Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 203 of 408|Showing 10101-10150 of 20393
L

lojban.io

lojban.io

49
EducationIcelandsmallHIGH

lojban.io is a specialized educational platform dedicated to the study and promotion of the constructed language Lojban. It offers free and open-source resources including courses, learning decks, and community engagement via a Discord server. The website targets language enthusiasts and learners interested in logical and constructed languages, positioning itself as a niche educational resource with a small but active user base. The platform is relatively young, established in 2020, and maintains a consistent brand and content quality with regular updates and community involvement. Technically, the website employs modern web technologies such as Bootstrap for styling, Font Awesome for icons, and integrates Google Analytics and Tag Manager for user tracking. It also supports Progressive Web App features, enhancing user experience across devices. Hosting and DNS services are managed via Cloudflare, providing performance and security benefits. The site demonstrates moderate performance and good mobile optimization but lacks some advanced accessibility features. From a security perspective, the site uses HTTPS with a good SSL configuration and has domain transfer protections in place. However, it lacks DNSSEC and important security headers like Content-Security-Policy and X-Frame-Options, which are recommended to enhance security posture. Privacy compliance is limited due to the absence of privacy and cookie policies, which is a notable gap given the use of tracking technologies. No incident response or vulnerability disclosure mechanisms are present. Overall, lojban.io presents a trustworthy and professional educational resource with a solid technical foundation but would benefit from improved privacy compliance and enhanced security headers. Strategic recommendations include implementing privacy and cookie policies, enabling DNSSEC, adding security headers, and establishing a vulnerability disclosure process to strengthen trust and compliance.

30
35
17
70
52
70
40
educationlanguagelojbanconstructedlanguageopensource+1 more
HTML5CSS (Bootstrap)JavaScriptGoogle Analytics+3
2025-07-27T19:50:21.433Z
liputenpo.org favicon

lipu tenpo

liputenpo.org

56
Non-profitGermanysmallMEDIUM

lipu tenpo is a registered association based in Germany that provides a cultural and educational platform primarily in the Toki Pona language. The website hosts a collection of articles and multimedia content licensed under CC BY-SA 4.0, targeting a general audience interested in this niche language and culture. The organization engages its community through Discord, Patreon, and Linktree, indicating active outreach and support mechanisms. The domain was registered in 2021, consistent with the association's founding timeline. Technically, the website is built with standard HTML5 and CSS3, utilizing Google Fonts and GoatCounter for lightweight, privacy-conscious analytics. The hosting is managed via Name.com, with no CMS or major frameworks detected, suggesting a custom or static site approach. The site is mobile-optimized with good navigation and SEO practices, though accessibility features are basic. Performance is moderate, with no blocking or WAF detected. From a security perspective, the site uses HTTPS and has domain transfer protections enabled, but lacks DNSSEC and security headers such as Content-Security-Policy or X-Frame-Options. There is no visible privacy or cookie policy, nor incident response or vulnerability disclosure information, which are areas for improvement. No sensitive data exposure or vulnerabilities were detected in the content. Overall, the security posture is moderate but could be enhanced with standard best practices. The overall risk assessment is low to moderate, with no critical issues found. Strategic recommendations include implementing DNSSEC, adding security headers, publishing privacy and cookie policies, and providing incident response contacts to improve compliance and trust. The site is trustworthy for its intended educational and cultural purpose but would benefit from enhanced security and privacy transparency.

15
35
2
60
95
70
100
educationculturenon-profittokiponacommunity
HTML5CSS3Google FontsGoatCounter analytics
2025-07-27T19:50:06.230Z
L

