Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 226 of 408|Showing 11251-11300 of 20393
A

Air France France

airfrance.fr

63
TransportationFranceenterpriseMEDIUM

Air France is a leading French airline offering flight booking services to over 230 destinations worldwide. The website serves as the official platform for ticket reservations, travel deals, and customer support, targeting general travelers and business customers. The site reflects Air France's strong market position as part of the Air France-KLM group, with a consistent brand presence and comprehensive service offerings. Technically, the website employs modern web technologies including Angular and Material Design components, ensuring a responsive and accessible user experience. The infrastructure supports good performance and SEO optimization, with mobile-friendly design and accessibility features. Security posture is robust, with HTTPS enforced, strong security headers, and cookie consent mechanisms in place. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is well addressed with clear privacy and cookie policies, including GDPR adherence and a visible data protection officer contact. Overall, the website demonstrates high professionalism, trustworthiness, and business credibility, suitable for an enterprise-level airline service. Strategic recommendations include publishing a public incident response policy and vulnerability disclosure framework to enhance transparency and security readiness.

-
40
17
85
90
85
100
airlinetravelbookingflightstransportation+2 more
AngularMaterial Design ComponentsJavaScriptJSON-LD+2

Partner Domains:

airfrance-klm.com
parent
transavia.com
subsidiary

+1 more partners

2025-07-22T07:40:19.970Z
pycoders.com favicon

PyCoder’s Weekly

pycoders.com

68
TechnologyN/asmallMEDIUM

PyCoder’s Weekly is a well-established online newsletter service focused on delivering weekly Python programming news and articles to a large community of over 171,000 subscribers. Founded in 2012, it serves Python developers and enthusiasts with curated content via a free email subscription model. The website is professionally designed with consistent branding and clear navigation, supporting a positive user experience and strong market positioning within the Python community. Technically, the site employs a modern tech stack including Bootstrap, jQuery, and Google Analytics for tracking, hosted with Cloudflare DNS and registered via NameCheap. The site is mobile optimized and uses HTTPS with CSRF protection on forms, indicating a reasonable level of digital maturity. However, some improvements could be made in accessibility and security headers to enhance protection. From a security perspective, the website demonstrates good practices such as HTTPS enforcement and domain transfer protection. There are no visible vulnerabilities or exposed sensitive data. However, the absence of DNSSEC, security policies, incident response contacts, and cookie consent mechanisms suggests room for improvement in compliance and transparency. Overall, PyCoder’s Weekly presents a trustworthy and professional online presence with a solid foundation but could benefit from enhanced security policies and privacy compliance measures to further strengthen its risk posture.

55
53
17
85
75
80
100
pythonnewsletteremailtechnologyprogramming
HTML5CSS3JavaScriptjQuery+4
2025-07-22T07:38:24.014Z
W

Wingware

wingware.com

67
TechnologyUnited StatessmallMEDIUM

Wingware is a specialized software company focused on developing Wing Python IDE, a comprehensive integrated development environment tailored exclusively for Python developers. With over 25 years of experience, Wingware offers advanced features such as AI-assisted coding, powerful debugging, remote development support, and integrated unit testing, targeting a broad audience including scientific researchers, web developers, and game developers. The company operates primarily through software licensing and support services, maintaining a strong niche position in the Python development tools market. Technically, the website employs a traditional web stack with jQuery and JavaScript, delivering a professional and accessible user experience. The site is hosted under a reputable registrar with HTTPS enforced and basic security headers implemented. While the site lacks advanced security headers and cookie consent mechanisms, it demonstrates good foundational security practices and a clean, well-structured design optimized for desktop and basic mobile use. From a security perspective, Wingware shows a mature posture with no evident vulnerabilities or exposed sensitive data. The domain registration is consistent with the business claims, and the website content is fully accessible without WAF or blocking mechanisms. However, the absence of explicit security policies, incident response contacts, and cookie consent indicates areas for improvement in compliance and transparency. Overall, Wingware presents a trustworthy and professional online presence with strong business credibility and technical quality. Strategic enhancements in privacy compliance and security policy publication would further strengthen their security posture and user trust.

45
53
17
75
77
85
100
pythonidesoftwaredevelopmentprogrammingtechnology
jQuery 3.7.1jQuery Tools 1.2.7JavaScriptHTML5+1
2025-07-22T07:38:19.004Z
talkpython.fm favicon

PDX Web Properties, LLC

talkpython.fm

65
TechnologyUnited StatessmallMEDIUM

Talk Python To Me is a well-established podcast platform focused on Python programming and related technologies, hosted by Michael Kennedy and operated by PDX Web Properties, LLC. The business offers a rich backlog of podcast episodes, online Python training courses, live streams, and branded merchandise, targeting Python developers, data scientists, and hobbyists. The company maintains a strong community presence with active social media channels and a professional, consistent brand image. The domain age and registrant information align well with the business history, supporting legitimacy and trustworthiness. Technically, the website employs modern web standards including HTML5, CSS3, JavaScript, and Bootstrap framework, with assets delivered via a CDN (bunny.net) for performance optimization. The site is mobile-optimized, accessible, and SEO-friendly, with structured data (JSON-LD) implemented for enhanced search engine visibility. Analytics are handled via Umami, a privacy-focused tool, indicating moderate user tracking with basic privacy compliance. From a security perspective, the site uses HTTPS and has domain transfer protections enabled, but lacks DNSSEC and published security policies or incident response contacts. No cookie consent mechanism or terms of service page was found, which are areas for improvement to enhance compliance and user trust. No vulnerabilities or suspicious content were detected, and the site is free from adult or questionable content. Overall, the website demonstrates a high level of professionalism, content quality, and business credibility, with room for improvement in privacy compliance and security transparency. The risk profile is low, with recommendations focusing on enhancing privacy notices, security disclosures, and DNS security features.

