Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

150477
Websites
130
Industries
113
Countries
52
Avg Score
Page 250 of 1029|Showing 12451-12500 of 51436
chef.se favicon

Chef och Chefakademin

chef.se

64
MediaSwedenmediumMEDIUM

Chef och Chefakademin is a well-established Swedish media and education company specializing in leadership development. Founded in 2003, it holds a strong market position as the largest leadership media provider in Sweden, offering leadership training, a leading leadership magazine, and digital tools to support leaders. The website reflects a professional and consistent brand image targeted at leaders and managers in Sweden and the Nordic region. Technically, the site is built on WordPress, leveraging modern technologies such as Google Tag Manager, Cookiebot for consent management, and Cloudflare DNS services. The site is mobile-optimized and performs moderately well, with good SEO and accessibility basics. Security posture is solid with HTTPS enforced, reCAPTCHA integration, and cookie consent mechanisms, though DNSSEC is not enabled and security headers are not explicitly detected. No critical vulnerabilities or exposed sensitive data were found. Privacy compliance is partially met with a cookie consent banner but lacks a clearly accessible privacy policy or terms of service in the analyzed content. Contact information is not explicitly provided on the analyzed page. Overall, the domain registration data aligns well with the business claims, supporting legitimacy and trustworthiness.

15
83
17
80
65
70
100
leadershipeducationmediaswedencookieconsent+2 more
WordPressGoogle Tag ManagerCloudflare DNSCookiebot+2

Partner Domains:

stripe.com
partner
cookiebot.com
partner

+2 more partners

2025-10-18T23:02:05.919Z
adra.org favicon

ADRA International

adra.org

50
Non-profitUnited StateslargeMEDIUM

ADRA International is a well-established global non-profit organization focused on humanitarian aid, development, and disaster relief across more than 120 countries. The organization operates through local offices and partners to fight poverty and create sustainable change. Their website reflects a professional and consistent brand image, with comprehensive content targeting donors, volunteers, and partners. The business model is centered on charitable donations, volunteer engagement, and strategic partnerships, positioning ADRA as a leading humanitarian agency with strong trust indicators including multiple certifications and transparent financial disclosures. Technically, the website is built on WordPress using Elementor, integrating modern analytics and marketing tools such as Google Tag Manager, Facebook Pixel, TikTok Pixel, and RudderLabs. The site is mobile optimized with good SEO practices and moderate performance. Hosting and domain registration are stable and consistent with the organization's profile. From a security perspective, the site uses HTTPS with good SSL configuration and some security headers, though DNSSEC is not enabled and there is no visible security.txt or vulnerability disclosure policy. No critical vulnerabilities or exposed sensitive data were detected. Privacy and cookie policies are present and indicate GDPR compliance, supporting responsible data protection practices. Overall, ADRA International's website demonstrates a mature digital presence with strong business credibility and good security posture. Minor improvements in DNS security and formal vulnerability disclosure could further enhance trust and resilience.

15
35
37
98
42
85
-
non-profithumanitariancharitydevelopmentdisasterrelief+3 more
WordPressElementorGoogle Tag ManagerGoogle Analytics+5

Partner Domains:

