content is well-structured and professional, featuring notable industry signatories, but lacks commercial or transactional elements. Technically, the website uses standard web technologies including HTML5, CSS, JavaScript, Google Fonts, and integrates Google Analytics and AddThis for tracking and social sharing. The site is moderately optimized for performance and mobile use but lacks advanced accessibility and SEO features. No CMS or hosting provider details are evident. From a security perspective, the domain is stable and legitimate with a long registration period and appropriate domain status flags. However, the site lacks DNSSEC, security headers, and visible HTTPS enforcement details. Privacy and cookie policies are absent, which impacts compliance and user trust. Tracking technologies are present without clear consent mechanisms. Overall, the website is a credible and professional advocacy platform with moderate technical maturity and security posture. Strategic improvements in privacy compliance, security headers, and contact transparency would enhance trust and compliance.

80
35
47
85
65
85
100
webstandardsmanifestowebdevelopmentjavascriptwebplatform+2 more
HTML5CSSJavaScriptGoogle Fonts (Chivo)+2
2025-10-21T03:38:33.824Z
A

Arche TI

archeti.com

68
TechnologyCanadamediumMEDIUM

Arche TI is a Canadian technology company specializing in Odoo ERP consulting, implementation, and optimization services. Positioned as the top Odoo integrator in Canada, they serve businesses primarily in Montreal, Quebec, Toronto, and other Canadian regions. Their key offerings include ERP consultation, project rescue, migration, customization, and ongoing support, targeting medium-sized businesses seeking digital transformation and operational efficiency. The company has a professional web presence with detailed service descriptions, client testimonials, and multiple office locations, reflecting a mature and credible business model. Technically, the website is built on the Odoo platform, leveraging modern web technologies such as JavaScript, FontAwesome, and Google Tag Manager for analytics. The site is mobile-optimized, accessible, and SEO-friendly, with fast to moderate performance. However, there is room for improvement in security headers and explicit privacy compliance features. From a security perspective, the site uses HTTPS and includes CSRF tokens, indicating a baseline security posture. The domain is registered with GoDaddy and secured with registrar locks, consistent with the business's age and claims. No critical vulnerabilities or suspicious patterns were detected, but the absence of a visible privacy policy and cookie consent mechanism represents compliance gaps. The presence of a named Data Protection Officer with contact details is a positive indicator. Overall, Arche TI presents a trustworthy and professional digital footprint with strong business credibility and technical maturity. Strategic enhancements in privacy compliance and security best practices would further strengthen their security posture and regulatory alignment.

70
35
17
85
72
85
100
odooerpconsultingcanadadigitaltransformation+2 more
OdooJavaScriptFontAwesomeGoogle Tag Manager+1
2025-10-21T02:36:13.459Z
zazumi.cz favicon

ZAZUMi – vše pro zahradu i domov

zazumi.cz

57
RetailCzech RepublicmediumMEDIUM

ZAZUMi.cz is a Czech Republic-based e-commerce retailer specializing in plants, gardening supplies, and pet products. The website offers a broad catalog of products for home and garden enthusiasts, including indoor plants, garden equipment, and pet accessories. The platform supports customer accounts with login and registration features and provides clear contact information for customer support. The site is professionally designed with good navigation and mobile optimization, targeting primarily Czech-speaking customers interested in gardening and home care. Technically, the website employs modern JavaScript libraries such as Algolia for search and Mailkit for email services, alongside Google Tag Manager for analytics. The site uses HTTPS, ensuring encrypted communication, but lacks visible security headers which could enhance protection against common web attacks. Performance is moderate with room for improvement in accessibility and SEO features. From a security perspective, the site demonstrates basic best practices such as secure login forms with CSRF tokens and encrypted connections. However, the absence of privacy and cookie policies, as well as no visible incident response or vulnerability disclosure mechanisms, indicates gaps in compliance and security maturity. The lack of WHOIS data for the domain raises concerns about domain registration transparency and trustworthiness. Overall, ZAZUMi.cz presents a functional and user-friendly e-commerce platform with a solid business focus but requires improvements in transparency, privacy compliance, and security hardening to enhance trust and regulatory adherence.

