Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 202 of 800|Showing 10051-10100 of 39982
sportzoo.store favicon

SportZoo, s. r. o.

sportzoo.store

53
RetailSlovakiasmallMEDIUM

SportZoo, s. r. o. operates an official e-commerce website specializing in collectible sports cards and related merchandise, primarily targeting collectors and sports enthusiasts in Slovakia and neighboring countries. The website offers a variety of products including albums, boxes, and starter packs, with clear product categorization and multilingual support. The business model is retail-focused, leveraging direct online sales and marketing through digital channels. The company positions itself as a legitimate Slovak manufacturer and retailer with a consistent brand presence and customer support availability. Technically, the website is built on the Upgates e-commerce platform, utilizing modern web technologies such as Google Tag Manager, Google Analytics 4, and Facebook Pixel for marketing and analytics. The site is mobile-optimized with a responsive design and includes cookie consent mechanisms to comply with basic privacy requirements. Performance is moderate with good SEO and accessibility features, though some advanced security headers are missing. From a security perspective, the site enforces HTTPS and manages cookie consent effectively. However, it lacks published security policies, incident response contacts, and vulnerability disclosure mechanisms. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data confirms the legitimacy of the domain registration, matching the company’s Slovak origin and business claims. Overall, the website demonstrates a solid business and technical foundation with room for improvement in privacy compliance and security transparency. Strategic recommendations include publishing comprehensive privacy and terms policies, enhancing security headers, and establishing formal incident response and vulnerability disclosure processes.

65
50
17
85
62
45
20
e-commercecollectiblecardssportsmerchandiseslovakiaretail
JavaScriptGoogle Tag ManagerGoogle Analytics 4Facebook Pixel+1
2025-10-17T21:26:05.499Z
dppcr.cz favicon

Povodňový plán České republiky

dppcr.cz

50
GovernmentCzech RepublicmediumMEDIUM

The website dppcr.cz serves as the official digital flood plan portal for the Czech Republic, providing comprehensive flood-related information, meteorological data, flood commission activities, and thematic maps. It targets government agencies, emergency responders, and public stakeholders involved in flood management. The site is well-structured with clear navigation and integrates links to national and European meteorological services, positioning itself as a key resource in national flood preparedness and response. Technically, the site uses standard web technologies including HTML5, CSS3, JavaScript with jQuery, and Google Fonts. It employs HTTPS and Google Analytics for tracking, though lacks advanced security headers and cookie consent mechanisms. Mobile optimization is basic but functional, and accessibility features are minimal. The hosting and domain registration are consistent with a Czech government entity, enhancing trustworthiness. From a security perspective, the site benefits from HTTPS and absence of visible vulnerabilities or sensitive data exposure. However, it lacks explicit privacy and cookie policies, security headers, and incident response contact information, which are important for compliance and user trust. The use of Google Analytics without consent mechanisms may pose privacy compliance risks under GDPR. Overall, the website is a credible and authoritative government resource with good content quality and business credibility. To improve, it should implement privacy and cookie policies with consent, enhance security headers, and provide clear contact information for security and data protection matters. These steps will strengthen compliance, user trust, and security posture.

15
10
2
60
62
75
100
governmentfloodemergencyczechrepublichydrology+2 more
HTML5CSS3JavaScriptjQuery+2
2025-10-17T21:25:45.428Z
valachnet.cz favicon

TKR Jašek s.r.o.

valachnet.cz

53
TelecommunicationsCzech RepublicsmallMEDIUM

TKR Jašek s.r.o. operates the VALACHNET.cz portal, providing regional telecommunications services including internet, television, telephone, mobile, and hosting primarily in the Valašsko region of the Czech Republic. The company has a long-standing presence since 1990 and targets residential and business customers within its service area. The website reflects a regional ISP with a focus on customer engagement and service announcements. Technically, the website uses a traditional tech stack with jQuery and jQuery UI libraries, serving content over HTTPS. While the site is functional and content-rich, it lacks advanced security headers and modern privacy compliance features such as a cookie consent mechanism. The site is moderately optimized for performance and accessibility but could benefit from modernization. Security posture is adequate with HTTPS enabled and no visible sensitive data exposure, but the absence of security headers and vulnerability disclosures indicates room for improvement. The lack of WHOIS data reduces domain trustworthiness, though the website content and business information appear consistent and legitimate. Overall, the site presents a trustworthy regional ISP with good business credibility but requires enhancements in security best practices and privacy compliance to align with modern standards.