adraconnections.org
partner
communityhub.adra.cloud
partner

+3 more partners

2025-10-18T23:02:00.911Z
G

General Conference Corporation of Seventh-day Adventists

adventistmission.org

73
Non-profitUnited StateslargeMEDIUM

The website adventistmission.org serves as the official mission portal for the Seventh-day Adventist Church, providing comprehensive resources, news, training, and donation options to support global missionary work. It targets church members, missionaries, donors, and supporters worldwide, positioning itself as a key platform for mission engagement within the Adventist community. The business model is non-profit and religious, backed by the General Conference Corporation of Seventh-day Adventists, a large and established organization. Technically, the site employs a modern tech stack including jQuery, Google Tag Manager, Fundraise Up for donations, and Bloomerang CRM for constituent management. It is hosted behind Cloudflare, ensuring good performance and security. The site is mobile-optimized with good SEO and basic accessibility features, though some improvements could be made in security headers and accessibility. Security posture is strong with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. The site uses a consent management platform for GDPR and cookie compliance, reflecting good privacy practices. However, it lacks publicly available security policies or incident response contacts, which could be improved to enhance trust. Overall, the site is professional, trustworthy, and well-maintained, with a high legitimacy score despite the absence of detailed WHOIS data due to privacy protection. Strategic recommendations include implementing security headers, publishing security and incident response policies, and adding vulnerability disclosure mechanisms to further strengthen security and compliance.

65
83
17
85
65
90
100
adventistmissionmissionariesnon-profitreligiousglobalmission+3 more
jQueryGoogle Tag ManagerFundraise UpBloomerang CRM+1
2025-10-18T23:01:20.839Z
utopie.cz favicon

Je víra v Boha utopie?

utopie.cz

37
OtherCzech RepublicsmallHIGH

The website www.utopie.cz is a Czech language content platform focused on religious and philosophical topics, particularly Christianity. It offers a series of thematic articles and a newsletter subscription, targeting a general audience interested in faith and spirituality. The site appears to be small-scale and content-driven without clear commercial intent or extensive business infrastructure. Technically, the site uses legacy JavaScript libraries such as jQuery 1.10.2, integrates Google Analytics and Facebook SDK for tracking, and includes Google Ads remarketing scripts. The site is moderately optimized for mobile and SEO but lacks advanced accessibility features and modern frameworks. Security-wise, the site uses HTTPS but lacks visible security headers and employs outdated libraries that may expose vulnerabilities. No privacy or cookie policies are present, which impacts compliance with GDPR and user trust. The WHOIS data is unavailable, limiting domain legitimacy verification and reducing overall trust. Suspicious hidden links to unrelated pharmaceutical domains were detected, which could indicate potential security or SEO manipulation risks. Overall, the site is functional and content-rich but requires improvements in security, privacy compliance, and domain transparency to enhance trust and resilience.

20
10
2
40
85
75
-
religionphilosophychristianityutopienewsletter+1 more
jQuery 1.10.2Google AnalyticsFacebook SDKGoogle Tag Manager+2

Partner Domains:

www.hopetv.cz
partner
www.awr.cz
partner

+1 more partners

2025-10-18T23:01:05.796Z
g24.si favicon

Generali G24

g24.si

60
FinanceSloveniamediumMEDIUM

Generali G24 is an established Slovenian online insurance platform offering a wide range of insurance products including vehicle, health, accident, travel, and pet insurance. The website is part of the Generali Slovenia group, positioning itself as a modern and reliable partner for customers seeking fast and easy insurance solutions online. The business model focuses on direct-to-consumer sales with an emphasis on digital convenience and customer trust. The site is well-branded and consistent with the parent company's identity. Technically, the website uses a mature technology stack including Liferay CMS, jQuery, Google Tag Manager, and analytics tools. Hosting is supported by Google Cloud DNS infrastructure, ensuring reliable performance and availability. The site is mobile optimized and accessible, with good SEO practices and structured navigation. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms compliant with GDPR. However, it lacks explicit security policies, incident response contacts, and vulnerability disclosure information. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data confirms domain legitimacy with consistent registration details and appropriate domain age. Overall, the website presents a low-risk profile with strong business credibility and good technical implementation. Strategic improvements could include enhancing security headers, publishing security policies, and adding vulnerability disclosure channels to further strengthen trust and compliance.

