Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

154913
Websites
130
Industries
113
Countries
52
Avg Score
Page 1803 of 3099|Showing 90101-90150 of 154913
thingelstad.com favicon

Jamie Thingelstad

thingelstad.com

58
TechnologyN/asmallMEDIUM

The website www.thingelstad.com is a personal blog and portfolio site for Jamie Thingelstad, a technologist and leader with expertise in software, architecture, and business. The site features a variety of content including blog posts, projects, photos, and podcasts, targeting a general audience interested in technology and personal insights. The business model is centered around personal branding and content sharing rather than commercial transactions. Technically, the site is built using the Hugo static site generator and hosted on Micro.blog, leveraging modern web technologies such as JavaScript ES6 modules and service workers. It employs privacy-respecting analytics (Plausible) and has a fast, mobile-optimized, and accessible design. Security posture is good with HTTPS enforced and no exposed vulnerabilities, though it lacks explicit security headers and formal security policies. The absence of privacy and cookie policies represents a compliance gap. WHOIS data is missing or unavailable, which raises some concerns about domain registration legitimacy despite the professional and active website content. Overall, the site scores well on content quality and technical implementation but has room for improvement in privacy compliance and domain registration transparency.

15
50
2
70
65
80
100
personalblogtechnologysoftwarearchitecturefamily+2 more
Hugo static site generatorJavaScript ES6 modulesService WorkerPlausible Analytics
2025-07-27T20:54:16.425Z
virginia.gov favicon

Commonwealth of Virginia

virginia.gov

68
GovernmentUnited StatesenterpriseMEDIUM

Virginia.gov is the official digital portal for the Commonwealth of Virginia, providing residents, businesses, and visitors with access to a wide range of government services and resources. The website serves as a centralized hub for information on state government, business, education, health, transportation, and public safety. It is positioned as a trusted and authoritative source for Virginia state government information and services. Technically, the site employs modern web technologies including jQuery, Font Awesome, and Google Tag Manager, with a focus on accessibility and mobile responsiveness. The site is well-structured with clear navigation and comprehensive metadata, supporting good SEO and user experience. Performance is moderate, with opportunities for optimization. From a security perspective, the site uses HTTPS and follows several best practices, though it lacks some security headers and explicit security policies. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism or GDPR indicators. WHOIS data is unavailable due to privacy protection, which is typical for government domains. Overall, Virginia.gov presents a high level of trustworthiness and professionalism, suitable for its role as a government portal. Strategic improvements in privacy compliance and security transparency would further enhance its posture.

50
53
47
75
72
60
100
governmentpublicservicesvirginiastateofficial+5 more
jQuery 3.5.1Font Awesome 6.5.1Google Tag Manager (gtag.js)Microsoft Forms embed+1
2025-07-27T20:53:51.310Z
M

maxeepy homepage

maxy.top

43
TechnologyIcelandsmallHIGH

The website maxy.top is a personal portfolio site for the developer known as 'maxeepy'. It primarily showcases open source projects hosted on platforms such as GitHub and Codeberg, and provides links to various social media profiles. The site is relatively new, with the domain registered in late 2023, and targets a general audience interested in technology and software development. The business model is personal branding and project showcasing rather than commercial services. The site is small in scale and focused on individual presence in the technology sector. Technically, the site is built using Python and the Flask framework, hosted by Spaceship, Inc. The HTML content is basic but functional, with moderate performance and basic mobile optimization. SEO and accessibility features are minimal but present. No CMS or advanced platforms are detected. The site does not use analytics or tracking services, indicating a privacy-conscious approach. From a security perspective, the site lacks advanced security headers and does not enable DNSSEC on the domain. There is no visible privacy or cookie policy, and no contact information is provided for incident response or data protection officers. The domain uses privacy protection for WHOIS data, which is justified given the personal nature of the site. No vulnerabilities or malicious content were detected, but security posture is basic and could be improved. Overall, the site is low risk with a moderate trust level. Strategic recommendations include adding privacy and cookie policies, implementing security headers, improving mobile and accessibility features, and providing contact information for better compliance and trust. The site serves well as a personal portfolio but lacks professional security and compliance maturity.