60
53
2
85
52
85
100
podcastpythoneducationtechnologytraining+1 more
HTML5CSS3JavaScriptFontAwesome Pro+2

Partner Domains:

training.talkpython.fm
subsidiary
pythongear.com
partner

+2 more partners

2025-07-22T07:38:08.958Z
cherrypy.dev favicon

The CherryPy team

cherrypy.dev

58
TechnologyN/asmallMEDIUM

CherryPy is an established open-source Python web framework project with a long history dating back to 2001. The website serves as an informational and resource hub for developers interested in using CherryPy, offering documentation, downloads, community links, and development resources. The project targets Python developers seeking a minimalist and pythonic web framework. The business model is primarily open-source with an enterprise subscription offering via Tidelift, indicating a hybrid approach to monetization. Technically, the website is simple, fast, and hosted on GitHub Pages. It uses standard web technologies including HTML5, CSS, and Google Fonts. The framework itself supports multiple Python platforms and versions, emphasizing flexibility and stability. The site is mobile optimized and provides clear navigation and relevant content for its audience. From a security perspective, the site does not expose forms or sensitive data, which reduces attack surface. However, no privacy or cookie policies are present, and no security headers were detected in the provided data, indicating room for improvement in security best practices. The domain registration data is consistent with the website content and supports legitimacy. No WAF or blocking mechanisms were detected. Overall, the website is professional, trustworthy, and serves its target audience well but would benefit from enhanced privacy compliance and security hardening to improve trust and regulatory adherence.

15
35
2
70
85
75
100
pythonwebframeworkopensourcecherrypysoftwaredevelopment
PythonWSGIHTML5CSS+1
2025-07-22T07:35:28.009Z
N

Nikola contributors

getnikola.com

61
TechnologyN/asmallMEDIUM

Nikola is an established open-source static site generator project founded in 2013, providing a Python-based tool for developers and content creators to build static websites efficiently. The website serves as a comprehensive resource with documentation, add-ons, and community support channels, positioning itself as a niche but mature player in the static site generation space. The business model revolves around free software distribution with community-driven development and support. Technically, the site is built with modern web standards including Bootstrap and FontAwesome, and leverages Cloudflare DNS for hosting infrastructure. The site is performant, mobile-optimized, and accessible, with a clean and professional design. Analytics are minimal, using StatCounter, and no intrusive advertising or tracking is present. From a security perspective, the site uses HTTPS and domain status locks but lacks DNSSEC and security headers. No forms collect sensitive data on the main page, and no explicit security or incident response policies are published. Privacy compliance is limited, with no cookie consent mechanism and only a basic license page serving as a privacy reference. Overall, the website is trustworthy and professional, suitable for its technical audience. However, improvements in privacy compliance, security headers, and vulnerability disclosure policies would enhance its security posture and user trust.

40
35
17
65
65
85
100
staticsitegeneratoropensourcepythondevelopertoolssoftware+1 more
Python 3HTML5CSSJavaScript+3
2025-07-22T07:35:17.940Z
mobileportland.com favicon

YouTube / Google

mobileportland.com

72
TechnologyN/aenterpriseMEDIUM

The analyzed page is a consent management interface hosted on the subdomain consent.youtube.com, which is part of YouTube, owned by Google LLC. The page is designed to manage user consent for cookies and privacy preferences, complying with GDPR and other privacy regulations. It is a minimalistic, functional page that integrates tightly with Google's infrastructure and services. The business behind the page is a global technology leader in online video sharing and advertising, with a strong market position and extensive user base. Technically, the page leverages modern web technologies including JavaScript, Material Design Components, and Google APIs. It is hosted on Google Cloud infrastructure, ensuring fast performance and high availability. The page is mobile-optimized and uses HTTPS to secure communications. While explicit security headers are not visible in the provided data, Google's standards imply strong security practices. From a security perspective, the page shows no signs of vulnerabilities or blocking by WAFs. The domain is legitimate, being a subdomain of youtube.com, a well-established domain owned by Google. Privacy compliance is indicated by the presence of consent management functionality, although explicit privacy and cookie policies were not found on this specific page. No contact information or incident response details are present. Overall, the page represents a secure, trustworthy, and professionally maintained component of YouTube's privacy compliance framework. It poses minimal risk and aligns with industry best practices for consent management.

90
50
2
85
75
90
100
consentyoutubegoogleprivacycookie+1 more
JavaScriptHTML5CSS3Google APIs
2025-07-22T07:33:36.850Z
donutjs.club favicon

Proxy Protection LLC

donutjs.club

54
OtherUnited StatessmallMEDIUM

Donut.js was a community-driven monthly meetup based in Portland, Oregon, focused on technology, creativity, and community engagement. The organization ran from 2016 to early 2020, hosting 38 events and 125 talks, and contributed financially to local social good organizations. The website serves as an archive and farewell message, reflecting a small, local community group rather than a commercial enterprise. The domain registration aligns well with the business history and location, indicating legitimacy and stable ownership. Technically, the website is a simple static site built with standard HTML, CSS, and JavaScript, hosted on DreamHost. It is mobile-optimized with good design and navigation clarity but lacks advanced frameworks or CMS. No analytics, advertising, or tracking technologies are present, reflecting a privacy-conscious approach or minimal digital footprint. Performance is moderate with basic accessibility features. From a security perspective, the site uses a domain status that prevents unauthorized transfers but lacks DNSSEC and visible security headers. There is no published privacy, cookie, or security policy, and no contact information for incident response or data protection officers. These gaps reduce compliance and security posture scores. However, no critical vulnerabilities or suspicious patterns were detected. Overall, the site is trustworthy for its purpose as a community archive but would benefit from improved privacy and security disclosures if it were to resume active operations or collect user data.