55
10
2
85
72
70
100
insuranceonlineinsurancecarinsurancetravelinsurancehealthinsurance+2 more
jQuery 1.12.3Google Tag ManagerGoogle AnalyticsYUI 3+3

Partner Domains:

www.generali.si
parent
www.generali-zame.si
related
2025-10-18T23:00:45.758Z
profisms.cz favicon

ProfiSMS

profisms.cz

56
TelecommunicationsCzech RepublicmediumMEDIUM

ProfiSMS is a Czech-based telecommunications company specializing in SMS marketing and customer communication platforms. With a strong market presence and a claim of 18 years in operation, it offers a comprehensive suite of messaging services including bulk SMS, 2-way SMS, SMS Voice, and Viber messaging. The company targets businesses and developers seeking efficient and reliable communication channels, supported by extensive API integrations and professional tools. The website reflects a mature digital presence with excellent content quality, clear navigation, and mobile optimization. Technically, the site employs modern technologies such as Google Tag Manager, reCAPTCHA, and Chatwoot for live chat support, indicating a well-maintained infrastructure. Security practices are evident in the use of HTTPS, end-to-end encryption claims, and a detailed cookie consent mechanism, although explicit security policies and incident response contacts are not publicly available. The absence of WHOIS data is a minor concern but does not significantly detract from the overall legitimacy given the professional presentation and business references. Strategic recommendations include enhancing transparency around security policies and improving HTTP security headers to further strengthen trust and compliance.

35
10
2
60
77
80
100
smsmarketingcpaasbulksmsvibermessagingapiintegration+4 more
Google Tag ManagerGoogle reCAPTCHAChatwoot live chatjQuery+3

Partner Domains:

stopsms.cz
partner
vercom.pl
parent
2025-10-18T23:00:00.672Z
darkyzbrna.cz favicon

DARKYZBRNA.cz

darkyzbrna.cz

10
RetailCzech RepublicsmallCRITICAL

The website www.darkyzbrna.cz operates as an e-commerce platform specializing in original gifts, practical accessories, and promotional items themed around the city of Brno. It targets a general audience interested in local souvenirs and unique design products. The business model is retail-focused, leveraging the Shoptet e-commerce platform to provide a professional and user-friendly shopping experience. The site is supported financially by the statutory city of Brno, indicating local institutional backing and trust. Technically, the website employs a modern but somewhat dated technology stack including jQuery 1.11.3, Google Tag Manager, Google Analytics 4, and Facebook Pixel for marketing and analytics. The platform is mobile-optimized with good accessibility and SEO practices. Cookie consent mechanisms and privacy policies are implemented in compliance with GDPR, reflecting a mature approach to privacy and user data protection. From a security perspective, the site uses HTTPS and CSRF tokens on forms, but lacks explicit security headers and documented incident response policies. The use of an outdated jQuery version presents a potential vulnerability. No WHOIS data was found, which raises concerns about domain registration transparency but does not directly impact the operational security of the website. Overall, the website is professionally maintained with good content quality and user experience. The main risk lies in the lack of WHOIS transparency and minor technical security improvements. Strategic recommendations include updating JavaScript libraries, enhancing security headers, and publishing incident response contacts to improve trust and compliance.

-
-
-
-
-
-
-
e-commercegiftssouvenirsbrnoretail+3 more
jQuery 1.11.3Google Tag ManagerGoogle Analytics 4Facebook SDK and Pixel+1
2025-10-18T22:58:40.487Z
strategy.com favicon

