Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149091
Websites
130
Industries
113
Countries
52
Avg Score
Page 23 of 143|Showing 1101-1150 of 7115
carrot.is favicon

iakoe

carrot.is

53
E-commerceUnited StatessmallMEDIUM

iakoe is a specialized Shopify agency focused on delivering design-led e-commerce solutions, balancing brand identity, user experience, and store optimization to create effective shopping experiences. Founded in 2019, the company targets design-conscious brands seeking Shopify development, UX design, SEO, CRO, and migration services. The website demonstrates a strong market position with notable client logos and positive testimonials, indicating trust and professionalism. Technically, the website employs a modern tech stack including Bootstrap, jQuery, Splide.js, and integrates analytics and marketing tools such as Google Analytics, HubSpot, and Crazy Egg. The site is mobile-optimized, accessible, and SEO-friendly, hosted via GoDaddy with a Craft CMS backend. Performance is moderate with good responsiveness and user experience. Security posture is solid with HTTPS enforced, CSRF protection on forms, and no exposed sensitive data. However, the absence of DNSSEC, security headers, and published security or privacy policies indicates room for improvement. Privacy compliance is limited due to missing privacy and cookie policies, which could pose regulatory risks. Overall, the website is professional, trustworthy, and technically competent but would benefit from enhanced security policies and privacy compliance to strengthen its risk posture and regulatory adherence.

70
85
52
40
35
2
55
shopifyagencye-commerceuxdesignseo+2 more
BootstrapjQuerySplide.jsFontAwesome+5
2025-10-25T02:10:45.670Z
saegewerke.de favicon

Deutsche Säge- und Holzindustrie Bundesverband e.V. (DeSH)

saegewerke.de

58
ManufacturingGermanymediumMEDIUM

The website saegewerke.de is the official platform of the Deutsche Säge- und Holzindustrie Bundesverband e.V. (DeSH), a German sawmill and wood industry association. It provides a comprehensive directory of wood suppliers, types of wood, and assortments, targeting industry professionals and businesses in the manufacturing and wood processing sectors. The platform facilitates connections between suppliers and buyers, offering detailed supplier profiles and industry news. The website is well-branded, consistent, and professionally designed, reflecting its role as an industry association hub. Technically, the site uses a modern tech stack including Bootstrap, jQuery, Popper.js, FontAwesome, and Google Maps API. It employs a custom CMS backend and includes a consent management system for GDPR compliance. The site is mobile-optimized and performs moderately well, with basic SEO and accessibility features implemented. From a security perspective, the site enforces HTTPS and uses cookie consent mechanisms. However, it lacks explicit published security policies and incident response contacts. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is good, with clear privacy and cookie policies present. The WHOIS data is minimal but consistent with the business's German identity. Overall, the website presents a low-risk profile with strong business credibility and good privacy compliance. Strategic recommendations include publishing a formal security policy, adding security headers, and providing incident response contact information to enhance trust and security posture.

100
70
100
60
15
33
2
woodsawmillsuppliermanufacturingindustry+2 more
Bootstrap CSSjQueryPopper.jsFontAwesome+2
2025-10-25T01:58:01.022Z
terminland.de favicon

Terminland GmbH

terminland.de

59
TechnologyGermanymediumMEDIUM

Terminland GmbH is a well-established German company specializing in online appointment booking solutions, serving a broad range of industries such as healthcare, automotive, legal, and beauty services. The company positions itself as a market leader in Germany with over 15,000 deployed appointment plans and more than 90 million booked appointments. Their platform offers 24/7 online booking capabilities, enhancing customer satisfaction and operational efficiency for service providers. The website reflects a mature digital presence with professional design, clear navigation, and comprehensive service descriptions tailored to their target B2B audience. Technically, the website employs a modern technology stack including jQuery, Bootstrap, and FontAwesome, hosted securely in German data centers operated by Equinix. The site is mobile-optimized and accessible, with good SEO practices and performance. Google Tag Manager and Google Analytics are used for tracking, with a GDPR-compliant cookie consent mechanism in place. However, explicit security headers are not visibly declared, and no dedicated security or incident response policies are published. From a security perspective, the site uses TLS encryption and is hosted in a reputable carrier-neutral data center, ensuring good baseline security. The absence of explicit security headers and vulnerability disclosure policies suggests room for improvement in security posture. No critical vulnerabilities or exposed sensitive data were detected in the analyzed content. Privacy compliance is strong, with clear privacy and cookie policies aligned with GDPR requirements. Overall, Terminland GmbH demonstrates a high level of professionalism, trustworthiness, and compliance suitable for its business domain. Strategic recommendations include enhancing security header implementation, publishing a formal security policy and incident response contacts, and considering a vulnerability disclosure program to further strengthen trust and security maturity.