15
40
2
60
52
70
40
personalportfoliodeveloperopensourcetechnology
PythonFlask
2025-07-27T20:53:46.252Z
planetminecraft.com favicon

Cyprezz LLC.

planetminecraft.com

64
TechnologyN/alargeMEDIUM

Planet Minecraft is a well-established community platform dedicated to Minecraft players and content creators worldwide. Operating since 2010 under Cyprezz LLC., it offers a wide range of user-generated content including maps, skins, mods, texture packs, and data packs. The site fosters social interaction through forums, groups, and content jams, positioning itself as a leading fan community in the Minecraft ecosystem. Its business model relies on community engagement and advertising revenue, supported by a large active user base exceeding 5 million members. Technically, the website employs modern web technologies including JavaScript frameworks, Google Tag Manager, and ad networks like Google Adsense and Venatus. It is mobile-optimized and implements HTTPS with good security practices such as CSRF tokens. However, it lacks some advanced security headers and explicit cookie consent mechanisms, which are important for GDPR compliance. The site integrates multiple analytics and tracking services, reflecting a moderate level of user tracking typical for community platforms. From a security perspective, the site demonstrates a solid posture with encrypted connections and no visible vulnerabilities or exposed sensitive data. The absence of a security.txt file and dedicated incident response contacts suggests room for improvement in vulnerability disclosure and incident management. The WHOIS data is unavailable, possibly due to privacy protection or query issues, which slightly reduces trust but is mitigated by the site's long history and consistent branding. Overall, Planet Minecraft presents a trustworthy, family-friendly environment with high-quality content and good technical implementation. Strategic enhancements in privacy compliance, security transparency, and WHOIS data availability would further strengthen its risk profile and user trust.

35
53
2
85
75
80
100
minecraftcommunitygamingmodsmaps+4 more
JavaScriptGoogle Tag ManagerGoogle AdsenseQuantcast+4
2025-07-27T20:53:16.017Z
bitwarden.com favicon

Bitwarden, Inc.

bitwarden.com

85
TechnologyUnited StatesenterpriseLOW

Bitwarden, Inc. operates a leading open source password management platform trusted by millions globally, serving individuals, families, businesses, and enterprises. Their product suite includes password management, secrets management, passwordless authentication, and developer tools, positioning them strongly in the cybersecurity technology market. The company emphasizes transparency, security, and compliance, supported by certifications such as SOC 2 and ISO 27001. Their business model is primarily SaaS with free and paid tiers, including self-hosting options for enterprises. Technically, Bitwarden employs a modern React-based web platform, leveraging Cloudflare for hosting and CDN services, and integrates analytics tools like Google Tag Manager and Plausible Analytics. The website demonstrates excellent performance, mobile optimization, accessibility, and SEO practices, reflecting a mature digital infrastructure. Security posture is robust, with enforced HTTPS, comprehensive security headers, a bug bounty program, and regular compliance audits. However, DNSSEC is not enabled, and a security.txt file is absent, representing areas for improvement. Privacy compliance is strong, with clear privacy and cookie policies and GDPR adherence. Contact information is available primarily via contact forms, with no explicit phone numbers or emails disclosed. Overall, Bitwarden presents a high-trust, professional, and secure online presence with minimal risk. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, and enhancing incident response transparency to further strengthen their security and compliance posture.

95
80
75
82
72
85
100
passwordmanagersecurityopensourceenterprisecompliance+1 more
ReactJavaScriptCSSGoogle Tag Manager+2
2025-07-27T20:53:00.717Z
pixelfed.social favicon

