Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157326
Websites
130
Industries
113
Countries
52
Avg Score
Page 21 of 22|Showing 1001-1050 of 1070
eiva.com favicon

EIVA a/s

eiva.com

70
EnergyDenmarkmediumMEDIUM

EIVA a/s is a well-established engineering company specializing in software and hardware solutions for maritime survey, offshore, and shallow water construction industries. With over 45 years of experience, EIVA offers a comprehensive portfolio including software products, equipment sales and rental, integrated system solutions, 24/7 support, and professional training services. Their market position is strong, supported by a professional website, active social media presence, and a broad customer base in the energy and transportation sectors. Technically, the website employs modern web technologies such as Google Tag Manager, Cookiebot for consent management, and lazy loading for performance optimization. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. Security-wise, the site enforces HTTPS and uses secure forms but lacks explicit security headers and a public security policy or incident response information, which are areas for improvement. The absence of WHOIS data for the domain is a notable anomaly, slightly reducing trust in domain registration transparency, though the overall business credibility remains high. Strategic recommendations include publishing a dedicated security policy, enhancing security headers, and providing incident response contacts to strengthen trust and compliance.

-
95
17
100
82
80
100
maritimesurveyengineeringsoftwarehardware+5 more
HTML5CSS3JavaScriptGoogle Tag Manager+4
2025-06-23T19:08:13.237Z
transparency.google favicon

Google Transparency

transparency.google

61
TechnologyUnited StatesenterpriseMEDIUM

The Google Transparency Center website serves as a comprehensive resource detailing Google's product policies, enforcement actions, and commitment to user safety and transparency. It targets a broad audience including users, developers, creators, and researchers, providing clear and accessible information about Google's approach to policy development and enforcement. The site reflects Google's position as a global technology leader with a strong emphasis on transparency and trust. Technically, the website is built on a modern, performant infrastructure leveraging Google's internal frameworks, Google Cloud hosting, and best practices in web development including responsive design, accessibility, and SEO optimization. The use of Google Tag Manager and Analytics indicates a mature digital analytics setup. From a security perspective, the site demonstrates excellent security posture with HTTPS enforcement, comprehensive security headers, and no detected vulnerabilities or exposed sensitive data. Privacy compliance is robust, with clear privacy and cookie policies and consent mechanisms in place. However, direct contact information for security or incident response is not prominently provided. Overall, the website is highly professional, trustworthy, and secure, reflecting Google's commitment to transparency and user protection. No critical issues or blocking mechanisms were detected, allowing for a full and detailed analysis.

45
68
2
60
52
70
100
transparencygooglepolicysecurityprivacy+2 more
Google Tag ManagerGoogle FontsWebP imagesSVG icons+2
2025-06-23T18:09:07.680Z
rastreator.com favicon

RASTREATOR COMPARADOR CORREDURÍA DE SEGUROS S.L.U

rastreator.com

64
FinanceSpainlargeMEDIUM

Rastreator.com is a well-established Spanish online comparison platform specializing in insurance, energy tariffs, finance products, and telecommunications offers. Founded in 2009, it serves consumers by providing transparent price comparisons and expert advisory services to help users select the best products in sectors such as car insurance, health insurance, mortgages, and energy. The website demonstrates a professional and consistent brand presence with comprehensive content and a user-friendly interface optimized for mobile devices. Technically, the site uses modern web technologies including lazy loading scripts and Google Tag Manager for analytics and marketing, hosted on a secure HTTPS platform. Security posture is strong with no visible vulnerabilities, though some security headers and explicit policies are missing. Privacy compliance is partially met with a cookie consent mechanism but lacks a visible privacy policy and terms of service in the provided content. The WHOIS data is notably absent, which slightly reduces trustworthiness but does not negate the legitimacy indicated by the website content and structured data. Overall, Rastreator.com is a credible and professional service with room for improvement in transparency and security documentation.