50
60
17
55
42
65
100
online-terminbuchungterminvereinbarungterminplanerterminlandonlinebooking+1 more
jQueryBootstrapFontAwesomeSweetAlert+2
2025-10-25T00:09:12.443Z
K

KATES Tennisanlagenbau Kamer & Kujtim Kabashi GbR

kates.de

9
OtherGermanysmallCRITICAL

KATES Tennisanlagenbau Kamer & Kujtim Kabashi GbR is a small, family-run business specializing in tennis court construction and maintenance services in Hamburg, Germany. The company offers a comprehensive range of services including new construction, renovation, seasonal preparation, winter services, and training seminars. Their market position is that of a niche regional specialist with decades of experience in the industry. The website is professionally designed, mobile-optimized, and provides clear navigation and contact options, including a contact form with CAPTCHA to prevent spam. Technically, the website is built on the Contao Open Source CMS platform and uses legacy jQuery 1.11.3 along with modern UI components like Slick Slider and FontAwesome. While the site performs moderately well and is mobile-friendly, the use of outdated JavaScript libraries and absence of security headers indicate areas for improvement. No analytics or tracking scripts were detected, suggesting minimal user tracking and a privacy-conscious approach, although no cookie consent mechanism was found. From a security perspective, the site uses HTTPS (assumed from base href), but lacks explicit security headers and uses an outdated jQuery version, which could expose it to vulnerabilities. The contact form includes CAPTCHA, which is a positive security measure. No incident response or security policies are publicly available. WHOIS data is minimal but does not raise immediate concerns, though registrant details do not fully match the business name, slightly reducing trust. Overall, the website is safe, professional, and trustworthy for its target audience, but could benefit from technical and compliance enhancements to improve security posture and GDPR adherence.

-
-
-
-
-
-
-
tennistenniscourtconstructiontenniscourtmaintenancesportsfacilityservicesfamilybusiness+1 more
jQuery 1.11.3Contao Open Source CMSSlick SliderFontAwesome+1
2025-10-24T21:58:37.439Z
thinwhite.co.uk favicon

Thinwhite - Tim Hack & Phil Daniels

thinwhite.co.uk

52
OtherUnited KingdomsmallMEDIUM

Thinwhite, operated by Tim Hack and Phil Daniels, is a small, established graphic design and web development agency based in Gloucestershire, UK. With over 20 years of experience, the company offers creative solutions in print, branding, web design, and SEO, targeting artisan and niche businesses. The website reflects a professional and client-focused approach, emphasizing transparency and quality service without retainers. Technically, the website is built on WordPress with modern plugins such as Yoast SEO and WPBakery Page Builder, ensuring good SEO and user experience. The site is mobile-optimized and uses standard web technologies including jQuery and FontAwesome. Hosting is provided by 123-Reg Limited, consistent with the UK location. Security posture is solid with HTTPS enforced, CAPTCHA on contact forms, and a GDPR-compliant cookie consent mechanism. However, explicit security headers are not detected and could be improved. No vulnerabilities or exposed sensitive data were found. Privacy policies are present and comprehensive enough for GDPR compliance. Overall, the website presents a low-risk profile with strong business credibility and good technical implementation. Strategic recommendations include enhancing security headers, conducting regular security audits, and publishing a formal security policy to further strengthen trust and compliance.

