Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 210 of 408|Showing 10451-10500 of 20393
typeof.net favicon

Belleve Invis

typeof.net

55
TechnologyN/asmallMEDIUM

Typeof.net is a personal website operated by Renzhi Li (aka be5invis), focusing on typography, type theory, and digital typeface design, notably the Iosevka programming font. The site serves a niche audience of typography enthusiasts and programmers interested in font design and text processing. The business model is that of an individual content creator and font designer, with a long-standing domain registration since 2009, indicating sustained activity and credibility in the niche. Technically, the website is built using the Hexo static site generator and hosted on GitHub Pages, leveraging modern web fonts and CSS libraries such as Font Awesome and Iosevka fonts. The site is performant and mobile-optimized with a clean, consistent design, though accessibility and SEO optimizations are basic. No advanced analytics or tracking technologies are detected, reflecting a privacy-conscious approach. From a security perspective, the site lacks several best practices: no DNSSEC, no security headers, and no published privacy or cookie policies. The domain is registered without privacy protection, consistent with the personal nature of the site. No contact or incident response information is provided, limiting transparency. Overall, the security posture is moderate but could be improved with standard web security enhancements. The overall risk is low given the non-commercial, informational nature of the site, but improvements in privacy compliance and security hardening are recommended to enhance trust and protect visitors. Strategic recommendations include enabling DNSSEC, adding security headers, publishing privacy and cookie policies, and providing contact information for security incidents.

15
50
2
55
72
80
100
typographytypefaceiosevkaprogrammingfontsdigitaltypography+1 more
HTML5CSS3Font AwesomeIosevka font+2
2025-07-27T03:23:38.467Z
headpats.online favicon

Private by Design, LLC

headpats.online

64
TechnologyUnited StatessmallMEDIUM

headpats.online is a small personal instance of the GoToSocial federated microblogging platform, operated by an individual named 'taavi'. The website serves as a personal space for microblogging within the fediverse, leveraging open-source software and the ActivityPub protocol to connect with other decentralized social networks. The site is modest in scale, hosting a single user with a limited number of posts, and does not currently allow new user registrations. The business model is essentially personal and non-commercial, focusing on community participation in decentralized social media. Technically, the site uses GoToSocial version 0.19.1 and standard web technologies including HTML5 and CSS with WebP images. The site is moderately optimized for performance and mobile devices, with good accessibility and basic SEO. Hosting details are not explicitly disclosed, but DNS records indicate use of multiple name servers including Hurricane Electric. The site lacks advanced security headers and DNSSEC is not enabled, which presents opportunities for improvement in security hardening. From a security perspective, the domain is protected with registrar status flags that prevent unauthorized transfers or deletions, but the WHOIS data shows an anomalous domain creation date set in the future, which may be a data error or placeholder. No privacy or cookie policies are present, and no vulnerability disclosure or incident response information is provided. The site does not employ tracking or advertising technologies, enhancing privacy but limiting business insights. Overall, the security posture is moderate but could be improved by adding standard security headers, enabling DNSSEC, and publishing privacy and cookie policies. The overall risk assessment is low given the personal nature of the site and absence of sensitive transactions or user registrations. Strategic recommendations include enabling DNSSEC, adding security headers, publishing privacy and cookie policies to improve compliance, and considering a vulnerability disclosure policy to enhance trust. These steps would strengthen the security posture and privacy compliance while maintaining the site's role as a personal federated social media instance.

75
50
2
55
75
85
100
gotosocialfediversemicrobloggingpersonalinstanceactivitypub
GoToSocial 0.19.1+git-6574dc8ActivityPub protocolHTML5CSS (multiple stylesheets)+1
2025-07-27T03:23:33.409Z
openpgp.org favicon

OpenPGP

openpgp.org

66
TechnologyN/asmallMEDIUM

OpenPGP.org is the official website for the OpenPGP standard, the most widely used email encryption protocol. The site provides information about the standard, its history, and software implementations across all major operating systems. It positions itself as a trusted, community-driven resource with a long-standing presence in the encryption technology space since 1997. The website is professionally designed with clear navigation and good mobile optimization, reflecting a mature digital presence. However, it lacks explicit privacy, cookie, and terms of service policies, which are important for compliance and user trust. Technically, the site uses modern web technologies including HTML5, CSS3, JavaScript, and the Jekyll static site generator with the Minimal Mistakes theme. It employs HTTPS for secure communication but does not implement advanced security headers or disclose security policies. No tracking or advertising technologies are detected, indicating a privacy-respecting approach. The absence of WHOIS data transparency limits the ability to fully verify domain legitimacy, though the open source presence on GitHub and RFC standard references support authenticity. From a security perspective, the site demonstrates good baseline practices such as HTTPS and no exposed sensitive data. However, it lacks published security policies, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for improving security posture and user confidence. Overall, the website is safe, professional, and trustworthy but could benefit from enhanced transparency and compliance documentation. Strategically, the site should prioritize publishing privacy and cookie policies, adding security headers, and providing clear contact information for security incidents. These steps will strengthen compliance with regulations like GDPR and improve overall trustworthiness in the security community.