Strategy

strategy.com

66
FinanceN/amediumMEDIUM

Strategy.com is a specialized financial analytics platform focusing on providing real-time market data and metrics related to MicroStrategy (MSTR) stock and Bitcoin. The website offers detailed financial indicators such as price, returns, market capitalization, trading volume, and Bitcoin holdings, targeting investors and financial analysts interested in these assets. The platform also extends its offerings to merchandising and software products, indicating a diversified business model within the finance and technology sectors. The site is professionally designed with consistent branding and clear navigation, supporting a good user experience for its target audience. Technically, the website leverages modern web technologies including React, Next.js, and Material-UI, with content managed via Contentstack CMS. It integrates marketing and analytics tools such as Google Tag Manager and Marketo, and employs OneTrust for cookie consent management, reflecting a mature digital infrastructure. Performance is moderate with good mobile optimization and basic accessibility features. SEO practices are well implemented with proper meta tags and Open Graph data. From a security perspective, the site enforces HTTPS and includes important security headers, contributing to a strong security posture. However, it lacks explicit security policy documentation, incident response contacts, and vulnerability disclosure mechanisms, which are areas for improvement. Privacy compliance is well addressed with comprehensive privacy and cookie policies and GDPR compliance indicators. The absence of direct contact emails or phone numbers slightly reduces business credibility. Overall, the website presents a trustworthy and professional front for its niche financial analytics services. The main risk factor is the absence of WHOIS registration data, which reduces transparency about domain ownership and age. Strategic recommendations include enhancing security transparency, adding incident response information, and improving direct contact availability to strengthen trust and compliance further.

40
88
2
75
72
75
100
financemarketdatabitcoinmicrostrategyanalytics+1 more
ReactNext.jsMaterial-UIGoogle Tag Manager+2
2025-10-18T21:57:16.687Z
exasol.com favicon

Exasol

exasol.com

72
TechnologyGermanymediumMEDIUM

Exasol is a technology company specializing in high-performance analytics engines designed to modernize data warehouses, accelerate analytics, and enable governed AI/ML models. The company positions itself as a trusted provider for global enterprises seeking cost-effective and reliable data analytics solutions. Their website reflects a mature digital presence with strong SEO, structured data, and multimedia content to engage their target audience of enterprise data professionals. Technically, the website is built on WordPress with integrations including Google Tag Manager, Cookiebot for consent management, and marketing/analytics tools such as HubSpot and Hotjar. The site is well-optimized for performance, mobile responsiveness, and accessibility, indicating a high level of digital maturity. From a security perspective, the site enforces HTTPS and uses Cloudflare services for bot management. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not present, representing areas for improvement. The privacy compliance is good with a cookie consent mechanism, but the absence of a visible privacy policy and terms of service reduces compliance confidence. Overall, the website is professional, secure, and trustworthy with minor gaps in explicit policy disclosures. Strategic enhancements in transparency and security documentation would further strengthen their risk posture and user trust.

90
100
17
55
47
85
100
analyticsdatawarehouseaimachinelearningbusinessintelligence+1 more
YouTube iframe APIGoogle Tag ManagerCookiebotNelio AB Testing+2
2025-10-18T21:57:11.679Z
corefiling.com favicon

CoreFiling

corefiling.com

64
TechnologyUnited KingdommediumMEDIUM

CoreFiling is a specialized technology company providing intelligent software and services focused on digital data collection and XBRL reporting solutions. Their flagship True North Data Platform addresses challenges faced by filers, data collectors, auditors, and software vendors, positioning them as a niche leader in the XBRL ecosystem. The website reflects a mature digital presence with professional design, structured data, and clear contact information, supporting their market credibility. Technically, the website is built on WordPress with the Divi theme, leveraging modern JavaScript libraries and analytics tools such as Google Analytics and Google Tag Manager. The site is mobile-optimized and SEO-friendly, though some accessibility features could be enhanced. Security posture is solid with HTTPS enforced and cookie consent implemented, but lacks some advanced security headers and explicit security policies. The absence of publicly available WHOIS data introduces some uncertainty regarding domain registration transparency, though the overall professional presentation and consistent branding mitigate concerns. No signs of blocking or WAF interference were detected, allowing full content analysis. Overall, CoreFiling demonstrates a strong business and technical foundation with room for improvement in privacy disclosures and security policy transparency to enhance trust and compliance.

