Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149319
Websites
130
Industries
113
Countries
52
Avg Score
Page 18 of 39|Showing 851-900 of 1917
giantrabbit.com favicon

Giant Rabbit LLC

giantrabbit.com

62
Non-profitN/asmallMEDIUM

Giant Rabbit LLC is a specialized digital agency focused on developing and supporting websites and data systems for nonprofit organizations. Established in 2003, the company offers a comprehensive suite of services including strategy, design, development, CRM selection and data migration, fundraising analytics, Drupal upgrades, project rescues, managed hosting, support, maintenance, and security. Their market position is niche, targeting nonprofits with pragmatic and mission-focused digital solutions. The website reflects a professional and consistent brand with clear service offerings and contact information. Technically, the website is built on Drupal 10, leveraging modern JavaScript and integrates Google Analytics and Google Tag Manager for tracking. Hosting and DNS services are provided via Amazon AWS infrastructure. The site demonstrates good mobile optimization, accessibility, and SEO practices, though performance is moderate. The absence of DNSSEC and security headers indicates room for improvement in security hardening. From a security perspective, the site uses HTTPS and domain registration protections but lacks published security policies, incident response information, and cookie consent mechanisms, which are important for GDPR compliance and user trust. No critical vulnerabilities or exposed sensitive data were detected. Overall, the security posture is moderate but could be enhanced with additional policies and technical controls. The overall risk assessment is low with recommendations to enable DNSSEC, implement cookie consent, publish security and incident response policies, and add security headers. These steps will improve compliance, user trust, and reduce potential attack surface.

80
53
2
85
72
85
40
nonprofitdigitalservicesdrupalwebdevelopmentdatamigration+1 more
Drupal 10JavaScriptGoogle AnalyticsGoogle Tag Manager+1
2025-10-09T14:12:27.066Z
scrum.org favicon

Scrum.org

scrum.org

72
EducationN/amediumMEDIUM

Scrum.org is a globally recognized educational organization founded by Scrum co-creator Ken Schwaber in 2009. It specializes in providing Professional Scrum training, certifications, consulting, and a rich set of learning resources to individuals and teams aiming to adopt Scrum and Agile methodologies effectively. The organization holds a strong market position with over 1.1 million certified professionals and a high Trustpilot rating, reflecting its credibility and quality of service. Technically, the website is built on Drupal 10, leveraging modern web technologies such as Bootstrap and Swiper.js for responsive design and user experience. It integrates Google Tag Manager and Google Analytics for tracking and marketing insights. The site demonstrates good performance, accessibility, and SEO optimization, with a mobile-friendly design and clear navigation. From a security perspective, Scrum.org employs HTTPS with strong SSL configuration and implements key security headers to protect users. No vulnerabilities or exposed sensitive data were detected in the analyzed content. Privacy and cookie policies are present and indicate GDPR compliance, although explicit security policies and incident response information are not publicly detailed. Overall, Scrum.org presents a low-risk profile with a professional, trustworthy online presence. The lack of WHOIS data is likely due to privacy protection and does not detract from the site's legitimacy given the strong brand consistency and comprehensive content. Strategic recommendations include publishing explicit security and incident response policies and adding a vulnerability disclosure program to enhance transparency and trust.

80
53
17
85
67
85
100
scrumagiletrainingcertificationprofessionalscrum+2 more
Drupal 10BootstrapSwiper.jsGoogle Tag Manager+1
2025-10-09T05:58:34.504Z
uvahealth.com favicon

University of Virginia Health System

uvahealth.com

58
HealthcareUnited StateslargeMEDIUM

UVA Health is a large, well-established healthcare provider operating a network of hospitals and clinics across Virginia. The organization offers a broad range of specialized medical services including cancer care, pediatrics, heart health, transplant, neurosciences, and primary care. The website reflects a strong market position with recognized accreditations such as Virginia's first NCI-Designated Comprehensive Cancer Center and the #1 Children's Hospital in Virginia. The target audience primarily includes patients and families seeking healthcare services in the region. UVA Health operates under the University of Virginia umbrella, reinforcing its credibility and institutional backing. Technically, the website is built on Drupal 10 and integrates modern technologies such as Google Tag Manager, Coveo Search, and Google Maps API. It is hosted with Akamai DNS infrastructure, ensuring reliable performance and availability. The site is mobile-optimized, accessible, and SEO-friendly, providing a positive user experience. Analytics and marketing tools are used responsibly with clear cookie consent mechanisms. From a security perspective, the site enforces HTTPS and employs domain status protections to prevent unauthorized changes. However, DNSSEC is not enabled, and some security headers like Content-Security-Policy are missing, representing areas for improvement. No WAF or blocking mechanisms interfere with content access, and no critical vulnerabilities were detected. Overall, UVA Health's website demonstrates high professionalism, trustworthiness, and compliance with privacy regulations such as GDPR. The domain registration data aligns well with the business identity, supporting legitimacy. Strategic recommendations include enhancing DNS security with DNSSEC, implementing additional security headers, and maintaining strong privacy and security practices to uphold trust and compliance.