85
50
2
70
75
70
100
encryptionemailsecurityopenpgpprivacy+1 more
HTML5CSS3JavaScriptFontAwesome
2025-07-27T03:23:28.386Z
C

Chaos Computer Club Darmstadt e.V.

hackint.org

51
TechnologyGermanysmallMEDIUM

hackint.org operates as a specialized communication network primarily serving the hacker community, offering IRC-based services compliant with IRCv3 standards, along with modern communication transports such as Matrix, Tor, and DN42. The network is managed by Chaos Computer Club Darmstadt e.V., a German non-profit organization, reflecting a community-driven, non-commercial model. The website provides detailed documentation, news updates, and support resources, positioning itself as a niche but trusted platform within the hacker and technology enthusiast ecosystem. From a technical perspective, the site employs standard web technologies including HTML5 and CSS3, and supports modern communication protocols. Hosting is provided by http.net Internet GmbH, a reputable German hosting provider. The site demonstrates good mobile optimization and clear navigation, though accessibility and SEO optimizations are basic. Security-wise, the domain benefits from a long registration history and transfer protection, and TLS 1.3 support is implemented. However, DNSSEC is not enabled, and no security headers or explicit security policies are published, indicating room for improvement in hardening the web presence. Security posture is moderate; while no critical vulnerabilities or malware indicators are present, the absence of privacy and cookie policies, security headers, and incident response information limits compliance and transparency. No contact emails or phone numbers are publicly listed, which may hinder user support and trust. Overall, the site is safe, professional, and trustworthy but would benefit from enhanced security and privacy disclosures to align with best practices and regulatory expectations.

30
35
2
70
85
75
40
hackerircmatrixtorcommunication+2 more
HTML5CSS3IRCv3.1IRCv3.2 (partial)+4
2025-07-27T03:23:23.346Z
M

majava.org

majava.org

61
TechnologyN/asmallMEDIUM

The website majava.org serves as a technical infrastructure hub offering a variety of IT services such as git hosting, mail, DNS, Kubernetes, VM hosting, and monitoring tools. It appears to be a small-scale, possibly community or privately maintained infrastructure platform targeting technical users and infrastructure administrators. The site content is minimalistic but functional, focusing on providing access to various internal and external services rather than marketing or commercial activities. From a technical perspective, the site uses modern web standards including WOFF2 fonts and CSS3, but lacks advanced frameworks or CMS platforms. The infrastructure services mentioned indicate a mature technical environment with Kubernetes, Ganeti, and Proxmox usage. Performance and mobile optimization are basic but adequate for the site's purpose. Security posture is moderate; no forms or inputs reduce attack surface, but the absence of security headers and lack of published security or privacy policies are notable gaps. WHOIS data is unavailable due to malformed queries, which limits domain trust verification and reduces overall legitimacy score. No evidence of HTTPS or SSL configuration was found in the provided data, which is a critical area for improvement. Overall, the site is safe with no adult or questionable content, but it lacks formal privacy, security, and compliance documentation. Strategic improvements in security headers, HTTPS enforcement, and policy publication would enhance trust and compliance.

50
50
2
60
75
85
100
technologyinfrastructuregitkubernetesvmhosting+2 more
woff2 fontsCSS3HTML5Phorge (issue tracking)+3
2025-07-27T03:23:13.294Z
wmflabs.org favicon

Wikimedia Foundation

wmflabs.org

68
TechnologyUnited StateslargeMEDIUM

Wikitech is a technical wiki platform operated by the Wikimedia Foundation, providing detailed documentation and information about Wikimedia's cloud services infrastructure. It serves as a collaborative resource for Wikimedia technical contributors, developers, and system administrators. The platform supports the Wikimedia ecosystem by offering transparent and accessible technical knowledge, reinforcing Wikimedia's position as a leading open knowledge organization. The website is built on the MediaWiki framework, leveraging modern web technologies such as JavaScript, CSS, and HTML5. It is hosted on Wikimedia's own infrastructure, ensuring fast performance, good mobile optimization, and accessibility. The technical maturity of the platform is high, with a focus on usability and clear navigation for its target technical audience. Security posture is strong, with HTTPS enforced and multiple security headers implemented. No vulnerabilities or exposed sensitive data were detected in the analyzed content. Privacy compliance is moderate on this specific page due to the absence of explicit privacy or cookie policies, but Wikimedia Foundation's overall privacy practices are known to be robust. Overall, the website is trustworthy, professional, and well-maintained, supporting Wikimedia's mission through high-quality technical documentation. Strategic recommendations include enhancing privacy policy visibility on all pages and maintaining rigorous security audits to uphold the platform's integrity.