15
35
2
70
72
70
100
communitytechmeetupportlandjavascriptevents+1 more
HTML5CSS3JavaScript
2025-07-22T07:33:16.761Z
indielogin.com favicon

IndieLogin.com

indielogin.com

47
TechnologyN/asmallHIGH

IndieLogin.com is a specialized technology service that enables users to sign in to applications using their own domain names, leveraging the IndieAuth protocol and fallback authentication methods such as Twitter, GitHub, email, or PGP keys. The service targets developers and website owners seeking decentralized and domain-based authentication solutions. The website is well-structured, with clear navigation and professional design, and it openly links to its GitHub repository, indicating transparency and open source development. Technically, the site uses a modern frontend stack including Bootstrap 4.1.0, jQuery 3.3.1, and FontAwesome 5.0.8, hosted on Linode with domain registration via NameCheap. The site is mobile-optimized and performs moderately well, though some SEO and accessibility features could be improved. Security posture is adequate with HTTPS enabled and domain transfer protection, but lacks advanced security headers and DNSSEC. No cookie consent or detailed privacy compliance mechanisms are present. Security-wise, the site shows no critical vulnerabilities or exposed sensitive data. However, it lacks a published security policy, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for improving trust and compliance. The domain age and registration details align well with the business history, supporting legitimacy. Overall, IndieLogin.com presents a trustworthy, niche authentication service with good technical implementation and moderate security maturity. Strategic improvements in privacy compliance, security headers, and incident response transparency would enhance its security posture and user trust.

15
53
2
60
52
75
40
authenticationindieauthloginwebsign-inopensource
HTML5CSS3Bootstrap 4.1.0jQuery 3.3.1+1
2025-07-22T07:32:56.690Z
kivy.org favicon

OVH sas

kivy.org

48
TechnologyFrancesmallHIGH

Kivy.org represents the official website for Kivy, an open source Python framework designed for rapid development of cross-platform GUI applications. The project is mature, founded in 2010, and hosted by OVH sas in France. It targets developers and businesses seeking to build multi-touch and innovative user interfaces across Windows, Linux, macOS, iOS, and Android platforms. The business model is community-driven, supported by contributors and backers, with sponsorship options available. The website demonstrates a consistent brand and a strong community presence via GitHub and social media channels. Technically, the site uses modern web technologies including Vue.js and Axios, with good mobile optimization and fast performance. Hosting is provided by OVH sas, a reputable provider. SEO and accessibility are basic to good, though no CMS is detected. The site lacks explicit privacy and cookie policies, which is a compliance gap. No security headers were detected in the provided data, and DNSSEC is not enabled, indicating room for security improvements. From a security perspective, the site uses HTTPS and has domain registration protections like clientDeleteProhibited and clientTransferProhibited statuses. However, the absence of security headers, privacy policies, and vulnerability disclosure mechanisms reduces the overall security posture. No critical vulnerabilities or suspicious patterns were found. The WHOIS data is consistent and legitimate, supporting trustworthiness. Overall, Kivy.org is a professional, trustworthy, and technically sound website supporting a well-established open source project. Strategic improvements in privacy compliance, security headers, and incident response transparency would enhance its security and compliance standing.

45
35
2
40
72
75
40
opensourcepythonguiframeworkcross-platformtechnology+1 more
HTML5CSS3JavaScriptVue.js+2
2025-07-22T06:30:41.264Z
xon.sh favicon

Private by Design, LLC

xon.sh

54
TechnologyUnited StatessmallMEDIUM

Xonsh is an open source project offering a modern, Python-powered shell environment that combines the power of Python 3.6+ with traditional shell primitives. The project targets developers, DevOps professionals, and system administrators seeking a versatile and cross-platform shell alternative. The website serves as a hub for documentation, downloads, community engagement, and extension discovery (xontribs). The business operates under Private by Design, LLC, based in the US, with a domain registered since 2016, reflecting a mature and stable presence. Technically, the website employs a modern front-end stack including Bootstrap, jQuery, and integrates GitHub APIs to dynamically display community extensions. It supports multiple platforms including Linux, macOS, and Windows. The site is mobile optimized with good SEO practices but lacks advanced accessibility features. Performance is moderate with no critical technical debt observed. From a security perspective, the site uses HTTPS and has domain-level protections like clientDeleteProhibited status but lacks DNSSEC and security headers. There are no published privacy, cookie, or security policies, which represents a compliance gap. No incident response or vulnerability disclosure information is available. Analytics usage is minimal and privacy impact low. No adult or questionable content is present, making the site safe for general audiences. Overall, the website is professional, trustworthy, and well-positioned within its niche. However, improvements in privacy compliance, security headers, and published policies would enhance its security posture and regulatory adherence.