50
53
17
40
42
75
100
healthcarepatientcaremedicalservicesuvahealthcancercenter+2 more
Drupal 10Google Tag ManagerGoogle TranslateCoveo Search+4

Partner Domains:

childrens.uvahealth.com
subsidiary
careers.uvahealth.org
partner

+1 more partners

2025-10-08T22:52:55.853Z
osha.gov favicon

Occupational Safety and Health Administration

osha.gov

66
GovernmentUnited StatesenterpriseMEDIUM

The Occupational Safety and Health Administration (OSHA) is a U.S. federal government agency under the Department of Labor dedicated to ensuring safe and healthy working conditions by setting and enforcing standards and providing training, outreach, education, and assistance. The website serves as a comprehensive resource for employers, workers, and safety professionals, offering regulatory information, enforcement data, training resources, and contact channels. It holds a strong market position as the authoritative source for occupational safety and health in the United States. Technically, the website is built on Drupal 10 with modern frameworks such as Bootstrap and integrates Google services for analytics and translation. It demonstrates good mobile optimization, accessibility, and SEO practices, although performance is moderate likely due to the extensive content and third-party integrations. The site uses HTTPS with strong SSL configuration and includes security headers, but could enhance security posture by adding more explicit headers and publishing vulnerability disclosure information. Security-wise, OSHA's website shows a mature security posture with no visible vulnerabilities or exposed sensitive data. However, it lacks a cookie consent mechanism and explicit incident response contact information, which are areas for improvement to align with privacy regulations and best practices. The WHOIS data is unavailable, which is typical for government .gov domains, but the domain's legitimacy is strongly supported by official branding and consistent government affiliation. Overall, the website is professional, trustworthy, and well-maintained, serving its public service mission effectively. Strategic recommendations include implementing cookie consent, publishing security policies and incident response contacts, and enhancing security headers to further strengthen trust and compliance.

30
53
25
70
90
75
100
governmentoccupationalsafetyhealthcompliancetraining+2 more
Drupal 10Bootstrap 4.6.2jQueryFont Awesome+3
2025-10-08T21:46:41.989Z
ahla.com favicon

American Hotel & Lodging Association

ahla.com

69
HospitalityUnited StateslargeMEDIUM

The American Hotel & Lodging Association (AHLA) operates a comprehensive and professionally designed website serving as the central hub for the U.S. hotel industry's advocacy, resources, events, and membership services. The site demonstrates a mature digital presence with extensive content, including policy guides, event calendars, industry initiatives, and partner networks. Technically, the website is built on Drupal 10 with modern front-end libraries and integrates multiple analytics and marketing tools such as Google Tag Manager, HubSpot, and Microsoft Clarity, indicating a data-driven approach to user engagement and marketing. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms, though explicit security headers and incident response policies are not clearly published. No critical vulnerabilities or exposed sensitive data were detected in the accessible content. Privacy compliance is well addressed with a comprehensive cookie policy and privacy documentation, supporting GDPR compliance. The absence of WHOIS data limits domain registration transparency, but the website's professional content and industry partnerships strongly support its legitimacy. Overall, AHLA's website reflects a robust and credible industry association platform with strong business credibility, good technical implementation, and a solid security posture. Strategic improvements could include publishing explicit security policies, incident response contacts, and enhancing security headers to further strengthen trust and compliance.

40
68
17
80
85
80
100
hospitalityhotelindustryadvocacyeventsmembership+3 more
Drupal 10jQuery UISlick CarouselTypekit Fonts+4

Partner Domains:

www.ahlafoundation.org
partner
ahlei.servsafebrands.com
partner

+1 more partners

2025-10-08T20:37:41.781Z
dol.gov favicon

U.S. Department of Labor

dol.gov

72
GovernmentUnited StatesenterpriseMEDIUM

The U.S. Department of Labor operates as a federal government agency providing comprehensive labor-related services including workplace safety, wage standards, unemployment insurance, and workforce training. The website serves a broad audience including workers, employers, and government entities, offering authoritative information and resources. The site is well-branded with consistent government seals and official contact information, reinforcing trust and legitimacy. Technically, the site is built on Drupal 10 with modern libraries such as FontAwesome and GSAP, and integrates multiple analytics and tracking tools including Google Analytics, Crazy Egg, and Siteimprove. The site is mobile-optimized, accessible, and performs well, reflecting a mature digital infrastructure. Hosting appears to leverage government or Akamai CDN services. Security posture is strong with HTTPS enforced and implied security headers, no exposed sensitive data, and secure form handling. However, the site lacks a visible cookie consent mechanism and explicit vulnerability disclosure or incident response contacts, which are areas for improvement. The WHOIS data is unavailable due to the .gov domain privacy norms but the domain's nature and content strongly support legitimacy. Overall, the site is a high-quality, trustworthy government resource with excellent content and technical implementation. Strategic enhancements in privacy compliance and security transparency would further strengthen its posture.