40
68
17
75
75
85
100
overviewscloudserviceswikimediatechnicaldocumentation
MediaWikiJavaScriptCSSHTML5
2025-07-27T03:22:58.185Z
wmcloud.org favicon

Wikimedia Foundation

wmcloud.org

68
TechnologyUnited StateslargeMEDIUM

The website wikitech.wikimedia.org is a technical documentation platform maintained by the Wikimedia Foundation, focusing on cloud services and infrastructure supporting Wikimedia projects. It serves as a resource for developers and technical contributors within the Wikimedia community, providing detailed information about cloud service usage and architecture. The site is part of the broader Wikimedia ecosystem, which is a globally recognized non-profit organization dedicated to free knowledge dissemination. Technically, the site is built on the MediaWiki platform, leveraging standard web technologies such as HTML5, CSS, and JavaScript. The infrastructure is hosted and managed by the Wikimedia Foundation, ensuring reliable performance and security. The website demonstrates good mobile optimization, accessibility, and SEO practices, contributing to a positive user experience. From a security perspective, the site enforces HTTPS, implements key security headers, and shows no signs of vulnerabilities or exposed sensitive data. While no explicit privacy or cookie policies were found on this specific page, the Wikimedia Foundation generally maintains comprehensive privacy practices across its domains. The absence of contact information and policy pages on this particular page slightly reduces privacy compliance scores but does not significantly impact overall trust. Overall, the website is trustworthy, professionally maintained, and aligned with the Wikimedia Foundation's mission. It poses minimal risk and serves as a valuable technical resource. Strategic recommendations include adding clear links to privacy and cookie policies on all pages and providing contact information to enhance transparency and compliance.

40
68
17
75
75
85
100
overviewscloudserviceswikimediatechnicaldocumentation
MediaWikiJavaScriptCSSHTML5
2025-07-27T03:22:53.148Z
K

Hi, I'm karx - karx's website

karx.xyz

46
TechnologyUnited StatessmallHIGH

The website karx.xyz is a personal portfolio site belonging to a computer science student at the University of Texas at Austin. It highlights the individual's skills in programming languages such as Rust, Python, Java, and C, as well as interests in Linux server administration and Docker. The site serves primarily as a showcase for personal projects and professional profiles, targeting technology enthusiasts, potential collaborators, and recruiters. The business model is personal branding and project demonstration, with no commercial transactions or services offered directly on the site. Technically, the site uses modern web technologies including ES modules and the flamethrower-router JavaScript framework to enable smooth page transitions. The hosting is inferred to be via Namecheap, consistent with the domain registrar information. The site is mobile optimized and has a clean, simple design with good navigation clarity. However, SEO and accessibility features are basic, and no CMS or analytics tools are detected. From a security perspective, the site uses HTTPS but lacks advanced security headers and policies such as Content-Security-Policy or X-Frame-Options. There are no privacy or cookie policies, and no incident response or vulnerability disclosure information is provided. The domain is privacy protected, which is reasonable for a personal site, and no suspicious WHOIS patterns are found. Overall, the security posture is moderate but could be improved with standard best practices. The overall risk assessment is low given the non-commercial nature and limited data collection. Strategic recommendations include implementing privacy and cookie policies, adding security headers, enabling DNSSEC, and providing vulnerability disclosure information to enhance trust and compliance.

15
35
17
60
52
75
40
personalportfoliotechnologyrustlinux+1 more
HTML5CSSJavaScript (ES Modules)flamethrower-router
2025-07-27T03:22:28.005Z
skwodo.com favicon

Skwodo's website

skwodo.com

57
TechnologyPolandsmallMEDIUM

The website skwodo.com is a personal portfolio site belonging to a beginner programmer from Poland named Skwodo. The site primarily serves as a personal presence and a showcase of programming interests, focusing on frontend development. It includes links to friends' websites and the source code repository on GitHub. The business model is minimal and personal, with no commercial or enterprise features. The market position is niche and informal, targeting general visitors interested in the author's programming journey. Technically, the site is built using the Zola static site generator, served with HTML, CSS, and JavaScript, and hosted behind Cloudflare DNS servers. The site is basic in design and functionality, with moderate performance and basic mobile optimization. No advanced CMS or analytics tools are detected, indicating a simple and lightweight infrastructure. From a security perspective, the site lacks several best practices such as security headers, privacy and cookie policies, and contact information for incident response. DNSSEC is not enabled, and no vulnerability disclosure or security policy information is present. However, no critical vulnerabilities or blocking mechanisms are detected, and the domain registration details are consistent and appropriate for a personal site. Overall, the site is low risk but also low in professionalism and compliance. Strategic improvements in privacy compliance, security headers, and contact information would enhance trust and security posture.

15
40
2
70
95
80
100
personalportfolioprogrammingstaticsitebeginner+1 more
HTML5CSSJavaScript
2025-07-27T03:22:22.968Z
diyhrt.wiki favicon

