Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 20 of 20|Showing 951-991 of 991
tickster.com favicon

Tickets for events across the Nordic region

tickster.com

45
OtherN/amediumHIGH

Tickster.com is an online ticketing platform focused on providing tickets for concerts, festivals, theater performances, and other events across the Nordic region. The website targets consumers in Nordic countries such as Norway, Sweden, and Denmark, offering localized access points for each country. The business model centers on event ticket sales and serves as a regional player in the event ticketing market. The site presents a professional and consistent brand image with good design and user experience, supporting mobile optimization and clear navigation. From a technical perspective, the website leverages modern technologies including Google Tag Manager, Cloudflare Insights, and Google Fonts, hosted via AWS Cloudfront CDN. The site uses HTTPS with an excellent SSL configuration, ensuring secure communications. However, explicit security headers are not visible in the HTML content, and no CMS or frameworks are clearly identified. Performance is moderate with good mobile responsiveness and basic accessibility features. Security posture is generally good with HTTPS enforced and cookie consent implemented via Cookiebot, indicating some privacy compliance efforts. However, the absence of visible privacy policy, terms of service, and contact information for security incidents reduces compliance confidence. No vulnerabilities or exposed sensitive data were detected in the provided content. The domain uses privacy protection for WHOIS data, which is justified for this commercial platform. Overall, the site appears legitimate and trustworthy but could improve transparency and security practices. The overall risk assessment is moderate with recommendations to publish privacy and terms policies, add security headers, provide clear contact channels for incident response, and enhance accessibility. These improvements would strengthen compliance, user trust, and security posture.

15
10
-
75
-
80
100
ticketingeventsnordicconcertsfestivals+2 more
Google Tag ManagerCloudflare InsightsGoogle FontsSVG graphics
2025-06-18T08:55:47.264Z
trafikverket.se favicon

Trafikverket

trafikverket.se

46
TransportationSwedenenterpriseHIGH

Trafikverket is the Swedish government agency responsible for the long-term planning and management of the country's transport systems, including road traffic, railways, shipping, and aviation. The website trafikverket.se serves primarily private individuals with comprehensive information on traffic conditions, driving licenses, and ongoing infrastructure projects. The agency holds a strong national position as the authoritative source for transport infrastructure in Sweden, offering key services such as traffic information, booking for driving tests, and updates on major construction projects. Technically, the website is built on the EPiServer CMS platform and utilizes modern web technologies including Bootstrap for responsive design and SVG for graphics. The site demonstrates good performance and accessibility, with clear navigation and mobile optimization. Privacy and cookie policies are well implemented, featuring a consent mechanism and detailed information pages. Analytics are handled via a proprietary Trafikverket Analytics Tag Manager, with moderate user tracking. From a security perspective, the site enforces HTTPS, employs strict referrer policies, and avoids exposing sensitive data. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not present, representing areas for improvement. The WHOIS data confirms the domain's legitimacy as a Swedish government entity, consistent with the website's content and business claims. Overall, Trafikverket.se is a professional, trustworthy, and well-maintained government website with strong content quality and technical implementation. Strategic recommendations include publishing formal security and incident response policies, adding vulnerability disclosure information, and enhancing security headers to further strengthen the security posture.

55
-
-
60
-
70
100
transportationgovernmenttrafficinformationswedenpublicservices
EPiServer CMSJavaScriptSVG graphicsAsync script loading
2025-06-18T08:55:47.126Z
pokerstars.com favicon

Rational Intellectual Holdings Limited

pokerstars.com

58
OtherMaltalargeMEDIUM

PokerStars, operated by Rational Intellectual Holdings Limited and owned by Flutter Entertainment, is a leading global online poker platform established in 2001. The website offers a comprehensive range of poker games, tournaments, and casino services, targeting online poker enthusiasts worldwide. It holds multiple licenses and certifications, including from the Malta Gaming Authority, ensuring regulatory compliance and player protection. The platform emphasizes secure transactions, responsible gaming, and player fund segregation, reinforcing its market leadership and trustworthiness. Technically, the website employs modern web technologies such as React, Google Tag Manager, Optimizely for A/B testing, and OneTrust for cookie consent management. The site is well-optimized for mobile devices, features fast loading times, and includes accessibility considerations. The content is professionally curated with clear navigation and SEO best practices, supporting a high-quality user experience. From a security perspective, PokerStars enforces HTTPS, implements strong security headers, and provides granular cookie consent options. The site does not expose sensitive data or use vulnerable libraries. However, it lacks a dedicated security policy page and explicit incident response contact details, which are recommended for enhanced transparency and readiness. Overall, PokerStars presents a robust, professional, and secure online poker environment with strong compliance and trust indicators. Strategic improvements in publishing security policies and incident response information would further strengthen its security posture and user confidence.