LIPUmanka

lipamanka.gay

56
OtherIcelandsmallMEDIUM

The website 'lipamanka.gay' is a personal site primarily focused on sharing essays, stories, and linguistic resources related to the creator's interests. It is a small-scale, niche site without commercial intent or business contact information. The site is hosted likely on GitHub Pages with domain registration through NameCheap, protected by privacy services. The technical infrastructure is basic, relying on standard HTML, CSS, and JavaScript, with minimal external dependencies. Analytics are implemented via GoatCounter, providing lightweight user tracking without aggressive data collection. From a security perspective, the site uses HTTPS and has domain transfer protection enabled, but lacks DNSSEC and security headers, which could be improved to enhance security posture. There are no privacy or cookie policies, nor terms of service, which limits compliance with GDPR and other privacy regulations. No contact or incident response information is provided, reducing transparency and trustworthiness from a security standpoint. Overall, the site is safe for general audiences, containing no adult or explicit content. The domain registration is recent and privacy protected, appropriate for a personal website. The lack of business information and policies limits the site's credibility and compliance maturity. Strategic improvements in security headers, privacy disclosures, and contact transparency would enhance trust and compliance.

15
40
2
70
95
70
100
personallinguisticsessaysstoriestokipona
HTML5CSSJavaScript
2025-07-27T19:49:51.004Z
A

Anna Kudriavtsev

ap5.dev

59
TechnologyN/asmallMEDIUM

The website ap5.dev is a personal professional portfolio and blog belonging to Anna Kudriavtsev, focusing on computing systems design and software development with an emphasis on correctness and maintainability. The site positions itself as a personal brand rather than a commercial business, targeting a general audience interested in technology and software development. The business model is primarily informational and portfolio-based, with links to a resume and GitHub repository. Technically, the website uses standard modern web technologies including HTML5, CSS3, and JavaScript, with external resources such as Google Fonts and a chat widget from cactus.chat. The site is moderately optimized for mobile and SEO, with good design quality and clear navigation. However, no CMS or hosting provider details are evident, and performance is moderate. From a security perspective, the site uses HTTPS and does not expose forms or sensitive data, but lacks explicit security headers and formal privacy or cookie policies. No vulnerability disclosure or incident response information is provided. The domain registration is privacy protected, which is appropriate for a personal site. Overall, the security posture is adequate but could be improved with additional headers and compliance documentation. The overall risk is low given the nature of the site, but strategic recommendations include implementing privacy and cookie policies, adding security headers, and providing vulnerability disclosure information to enhance trust and compliance.

15
35
2
70
95
80
100
personalportfoliotechnologyblogprofessional
HTML5CSS3JavaScript
2025-07-27T19:49:45.994Z
P

Pontus Henriksson

pontushenriksson.com

55
TechnologyN/asmallMEDIUM

The website pontushenriksson.com represents a personal portfolio for an individual web developer and programmer named Pontus Henriksson. The site is currently under development with a legacy site linked for reference. The business model is focused on showcasing skills and previous work to attract freelance or contract opportunities. The target audience includes potential clients or employers seeking web development and design services. The website is hosted on Cloudflare Pages and uses basic modern web technologies such as HTML5, CSS3, and JavaScript. The design is responsive and user-friendly, though content is minimal and lacks comprehensive business or contact information. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and security headers, which are recommended to enhance protection. No privacy, cookie, or terms of service policies are present, indicating limited compliance with GDPR or other privacy regulations. No contact emails, phone numbers, or social media links are provided, reducing business credibility and user trust. Analytics are implemented via Cloudflare Pages Analytics with minimal user tracking. Overall, the website is safe with no adult or questionable content detected. The domain registration is consistent with the website's new status and shows no suspicious patterns. The security posture is moderate but can be improved by adding security headers and privacy policies. The site’s technical implementation is adequate for a personal portfolio but lacks advanced SEO and accessibility features. Strategic recommendations include implementing privacy and cookie policies, adding security headers, providing clear contact information, enabling DNSSEC, and enhancing SEO and accessibility to improve user trust and compliance.