45
68
17
60
75
65
100
xbrldatacollectiondigitalreportingtechnologysoftware+2 more
WordPress 6.7.2Divi Theme 4.12.1jQuery 3.7.1Google Analytics (gtag.js)+3

Partner Domains:

corefiling.com
partner
2025-10-18T21:57:06.668Z
viessmann.group favicon

Viessmann Generations Group GmbH & Co. KG

viessmann.group

70
EnergyGermanylargeMEDIUM

Viessmann Generations Group GmbH & Co. KG operates as an impact-driven investment ecosystem focused on sustainable and long-term investments across energy, environmental, and social sectors. The company emphasizes co-creating living spheres for future generations by investing in majority, minority, generational, and early-stage innovation ventures. Their portfolio includes companies specializing in grid infrastructure, district heating and cooling, clean cold solutions, renewable energy, and health-related sectors. The website reflects a mature digital presence with professional design, clear navigation, and comprehensive content that aligns with their business objectives. Technically, the website is built on Webflow with modern JavaScript libraries such as GSAP and Lenis for smooth animations and scrolling. It integrates Google Tag Manager and Usercentrics CMP for analytics and privacy compliance, respectively. The site is well-optimized for performance and mobile responsiveness, with good accessibility and SEO practices observed. From a security perspective, the site enforces HTTPS and uses privacy-compliant cookie consent mechanisms. While explicit security headers are not fully confirmed, no vulnerabilities or exposed sensitive data were detected. The WHOIS data is limited due to TLD restrictions and privacy protection but does not raise legitimacy concerns. Overall, the security posture is solid but could be enhanced by publishing explicit security policies and incident response contacts. The overall risk assessment is low, with the company demonstrating strong business credibility, compliance with privacy regulations, and a professional online presence. Strategic recommendations include enhancing security header implementation, publishing a security policy, and adding vulnerability disclosure mechanisms to further strengthen trust and resilience.

60
65
55
60
57
80
100
investmentsustainabilityenergygreenhousegasesphilanthropy+2 more
WebflowGoogle Tag ManagerUsercentrics CMPLenis smooth scrolling+2

Partner Domains:

carrier.com
partner
gritec.com
subsidiary

+3 more partners

2025-10-18T21:57:01.658Z
ictrutnov.cz favicon

Informační centrum Trutnov

ictrutnov.cz

46
HospitalityCzech RepublicsmallHIGH

The website www.ictrutnov.cz serves as the official Tourist Information Center for the city of Trutnov, Czech Republic. It provides comprehensive visitor information including local attractions, events, and practical visitor services. The site targets tourists and visitors interested in exploring the region, offering multilingual support and a well-organized content structure. The business operates primarily in the hospitality and government/non-profit sectors, focusing on tourism promotion and visitor assistance. Technically, the website is built on Drupal 8 CMS and integrates modern web technologies such as Google Analytics, Google Tag Manager, FontAwesome icons, and AddToAny sharing tools. The site demonstrates good mobile optimization, accessibility, and SEO practices, with a moderate performance profile. Cookie consent and GDPR compliance mechanisms are implemented, reflecting awareness of privacy regulations. From a security perspective, the site uses HTTPS and cookie consent banners but lacks explicit security headers and incident response information. No vulnerabilities or exposed sensitive data were detected in the content. The absence of WHOIS data limits domain trust verification, although the website's official branding and contact information support its legitimacy. Overall, the site is professional, user-friendly, and trustworthy for its intended audience. Strategic improvements include enhancing security headers, publishing security policies, and improving domain registration transparency to strengthen trust and compliance.