40
63
-
85
-
90
100
onlinepokergamingcasinopokertournamentsresponsiblegaming+1 more
ReactGoogle Tag ManagerOptimizelyOneTrust Cookie Consent+1

Partner Domains:

www.flutter.com
parent
www.starsaffiliateclub.com
partner
2025-06-18T08:07:08.672Z
framercommerce.com favicon

Butter Supply Inc.

framercommerce.com

64
E-commerceUnited StatessmallHIGH

Framer Commerce is a specialized SaaS platform that enables users to design and launch custom Shopify e-commerce stores using the Framer design tool. Positioned as an award-winning plugin, it targets Shopify store owners and no-code builders seeking advanced e-commerce capabilities integrated with a visual design environment. The platform offers features such as live product filtering, multi-currency support, subscription management, and analytics integration, positioning itself as a modern e-commerce stack solution. Technically, the website leverages Framer's framework, Shopify's Storefront API via GraphQL, and integrates analytics tools like Google Analytics and Hotjar, demonstrating a mature and modern digital infrastructure. Security practices include HTTPS enforcement, use of access tokens with limited scope, and secure form handling, although explicit security policies and incident response information are not publicly available. Overall, the site is professional, well-designed, and trustworthy, with minor gaps in privacy compliance such as the absence of a cookie consent mechanism. Strategic recommendations include enhancing privacy compliance, publishing security policies, and providing clearer contact channels to further strengthen trust and compliance.

40
58
33
70
54
75
100
e-commerceshopifyframerno-codeplugin+1 more
FramerShopify Storefront APIGraphQLGoogle Analytics+3

Partner Domains:

shopify.com
partner
framer.com
partner

+1 more partners

2025-06-18T00:26:42.616Z
bernd-gruber.at favicon

Bernd Gruber GmbH

bernd-gruber.at

24
Real EstateAustriasmallCRITICAL

Bernd Gruber GmbH operates as a boutique interior design and craftsmanship firm based in Austria, specializing in high-end interior architecture and handcrafted furniture. The company leverages a rich heritage of 60 years in woodworking combined with 20 years of interior design experience, targeting affluent clients seeking bespoke design solutions. Their business model includes both service delivery through projects and product sales via an online shop. The website reflects a professional and consistent brand image with good content quality and clear navigation, supporting their market positioning as a premium provider in the real estate and hospitality sectors. Technically, the website is built on TYPO3 CMS and hosted on Conova infrastructure, utilizing modern web technologies such as SVG graphics and Google Tag Manager for analytics and marketing. However, the site suffers from a critical security shortfall due to the absence of HTTPS, which severely impacts its security posture. Performance metrics are not optimal, indicating room for improvement in loading speed and technical optimization. Mobile responsiveness and SEO are adequately addressed. Security-wise, the lack of SSL/TLS encryption is a major vulnerability, exposing users to potential data interception risks. While some security headers are present, the overall security configuration is basic and requires urgent enhancement. Privacy compliance is well managed with a comprehensive cookie consent mechanism and clear privacy policy, aligning with GDPR requirements. Contact information is transparent and easily accessible, enhancing business credibility. Overall, the website presents a trustworthy and professional front but must prioritize implementing HTTPS and improving security configurations to protect user data and maintain compliance. Strategic recommendations include securing the site with a valid SSL certificate, enabling modern TLS protocols, and enhancing security headers. These steps will significantly improve the site's security score and user trust, supporting the company's premium market positioning.