35
58
25
85
100
85
100
governmentlaboremploymentworkplacesafetyapprenticeship+3 more
Drupal 10FontAwesome 6.4.0Google Tag ManagerGoogle Analytics+4
2025-10-08T20:33:59.329Z
eac.gov favicon

U.S. Election Assistance Commission

eac.gov

67
GovernmentUnited StatesmediumMEDIUM

The U.S. Election Assistance Commission (EAC) is a federal government agency dedicated to improving election administration and supporting voters and election officials across the United States. The website serves as a comprehensive resource hub offering election management guidelines, voter information, election technology certification, research data, and grant management resources. It targets election officials, voters, researchers, and government stakeholders, positioning itself as the authoritative federal entity in election assistance. Technically, the website is built on Drupal 10 and employs modern web technologies including jQuery, Flexslider, and Google Tag Manager. It demonstrates good mobile optimization, accessibility, and SEO practices. The site uses HTTPS exclusively, ensuring secure connections, and integrates social media channels for broader engagement. From a security perspective, the site follows best practices such as HTTPS enforcement and secure external linking. However, explicit security headers are not clearly visible in the HTML, and there is no visible cookie consent mechanism or vulnerability disclosure policy. WHOIS data is unavailable, which is typical for .gov domains, but this limits domain registration transparency. Overall, the site exhibits a strong security posture appropriate for a government agency. The overall risk assessment is low given the official nature, secure infrastructure, and absence of suspicious content. Strategic recommendations include implementing explicit cookie consent for privacy compliance, publishing a vulnerability disclosure policy, enhancing security headers, and providing incident response contact information to further strengthen trust and compliance.

40
53
17
85
75
85
100
governmentelectionsvotingelectionadministrationusgovernment+2 more
Drupal 10jQueryChosen jQuery pluginFlexslider+3
2025-10-08T18:15:52.949Z
cmu.edu favicon

Carnegie Mellon University

cmu.edu

70
EducationUnited StateslargeMEDIUM

Carnegie Mellon University is a prestigious private global research university based in Pittsburgh, USA, recognized among the top 20 universities in the United States. It offers a broad range of undergraduate, graduate, and continuing education programs with a strong emphasis on technology, artificial intelligence, and interdisciplinary research. The university has a large faculty body, notable alumni, and a history of pioneering contributions to AI and robotics. The website reflects a mature digital presence with comprehensive academic and campus life information targeting students, faculty, alumni, and researchers. Technically, the website is built on Drupal 10 CMS and integrates multiple modern analytics and marketing tools such as Google Tag Manager, Microsoft Clarity, Facebook Pixel, and LinkedIn Insight Tag. The site is mobile-optimized, accessible, and SEO-friendly, though performance is moderate. Security posture is good with HTTPS enabled and no visible sensitive data exposure, but lacks explicit security headers and a vulnerability disclosure policy. The WHOIS data is unavailable, which is typical for .edu domains due to registry policies, but the domain and content strongly indicate legitimacy. Privacy compliance is partially met with a comprehensive privacy policy but lacks a cookie consent mechanism. Overall, the site is professional, trustworthy, and well-maintained, serving as a key digital asset for Carnegie Mellon University.

50
58
47
75
77
70
100
educationuniversityresearchtechnologyartificialintelligence+2 more
Drupal 10Google Tag ManagerGoogle AdsenseMicrosoft Clarity+5
2025-10-08T17:04:54.688Z
kro-ncrv.nl favicon

KRO-NCRV

kro-ncrv.nl

64
MediaNetherlandslargeMEDIUM

KRO-NCRV is a prominent Dutch public broadcasting organization dedicated to producing mission-driven media content aimed at fostering a fairer, greener, and kinder society. The website serves as a comprehensive portal for their television, radio, podcast, and online content offerings, targeting a broad Dutch-speaking audience interested in socially conscious programming. The organization appears well-established within the Dutch media landscape, with strong branding consistency and a professional online presence. Technically, the website is built on Drupal 10, leveraging modern web technologies including lazy loading for images, Google Tag Manager for analytics, and Hotjar for user behavior insights. The site is mobile-optimized and accessible, with good SEO practices evident. Security posture is solid with HTTPS enforced and cookie consent mechanisms in place, although explicit security headers and incident response information are not publicly visible. Overall, the site demonstrates a mature digital infrastructure and a high level of professionalism. However, the absence of explicit privacy policy and terms of service pages, as well as lack of direct contact information, slightly detracts from privacy compliance and user trust. No signs of malicious content or blocking mechanisms were detected, indicating a safe and accessible platform.