25
65
17
75
82
65
100
insurancecomparisonfinanceenergytelecommunications+3 more
JavaScriptGoogle Tag ManagerRocket Lazy Load ScriptsWeb fonts (Google Fonts - Raleway)+1

Partner Domains:

compararcoche.com
partner
2025-06-23T14:47:04.086Z
ggdrotterdamrijnmond.nl favicon

GGD Rotterdam-Rijnmond

ggdrotterdamrijnmond.nl

69
HealthcareNetherlandslargeMEDIUM

GGD Rotterdam-Rijnmond is a regional public health organization dedicated to protecting and promoting the health of residents in the Rotterdam-Rijnmond area. The website serves as an official portal providing health information, vaccination services, sexual health testing, travel health advice, and public health research. It targets residents, healthcare professionals, and travelers, positioning itself as a trusted government health authority. The site is well-branded with municipal affiliation and maintains active social media channels for outreach. Technically, the website is built on modern frameworks including Next.js and React, with evidence of Drupal CMS usage for content management. It employs accessibility features such as ReadSpeaker for text-to-speech and is optimized for mobile devices. Performance is fast, and SEO best practices are followed with proper meta tags and structured content. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms. While explicit security headers are not fully confirmed, no vulnerabilities or exposed sensitive data were detected. The absence of a published security policy or vulnerability disclosure page suggests room for improvement in transparency and incident response readiness. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance with privacy regulations such as GDPR. The domain registration aligns with the organization's public nature, reinforcing legitimacy. Strategic recommendations include enhancing security header implementation, publishing security policies, and adding vulnerability disclosure mechanisms to further strengthen security posture.

80
83
2
60
75
65
100
healthcarepublichealthvaccinationssexualhealthtravelhealth+1 more
Next.jsReactReadSpeaker (webReader.js)Custom fonts (Avenir Next)+1
2025-06-23T14:45:03.649Z
rcophth.ac.uk favicon

The Royal College of Ophthalmologists

rcophth.ac.uk

40
HealthcareUnited KingdommediumHIGH

The Royal College of Ophthalmologists is a UK-based professional membership organisation and charity dedicated to promoting and supporting the ophthalmic profession nationally and internationally. The website serves as a comprehensive resource for members, trainees, researchers, and patients, offering information on training, examinations, research, policy, and events. The organisation holds a strong market position as the authoritative body for ophthalmology in the UK, with a clear focus on education, professional development, and advocacy. Technically, the website is built on WordPress with a modern tech stack including jQuery, Google Tag Manager, and cookie consent tools. It demonstrates good digital maturity with responsive design, accessibility considerations, and SEO optimization. Performance is moderate, with room for improvement in hosting and caching strategies. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms, but lacks visible advanced security headers and a public security policy or incident response information. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with clear privacy and cookie policies and GDPR adherence. Overall, the website is professional, trustworthy, and well-maintained, with minor recommendations to enhance security headers and publish security policies. The domain registration data aligns well with the organisation's claims, supporting legitimacy and trustworthiness.

15
68
10
-
42
-
100
healthcareprofessionalmembershipeducationophthalmologyukcharity
jQuery 3.3.1Yoast SEO pluginGoogle Tag ManagerCookieControl by Civic UK+5
2025-06-22T15:06:09.429Z
mentor.com favicon

Siemens Digital Industries Software

mentor.com

49
TechnologyUnited StatesenterpriseHIGH

Siemens Digital Industries Software operates a comprehensive and professional website dedicated to Electronic Design Automation (EDA) solutions. The company offers a broad portfolio of software, hardware, and services aimed at streamlining the design, verification, and manufacturing of integrated circuits and electronic systems. Siemens holds a strong market position as a leading provider in the technology and manufacturing sectors, supported by its parent company Siemens AG. The website targets professionals in electronic design, manufacturing, and related industries, providing detailed product information, training, and consulting services. Technically, the website employs modern web technologies including custom web components, advanced video players, and a robust content delivery network. It demonstrates excellent performance, mobile optimization, and accessibility features. The use of structured data and Open Graph metadata enhances SEO and social media integration. Consent management is implemented via Usercentrics, reflecting a commitment to privacy compliance. From a security perspective, the site enforces HTTPS and integrates security best practices such as trusted script sources and consent management. However, explicit security headers and a public security policy are not evident, suggesting areas for improvement. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website is highly professional, trustworthy, and well-aligned with Siemens' corporate identity. It effectively serves its target audience with rich content and a strong technical foundation. Strategic recommendations include enhancing security headers, publishing a security policy, and improving privacy policy visibility to further strengthen compliance and trust.