30
-
-
50
-
85
20
interiordesignhandwerkinnenarchitekturberndgruberkitzbhel+4 more
TYPO3 CMSnginxGoogle Tag ManagerLinkedIn Insight Tag+1
2025-06-15T22:12:46.327Z
mohemian.com favicon

mohemian services GmbH

mohemian.com

32
TechnologyAustriasmallHIGH

mohemian services GmbH is a small Austrian technology consultancy specializing in translating business needs into technology solutions. Their offerings include business strategy, entrepreneurial thinking, experience design, corporate governance, and technical architecture and development. The company targets tech startups, corporate ventures, and clients seeking innovative digital product development. Their market position is that of a niche, visionary technology partner with a focus on professional execution and agile processes. Technically, the website is built on GravCMS, hosted on Hetzner infrastructure, and uses nginx as the web server. The site includes modern SVG graphics and several Grav plugins for markdown notices, forms, and login functionality. However, the site lacks a valid SSL certificate and does not serve content over HTTPS, which is a critical security shortfall. Performance metrics are missing, but the site appears to have good mobile optimization and basic accessibility features. From a security perspective, the site implements several security headers such as HSTS, X-Frame-Options, and X-XSS-Protection, but the absence of HTTPS and TLS protocols severely undermines security posture. No incident response or security policy information is provided, and no vulnerability disclosure or security.txt file is found. Email security could be improved by adding a DMARC record. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism. Overall, the website is professional and trustworthy in terms of business presentation but requires urgent improvements in security infrastructure, especially enabling HTTPS with a valid certificate. Adding cookie consent and incident response information would enhance compliance and trust. The domain registration data aligns well with the business claims, supporting legitimacy. Strategic recommendations include securing the website with HTTPS, implementing cookie consent, publishing security policies, and improving email security.

60
18
-
50
-
75
40
technologyconsultingbusinessstrategyexperiencedesignsoftwaredevelopment
nginxGravCMSSVG graphicsMarkdown notices plugin+2
2025-06-15T21:55:00.611Z
confida.at favicon

CONFIDA Steiermark Steuerberatung GmbH

confida.at

39
FinanceAustriamediumHIGH

CONFIDA Steiermark Steuerberatung GmbH is a professional tax advisory and auditing firm with a strong regional presence in Austria and Southeast Europe, including Croatia, Serbia, and Slovenia. The company offers a broad range of services such as tax consulting, auditing, corporate consulting, payroll accounting, and controlling. Their market position is that of an established medium-sized firm with multiple subsidiaries and offices, targeting businesses and individuals requiring financial and tax services. The website reflects a professional business model focused on client service and regional expertise. Technically, the website is hosted on an nginx server with DNS managed by net4you.net and uses Matomo analytics for privacy-conscious user tracking. The site employs modern web technologies including SVG graphics and JavaScript modules, and it is optimized for mobile devices with good accessibility and SEO practices. However, performance metrics indicate slow loading times, which could be improved. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical vulnerability impacting user trust and data protection. While some security headers are present, the absence of TLS protocols and OCSP stapling reduces the overall security posture. Privacy policies and cookie consent mechanisms are implemented, indicating compliance with GDPR requirements, but no explicit security policy or incident response information is provided. Overall, the website is professionally designed and content-rich, supporting the company's credibility and trustworthiness. The main risk lies in the missing SSL/TLS configuration, which should be addressed urgently to protect users and improve the security score. Strategic recommendations include implementing HTTPS, enhancing SSL configuration, and adding security and incident response documentation to strengthen compliance and trust.

55
-
5
50
-
75
100
steuerberaterwirtschaftsprferunternehmensberatunggrndungsberatungfinance+2 more
nginxMatomo AnalyticsSVG graphicsJavaScript modules

Partner Domains:

inaa.org
partnerpending
atikon.com
partnerpending
2025-06-15T21:52:10.636Z
casinos.at favicon

Casinos Austria AG

casinos.at

40
HospitalityAustrialargeHIGH

Casinos Austria AG operates a comprehensive network of casinos across Austria, providing a wide range of gaming options including poker, slot machines, and table games, complemented by hospitality services such as restaurants and event locations. The website serves as the official digital presence, targeting casino visitors and players with detailed information on locations, events, membership benefits, and promotional packages. The company holds a strong market position as a leading casino operator in Austria, supported by consistent branding and trust indicators such as recognized certifications and responsible gaming initiatives. Technically, the website is built on TYPO3 CMS and employs modern web technologies including JavaScript and SVG graphics. It integrates multiple analytics and marketing tools with user consent mechanisms, ensuring good digital maturity. The site is mobile-optimized and accessible, with good SEO practices and clear navigation enhancing user experience. From a security perspective, while the site implements several important security headers and content security policies, it currently lacks a valid SSL certificate and does not support modern TLS protocols, significantly weakening its security posture. This exposes the site to risks related to unencrypted traffic and potential interception. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR adherence. The presence of a responsible disclosure page indicates a proactive approach to vulnerability management. Overall, the site is professional and trustworthy but requires urgent improvements in SSL/TLS configuration to secure user data and maintain trust. Strategic recommendations include obtaining a valid SSL certificate, enabling TLS 1.2 or higher, and fully activating HSTS. These steps will enhance security, compliance, and user confidence, supporting the company’s strong market presence and digital strategy.