15
35
2
60
62
75
100
xonshpythonshellopensourcedevelopertoolsshell+2 more
HTML5CSS3 (Bootstrap, icofont, animate.css)Python (implied by product)GitHub API integration (for dynamic xontribs list)+2
2025-07-22T06:30:06.082Z
openstack.org favicon

OpenStack

openstack.org

66
TechnologyN/alargeMEDIUM

OpenStack is a prominent open source cloud computing infrastructure project, recognized as one of the most active open source initiatives globally. The website serves as a hub for developers, IT professionals, and enterprises interested in cloud infrastructure solutions. It offers information about the project, community, and enterprise support options. The business model revolves around open source software development and community collaboration, positioning OpenStack as a key player in the cloud technology sector. Technically, the website is built using modern web technologies such as Gatsby (React-based static site generator) and Font Awesome for icons. The site demonstrates good design quality, mobile optimization, and SEO practices, although some accessibility features could be improved. Performance is moderate, with no evident blocking or WAF interference. From a security perspective, the site lacks visible security headers and explicit privacy or cookie policies in the provided content. WHOIS data is unavailable due to query failure or privacy protection, which is common for open source projects but limits direct verification of registrant details. No critical vulnerabilities or exposed sensitive data were detected, but improvements in security best practices and compliance documentation are recommended. Overall, OpenStack's website is trustworthy and professional, reflecting its status in the technology industry. Strategic recommendations include enhancing security headers, publishing clear privacy and cookie policies, and providing incident response and vulnerability disclosure information to strengthen user trust and compliance posture.

65
83
17
70
65
55
100
React (Gatsby)Font AwesomeGoogle FontsCSS3+1
2025-07-22T06:30:01.064Z
pypi.org favicon

Python Software Foundation

pypi.org

75
TechnologyUnited StateslargeMEDIUM

The Python Package Index (PyPI) is a critical infrastructure platform operated by the Python Software Foundation, serving as the official repository for Python software packages. It enables developers to find, install, and publish Python packages, supporting the global Python community. The platform is well-established with a domain age since 2015 and strong backing by reputable sponsors such as AWS, Google, and Fastly, reflecting its market leadership and trustworthiness. Technically, PyPI employs a modern technology stack including JavaScript, CSS, and custom Python-based Warehouse software, hosted on AWS with Fastly CDN for performance optimization. The website is well-optimized for mobile and accessibility, with good SEO practices and fast performance. The use of HTTPS and reputable DNS providers enhances its security posture, although DNSSEC is not enabled. From a security perspective, PyPI demonstrates strong practices such as HTTPS enforcement and domain transfer protection. However, there is room for improvement by enabling DNSSEC, adding security headers, and publishing a security.txt file to facilitate vulnerability disclosures. No critical vulnerabilities or exposed sensitive data were detected. Overall, PyPI presents a high level of professionalism, security, and compliance with privacy policies. It is a trusted platform for Python developers worldwide. Strategic recommendations include enhancing DNS security, formalizing incident response information, and improving transparency around security policies to further strengthen trust and resilience.

90
53
2
85
100
85
100
pythonpackageindexopensourcesoftwarerepositorydevelopertools
JavaScriptCSSHTML5FontAwesome+4
2025-07-22T06:29:25.391Z
A

ASIN.cc

asin.cc

44
TechnologyN/asmallHIGH

ASIN.cc is a small technology-focused website offering a specialized utility service for shortening Amazon product links using ASIN or ISBN-10 codes. The service emphasizes computed shortlinks that are programmatically determinable, providing robustness over traditional database-stored shortlinks. The site targets Amazon shoppers, affiliate marketers, and developers who require concise Amazon URLs. The business model appears to be a free tool, potentially monetized through affiliate marketing or traffic generation. Technically, the website is built with basic HTML, CSS, and JavaScript, hosted on DreamHost. It uses no detected CMS or advanced frameworks. The site performs well with fast loading times but has only basic mobile optimization and accessibility features. SEO is minimal but sufficient for its niche purpose. No analytics or advertising scripts were detected, indicating minimal user tracking. From a security perspective, the site uses HTTPS but lacks DNSSEC and important security headers such as Content-Security-Policy and Strict-Transport-Security. There are no published privacy, cookie, or security policies, nor incident response or vulnerability disclosure information. The absence of contact information limits user trust and compliance with privacy regulations. The WHOIS data is consistent and indicates a legitimate domain with a long registration period. Overall, ASIN.cc is a functional niche utility with a moderate security posture and limited compliance maturity. Strategic improvements in security headers, privacy policies, and contact transparency would enhance trust and compliance.

15
35
2
70
62
75
20
amazonasinlinkshortenere-commerceutility
JavaScriptCSSHTML5
2025-07-22T06:27:03.680Z
M

Micropub Rocks!

micropub.rocks

47
TechnologyN/asmallHIGH

Micropub Rocks! is a specialized online validator tool designed to assist developers and implementers in testing their Micropub client and server implementations. The website provides various testing capabilities and publishes implementation reports, targeting a niche audience within the IndieWeb and Micropub community. The business model is based on offering an open source, freely accessible validation service, with no evident commercial monetization or advertising. The site is small in scale and founded around 2016, consistent with the domain registration date. Technically, the website uses a straightforward technology stack including HTML5, CSS with Semantic UI, and JavaScript with jQuery. Hosting is provided by Linode, a reputable VPS provider. The site is moderately optimized for mobile and performance, with basic accessibility and SEO features. The code is open source and publicly available on GitHub, enhancing transparency. From a security perspective, the site lacks several modern security best practices such as DNSSEC, security headers, and visible SSL/TLS configuration details. The domain is privacy protected, which is reasonable for a small open source project. The site uses an email-based sign-in mechanism with a simple anti-bot field to facilitate authorization testing without complex authentication flows. No privacy or cookie policies are present, which is a compliance gap. No incident response or vulnerability disclosure information is provided. Overall, the website is functional and trustworthy within its niche but would benefit from improved security hardening and privacy compliance. The risk level is low given the nature of the site and its limited data collection. Strategic improvements in security headers, DNSSEC, and privacy documentation would enhance trust and compliance.

