Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157329
Websites
130
Industries
113
Countries
52
Avg Score
Page 263 of 800|Showing 13101-13150 of 39982
chase.com favicon

Chase

chase.com

56
FinanceUnited StatesenterpriseMEDIUM

Chase is a leading financial institution providing a wide range of banking and financial services including credit cards, mortgages, auto loans, investing, and business banking. The website serves both personal and business customers with a comprehensive digital platform that supports account management, payments, and financial planning. The brand is well-established with a strong market position as part of JPMorgan Chase & Co., one of the largest banking organizations in the United States. Technically, the website employs modern web technologies such as React and Next.js, ensuring a fast, responsive, and accessible user experience across devices. The site is well-optimized for SEO and includes comprehensive metadata and structured data to enhance search visibility. Security is robust with HTTPS enforcement, secure login forms, and multiple security headers implemented to protect users and data. From a security perspective, the site demonstrates strong best practices including secure forms, no exposed sensitive data, and use of security headers. However, the absence of a publicly visible vulnerability disclosure program and incident response contact details suggests areas for improvement. Privacy compliance is well addressed with clear privacy and cookie policies, including GDPR considerations. Overall, the website is professional, trustworthy, and secure, reflecting the stature of a major financial services provider. The WHOIS data anomaly does not detract from the legitimacy but should be further investigated to ensure domain registration transparency. Strategic recommendations include enhancing vulnerability disclosure visibility, maintaining security certifications, and continuous monitoring of third-party scripts.

-
-
-
85
82
90
100
bankingfinancecreditcardsmortgageautoloans+2 more
ReactJavaScriptWebpackNext.js+2

Partner Domains:

www.jpmorgan.com
parent
autofinance.chase.com
subsidiary

+2 more partners

2025-10-11T05:32:34.902Z
workers.dev favicon

Cloudflare

workers.dev

74
TechnologyN/aenterpriseMEDIUM

Cloudflare Workers Platform is a leading serverless computing service that enables developers to deploy code globally on Cloudflare's extensive network infrastructure. The platform supports AI inference, storage, and compute capabilities, targeting developers and enterprises seeking scalable, low-latency edge computing solutions. The website is professionally designed, well-branded, and provides comprehensive information about the platform's features and customer base, including major companies like Shopify and Atlassian. Technically, the site leverages modern web technologies including Astro framework, React Flow for interactive diagrams, and Cloudflare's own CDN and infrastructure. The site is optimized for performance and mobile responsiveness, with good accessibility and SEO practices. Security posture is strong with HTTPS enforced and no visible vulnerabilities, though explicit security headers and policies could be improved. Privacy compliance is limited on this page, with no visible privacy or cookie policies or consent mechanisms. Contact and incident response information is not provided here, which could be enhanced to improve trust and compliance. The WHOIS data for the subdomain is not available, which is expected for subdomains, and the main domain cloudflare.com is a well-established and reputable entity. Overall, the site is trustworthy, professional, and technically sound, but could improve in privacy transparency and security policy disclosures to further enhance compliance and user trust.

95
70
2
82
65
90
100
serverlesscloudcomputingedgecomputingdeveloperplatformcloudflare+4 more
JavaScriptTypeScriptReact FlowAstro framework+3
2025-10-11T05:31:59.702Z
myptv.com favicon

PTV Logistics

myptv.com

74
TransportationN/alargeMEDIUM

PTV Logistics is a globally recognized provider of advanced software solutions specializing in route planning, optimization, real-time transport visibility, and delivery management. With over 40 years of expertise, the company targets logistics and transport managers aiming to enhance operational efficiency, reduce costs, and support sustainable logistics practices including fleet electrification. The website reflects a mature digital presence with comprehensive content, professional design, and strong GDPR compliance mechanisms including a detailed privacy policy and cookie consent management. Technically, the website leverages modern frameworks such as Drupal 10 and Tailwind CSS, integrates Google Tag Manager for analytics, and employs Google reCAPTCHA Enterprise for bot mitigation. The infrastructure supports mobile responsiveness and accessibility, ensuring a positive user experience across devices. However, the absence of explicit WHOIS registration data and lack of direct contact emails or phone numbers slightly diminish the business credibility from a domain registration perspective. Security posture is robust with HTTPS enforced, security headers implied, and privacy compliance well addressed. Yet, the site lacks visible security policies, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for enhanced trust and transparency. Overall, PTV Logistics presents a professional and secure online platform suitable for its target audience, though improvements in domain transparency and security communication would strengthen its risk profile and stakeholder confidence.

