Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 27 of 166|Showing 1301-1350 of 8294
krystal.co.uk favicon

Krystal Hosting Ltd

krystal.co.uk

77
TechnologyUnited KingdommediumLOW

Krystal Hosting Ltd is a UK-based web hosting provider specializing in premium, green hosting solutions powered by 100% renewable energy. The company offers a broad range of hosting services including shared web hosting, business hosting, managed WordPress hosting, reseller hosting, VPS, dedicated servers, and a proprietary public cloud platform called Katapult. Positioned as a sustainable and customer-focused hosting provider, Krystal emphasizes performance, security, and environmental responsibility, supported by certifications such as ISO 27001 and B Corp status. Their market position is strengthened by a strong client base, high customer satisfaction ratings, and a commitment to planting trees for every active client. Technically, the website is built on modern frameworks like Next.js and React, ensuring fast performance and excellent mobile optimization. The infrastructure leverages NVMe SSD storage and LiteSpeed caching to deliver high-speed hosting services. Security is robust, with enforced HTTPS, DDoS protection, real-time malware scanning, and daily backups, aligning with their ISO 27001 certification. Privacy compliance is well addressed with clear privacy and cookie policies, including consent mechanisms. Overall, Krystal demonstrates a mature digital presence with strong security posture and business credibility. The website is professional, accessible, and optimized for SEO, providing a trustworthy user experience. No critical vulnerabilities or suspicious activities were detected, and the WHOIS data confirms the legitimacy and consistency of the domain registration. Strategic recommendations include publishing explicit incident response and vulnerability disclosure policies to enhance transparency and security readiness, adding a security.txt file for vulnerability reporting, and considering the publication of Data Protection Officer contact details to strengthen GDPR compliance and trust.

95
53
55
75
72
80
100
webhostinggreenhostingcloudhostingukhostingiso27001+2 more
Next.jsReactcPanelLiteSpeed caching+1

Partner Domains:

katapult.io
partner
sirportly.com
partner

+1 more partners

2025-10-23T09:16:51.328Z
checkyouridea.com favicon

MARS – Center for Entrepreneurship

checkyouridea.com

41
EducationGermanysmallHIGH

CheckYourIdea is an educational and startup support platform developed by the MARS Center for Entrepreneurship at Mannheim University of Applied Sciences, in collaboration with Worms University of Applied Sciences. The platform offers a free online tool to assess the maturity level of business ideas and provides personalized two-page feedback reports. It targets founders, startup consultants, and investors, aiming to facilitate efficient startup consulting and investment decision-making. The business model focuses on providing value through academic partnerships and embedding options for institutions. Technically, the website is built using modern web technologies including React and Next.js, hosted under a reputable registrar. The site is well-optimized for performance, mobile-friendly, and accessible, with a clean and professional design. SEO and metadata are properly implemented, enhancing discoverability. From a security perspective, the site uses HTTPS and secure form inputs but lacks advanced security headers and explicit security policies. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with a comprehensive privacy and cookie policy, including consent mechanisms. However, terms of service and incident response information are absent. Overall, the website presents a low-risk profile with strong business credibility and technical maturity. Recommendations include enabling DNSSEC, adding security headers, publishing security policies, and considering a vulnerability disclosure program to further enhance trust and security posture.

20
53
2
70
52
45
-
businessstartupeducationassessmententrepreneurship
ReactNext.jsJavaScriptCSS
2025-10-23T08:50:40.579Z
eventbrite.at favicon

Eventbrite

eventbrite.at

73
TechnologyAustriaenterpriseMEDIUM

Eventbrite is a leading global technology company specializing in online event discovery, creation, and ticketing services. The website targets event organizers and attendees primarily in Austria and German-speaking regions, offering a comprehensive platform for managing and marketing events. The company holds a strong market position with a mature digital presence and localized content tailored for Austria. The platform provides key services including event discovery, ticket sales, event marketing, and payment processing, supported by a robust technical infrastructure. Technically, the website leverages modern web technologies such as React, integrates multiple analytics and marketing tools including Google Analytics, Facebook Pixel, TikTok Pixel, and Branch.io, and employs a consent management system via Transcend. The site is hosted on reliable CDN infrastructure, optimized for performance, mobile responsiveness, and accessibility, ensuring a high-quality user experience. From a security perspective, Eventbrite enforces HTTPS with strong SSL configurations, implements essential security headers, and manages user consent effectively. No critical vulnerabilities or exposed sensitive data were detected. However, explicit incident response contact information and a vulnerability disclosure policy could enhance their security posture further. Overall, Eventbrite's website demonstrates a high level of professionalism, security, and privacy compliance, making it a trustworthy platform for event management and ticketing. Strategic recommendations include publishing clear incident response contacts, adding a security.txt file, and continuous monitoring of third-party scripts to maintain security integrity.