20
50
2
70
52
70
40
micropubvalidatoropensourcetechnologydevelopertools
HTML5CSS (Semantic UI)JavaScriptjQuery
2025-07-22T06:25:58.212Z
W

Webmention Rocks!

webmention.rocks

44
TechnologyIcelandsmallHIGH

Webmention Rocks! is a niche technical website providing a validator and test suite for the Webmention protocol, primarily targeting developers and implementers within the IndieWeb and web standards communities. The site offers a variety of tests for endpoint discovery, updates, deletes, and receiver functionality, and encourages users to submit implementation reports to the W3C. It is open source and hosted on Linode, with a domain registered in 2016 and privacy protection enabled. From a technical perspective, the website uses a classic web stack including jQuery 1.11.3 and Semantic UI for styling and interactivity. The site is moderately performant, mobile optimized, and has a clear navigation structure. However, accessibility and SEO optimizations are basic. No CMS is detected, indicating a custom or static site. Security posture is moderate; the domain uses clientTransferProhibited status to prevent unauthorized transfers but lacks DNSSEC and visible security headers. No privacy or cookie policies are present, and no contact information is provided for security incidents or general inquiries. There are no signs of vulnerabilities or malicious content, and the site content is safe for general audiences. Overall, the website is a credible and useful tool within its niche but would benefit from improved security practices, privacy compliance, and contact transparency to enhance trust and compliance.

15
50
2
60
42
70
40
webmentionvalidatoropensourcewebstandardsdevelopertool
jQuery 1.11.3Semantic UIHTML5CSS3+1
2025-07-22T06:25:53.204Z
M

Micropub

micropub.net

45
TechnologyN/asmallHIGH

Micropub.net serves as an informational website dedicated to the Micropub open API standard, which enables users to create posts on their own domains using third-party clients. The site primarily targets developers and members of the IndieWeb community interested in decentralized social web publishing. It provides links to the official specification, test suites, and implementation reports, positioning itself as a niche resource within the technology standards space. The website is simple and content-focused, reflecting its role as a documentation and community resource rather than a commercial entity. From a technical perspective, the site is hosted on Linode with domain registration through NameCheap, Inc. The technology stack is minimal, consisting of static HTML and CSS without advanced frameworks or CMS platforms. Performance and mobile optimization are basic but adequate for the site's purpose. SEO and accessibility features are minimal but sufficient given the limited scope of content. Security posture is moderate but could be improved. The site lacks DNSSEC, security headers, and privacy or cookie policies, which are important for compliance and user trust. No contact or incident response information is provided, limiting transparency in security matters. The domain is well aged and registered without privacy protection, which aligns with the open and community-driven nature of the project, supporting legitimacy. Overall, micropub.net is a trustworthy and safe resource for its intended audience but would benefit from enhanced security practices and compliance documentation to improve user trust and meet modern web standards.

15
50
2
60
52
70
40
apiopenstandardindiewebw3cmicropub+1 more
HTML5CSS3
2025-07-22T06:25:37.742Z
W

Webmention

webmention.net

43
TechnologyN/asmallHIGH

Webmention.net serves as an informational hub for the Webmention protocol, a W3C Social Web Working Group specification contributed by the IndieWeb community. The site provides links to the latest published versions, drafts, and implementations of the protocol, targeting developers and web technologists interested in decentralized social web standards. The website is minimalistic, focusing on content delivery rather than commercial services or user engagement features. Technically, the site is hosted on Linode with domain registration through NameCheap, indicating a stable and reputable infrastructure. The technology stack is basic, consisting primarily of HTML and CSS, with no detected CMS or advanced frameworks. Performance and mobile optimization are moderate to basic, reflecting the simple nature of the site. From a security perspective, the site lacks advanced security headers, privacy policies, cookie consent mechanisms, and contact information for incident response. DNSSEC is not enabled, which is a recommended improvement for domain security. No analytics or tracking technologies are present, which reduces privacy concerns but also limits business intelligence capabilities. Overall, the website is safe and trustworthy for its intended audience but would benefit from enhanced security practices, privacy compliance documentation, and improved technical sophistication to better serve its community and maintain trust.

15
40
17
60
42
70
40
webmentionw3cindiewebwebprotocolsocialweb
HTML5CSS
2025-07-22T06:25:32.694Z
O

Okta, Inc.

oauth2simplified.com

51
TechnologyUnited StatessmallMEDIUM

OAuth2Simplified.com is a specialized educational website dedicated to providing comprehensive guidance on building OAuth 2.0 servers. The site offers a variety of resources including a well-regarded book authored by Aaron Parecki, online courses on OAuth and advanced security topics, and related merchandise. The business is positioned as a niche authority in the OAuth and API security space, targeting developers, architects, and technical professionals interested in secure API authorization frameworks. The site is published by Okta, Inc., a recognized leader in identity and access management, lending strong credibility to the content and offerings. Technically, the website is well-constructed with modern HTML5 and CSS, uses reputable third-party services such as MailChimp for email marketing and Fathom Analytics for privacy-focused analytics, and is hosted on Linode, a reliable cloud provider. The site is mobile optimized and demonstrates good SEO and accessibility practices. Security posture is solid with HTTPS enforced and no visible vulnerabilities, though it lacks some security headers and formal privacy and cookie policies, which are areas for improvement. No contact emails or phone numbers are explicitly provided, which may impact user trust and compliance. Overall, the website is professional, trustworthy, and serves as a valuable resource in its domain, but would benefit from enhanced privacy compliance and security policy disclosures.