70
85
17
80
72
85
100
logisticsrouteplanningoptimizationdeliverymanagementtransportvisibility+4 more
Drupal 10Tailwind CSSJavaScriptGoogle reCAPTCHA Enterprise+2

Partner Domains:

legal.myptv.com
partner
login.myptv.com
partner

+3 more partners

2025-10-11T04:27:02.677Z
T

Thuisbezorgd

thuisbezorgd.nl

76
E-commerceNetherlandslargeLOW

Thuisbezorgd.nl is a leading Dutch online food and grocery delivery platform, founded in 2000 and operating under the parent company Just Eat Takeaway.com. The website offers a comprehensive range of services including takeaway food ordering, grocery deliveries, corporate ordering, and courier recruitment. It targets consumers in the Netherlands seeking convenient delivery options from over 15,000 restaurants and stores. The platform is well-positioned in the market with a strong brand presence and extensive service offerings. Technically, the website employs modern web technologies such as React and Next.js, supported by robust infrastructure likely hosted on cloud platforms. It integrates advanced analytics and marketing tools including Google Tag Manager, Snowplow, and Braze, reflecting a mature digital ecosystem. The site is optimized for performance, mobile responsiveness, accessibility, and SEO, providing an excellent user experience. From a security perspective, the site enforces HTTPS, implements key security headers, and follows best practices in form security and data protection. While no critical vulnerabilities were detected, the absence of a dedicated security policy page and security.txt file suggests room for improvement in transparency and incident response readiness. Privacy compliance is strong, with clear privacy and cookie policies and GDPR adherence. Overall, Thuisbezorgd.nl demonstrates a high level of professionalism, security, and compliance, making it a trustworthy platform for users. Strategic recommendations include enhancing security transparency, publishing a security.txt file, and maintaining vigilant third-party script management to sustain its strong security posture.

70
88
35
72
82
70
100
fooddeliverygrocerydeliverye-commercenetherlandsthuisbezorgd+1 more
ReactNext.jsJavaScriptCloudinary+5

Partner Domains:

justeattakeaway.com
parent
convercent.com
partner

+2 more partners

2025-10-11T04:25:42.097Z
tanjug.rs favicon

Mainstream Public Cloud Services d.o.o.

tanjug.rs

55
MediaSerbiamediumMEDIUM

Tanjug.rs is a well-established Serbian news portal providing comprehensive coverage of national and international news including politics, sports, culture, and economy. The website offers multimedia content such as photo galleries, video stories, and live TV streaming, targeting a broad general audience interested in current events. The business model appears to be media publishing with subscription-based access for certain content, supported by advertising revenue. The domain has been active since 2008 and is hosted by Mainstream Public Cloud Services d.o.o., indicating a stable and legitimate online presence. Technically, the website employs modern web technologies including Google Fonts, jQuery Fancybox, Swiper, Owl Carousel, and Google Tag Manager for analytics and advertising. The site is mobile-optimized with good navigation and content structure, although accessibility features are basic. Performance is moderate, with room for improvement in loading speed and advanced SEO. From a security perspective, the site uses HTTPS with a good SSL configuration but lacks DNSSEC and advanced security headers such as Content-Security-Policy and X-Frame-Options. There is no visible security policy, incident response information, or vulnerability disclosure mechanism, which are areas for improvement. Privacy compliance is partial; a privacy policy is present but cookie consent mechanisms and GDPR compliance indicators are minimal. Overall, Tanjug.rs is a credible and professional media website with a solid business foundation and good technical implementation. However, enhancements in security posture, privacy compliance, and transparency regarding contact and incident response would strengthen trust and regulatory adherence.

15
35
17
70
62
60
100
newsmediaserbiapoliticssports+2 more
Google FontsjQuery FancyboxSwiperOwl Carousel+5
2025-10-11T04:25:01.506Z
fena.ba favicon