Private by Design, LLC

diyhrt.wiki

60
HealthcareUnited StatessmallMEDIUM

The website diyhrt.wiki serves as an informational resource dedicated to providing guidance on DIY Hormone Replacement Therapy (HRT) primarily for transgender individuals. It offers various guides including Transfem and Transmasc hormone therapy, blood testing information, injection supplies, and telehealth resources. The site positions itself as a niche community resource addressing accessibility challenges faced by transgender people in obtaining HRT. The business model is non-commercial, focusing solely on education and support without selling products or services. Technically, the site is built with standard HTML5 and CSS3, leveraging Google Fonts and Cloudflare DNS services. The website demonstrates moderate performance and good mobile optimization with clear navigation and consistent branding. However, it lacks advanced frameworks or CMS platforms and does not implement DNSSEC or visible security headers, which are areas for improvement. From a security perspective, the site uses HTTPS and has domain registration protections in place, but it lacks privacy and cookie policies, security headers, and incident response information. No analytics or tracking scripts were detected, indicating minimal user tracking. The WHOIS data is consistent and transparent, with no privacy protection, aligning with the site's small-scale informational nature. Overall, the security posture is moderate but could be enhanced by implementing DNSSEC, security headers, and compliance documentation. The content is adult-oriented, with an age verification banner restricting access to users 18 or older, but it does not contain explicit or NSFW material. The site is trustworthy for its intended audience but would benefit from improved privacy compliance and security best practices to enhance user trust and regulatory adherence.

25
35
2
85
75
85
100
diyhrttransgenderhormonereplacementtherapyhealthcare+1 more
HTML5CSS3Google Fonts (Comfortaa, Poppins)Cloudflare DNS
2025-07-27T03:21:57.803Z
haskell.org favicon

Haskell.org, Inc.

haskell.org

51
TechnologyN/asmallMEDIUM

Haskell.org is the official home page for the Haskell programming language, a purely functional, statically typed language widely used in academia and industry. The site serves as a comprehensive resource hub offering documentation, downloads, community engagement, and educational tools such as an interactive playground. It is maintained by Haskell.org, Inc., a non-profit organization, and supported by reputable sponsors and partners including Fastly, Status.io, Scarf, DreamHost, and Digital Ocean. The website targets developers and programmers interested in functional programming paradigms and aims to promote the adoption and understanding of Haskell. Technically, the website is well-constructed using modern web technologies including Bootstrap, jQuery, and Glider.js for UI components. It leverages CDN and cloud hosting providers to ensure fast and reliable access globally. The site is mobile-optimized, accessible, and SEO-friendly, providing a smooth user experience. However, explicit privacy and cookie policies are not present, and no contact emails or phone numbers are listed, which could be improved for transparency and compliance. From a security perspective, the site uses HTTPS and has a dedicated security page, but lacks explicit security headers and a published security.txt file for vulnerability disclosure. No obvious vulnerabilities or exposed sensitive data were detected. The WHOIS data for the domain is incomplete or unavailable, which slightly reduces trustworthiness but is mitigated by the site's professional appearance, community trust, and sponsorships. Overall, Haskell.org is a high-quality, trustworthy resource for the Haskell community with strong technical foundations and good security posture. Enhancements in privacy compliance, security header implementation, and WHOIS transparency would further strengthen its credibility and user trust.

45
35
17
60
52
75
40
haskellfunctionalpureprogramminglazy
HTML5CSSJavaScriptBootstrap+5

Partner Domains:

fastly.com
partner
status.io
partner

+3 more partners

2025-07-27T03:21:27.614Z
alia.science favicon

Private by Design, LLC

alia.science

60
OtherUnited StatessmallMEDIUM

The website alia.science is a personal portfolio and blog site titled 'Alia Lescoulie', operated by an entity registered as Private by Design, LLC in the US. The site features sections about the author, projects, and blog posts focused on science, technology, and games. It serves a general audience interested in these topics and functions primarily as a personal showcase and content platform. The domain is newly registered in 2024, consistent with the site's content and scope. Technically, the site is built with basic HTML and CSS without advanced frameworks or CMS detected. Hosting and DNS services appear to be provided by Porkbun, the registrar. The site shows moderate performance and basic mobile optimization but lacks modern security headers and DNSSEC. No analytics or advertising technologies are present, indicating minimal tracking and a privacy-conscious approach. From a security perspective, the site uses HTTPS (assumed but not explicitly confirmed), but no security headers or policies are implemented. There are no privacy or cookie policies, no contact or incident response information, and no vulnerability disclosure mechanisms. The WHOIS data is transparent and consistent with the website content, with no suspicious patterns. Overall, the security posture is basic and could be improved with standard best practices. The overall risk is low given the personal nature and limited data collection, but the site would benefit from adding privacy and security policies, enabling DNSSEC, and improving security headers to enhance trust and compliance.

15
50
17
65
95
85
100
personalblogsciencetechnologyportfolio
HTML5CSS
2025-07-27T03:20:57.424Z
xxiivv.com favicon

Echorridoors

xxiivv.com

53
OtherN/asmallMEDIUM

The website 'Echorridoors' hosted at xxiivv.com is an artistic and experimental project with a focus on ambient and creative content. It references artists and collaborators but does not present itself as a commercial business. The site is minimalistic, with a black background, SVG logo, ambient audio, and links to a wiki and a webring, indicating a niche community or collective. The domain is well established, created in 2008, and hosted on Media Temple servers, suggesting stable infrastructure. Technically, the site uses basic HTML5, CSS3, and SVG graphics with audio autoplay. There is no evidence of modern frameworks or CMS platforms. The site has basic mobile optimization and accessibility but lacks advanced SEO and security headers. No analytics or tracking scripts were detected, indicating minimal user tracking. From a security perspective, the site uses HTTPS (implied by domain and hosting but not explicitly confirmed), but DNSSEC is not enabled. No privacy or cookie policies are present, and no contact or incident response information is provided. The absence of security headers and policies reduces the overall security posture. However, no vulnerabilities or malicious content were detected. Overall, the site is low risk but lacks many standard compliance and security features expected for commercial or data-sensitive websites. Strategic improvements include adding privacy and cookie policies, enabling DNSSEC, implementing security headers, and providing contact information to enhance trust and compliance.