80
-
15
50
-
90
100
casinogamingpokerslotsevents+3 more
TYPO3 CMSJavaScriptSVG graphicsJentis analytics+1

Partner Domains:

lotterien.at
partnerpending
trustedshops.at
partnerpending

+1 more partners

2025-06-15T21:47:05.513Z
documentator.io favicon

WebBuilds B.V.

documentator.io

40
TechnologyN/asmallHIGH

Documentator is a technology SaaS company providing a documentation platform designed to simplify the creation and management of product and developer documentation. Positioned as an affordable alternative to established documentation tools, it targets developers and product teams seeking an easy-to-use, flexible solution with features like custom domains, translation support, and analytics. The business operates under WebBuilds B.V., founded in 2020, and offers tiered subscription plans with a free trial to attract users. Technically, the website employs modern JavaScript frameworks (likely Vue.js), Cloudflare DNS services, and Matomo analytics configured for privacy. However, the site suffers from a critical security shortfall due to an invalid SSL certificate and lack of HTTPS enforcement, which significantly impacts its security posture. Performance is moderate to slow, with good mobile optimization and basic accessibility features. Security-wise, the absence of HTTPS, missing security headers, and lack of DNS security records (DMARC, CAA) present vulnerabilities that could expose users to risks. Privacy compliance is reasonably addressed with a comprehensive privacy policy and GDPR references, but no cookie consent mechanism is implemented. Business credibility is supported by clear policies, testimonials, and transparent pricing. Overall, Documentator is a functional and professional SaaS platform with solid business fundamentals but requires urgent improvements in security infrastructure to protect user data and enhance trust.

50
43
25
40
85
75
40
documentationsaasdocumentationtooldevelopertooldocumentationplatform
JavaScriptMatomo AnalyticsCloudflare DNSCSS (custom styles)+1

Partner Domains:

ploi.io
partner73
filapanel.com
partnerpending

+1 more partners

2025-06-14T22:03:56.155Z
dmarc.io favicon

dmarcian

dmarc.io

61
TechnologyN/asmallMEDIUM

dmarc.io is a specialized resource center focused on DMARC (Domain-based Message Authentication, Reporting & Conformance) compliance and email security. Powered by dmarcian.com, it provides public information about DMARC sources, forwarders, and best practices for sending email on behalf of others. The site targets deployers, operators, and developers interested in DMARC deployment and compliance. It operates as a niche information repository with a clear focus on email authentication and security standards. Technically, the website uses modern JavaScript modules and integrates analytics tools such as Google Tag Manager and Hotjar for user behavior tracking. Hosting and DNS services are provided by Google Cloud DNS. However, the site lacks a valid SSL/TLS certificate and does not serve content over HTTPS, which is a significant security shortfall. Performance is moderate, with a page load time of approximately 3.7 seconds and a moderate number of resources. From a security perspective, the site enforces a strict DMARC policy at the DNS level with a reject policy, which is a strong positive indicator for email security. However, the absence of HTTPS, lack of security headers, and missing advanced TLS protocols reduce the overall security posture. No privacy or cookie policies are present, and no contact forms or direct contact information are provided on the site, limiting transparency and compliance with privacy regulations. Overall, dmarc.io serves as a valuable technical resource for DMARC-related information but requires significant improvements in web security practices, privacy compliance, and transparency to enhance trustworthiness and user confidence.