JU Federalna novinska agencija (FENA)

fena.ba

53
MediaBosnia and HerzegovinamediumMEDIUM

Federalna novinska agencija (FENA) operates as a national news agency providing comprehensive news coverage from Bosnia and Herzegovina, the region, and international affairs. The website offers a broad range of news categories including politics, economy, culture, sports, and multimedia content such as photos and videos. The agency maintains a professional market position with affiliations to recognized news alliances, enhancing its credibility and reach. Technically, the website employs modern web technologies including Google Fonts, Google Analytics, Facebook SDK, and Google Publisher Tags for advertising. The site is mobile optimized with good navigation and content structure, although it lacks explicit CMS identification. Performance is moderate with asynchronous script loading to improve user experience. From a security perspective, the site uses HTTPS with good SSL configuration but lacks important security headers and a cookie consent mechanism, which impacts privacy compliance. No visible forms or sensitive data exposure were detected, but incident response and security policies are not publicly documented. The WHOIS data aligns well with the business identity, supporting legitimacy. Overall, the website is a reliable and professional news source with room for improvement in privacy compliance and security best practices. Strategic enhancements in these areas would strengthen user trust and regulatory adherence.

55
35
17
85
72
85
-
newsmediabosniaandherzegovinajournalismmultimedia+5 more
Google FontsGoogle AnalyticsGoogle Tag ManagerFacebook SDK+4

Partner Domains:

newsalliance.org
partner
abnase.com
partner

+2 more partners

2025-10-11T04:24:36.199Z
getstream.io favicon

Stream

getstream.io

71
TechnologyN/aenterpriseMEDIUM

Stream is a technology company specializing in scalable APIs and SDKs for building in-app chat messaging, video, and activity feeds. Established in 2014, it serves a large enterprise market with over 1 billion end users and 2000+ apps relying on its platform. The company positions itself as a leader in developer experience and enterprise-grade infrastructure, offering high availability and compliance certifications such as HIPAA, GDPR, ISO 27001, and SOC 2. The website reflects a mature digital presence with modern frameworks and a strong focus on developer tools and integrations. Technically, the website is built using Next.js and React, hosted on AWS infrastructure, and leverages Prismic CMS for content management. It demonstrates fast performance, mobile optimization, and good SEO practices. The presence of Cookiebot indicates a commitment to cookie consent and privacy compliance, although explicit privacy and terms of service documents are not found in the provided content. From a security perspective, the site uses HTTPS with strong SSL configuration and displays multiple compliance certifications, indicating a robust security posture. However, there is room for improvement in publishing explicit security policies, incident response contacts, and vulnerability disclosure mechanisms. No critical vulnerabilities or suspicious patterns were detected. Overall, Stream presents a professional, trustworthy, and technically advanced platform with a strong market position in the developer tools space. Strategic recommendations include enhancing transparency around privacy and security policies and adding direct contact information to improve user trust and compliance.

65
65
17
85
77
75
100
chatvideoactivityfeedssdkapi+5 more
ReactNext.jsPrismic CMSAWS DNS+4
2025-10-11T04:21:55.869Z
B

Boston Consulting Group

bcg.com

77
OtherN/aenterpriseLOW

Boston Consulting Group (BCG) is a globally recognized management consulting firm specializing in strategic management consulting and business transformation services. The website reflects BCG's market position as a leader in consulting, targeting business leaders and organizations seeking to address complex challenges. The site content is professionally crafted, emphasizing BCG's expertise and global reach. Technically, the website employs modern web technologies including Adobe Analytics, TrustArc for consent management, and SVG-based iconography. The site is well-optimized for mobile devices and accessibility, with good SEO practices and performance. The use of advanced analytics and consent frameworks indicates a mature digital infrastructure. From a security perspective, the site enforces HTTPS and integrates consent management for privacy compliance. However, explicit security headers are not evident in the provided data, and no public security policy or incident response information is available. No vulnerabilities or exposed sensitive data were detected in the analysis. Overall, the website presents a low risk profile with strong business credibility and privacy compliance. The absence of WHOIS data limits domain trust assessment but does not detract from the site's professional presentation and operational maturity. Strategic recommendations include enhancing security headers, publishing security policies, and establishing a vulnerability disclosure program to further strengthen trust and security posture.

30
83
73
85
79
85
100
consultingmanagementbusinessstrategyprivacy+2 more
Adobe AnalyticsTrustArc Consent ManagementModernizrWeb Components+3
2025-10-11T04:21:35.834Z
nba.nl favicon