60
20
72
85
2
15
80
graphicdesignwebdesignbrandingprintseo+3 more
WordPressYoast SEOWPBakery Page BuilderjQuery+5
2025-10-24T21:29:29.610Z
gut-ausgebildet.de favicon

Ministerium für Wirtschaft, Arbeit und Tourismus Baden-Württemberg

gut-ausgebildet.de

57
EducationGermanymediumMEDIUM

gut-ausgebildet.de is an official educational and vocational training information portal supported by the Ministry of Economy, Labor and Tourism Baden-Württemberg. It serves as a comprehensive resource for students, trainees, parents, and educators in the Baden-Württemberg region, providing detailed information on apprenticeship opportunities, career guidance, and related initiatives such as Praktikumswoche and AzubiCardBW. The platform is well-positioned as a trusted government-backed source with strong partnerships across regional economic and labor organizations. Technically, the website is built on TYPO3 CMS, leveraging modern web technologies including Bootstrap and Matomo analytics for privacy-conscious user tracking. The site demonstrates good mobile optimization, accessibility, and SEO practices, ensuring a positive user experience. The use of no-cookie YouTube embeds and a clear cookie consent mechanism reflects a commitment to privacy compliance. From a security perspective, the site enforces HTTPS and implements cookie consent but lacks explicit security headers and published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the content. The WHOIS data aligns with the website's official nature, showing consistent domain registration without privacy protection, supporting legitimacy. Overall, gut-ausgebildet.de presents a secure, professional, and trustworthy platform with excellent content quality and strong business credibility. Strategic improvements could include enhancing HTTP security headers and publishing explicit security and incident response policies to further strengthen security posture and user trust.

-
62
60
70
75
17
83
educationvocationaltrainingbaden-wrttemberggovernmentyouth+2 more
TYPO3 CMSMatomo AnalyticsBootstrapFontAwesome+2

Partner Domains:

www.dgb.de
partner
handwerk-bw.de
partner

+3 more partners

2025-10-24T21:06:46.888Z
w3schools.com favicon

W3Schools

w3schools.com

76
EducationN/alargeLOW

W3Schools is a globally recognized online educational platform specializing in web development and programming tutorials. It offers a comprehensive range of free tutorials, references, exercises, and quizzes covering popular technologies such as HTML, CSS, JavaScript, Python, SQL, and more. The platform also provides paid certification programs and premium plans to enhance learning experiences. W3Schools targets a broad audience including students, educators, and professional developers, maintaining a strong market position as a leading resource for web development education. Technically, the website employs modern web standards including HTML5, CSS3, and JavaScript, with integration of Google Tag Manager and reCAPTCHA for analytics and security. The site is mobile-optimized, fast-loading, and accessible, with a consistent and professional design. Security best practices are observed, including HTTPS enforcement and security headers, though explicit security policies and incident response information are not publicly detailed. The security posture is strong with no detected vulnerabilities or exposed sensitive data. Privacy compliance is robust, featuring comprehensive privacy and cookie policies with GDPR adherence and user consent mechanisms. However, direct contact information for security incidents or general inquiries is not readily available, which could be improved to enhance trust and incident handling. Overall, W3Schools presents a low-risk profile with high trustworthiness, excellent content quality, and solid technical implementation. Strategic recommendations include publishing explicit security and incident response policies, adding vulnerability disclosure mechanisms, and providing clearer contact channels for security and support inquiries to further strengthen the platform's security culture and user trust.

100
80
85
95
47
80
30
htmlcssjavascriptpythonsql+5 more
HTML5CSS3JavaScriptGoogle Tag Manager+4
2025-10-24T21:06:22.713Z
onkopedia.com favicon

Deutsche Gesellschaft für Hämatologie und Medizinische Onkologie e.V.