40
50
2
40
75
70
100
portfoliowebdeveloperprogrammerpersonalwebsitecloudflare
HTML5CSS3JavaScript
2025-07-27T19:45:11.043Z
is-a.dev favicon

is-a.dev - Free subdomains for developers

is-a.dev

61
TechnologyN/asmallMEDIUM

The website is-a.dev offers a free subdomain registration service targeted primarily at developers. It enables users to obtain free `.is-a.dev` subdomains by following instructions hosted on a GitHub repository. The service is positioned as a niche developer tool with a small-scale operation founded in 2020. The website content is clear, relevant, and professionally presented with consistent branding and a focus on developer engagement through GitHub and Discord communities. From a technical perspective, the site uses modern web technologies including HTML5, CSS3, JavaScript, and is hosted behind Cloudflare, ensuring fast performance and good mobile optimization. The presence of Carbon Ads and Cloudflare Insights indicates minimal advertising and analytics usage, with a low level of user tracking. SEO and accessibility are adequately addressed, though accessibility is basic. Security posture is solid with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. However, the site lacks explicit security headers and formal privacy or cookie policies, which are important for compliance and trust. Incident response is partially addressed via a GitHub abuse reporting mechanism, but no dedicated security contact or vulnerability disclosure policy is present. Overall, the website is trustworthy and functional with a good balance of usability and security for its scope. The main risks relate to privacy compliance and formal security governance, which could be improved to enhance user trust and regulatory adherence.

25
50
2
70
75
85
100
developersubdomainfreegithubcloudflare+1 more
HTML5CSS3JavaScriptCloudflare+1
2025-07-27T19:44:35.831Z
refact0r.dev favicon

refact0r

refact0r.dev

58
TechnologyN/asmallMEDIUM

The website refact0r.dev is a personal portfolio and blog belonging to a student interested in computer science, web development, and design. It serves as a platform to showcase projects, share blog content, and present personal interests. The site is built using modern web technologies including SvelteKit, and it demonstrates good design quality, mobile optimization, and user experience. However, it lacks formal business information, contact details, and compliance documentation such as privacy or cookie policies. From a technical perspective, the site uses a modern JavaScript framework (SvelteKit) and includes minimal analytics via umami, indicating a lightweight and privacy-conscious approach. The performance appears fast, and the site is mobile responsive. However, no security headers were detected in the provided data, and there is no evidence of HTTPS enforcement or advanced security practices. Security posture is moderate but could be improved by implementing standard security headers, privacy policies, and incident response information. The absence of contact information and compliance documents reduces trust and business credibility. No vulnerabilities or suspicious content were detected, and the domain registration uses privacy protection, which is appropriate for a personal site. Overall, the site is a well-designed personal portfolio with room for improvement in security, privacy compliance, and business transparency. Strategic recommendations include adding privacy and cookie policies, implementing security headers, providing contact information, and considering a vulnerability disclosure policy to enhance trust and compliance.

30
50
2
60
75
75
100
portfolioblogpersonaltechnologystudent
HTML5CSS3JavaScriptSvelteKit
2025-07-27T19:44:15.778Z
O

Offenciv Security

terminaate.site

51
TechnologyRussiasmallMEDIUM

The website terminaate.site is a personal portfolio of a young web developer from Russia specializing in React and Next.js, with interests in backend and DevOps. The site serves as a showcase of skills and projects, targeting potential collaborators or clients interested in modern web development technologies. The technical infrastructure is modern, leveraging popular JavaScript frameworks, bundlers, and backend tools, hosted with Cloudflare DNS and employing HTTPS. The site is well-designed with good navigation and mobile optimization, though it lacks formal privacy and cookie policies, as well as contact information, which limits its professional completeness. From a security perspective, the site uses HTTPS and modern frameworks but lacks security headers and formal security policies. The WHOIS data raises concerns due to an inconsistent domain creation date set in the future and a registrant organization name that does not clearly align with the personal portfolio branding. No WAF or blocking mechanisms are detected, and the site includes minimal user tracking via Umami analytics. Overall, the security posture is moderate but could be improved with better compliance and security practices. The overall risk is moderate with no critical vulnerabilities detected, but the lack of privacy compliance and contact information, combined with suspicious WHOIS data, suggests caution. Strategic improvements in security headers, privacy policies, and domain registration accuracy are recommended to enhance trust and compliance.