Koninklijke Nederlandse Beroepsorganisatie van Accountants

nba.nl

54
FinanceNetherlandslargeMEDIUM

The Koninklijke Nederlandse Beroepsorganisatie van Accountants (NBA) is the official professional organization for accountants in the Netherlands, providing regulatory guidance, educational resources, and member services. The website serves as a comprehensive portal for accountants to access current regulations, tools, events, and professional development materials. It holds a strong market position as the authoritative body for accounting professionals in the country. Technically, the website employs modern web technologies including Vue.js, EpiServer CMS, and integrates telemetry and analytics via Microsoft Application Insights and Google Tag Manager. The site is hosted likely on Microsoft Azure, with good mobile optimization and moderate performance. SEO and accessibility are adequately addressed, though accessibility could be improved. From a security perspective, the site enforces HTTPS and uses telemetry for monitoring but lacks explicit security headers and visible security policies such as privacy or cookie policies. No vulnerability disclosure or incident response contacts are published, which could be improved to enhance trust and compliance. No critical vulnerabilities or suspicious content were detected. Overall, the website is professional, trustworthy, and well-aligned with its business purpose. However, it would benefit from enhanced privacy compliance, explicit contact information, and improved security policy transparency to strengthen its security posture and user trust.

85
10
2
70
-
80
100
accountingfinanceprofessionalorganizationnetherlandseducation+1 more
JavaScriptGoogle Tag ManagerMicrosoft Application InsightsAzure Monitoring+2
2025-10-11T04:20:40.670Z
matrix.org favicon

Matrix.org Foundation

matrix.org

67
TechnologyN/amediumMEDIUM

Matrix.org operates as the foundation and hub for the Matrix open protocol, which enables secure, decentralized communication across chat, VoIP, and data transfer. The organization positions itself as a leading open communication protocol with a strong community and open source ecosystem, offering clients, servers, bridges, SDKs, and hosting solutions. The website reflects a mature, well-established technology entity with a medium-sized footprint and a focus on transparency and security. Technically, the website is well-constructed with modern HTML5, CSS, and JavaScript technologies, hosted behind Cloudflare DNS services. It demonstrates excellent design quality, mobile optimization, and accessibility. The use of privacy-conscious analytics (Plausible) and absence of intrusive advertising reflects a privacy-aware digital maturity. However, the lack of DNSSEC and cookie consent mechanisms are areas for improvement. From a security perspective, the site enforces HTTPS, maintains domain transfer restrictions, and publishes a security disclosure policy and hall of fame, indicating a proactive security posture. No critical vulnerabilities or exposed sensitive data were detected. The absence of security headers and a security.txt file are minor gaps. Overall, the security posture is strong but could be enhanced with additional DNS and header configurations. The overall risk assessment is low, with the website demonstrating high professionalism, trustworthiness, and compliance with GDPR principles, though cookie consent implementation is recommended. Strategic recommendations include enabling DNSSEC, adding cookie consent, publishing security.txt, and providing explicit DPO contact information to further strengthen compliance and trust.

80
35
2
85
75
70
100
opensourcedecentralizedcommunicationmatrixprotocolsecurechattechnology
HTML5CSSJavaScriptCloudflare DNS
2025-10-11T04:19:30.502Z
fontstore.com favicon

Fontstore Ltd.

fontstore.com

57
TechnologyIndiasmallMEDIUM

Fontstore.com is a specialized e-commerce platform offering premium font distribution services, primarily targeting designers and businesses requiring multilingual font solutions. The company, Fontstore Ltd., has been operating since 2003, positioning itself as a niche player in the font licensing market with a focus on quality and language diversity. The website is professionally designed with good navigation and content relevance, supporting a positive user experience for its target audience. Technically, the site employs modern JavaScript frameworks, likely Vue.js, and integrates Stripe for secure payment processing. Hosting is provided via GoDaddy, and the domain is well-established with standard domain status protections. Performance and mobile optimization are adequate, though accessibility features are basic. SEO practices appear solid with proper meta tags and Open Graph data. From a security perspective, the site uses HTTPS and Stripe for payments, which is a strong positive. However, it lacks DNSSEC, visible security headers, and formal privacy or cookie policies, which are important for compliance and trust. No incident response or vulnerability disclosure information is present, indicating room for improvement in security transparency and readiness. Overall, the website is legitimate and professionally maintained but would benefit from enhanced privacy compliance, security headers, and clearer contact information to improve trust and regulatory adherence.