55
25
5
50
-
75
100
technologymanufacturingelectronicdesignautomationsiemenseda+1 more
JavaScriptXMLHttpRequestGoogle Tag ManagerUsercentrics Consent Management+3

Partner Domains:

mendix.com
partner
partnerfinder.plm.automation.siemens.com
partner
2025-06-22T08:59:45.067Z
glove.fit favicon

Glove Technologies, Inc.

glove.fit

52
TechnologyN/asmallMEDIUM

Glove Technologies, Inc. operates the website glove.fit, offering a SaaS platform that converts website visitors into qualified leads through real-time AI-driven personalization and visitor tracking. Their technology focuses on understanding visitor behavior, building visitor signal maps, and dynamically personalizing content to optimize lead conversion for B2B SaaS companies and enterprise clients. The platform emphasizes ease of installation with a single script tag and promises significant improvements in inbound lead generation. Technically, the website leverages modern JavaScript frameworks, likely React, and integrates third-party services such as HubSpot forms and Contentsquare for analytics and tracking. The site is hosted on Amazon Cloudfront CDN, ensuring moderate performance and good mobile optimization. However, accessibility and SEO optimizations are basic and could be improved. From a security perspective, the site uses HTTPS and avoids exposing sensitive data in its HTML. However, it lacks visible security headers, a published security policy, incident response contacts, and vulnerability disclosure mechanisms. Privacy compliance is limited, with a privacy policy present but no cookie consent mechanism or explicit GDPR compliance indicators. Overall, the website presents a professional and functional digital presence with moderate security and privacy maturity. Strategic improvements in privacy compliance, security policy transparency, and accessibility would enhance trust and compliance posture.

15
53
25
70
-
80
100
leadgenerationaipersonalizationvisitortrackingb2bsaasreal-timeanalytics
JavaScriptHubSpot forms (hsforms.net)Contentsquare (hj.contentsquare.net)Cloudfront CDN+2
2025-06-18T16:59:38.824Z
ambita.no favicon

Sikri AS

ambita.no

73
Real EstateNorwaylargeMEDIUM

Ambita, operated by Sikri AS, is a leading Norwegian company specializing in digital solutions for the real estate market. Their website showcases a comprehensive portfolio of services including property information portals, digital registration (tinglysing), and collaborative digital tools aimed at streamlining property transactions and management. The company targets a broad audience including real estate professionals, financial institutions, municipalities, and private individuals, positioning itself as a key technology enabler in the Norwegian property sector. Technically, the website is built on the HubSpot CMS platform, leveraging modern web technologies such as Google Analytics 4, Piwik PRO for analytics, Cookiebot for cookie consent management, and Zendesk for customer support. The site demonstrates good performance, mobile optimization, and accessibility features, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS with strong SSL configuration and implements multiple security headers to protect users. The presence of a detailed cookie consent mechanism and privacy policy indicates compliance with GDPR and related privacy regulations. However, no explicit security policy or incident response information is published, which could be improved. Overall, Ambita's website reflects a professional, trustworthy, and well-managed digital presence with strong business credibility and compliance posture. Strategic recommendations include publishing a dedicated security policy, providing incident response contacts, and adding a vulnerability disclosure mechanism to further enhance trust and security transparency.