30
35
2
40
72
60
100
terminaateterminatereactreactjstermi+10 more
JavaScriptTypeScriptHTML5CSS3+16
2025-07-27T19:43:30.288Z
A

meowem weowe me oe wmewoe mweweowemweowmewoewme ewemweowmewoemw eo wemwemwmemwmewoewmem wmewoewmewoemw eowmemweowemweow memwemw memwm ewoewmem weowme woemweowme woewo emwme mwem wmemmewoe meow emwo emweo wmewoe mweowme wemwewoemweo mmewow memwowem weowmewoeweow memwemwmewo me mwmewmeo

aprl.cat

58
TechnologyUnited KingdomsmallMEDIUM

The website aprl.cat is a personal site belonging to an individual named April, a 20-year-old from the UK with interests in programming, music, skateboarding, and cats. The site serves as a personal blog and portfolio showcasing her hobbies, technical skills, and social media presence. It targets a general audience interested in personal tech and music culture. The site is small-scale and non-commercial, with no evident business operations or monetization. Technically, the site is custom-built with vanilla HTML, CSS, and JavaScript, hosted behind Cloudflare DNS and CDN services. It integrates WebSocket connections to the Lanyard API for real-time Discord presence updates. The site lacks a CMS and advanced frameworks but uses modern programming languages and tools in the background as described by the owner. Security posture is moderate with domain transfer protections but lacks DNSSEC and security headers. Privacy and cookie policies are absent, reducing compliance. WHOIS data shows inconsistencies, notably a domain creation date in the future, which raises questions about domain legitimacy. Overall, the site is functional and moderately secure but would benefit from improved security headers, privacy compliance, and WHOIS data accuracy.

50
35
2
70
75
70
100
personalprogrammingmusicskateboardingcats+3 more
HTML5CSS3JavaScriptCloudflare DNS+8
2025-07-27T19:43:25.249Z
G

garnix.dev

garnix.dev

49
TechnologyN/asmallHIGH

The website garnix.dev is a personal blog and content sharing platform maintained by an individual named Emilia. It primarily offers blog posts, music recommendations, and personal content, targeting a general audience interested in technology and related community topics. The site is small in scale and operates as a niche personal blog without commercial business infrastructure or formal corporate presence. Technically, the site is built with standard HTML, CSS, and JavaScript, featuring a simple but consistent design and basic mobile optimization. It uses a fetch API call to an external HTTPS endpoint for form submissions, indicating some level of modern web technology usage. However, there is no evidence of advanced frameworks, CMS, or hosting provider details. SEO and accessibility features are basic, and no structured metadata or Open Graph tags are present. From a security perspective, the site uses HTTPS for external requests but lacks visible security headers and formal security policies. The contact form is minimal and lacks CSRF protection or input validation beyond a non-empty check. No privacy, cookie, or terms of service policies are published, which limits compliance with GDPR and other privacy regulations. The domain uses WHOIS privacy protection, which is common for personal sites and justified here. No suspicious or malicious indicators were found. Overall, the site is safe and trustworthy for general audiences but would benefit from improved security practices, privacy disclosures, and business contact information to enhance credibility and compliance. The AI score reflects a functional but basic personal website with room for improvement in security and privacy compliance.

15
40
2
70
75
85
40
personalblogtechnologymusiccommunityprivacy
HTML5CSS3JavaScriptFetch API
2025-07-27T19:43:20.227Z
experiencegoldcoast.com favicon