15
50
2
65
62
70
100
artcreativemusicambientexperimental
HTML5SVGCSS3Audio autoplay
2025-07-27T03:20:47.406Z
git.gay favicon

Private by Design, LLC

git.gay

50
TechnologyUnited StatessmallMEDIUM

git.gay is a niche collaboration platform designed to empower queer developers by providing Git hosting, continuous integration, and static site hosting services. Operated by the collective 'besties', it emphasizes community values, open source software, and privacy by avoiding ads and third-party trackers. The platform leverages a fork of Forgejo, ensuring open source transparency and configurability. The website presents a professional and consistent brand image targeting queer and neurodiverse developers, positioning itself as a community-centric alternative to corporate platforms. Technically, git.gay uses modern web technologies including Forgejo, Cloudflare DNS, and custom JavaScript for enhanced user experience and error handling. The site is mobile optimized with good SEO practices and minimal user tracking, reflecting a mature digital infrastructure. However, DNSSEC is not enabled, and security headers are not visibly implemented, indicating areas for improvement in security hardening. From a security perspective, the site enforces HTTPS and employs CSRF tokens, with no detected vulnerabilities or exposed sensitive data. Privacy policies and terms of service are present but basic, and no explicit incident response or vulnerability disclosure policies are published. The absence of cookie consent mechanisms despite script usage suggests a potential compliance gap. Overall, the security posture is solid but could benefit from enhanced transparency and technical controls. The domain registration is transparent and consistent with the business profile, registered to Private by Design, LLC in the US, matching the website's operational claims. The domain age aligns with the platform's founding date, supporting legitimacy. No suspicious WHOIS patterns or privacy protections obscure ownership, enhancing trustworthiness. The platform's focus on community and open source principles further supports a positive risk profile. Strategic recommendations include enabling DNSSEC, implementing comprehensive security headers, publishing detailed security and incident response policies, adding cookie consent mechanisms, and establishing a vulnerability disclosure process. These steps will strengthen security, compliance, and user trust, supporting git.gay's mission as a safe and empowering platform for queer developers.

45
53
2
70
75
75
-
gitforgeforgejoqueeropensource+2 more
Forgejo (fork of Gitea)Cloudflare DNSJavaScriptHTML5+1

Partner Domains:

besties.house
partner
2025-07-27T03:20:27.350Z
servfail.network favicon

SERVFAIL :: main

servfail.network

57
TechnologyN/asmallMEDIUM

Project SERVFAIL is a small-scale, open-source authoritative DNS nameserver network currently in beta. It offers free DNS hosting services with a lightweight, no-JavaScript web interface and a PowerDNS-compatible API for automation. The project is community-driven with collaboration among several contributors and encourages donations and contributions. The website content is technical and targeted at DNS users and beta testers. The market position is niche, focusing on DNS infrastructure enthusiasts and small-scale users. Technically, the website uses basic HTML and CSS without JavaScript, which reduces attack surface but also limits interactivity. The site lacks advanced frameworks or CMS and shows moderate performance and basic mobile optimization. No explicit hosting provider or SSL configuration details were found. The site links to several partner domains and community resources, indicating an active ecosystem. From a security perspective, the site lacks visible HTTPS enforcement and security headers, and no privacy or cookie policies are present, which impacts compliance and trust. The WHOIS data is unavailable or malformed, limiting domain legitimacy verification. No contact emails or phone numbers are provided, reducing transparency. However, the open-source nature and community engagement are positive trust signals. Overall, the site is functional and relevant for its niche but requires improvements in security posture, privacy compliance, and domain transparency to enhance trust and professional credibility.

25
50
2
70
65
85
100
dnsauthoritativenameserveropensourcebetatechnology+1 more
HTML5CSSPowerDNS API

Partner Domains:

famfo.xyz
partner
scholz.ruhr
partner

+2 more partners

2025-07-27T03:20:22.340Z
ezri.pet favicon

Private by Design, LLC

ezri.pet

9
TechnologyUnited StatessmallCRITICAL

The website ezri.pet represents a personal and academic online presence of a 21-year-old computer science student based in New York City. The individual operates a small internet hosting service with its own ASN and is involved in academic research in computer systems and networking. The site serves as a portfolio and contact point, featuring links to various social media and communication platforms, and showcases personal projects and interests. The business model is small-scale and niche, focusing on personal hosting and academic collaboration rather than commercial enterprise. Technically, the website is built with standard HTML5 and CSS using Pure.css for styling, with some JavaScript for interactive elements. It is hosted under a domain registered with Porkbun LLC and uses DNS services from Hurricane Electric and kjsl.com. The site is mobile responsive and well-structured, though it lacks advanced SEO and accessibility features. No CMS or major frameworks are detected, indicating a custom or static site approach. From a security perspective, the site uses domain status flags to prevent unauthorized transfer or deletion but lacks DNSSEC and security headers such as CSP or HSTS. There is no privacy or cookie policy, and no incident response or vulnerability disclosure information is provided. No analytics or advertising scripts are present, indicating minimal tracking and good privacy by default. The domain registration is transparent and consistent with the website's stated purpose, enhancing trustworthiness. Overall, the site is safe, professional, and trustworthy for its intended audience but would benefit from implementing basic privacy and security policies, enabling DNSSEC, and adding security headers to improve its security posture and compliance. The lack of privacy and cookie policies currently limits its privacy compliance score.

-
-
-
-
-
-
-
personalacademictechnologyhostingstudent+1 more
HTML5CSS (Pure.css)JavaScript
2025-07-27T03:19:21.892Z
N

Njalla Okta LLC

cqql.site

35
TechnologySaint Kitts and NevissmallHIGH

The website cqql.site is a personal technical blog operated by an individual or small entity registered as Njalla Okta LLC in Saint Kitts and Nevis. The site focuses on technology-related content including hacking tutorials, generative art, CTF writeups, and queer/trans community resources. It serves a niche audience of technology enthusiasts and members of the queer/trans community interested in technical topics. The business model is content publishing and community engagement without evident commercial transactions. The domain is newly registered in May 2024 with privacy protection, consistent with the website's privacy-conscious theme. Technically, the site is a static HTML/CSS site hosted via Njalla, a privacy-focused hosting provider. The site is basic but functional with good content relevance and navigation clarity. Mobile optimization and accessibility are basic but adequate. No CMS or advanced frameworks are detected. Performance is likely fast due to static content delivery. SEO and metadata are minimal but present. From a security perspective, the site lacks HTTPS enforcement information and security headers in the provided data, which lowers its security posture. No privacy or cookie policies are present, indicating limited compliance with privacy regulations. No forms or data collection mechanisms are detected, reducing exposure to input-based vulnerabilities. The domain registration is legitimate and consistent with the website content and operator profile. No WAF or blocking mechanisms are detected. Overall, the site is a safe, niche personal blog with moderate trustworthiness but could improve security and privacy compliance. Strategic recommendations include implementing HTTPS with HSTS, adding security headers, publishing privacy and cookie policies, and establishing vulnerability disclosure and incident response information to enhance trust and security posture.

-
-
-
60
52
80
20
technologybloghackingctfqueer+2 more
HTML5CSSStatic site
2025-07-27T03:19:05.625Z
msx.gay favicon

Private by Design, LLC

msx.gay

56
OtherUnited StatessmallMEDIUM

The website msx.gay is a personal portfolio and social presence site belonging to an individual known as msxdotgay, a neurodivergent young adult from rural Iowa. The site serves as a platform to share personal projects, photography, writings, and interests including LGBTQ+ identity and cats. The business model is non-commercial and focused on personal expression and community engagement. The domain is registered under Private by Design, LLC, a privacy-focused registrar, consistent with the personal nature of the site. Technically, the site is hosted on Neocities, uses basic HTML, CSS, and JavaScript, and includes a small external script for a cat animation. The site is served over HTTPS but lacks advanced security headers and modern CMS or frameworks. Performance and mobile optimization are basic but functional. No analytics or tracking scripts are present, indicating a privacy-conscious approach. From a security perspective, the site benefits from HTTPS and domain transfer protections but lacks DNSSEC and security headers. There are no forms or data collection points, reducing attack surface. However, the absence of privacy and cookie policies, security.txt, and vulnerability disclosure mechanisms indicates room for improvement in compliance and security transparency. Overall, the site is safe, family-friendly, and trustworthy as a personal website. Strategic recommendations include adding privacy and cookie policies, enabling DNSSEC, implementing security headers, and publishing a security.txt file to enhance security posture and compliance.

40
-
2
70
85
85
100
personallgbtqphotographyprojectscats+4 more
Pop!_OSFedoraWindows 2000/XP/7 (mentioned)HTML5+3
2025-07-27T03:18:34.717Z
dimden.dev favicon

dimden

dimden.dev

57
TechnologyUkrainesmallMEDIUM

The website dimden.dev is a personal portfolio and blog of a Ukrainian programmer known as dimden. It serves as a platform to showcase open source projects, share blog posts, and engage with a community primarily through Discord and Patreon. The site targets programmers, tech enthusiasts, and followers of the author's work. The business model is centered around personal branding, community engagement, and open source contributions, with no direct commercial sales evident. The market position is niche, focusing on a dedicated audience interested in programming and retro-inspired web culture. Technically, the website employs a modern JavaScript-based stack with custom scripts and uses HTTPS with Google Analytics and Tag Manager for tracking. The site is hosted on platforms like Neocities and Nekoweb, with some projects leveraging µWebSockets. Performance is moderate, with basic mobile optimization and accessibility features. SEO is basic but functional, with proper meta tags and Open Graph images. From a security perspective, the site benefits from HTTPS and lacks exposed sensitive data or vulnerable libraries. However, it lacks important security headers such as Content-Security-Policy and Strict-Transport-Security, and does not provide privacy or cookie policies, which impacts compliance. No vulnerability disclosure or incident response information is available. Overall, the security posture is moderate but could be improved with standard best practices. The overall risk is low given the personal nature of the site and absence of sensitive transactions or user data collection. Strategic recommendations include implementing security headers, adding privacy and cookie policies, and establishing a vulnerability disclosure process to enhance trust and compliance.