55
10
17
60
65
80
100
gardeningplantse-commercehomepetsupplies+1 more
JavaScriptAlgolia SearchMailkitGoogle Tag Manager+2
2025-10-21T02:34:24.149Z
U

University of Wisconsin–Madison

wisc.edu

67
EducationUnited StatesenterpriseMEDIUM

The University of Wisconsin–Madison is a prestigious public research university located in Madison, Wisconsin, founded in 1849. It offers comprehensive education opportunities to undergraduate, graduate, and professional students, and is recognized as one of the top-ranked research institutions in the United States. The university emphasizes public service through the Wisconsin Idea, aiming to improve lives beyond campus boundaries. Its website reflects a mature digital presence with extensive content, clear navigation, and strong branding consistency. Technically, the site employs modern web technologies including Google Tag Manager, Google Analytics, and Eloqua for marketing and analytics. The site is well-optimized for mobile and accessibility, with good SEO practices. Hosting appears to be managed via university infrastructure or a dedicated CDN. Performance is moderate, with room for improvement in security headers and explicit security policy disclosures. Security posture is solid with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. Privacy compliance is strong, featuring comprehensive privacy and cookie policies with user consent mechanisms. However, the absence of a published security policy or vulnerability disclosure program is noted. WHOIS data is unavailable, which is unusual but does not detract from the overall legitimacy given the institutional nature and external trust signals. Overall, the website is professional, trustworthy, and well-maintained, supporting the university's mission and public image effectively.

15
83
2
88
77
85
100
educationuniversityresearchpublicservicehighereducation+2 more
Google Tag ManagerGoogle Analytics (gtag.js)Eloqua trackingIntersectionObserver+3
2025-10-21T02:33:43.175Z
ceasciences.fr favicon

Commissariat à l’énergie atomique et aux énergies alternatives (CEA)

ceasciences.fr

59
EnergyFrancelargeMEDIUM

The website represents the Direction de la Recherche Fondamentale (DRF) of the Commissariat à l’énergie atomique et aux énergies alternatives (CEA), a major French public research institution. It showcases extensive scientific research activities across multiple disciplines including physics, chemistry, biology, and health sciences, supported by a large community of over 6000 researchers. The site serves multiple audiences including researchers, institutional partners, journalists, and the general public, providing news, resources, and institutional information. The business model is focused on public research and innovation with strong ties to academic and industrial partners. Technically, the site is built on Microsoft SharePoint, leveraging standard web technologies and integrating Matomo analytics for user tracking and Google reCAPTCHA for bot protection. The infrastructure appears stable and professionally maintained, with moderate performance and basic mobile optimization. SEO and accessibility are adequately addressed, though some improvements could be made. From a security perspective, the site uses HTTPS and implements standard SharePoint security features such as form digest tokens. However, explicit security headers like Content-Security-Policy and X-Frame-Options are not evident. Privacy compliance is good with a comprehensive GDPR-aligned privacy policy, but lacks a visible cookie consent mechanism. No incident response or vulnerability disclosure information is published. Overall, the website is trustworthy, professional, and aligned with the institutional identity of CEA. It poses low risk from a security and privacy standpoint but could enhance transparency and user consent mechanisms to improve compliance and user trust.

55
10
17
70
67
65
100
researchscienceenergytechnologyeducation+4 more
Microsoft SharePointJavaScriptMatomo AnalyticsGoogle reCAPTCHA

Partner Domains:

cea.tech
partner
cadarache.cea.fr
partner

+3 more partners

2025-10-21T02:32:32.991Z
gvuo.cz favicon

Galerie výtvarného umění v Ostravě, p. o.

gvuo.cz

49
Non-profitCzech RepublicmediumHIGH

Galerie výtvarného umění v Ostravě, p. o. is the oldest regional art gallery in Ostrava, Czech Republic, established in 1952. It operates as a non-profit cultural institution under the Moravskoslezský kraj (Moravian-Silesian Region) and offers art exhibitions, educational programs, virtual tours, and an e-shop. The website reflects a well-established institution with a clear focus on art and culture, targeting the general public and educational sectors. The business model is centered on cultural enrichment and public engagement rather than commercial profit. Technically, the website employs a modern technology stack including HTML5, CSS3, JavaScript libraries such as jQuery, Leaflet.js for maps, and Google Analytics for tracking. It uses the Shopnero CMS platform and is hosted by Active24. The site is mobile-optimized with good SEO practices and structured data enhancing search engine visibility. Performance is moderate with room for optimization. From a security perspective, the site uses HTTPS with a good SSL configuration and implements cookie consent mechanisms. However, it lacks explicit security headers and a published security policy or incident response contacts. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with a clear privacy policy and GDPR adherence. Overall, the website is professional, trustworthy, and well-maintained, with a strong cultural and educational focus. Strategic improvements in security policies and accessibility could further enhance its posture and user trust.