55
68
2
70
72
65
100
publicbroadcastingmediadutchsocialissuestelevision+3 more
Drupal 10JavaScriptLazySizes (lazy loading images)Google Tag Manager+2
2025-10-08T16:49:52.918Z
noaa.gov favicon

National Oceanic and Atmospheric Administration

noaa.gov

69
GovernmentUnited StatesenterpriseMEDIUM

The National Oceanic and Atmospheric Administration (NOAA) is a U.S. Department of Commerce agency dedicated to providing authoritative information and services related to weather, climate, oceans, coasts, fisheries, satellites, research, marine and aviation, charting, sanctuaries, and education. The website serves a broad audience including the general public, researchers, government entities, and educators, positioning NOAA as the primary federal source for oceanic and atmospheric data and services. Technically, the website is built on Drupal 10 CMS with a modern JavaScript stack including jQuery, Handlebars.js, and various UI libraries. The site demonstrates excellent mobile optimization, accessibility, and SEO practices. It employs secure HTTPS connections and integrates multiple analytics and tracking tools such as Google Tag Manager and DigitalGov analytics, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS and secure form practices but lacks explicit security headers and a public vulnerability disclosure policy. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data is unavailable or redacted, which is typical for U.S. government .gov domains, and does not detract from the site's legitimacy. Overall, NOAA's website is a highly professional, secure, and trustworthy government resource with comprehensive content and strong branding. Strategic improvements could include adding explicit security headers, publishing a vulnerability disclosure policy, and enhancing cookie consent mechanisms to further strengthen privacy compliance.

55
53
17
65
90
85
100
governmentweatherclimateoceaneducation+4 more
Drupal 10jQueryGoogle Tag ManagerHandlebars.js+4
2025-10-08T16:42:10.508Z
nemicroelectronics.org favicon

Massachusetts Technology Collaborative

nemicroelectronics.org

65
TechnologyUnited StatesmediumMEDIUM

The Northeast Microelectronics Coalition (NEMC) is a regional technology hub under the Massachusetts Technology Collaborative, focused on advancing microelectronics innovation and industry leadership in the Northeastern United States. The website highlights grant programs such as the PROPEL Program, membership opportunities, workforce development, and industry news, positioning NEMC as a key facilitator in the semiconductor ecosystem. The organization appears to be relatively new, founded in 2023, with a clear mission to support semiconductor companies and stakeholders through funding and collaboration. Technically, the website is built on Drupal 10 CMS, leveraging modern web technologies including Google Tag Manager for analytics and Google reCAPTCHA for form security. The site is mobile-optimized and includes accessibility features, reflecting a mature digital infrastructure. Performance is moderate, with good SEO and navigation clarity. From a security perspective, the site uses HTTPS and has implemented spam prevention on forms. However, DNSSEC is not enabled, and security headers are not explicitly detected, indicating room for improvement. No explicit security or incident response policies are published, and privacy compliance mechanisms such as cookie consent banners are absent, which may pose compliance risks. Overall, the website demonstrates a professional and trustworthy presence with strong business credibility. Strategic recommendations include enhancing security posture by enabling DNSSEC and security headers, publishing privacy and security policies, and implementing cookie consent mechanisms to improve compliance and user trust.

80
53
17
40
77
70
100
microelectronicstechnologycoalitiongrantsmembership+4 more
Drupal 10Google Tag ManagerGoogle reCAPTCHA v2Swiper.js (carousel)+1

Partner Domains:

masstech.org
parent
aihub.masstech.org
partner

+3 more partners

2025-10-08T12:46:19.454Z
masscybercenter.org favicon

Massachusetts Technology Collaborative

masscybercenter.org

68
TechnologyUnited StatesmediumMEDIUM

MassCyberCenter is a government-affiliated cybersecurity collaborative under the Massachusetts Technology Collaborative, focused on enhancing economic growth through cybersecurity ecosystem outreach and resiliency within Massachusetts. The website serves as a hub for cybersecurity workforce development, grants, resources, events, and a jobs board targeting municipalities, small businesses, non-profits, and cybersecurity professionals. The organization holds a strong regional market position as a key resource for cybersecurity initiatives in the Commonwealth. Technically, the website is built on Drupal 10, leveraging modern web technologies including Google Tag Manager and Google reCAPTCHA for analytics and security. The site is mobile-optimized, accessible, and demonstrates good SEO practices. Hosting details are limited but the domain registrar is Network Solutions, LLC, with a domain age consistent with the organization's founding. Security posture is solid with HTTPS enforced and use of CAPTCHA on forms, though DNSSEC is not enabled and some security headers are missing. Privacy compliance is partially addressed with a comprehensive privacy policy but lacks a cookie consent mechanism. Contact information is clearly presented, enhancing business credibility. Overall, the website is professional, trustworthy, and well-positioned to serve its audience. Strategic improvements in security headers, DNSSEC, and privacy consent would further strengthen its posture.