Pixelfed

pixelfed.social

61
TechnologyCanadamediumMEDIUM

Pixelfed.social is the original and main instance of the decentralized photo sharing social media platform Pixelfed, operated by the lead developer known as @dansup. The platform offers a federated social media experience focusing on photo posts, albums, filters, and video support, targeting general users interested in privacy-respecting social media alternatives. The website is professionally designed with good content quality and clear navigation, supporting mobile optimization and modern web technologies such as Vue.js and Plyr media player. Hosting and DNS are managed by Cloudflare, ensuring reliable performance and security. The domain is well-established since 2018, consistent with the business history. From a security perspective, the site uses HTTPS and has domain transfer protections but lacks DNSSEC and some security headers. There is no explicit public security or incident response policy, and no cookie consent mechanism was detected, which may impact GDPR compliance. The platform enforces community rules prohibiting hate speech, harassment, explicit content, and illegal activities, contributing to a safe user environment. Overall, the security posture is good but could be improved with enhanced policies and technical controls. The business model centers on providing a decentralized, federated photo sharing service with a strong community focus. The site maintains transparency with contact email and clear rules but lacks some formal compliance disclosures. The platform is positioned as a privacy-conscious alternative to mainstream social media, appealing to users valuing decentralization and open-source principles. Strategic recommendations include implementing cookie consent, enabling DNSSEC, publishing security policies, and adding security headers to strengthen trust and compliance.

50
53
17
35
75
75
100
photosharingsocialmediadecentralizedfederatedopensource
Cloudflare (DNS and hosting)JavaScriptVue.js (implied by VueCarousel classes)Plyr (media player library)+1

Partner Domains:

pixelfed.org
partner
2025-07-27T20:52:55.686Z
heroicons.com favicon

Tailwind Labs

heroicons.com

59
TechnologyN/asmallMEDIUM

Heroicons is an open source SVG icon library created and maintained by Tailwind Labs, the makers of Tailwind CSS. The website offers a comprehensive set of 316 hand-crafted icons under the permissive MIT license, targeting developers and designers who use Tailwind CSS or modern frontend frameworks like React and Vue. The site is well-positioned in the technology sector as a popular resource for UI/UX assets, with a small but focused business model centered on open source community engagement and design tooling. Technically, the website is built using modern web technologies including React, Vue, and Next.js, styled with Tailwind CSS. It is hosted with Cloudflare DNS and served over HTTPS, ensuring good performance, mobile optimization, and accessibility. The site lacks a CMS and does not appear to use advertising or tracking services, reflecting a clean and developer-friendly infrastructure. From a security perspective, the site benefits from HTTPS and absence of exposed sensitive data or vulnerable libraries. However, it lacks explicit security headers and formal policies such as privacy, cookie, or terms of service documents, which are important for compliance and user trust. No incident response or vulnerability disclosure mechanisms are publicly available. Overall, Heroicons presents a low-risk profile with strong technical and business credibility but could improve privacy compliance and security transparency. Strategic recommendations include publishing privacy and cookie policies, adding security headers, and providing a vulnerability disclosure channel to enhance trust and compliance.

30
35
17
60
75
75
100
svgiconstailwindcssopensourcereactvue+2 more
ReactVueSVGNext.js
2025-07-27T20:52:05.394Z
expresslanes.com favicon

Transurban (USA) Operations Inc.

expresslanes.com

67
TransportationUnited StateslargeMEDIUM

Express Lanes, operated by Transurban (USA) Operations Inc., is a well-established transportation service provider focused on express toll lanes in Northern Virginia. The website offers comprehensive services including toll payments, trip planning, and real-time traffic updates, supported by a mobile app to enhance user convenience. The company holds a strong market position as a key regional express lanes operator with a clear business model centered on transportation infrastructure and customer service. Technically, the website is built on Drupal 8, leveraging modern web technologies such as jQuery, Google Analytics, and Facebook Pixel for analytics and marketing. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. Hosting and domain registration are stable and consistent with the business profile, with Amazon Registrar as the domain registrar and AWS DNS servers. From a security perspective, the site enforces HTTPS, employs domain status locks to prevent unauthorized changes, and implements a cookie consent mechanism aligned with GDPR requirements. However, DNSSEC is not enabled, and no explicit security or incident response policies are published, indicating areas for improvement. No vulnerabilities or suspicious content were detected. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance, making it a reliable platform for its users. Strategic recommendations include enabling DNSSEC, publishing security policies, and implementing a vulnerability disclosure program to further enhance security posture and user trust.