Experience Gold Coast

experiencegoldcoast.com

70
HospitalityAustraliamediumMEDIUM

Experience Gold Coast operates a comprehensive tourism and education portal focused on promoting the Gold Coast region in Australia. The website offers rich content including attractions, events, accommodation, and student resources, positioning itself as a regional destination marketing organization. The business is relatively new, founded in 2022, and targets tourists, students, and locals interested in exploring the Gold Coast. The company leverages partnerships with local arts, education, and event organizations to enhance its offerings. Technically, the website is built on a modern stack including Sitecore CMS, Bootstrap 4, and hosted likely on Microsoft Azure infrastructure. It integrates multiple third-party analytics and marketing tools such as Microsoft Application Insights, Google Tag Manager, TikTok Pixel, and others, indicating a mature digital marketing approach. The site is mobile optimized and accessible with good SEO practices. From a security perspective, the website enforces HTTPS and uses domain status locks to protect domain integrity. However, it lacks DNSSEC and explicit security headers in the HTML content. Privacy compliance is weak due to the absence of visible privacy and cookie policies and consent mechanisms. No incident response or vulnerability disclosure policies are published. Extensive third-party tracking scripts raise privacy concerns. Overall, the website is professional and functional with good business credibility but requires improvements in privacy compliance and security hardening to reduce risk and enhance user trust.

80
70
17
70
82
60
100
experiencegoldcoastholidayspackagestourism+3 more
HTML5CSS3JavaScriptBootstrap 4+13

Partner Domains:

hota.com.au
partner
studygoldcoast.org.au
partner

+3 more partners

2025-07-27T18:39:06.466Z
P

Private by Design, LLC

micenest.xyz

50
OtherUnited StatessmallMEDIUM

The website micenest.xyz represents a nascent creative collective or idea incubation platform with minimal current content. The site serves primarily as a placeholder with a unique custom font and a promise of future content additions by 2025. The business behind the domain is registered under a privacy-protected entity, Private by Design, LLC, based in the US, consistent with the early-stage nature of the project. The lack of detailed business information, contact details, or policies indicates the site is not yet fully operational or publicly mature. From a technical perspective, the website employs basic HTML and CSS with a custom font and minimal external dependencies. Hosting is provided by Porkbun, LLC, the domain registrar. There is no evidence of advanced frameworks, CMS, or analytics tools. Performance and mobile optimization are basic but functional. SEO and accessibility features are minimal, reflecting the placeholder status. Security posture is limited; no security headers or DNSSEC are enabled, and no privacy or cookie policies are present. The domain uses privacy protection, which is reasonable for the business type and stage. No vulnerabilities or malicious indicators were detected. Overall, the site is safe but lacks maturity in security and compliance. The overall risk is low given the minimal content and no sensitive data handling. Strategic recommendations include implementing security best practices, adding privacy and cookie policies, and providing contact and incident response information to improve trust and compliance as the site develops.

15
50
2
60
52
75
100
creativeplaceholderminimalprivacy-protectedearly-stage
CSS @font-facewoff2 fontHTML5
2025-07-27T18:37:50.544Z
kitsunes.dev favicon

KitsuDev

kitsunes.dev

48
TechnologyN/asmallHIGH

KitsuDev is a small-scale technology service provider specializing in hosting Forgejo instances and offering free static page hosting through its KitsuPage service. The website targets developers and small project owners who seek free and safe hosting solutions. The business model is primarily donation-supported, emphasizing community and small-scale operations. The site branding is consistent and content quality is good, focusing on clear messaging and developer-centric services. Technically, the website is built on Forgejo, a modern Git forge platform, with standard web technologies including JavaScript, HTML5, and CSS3. The site performs well with fast loading times and good mobile optimization. Accessibility is basic but functional. SEO practices are present but could be enhanced. The infrastructure appears modern and well-maintained, though hosting provider details are not explicitly disclosed. From a security perspective, the site enforces HTTPS and implements CSRF tokens, indicating a baseline security posture. However, it lacks explicit security headers such as Content Security Policy and HSTS, and does not provide privacy or cookie policies, which are important for compliance and user trust. No contact information or incident response channels are provided, limiting transparency. No vulnerabilities or exposed sensitive data were detected in the HTML content. Overall, the website presents a moderate risk profile with good technical foundations but gaps in privacy compliance and security best practices. Strategic improvements in policy publication, security headers, and contact transparency would enhance trust and compliance. The domain uses privacy protection, which is justified given the small-scale nature of the business. No suspicious patterns were found in WHOIS data or website content.