80
53
47
40
67
70
100
cybersecuritymassachusettsgovernmenttechnologyworkforcedevelopment+3 more
Drupal 10Google Tag ManagerGoogle reCAPTCHAVimeo Player API+1

Partner Domains:

masstech.org
partner
aihub.masstech.org
partner

+3 more partners

2025-10-08T11:18:52.996Z
commonsense.org favicon

Common Sense Media

commonsense.org

68
Non-profitUnited StateslargeMEDIUM

Common Sense Media is a leading nonprofit organization dedicated to making the digital world safer and healthier for children and families. Their services include media ratings, educational resources, advocacy for tech accountability, and research on digital well-being. The organization targets families, educators, and policymakers, positioning itself as a trusted authority in child digital safety and education. The website reflects a mature digital presence with a professional design, clear navigation, and comprehensive content tailored to its audience. Technically, the site is built on Drupal 10 with PHP 8.3.26, leveraging modern web technologies including Google Tag Manager, Google Analytics, and OneTrust for consent management. The site is mobile-optimized, accessible, and employs security best practices such as HTTPS, CAPTCHA on forms, and content security policies. Performance is moderate, with CDN usage enhancing delivery. Security posture is strong with no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies, GDPR compliance indicators, and user consent mechanisms. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not present and could be improved. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance suitable for a nonprofit organization focused on child safety and education. The lack of WHOIS data is likely due to privacy protection, which is justified for this business type. No signs of malicious or suspicious activity were detected.

65
68
17
80
75
55
100
nonprofiteducationchildsafetydigitalliteracymediaratings+3 more
Drupal 10PHP 8.3.26Google Tag ManagerGoogle Analytics+2
2025-10-08T11:16:52.370Z
home.cern favicon

CERN

home.cern

68
EducationSwitzerlandlargeMEDIUM

CERN is a globally recognized intergovernmental scientific research organization specializing in fundamental physics. The website serves as a comprehensive portal for scientific research, educational resources, news, and events related to particle physics. It targets scientists, educators, and the general public interested in physics and science. The site is professionally designed, well-branded, and provides rich, relevant content with clear navigation and mobile optimization. Technically, the website is built on Drupal 10 CMS, utilizing modern JavaScript libraries such as Owl Carousel and Prism.js, and employs Matomo for privacy-conscious analytics. The site is hosted securely with HTTPS and enforces clientTransferProhibited status on the domain, though DNSSEC is not enabled, representing a minor security gap. Security posture is solid with HTTPS and some security best practices, but lacks explicit security headers and a public vulnerability disclosure or security.txt file. Privacy compliance is partial due to the absence of visible privacy and cookie policies or consent mechanisms. Contact information is available primarily via contact forms and physical address, with no direct emails or phone numbers exposed. Overall, the website is trustworthy, authoritative, and well-maintained, with recommendations to improve privacy compliance and DNS security to enhance user trust and security posture.

40
83
17
60
85
70
100
physicscernlhcscienceresearch+2 more
Drupal 10Matomo AnalyticsOwl CarouselPrism.js+1
2025-10-08T08:37:43.266Z
ftc.gov favicon

Federal Trade Commission

ftc.gov

76
GovernmentUnited StatesenterpriseLOW

The Federal Trade Commission (FTC) is a U.S. government agency dedicated to protecting consumers and promoting competition. The website serves as the official digital presence, offering resources such as fraud reporting, consumer alerts, and legal information. It targets American consumers, businesses, and legal professionals, positioning itself as the primary federal authority in consumer protection and antitrust enforcement. The site reflects a mature, enterprise-level government entity with a long history dating back over 100 years. Technically, the website is built on Drupal 10, leveraging modern web technologies including jQuery UI and Google Tag Manager. It demonstrates good mobile optimization, accessibility, and SEO practices. The infrastructure appears robust and professionally maintained, with no signs of technical debt or performance bottlenecks. From a security perspective, the site enforces HTTPS, implements key security headers, and avoids exposing sensitive data. It uses trusted analytics and marketing tools with privacy considerations. The presence of security policies, incident response contacts, and vulnerability disclosure programs indicates a mature security posture aligned with government standards. Overall, the FTC website is a highly credible, secure, and well-maintained government resource. It effectively balances transparency, user experience, and compliance, making it a trustworthy platform for consumer protection information and services.