35
25
2
60
65
65
100
ispinternettelevisiontelephonehosting+3 more
jQueryjQuery UIJavaScriptCSS+1

Partner Domains:

tka.cz
partner
fixpro.cz
partner

+2 more partners

2025-10-17T21:25:20.287Z
gopay.com favicon

GoPay s.r.o.

gopay.com

71
FinanceCzech RepublicmediumMEDIUM

GoPay s.r.o. operates a professional payment gateway service targeting merchants and e-commerce businesses primarily in the Czech Republic and surrounding European markets. The company offers a comprehensive payment solution with over 80 features including support for Apple Pay, Google Pay, multiple currencies, and localized payment experiences in 19 languages. The website reflects a mature business with over 18,000 merchants and more than 10 years of operational history, positioning GoPay as a trusted player in the payment processing industry. Technically, the website is built with modern web technologies including HTML5 video, JavaScript, and CSS3, and integrates Google Tag Manager for analytics and marketing. The site is hosted on Amazon Web Services, indicating a robust infrastructure. The website is mobile optimized, fast loading, and includes cookie consent mechanisms compliant with GDPR, reflecting a high level of digital maturity. From a security perspective, the site enforces HTTPS and PCI DSS certification is prominently displayed, indicating adherence to industry security standards. However, the absence of explicit security headers and a published security policy or incident response contact represents areas for improvement. No vulnerabilities or exposed sensitive data were detected in the content. Overall, the website is professional, trustworthy, and compliant with privacy regulations, but the lack of WHOIS domain registration data raises concerns about domain legitimacy. Strategic recommendations include publishing a security policy, adding security headers, and clarifying domain registration details to enhance trust and security posture.

95
65
17
70
77
65
100
paymentgatewaye-commercefinancetechnologypcidss+3 more
JavaScriptGoogle Tag ManagerVideo HTML5CSS3+2

Partner Domains:

demo.gopay.com
service
auth.gopay.com
service

+3 more partners

2025-10-17T21:24:40.158Z
wpdownloadmanager.com favicon

WordPress Download Manager

wpdownloadmanager.com

48
TechnologyN/amediumHIGH

WordPress Download Manager is a well-established WordPress plugin provider specializing in file and document management as well as digital product e-commerce solutions. The company, operating under W3 Eden, Inc., offers a comprehensive suite of features including membership management, access control, and multiple payment gateway integrations. With over 10 million downloads, it holds a strong market position within the WordPress ecosystem, targeting site owners and developers who require robust digital asset management and sales capabilities. The website is professionally designed, mobile-optimized, and provides extensive documentation and support channels, enhancing user experience and trust. Technically, the site leverages WordPress CMS with modern technologies such as Bootstrap, jQuery, and CDN hosting via Cloudfront for performance optimization. Integration with Google Analytics and payment APIs like Stripe and PayPal indicates a mature digital infrastructure. Security practices include HTTPS enforcement, password protection, and social lock features, although explicit security headers and incident response policies are not prominently documented. The security posture is solid with no evident vulnerabilities or exposed sensitive data, but the lack of WHOIS transparency for the domain raises some concerns about registration legitimacy. Privacy and cookie policies are present and GDPR compliant, reflecting good privacy practices. Overall, the site demonstrates a high level of professionalism and technical maturity, though improvements in domain registration transparency and security policy visibility are recommended. Strategically, the company should focus on enhancing domain registration transparency, formalizing security incident response procedures, and publishing a vulnerability disclosure policy to strengthen trust and compliance. Continuous monitoring of third-party scripts and security headers will further improve the security posture and user confidence.

20
35
2
80
62
80
20
wordpressdownloadmanagerdigitalproductse-commercefilemanagement+2 more
WordPressPHPJavaScriptBootstrap+4

Partner Domains:

wpliveforms.com
partner
wpattire.com
partner
2025-10-17T21:24:05.074Z
aumovio.com favicon

AUMOVIO SE

aumovio.com

63
TransportationN/alargeMEDIUM

AUMOVIO SE is a technology-driven company specializing in future mobility solutions, focusing on software-defined vehicles, electric mobility, vehicle electrical/electronic architectures, safety, driver assistance, user experience, and cybersecurity. The company has a strong market position supported by a diverse portfolio of products and services and is publicly listed on the Frankfurt Stock Exchange since September 2025. The website reflects a mature digital presence with comprehensive corporate governance and investor relations information, targeting automotive industry professionals, investors, and potential employees. Technically, the website employs modern web technologies including Adobe Experience Manager components, Google Tag Manager, and consent management tools, ensuring good performance, mobile optimization, and accessibility. The site uses HTTPS and includes privacy and cookie policies with consent mechanisms, indicating compliance with GDPR and related regulations. From a security perspective, while HTTPS and consent management are in place, the absence of visible security headers and incident response information suggests room for improvement. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data is missing or unavailable, which raises some concerns about domain registration transparency, though the professional site and corporate disclosures mitigate this risk. Overall, the website presents a professional, trustworthy, and well-maintained digital front for AUMOVIO SE, with recommendations to enhance security headers, publish incident response policies, and clarify domain registration details to strengthen trust and compliance.