onkopedia.com

65
HealthcareGermanymediumMEDIUM

Onkopedia is a well-established German-language medical guideline portal specializing in hematology and oncology. It serves healthcare professionals by providing up-to-date clinical guidelines, drug assessments, and educational webinars. The platform is affiliated with reputable medical societies in Germany, Austria, and Switzerland, reinforcing its credibility and market position as a leading oncology guideline resource in the German-speaking region. The business model is non-profit and focused on knowledge dissemination within the healthcare sector. Technically, the website is built on the Plone CMS, uses modern web technologies including HTML5, CSS3, JavaScript, and jQuery, and is hosted by Hetzner Online GmbH. The site is mobile optimized with good navigation and professional design, though accessibility features are basic. Security posture is solid with HTTPS enforced and no visible vulnerabilities, but lacks some security headers and explicit incident response information. Privacy compliance is good with a comprehensive privacy policy, but the absence of a cookie consent mechanism is a minor gap. Overall, the domain registration data is consistent and trustworthy, supporting the legitimacy of the site. Strategic recommendations include enhancing security headers, implementing cookie consent, and publishing security policies to improve compliance and trust.

70
100
60
85
17
53
50
healthcaremedicalguidelinesoncologyhematologyeducation+1 more
HTML5CSS3JavaScriptjQuery+2

Partner Domains:

dgho.de
partner
oegho.at
partner

+2 more partners

2025-10-24T20:55:56.227Z
askoe-ooe.at favicon

ASKÖ Oberösterreich

askoe-ooe.at

52
Non-profitAustriamediumMEDIUM

ASKÖ Oberösterreich is a regional non-profit sports association dedicated to promoting diverse sports activities and supporting sports clubs in Upper Austria. The organization provides a wide range of services including club support, sports education, fitness and health programs, and competitive sports event organization. It serves sports clubs, athletes, and community members, positioning itself as a key regional player in sports promotion. The website reflects a professional and consistent brand image aligned with its mission. Technically, the website uses a moderate technology stack including jQuery, FontAwesome, Owl Carousel, and a proprietary CMS by Internetkonzepte.at. The site is mobile optimized and performs moderately well, with basic SEO and accessibility features. Privacy and cookie policies are present and GDPR compliant, though explicit security policies and incident response contacts are not found. From a security perspective, the site enforces HTTPS and uses secure external scripts but lacks advanced security headers and a vulnerability disclosure policy. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data is consistent with the website's claims, indicating a legitimate and established organization. Overall, the website is trustworthy, professionally maintained, and compliant with privacy regulations. Strategic improvements in security headers, incident response transparency, and accessibility could enhance its security posture and user trust.

35
28
17
85
62
85
20
sportsnon-profiteducationfitnesscommunity+2 more
jQuery 3.6.0FontAwesomeOwl CarouseljQuery UI+3

Partner Domains:

www.askoe.at
partner
www.askoe-burgenland.at
partner

+3 more partners

2025-10-24T20:14:48.069Z
hbz-nrw.de favicon

Hochschulbibliothekszentrum des Landes Nordrhein-Westfalen (hbz)

hbz-nrw.de

10
EducationGermanymediumCRITICAL

The Hochschulbibliothekszentrum des Landes Nordrhein-Westfalen (hbz) is a key regional institution supporting library processes and services across academic institutions in North Rhine-Westphalia, Germany. Their website provides comprehensive information about their products, projects, literature search services, and publications, targeting libraries, researchers, and students. The organization is positioned as an essential service provider in the education sector with a medium-sized operational scale and a founding date consistent with the domain registration. Technically, the website is built on the Plone CMS platform, utilizing modern web technologies such as jQuery, Leaflet.js, and FontAwesome. It is mobile-optimized, accessible, and integrates Matomo analytics for privacy-conscious user tracking. The site is served over HTTPS with no detected blocking or WAF interference, indicating good digital maturity. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks explicit security headers and does not publish a dedicated security policy or incident response contacts. Privacy compliance is well addressed with clear privacy and cookie policies, including a consent mechanism. Contact information is available but no direct email addresses are listed in the HTML content. Overall, the website is professional, trustworthy, and safe for general audiences. Strategic improvements include adding security headers, publishing a security policy, and implementing a vulnerability disclosure mechanism to enhance security posture and transparency.