55
58
47
85
90
80
100
governmentconsumerprotectionlegalfraudreportingprivacy+1 more
Drupal 10jQuery UIGoogle Tag ManagerAddToAny+1

Partner Domains:

reportfraud.ftc.gov
service
public.govdelivery.com
partner
2025-10-08T08:35:32.055Z
healthypeople.gov favicon

U.S. Department of Health and Human Services

healthypeople.gov

54
GovernmentUnited StatesenterpriseMEDIUM

The website odphp.health.gov/healthypeople is an official U.S. government health promotion platform under the Office of Disease Prevention and Health Promotion, part of the U.S. Department of Health and Human Services. It provides data-driven national health objectives and resources aimed at improving public health over the next decade. The site targets a broad audience including the general public, health professionals, and policymakers, offering tools, priority health areas, and evidence-based resources. The business model is a government public health initiative focused on education and data dissemination. Technically, the site is built on Drupal 10 CMS and leverages modern web technologies such as Google Tag Manager and OverlayScrollbars. It demonstrates good mobile optimization, accessibility, and SEO practices. Performance is moderate, with room for improvement in explicit security headers and cookie consent mechanisms. Analytics usage is moderate, primarily through Google Analytics via GTM, with privacy policies linked to authoritative HHS pages. From a security perspective, the site enforces HTTPS and links to a vulnerability disclosure policy, indicating a mature security posture. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of explicit security headers and incident response contact details suggests areas for enhancement. WHOIS data is minimal and incomplete, typical for .gov domains, but the domain's legitimacy is strongly supported by the official content and branding. Overall, the website is professional, trustworthy, and well-maintained, with minor recommendations to improve privacy compliance and security headers to further strengthen its posture.

80
53
35
-
77
-
100
healthgovernmentpublichealthhealthpromotionhealthypeople2030
Drupal 10Google Tag ManagerOverlayScrollbarsWeb Vitals
2025-10-08T06:13:30.436Z
health.gov favicon

Office of the Assistant Secretary for Health

health.gov

72
GovernmentUnited StatesenterpriseMEDIUM

The Office of the Assistant Secretary for Health (OASH) operates as a key component of the U.S. Department of Health and Human Services, providing leadership on health policy, programs, and initiatives aimed at improving the health and well-being of Americans. The website serves as an authoritative source for health information, advisory committees, grants, and career opportunities, targeting a broad audience including the general public, health professionals, and government stakeholders. The site maintains a strong market position as an official government resource with comprehensive content and clear navigation. Technically, the website is built on Drupal 10 and leverages the U.S. Web Design System (USWDS) to ensure accessibility, mobile responsiveness, and consistent branding. Integration with Google Tag Manager and Digital Analytics Program indicates moderate user tracking and analytics capabilities. Performance is moderate with good SEO and accessibility features, though there is room for improvement in security headers and DNS security. From a security perspective, the site enforces HTTPS with a valid SSL certificate and has domain transfer protections in place. However, DNSSEC is not enabled, and security headers are not explicitly detected, representing areas for enhancement. The presence of a vulnerability disclosure policy is a positive indicator, though incident response contact details are not found. Privacy compliance is partial, with a comprehensive privacy policy but no detected cookie consent mechanism. Overall, the website demonstrates a high level of professionalism, trustworthiness, and content quality consistent with a U.S. government health agency. Strategic improvements in DNS security, security headers, and privacy consent mechanisms would further strengthen its security posture and compliance standing.

65
53
35
70
72
90
100
governmenthealthpublichealthnutritionpolicy+3 more
Drupal 10Google Tag ManagerFont Awesome 6US Web Design System (USWDS)+1

Partner Domains:

www.hhs.gov
partner
odphp.health.gov
partner

+3 more partners

2025-10-08T06:13:25.383Z
C

Centers for Medicare & Medicaid Services (CMS)

medicaid.gov

52
GovernmentUnited StatesenterpriseMEDIUM

Medicaid.gov is the official U.S. government website dedicated to providing comprehensive information and resources about Medicaid and the Children's Health Insurance Program (CHIP). It serves a broad audience including U.S. residents seeking healthcare coverage information, state agencies, healthcare providers, and policymakers. The site is authoritative and well-positioned as the primary source for Medicaid and CHIP program details, federal policy guidance, and state resources. Technically, the website is built on Drupal 10, leveraging modern web technologies such as FontAwesome for icons and Tealium Tag Manager for analytics and tracking. The site demonstrates good mobile optimization, accessibility, and SEO practices, contributing to an excellent user experience. Security-wise, the site enforces HTTPS and uses official .gov branding, which are strong trust indicators. However, explicit security headers and privacy-related policies such as privacy and cookie policies with consent mechanisms are not evident in the provided content, representing areas for improvement. Overall, the domain appears legitimate and trustworthy, consistent with a U.S. government entity, despite limited WHOIS data availability. Strategic recommendations include enhancing security headers, publishing clear privacy and cookie policies, and providing vulnerability disclosure information to strengthen security posture and user trust.