15
35
2
85
65
75
100
personalblogprogrammingjavascriptopensource+2 more
JavaScriptHTML5CSS3Google Analytics+2

Partner Domains:

ourworldofpixels.com
partner
discord.gg
partner

+3 more partners

2025-07-27T03:18:24.648Z
F

Lea's Game Archive • /

futacockinside.me

55
OtherGermanysmallMEDIUM

The website futacockinside.me operates as a personal game archive titled "Lea's Game Archive". It hosts various directories of game files across multiple platforms, accessible only after password authentication. The site is clearly intended for personal use rather than commercial purposes, with no evident business or contact information provided. The domain is relatively new, registered in 2022, and the hosting setup includes suspicious nameservers that may pose security concerns. The site uses a custom analytics script but lacks standard privacy and cookie policies, which impacts its compliance posture. Technically, the site is built with basic HTML, CSS, and JavaScript, including Google Fonts for styling. It is moderately optimized for mobile devices but lacks advanced SEO and accessibility features. No CMS or major frameworks are detected. The hosting provider is not clearly identified beyond the registrar and suspicious DNS configuration. Performance appears moderate with no major errors or broken elements. From a security perspective, the site lacks DNSSEC, security headers, and visible HTTPS enforcement details, which lowers its security posture. The use of suspicious nameservers and absence of privacy or security policies further reduce trustworthiness. However, no WAF or blocking mechanisms are detected, and the content is safe with no adult or explicit material. Overall, the site is functional but has significant gaps in security and compliance best practices. The overall risk assessment suggests caution due to DNS and security configuration concerns. Strategic recommendations include improving DNS security, implementing HTTPS and security headers, adding privacy and cookie policies, and providing clear contact information to enhance trust and compliance.

45
35
2
70
52
85
100
gamearchivepersonalusepasswordprotectedgamefilesanalytics
HTML5CSS3JavaScriptGoogle Fonts (Fira Mono)
2025-07-27T03:18:19.638Z
T

Lexi's Archive • /

transgendersurgeri.es

43
OtherN/asmallHIGH

The website transgendersurgeri.es serves as a personal archive platform titled "Lexi's Archive" that hosts various directories and files intended for private use. It employs a password-protected mechanism to restrict downloads, indicating a focus on controlled access rather than public business operations. The site lacks any business branding, contact information, or commercial content, positioning it as a personal or small group resource rather than a commercial entity. Technically, the site is built with basic HTML, CSS, and JavaScript, utilizing the Fira Mono font and a third-party analytics script from lea.pet. The design is minimalistic with basic mobile responsiveness and limited SEO optimization. No CMS or advanced frameworks are detected. The site does not display any privacy or cookie policies, nor does it provide contact or legal information, which limits its compliance posture. From a security perspective, the site uses a numeric key-based password protection for downloads and sets cookies with SameSite=Strict attributes, which is a positive practice. However, there is no visible enforcement of HTTPS or security headers, and no privacy or cookie consent mechanisms are present. The WHOIS data is inaccessible due to Red.es restrictions, preventing verification of domain registration details and reducing trustworthiness. No WAF or blocking mechanisms are detected, and the content is accessible without challenge. Overall, the site scores low on business credibility and privacy compliance, with moderate technical implementation and security posture. It is safe in terms of content, containing no adult or explicit material. Strategic recommendations include implementing HTTPS, publishing privacy and cookie policies, adding contact information, and enhancing security headers to improve trust and compliance.

15
25
2
40
52
75
100
personalarchivepassword-protectedfile-hostingminimal
HTML5CSS3JavaScriptFira Mono font+1
2025-07-27T03:17:59.562Z
B

brodokk.space

brodokk.space

49
TechnologyFrancesmallHIGH

The website brodokk.space serves as a personal homepage for an individual known as Brodokk, who identifies as a Fennec fox persona. The site highlights personal and professional programming activities, server management, and participation in various online communities and projects. The content is straightforward, primarily textual with some images, and links to multiple social media and community platforms. The website is small-scale and targeted at a general audience interested in technology and creative online communities. From a technical perspective, the site is built with basic HTML and CSS, hosted by Gandi SAS, and does not use any advanced frameworks or CMS. The site is moderately optimized for mobile devices and accessibility but lacks advanced SEO and performance optimizations. No analytics or advertising technologies are detected, indicating a privacy-conscious or minimalistic approach. Security posture is basic; the domain uses HTTPS (implied by the URL), but no DNSSEC is enabled, and no security headers are present. There are no forms or data collection points, reducing attack surface but also limiting user interaction. The WHOIS data is transparent and consistent with the website's personal nature, with no privacy protection used. No privacy or cookie policies are present, which is a compliance gap. Overall, the website is low risk, safe for general audiences, and serves as a personal portfolio and community hub. Strategic recommendations include improving security headers, adding privacy and cookie policies, enabling DNSSEC, and enhancing mobile and accessibility features to improve user experience and compliance.