15
35
2
85
72
80
40
oauthoauth20securityapiauthorization+3 more
HTML5CSSGoogle FontsMailChimp (email signup form)+1
2025-07-22T06:25:27.684Z
A

Aaron Parecki

aaronpk.tv

46
MediaN/asmallHIGH

Aaron Parecki operates a personal brand website focused on livestreaming tutorials, gear reviews, and consulting services. The site targets livestreaming enthusiasts and professionals seeking expert advice and educational content. The business model combines content creation with paid consulting and affiliate marketing, positioning Aaron Parecki as a niche expert in the media space. The website is well-branded, content-rich, and supported by active social media channels, enhancing its market presence. Technically, the website is built using standard web technologies including HTML5, CSS3, JavaScript, and jQuery, hosted on Linode infrastructure. The design is responsive and user-friendly, with embedded video content and calendar integration. Analytics are handled via privacy-focused Fathom Analytics, indicating a moderate level of digital maturity. However, the site lacks CMS usage and some modern security headers, which could be improved. From a security perspective, the site uses HTTPS and avoids exposing sensitive data. The domain is privacy protected but consistent with a personal brand site. No security or incident response policies are published, and no cookie or privacy policies are present, representing compliance gaps. DNSSEC is not enabled, and security headers are missing, suggesting room for security posture enhancement. Overall, the website is trustworthy, professional, and safe for general audiences. Strategic improvements in privacy compliance, security headers, and formal policies would strengthen its security and regulatory posture, supporting long-term business credibility and user trust.

15
35
2
70
62
65
40
livestreamtutorialsvideoconsultingmedia+1 more
HTML5CSS3JavaScriptjQuery+1

Partner Domains:

photojoseph.com
partner
heretorecord.com
partner

+2 more partners

2025-07-22T06:24:27.451Z
ref-bl.ch favicon

Evangelisch-reformierte Kirche Basel-Landschaft

ref-bl.ch

67
GovernmentSwitzerlandmediumMEDIUM

The Evangelisch-reformierte Kirche Basel-Landschaft operates a professional and well-structured website serving its community in Basel-Landschaft, Switzerland. The site provides comprehensive information about church services, community engagement, and social support, targeting members and prospective members of the regional church. The organization positions itself as a key religious and non-profit entity in the region, with clear branding and consistent messaging. Technically, the website employs modern web technologies including UIkit, jQuery, and FontAwesome, supported by a CloudTec CMS platform. It integrates privacy-conscious analytics via Matomo and implements a robust cookie consent mechanism through Cookiebot, reflecting a mature digital infrastructure. The site is mobile-optimized and SEO-friendly, though some accessibility improvements could be made. From a security perspective, the website enforces HTTPS and uses a Content-Security-Policy header, ensuring a good baseline security posture. However, additional security headers and explicit incident response information are absent. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with a detailed GDPR-compliant privacy policy and user consent mechanisms. Overall, the website is trustworthy, professionally maintained, and aligned with the organization's mission. Strategic enhancements in security headers, incident response transparency, and accessibility would further strengthen its posture.

65
83
2
60
62
80
100
HTML5CSS3JavaScriptCookiebot+3
2025-07-22T05:23:14.095Z
P

pin13

pin13.net

44
TechnologyN/asmallHIGH

pin13.net is a personal and technical utility website primarily focused on providing developer tools such as a Microformats parser, character counter, JSON prettifier, Instagram caption formatter, and number base converter. The site is closely associated with Aaron Parecki, a known figure in the IndieWeb and OAuth communities, as evidenced by multiple links to his personal projects and related technical standards. The website targets developers and technical users interested in microformats and web standards. The business model is personal and utility-focused without commercial complexity, relying on affiliate links such as Amazon referrals. Technically, the site uses a simple stack with HTML, CSS, JavaScript, and jQuery 1.3.2, hosted on Linode servers. While functional, the technology is somewhat outdated, particularly the jQuery version, which may expose the site to security vulnerabilities. The site lacks modern security headers and DNSSEC, and there is no visible privacy or cookie policy, which limits compliance with privacy regulations. Google Analytics is used for tracking, and an Amazon affiliate program is integrated. From a security perspective, the site is accessible without WAF or blocking mechanisms, but it lacks advanced security features such as CSP, HSTS, and CSRF protections. The absence of DNSSEC and use of an outdated JavaScript library are notable weaknesses. No sensitive data exposure or critical vulnerabilities were detected, but improvements are recommended to enhance security posture and privacy compliance. Overall, pin13.net is a small, niche technical site with moderate trustworthiness and basic security. Strategic improvements in security practices, privacy policies, and technology modernization would enhance its reliability and compliance.