55
50
47
85
-
85
100
automotivemobilitytechnologysoftwareelectricvehicles+5 more
JavaScriptAdobe Helix RUMGoogle Tag ManagerLinkedIn Insight Tag+1

Partner Domains:

www.continental-aftermarket.com
partner
engineering-solutions.aumovio.com
subsidiary

+3 more partners

2025-10-17T20:22:56.834Z
mayfieldfoundation.org favicon

Mayfield Education & Research Foundation

mayfieldfoundation.org

52
HealthcareUnited StatessmallMEDIUM

The Mayfield Education & Research Foundation is a specialized non-profit organization focused on advancing care for patients with brain and spine disorders through education and research. Established in 2011 and based in Cincinnati, Ohio, the foundation offers educational programs, supports research initiatives, and engages donors to further its mission. The website reflects a professional and consistent brand presence targeting patients, medical professionals, researchers, and donors. Technically, the website employs a modern tech stack including Bootstrap 4.3.1, jQuery, and Google Tag Manager for analytics. The site is mobile-optimized with good SEO practices and clear navigation, though accessibility features are basic. Hosting details are not explicit but DNS is managed via Register.com. Performance is moderate with no critical technical issues detected. From a security perspective, the site uses HTTPS and Google Tag Manager but lacks DNSSEC and visible security headers such as CSP or HSTS. No privacy or cookie policies are present, indicating compliance gaps with GDPR and related regulations. No forms or data collection fields are detected on the main page, reducing immediate risk exposure. WHOIS data aligns well with the website's claims, supporting legitimacy. Overall, the site is trustworthy and professional but would benefit from enhanced security headers, DNSSEC implementation, and explicit privacy and cookie policies to improve compliance and user trust.

65
35
2
70
77
70
20
non-profithealthcareeducationresearchbrain+2 more
HTML5CSS3JavaScriptjQuery 3.4.1+2
2025-10-17T20:22:16.691Z
megeve-booking.com favicon

Mairie de Megève

megeve-booking.com

61
HospitalityFrancemediumMEDIUM

The website megeve-booking.com serves as the official online booking platform for the Megève tourism office, specializing in accommodation and activity reservations in the Megève ski resort area in Haute-Savoie, France. It targets tourists and visitors seeking a seamless booking experience for hotels, chalets, and local activities. The platform is positioned as a trusted and official channel supported by the local municipality (Mairie de Megève), enhancing its credibility and market presence. Technically, the site employs modern web technologies including JavaScript frameworks, lazy loading for images, and integrates Google Tag Manager and Cookiebot for analytics and privacy compliance. The platform is hosted under a stable domain registered in 2021 with a 5-year validity period. The website is mobile-optimized and SEO-friendly, providing a good user experience with clear navigation and professional design. From a security perspective, the site uses HTTPS with a good SSL configuration and implements cookie consent mechanisms. However, it lacks DNSSEC and explicit security headers, and no dedicated security policy or incident response contact is published. No vulnerabilities or exposed sensitive data were detected in the analysis. Overall, the security posture is solid but could be improved with additional security best practices. The overall risk assessment is low, with no signs of malicious activity or suspicious content. The site complies with GDPR requirements, providing privacy and cookie policies, and offers clear contact information. Strategic recommendations include enabling DNSSEC, adding security headers, publishing a security policy, and considering a security.txt file to enhance transparency and trust.