20
50
17
70
37
75
40
technologyhostingforgejoopensourcedeveloper
ForgejoJavaScriptHTML5CSS3
2025-07-27T18:37:45.409Z
C

The Catppuccin Webring

ctp-webr.ing

59
OtherN/asmallMEDIUM

The Catppuccin Webring is a community-driven website that aggregates links to various personal and developer websites themed around the Catppuccin aesthetic. It serves as a niche platform for enthusiasts and developers to connect and share their sites. The website is simple, primarily built with HTML and CSS, and uses the ringfairy framework to manage the webring functionality. There is no indication of commercial activity or a formal business entity behind the site. From a technical perspective, the site is lightweight and performs well with good mobile optimization and basic accessibility. However, it lacks advanced SEO features and does not implement security best practices such as HTTPS enforcement or security headers. No analytics or tracking technologies are present, indicating a privacy-conscious or minimalistic approach. Security posture is minimal; no security policies, incident response contacts, or vulnerability disclosures are provided. The absence of HTTPS confirmation and security headers lowers the security score. Privacy compliance is also lacking, with no privacy or cookie policies found. The site does not collect user data via forms or other means, reducing privacy risks but also limiting engagement. Overall, the site is safe and appropriate for general audiences, with no adult or explicit content detected. The lack of business information and policies suggests it is a hobbyist or community project rather than a commercial enterprise. Strategic recommendations include implementing HTTPS, adding privacy and cookie policies, and improving security headers to enhance trust and compliance.

30
50
2
60
95
75
100
communitywebringdeveloperpersonalsitescatppuccin
HTML5CSS3
2025-07-27T18:37:40.207Z
U

Scrumpy System

uwu.gal

59
TechnologyUnited StatessmallMEDIUM

The website 'Scrumpy System' at uwu.gal represents a small technology-focused community comprising software engineers, community managers, and web developers. The site provides a professional and visually consistent experience with clear navigation and social media integration, targeting a general audience interested in technology and software development. The business model appears to be community and service-oriented without explicit commercial transactions or e-commerce features. The domain is relatively new, created in late 2022, aligning with the site's small-scale and emerging presence. Technically, the site employs modern web technologies including HTML5, CSS3, JavaScript, Google Fonts, and FontAwesome icons. Hosting and DNS are managed via Cloudflare, ensuring good SSL configuration and moderate performance. The site is mobile optimized and includes interactive elements such as clocks and a starmap iframe. However, accessibility features are basic, and SEO is adequately addressed through meta tags and Open Graph data. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and important security headers like Content-Security-Policy. There are no published privacy, cookie, or incident response policies, which limits compliance with GDPR and other regulations. No forms or data collection mechanisms are present on the main page, reducing immediate risk but also limiting user engagement features. Overall, the website is safe and professional but would benefit from enhanced privacy and security policies, improved transparency, and additional compliance measures. Strategic recommendations include enabling DNSSEC, publishing privacy and cookie policies, adding security headers, and establishing incident response and vulnerability disclosure protocols to strengthen trust and security posture.

50
35
2
70
75
70
100
technologysoftwareengineeringcommunitywebdevelopmentopensource
HTML5CSS3JavaScriptFontAwesome+3
2025-07-27T18:36:44.892Z
hrtcafe.net favicon

HRT Cafe

hrtcafe.net

58
HealthcareN/asmallMEDIUM

HRT Cafe is a niche healthcare informational website focused on providing resources and vendor listings for DIY hormone replacement therapy (HRT) targeted at transgender individuals who cannot access traditional medical channels. The site offers detailed medication guides, vendor information for homebrew and pharmaceutical suppliers, and DIY compounding instructions. The business operates as a small-scale, community-oriented resource launched in early 2024, with a clear focus on serving a specialized audience. Technically, the website employs a modern frontend stack including Bootstrap, jQuery, and Font Awesome, hosted via Cloudflare. The site is mobile-optimized with good navigation and content structure, though accessibility features are basic. No CMS or advanced analytics tools are detected, indicating a lightweight and privacy-conscious implementation. From a security perspective, the site enforces HTTPS and uses Cloudflare as registrar and likely CDN provider, but lacks DNSSEC and security headers such as Content-Security-Policy or X-Frame-Options. There are no published security or incident response policies, and privacy compliance is limited due to absence of privacy and cookie policies. Contact information is minimal, limited to a ProtonMail email address. Overall, the website is functional, informative, and safe for general audiences, but would benefit from enhanced security practices, privacy compliance improvements, and more transparent business information to increase trust and credibility.