35
25
2
70
75
80
20
artgallerycultureeducationnon-profit+4 more
HTML5CSS3JavaScriptjQuery+7

Partner Domains:

www.msk.cz
partner
eshop.gvuo.cz
related
2025-10-21T02:31:16.169Z
bezruci.cz favicon

Divadlo Petra Bezruče, s.r.o.

bezruci.cz

43
HospitalityCzech RepublicmediumHIGH

Divadlo Petra Bezruče, s.r.o. is a regional theatre company based in Ostrava, Czech Republic, providing theatrical performances, ticketing services, subscriptions, and cultural event hosting. The website serves as a portal for program schedules, ticket reservations, and company information, targeting local theatre audiences and cultural enthusiasts. The business operates with support from local government and cultural partners, positioning itself as a key cultural institution in the region. Technically, the website employs modern front-end technologies including Bootstrap, JavaScript libraries like WOW.js, and a cookie consent mechanism from TermsFeed. The site is mobile-optimized with responsive design and provides a user-friendly navigation experience. However, there is no evidence of a CMS or advanced analytics tools, and performance is moderate. From a security perspective, the site uses HTTPS but lacks visible security headers and published privacy or terms of service policies. Cookie consent is implemented with express consent, indicating some GDPR awareness. The absence of WHOIS data reduces domain trustworthiness, but the professional presentation and clear contact information mitigate some concerns. Overall, the website is functional and professional but would benefit from enhanced security practices, published privacy documentation, and WHOIS transparency to improve trust and compliance.

15
40
17
40
85
75
-
theatrecultureperformanceticketingarts+2 more
JavaScriptCSSHTML5Bootstrap+3
2025-10-21T02:31:06.151Z
Z

ZEDD

zedd.fr

9
OtherFrancesmallCRITICAL

ZEDD is a small, French communication agency based in Grenoble specializing in responsible and sustainable communication services. The company positions itself as a pioneer in the Auvergne Rhône-Alpes region, offering consulting, creation, development, and maintenance services with a focus on eco-conception and digital responsibility. The website content is professionally presented in French, targeting organizations seeking sustainable communication solutions. Technically, the website uses modern web technologies including JavaScript, CSS, and SVG graphics, with the SPIP CMS platform. Hosting is local to Grenoble, leveraging a datacenter with a positive carbon footprint, reflecting the company's environmental values. The site is moderately optimized for performance and mobile devices, with good SEO practices but basic accessibility features. Security posture is moderate; HTTPS is implied but no explicit security headers or policies are present. No privacy or cookie policies are found, indicating gaps in GDPR compliance. Contact information is clearly provided, but no incident response or vulnerability disclosure mechanisms are visible. No tracking or advertising scripts were detected, suggesting minimal user tracking. Overall, the website is trustworthy and professional but would benefit from enhanced privacy compliance and security best practices to improve user trust and regulatory adherence.

-
-
-
-
-
-
-
communicationresponsiblegrenobleeco-conceptiondigital+1 more
JavaScriptCSSSVG
2025-10-21T02:30:05.938Z
cae29.coop favicon

CHRYSALIDE

cae29.coop

52
OtherFrancesmallMEDIUM

CAE 29 is a French cooperative organization under the legal entity CHRYSALIDE, founded in 2014, providing shared enterprise and employment cooperative services primarily in the Finistère region. The website serves as an informational and engagement platform for entrepreneurs and project holders seeking cooperative business support, administrative delegation, and training. The business model focuses on collective entrepreneurship and professional autonomy within a cooperative framework, positioning CAE 29 as a regional leader in this niche. Technically, the website is built on the SPIP CMS platform, hosted by Gandi SAS, and uses standard web technologies including JavaScript and CSS. The site demonstrates moderate performance and basic mobile optimization, with good SEO practices and clear navigation. However, there is room for improvement in accessibility and modern security practices. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and explicit security headers. There is no cookie consent mechanism or detailed privacy policy, which may pose compliance risks under GDPR. No incident response or security policy information is published, and no analytics or tracking services are detected, indicating minimal user tracking. Overall, CAE 29 presents a trustworthy and professional online presence with a solid business foundation. Strategic improvements in security headers, DNSSEC, privacy compliance, and incident response transparency would enhance its security posture and regulatory adherence.

50
35
17
85
42
70
40
cooperativeentrepreneurshipfinistrefrancespip+2 more
SPIP CMSJavaScriptCSS
2025-10-21T01:26:59.160Z