-
-
-
-
-
-
-
educationlibraryresearchinformationservicesgermany+2 more
Plone CMSjQueryLeaflet.jsFontAwesome+1
2025-10-24T20:11:31.767Z
teutoowl.de favicon

OWL Verkehr GmbH

teutoowl.de

57
TransportationGermanymediumMEDIUM

OWL Verkehr GmbH operates as a regional public transportation service provider and information portal for the TeutoOWL network in Germany. The company offers a range of services including schedule information, ticket sales (such as Deutschlandticket, JobTickets, and SchülerTickets), subscription management, and mobility services like call-collect taxis and night buses. The website targets public transport users in the OWL region, providing comprehensive and accessible information to facilitate mobility. Technically, the website is built on TYPO3 CMS, leveraging modern web technologies such as jQuery, Bootstrap, and FontAwesome. It employs Matomo analytics with a cookie consent mechanism, indicating a privacy-conscious approach. The site is hosted on infrastructure associated with DomainControl, uses HTTPS with strong SSL configuration, and demonstrates good mobile optimization and accessibility. From a security perspective, the website enforces HTTPS and uses privacy-friendly analytics. However, it lacks explicit security policy documentation and incident response contact details. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data is limited but consistent with a legitimate regional transportation entity. Overall, the site maintains a good security posture with room for improvement in transparency and security headers. The overall risk assessment is low, with the website presenting a professional, trustworthy, and compliant digital presence. Strategic recommendations include publishing a security policy, adding incident response contacts, enhancing security headers, and maintaining regular security audits to sustain and improve the security posture.

25
83
2
85
95
60
20
publictransportationticketsbustrainowlverkehr+3 more
TYPO3 CMSjQueryBootstrapFontAwesome+4
2025-10-24T19:17:11.313Z
tmc-gmbh.de favicon

TMC GmbH

tmc-gmbh.de

38
MediaGermanymediumHIGH

TMC GmbH is a medium-sized marketing agency based in Germany, specializing in creating emotional brand experiences across digital and analog environments. The company operates multiple specialized agencies under its group, including Amplio®, TMC Brandwork, and TMC Live, offering services such as marketing consulting, brand development, event management, and video production. The website reflects a strong market position as the largest marketing agency in the Ostwestfalen-Lippe region, targeting businesses seeking comprehensive marketing solutions. Technically, the website is built on a modern stack including OctoberCMS, JavaScript libraries like jQuery and Vime.js for video playback, and integrates Google Tag Manager and CookieFirst for analytics and consent management. The site is mobile-optimized with good SEO practices and a professional design, providing a positive user experience. From a security perspective, the site enforces HTTPS and includes a cookie consent mechanism, but lacks explicit security headers and documented security policies or incident response information. No vulnerabilities or exposed sensitive data were detected in the HTML content. WHOIS data is consistent with a legitimate business domain, with no privacy protection or suspicious patterns. Overall, the website demonstrates a high level of professionalism, good security posture, and compliance with privacy regulations, making it a trustworthy digital presence for the company.

15
28
2
65
42
45
20
marketingbrandingdigitalmarketingeventmanagementconsulting+2 more
JavaScriptjQueryFontAwesomeVime.js (video player)+2

Partner Domains:

tmc-amplio.de
subsidiary
tmc-brandwork.de
subsidiary

+1 more partners

2025-10-24T19:15:29.337Z
rbalibros.com favicon

RBA Libros

rbalibros.com

66
MediaSpainlargeMEDIUM

RBA Libros is a prominent Spanish publishing house specializing in adult fiction and non-fiction literature, offering a diverse catalog through multiple well-known imprints such as Gredos, Serie Negra, and National Geographic. The company operates under the Grupo RBA umbrella, positioning itself as a key player in the Spanish media and publishing sector. Their website provides comprehensive access to their catalog, news, and social media engagement, targeting general adult readers interested in literary content. Technically, the website employs a modern JavaScript stack including RequireJS, jQuery, and LazySizes for optimized content delivery and lazy loading. It integrates GDPR-compliant consent management via the Didomi SDK and uses Google Tag Manager for analytics and marketing. Hosting of static content is done through Microsoft Azure Blob Storage, indicating a robust infrastructure. The site is mobile-optimized with good SEO and accessibility practices, although some improvements in security headers could be made. From a security perspective, the site enforces HTTPS and uses consent mechanisms aligned with GDPR. However, the absence of explicit security headers and a published security policy or incident response contact reduces the overall security posture. The missing WHOIS domain registration data is a notable concern, as it creates uncertainty about domain legitimacy despite the professional appearance and consistent branding of the website. Overall, RBA Libros presents a trustworthy and professional digital presence with strong content and compliance features. The primary risk lies in the lack of transparent domain registration information and some minor security best practice gaps. Addressing these would enhance trust and security assurance for users and partners.