75
50
2
40
82
60
100
tourismbookingskimegvefrance+3 more
JavaScriptGoogle Tag ManagerCookiebotReact (implied by react-select input)+1
2025-10-17T20:19:50.292Z
spin-on.fr favicon

Spin On

spin-on.fr

61
TechnologyFrancesmallMEDIUM

Spin On is a small, professional web agency based in Besançon, France, specializing in the creation of websites, e-commerce platforms, mobile applications, and custom software development. The company has been operating since 2013 and serves primarily local and regional businesses. Their website demonstrates a solid digital presence with a focus on GDPR compliance and user privacy, evidenced by the integration of Cookiebot for cookie consent management. The agency leverages modern web technologies and frameworks such as WordPress, Drupal, Prestashop, and Laravel to deliver tailored solutions to clients. Technically, the website employs a modern tech stack including JavaScript libraries like jQuery, TweenMax, and Rellax for enhanced user experience and performance optimizations such as lazy loading. Hosting is provided via DigitalOcean, a reputable cloud provider, ensuring reliable infrastructure. The site is mobile-optimized and SEO-friendly, although accessibility features are basic and could be improved. From a security perspective, the site uses HTTPS and implements a comprehensive cookie consent mechanism, but lacks explicit security headers and documented security policies. No vulnerabilities or exposed sensitive data were detected in the provided content. The use of Facebook Pixel and Google Analytics indicates moderate user tracking, balanced with GDPR compliance. Overall, Spin On presents a trustworthy and professional digital footprint with room for improvement in security hardening and accessibility. The domain registration data aligns well with the business profile, supporting legitimacy. Strategic recommendations include enhancing security headers, publishing security and incident response policies, and improving accessibility compliance to strengthen trust and compliance posture.

15
83
2
85
62
60
100
webagencywebdevelopmentecommercecustomapplicationsgdpr+2 more
HTML5CSS3JavaScriptjQuery+5
2025-10-17T20:19:30.227Z
alidns.com favicon

Alibaba Cloud Computing (Beijing) Co., Ltd.

alidns.com

59
TechnologyChinaenterpriseMEDIUM

Alibaba Cloud Computing (Beijing) Co., Ltd. operates the alidns.com website, providing global public recursive DNS services as part of Alibaba Cloud's internet infrastructure offerings. The website positions itself as a reliable, fast, and secure DNS service provider, targeting both general internet users and enterprise customers. The business is well-established, with a domain age of over 15 years and strong brand association with Alibaba Group. Key services include public DNS resolution, cloud DNS authoritative services, and support for modern DNS security protocols such as DoH and DoT. Technically, the website employs modern JavaScript frameworks and Alibaba's proprietary analytics tools, ensuring good performance and mobile optimization. The hosting is managed by Alibaba Cloud, ensuring robust infrastructure and fast content delivery. However, the site lacks explicit privacy and cookie policies, which is a gap in compliance and user transparency. From a security perspective, the site uses HTTPS and modern tracking scripts but does not disclose security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the content. The WHOIS data confirms the domain's legitimacy and consistency with the business entity. Overall, the website is professional and trustworthy but would benefit from enhanced privacy compliance and explicit security disclosures to improve user trust and regulatory adherence.

65
50
2
40
57
80
100
dnspublicdnsalibabacloudcloudservicesinternetinfrastructure+3 more
JavaScriptReact (implied by JSX-like class names)Ant Design IconsAlibaba Cloud analytics scripts+2
2025-10-17T20:19:15.188Z
mfkkarvina.cz favicon

MFK Karviná a.s.

mfkkarvina.cz

40
OtherCzech RepublicsmallHIGH

MFK Karviná a.s. operates an official website for their football club, primarily targeting local football fans and sports enthusiasts in the Czech Republic. The site provides basic information about the club, ticket sales, and news updates. The business model is focused on sports club promotion and fan engagement within the regional football league context. The website is modest in content and design, reflecting a small-sized organization with limited digital maturity. Technically, the website uses basic JavaScript and CSS with legacy character encoding (windows-1250). There is no evidence of modern CMS or advanced frameworks. Mobile optimization and accessibility are basic, and no advanced SEO or analytics tools are detected. The site lacks HTTPS, security headers, and privacy compliance mechanisms, indicating a low level of security and privacy maturity. From a security perspective, the absence of HTTPS and security headers is a significant vulnerability. No privacy policy or cookie consent mechanisms are present, which may expose the organization to GDPR compliance risks. The lack of contact information and incident response details further weakens the security posture. However, no malicious or adult content is detected, and the site is accessible without WAF or blocking mechanisms. Overall, the website presents moderate trustworthiness based on content alignment with the football club's identity but suffers from critical security and privacy shortcomings. Strategic improvements in HTTPS implementation, privacy compliance, and security best practices are recommended to enhance trust and protect user data.