55
83
10
70
92
85
100
realestatetechnologydigitalservicespropertyinformationgdpr+2 more
HubSpot CMSGoogle Tag ManagerGoogle Analytics 4Cookiebot+5

Partner Domains:

kunde.samhandling.ambita.com
partner
dms.ambita.com
partner

+3 more partners

2025-06-18T14:08:03.169Z
sklkommentus.se favicon

Adda AB

sklkommentus.se

47
GovernmentSwedenmediumHIGH

Adda AB operates as a specialized service provider supporting the Swedish public sector through framework agreements, procurement support, competence development, and training. The company targets employees within municipalities, regions, and other public organizations, offering both digital and printed resources to facilitate efficient public procurement and workforce development. The website reflects a mature market position with clear service offerings and a professional digital presence. Technically, the website employs modern web technologies including Vue.js, Microsoft Application Insights for telemetry, and Google reCAPTCHA v3 for bot protection. The site is built on the Episerver CMS platform, ensuring structured content management and good SEO practices. Mobile optimization and accessibility are well addressed, contributing to a positive user experience. From a security perspective, the site benefits from HTTPS encryption, cookie consent mechanisms, and monitoring tools. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are absent, representing areas for improvement. No critical vulnerabilities or blocking mechanisms were detected, indicating a solid security posture overall. The overall risk profile is low with recommendations to enhance transparency around security policies and incident handling. Strategic improvements in security headers and vulnerability disclosure would further strengthen trust and compliance.

75
-
-
55
-
65
100
ramavtalkompetensutvecklingoffentligsektorupphandlingutbildning+2 more
JavaScriptGoogle reCAPTCHA v3Microsoft Application InsightsGoogle Fonts+1
2025-06-18T08:55:52.447Z
nacka.se favicon

Nacka kommun

nacka.se

38
GovernmentSwedenlargeHIGH

Nacka kommun operates as the official municipal government website serving over 100,000 residents in Nacka, Sweden. The site provides comprehensive information about municipal services including education, social support, urban development, and local politics. It targets residents, businesses, and visitors seeking municipal resources and engagement opportunities. The business model is public sector focused, delivering essential community services and governance information. Technically, the website is built on the EPiServer CMS platform, leveraging modern JavaScript frameworks, SVG icons, and Azure Application Insights for analytics. The site demonstrates good mobile optimization, accessibility, and SEO practices, with a moderate performance profile. Hosting appears to be on Microsoft Azure infrastructure, ensuring reliability and scalability. From a security perspective, the site enforces HTTPS with strong SSL configuration and implements cookie consent mechanisms aligned with GDPR requirements. While explicit security headers are not fully documented in the HTML, best practices are implied. No critical vulnerabilities or exposed sensitive data were detected. However, the site lacks a published security policy or incident response contact, which could enhance transparency and trust. Overall, Nacka kommun's website is a professional, trustworthy, and well-maintained digital presence for a government entity. It balances user experience, compliance, and technical robustness effectively, supporting its role as a key information and service portal for the municipality.

60
15
-
75
-
65
-
municipalitygovernmentpublicservicesswedennacka+3 more
JavaScriptSVG iconsAzure Application InsightsRequireJS+1
2025-06-18T08:55:50.502Z
vasttrafik.se favicon

Västtrafik AB

vasttrafik.se

52
TransportationSwedenlargeMEDIUM

Västtrafik AB operates as the regional public transportation authority for Västra Götaland, Sweden, providing comprehensive travel planning, ticketing, and traffic information services. The website serves a broad audience of public transport users in the region, offering tools and information to facilitate travel across multiple modes including bus, tram, train, and ferry. The business is positioned as a key regional transport provider under the Västra Götalandsregionen umbrella, with a large operational scale and a focus on sustainable and accessible mobility solutions. Technically, the website is built on the EPiServer CMS platform, leveraging modern JavaScript frameworks and libraries, including Matomo for analytics and EPiServer Forms for user feedback and contact forms. The site demonstrates good mobile optimization, accessibility, and SEO practices, with a moderate to fast performance profile. Hosting appears to be managed by the regional government infrastructure, ensuring reliability and alignment with public sector standards. From a security perspective, the site enforces HTTPS, uses secure cookies, and implements cookie consent mechanisms compliant with GDPR. While explicit security policies and incident response contacts are not published, the site shows adherence to best practices with no visible vulnerabilities or exposed sensitive data. The use of nonce attributes in scripts and consent-based tracking further enhance security and privacy. Overall, Västtrafik's website reflects a mature digital presence with strong business credibility, good technical implementation, and a solid security posture. Strategic recommendations include publishing detailed security policies, incident response information, and vulnerability disclosure guidelines to further enhance trust and compliance.