15
35
2
50
62
80
40
technologydeveloper-toolsindiewebmicroformatspersonal-site
HTML5CSSJavaScriptjQuery 1.3.2+2
2025-07-22T05:15:45.462Z
aaronparecki.com favicon

Aaron Parecki

aaronparecki.com

54
TechnologyUnited StatessmallMEDIUM

Aaron Parecki's website serves as a comprehensive professional portfolio highlighting his leadership in identity standards, OAuth, and OpenID communities. The site targets developers and security professionals interested in identity protocols and related technologies. It features extensive content including articles, presentations, and personal projects, establishing a strong market position as a thought leader in technology standards. The business model is primarily personal branding and consulting with a focus on education and community engagement. Technically, the website is well-constructed using modern web technologies such as Semantic UI, jQuery, and JSON-LD structured data. It is hosted on Linode, ensuring reliable performance and fast loading times. The site is mobile-optimized and accessible, with good SEO practices and minimal user tracking, leveraging privacy-respecting analytics. From a security perspective, the site enforces HTTPS and uses domain transfer protection, but lacks DNSSEC and explicit security headers. There is no published security policy or incident response contact, and privacy and cookie policies are absent, which may impact compliance with regulations like GDPR. No vulnerabilities or suspicious patterns were detected, and the WHOIS data aligns well with the website's claims, indicating legitimacy. Overall, the website demonstrates high professionalism and trustworthiness with excellent content quality and technical implementation. Strategic improvements include adding privacy and cookie policies, enabling DNSSEC, publishing security policies, and implementing security headers to enhance compliance and security posture.

25
35
17
85
62
80
40
oauthidentitytechnologyindiewebopenid+3 more
HTML5CSS3JavaScriptjQuery 1.12.0+6
2025-07-22T05:15:40.443Z
microformats.io favicon

Microformats : Meaningful HTML

microformats.io

42
TechnologyN/asmallHIGH

Microformats.io is an open community-driven project focused on providing simple, semantic HTML standards to enhance web content meaning and interoperability. The website serves primarily as an educational and resource hub for developers interested in microformats, offering specifications, parser libraries, and community support. The project is positioned as a niche but important contributor to web standards and semantic web technologies. Technically, the website is built with modern HTML5 and Bootstrap CSS, hosted on Linode infrastructure. It demonstrates good mobile optimization and clear navigation, though some accessibility features could be improved. The site lacks advanced security headers and DNSSEC, representing areas for technical enhancement. No CMS or complex backend technologies are detected. From a security perspective, the site uses HTTPS (implied by domain and standard practice), but no explicit security headers or policies are present. The WHOIS data shows privacy protection, which is reasonable for this type of open project. No vulnerabilities or exposed sensitive data were found. However, the absence of privacy and cookie policies indicates compliance gaps, especially regarding GDPR. Overall, the website is trustworthy and professional for its purpose but would benefit from improved security practices and privacy compliance documentation. The risk level is low given the non-commercial, informational nature of the site, but strategic improvements are recommended to enhance trust and security posture.

15
35
2
60
42
70
40
microformatshtmlsemanticwebwebstandardsopensource+1 more
HTML5Bootstrap CSSCustom CSS
2025-07-22T05:15:35.421Z
tasty-group.ch favicon

Tasty Group AG

tasty-group.ch

55
TechnologySwitzerlandmediumMEDIUM

Tasty Group AG is a Swiss syndicate of digital agencies specializing in digital design, video production, web development, and online marketing. The company consolidates multiple Swiss agencies under its umbrella, positioning itself as an established player in the Swiss digital services market. The website presents a professional image with clear branding and links to its subsidiary agencies, targeting businesses seeking comprehensive digital agency services in Switzerland. Technically, the website is built with standard HTML5, CSS3, and JavaScript, without reliance on advanced frameworks or CMS platforms. The site is moderately optimized for mobile devices and offers a good user experience with clear navigation. However, there is no evidence of advanced analytics, marketing tools, or tracking technologies, indicating a minimal data collection approach. From a security perspective, the site lacks published privacy and cookie policies, security headers, and incident response information, which are critical for compliance and trust. SSL status is unknown from the provided data, and no vulnerability disclosures or security.txt files are present. These gaps suggest room for improvement in security posture and regulatory compliance. Overall, the website is safe and professional but would benefit from enhanced privacy compliance, security best practices, and transparency measures to strengthen trust and reduce risk.

30
50
2
60
52
75
100
digitalagencywebagencyexplainervideoeventswitzerland+1 more
HTML5CSS3JavaScript

Partner Domains:

comvation.com
subsidiary
cleverclipstudios.com
subsidiary

+2 more partners

2025-07-22T04:13:22.029Z
gasinsideinformationplatform.pl favicon

Gas Inside Information Platform (GIIP)

gasinsideinformationplatform.pl

71
EnergyPolandsmallMEDIUM

Gas Inside Information Platform (GIIP) operates as a specialized platform dedicated to wholesale energy market participants, facilitating compliance with the REMIT regulation (EU) No 1227/2011 by providing a channel for disclosure of inside information. The platform is recognized and listed by the Agency for the Cooperation of Energy Regulators (ACER), positioning it as a trusted service provider within the European energy regulatory ecosystem. The website content clearly targets energy market participants requiring regulatory compliance services, offering key services such as publishing Urgent Market Messages and client onboarding. Technically, the website employs a standard modern web stack including HTML5, CSS, JavaScript, jQuery, and Bootstrap 3.3.7. It integrates Google Analytics for visitor tracking and implements a cookie consent mechanism compliant with EU regulations. Hosting is provided by OVH SAS, a reputable registrar and hosting provider. The site demonstrates moderate performance and good mobile optimization, though accessibility features are basic. SEO practices are present but could be enhanced. From a security perspective, the site enforces HTTPS and uses CSRF tokens in meta tags, indicating attention to secure form handling. However, DNSSEC is not enabled, and security headers are not explicitly detected, suggesting room for improvement in hardening the site against common web threats. No explicit security or incident response policies are published, and no vulnerability disclosure mechanisms are evident. Privacy compliance is basic but present, with clear privacy and cookie policies and a consent banner. Overall, the website is legitimate, professional, and trustworthy with no signs of malicious or adult content. The domain registration data aligns well with the business timeline and sector. Recommendations include enabling DNSSEC, adding security headers, publishing security policies, and enhancing accessibility and SEO for improved user experience and security posture.

