Skip to main content

High-risk security reports

Browse 46,362 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155885
Websites
130
Industries
113
Countries
52
Avg Score
Page 23 of 928|Showing 1101-1150 of 46362
B

Benchmark Group

benchmark-group.co.uk

48
OtherN/asmallHIGH

The domain benchmark-group.co.uk is currently not registered and is parked by GoDaddy.com. The website content is minimal, consisting solely of a parking page with no active business presence or content. The page includes a Trustpilot widget linking to GoDaddy's reviews and some Yahoo advertising, but no company-specific information or services are offered. The domain WHOIS lookup failed due to the domain name violating Nominet UK's naming rules, indicating the domain is not legitimately registered. Technically, the site uses basic JavaScript and CSS assets related to the parking service, with no advanced CMS or frameworks detected beyond the parking system scripts. The site lacks HTTPS information and security headers, and no forms or data collection mechanisms are present. Mobile optimization and accessibility are basic, reflecting the minimal nature of the page. From a security perspective, the site has a very low posture due to the absence of HTTPS, security headers, and any privacy or cookie compliance mechanisms. No contact or incident response information is provided. The domain's legitimacy is highly questionable as it is not registered, and the WHOIS data confirms this. Overall, the site represents a placeholder with no active business or security maturity. The overall risk is low in terms of direct threats but high in terms of trust and credibility. Strategic recommendations include registering a valid domain, implementing HTTPS and security headers, adding privacy and cookie policies, and providing clear business and contact information to establish legitimacy and trust.

100
62
60
60
53
25
2
parkeddomaindomainparkinggodaddytrustpilotyahooads
JavaScriptTrustpilot widget
2026-07-14T07:21:42.837Z
G

Logo-123Reg-Contrast

gdsteel.co.uk

49
OtherN/asmallHIGH

The website gdsteel.co.uk currently serves as a parked domain landing page hosted by 123 Reg, with no active business content or services presented. The domain registration appears problematic as the WHOIS lookup failed due to domain naming rules violations, indicating the domain may not be properly registered or is reserved. The page contains minimal content, primarily advertising and a call to purchase the domain, with no contact or company information available. From a technical perspective, the site uses JavaScript and React-based scripts served by 123 Reg's parking platform. There is no evidence of HTTPS or security headers, and no forms or data collection mechanisms are present. The site is mobile responsive at a basic level but lacks SEO optimization and accessibility features. Security posture is weak due to the absence of HTTPS, security headers, and any security best practices. Privacy compliance is minimal with only a basic privacy policy link and no cookie consent mechanisms. The lack of registrant data and domain registration issues further reduce trustworthiness. Overall, the site poses low risk but also offers no business value or credibility. Strategic recommendations include securing proper domain registration, implementing HTTPS, adding security headers, and providing clear business and contact information to improve trust and compliance.

57
70
70
100
25
53
2
parkeddomain123regdomainparkingplaceholder
JavaScriptReact
2026-07-14T07:20:59.528Z
charlesmilnes.co.uk favicon

Charles Milnes & Company Ltd

charlesmilnes.co.uk

44
MediaUnited KingdomsmallHIGH

Charles Milnes & Company Ltd is a specialized insurance brokerage firm focused on media, technology, production, and professional services sectors. With over 20 years of experience, the company offers tailored insurance solutions including cyberliability, production insurance, and professional indemnity. Their market position is that of a trusted niche broker with a strong client base and FCA authorization, emphasizing personalized and knowledgeable service. The website is built on a modern WordPress platform with Jetpack and Mapbox integrations, demonstrating a good level of digital maturity. The site is well-designed, mobile-optimized, and provides clear navigation and rich content relevant to their target audience. Technical implementation is solid, though there is room for improvement in security headers and cookie consent mechanisms. Security posture is generally good with HTTPS enforced and secure form handling, but lacks explicit security policies and incident response contacts. The absence of WHOIS data due to domain registration errors introduces some uncertainty about domain legitimacy, though the website content and business information appear professional and credible. Overall, the risk assessment is moderate with recommendations to enhance security headers, implement cookie consent for GDPR compliance, and clarify domain registration details to improve trust and compliance.