15
25
2
70
85
60
20
footballsportsczechrepublicmfkkarvin2liga
JavaScriptCSS
2025-10-17T20:18:55.089Z
fkjablonec.cz favicon

Fotbalový Klub Jablonec a.s.

fkjablonec.cz

47
MediaCzech RepublicmediumHIGH

FK Jablonec is a well-established Czech football club with a strong digital presence through its official website. The site serves as a comprehensive platform for fans and stakeholders, offering news, match information, player statistics, ticketing details, and a merchandise e-shop. The club maintains active engagement with its audience via multiple social media channels and partners with various sponsors and organizations, reflecting a solid market position within Czech football. The website's design is professional and consistent with the club's branding, targeting football enthusiasts and the local community. Technically, the site employs modern web technologies including JavaScript, Google Tag Manager, and custom CSS, hosted on a Czech hosting provider, ensuring moderate performance and good mobile optimization. Security-wise, the site uses HTTPS and implements a detailed cookie consent mechanism aligned with GDPR requirements, though it lacks explicit security headers and incident response contact information. Overall, FK Jablonec's website demonstrates a mature digital infrastructure with room for enhanced security practices and transparency. Strategic recommendations include adding security headers, publishing a security.txt file, and providing clearer contact information for privacy and incident response. These improvements would strengthen the club's trustworthiness and compliance posture while maintaining its strong fan engagement and business credibility.

20
40
2
70
62
80
20
footballsportsclubczechrepublicfkjablonec+4 more
JavaScriptGoogle Tag ManagerFontFaceObserverCSS3+1

Partner Domains:

fanshop.fkjablonec.cz
partner
esports.cz
partner

+2 more partners

2025-10-17T20:18:40.032Z
fchk.cz favicon

FC Hradec Králové, a.s.

fchk.cz

53
OtherCzech RepublicmediumMEDIUM

FC Hradec Králové, a.s. operates an official website serving as the primary digital platform for the Czech football club FC Hradec Králové. The site provides comprehensive information including match schedules, team rosters, news updates, ticketing services, and a fanshop for merchandise. The club has a strong market presence in Czech football, with a history dating back over 120 years, positioning itself as a well-established sports entity. The website targets football fans, local community members, and sports enthusiasts, offering a user-friendly and content-rich experience. Technically, the website employs modern JavaScript libraries such as GSAP and Swiper.js for animations and interactive elements, alongside Google Analytics and Facebook Pixel for analytics and marketing. The site is mobile-optimized, accessible, and SEO-friendly, hosted under a Czech registrar with consistent domain registration data. Cookie consent mechanisms and GDPR compliance are well implemented, reflecting a mature approach to privacy and user data protection. From a security perspective, the website enforces HTTPS and uses cookie consent categories to manage tracking scripts responsibly. While explicit security headers are not fully confirmed, no critical vulnerabilities or exposed sensitive data were detected. The absence of a public security policy or incident response contact suggests room for improvement in transparency and readiness. Overall, the website demonstrates a high level of professionalism, content quality, and trustworthiness, with a strong alignment between domain registration and business identity. Strategic recommendations include enhancing security header implementation, publishing a security policy, and establishing a vulnerability disclosure process to further strengthen the security posture.

20
40
2
100
72
85
20
sportsfootballclubczechrepublicfanengagement+4 more
GSAPSwiper.jsGoogle AnalyticsSeznam retargeting+4

Partner Domains:

fchk.enigoo.cz
partner
www.jakojedenteam.cz
partner

+3 more partners

2025-10-17T20:18:19.974Z
fcslovacko.cz favicon

1.FC Slovácko, a. S.

fcslovacko.cz

53
OtherCzech RepublicmediumMEDIUM

1.FC Slovácko, a. S. is a professional football club based in the Czech Republic, operating an official website that serves as a hub for club information, match results, team rosters, and fan engagement. The website targets football fans and the local community, providing news, multimedia content, and links to social media and a fanshop. The club competes in the top Czech football league, positioning itself as a recognized sports entity in the region. The website infrastructure utilizes modern web technologies including JavaScript, Google Tag Manager, YouTube Player API, and the Nette Framework. It demonstrates good mobile optimization and responsive design, with a moderate performance profile. The site is hosted securely with HTTPS and integrates external content and partner links effectively, though some technical improvements in security headers and privacy disclosures are recommended. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks explicit security headers and formal privacy or cookie policies, which are important for compliance and user trust. No vulnerabilities or suspicious content were detected. The absence of WHOIS data limits domain registration insights but the overall digital presence and partner ecosystem support legitimacy. Overall, the website is professional and trustworthy, with room for enhancement in privacy compliance and security best practices. Strategic improvements in these areas will strengthen user confidence and regulatory adherence.