15
50
17
65
65
80
100
healthcaretransgenderdiyhrthormonereplacementtherapymedicationguides+1 more
HTML5BootstrapjQueryFont Awesome+1
2025-07-27T18:36:34.852Z
symtrkl.gay favicon

Private by Design, LLC

symtrkl.gay

44
OtherUnited StatessmallHIGH

The website symtrkl.gay is a personal portfolio and creative hub for Jennifer (SymTrkl), a transfeminine artist and writer based in the United States. The site showcases her work in illustration, web design, FPV drone piloting, and writing, with links to various social media and creative platforms. The business model centers on personal branding, commissions, and community support through platforms like Ko-Fi and Patreon. The site targets a general audience with a mature content segment including erotica and adult social media links. Technically, the site is built with standard HTML, CSS, and JavaScript, hosted via Porkbun with domain privacy protection. The site is moderately optimized for mobile and performance but lacks advanced SEO and accessibility features. No CMS or major frameworks are detected, indicating a custom or static site approach. From a security perspective, the domain uses registrar locks to prevent unauthorized changes but lacks DNSSEC and security headers. There is no visible HTTPS enforcement information, no privacy or cookie policies, and no incident response contacts. The site does not use analytics or tracking scripts, minimizing privacy risks but also limiting business intelligence. Overall, the site is legitimate and consistent with a personal creative portfolio but would benefit from improved security practices, privacy compliance, and clearer contact information to enhance trust and professionalism.

15
35
2
60
72
75
20
personalportfoliocreativeadulttransfeminine+3 more
HTML5CSS (external stylesheet symtrkl_dotgay.css)JavaScript (custom lore.js script)
2025-07-27T18:35:49.515Z
F

home - olivia

floof.gay

40
OtherN/asmallHIGH

The website floof.gay is a personal site belonging to an individual named Olivia, serving as a small corner of the internet to share personal interests, social media presence, and blog content. The site is positioned as a personal brand rather than a commercial business, targeting a general audience interested in the author's activities and social links. The site leverages modern web technologies such as Dev.css and web fonts to provide a clean and responsive user experience. The technical infrastructure is straightforward, hosted likely via NameCheap with privacy-protected WHOIS registration, reflecting a typical personal website setup. From a security perspective, the site uses HTTPS and has domain transfer protections enabled, but lacks DNSSEC and security headers, which are recommended for improved security posture. There are no privacy or cookie policies present, and no contact information or forms for data collection, indicating minimal compliance with privacy regulations. No analytics or advertising scripts were detected, suggesting limited tracking and data collection. Overall, the site is safe and appropriate for general audiences, with no adult or questionable content detected. The domain is recently registered and privacy protected, consistent with a personal site. The security posture is moderate but could be improved with additional headers and policies. The site’s business credibility is limited due to its personal nature and lack of formal business information. Strategic recommendations include adding privacy and cookie policies, implementing security headers, enabling DNSSEC, and considering a security.txt file for vulnerability disclosure to enhance trust and compliance.