70
27
60
40
15
2
58
insurancemediatechnologyriskmanagementprofessionalservices+2 more
WordPress 7.0.1Jetpack pluginMapbox GL JSSmooth Back To Top Button plugin+3
2026-07-14T07:19:33.897Z
A

Security Verification

acerlandscapes.co.uk

47
OtherN/asmallHIGH

The website www.acerlandscapes.co.uk is currently inaccessible beyond a security verification page implementing Google reCAPTCHA v3, indicating the presence of a Web Application Firewall or bot mitigation service blocking direct access. The WHOIS lookup for the domain failed with an error from the Nominet UK registry stating the domain name is invalid due to naming rules, suggesting the domain may not be properly registered or is misconfigured. No business, contact, privacy, or cookie policy information is available on the page, limiting the ability to assess the company's legitimacy or compliance posture. Technically, the site uses Bootstrap 5.3.3 and Google reCAPTCHA v3 for bot protection, but no other technologies or CMS platforms are detectable. The lack of visible security headers, HTTPS information, or privacy policies indicates a weak security and compliance posture. The website's content quality and user experience are poor due to the blocking mechanism preventing access to actual content. Security-wise, the site benefits from reCAPTCHA to mitigate automated abuse but lacks other visible security best practices such as security headers or documented incident response policies. The domain's questionable registration status further reduces trustworthiness. Overall, the site scores low on security, privacy, and business credibility metrics, primarily due to the blocking mechanism and missing WHOIS data. Strategically, the site requires immediate remediation to resolve domain registration issues, improve transparency with privacy and contact information, and enhance security headers and HTTPS configuration. Without these improvements, the site risks poor user trust and potential compliance violations.

57
100
70
60
2
50
15
securitycaptchabotprotectionwafblocked
Bootstrap 5.3.3Google reCAPTCHA v3
2026-07-14T07:19:12.435Z
callund.com favicon

Callund Consulting Ltd.

callund.com

48
GovernmentUnited KingdomsmallHIGH

Callund Consulting Ltd. is a UK-based independent consulting firm specializing in actuarial, economic, and policy advice related to pensions and social security reform. Founded in 1975, the company serves governments, social institutions, and enterprises primarily in frontier markets, often supported by international donors. Their expertise spans actuarial advice, policy development, capital markets, IT, and insurance consulting, with a strong international footprint across more than 50 countries. The website reflects a professional consulting business with clear service offerings and a focus on sustainable social security systems. Technically, the website is built on WordPress using the Divi theme and includes common plugins such as Contact Form 7 and a cookie notice plugin. The site is accessible, mobile-optimized, and includes a cookie consent mechanism. However, the technology stack is somewhat dated (e.g., jQuery 1.12.4) and lacks advanced security headers. Performance is moderate, and SEO and accessibility are basic but functional. From a security perspective, the site enforces HTTPS and uses nonce tokens in forms, but lacks visible security headers like CSP or HSTS. The WHOIS data for the domain is missing, indicating potential domain expiration or privacy protection, which raises concerns about domain legitimacy. No explicit security or incident response policies are published, and no vulnerability disclosure mechanisms are present. Overall, while the business content and presentation are professional and credible, the missing WHOIS data and limited security policies reduce trustworthiness. Strategic improvements in domain registration transparency, security headers, and privacy documentation are recommended to enhance the security posture and compliance.

100
55
75
-
15
50
17
consultingpensionssocialsecurityactuarialpolicy+3 more
WordPress 5.5.18Divi Theme 4.4.9jQuery 1.12.4Contact Form 7 plugin+1
2026-07-14T07:17:08.891Z
darkegroup.co.uk favicon

Darke Group Ltd

darkegroup.co.uk

42
ManufacturingUnited KingdommediumHIGH

Darke Group Ltd is a UK-based company specializing in bespoke steel fabrications and complex architectural metalwork, serving architects, designers, contractors, and developers. The company offers a comprehensive range of services including structural steelwork, architectural metalwork, steel boats, staircases, balconies, handrails, and balustrades. Established in 2009, Darke Group holds a strong market position as a leading UK provider in its sector, supported by accreditations and client testimonials. The website reflects a professional and consistent brand image with good content quality and clear navigation. Technically, the website is built on WordPress using common plugins such as Slider Revolution and Contact Form 7. It employs modern JavaScript libraries like jQuery and integrates Google Analytics and Tag Manager for user tracking. Hosting is provided by Fasthosts Internet Ltd, a reputable registrar. The site demonstrates moderate performance and good mobile optimization but lacks some advanced accessibility features. From a security perspective, the site uses HTTPS with good SSL configuration but lacks visible security headers and an incident response contact. There is no cookie consent mechanism despite having a cookie policy, which may affect GDPR compliance. No vulnerabilities or exposed sensitive data were detected in the HTML content. Overall, the security posture is adequate but could be improved with additional headers and formal incident response procedures. The overall risk assessment indicates a trustworthy and professional business website with minor compliance and security gaps. Strategic recommendations include implementing security headers, adding a cookie consent mechanism, establishing an incident response contact, and maintaining up-to-date software to enhance security and compliance posture.