100
25
2
55
62
80
20
sportsfootballclubczechrepublicsoccer+3 more
JavaScriptYouTube Player APIGoogle Tag ManagerNette Framework (netteForms.min.js)+3

Partner Domains:

fanshop.fcslovacko.cz
partner
www.zgroup.cz
partner

+3 more partners

2025-10-17T20:17:59.923Z
fanshopfcb.cz favicon

FANSHOP

fanshopfcb.cz

57
RetailCzech RepublicsmallMEDIUM

The website fanshopfcb.cz operates as an e-commerce platform specializing in fan merchandise for FC Baník Ostrava, offering a variety of products including clothing, accessories, and wines. The site targets fans of the football club and general sports merchandise buyers primarily in the Czech Republic. The business model is focused on online retail with a niche market position serving regional fan communities. Technically, the website employs a mix of JavaScript libraries such as jQuery and Swiper.js, integrates Google Analytics for tracking, and uses external services like Mapy.cz API and Packeta for shipping. The platform appears to be built on a proprietary or custom CMS (likely K2). The site is mobile optimized with moderate performance and basic SEO and accessibility features. From a security perspective, the site enforces HTTPS and uses secure login forms but lacks visible security headers and comprehensive privacy or terms of service documentation. No WHOIS data is available, which raises concerns about domain registration transparency. The site includes cookie consent mechanisms but does not provide explicit privacy policy details, impacting privacy compliance. Overall, the website presents a functional and professional e-commerce presence with room for improvement in security best practices, privacy transparency, and domain registration legitimacy. Strategic recommendations include implementing security headers, publishing privacy and terms policies, and verifying domain registration details to enhance trust and compliance.

45
25
2
70
72
75
100
e-commercefanmerchandisesportsfcbankostravaretail+1 more
JavaScriptjQuery 3.2.1Swiper.jsGoogle Tag Manager+2
2025-10-17T20:17:54.907Z
mestokladno.cz favicon

Statutární město Kladno

mestokladno.cz

52
GovernmentCzech RepublicmediumMEDIUM

The website mestokladno.cz serves as the official online portal for the statutory city of Kladno in the Czech Republic. It provides residents and visitors with comprehensive municipal information including news, events, administrative services, and contact details. The site is positioned as a trusted government resource with a clear focus on public service delivery and community engagement. The target audience primarily consists of local citizens and stakeholders interested in city governance and services. From a technical perspective, the website employs a proprietary CMS platform (Vismo) and integrates modern web technologies such as HTML5, CSS, JavaScript, and Google Analytics for performance monitoring. The site is mobile-optimized and accessible, with a clear navigation structure and compliance with privacy regulations including GDPR. Cookie consent mechanisms are implemented effectively, enhancing user privacy. Security-wise, the site benefits from HTTPS encryption and does not expose sensitive data or vulnerable libraries. However, it lacks explicit published security policies and incident response contacts, which are recommended for enhanced transparency and preparedness. No critical vulnerabilities or suspicious activities were detected. Overall, mestokladno.cz demonstrates a solid security posture and business credibility consistent with an official municipal website. Strategic improvements in security policy publication and incident response readiness would further strengthen its trustworthiness and compliance profile.

55
25
17
85
75
55
20
governmentmunicipalcityczechrepublicpublicservices+3 more
HTML5CSSJavaScriptGoogle Analytics+1
2025-10-17T20:17:34.857Z
vilgain.ch favicon

Vilgain

vilgain.ch

72
E-commerceSwitzerlandmediumMEDIUM

Vilgain is a Swiss-based e-commerce company specializing in sports nutrition, functional foods, supplements, cosmetics, and related wellness products. The website targets health-conscious consumers primarily in the DACH region and Switzerland, offering a broad product catalog with multiple localized domains to serve various European markets. The business model focuses on direct online retail with value-added content such as expert articles and recipes, supported by strong customer trust signals including a Trusted Shops certification and a 100% money-back guarantee. Technically, the website employs modern JavaScript frameworks, lazy loading, responsive design, and integrates error monitoring via Sentry and analytics through Google Tag Manager. The site is well-optimized for mobile devices and SEO, though some accessibility features are basic. Security posture is solid with HTTPS enforced and nonce attributes for scripts, but lacks explicit security headers and published security policies. From a security and compliance perspective, the site does not expose sensitive data or vulnerable libraries in the analyzed content. However, it lacks visible privacy and cookie policies, consent mechanisms, and incident response or vulnerability disclosure information, which are critical for GDPR compliance and user trust. No contact emails or phone numbers were found in the provided HTML, limiting direct communication channels. Overall, Vilgain presents a professional and trustworthy e-commerce platform with good technical infrastructure and strong business credibility. To enhance security and compliance, it should publish comprehensive privacy and cookie policies, implement consent mechanisms, and provide clear contact information and security incident procedures.