50
50
17
85
72
75
100
publishingbooksfictionnon-fictionliterature+4 more
RequireJSjQueryLazySizesVideo.js+3

Partner Domains:

www.rba.es
parent
foreignrights.rba.es
related

+2 more partners

2025-10-24T19:15:24.324Z
dlrg.net favicon

DLRG

dlrg.net

66
Non-profitGermanymediumMEDIUM

DLRG.net serves as the Internet Service Center (ISC) for the Deutsche Lebens-Rettungs-Gesellschaft (DLRG), a German non-profit organization focused on water rescue and safety. The website functions as an intranet portal providing active members with access to documents, news, examination tools, and seminar management applications. The platform targets active DLRG members and supports their operational and administrative needs through a secure login system and member-specific applications. The domain is well-established since 1999, reflecting a mature digital presence aligned with the organization's history. Technically, the website employs standard web technologies including jQuery, FontAwesome, and Bootstrap, hosted on AWS infrastructure. The site is mobile-optimized with responsive design and basic accessibility features. However, there is room for improvement in SEO and accessibility enhancements. Security posture is solid with HTTPS enforced and domain transfer protection, but lacks DNSSEC and explicit security headers, which are recommended to strengthen defenses. From a security and compliance perspective, the site provides secure login forms with input validation but lacks visible cookie consent mechanisms and detailed privacy or security policies on the main site. No incident response or vulnerability disclosure information is published, which could be improved to enhance transparency and trust. The absence of advertising and tracking scripts indicates a privacy-conscious approach, though cookie policy implementation is advised for GDPR compliance. Overall, dlrg.net is a trustworthy and professional portal serving a defined non-profit community with a good balance of functionality and security. Strategic improvements in security headers, cookie consent, and policy transparency would further elevate its compliance and security posture.

75
53
2
70
77
70
100
non-profitmembershipintranetdlrggermany+3 more
jQueryFontAwesomeBootstrap (implied by navbar classes)AWS DNS hosting
2025-10-24T18:34:25.797Z
dlrg-jugend.de favicon

DLRG DLRG-Jugend Bundesebene

dlrg-jugend.de

70
Non-profitGermanymediumMEDIUM

DLRG-Jugend Bundesebene is a German non-profit youth organization affiliated with the German Life Saving Association (DLRG). It focuses on youth engagement, education, and community activities related to water safety and youth development. The website serves as an information hub for events, campaigns, and volunteer opportunities targeted primarily at German-speaking youth and volunteers. The organization maintains a consistent brand presence and provides comprehensive contact and privacy information, reflecting a mature digital presence. Technically, the website is built on TYPO3 CMS, leveraging modern responsive design frameworks such as Bootstrap and FontAwesome. Hosting is provided via Amazon AWS infrastructure, ensuring reliable performance and scalability. The site incorporates GDPR-compliant cookie consent mechanisms and uses both Google Analytics and Plausible Analytics for visitor tracking, with user opt-in consent. From a security perspective, the site enforces HTTPS and employs cookie consent for analytics tracking, but lacks explicit security headers and publicly available security or incident response policies. No vulnerabilities or suspicious content were detected. Overall, the site demonstrates a good security posture appropriate for a non-profit organization. The overall risk is low, with recommendations focusing on enhancing security headers, publishing incident response information, and considering a vulnerability disclosure policy to further strengthen trust and compliance.