80
15
5
65
-
65
100
publictransporttravelplanningticketsregionalservicessweden+1 more
JavaScriptMatomo AnalyticsEPiServer FormsBootstrap (implied by data-bs-toggle attributes)+1

Partner Domains:

vgregion.se
partner
mittkonto.vasttrafik.se
service

+2 more partners

2025-06-18T08:55:50.017Z
ostersund.se favicon

Östersunds kommun

ostersund.se

44
GovernmentSwedenlargeHIGH

Östersunds kommun operates as the official municipal government website for the city of Östersund, Sweden, providing comprehensive information and services related to education, care, culture, infrastructure, business, and politics. The website targets residents and visitors, offering e-services, news updates, and contact channels to facilitate community engagement and service delivery. The site holds a strong market position as a trusted government portal with consistent branding and clear communication of municipal functions. Technically, the website is built on the SiteVision CMS platform, utilizing jQuery and standard web technologies. It demonstrates good mobile optimization, accessibility, and SEO practices, although performance is moderate. The presence of cookie consent mechanisms and Google site verification indicates a reasonable level of digital maturity. From a security perspective, the site uses HTTPS and includes some security best practices such as CSRF token placeholders and cookie consent. However, it lacks explicit security headers, published security policies, and incident response contacts, which are areas for improvement. Tracking is performed via Vizzit analytics, with moderate user tracking levels. Overall, the website is professional, trustworthy, and well-suited for its public sector role. Strategic enhancements in security policy transparency and technical security controls would further strengthen its posture and compliance.

40
-
-
73
-
65
100
municipalitygovernmentpublicservicesswedene-services+2 more
jQuerySiteVision CMSJavaScriptCSS+1
2025-06-18T08:55:49.905Z
S

Stockholms stad

stockholm.se

58
GovernmentSwedenlargeMEDIUM

Stockholms stad operates an official municipal website serving over 960,000 residents and approximately 40,000 employees. The website provides comprehensive access to city services, including education, family support, cultural activities, traffic information, and business resources. It targets residents, businesses, and visitors, positioning itself as the authoritative digital portal for Stockholm city government. The site is well-branded, professionally designed, and offers clear navigation and accessibility features. Technically, the website employs modern web technologies including JavaScript, SVG icons, React components, and Piwik PRO analytics. The presence of Episerver CMS is inferred from script paths. The site is mobile-optimized and demonstrates good SEO and accessibility practices. Performance is moderate, with asynchronous script loading and structured content. From a security perspective, the site enforces HTTPS, uses cookie consent mechanisms with granular controls, and avoids exposing sensitive data. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not found. Security headers are not explicitly detected in the HTML content, suggesting room for improvement. Overall, the website is trustworthy, professionally maintained, and compliant with GDPR requirements. The domain registration data aligns with the official city ownership, reinforcing legitimacy. No blocking or WAF interference was detected, allowing full content access and analysis.