15
35
2
70
52
70
-
personalblogsocialfediverseopensource+1 more
HTML5CSSJavaScriptDev.css+2
2025-07-27T18:35:39.457Z
tokipona.org favicon

Toki Pona (official site)

tokipona.org

45
EducationN/asmallHIGH

The website tokipona.org serves as the official hub for the Toki Pona constructed language, created by Sonja Lang in 2001. It offers comprehensive educational resources including books, dictionaries, community links, and multimedia content. The site targets language learners, conlang enthusiasts, and educators globally, positioning itself as the authoritative source for Toki Pona with recognition from ISO 639-3 and university usage. The business model is primarily informational with commercial elements through book and merchandise sales. Technically, the site employs modern frontend technologies such as Bootstrap 5, jQuery, Chart.js, and Google Fonts, hosted by Vodien Internet Solutions. Performance and mobile optimization are good, though accessibility and SEO are basic. The site uses HTTPS and Google Analytics for tracking but lacks advanced security headers and privacy/cookie policies, indicating room for compliance improvement. Security posture is moderate with no visible vulnerabilities or exposed sensitive data, but the absence of security headers and vulnerability disclosure policies are notable gaps. The domain is well-established since 2001, registered with a reputable registrar, and shows no suspicious patterns, supporting legitimacy. Overall, the site is professional, content-rich, and trustworthy but should enhance privacy compliance and security best practices to improve user trust and regulatory adherence.

15
35
17
85
62
70
-
languageconstructedlanguagetokiponaeducationcommunity+2 more
HTML5CSS3Bootstrap 5.3.7jQuery 3.7.1+3
2025-07-27T18:34:08.883Z
P

Private by Design, LLC

starlightnet.work

47
TechnologyUnited StatessmallHIGH

The Starlight Network is a small, privacy-focused technology and community project operated by two individuals, Alexia and Nelson. The website serves as a platform for their blog posts, community engagement, and hosting of services that emphasize privacy, decentralization, and usability. The business model is community-supported, relying on donations via Liberapay, and targets technology enthusiasts interested in privacy and social interaction. The domain is newly registered in 2025 with protections to prevent unauthorized transfers or deletions, aligning with the privacy-centric ethos of the project. Technically, the website is built with basic HTML and CSS, with no detected CMS or advanced frameworks. The site is moderately optimized for performance and mobile use but lacks advanced SEO and accessibility features. No analytics or tracking scripts are present, indicating a minimal data collection approach. The hosting provider is not explicitly identified, but the domain registrar is Porkbun, known for privacy-friendly services. From a security perspective, the site lacks DNSSEC, security headers, and visible HTTPS enforcement details, which lowers its security posture. There is no published security policy or incident response information, and no cookie or privacy consent mechanisms are implemented. However, domain registration protections and the absence of suspicious content or vulnerabilities suggest a moderate security maturity level. Overall, the website is safe for general audiences, with no adult or questionable content detected. The site is professionally presented but could benefit from enhanced security measures, privacy compliance improvements, and clearer contact information to increase trust and credibility.

15
50
2
60
65
75
40
technologycommunityprivacydecentralizationblog
HTML5CSS3
2025-07-27T17:32:01.723Z
squeakable.dev favicon

(un)Squeakable Code

squeakable.dev

55
TechnologyN/asmallMEDIUM

The website squeakable.dev is a personal portfolio and blog site titled '(un)Squeakable Code'. It primarily serves as a space for the owner to share projects, blog posts, and links to related community sites. The content is minimal and informal, targeting a general audience interested in technology and personal projects. The site does not represent a commercial business entity and lacks formal business information or contact details. Technically, the site is a simple static HTML/CSS implementation without detectable CMS or advanced frameworks. There is no evidence of analytics, advertising, or tracking technologies. The site appears moderately optimized for mobile and accessibility but lacks advanced SEO features. No security headers or HTTPS status information was detected from the provided data, indicating potential areas for improvement in security posture. From a security perspective, the site does not provide privacy policies, cookie consent mechanisms, or incident response information. The WHOIS data is privacy protected, which is reasonable for a personal site. No vulnerabilities or suspicious patterns were identified, but the absence of security best practices and policies limits the overall security maturity. Overall, the site is low risk but would benefit from implementing HTTPS, security headers, privacy and cookie policies, and contact information to improve trust and compliance. The content is safe for general audiences with no adult or explicit material detected.

30
50
2
65
52
85
100
personalportfolioblogtechnologycommunity
HTML5CSS3
2025-07-27T17:31:56.704Z