70
100
2
70
77
60
100
non-profityoutheducationwatersafetytypo3+3 more
TYPO3 CMSBootstrap (navbar, responsive design)FontAwesomeGoogle Analytics+1

Partner Domains:

dlrg.net
partner
hilfe.dlrg.net
partner

+1 more partners

2025-10-24T18:34:15.778Z
hiz-saarland.de favicon

Hochschul-IT-Zentrum des Saarlandes

hiz-saarland.de

60
EducationGermanymediumMEDIUM

The Hochschul-IT-Zentrum des Saarlandes operates as a regional IT service center supporting higher education institutions in Saarland, Germany. It provides a range of IT services including user account management, network access (WLAN, VPN), email and groupware solutions, hardware procurement, and cloud services. The website is professionally designed using TYPO3 CMS and targets students, employees, guests, and academic facilities. It maintains partnerships with multiple universities in the region, reinforcing its role as a central IT hub for academic institutions. Technically, the website leverages modern web technologies such as TYPO3 CMS, Bootstrap, and jQuery, hosted likely within university or DFN infrastructure. The site is mobile optimized and offers good navigation and content relevance. However, some improvements in accessibility and SEO could be considered. Security posture is moderate with HTTPS usage and secure form handling, but lacks explicit security headers and published security policies. Privacy compliance is basic with a privacy policy present but no cookie consent mechanism. Overall, the security posture is sound for an academic IT service provider, with no visible vulnerabilities or exposed sensitive data. The WHOIS data aligns well with the website's academic context, indicating legitimacy and trustworthiness. The site does not engage in advertising or extensive user tracking, supporting a privacy-conscious approach. Strategic recommendations include implementing security headers, adding cookie consent mechanisms, publishing security and incident response policies, and considering a vulnerability disclosure program to enhance trust and compliance.

70
28
2
70
62
65
100
educationitservicesacademictypo3university+1 more
TYPO3 CMSBootstrapjQueryFontAwesome

Partner Domains:

www.uni-saarland.de
partner
www.htwsaar.de
partner

+2 more partners

2025-10-24T17:49:14.769Z
qaa.ac.uk favicon

The Quality Assurance Agency for Higher Education

qaa.ac.uk

72
EducationUnited KingdommediumMEDIUM

The Quality Assurance Agency for Higher Education (QAA) is a UK-based independent charity and the expert quality body for tertiary education. It provides impartial regulatory and collaborative quality assurance and enhancement services across the UK and internationally. The organization is trusted by governments, funding bodies, and higher education providers, offering services such as membership, accreditation, training, and sector resources. The website reflects a mature, professional entity with a clear focus on education quality and standards. Technically, the website is built on the Sitefinity CMS platform, leveraging modern analytics tools including Google Analytics and Microsoft Clarity, and employs Google Tag Manager for marketing and tracking. The site is mobile-optimized, accessible, and well-structured with comprehensive navigation and content. Security certifications such as ISO 27001 and Cyber Essentials are prominently displayed, indicating a strong commitment to information security. Security posture is solid with HTTPS enforced and cookie consent mechanisms in place. However, explicit security headers and a public security policy or incident response contact are not found, representing areas for improvement. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is good, with clear privacy and cookie policies aligned with GDPR requirements. Overall, the website and organization present a low-risk profile with high trustworthiness. Strategic recommendations include enhancing security headers, publishing a security policy and incident response details, and implementing a vulnerability disclosure program to further strengthen security and transparency.

55
68
17
100
72
75
100
educationqualityassurancehighereducationukaccreditation+3 more
Google Tag ManagerGoogle AnalyticsMicrosoft ClarityjQuery+2