95
15
-
92
-
75
100
governmentmunicipalstockholmpublicservicessweden+1 more
JavaScriptSVG iconsPiwik PRO analyticsReact (react-components.js)+2
2025-06-18T08:55:47.082Z
wkoecg.at favicon

Wirtschaftskammer Österreich (WKO)

wkoecg.at

40
OtherAustrialargeHIGH

The website wkoecg.at serves as an official business directory for Austrian companies, operated by the Wirtschaftskammer Österreich (WKO), the Austrian Chamber of Commerce. It provides a comprehensive and up-to-date listing of over 600,000 Austrian businesses, targeting business users and the general public seeking company information. The platform offers additional services such as ECG compliance support and eServices, positioning itself as a central hub for business-related information in Austria. Technically, the site is built on an ASP.NET WebForms framework with modern JavaScript enhancements, including Google Tag Manager and a consent management platform to comply with privacy regulations. The site demonstrates good accessibility and SEO practices, with structured navigation and mobile optimization. However, performance metrics are unavailable, and the hosting provider is not explicitly identified. From a security perspective, the site lacks a valid SSL/TLS certificate, resulting in no HTTPS availability, which is a critical vulnerability exposing users to potential data interception. While security headers such as HSTS, X-Frame-Options, and secure cookie flags are implemented, the absence of HTTPS severely undermines the overall security posture. Privacy policies and cookie consent mechanisms are present and appear comprehensive, supporting GDPR compliance. Overall, the site is a credible and authoritative business resource with strong content and privacy compliance but suffers from a critical security flaw due to missing valid HTTPS. Addressing this issue is paramount to protect user data and maintain trust. Strategic improvements in SSL deployment and ongoing security audits are recommended to elevate the site's security and user confidence.

45
18
25
50
-
85
100
businessdirectoryaustriachamberofcommercecompanysearchecgservice+1 more
ASP.NETJavaScriptGoogle Tag ManagerSVG icons+3
2025-06-16T16:20:15.939Z
benteler.de favicon

BENTELER

benteler.de

47
ManufacturingGermanyenterpriseMEDIUM

BENTELER is a well-established enterprise specializing in metal processing with a strong focus on automotive and industrial sectors. Founded in 1876, the company has a significant global presence with 90 locations worldwide, offering a diverse range of products including automotive components, steel/tube products, mechanical engineering, and glass processing equipment. The website reflects a mature business model targeting industrial clients and partners, with a clear emphasis on sustainability and innovation. Technically, the website is built on TYPO3 CMS, utilizing modern web technologies such as ES6 JavaScript modules, lazy loading, and SVG icons. It demonstrates excellent mobile optimization, accessibility, and SEO practices, ensuring a fast and user-friendly experience. The presence of comprehensive meta tags, structured data, and multi-language support further enhance its digital maturity. From a security perspective, the site enforces HTTPS, employs Google reCaptcha for bot prevention, and implements a granular cookie consent mechanism compliant with GDPR. No critical vulnerabilities or exposed sensitive data were detected. However, explicit security policy and incident response contact details are not prominently available, suggesting areas for improvement. Overall, BENTELER's website is professional, secure, and compliant, reflecting its enterprise status and global operations. Strategic enhancements in security transparency and incident response readiness could further strengthen its trustworthiness and compliance posture.

75
30
13
70
-
60
40
manufacturingautomotivemetalprocessingglobalpresenceprivacy+3 more
TYPO3 CMSJavaScript ES6 modulesLazy loading imagesSVG icons+4

Partner Domains:

career.benteler.de
subsidiary
benteler-glass.com
subsidiary
2025-06-15T22:28:32.815Z
poloplast.com favicon

POLOPLAST GmbH & Co KG

poloplast.com

40
ManufacturingAustrialargeHIGH

POLOPLAST GmbH & Co KG is a well-established Austrian manufacturer specializing in plastic pipe systems with a strong presence across Europe. The company emphasizes sustainability, innovation, and quality, offering a broad range of products including multilayer pipe systems, building drainage, and wastewater disposal solutions. Their market position is that of a technology leader with a large operational scale and a parent company affiliation with Wietersdorfer. The website reflects a professional business with clear contact information and comprehensive privacy and cookie policies, supporting GDPR compliance. Technically, the website is built on TYPO3 CMS and uses modern web technologies including Bootstrap for responsive design. However, the site suffers from slow performance and lacks HTTPS support, which is a critical security concern. The absence of SSL/TLS encryption and security headers exposes the site to potential risks and undermines user trust. Analytics and tracking tools such as Google Analytics and LeadFeeder are used with appropriate cookie consent mechanisms. Security posture is weak due to the lack of HTTPS and security headers, though no active vulnerabilities or malware were detected. Privacy compliance is strong with clear policies and consent banners. Business credibility is high given the detailed company information and social media presence. Overall, the site is functional and professional but requires urgent security improvements to protect user data and enhance trust. Strategic recommendations include immediate implementation of a valid SSL certificate, addition of security headers, performance optimization, and enhancement of incident response information to strengthen security culture and compliance.