55
68
2
70
72
85
100
transportationtollpaymentexpresslanesvirginiacommute+1 more
Drupal 8jQueryGoogle AnalyticsGoogle Tag Manager+2

Partner Domains:

transurban.com
parent
495next.vdot.virginia.gov
partner

+1 more partners

2025-07-27T19:51:27.017Z
funnelback.com favicon

Squiz

funnelback.com

63
TechnologyN/amediumMEDIUM

Squiz is a technology company specializing in AI-powered enterprise search and digital experience platforms. Their flagship product, Funnelback Search, leverages over 25 years of search innovation and 70+ ranking signals to deliver highly accurate and relevant search results across multiple content sources. The company targets enterprise clients in sectors such as Higher Education, Government, and Professional Services, offering a comprehensive suite of tools including content management, personalization, conversational AI, and analytics. Technically, the website demonstrates a mature digital infrastructure with modern JavaScript libraries, HubSpot integration for forms, and extensive use of analytics and tracking tools. Security posture is strong with HTTPS enforced and privacy policies in place, although explicit security headers are not clearly visible in the HTML. The absence of WHOIS domain registration data is a notable anomaly but does not detract significantly from the overall legitimacy given the professional presentation and trust indicators on the site. Overall, Squiz presents as a credible and established player in the enterprise search market with a well-implemented digital presence.

40
68
17
60
52
85
100
enterprisesearchaisearchdigitalexperienceplatformcontentmanagementconversationalai+3 more
jQueryHubSpot formsGoogle Tag ManagerFacebook Pixel+5

Partner Domains:

partner.squiz.net
partner
help.squiz.net
service

+3 more partners

2025-07-27T19:51:16.998Z
raspberrypi.org favicon

Raspberry Pi Foundation

raspberrypi.org

74
EducationUnited KingdomlargeMEDIUM

The Raspberry Pi Foundation is a well-established UK-based charity focused on empowering young people through computing education and digital technologies. It operates a large-scale educational ecosystem including free resources, teacher training, coding clubs, and research initiatives. The organization holds a strong market position as a global leader in computing education for youth, supported by a consistent brand and professional online presence. Technically, the website is built on a modern Ruby on Rails stack with advanced frontend frameworks like Stimulus and Turbo, hosted behind Cloudflare with strong security headers and HTTPS enforcement. The site demonstrates excellent performance, mobile optimization, and accessibility features, reflecting a mature digital infrastructure. From a security perspective, the site follows best practices including content security policies, cookie consent management, and no visible vulnerabilities or exposed sensitive data. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not publicly documented, representing an area for improvement. Overall, the website and organization exhibit a high level of trustworthiness and professionalism with no signs of malicious activity or content safety concerns. The domain WHOIS data is privacy protected, which is typical for non-profits, and does not detract from the legitimacy of the entity. Strategic recommendations include enhancing transparency around security policies and incident response, and publishing vulnerability disclosure information to further strengthen trust.

65
83
2
93
75
85
100
educationcharitycomputingcodingyouth+2 more
Ruby on RailsStimulusJSTurboGoogle Tag Manager+2

Partner Domains:

codeclub.org
partner
adacomputerscience.org
partner

+3 more partners

2025-07-27T19:51:06.879Z
L

lojban.io

lojban.io

49
EducationIcelandsmallHIGH

lojban.io is a specialized educational platform dedicated to the study and promotion of the constructed language Lojban. It offers free and open-source resources including courses, learning decks, and community engagement via a Discord server. The website targets language enthusiasts and learners interested in logical and constructed languages, positioning itself as a niche educational resource with a small but active user base. The platform is relatively young, established in 2020, and maintains a consistent brand and content quality with regular updates and community involvement. Technically, the website employs modern web technologies such as Bootstrap for styling, Font Awesome for icons, and integrates Google Analytics and Tag Manager for user tracking. It also supports Progressive Web App features, enhancing user experience across devices. Hosting and DNS services are managed via Cloudflare, providing performance and security benefits. The site demonstrates moderate performance and good mobile optimization but lacks some advanced accessibility features. From a security perspective, the site uses HTTPS with a good SSL configuration and has domain transfer protections in place. However, it lacks DNSSEC and important security headers like Content-Security-Policy and X-Frame-Options, which are recommended to enhance security posture. Privacy compliance is limited due to the absence of privacy and cookie policies, which is a notable gap given the use of tracking technologies. No incident response or vulnerability disclosure mechanisms are present. Overall, lojban.io presents a trustworthy and professional educational resource with a solid technical foundation but would benefit from improved privacy compliance and enhanced security headers. Strategic recommendations include implementing privacy and cookie policies, enabling DNSSEC, adding security headers, and establishing a vulnerability disclosure process to strengthen trust and compliance.