30
73
17
100
82
90
100
eventmanagementticketingeventsonlineticketseventmarketing+2 more
ReactGoogle AnalyticsGoogle Tag ManagerBranch.io+3

Partner Domains:

branch.io
partner
2025-10-23T06:29:58.611Z
easyname.eu favicon

easyname

easyname.eu

67
TechnologyAustriamediumMEDIUM

easyname is a medium-sized Austrian technology company specializing in web hosting, domain registration, and website building services. The company targets individuals and businesses seeking reliable and easy-to-use online presence solutions. Their market position is that of an established regional player with a multilingual website offering a broad portfolio of services including VPS hosting, SSL certificates, and marketing tools. The website content is professional, well-structured, and designed to facilitate user engagement and conversion. Technically, the website leverages modern web technologies such as React and Chakra UI, with integrations for Google Tag Manager and a consent management platform to ensure privacy compliance. The site is mobile-optimized and accessible, with good SEO practices evident in meta tags and structured data. Performance is moderate, with deferred scripts and optimized assets. From a security perspective, the site enforces HTTPS and uses consent management for cookies, but lacks explicit security headers and publicly available security policies or incident response information. No vulnerabilities or exposed sensitive data were detected in the HTML content. The WHOIS data is consistent with the business claims, supporting legitimacy. Overall, easyname presents a trustworthy and professional online presence with good privacy compliance and a solid technical foundation. Strategic improvements in security headers and transparency around security policies would further enhance their security posture and trustworthiness.

80
33
10
70
72
85
100
webhostingdomainswebsitebuildersslvps+2 more
ReactChakra UIGoogle Tag ManagerConsent Manager+1
2025-10-23T06:28:58.168Z
misterspex.com favicon

Mister Spex SE

misterspex.com

11
RetailFinlandlargeCRITICAL

Mister Spex SE is a leading European omnichannel eyewear retailer founded in 2007, specializing in the sale of prescription glasses, sunglasses, and contact lenses. The company operates multiple online stores across Europe and physical retail locations, serving over 7.1 million customers. Their business model focuses on digital innovation, including virtual try-on and home trial services, positioning them as a market leader in digital eyewear retail. The website is professionally designed, mobile-optimized, and provides comprehensive product and service information in Finnish, targeting Finnish consumers. Technically, the site leverages modern frameworks such as Next.js and React, uses CDN services like CloudFront, and integrates advanced personalization and consent management tools, reflecting a mature digital infrastructure. Security-wise, the site enforces HTTPS, implements strong security headers, and uses cookie consent mechanisms, though it lacks publicly available security policies or incident response details. Overall, the site demonstrates a high level of professionalism, trustworthiness, and compliance with privacy regulations, making it a reliable platform for consumers. Strategic recommendations include publishing explicit security and incident response policies and adding vulnerability disclosure information to enhance transparency and trust.

-
-
-
-
-
-
-
eyewearopticsecommerceglassescontactlenses+4 more
ReactNext.jsCloudinary (image hosting)Google Tag Manager+2
2025-10-23T05:25:15.644Z
passware.com favicon

Passware

passware.com

67
TechnologyN/amediumMEDIUM

Passware operates as a specialized software company providing password recovery and decryption tools primarily targeting forensic teams, businesses, and home office users. The company positions itself as a world leader in encrypted electronic evidence discovery, serving high-profile clients including law enforcement agencies and Fortune 500 corporations. Their product suite includes solutions for files, disks, and mobile devices with distributed computing capabilities and hardware acceleration. Technically, the website is built on a modern React and Next.js framework, leveraging Google Tag Manager for analytics and OneTrust for cookie consent management. The site is well-structured, mobile-optimized, and provides a professional user experience. However, there is a lack of explicit security headers and no visible incident response or vulnerability disclosure information, which could be improved. Security posture is solid with HTTPS enforced and no exposed sensitive data, but the absence of WHOIS data for the domain introduces a transparency concern. Despite this, the website's branding, client references, and comprehensive privacy and cookie policies indicate a legitimate and trustworthy business. Overall, the risk is moderate due to the WHOIS data gap, but the company demonstrates strong market presence and technical maturity. Strategic improvements in security transparency and direct contact information could enhance trust and compliance.