65
55
-
52
68
15
2
architecturalmetalworksteelfabricationconstructionbalconiesstaircases+3 more
jQuerySlider RevolutionContact Form 7PrettyPhoto+2
2026-07-14T07:16:26.179Z
scottish-rowing.org.uk favicon

Scottish Rowing

scottish-rowing.org.uk

47
Non-profitUnited KingdomsmallHIGH

Scottish Rowing serves as the official governing body for rowing in Scotland, overseeing the sport's governance, development, and promotion across the country. The organization supports approximately 28 affiliated clubs and a membership base of around 2,500 individuals. Their services include organizing competitions, supporting coaching and volunteer efforts, and providing resources related to safety and wellbeing. The website reflects a well-structured, community-focused non-profit entity with a clear mission to develop rowing in Scotland. Technically, the website is built on the Joomla CMS platform, utilizing common web technologies such as jQuery and FontAwesome. The site demonstrates good mobile optimization and moderate performance, with a clean and professional design. However, some improvements could be made in accessibility and the implementation of security headers. The site uses HTTPS with a valid SSL configuration, ensuring secure communications. From a security perspective, the website shows a solid baseline with HTTPS and CSRF token usage, but lacks advanced security headers and a cookie consent mechanism, which are important for compliance and protection. No vulnerabilities or exposed sensitive data were detected in the provided content. The absence of WHOIS data for the queried www subdomain is due to an invalid query rather than a security concern, as the main domain likely exists and is properly registered. Overall, Scottish Rowing's website is trustworthy and professional, serving its community effectively. Strategic recommendations include enhancing privacy compliance with cookie consent, adding security headers, publishing incident response and security policies, and clarifying WHOIS information by querying the correct domain. These steps will strengthen the site's security posture and regulatory compliance while maintaining user trust.

55
65
47
20
53
27
30
rowingsportsgoverningbodyscotlandnon-profit+2 more
Joomla CMSjQueryFontAwesomeCamera slideshow plugin+1
2026-07-14T07:15:38.107Z
tigerlilytraining.co.uk favicon

Tigerlily Training Ltd

tigerlilytraining.co.uk

48
EducationUnited KingdommediumHIGH

Tigerlily Training Ltd is a well-established UK-based provider of specialist first aid training courses for individuals and businesses. Founded in 2010, the company offers a wide range of accredited courses including First Aid at Work, Paediatric First Aid, Mental Health First Aid, Fire Marshal training, and Food Hygiene. Their business model focuses on delivering training both at their venues across the UK and in-house at client workplaces, targeting a broad audience from individuals to corporate clients. The website demonstrates a strong market position supported by extensive customer reviews and active social media engagement. Technically, the website employs a modern JavaScript stack including jQuery, Knockout.js, and various UI libraries for a responsive and interactive user experience. It integrates analytics and marketing tools such as Google Analytics, Google Tag Manager, Facebook SDK, and LiveChat, indicating a mature digital infrastructure. The site is mobile-optimized with good SEO and accessibility practices, although some accessibility features could be enhanced. From a security perspective, the site uses HTTPS with a good SSL configuration and includes several security best practices such as secure forms and no exposed sensitive data. However, some security headers like Content-Security-Policy and X-Frame-Options are not explicitly detected and could be improved. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR adherence. Contact information is transparent and professional, enhancing business credibility. Overall, Tigerlily Training Ltd presents a trustworthy, professional, and secure online presence with a comprehensive offering in the education sector. The website quality, business credibility, and security posture are strong, with minor recommendations for security header enhancements and ongoing third-party script audits to maintain security integrity.