30
35
17
70
52
70
40
educationlanguagelojbanconstructedlanguageopensource+1 more
HTML5CSS (Bootstrap)JavaScriptGoogle Analytics+3
2025-07-27T19:50:21.433Z
fincxjejo.com favicon

Finĉjejo

fincxjejo.com

62
OtherN/asmallMEDIUM

The website fincxjejo.com is a personal site dedicated to sharing ideas, projects, and creations related to the Esperanto language by an individual named Fingtam (Finĉjo). It serves as a cultural and educational platform targeting Esperanto learners and enthusiasts. The site is hosted on Google Sites, leveraging Google's infrastructure and technologies such as Google Fonts and APIs. The content is primarily textual with links to social media channels including YouTube and Facebook. The site lacks formal business structure and operates as a small-scale personal project without commercial intent. From a technical perspective, the site is built on a modern, stable platform (Google Sites) ensuring reliable hosting and HTTPS security. The site demonstrates moderate performance and good mobile optimization but lacks advanced SEO and accessibility features. No custom frameworks or CMS beyond Google Sites are used. The absence of security headers beyond HTTPS is noted, and no forms or interactive data collection mechanisms are present. Security posture is adequate for a personal site with HTTPS enforced, but the lack of additional security headers and absence of privacy or terms of service pages indicate room for improvement. The WHOIS data is unavailable, raising concerns about domain registration legitimacy, although the site content and hosting platform suggest no malicious intent. Privacy compliance is minimal, with only a cookie consent banner present. Overall, the site is low risk but would benefit from improved transparency regarding domain registration, privacy policies, and enhanced security practices. Strategic recommendations include adding privacy and terms pages, implementing security headers, and clarifying domain registration status to improve trustworthiness.

70
50
2
60
72
75
100
esperantolanguagelearningpersonalwebsitegooglesiteseducation
Google SitesGoogle FontsGoogle APIsJavaScript
2025-07-27T19:50:16.399Z
lipukule.org favicon

Private by Design, LLC

lipukule.org

58
OtherUnited StatessmallMEDIUM

Lipukule.org is a niche cultural and linguistic website dedicated to the toki pona language and related content. It provides articles and posts that explore various themes in toki pona, targeting enthusiasts and learners of this constructed language. The website operates under the ownership of Private by Design, LLC, a US-based entity, with domain registration consistent with the site's scale and focus. The business model centers on content publication and community engagement via Discord and Telegram channels, without evident commercial transactions or e-commerce features. Technically, the website is built using the modern SvelteKit framework with JavaScript and CSS, delivering a good user experience with responsive design and clear navigation. Performance is moderate, and accessibility is basic but functional. No major technical debt or outdated technologies were detected. However, the site lacks advanced SEO optimization and accessibility features. From a security perspective, the site uses HTTPS but lacks security headers and published security policies. No privacy or cookie policies are present, and no contact information is provided, which limits compliance with GDPR and other privacy regulations. No vulnerability disclosure or incident response information is available. The domain registration is transparent and consistent with the website's purpose, supporting legitimacy. Overall, the website is safe, with no adult or explicit content detected. The content quality and business credibility are good, but privacy compliance and security posture need improvement. Strategic recommendations include implementing privacy and cookie policies, adding security headers, publishing a vulnerability disclosure policy, and enhancing accessibility and SEO.