40
25
17
70
52
85
-
tourisminformationcentertrutnoveventsvisitorservices+1 more
Drupal 8Google AnalyticsGoogle Tag ManagerFontAwesome+1
2025-10-18T21:55:16.446Z
I

Invoice Ninja

invoicing.co

57
TechnologyN/asmallMEDIUM

Invoice Ninja operates as a SaaS platform specializing in invoicing and billing solutions primarily targeting freelancers and small businesses. The website serves as a web application built with Flutter Web technology, integrating modern authentication methods such as Google, Apple, and Microsoft OAuth. The platform offers key services including online invoicing, payment processing, and PDF invoice generation. The market position is that of a niche invoicing software provider with a small business scale and moderate brand consistency. From a technical perspective, the site leverages a modern tech stack with Flutter, OAuth libraries, and client-side PDF rendering. Hosting appears to be via Cloudflare, with analytics implemented through Google Tag Manager and Cloudflare Insights. Performance and mobile optimization are moderate to good, though SEO and accessibility features are basic. The site uses service workers for offline capabilities and update management. Security posture shows some strengths such as HTTPS usage (inferred), OAuth authentication, and service worker management. However, no security headers are detected, and no visible privacy or cookie policies are present, indicating gaps in compliance and security best practices. No contact information or incident response channels are provided, limiting transparency and trust. Overall, the website is functional and moderately secure but lacks comprehensive privacy compliance and visible business contact details. Strategic improvements in security headers, privacy disclosures, and contact transparency would enhance trust and compliance. The risk level is moderate with no critical vulnerabilities detected in the static content analyzed.

25
35
2
70
75
85
100
invoicingbillingsaasflutteroauth+2 more
Flutter WebGoogle Tag Managerpdf.jsApple OAuth+2
2025-10-18T21:54:01.270Z
L

LUMITOS AG

chemie.de

55
ManufacturingGermanymediumMEDIUM

chemie.de is a leading German-language industry portal serving the chemical sector, providing comprehensive news, product catalogs, company directories, white papers, job listings, and educational resources. The platform targets professionals in chemical manufacturing, laboratory and process technology, research, and science. Operated by LUMITOS AG, the site demonstrates a mature digital presence with consistent branding and high-quality content tailored to industry needs. The business model centers on content aggregation and industry networking, positioning chemie.de as a trusted resource within its niche market. Technically, the website employs modern web technologies including jQuery, Bootstrap, Matomo, and Google Tag Manager, alongside a consent management platform to ensure GDPR compliance. The site is mobile-optimized with good SEO and accessibility basics, although some accessibility enhancements could be considered. Performance is moderate, with no significant technical debt or outdated components detected. From a security perspective, the site enforces HTTPS and uses consent management for cookies, but lacks explicit security headers and published security policies or incident response information. No vulnerabilities or exposed sensitive data were found in the analyzed content. The WHOIS data is consistent and transparent, reinforcing the domain's legitimacy. Overall, the security posture is solid but could be improved with additional headers and formal policies. The overall risk assessment is low, with the site presenting a professional, trustworthy, and compliant digital presence. Strategic recommendations include enhancing security headers, publishing security and incident response policies, and improving accessibility features to further strengthen trust and compliance.

20
40
2
75
52
65
100
chemistryindustryportallaboratoryprocesstechnologynews+5 more
jQuery 3.6.0Bootstrap 5Matomo Tag ManagerGoogle Tag Manager+1

Partner Domains:

www.lumitos.com
partner
www.chemeurope.com
partner

+1 more partners

2025-10-18T21:52:30.812Z
T

Threadless

threadless.com

73
E-commerceN/amediumMEDIUM

Threadless is an established e-commerce platform specializing in artist-designed apparel, accessories, and home decor. It operates a global marketplace that empowers independent artists to sell their designs on a variety of products, including t-shirts, hoodies, bags, and wall art. The platform also supports community engagement through design challenges and artist shops, fostering a vibrant creative ecosystem. The website is professionally designed with a clear focus on user experience and mobile optimization, supporting a broad consumer audience interested in unique, artist-driven merchandise. Technically, the site leverages modern web technologies such as jQuery, Google Tag Manager, Facebook Pixel, and lazy loading for images, ensuring efficient content delivery and robust marketing analytics. The presence of security headers and enforced HTTPS indicates a strong security posture, although some improvements in content security policy and public security policies could enhance protection. Privacy compliance is well addressed with comprehensive privacy and cookie policies, including consent mechanisms aligned with GDPR requirements. Security-wise, the site demonstrates good practices with no visible vulnerabilities or exposed sensitive data. However, the absence of publicly available incident response contacts and vulnerability disclosure policies suggests areas for improvement in transparency and readiness. The WHOIS data for the domain is unavailable, which is a minor concern but common for privacy-conscious businesses. Overall, the site presents a low risk profile with strong trust signals and a professional e-commerce presence. Strategically, Threadless should focus on enhancing its public security documentation and consider publishing vulnerability disclosure and incident response information to build further trust. Continuous monitoring of third-party scripts and regular security audits will help maintain a secure environment. The platform's strong community and artist support position it well for sustained growth in the niche of artist-driven e-commerce.