15
35
2
85
72
80
40
personaltechnologyprogrammingcommunityportfolio
HTML5CSS
2025-07-27T02:17:22.406Z
akselmo.dev favicon

Akseli Lahtinen

akselmo.dev

48
TechnologyN/asmallHIGH

The website akselmo.dev is a personal blog authored by Akseli Lahtinen, focusing on topics such as gaming, game development, free and open source software (FOSS), and programming. It serves a niche audience of gamers, developers, and open source enthusiasts. The blog has a consistent and professional presentation with a rich archive of posts dating back to 2016, indicating a well-established presence in its domain. The business model is primarily content sharing without commercial transactions or services. Technically, the site is built with standard web technologies (HTML, CSS, JavaScript) and uses Goat Counter for privacy-respecting analytics. The site appears to be hosted on Hetzner, inferred from blog content, and is likely a static or custom-built blog without a CMS. The site is performant, mobile-optimized, and SEO-friendly, though accessibility features are basic. From a security perspective, the site uses HTTPS and does not expose sensitive data or forms. However, no explicit security headers were detected, and no privacy or cookie policies are present, which are areas for improvement. The domain registration data is consistent with the website content and author identity, supporting high legitimacy and trustworthiness. Overall, the site is low risk with good content quality and technical implementation but would benefit from enhanced privacy compliance and security best practices to improve user trust and regulatory adherence.

15
50
2
70
52
75
40
gaminggamedevfossprogrammingpersonalblog+1 more
HTML5CSS3JavaScript
2025-07-27T02:17:02.313Z
noscript.net favicon

Giorgio Maone

noscript.net

10
TechnologyN/asmallCRITICAL

NoScript.net is the official website for the NoScript Security Suite, a free and open-source browser extension that enhances user security by blocking malicious scripts and allowing trusted content only. The project is well-established since 2005 and is integrated into the Tor Browser, positioning it as a trusted tool in the privacy and security software market. The website targets privacy-conscious users and security experts seeking enhanced browser protection. The business model is donation-based, emphasizing free software principles. Technically, the website is built with standard web technologies (HTML, CSS, JavaScript) and supports multiple major browsers. The site is well-structured, mobile-optimized, and accessible, with good SEO practices. However, some modern security enhancements like DNSSEC are not enabled, and no explicit security headers were detected in the provided data. The site does not appear to use any CMS or complex frameworks, reflecting a lightweight and focused technical infrastructure. From a security perspective, the website promotes strong security practices through its product, including script blocking and anti-XSS protections. However, the site itself lacks published privacy, cookie, or security policies, and no contact information or vulnerability disclosure mechanisms are provided. DNSSEC absence and missing security headers represent minor security gaps. Overall, the security posture is good but could be improved with better transparency and technical hardening. The overall risk assessment is low given the nature of the site and its content. Strategic recommendations include publishing privacy and cookie policies, enabling DNSSEC, adding security headers, and providing clear contact and vulnerability disclosure information to enhance trust and compliance.

-
-
-
-
-
-
-
securitybrowserextensionnoscriptopensource+5 more
HTML5CSSJavaScript
2025-07-27T02:15:42.006Z
O

Open Camera (Mark Harman)

opencamera.org.uk

56
TechnologyUnited KingdomsmallMEDIUM

Open Camera is a small-scale, open source software project focused on providing an advanced camera application for Android devices. The website serves primarily as an informational and download portal, featuring detailed descriptions of app features, licensing, and links to source code repositories. The business model is based on free software distribution with revenue generated through website advertising. The target audience is Android users seeking enhanced camera functionality beyond stock apps. Technically, the website is a static site hosted by 123-Reg Limited, utilizing standard web technologies such as HTML, CSS, and JavaScript. It integrates Google services including Analytics, Tag Manager, and Adsense for tracking and monetization. The site is mobile-optimized with a basic but functional design and navigation structure. However, it lacks advanced CMS features and some modern security headers. From a security perspective, the site uses HTTPS (implied by domain and Google services usage) and implements cookie consent with anonymized IP tracking for analytics, indicating some privacy awareness. However, no explicit security policies, incident response contacts, or vulnerability disclosure mechanisms are present. The absence of security headers and contact information for security incidents suggests room for improvement in security posture. Overall, the website is trustworthy and professionally maintained for its niche purpose but would benefit from enhanced security practices and clearer privacy compliance documentation. The domain registration data supports legitimacy with consistent and long-term ownership.

15
95
2
60
42
60
100
opensourceandroidcameraphotographytechnology+3 more
HTML5CSSJavaScriptGoogle Analytics+2
2025-07-27T02:15:26.962Z