15
50
2
70
77
65
100
fontstypographyfontlicensingmultilingualfontse-commerce
JavaScriptStripe payment integrationCustom fonts (woff2)SVG icons
2025-10-11T03:16:45.147Z
M

You're invited to talk on Matrix

matrix.to

59
TechnologyN/asmallMEDIUM

Matrix.to is a specialized web service that facilitates the creation of shareable links for Matrix rooms, users, and messages, enabling users to join decentralized and secure communication channels without being tied to any specific client application. It operates within the Matrix ecosystem, which is an open network for secure, decentralized communication. The website targets users and communities interested in privacy-focused chat solutions and supports the broader adoption of Matrix technology. Technically, the website employs client-side JavaScript and CSS to deliver its functionality, emphasizing privacy by processing data locally in the browser. The site is moderately optimized for performance and mobile use, though accessibility and SEO features are basic. No content management system or hosting provider details are evident from the provided data. From a security perspective, the site uses HTTPS (implied by the domain and external links) but lacks visible security headers and formal privacy or cookie policies, which limits its compliance posture. No contact information or incident response channels are provided, which could hinder user trust and security incident handling. The absence of tracking or advertising technologies aligns with the privacy-centric ethos of the Matrix ecosystem. Overall, Matrix.to presents a trustworthy and niche service with good content quality and business credibility but would benefit from enhanced privacy compliance, security best practices, and clearer user support channels to improve its security posture and user trust.

30
50
2
70
75
75
100
matrixdecentralizedcommunicationsecurechat+1 more
JavaScriptCSS
2025-10-11T03:15:58.973Z
raygun.io favicon

Raygun

raygun.io

77
TechnologyN/amediumLOW

Raygun is a well-established technology company specializing in application monitoring solutions for web and mobile applications. Their platform offers comprehensive services including crash reporting, real user monitoring, application performance monitoring, and AI-driven error resolution. The company targets developers, CTOs, product managers, and performance engineers, positioning itself as a trusted partner for businesses ranging from startups to Fortune 500 companies. The website reflects a mature SaaS business model with a strong focus on customer experience and technical excellence. Technically, the website is built on modern frameworks and technologies including Webflow CMS, JavaScript libraries, and integrates with multiple analytics and marketing platforms such as Google Tag Manager, HubSpot, and Snowplow. Hosting is provided via Amazon AWS, ensuring scalability and performance. The site is well-optimized for mobile devices and accessibility, with fast loading times and clear navigation. From a security perspective, the site enforces HTTPS, employs clientTransferProhibited domain status, and claims compliance with major regulations such as HIPAA, GDPR, CCPA, and PCI. However, DNSSEC is not enabled, and no explicit security.txt or incident response contacts were found. The privacy and cookie policies are comprehensive and include consent mechanisms, supporting GDPR compliance. Overall, Raygun's website demonstrates a high level of professionalism, technical maturity, and security awareness. The domain's long registration history and consistent WHOIS data further reinforce the company's legitimacy. Minor improvements could be made in DNS security and incident response transparency to enhance trust and security posture.

60
80
47
75
82
80
100
applicationmonitoringcrashreportingrealusermonitoringaierrorresolutionsaas+3 more
JavaScriptjQueryGoogle Tag ManagerSnowplow Analytics+2
2025-10-11T03:14:08.571Z
about.google favicon

Google

about.google

62
TechnologyUnited StatesenterpriseMEDIUM

Google LLC is a global technology leader specializing in internet-related products and services including search, cloud computing, AI, and consumer electronics. The company holds a dominant market position with a broad portfolio of innovative AI products and services, targeting a general audience worldwide. The website about.google serves as a corporate information hub showcasing Google's technology, products, research, and global impact. The site is professionally designed, mobile-optimized, and provides comprehensive information about Google's offerings and initiatives. Technically, the website leverages modern web technologies including HTML5, CSS3, JavaScript, Google Tag Manager, and Google Fonts, hosted on Google Cloud infrastructure. The use of internal frameworks like Google Glue and Webpack indicates a mature and scalable technical infrastructure. Performance is fast, with excellent SEO and accessibility features implemented. From a security perspective, the website enforces HTTPS with strong SSL configuration and includes multiple security headers. It employs cookie consent mechanisms and integrates Google Tag Manager for analytics and marketing. No vulnerabilities or exposed sensitive data were detected. Privacy policies and terms of service are comprehensive and GDPR compliant, reflecting a strong commitment to user privacy and data protection. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance. It effectively supports Google's brand and business objectives while maintaining robust security and privacy standards.

60
68
2
60
42
70
100
technologyaigooglecorporateproducts+4 more
HTML5CSS3JavaScriptGoogle Tag Manager+2

Partner Domains:

deepmind.google
subsidiary
cloud.google.com
subsidiary

+3 more partners

2025-10-11T03:11:47.761Z