55
83
17
100
65
80
100
e-commerceartistmarketplaceapparelprint-on-demandcommunity+3 more
jQueryGoogle Tag ManagerFacebook PixelHandlebars.js+2
2025-10-18T21:52:20.795Z
bootstrapmade.com favicon

BootstrapMade

bootstrapmade.com

68
TechnologyN/asmallMEDIUM

BootstrapMade is a specialized provider of free and premium Bootstrap templates and themes, catering primarily to web developers, startups, and businesses seeking professional and responsive website designs. Established in 2013, the company has built a strong market presence with over 9 million downloads and a broad portfolio of templates across multiple industries. Their business model revolves around offering both free templates with footer credits and premium templates with advanced features and dedicated support, supplemented by a visual Bootstrap Template Builder for premium users. Technically, the website is built on modern web standards using Bootstrap 5, HTML5, CSS3, and JavaScript, hosted and protected by Cloudflare infrastructure. The site demonstrates excellent mobile optimization, fast performance, and good SEO practices. Analytics and tracking are implemented via Google Tag Manager and Cloudflare Insights, reflecting a moderate level of user tracking balanced with privacy considerations. From a security perspective, the site enforces HTTPS and uses Cloudflare DNS and hosting, providing a solid SSL configuration. However, explicit security headers such as Content-Security-Policy and X-Frame-Options are not visibly implemented, and no public security policy or incident response contacts are provided. Forms use secure POST methods, and no sensitive data exposure or vulnerabilities were detected in the HTML content. Overall, BootstrapMade presents a trustworthy and professional online presence with high-quality content and technical maturity. The absence of direct contact emails or phone numbers is mitigated by a contact form. Privacy and cookie policies are present with consent mechanisms, supporting GDPR compliance. Recommendations include enhancing security headers, publishing a security policy, and adding vulnerability disclosure information to further strengthen trust and security posture.

50
68
17
65
75
80
100
bootstraptemplatesthemesfreepremium+4 more
Bootstrap 5HTML5CSS3JavaScript+4
2025-10-18T21:51:10.473Z
aquahoteldecin.cz favicon

Děčínská sportovní, příspěvková organizace

aquahoteldecin.cz

59
HospitalityCzech RepublicsmallMEDIUM

The website booking.previo.app hosts a direct online booking platform for Aqua Hotel, operated by Děčínská sportovní, a Czech hospitality organization. The platform facilitates hotel reservations with clear business and contact information, supporting multiple languages and currencies. The site includes comprehensive privacy and cookie policies with consent mechanisms, and detailed terms of service including cancellation policies. The business targets general audiences seeking accommodation in Děčín, Czech Republic, positioning itself as a small local hospitality provider with direct booking capabilities. Technically, the website employs modern JavaScript libraries, Google Tag Manager, and analytics tools such as Smartlook and Contentsquare. The design is responsive and user-friendly, with good navigation and content relevance. However, some security best practices like security headers are missing, representing an area for improvement. The SSL configuration is good, and no critical vulnerabilities or exposed sensitive data were detected. From a security and compliance perspective, the site demonstrates good GDPR compliance with clear privacy disclosures and cookie consent. Incident response and security policy details are not explicitly provided, which could be enhanced. No suspicious or adult content is present, making the site safe for general users. The domain registration aligns well with the business entity, supporting legitimacy. Overall, the website is a professionally maintained hospitality booking platform with solid privacy and compliance posture, moderate technical sophistication, and room for security enhancements. Strategic recommendations include implementing security headers, enhancing incident response transparency, and continuous monitoring of third-party scripts to maintain security and trust.