-
53
17
85
-
80
100
governmenthealthcaremedicaidchipus+3 more
Drupal 10FontAwesomeTealium Tag ManagerChartbeat
2025-10-08T06:13:05.107Z
insurekidsnow.gov favicon

Centers for Medicare & Medicaid Services

insurekidsnow.gov

39
GovernmentUnited StateslargeHIGH

InsureKidsNow.gov is an official U.S. government website managed by the Centers for Medicare & Medicaid Services (CMS), providing comprehensive information and resources about Medicaid and the Children's Health Insurance Program (CHIP) for children and teens. The site targets parents and caregivers seeking free or low-cost health and dental coverage options, offering tools such as a dentist locator, outreach materials, and mental health resources. It holds a strong market position as a trusted government resource with authoritative content and consistent branding. Technically, the website is built on Drupal 10 with integration of modern frameworks like Bootstrap and USWDS, ensuring mobile responsiveness, accessibility, and good SEO practices. The site uses various analytics and performance monitoring tools such as Tealium and Boomerang, and loads content securely over HTTPS. While the site lacks explicit cookie consent mechanisms and some security headers, it follows best practices for secure forms and data handling. From a security perspective, the site benefits from the inherent trust of the .gov domain and HTTPS encryption. No vulnerabilities or exposed sensitive data were detected in the content. However, improvements could be made by adding security headers, publishing a vulnerability disclosure policy, and providing incident response contacts. The WHOIS data is not publicly available, consistent with .gov domain privacy policies, but the domain expiry and usage align with legitimate government operations. Overall, InsureKidsNow.gov demonstrates a high level of professionalism, trustworthiness, and compliance with privacy standards. It effectively serves its mission to inform and assist families in accessing health coverage for children, with a solid technical foundation and secure environment.

65
58
2
-
-
-
100
governmenthealthcaremedicaidchipchildren+4 more
Drupal 10Bootstrap 4.3.1jQuery 3.7.1Popper.js+5

Partner Domains:

medicaid.gov
partner
www.hhs.gov
partner

+3 more partners

2025-10-08T06:13:00.080Z
sba.gov favicon

U.S. Small Business Administration

sba.gov

71
GovernmentUnited StateslargeMEDIUM

The U.S. Small Business Administration (SBA) is a federal government agency dedicated to supporting America's small businesses by providing access to funding, counseling, disaster assistance, and federal contracting opportunities. The website serves as a comprehensive portal for entrepreneurs and small business owners to access resources, learn about SBA programs, and connect with local assistance partners. The SBA holds a strong market position as the official government entity for small business support in the United States, targeting a broad audience of small business stakeholders. Technically, the SBA website is built on Drupal 10 and leverages modern web technologies including the U.S. Web Design System (USWDS), Google Tag Manager, and Facebook Pixel for analytics and marketing. The site is mobile-optimized, accessible, and well-structured, providing a professional user experience. However, some security best practices such as explicit security headers and cookie consent mechanisms could be improved. From a security perspective, the site enforces HTTPS and does not expose sensitive data in the HTML. The lack of visible security headers and absence of a vulnerability disclosure policy are areas for enhancement. The WHOIS data is incomplete, likely due to .gov domain registry policies, but the domain and content strongly indicate legitimacy and trustworthiness. Overall, the SBA website presents a low-risk profile with strong business credibility and good technical implementation. Strategic recommendations include adding security headers, implementing cookie consent, and publishing incident response and vulnerability disclosure information to further enhance trust and compliance.

70
53
47
80
100
30
100
smallbusinessgovernmentfundingloansfederalcontracting+3 more
Drupal 10Google Tag ManagerFacebook PixelUSWDS (U.S. Web Design System)
2025-10-08T06:12:40.028Z
sam.gov favicon

U.S. General Services Administration

sam.gov

70
GovernmentUnited StatesenterpriseMEDIUM

SAM.gov is the official U.S. government platform managed by the General Services Administration, providing comprehensive services related to federal contracting, entity registration, federal assistance, wage determinations, and federal hierarchy data. It serves as a critical resource for businesses and entities seeking to engage with the federal government. The platform is well-established, with a domain age dating back to 2004, and is positioned as a trusted authoritative source in the government procurement ecosystem. Technically, SAM.gov leverages Drupal 10 CMS, integrates with Google Analytics and Tag Manager for analytics, and uses AWS for DNS hosting. The site demonstrates good mobile optimization, accessibility, and SEO practices, contributing to a positive user experience. Security-wise, the site enforces HTTPS and has domain transfer protections, but could improve by enabling DNSSEC and publishing explicit security headers and incident response information. Privacy compliance is partially addressed with clear privacy and terms policies, though cookie consent mechanisms are absent. Overall, SAM.gov exhibits a strong security posture and high business credibility, with recommendations to enhance transparency and security controls further.