65
47
65
20
17
68
15
firstaidtrainingeducationhealthcareuk+5 more
jQueryKnockout.jsMoment.jsGoogle Analytics+6
2026-07-14T07:15:16.736Z
filpumps.co.uk favicon

Filpumps

filpumps.co.uk

48
EnergyUnited KingdommediumHIGH

Filpumps is a Scottish engineering specialist with over 35 years of experience, focusing on pump systems and fluid solutions for water, wastewater, and industrial applications. Their services include borehole drilling, water treatment, pump and tank specialist services, and engineering support, targeting homes, farms, and industrial sectors primarily in Scotland. The company operates an online shop for pumps and related products, reinforcing their business model of combining service and product sales. The website is professionally designed with consistent branding and clear navigation, reflecting a medium-sized enterprise with a strong local market position. Technically, the website is built on WordPress with WooCommerce and leverages modern marketing and analytics tools such as Google Analytics, Microsoft Clarity, HubSpot, and MailerLite. The site is mobile-optimized and SEO-friendly, though performance is moderate. Security-wise, the site uses HTTPS with valid SSL certificates and employs reCAPTCHA for form protection. However, it lacks visible security headers and explicit privacy or cookie policies, which are areas for improvement. The security posture is solid but could be enhanced by implementing security headers, publishing incident response and vulnerability disclosure policies, and improving privacy compliance. No critical vulnerabilities or exposed sensitive data were detected. Overall, the site is trustworthy and professional but would benefit from enhanced transparency and security best practices. Strategically, Filpumps should focus on improving privacy and cookie policy disclosures, implementing security headers, and formalizing incident response procedures to strengthen compliance and trust. Continued investment in technical modernization and accessibility will support sustained growth and market leadership.

65
62
20
70
15
2
73
engineeringpumpswaterwastewaterborehole+4 more
WordPressWooCommerceYoast SEOSlider Revolution+6
2026-07-14T07:14:23.208Z
colemanbuilding.co.uk favicon

Coleman Building Company LLP

colemanbuilding.co.uk

45
Real EstateUnited KingdomsmallHIGH

Coleman Building Company LLP is a well-established high-end building contractor based in Hampshire, UK, with a history dating back to 1977. The company specializes in bespoke new builds, extensions, and refurbishment projects, targeting clients seeking luxury residential construction services. Their website reflects a professional and consistent brand image, showcasing key team members and client testimonials that reinforce their market position. Technically, the website is built on WordPress using Elementor, with modern libraries such as jQuery and Swiper.js. Hosting is provided by GoDaddy, and the site uses HTTPS with a good SSL configuration. However, there is room for improvement in security headers and privacy compliance, as no cookie consent mechanism or security policies are published. From a security perspective, the site is accessible without WAF or blocking mechanisms, but lacks some best practices such as security headers and incident response information. No vulnerabilities or exposed sensitive data were detected. Overall, the site is secure but could enhance its posture by adopting additional security controls and privacy compliance features. The overall risk is moderate with no critical issues detected. Strategic recommendations include implementing security headers, adding cookie consent, publishing security and incident response policies, and maintaining regular updates to plugins and themes to mitigate vulnerabilities.

55
27
65
20
40
53
25
constructionbuildingcontractorhampshirenewbuildsextensions+2 more
WordPressElementorjQuerySwiper.js+1
2026-07-14T07:13:56.579Z
G

Gordon Associates

gordonassociates.co.uk

43
TechnologyUnited KingdomsmallHIGH

Gordon Associates is a UK-based software development company specializing in mission-critical, large-scale web applications primarily for multi-national businesses and the education sector. Their offerings include bespoke software solutions and a suite of products tailored for awarding organisations, exam boards, trade associations, and training providers. The company positions itself as a provider of business solutions that integrate seamlessly with client operations, emphasizing quality and client satisfaction. Technically, the website is built on WordPress CMS, utilizing Bootstrap for responsive design, Google Fonts for typography, and common plugins such as Yoast SEO and Contact Form 7 with Google reCAPTCHA for form security. The site is HTTPS secured with a valid SSL certificate, though it lacks some advanced security headers. Performance and mobile optimization are good, with clear navigation and professional design. From a security perspective, the site demonstrates basic best practices such as HTTPS and CAPTCHA integration but lacks security headers and a cookie consent mechanism. The WHOIS data is unavailable due to domain registration issues, which introduces some uncertainty regarding domain legitimacy. No major vulnerabilities or exposed sensitive data were detected. Overall, the website presents a professional and trustworthy business front with room for improvement in privacy compliance and security hardening. The domain registration irregularity is a concern but does not directly impact the visible business operations or content.