70
18
5
50
-
90
100
pipesystemmultilayerpipesystembuildingdrainagemulti-layerplasticpipesystems+2 more
TYPO3 CMSJavaScriptCSSSVG icons
2025-06-15T21:50:49.439Z
5

555photography

555photography.com

38
MediaN/asmallHIGH

555photography is a small professional photography business specializing in wedding, family, engagement, and event photography. The business leverages the SmugMug platform to showcase its portfolio and manage client galleries, positioning itself as a niche service provider in the media sector. The website content is relevant and well-structured, targeting individuals and families seeking professional photography services. The business model relies on online presence and client engagement through SmugMug's infrastructure. Technically, the website is hosted on SmugMug's infrastructure using nginx and Amazon CloudFront CDN, with modern JavaScript frameworks and responsive design ensuring good mobile optimization and user experience. However, performance metrics are limited, and some technical debt is evident in the use of older YUI libraries alongside modern modules. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability impacting user trust and data protection. While some security headers are present, the absence of HTTPS and other advanced security features significantly lowers the security posture. Privacy policies and terms of service are available on the SmugMug domain, indicating compliance with GDPR and cookie consent mechanisms, but no explicit security or incident response policies are found. Overall, the website presents a moderate risk profile primarily due to missing HTTPS and limited direct business contact information. Strategic improvements in SSL implementation, security policy publication, and direct contact channels would enhance trust and compliance.

50
-
-
50
-
70
100
photographyweddingfamilyprofessionalengagement+1 more
nginxSmugMug platformCloudFront CDNJavaScript ES6 modules+5
2025-06-15T21:49:48.353Z
amgen.com favicon

Amgen Inc.

amgen.com

40
HealthcareUnited StatesenterpriseHIGH

Amgen Inc. is a leading global biotechnology company focused on developing innovative biologic medicines to treat serious illnesses. The website reflects a mature enterprise with comprehensive content covering its science, products, corporate responsibility, and investor relations. The target audience includes healthcare professionals, patients, investors, and partners. The business model centers on research, development, manufacturing, and delivery of biologic therapeutics, positioning Amgen as a pioneer in biotechnology with a strong market presence. Technically, the website employs modern JavaScript libraries such as jQuery and Slick Carousel, uses lazy loading for images, and integrates Google Tag Manager and Cookiebot for analytics and privacy compliance. Hosting is via Amazon CloudFront CDN, supporting global content delivery. The site is mobile optimized with good SEO and accessibility basics, though some accessibility features could be enhanced. From a security perspective, the site implements several security headers including Content Security Policy and X-Frame-Options. However, a critical issue is the absence of a valid SSL certificate and HTTPS support, which severely impacts the security posture. No TLS protocols are enabled, and HSTS is not properly configured. These gaps expose users to potential risks and undermine trust. Overall, the website is professionally designed and content-rich, but the lack of HTTPS and valid SSL certificate is a major security concern. Strategic improvements in SSL/TLS deployment and enhanced security configurations are essential to protect user data and maintain trust. Privacy compliance is well addressed with Cookiebot and clear privacy and cookie policies. Business credibility is high, supported by consistent branding and comprehensive corporate information.

75
18
5
50
-
85
100
biotechnologyhealthcarepharmaceuticalscorporateresponsibilityclinicaltrials
jQuerySlick CarouselGoogle Tag ManagerCookiebot+3
2025-06-15T21:49:11.173Z