95
83
17
40
77
75
100
energyremitinsideinformationplatformwholesaleenergymarketcompliance+1 more
HTML5CSSJavaScriptjQuery+3
2025-07-22T04:08:25.851Z
westmetall.com favicon

Westmetall GmbH & Co. KG

westmetall.com

47
ManufacturingGermanysmallHIGH

Westmetall GmbH & Co. KG operates as a specialized supplier and trader of non-ferrous metals, including primary metals, wires, cables, semi-finished products, and scrap metals. The company targets businesses in the metal trading and recycling sectors, offering direct access to international metal markets with a focus on price advantages and risk reduction. The website presents a professional and consistent brand image with clear navigation and relevant business content. Technically, the website is built using depage-cms v2.6.1 with standard HTML, CSS, and JavaScript. The site shows moderate performance and basic mobile optimization. SEO practices are adequately implemented with proper meta tags and keywords. However, no advanced analytics or tracking technologies are detected, indicating a minimal user tracking approach. From a security perspective, the site lacks visible security headers and cookie consent mechanisms, which are important for GDPR compliance and overall security posture. The WHOIS data is missing, which raises concerns about domain legitimacy and trustworthiness. No contact emails or phone numbers are explicitly provided on the homepage, limiting direct communication channels. Overall, the website is functional and business-appropriate but would benefit from enhanced security measures, improved privacy compliance, and clearer contact information to strengthen trust and credibility.

15
53
2
85
62
75
20
westmetallnon-ferrousmetalsmetaltradingscrapmetalrecycling+1 more
HTML5CSSJavaScript
2025-07-22T04:07:25.495Z
kirchenbote-online.ch favicon

Kirchenbote Online

kirchenbote-online.ch

64
MediaSwitzerlandsmallMEDIUM

Kirchenbote Online is a regional Swiss media platform focused on church-related news and cultural topics across several cantons including Baselland, Basel-Stadt, Luzern, Schaffhausen, Schwyz, Solothurn, Uri, and Zug. The website offers news articles, event agendas, book recommendations, and digital e-paper services targeting residents and church community members interested in religious and societal issues. The platform maintains partnerships with other cantonal church news providers, enhancing its regional presence. Technically, the website employs modern web technologies including Bootstrap, jQuery, Google Tag Manager, and Google reCAPTCHA for bot protection. It features a cookie consent mechanism compliant with GDPR standards, ensuring user privacy choices are respected. The site is mobile-optimized with good navigation and professional design, though some accessibility and SEO aspects could be improved. From a security perspective, the site enforces HTTPS and uses cookie consent with opt-in. However, it lacks explicit security headers and a published security policy or incident response contact. No vulnerabilities or exposed sensitive data were detected. The WHOIS data aligns well with the website's business focus, indicating legitimacy and trustworthiness. Overall, Kirchenbote Online presents a professional, trustworthy, and GDPR-compliant media platform with moderate technical sophistication and a solid security posture. Opportunities exist to enhance security headers, publish terms of service, and improve accessibility and SEO for better user experience and compliance.

15
83
17
70
72
75
100
churchnewsregionalmediaswitzerland+3 more
HTML5CSS3JavaScriptBootstrap+4

Partner Domains:

www.kirchenbote-sg.ch
partner
www.kirchenbote-tg.ch
partner

+2 more partners

2025-07-22T03:03:16.649Z
refbl.ch favicon

Evangelisch-reformierte Kirche des Kantons Basel-Landschaft

refbl.ch

69
GovernmentSwitzerlandmediumMEDIUM

The Evangelisch-reformierte Kirche des Kantons Basel-Landschaft operates as a regional religious institution serving the Basel-Landschaft canton in Switzerland. The organization provides a broad range of community and spiritual services including church communities, pastoral care, social services, and educational programs. Their website is professionally designed, content-rich, and targets members and interested individuals within the local community. The institution maintains an active social media presence and complies with GDPR and cookie consent regulations, reflecting a mature digital presence. Technically, the website leverages modern web technologies including HTML5, CSS3, JavaScript, jQuery, and the Uikit framework, hosted on a CloudTec CMS platform. It employs Matomo for analytics and Cookiebot for cookie consent management, indicating a focus on privacy compliance. The site is mobile-optimized and performs moderately well, with good SEO and accessibility features. From a security perspective, the website enforces HTTPS and implements a Content-Security-Policy header, but lacks additional security headers and publicly available security policies or incident response information. No vulnerabilities or exposed sensitive data were detected. The WHOIS data aligns well with the website's identity, supporting legitimacy and trustworthiness. Overall, the website presents a low-risk profile with strong business credibility and privacy compliance. Strategic improvements in security headers, incident response transparency, and vulnerability disclosure could further enhance its security posture and trustworthiness.

65
83
2
60
72
85
100
religionchurchcommunitynon-profitswitzerland+2 more
HTML5CSS3JavaScriptjQuery+4
2025-07-22T03:03:06.560Z