65
57
-
70
15
58
2
softwareeducationtechnologybespokesoftwarewebdevelopment
BootstrapjQueryGoogle FontsYoast SEO plugin+2
2026-07-14T07:08:00.913Z
inspectionsystemservices.co.uk favicon

Inspection System Services

inspectionsystemservices.co.uk

46
ManufacturingUnited KingdomsmallHIGH

Inspection System Services (ISS) is a UK-based specialist company providing metal detection and check weighing inspection services primarily to the food production industry. Established in 1996, ISS offers a range of services including maintenance contracts, consultancy, training, equipment sales, and technical support. The company positions itself as a trusted partner to major UK food producers and retailers, emphasizing safety and compliance. The website reflects a professional business presence with clear service offerings and client logos, targeting UK food manufacturers and retailers. Technically, the website is built on WordPress with modern plugins such as Yoast SEO and uses Google Analytics and Google Tag Manager for tracking. The site is mobile-optimized and has good SEO practices but lacks some advanced accessibility features. Hosting is provided by 123-Reg Limited, consistent with the UK location. Performance is moderate with standard modern web technologies. From a security perspective, the site uses HTTPS and does not expose sensitive data in the HTML. However, it lacks important security headers like Content-Security-Policy and HSTS, and no privacy or cookie policies are published, which is a compliance risk under GDPR. No incident response or vulnerability disclosure information is available. The site uses tracking technologies but does not provide explicit user consent mechanisms. Overall, the website is professional and trustworthy but requires improvements in privacy compliance and security hardening to reduce risk and enhance user trust. Adding privacy and cookie policies, security headers, and incident response information would strengthen the security posture and regulatory compliance.

70
57
60
40
53
15
2
inspectionmetaldetectioncheckweighingfoodproductionconsultancy+3 more
WordPress 7.0.1Yoast SEO pluginjQuery 2.2.0Google Tag Manager+5
2026-07-13T07:27:00.216Z
V

VTF Ltd

vtfl.co.uk

34
EnergyUnited KingdomsmallHIGH

VTF Ltd is a UK-based company specializing in LPG vessel refurbishment, positioning itself as a leading service provider in this niche energy sector. The website currently serves as a placeholder with minimal content, indicating a forthcoming full site launch. Contact information including a company email and phone number is provided, supporting basic business communication needs. The company targets UK businesses and LPG vessel owners requiring refurbishment services. Technically, the website is built on WordPress using a coming soon plugin, with standard libraries such as jQuery, Tailwind CSS, and FontAwesome. The site is accessible over HTTPS but lacks advanced security headers and privacy compliance features. Mobile optimization and accessibility are basic, and no analytics or tracking tools are detected, indicating a low digital maturity level at this stage. From a security perspective, the site benefits from HTTPS but misses critical security headers and privacy policies, which are essential for GDPR compliance and user trust. No forms or data collection mechanisms are present, reducing immediate data protection risks but also limiting user engagement. The WHOIS lookup for the subdomain 'www.vtfl.co.uk' failed as expected since subdomains are not separately registered, but no base domain WHOIS data was provided, limiting domain legitimacy verification. Overall, the website presents a safe, business-focused presence with moderate trustworthiness but requires significant improvements in privacy, security policies, and content depth to enhance credibility and compliance.

47
40
60
-
50
2
20
lpgvesselrefurbishmentenergycomingsoonuk
WordPressjQueryTailwind CSSFontAwesome
2026-07-13T07:26:12.770Z
O

Attention Required! | Cloudflare

onetoonesupportservices.co.uk

47
OtherN/asmallHIGH

The website www.onetoonesupportservices.co.uk is currently inaccessible due to a Cloudflare Web Application Firewall (WAF) block. The content served is a security challenge page indicating that the visitor has been blocked due to triggered security rules. Consequently, no meaningful business or website content is available for analysis. The WHOIS lookup for the domain failed with an error from Nominet UK stating that the domain name contravenes naming rules, specifically that it contains too many parts, indicating the domain may not be validly registered or is misconfigured. From a technical perspective, the site is protected by Cloudflare, but no further technical details such as CMS, hosting provider beyond Cloudflare, or security headers could be extracted. The lack of accessible content prevents assessment of SEO, accessibility, or performance. No contact information, privacy policies, or business details are available, limiting the ability to evaluate compliance or business credibility. Security posture is currently poor due to the inability to access the site and verify HTTPS configuration, security headers, or vulnerability status. The domain registration issues further reduce trustworthiness. Overall, the site appears non-functional or misconfigured, and the domain registration status raises legitimacy concerns. Strategic recommendations include resolving the Cloudflare block to allow legitimate access, ensuring proper domain registration compliance with Nominet UK rules, publishing essential policies and contact information, and implementing security best practices including security headers and HTTPS enforcement.

42
60
55
100
35
2
65
Cloudflare
2026-07-13T07:26:02.276Z