80
73
17
70
77
75
100
sportsnutritionsupplementsfunctionalfoodse-commercehealth+3 more
JavaScriptSentry (error monitoring)Google Tag ManagerLazy loading images+1

Partner Domains:

vilgain.com
sister
vilgain.de
sister

+3 more partners

2025-10-17T20:16:09.535Z
vilgain.co.uk favicon

Vilgain

vilgain.co.uk

73
RetailUnited KingdommediumMEDIUM

Vilgain is a UK-based e-commerce business specializing in sports nutrition, functional foods, sportswear, and fitness equipment. The company targets athletes and health-conscious consumers, offering a range of products designed to improve athletic performance and overall health. The website is professionally designed with consistent branding and clear navigation, supporting a positive user experience. The business has a moderate market position with a focus on quality and customer satisfaction, as evidenced by trust signals such as a money-back guarantee and positive reviews on Trustpilot. Technically, the website employs modern web technologies including JavaScript, Sentry for error tracking, and Google Tag Manager for analytics and marketing. The site is mobile-optimized and uses HTTPS with a good SSL configuration, though it lacks some advanced security headers. Performance is moderate, and SEO practices are adequately implemented. Privacy compliance is weak due to the absence of explicit privacy and cookie policies and consent mechanisms. From a security perspective, the site benefits from HTTPS and nonce attributes on scripts, reducing risks of injection attacks. However, the lack of security headers and formal incident response or vulnerability disclosure policies indicates room for improvement. No critical vulnerabilities or suspicious patterns were detected. The domain registration is consistent and appropriate for the business age and scope. Overall, Vilgain presents a trustworthy and professional e-commerce platform with good technical and security foundations but requires enhancements in privacy compliance and security best practices to further strengthen its posture.

80
73
17
85
77
75
100
sportsnutritionfunctionalfoodse-commercehealthsupplementsprotein+1 more
JavaScriptSentryGoogle Tag ManagerLazyLoad images+2

Partner Domains:

vilgain.com
sister
vilgain.de
sister

+3 more partners

2025-10-17T20:16:04.514Z
openweather.co.uk favicon

OpenWeather

openweather.co.uk

61
TechnologyUnited KingdomenterpriseMEDIUM

OpenWeather is a leading provider of global weather data and forecasting solutions tailored for businesses across multiple weather-sensitive industries. The company leverages AI-powered hyperlocal weather models to deliver high-resolution, real-time weather insights that help enterprises optimize operations, mitigate risks, and make informed decisions. With a strong market presence supported by over 7 million users worldwide and operations in more than 190 countries, OpenWeather positions itself as a trusted partner for industries such as energy, transportation, retail, agriculture, and emergency services. Technically, the website is built on a modern React and Next.js framework, ensuring fast performance, mobile optimization, and good SEO practices. The infrastructure supports high scalability with distributed data centers and efficient API delivery. The site integrates analytics and marketing tools like Google Tag Manager and Leadinfo for user tracking and engagement. From a security perspective, OpenWeather demonstrates a mature posture with HTTPS enforcement, ISO 27001 certification, and corporate security policies emphasizing confidentiality, integrity, and availability. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is well addressed with comprehensive privacy and cookie policies, including consent mechanisms aligned with GDPR requirements. Overall, OpenWeather presents a professional, trustworthy, and technically sound digital presence that supports its enterprise-grade weather data services. Strategic recommendations include enhancing incident response visibility and publishing a vulnerability disclosure policy to further strengthen security transparency and user trust.