Partner Domains:

www.membershipresources.qaa.ac.uk
partner
www.enhancementthemes.ac.uk
partner

+2 more partners

2025-10-24T17:45:45.771Z
fylkesmannen.no favicon

Statsforvalteren

fylkesmannen.no

66
GovernmentNorwaylargeMEDIUM

Statsforvalteren.no is the official website of the Norwegian government agency representing the state at the county level. The agency is responsible for implementing decisions, goals, and guidelines from the Norwegian Parliament and government, acting as a vital link between municipalities and central authorities. The website provides access to public services, complaint handling, forms, news, and job postings relevant to the agency's functions. It targets Norwegian citizens, public sector employees, and municipalities, offering content primarily in Norwegian with language options including English and regional languages. Technically, the website employs modern web technologies including Bootstrap for responsive design, JavaScript libraries, and integrates analytics tools such as Azure Application Insights, Hotjar, Maze Analytics, and Siteimprove Analytics. The site is served over HTTPS with good mobile optimization and accessibility features, though explicit security headers are not evident. The site lacks a cookie consent mechanism despite using tracking scripts, which is a privacy compliance gap. From a security perspective, the site demonstrates a solid posture with HTTPS enforcement and no visible vulnerabilities or exposed sensitive data. However, the absence of explicit security headers and a published security or incident response policy are areas for improvement. The WHOIS data is unavailable due to Norid's privacy policies, but the domain's .no TLD and consistent government-related content strongly indicate legitimacy and trustworthiness. Overall, Statsforvalteren.no is a professionally maintained government website with good content quality and technical implementation. Strategic recommendations include enhancing privacy compliance with cookie consent, publishing security policies, and adding security headers to strengthen the security posture and user trust.

40
50
2
98
75
85
100
governmentnorwaypublicservicesstatsforvalterenregionalauthority+2 more
JavaScriptAzure Application InsightsHotjarMaze Analytics+3
2025-10-24T17:44:04.048Z
J

Jobbnorge.no

jobbnorge.no

75
OtherNorwaymediumMEDIUM

Jobbnorge.no is a Norwegian online recruitment platform focused on connecting job seekers with employers across Norway. The website offers job search functionality and recruitment tools, positioning itself as an important player in the Norwegian recruitment market. The platform targets both job seekers and employers, providing a streamlined experience for finding and posting jobs. The business model revolves around providing digital recruitment services and tools to facilitate hiring processes. Technically, the website employs modern technologies including ASP.NET, Matomo analytics, and Cloudflare for hosting and security. It features a comprehensive cookie consent mechanism compliant with GDPR, enhancing user privacy and transparency. Security posture is strong with HTTPS enforced and device fingerprinting used for security purposes, although some security headers could be improved. Overall, the website is professional, well-branded, and trustworthy, with good mobile optimization and accessibility. However, the lack of publicly available WHOIS data slightly reduces trust but is likely due to privacy protection. Strategic recommendations include publishing a privacy policy page, terms of service, and a vulnerability disclosure policy to further enhance compliance and trust.

85
83
17
85
67
85
100
jobsearchrecruitmentnorwaycookieconsentanalytics+1 more
Matomo AnalyticsCookieInformation cookie consentFontAwesomeGoogle Fonts+5
2025-10-24T17:43:58.450Z
dlhsako.com favicon

Pemerintah Sako

dlhsako.com

56
GovernmentIndonesiasmallMEDIUM

The website dlhsako.com represents the official online presence of the Dinas Lingkungan Hidup Sako, a government environmental agency in Indonesia. It provides information about environmental management services, including waste management, pollution control, and public complaint handling. The site targets the general public and local community, aiming to inform and facilitate environmental governance. The domain is newly registered in 2024, consistent with a new government initiative. Technically, the website uses modern web technologies such as Laravel Livewire, Swiper.js, and FontAwesome, with a responsive design optimized for mobile devices. The site is hosted with Cloudflare DNS but lacks DNSSEC and some security headers, indicating room for security improvements. No analytics or tracking scripts were detected, suggesting minimal user tracking. From a security perspective, HTTPS is properly implemented, and domain transfer protections are in place. However, the absence of privacy and cookie policies, security headers, and vulnerability disclosure mechanisms represent compliance and security gaps. The site does not appear to be blocked by any WAF or security challenge, allowing full content access. Overall, the website is professional and trustworthy as a government entity but would benefit from enhanced privacy compliance and security hardening to improve user trust and regulatory adherence.

15
53
17
60
60
70
100
governmentenvironmentindonesiapublicserviceenvironmentalagency
HTML5CSS3JavaScriptLivewire+3
2025-10-24T17:37:31.965Z