20
35
17
65
72
85
100
hotelbookingreservationhospitalityprivacy+3 more
JavaScriptjQueryGoogle Tag ManagerSmartlook+1
2025-10-18T21:50:40.048Z
peatix.com favicon

Peatix Inc.

peatix.com

71
TechnologyJapanmediumMEDIUM

Peatix Inc. operates a well-established online platform specializing in event ticketing and community management, targeting event organizers and attendees globally. Founded in 2010, the company offers tools to promote, manage, and sell tickets for events, emphasizing simplicity, transparency, and customer support. The website reflects a professional and consistent brand image with a clear focus on its core business services. Technically, the website leverages modern JavaScript frameworks such as Vue.js, integrates Google Tag Manager and Facebook SDK for analytics and marketing, and is hosted on Amazon AWS infrastructure. The site is mobile-optimized and employs cookie consent mechanisms compliant with GDPR, enhancing user privacy and regulatory adherence. From a security perspective, Peatix enforces HTTPS, includes anti-clickjacking measures, and provides granular cookie consent options. However, there is room for improvement by enabling DNSSEC, adding explicit security headers, and publishing a formal security policy and incident response contacts. No critical vulnerabilities or exposed sensitive data were detected. Overall, Peatix presents a secure, compliant, and professionally maintained online presence with moderate to high trustworthiness. Strategic enhancements in security transparency and contact information disclosure would further strengthen its posture and user confidence.

75
65
2
100
72
70
100
eventmanagementticketingcommunityonlineregistrationpayment+1 more
JavaScriptjQueryGoogle Tag ManagerOneTrust Cookie Consent+1
2025-10-18T21:50:28.816Z
chachar.cz favicon

Chachar catering s.r.o.

chachar.cz

46
RetailCzech RepublicmediumHIGH

Chachar catering s.r.o. operates a regional pizza delivery and catering service in the Czech Republic, established since 2006. The company offers fast delivery of pizza, wings, and other fresh food items through an online ordering platform and telephone. With multiple branch locations across various Czech cities, the business targets general consumers seeking convenient food delivery. The website is professionally designed with consistent branding and good content quality, supporting a medium-sized enterprise model focused on retail and hospitality sectors. Technically, the website is built on WordPress 4.9.8 with a modern tech stack including jQuery, Bootstrap, Google Tag Manager, and reCAPTCHA for security. Hosting is consistent with Czech providers, and the site uses HTTPS with no detected blocking or WAF interference. Performance and mobile optimization are good, though accessibility is basic. SEO practices are adequate with proper meta tags and structured navigation. Security posture is solid with HTTPS, reCAPTCHA, and cookie consent mechanisms in place. However, explicit security headers and a formal security policy or incident response contacts are absent. No vulnerabilities or exposed sensitive data were found in the HTML content. Privacy compliance is evident with GDPR-related pages and cookie consent, though no dedicated data protection officer contact was identified. Overall, the website and business present a trustworthy and professional front with low risk. Strategic improvements include enhancing security headers, updating WordPress to the latest version, and publishing explicit security and incident response policies to further strengthen trust and compliance.

20
10
2
90
62
80
20
pizzafooddeliverycateringczechrepubliconlineordering+1 more
WordPress 4.9.8jQuery 3.3.1Bootstrap 4.3.1Google Tag Manager+5

Partner Domains:

bilovec-chachar.cz
subsidiary
bolatice-chachar.cz
subsidiary

+3 more partners

2025-10-18T20:48:42.228Z