20
73
37
85
72
70
40
weatherbusinessforecastaimeteorology+3 more
ReactNext.jsJavaScriptGoogle Tag Manager+2
2025-10-17T19:10:04.708Z
oiml.org favicon

International Organization of Legal Metrology

oiml.org

65
GovernmentFrancemediumMEDIUM

The International Organization of Legal Metrology (OIML) is a well-established international standard-setting body focused on legal metrology. It supports governments and regulatory bodies worldwide by developing standards, certification systems, and training to ensure measurement accuracy and consumer protection. The organization has a strong market position with over 130 members and a history dating back to 1955. The website reflects a professional, government/non-profit entity with clear content and consistent branding. Technically, the website is built on the Plone CMS platform, using modern web technologies such as HTML5, CSS, and JavaScript. It is mobile-optimized and accessible, with good SEO practices. The site uses HTTPS with excellent SSL configuration, though it lacks some security headers and cookie consent mechanisms. No analytics or tracking scripts were detected, indicating a privacy-conscious approach. From a security perspective, the site demonstrates good practices with no visible vulnerabilities or exposed sensitive data. However, the absence of a published security policy, incident response contacts, and vulnerability disclosure mechanisms are areas for improvement. The WHOIS data is unavailable due to malformed responses, which slightly reduces trust but is likely due to registry restrictions rather than malicious intent. Overall, the site is trustworthy, professional, and secure, serving its audience effectively. Strategic improvements in privacy compliance and security transparency would enhance its posture further.

45
53
17
70
77
80
100
legalmetrologystandardscertificationgovernmentnon-profit+1 more
Plone CMSFontAwesomeJavaScriptCSS+1
2025-10-17T19:09:34.500Z
adf.org.au favicon

Alcohol and Drug Foundation

adf.org.au

64
Non-profitAustralialargeMEDIUM

The Alcohol and Drug Foundation (ADF) is a well-established Australian non-profit organization dedicated to preventing and minimizing harm caused by alcohol and other drugs. Funded by the Australian government, ADF provides evidence-based programs, advocacy, education, and community support services nationwide. The website reflects a strong market position as a leading authority in alcohol and drug harm prevention in Australia, targeting the general public and affected communities with accessible, comprehensive resources and support tools. Technically, the website employs modern web technologies including Vue.js, Google Tag Manager, and multiple analytics and marketing integrations such as Facebook Pixel and Microsoft Clarity. Hosting is inferred to be on Amazon AWS infrastructure, and the site demonstrates good mobile optimization and accessibility features, including the ReciteMe accessibility toolbar. SEO practices are solid with proper metadata and structured data. From a security perspective, the site uses HTTPS with a good SSL configuration and domain registration protections that prevent unauthorized transfers or renewals. However, there is a lack of visible security headers and no published security or incident response policies. The absence of a cookie consent mechanism despite extensive tracking scripts is a privacy compliance gap. Overall, the security posture is good but could be improved with additional headers and transparency. The overall risk assessment is moderate-low risk with strong business credibility and technical maturity. Strategic recommendations include implementing cookie consent, publishing security policies, enabling DNSSEC, and adding security headers to enhance protection and compliance. These improvements will strengthen trust and reduce potential privacy and security risks.

40
53
10
85
72
70
100
alcoholanddrugfoundationpreventionprogramsdrugeducationharmreductionadvocacy+3 more
JavaScriptGoogle Tag ManagerFacebook PixelBing Ads+4

Partner Domains:

druginfo.com.au
partner
alcohol-and-drug-foundation-shop.myshopify.com
partner

+1 more partners

2025-10-17T19:09:19.398Z
chromatix.com.au favicon

Chromatix

chromatix.com.au

60
TechnologyAustraliasmallMEDIUM

Chromatix is a Melbourne-based web design and development company specializing in creating professional websites and digital solutions for businesses. The company targets local and Australian businesses seeking to establish or enhance their online presence with quality design and development services. The website reflects a professional brand image with consistent branding and good content quality, positioning Chromatix as a credible player in the local digital agency market. Technically, the website is built on WordPress with a custom child theme, leveraging modern web technologies including JavaScript and CSS. Google Tag Manager is integrated for analytics and marketing tracking. The site demonstrates good mobile optimization and moderate performance, though there is room for improvement in accessibility and SEO fine-tuning. From a security perspective, the site uses HTTPS with a good SSL configuration but lacks several important security headers. No explicit privacy or cookie policies were found, indicating compliance gaps with GDPR and other privacy regulations. No incident response or vulnerability disclosure information is provided, which could be improved to enhance trust and security posture. Overall, the website is safe and professional, with no signs of malicious content or blocking by WAFs. The domain WHOIS data is limited due to .au domain privacy policies but shows no suspicious patterns. Strategic recommendations include adding comprehensive privacy and cookie policies, implementing security headers, and publishing incident response details to strengthen compliance and security maturity.

15
70
17
80
52
70
100
webdesignwebdevelopmentmelbournedigitalagencytechnology
JavaScriptCSSHTML5Google Tag Manager
2025-10-17T19:07:33.892Z