55
53
17
73
90
85
100
governmentfederalcontractingentityregistrationfederalassistance+1 more
Drupal 10YouTube iframe APIGoogle Tag ManagerGoogle Analytics+1

Partner Domains:

acquisition.gov
partner
usaspending.gov
partner

+2 more partners

2025-10-08T06:12:19.944Z
ahrq.gov favicon

Agency for Healthcare Research and Quality

ahrq.gov

68
GovernmentUnited StateslargeMEDIUM

The Agency for Healthcare Research and Quality (AHRQ) is a U.S. government agency under the Department of Health and Human Services focused on advancing healthcare quality, safety, accessibility, and affordability through research, data analytics, and funding programs. The website serves healthcare professionals, researchers, policymakers, and the public by providing authoritative resources, tools, and publications. It holds a strong market position as an official government source for healthcare research and quality improvement. Technically, the website is built on Drupal 10 and incorporates modern web technologies including Google Tag Manager, Google Analytics, Leaflet.js, and D3.js for data visualization. The site is mobile-optimized, accessible, and well-structured with good SEO practices. Performance is moderate with room for optimization. From a security perspective, the site enforces HTTPS and uses some security headers, though it lacks explicit Content Security Policy and other advanced headers. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is basic with a privacy policy and cookie policy present but no explicit consent mechanism. WHOIS data is incomplete but the .gov domain and content strongly support legitimacy. Overall, the site is professional, trustworthy, and safe with a high AI score of 87. Recommendations include enhancing security headers, implementing cookie consent for GDPR compliance, and publishing a vulnerability disclosure policy to further strengthen trust and security posture.

40
53
17
85
100
65
100
healthcaregovernmentresearchqualitysafety+4 more
Drupal 10Google Tag ManagerGoogle AnalyticsLeaflet.js+2
2025-10-08T04:00:06.451Z
medicare.gov favicon

Centers for Medicare & Medicaid Services

medicare.gov

72
HealthcareUnited StatesenterpriseMEDIUM

Medicare.gov is the official U.S. government website managed by the Centers for Medicare & Medicaid Services (CMS). It provides comprehensive information and services related to Medicare health insurance for people aged 65 or older and younger individuals with disabilities. The site offers key functionalities such as plan comparison, account management, provider lookup, fraud reporting, and customer support including live chat. It serves as a trusted authoritative source for Medicare-related information in the United States. Technically, the website is built on Drupal 10 CMS and leverages modern web technologies including Font Awesome icons, YouTube API for video content, and Tealium for tag management and analytics. The site is well-optimized for mobile devices and accessibility, featuring structured data (JSON-LD) for enhanced SEO and rich search results. Performance is moderate with asynchronous script loading to improve user experience. From a security perspective, the site enforces HTTPS and employs secure form practices including consent checkboxes. However, explicit security headers such as Content-Security-Policy and cookie consent mechanisms are not detected, representing areas for improvement. The WHOIS data is unavailable due to the .gov domain nature, but the domain's legitimacy is strongly supported by official branding, content, and government affiliation. Overall, Medicare.gov demonstrates a high level of professionalism, trustworthiness, and compliance with privacy standards. It effectively serves its target audience with clear navigation, relevant content, and multiple contact channels. Strategic recommendations include enhancing security headers, implementing cookie consent, and publishing security and incident response policies to further strengthen trust and compliance.

55
53
17
85
100
80
100
governmenthealthcaremedicareinsuranceusgov+2 more
Drupal 10Font Awesome 6 ProYouTube iframe APITealium tag management+3
2025-10-08T03:59:51.323Z
nih.gov favicon

National Institutes of Health

nih.gov

75
GovernmentUnited StatesenterpriseMEDIUM

The National Institutes of Health (NIH) is a premier U.S. government medical research agency under the Department of Health and Human Services. The website serves as a comprehensive portal for health information, research funding, clinical trials, and educational resources targeting a broad audience including the public, researchers, and medical professionals. It holds a strong market position as a trusted federal entity advancing biomedical research and public health. Technically, the site is built on Drupal 10, leveraging modern web technologies and integrations such as Google Tag Manager and Verint SDK for analytics and user experience enhancements. The website demonstrates excellent mobile optimization, accessibility, and SEO practices, ensuring broad usability and reach. From a security perspective, the site enforces HTTPS, uses external link best practices, and links to a vulnerability disclosure policy, indicating a mature security posture. However, explicit security headers and incident response contacts could be more visible. Privacy compliance is good with a comprehensive privacy policy, though a cookie consent mechanism is absent. Overall, the NIH website is a highly credible, professional, and secure government resource with minor areas for improvement in privacy consent and security header transparency.

85
53
20
85
85
85
100
nihhealthmedicalresearchgrantsclinicaltrials+3 more
Drupal 10Google Tag ManagerVerint Unified WebSDKCrazyEgg+1
2025-10-08T03:59:36.293Z