30
50
2
70
72
75
100
tokiponalanguageculturelipukulecommunity
SvelteKitJavaScriptCSS
2025-07-27T19:50:11.360Z
liputenpo.org favicon

lipu tenpo

liputenpo.org

56
Non-profitGermanysmallMEDIUM

lipu tenpo is a registered association based in Germany that provides a cultural and educational platform primarily in the Toki Pona language. The website hosts a collection of articles and multimedia content licensed under CC BY-SA 4.0, targeting a general audience interested in this niche language and culture. The organization engages its community through Discord, Patreon, and Linktree, indicating active outreach and support mechanisms. The domain was registered in 2021, consistent with the association's founding timeline. Technically, the website is built with standard HTML5 and CSS3, utilizing Google Fonts and GoatCounter for lightweight, privacy-conscious analytics. The hosting is managed via Name.com, with no CMS or major frameworks detected, suggesting a custom or static site approach. The site is mobile-optimized with good navigation and SEO practices, though accessibility features are basic. Performance is moderate, with no blocking or WAF detected. From a security perspective, the site uses HTTPS and has domain transfer protections enabled, but lacks DNSSEC and security headers such as Content-Security-Policy or X-Frame-Options. There is no visible privacy or cookie policy, nor incident response or vulnerability disclosure information, which are areas for improvement. No sensitive data exposure or vulnerabilities were detected in the content. Overall, the security posture is moderate but could be enhanced with standard best practices. The overall risk assessment is low to moderate, with no critical issues found. Strategic recommendations include implementing DNSSEC, adding security headers, publishing privacy and cookie policies, and providing incident response contacts to improve compliance and trust. The site is trustworthy for its intended educational and cultural purpose but would benefit from enhanced security and privacy transparency.

15
35
2
60
95
70
100
educationculturenon-profittokiponacommunity
HTML5CSS3Google FontsGoatCounter analytics
2025-07-27T19:50:06.230Z
L

LIPUmanka

lipamanka.gay

56
OtherIcelandsmallMEDIUM

The website 'lipamanka.gay' is a personal site primarily focused on sharing essays, stories, and linguistic resources related to the creator's interests. It is a small-scale, niche site without commercial intent or business contact information. The site is hosted likely on GitHub Pages with domain registration through NameCheap, protected by privacy services. The technical infrastructure is basic, relying on standard HTML, CSS, and JavaScript, with minimal external dependencies. Analytics are implemented via GoatCounter, providing lightweight user tracking without aggressive data collection. From a security perspective, the site uses HTTPS and has domain transfer protection enabled, but lacks DNSSEC and security headers, which could be improved to enhance security posture. There are no privacy or cookie policies, nor terms of service, which limits compliance with GDPR and other privacy regulations. No contact or incident response information is provided, reducing transparency and trustworthiness from a security standpoint. Overall, the site is safe for general audiences, containing no adult or explicit content. The domain registration is recent and privacy protected, appropriate for a personal website. The lack of business information and policies limits the site's credibility and compliance maturity. Strategic improvements in security headers, privacy disclosures, and contact transparency would enhance trust and compliance.

15
40
2
70
95
70
100
personallinguisticsessaysstoriestokipona
HTML5CSSJavaScript
2025-07-27T19:49:51.004Z
A

Anna Kudriavtsev

ap5.dev

59
TechnologyN/asmallMEDIUM

The website ap5.dev is a personal professional portfolio and blog belonging to Anna Kudriavtsev, focusing on computing systems design and software development with an emphasis on correctness and maintainability. The site positions itself as a personal brand rather than a commercial business, targeting a general audience interested in technology and software development. The business model is primarily informational and portfolio-based, with links to a resume and GitHub repository. Technically, the website uses standard modern web technologies including HTML5, CSS3, and JavaScript, with external resources such as Google Fonts and a chat widget from cactus.chat. The site is moderately optimized for mobile and SEO, with good design quality and clear navigation. However, no CMS or hosting provider details are evident, and performance is moderate. From a security perspective, the site uses HTTPS and does not expose forms or sensitive data, but lacks explicit security headers and formal privacy or cookie policies. No vulnerability disclosure or incident response information is provided. The domain registration is privacy protected, which is appropriate for a personal site. Overall, the security posture is adequate but could be improved with additional headers and compliance documentation. The overall risk is low given the nature of the site, but strategic recommendations include implementing privacy and cookie policies, adding security headers, and providing vulnerability disclosure information to enhance trust and compliance.

15
35
2
70
95
80
100
personalportfoliotechnologyblogprofessional
HTML5CSS3JavaScript
2025-07-27T19:49:45.994Z