15
40
25
85
100
70
100
dmarcemailsecuritydnscompliancedmarcian
JavaScript ES ModulesHotjar (analytics and heatmaps)Google Tag ManagerSVG graphics

Partner Domains:

dmarcian.com
parent70
2025-06-14T20:42:29.208Z
sidnfonds.nl favicon

SIDN fonds : een sterk internet voor iedereen

sidnfonds.nl

40
TechnologyNetherlandsmediumHIGH

SIDN fonds is a Dutch non-profit organization dedicated to supporting innovative internet projects that contribute to a safer and more inclusive internet. With over 400 projects funded since 2015, it holds a strong position within the Dutch internet community, focusing on themes such as cybersecurity, digital accessibility, and public values. The website provides comprehensive information about its mission, funding opportunities, and supported projects, targeting innovators and organizations involved in internet initiatives. Technically, the website is hosted on Google Cloud infrastructure using OpenResty as the web server. It employs a robust Content Security Policy and integrates multiple analytics and marketing tools including Piwik PRO and Google Analytics. The site is mobile-optimized with good accessibility and SEO practices. However, a critical security gap is the absence of a valid SSL/TLS certificate, resulting in no HTTPS support, which significantly impacts the security posture. Security-wise, while several security headers are implemented, the lack of HTTPS and disabled TLS protocols expose the site to risks such as data interception and man-in-the-middle attacks. No explicit security or incident response policies are published, and no vulnerability disclosure mechanisms are evident. Privacy and cookie policies are present and appear comprehensive, supporting GDPR compliance. Overall, the site is professionally designed and content-rich but requires urgent improvements in SSL/TLS deployment to enhance security and trustworthiness. Strategic recommendations include obtaining a valid SSL certificate, enabling modern TLS protocols, and enhancing security headers to protect users and data effectively.

90
-
25
50
100
90
100
internetfundingtechnologynon-profitprivacy+2 more
OpenResty (web server)Piwik PRO (analytics)SVG graphicsJavaScript with inline and external scripts
2025-06-14T19:46:51.477Z
munich-urban-colab.de favicon

Munich Urban Colab GmbH

munich-urban-colab.de

40
Real EstateGermanymediumHIGH

Munich Urban Colab GmbH operates a prominent innovation and coworking space in Munich, Germany, focused on developing and testing solutions for the future city through interdisciplinary and cross-sector collaboration. Positioned as one of Europe's largest startup centers, it serves startups, entrepreneurs, researchers, and public sector entities with services including coworking spaces, event venues, and community building. The website reflects a professional and well-branded digital presence with strong partnerships from major corporations and academic institutions. Technically, the site uses modern JavaScript modules, animation libraries, and a cookie consent management platform, but suffers from slow load times and lacks a valid SSL certificate, which impacts security posture. Security practices are basic, with no security headers or HSTS enabled, and no incident response or vulnerability disclosure policies found. Privacy compliance is good, with a clear privacy policy and cookie consent mechanism. Overall, the site is trustworthy and professional but requires urgent improvements in SSL and security configurations to enhance user trust and compliance.

50
18
25
70
100
75
100
innovationcoworkingsmartcitycollaborationstartup+1 more
JavaScript ES ModulesVite (build tool)GSAP (animation)Usercentrics (cookie consent)+2

Partner Domains:

unternehmertum.de
parentpending
sap.com
partner96

+3 more partners

2025-06-14T19:42:36.167Z
edmond-de-rothschild.fr favicon

Edmond de Rothschild

edmond-de-rothschild.fr

49
banking and financial servicesFrancelargeHIGH

The website's overall security posture is critically deficient, primarily due to the complete lack of HTTPS encryption, which exposes all data transmissions to interception and undermines user trust. Compliance with GDPR is severely lacking, with missing privacy and cookie policies, absence of a consent banner, and inadequate privacy measures for EU users, creating significant legal and reputational risks. The NIS2 compliance score is extremely low, indicating insufficient organizational security frameworks, policies, and incident response readiness, which heightens vulnerability to cyber incidents and regulatory penalties. While network security and DNS health show relatively strong results, essential protections like DNSSEC are not fully implemented. Security headers are mostly present but missing critical components such as the X-XSS-Protection header. Email security has gaps with missing DKIM records, potentially impacting email deliverability and phishing protections. Immediate remediation is needed to address encryption, privacy compliance, and governance frameworks to safeguard user data, maintain regulatory compliance, and protect business continuity. Without urgent action, the organization risks data breaches, regulatory fines, and loss of customer trust.

85
-
5
85
-
85
100
bankingprivate bankingwealth managementinvestmentasset management+3 more
Google Tag ManagerCookiebotUmbraco EngageSVG graphics+3

Partner Domains:

edram.com
partnerpending
edmondderothschildheritage.com
subsidiarypending

+2 more partners

2025-06-13T18:10:48.117Z