65
53
2
75
82
75
100
passwordrecoveryforensicsdecryptionsecuritysoftware+3 more
ReactNext.jsGoogle Tag ManagerOneTrust Cookie Consent
2025-10-23T05:20:29.388Z
helmholtz.social favicon

Hermann von Helmholtz-Gemeinschaft Deutscher Forschungszentren e.V.

helmholtz.social

72
GovernmentGermanymediumMEDIUM

The website helmholtz.social serves as a dedicated Mastodon instance for the Helmholtz Association of German Research Centers, facilitating decentralized and institutional scientific communication. It is positioned as a non-commercial platform targeting Helmholtz centers, their member institutions, and selected initiatives. The platform leverages modern open-source technologies, primarily Mastodon version 4.4.8, with a React-based frontend and WebSocket streaming for real-time feeds. Hosting is provided by a German company with servers located in the EU, ensuring compliance with regional data protection laws. From a security perspective, the site enforces HTTPS and employs encrypted connections, though explicit security headers are not evident in the HTML source. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with a comprehensive GDPR-aligned privacy policy and clear data retention practices. Contact information and legal disclosures are thorough, enhancing business credibility and trust. However, the absence of a cookie consent mechanism and terms of service page are areas for improvement. Overall, the site demonstrates a mature technical infrastructure and a solid security posture appropriate for an institutional platform. The lack of WHOIS data due to TLD restrictions is mitigated by the detailed legal imprint and contact transparency. The platform is safe for general audiences, with no adult or questionable content. Strategic recommendations include enhancing security headers, publishing incident response policies, and implementing cookie consent to further strengthen compliance and trust.

80
70
17
70
85
75
100
mastodonsocialmediascientificcommunicationhelmholtznon-commercial+2 more
Mastodon 4.4.8ReactJavaScript ES ModulesCSS+1
2025-10-23T05:19:14.059Z
reservix.de favicon

Reservix GmbH

reservix.de

68
E-commerceGermanymediumMEDIUM

Reservix GmbH operates a well-established online ticketing platform primarily serving the German market. The website offers a broad range of event tickets including concerts, sports, musicals, and family events. The platform targets general consumers seeking convenient online ticket purchases and event information. The business model is e-commerce focused, with additional services such as voucher sales and event promotion. The company demonstrates consistent branding and maintains a professional online presence with good content quality and user experience. Technically, the website leverages modern JavaScript frameworks including React and Swiper.js for UI components, and integrates Google Tag Manager and Usercentrics for marketing and consent management. Hosting is provided via Amazon AWS, indicated by the DNS infrastructure. The site is mobile optimized and accessible, with good SEO practices and structured data for enhanced search engine visibility. From a security perspective, the site enforces HTTPS and uses a consent management platform to comply with GDPR. However, explicit security headers are not evident in the HTML content, and no published security or incident response policies were found. No vulnerabilities or exposed sensitive data were detected. The WHOIS data aligns with a legitimate business, showing no privacy protection and consistent domain registration. Overall, Reservix.de presents a secure, professional, and user-friendly ticketing portal with strong compliance and marketing practices. Strategic improvements could include publishing explicit security policies and enhancing HTTP security headers to further strengthen the security posture.

70
45
2
75
100
70
100
ticketingeventsconcertssportsecommerce+1 more
JavaScriptReactSwiper.jsGoogle Tag Manager+2
2025-10-23T03:02:35.009Z
digitalconcerthall.com favicon

Berliner Philharmoniker

digitalconcerthall.com

67
MediaGermanymediumMEDIUM

The Digital Concert Hall is a specialized streaming platform operated under the brand of the Berliner Philharmoniker, a world-renowned classical orchestra based in Germany. The platform offers live and on-demand streaming of concerts, films, interviews, and other classical music content, targeting classical music enthusiasts globally. The business model is subscription-based, with options for monthly or annual access, positioning it as a niche leader in classical music digital media. Technically, the website leverages modern web technologies including React and Theoplayer for video streaming, with good mobile optimization and accessibility features. The presence of structured data and SEO best practices enhances discoverability. Security posture is strong with HTTPS enforced and multiple security headers present, though the absence of a visible cookie consent mechanism and published security policies are areas for improvement. The lack of WHOIS data is a notable anomaly, potentially indicating privacy protection or a recent domain registration, which slightly reduces trustworthiness. Overall, the site is professional, trustworthy, and well-positioned in its market segment.

55
53
2
65
100
75
100
classicalmusicstreamingconcertsberlinerphilharmonikermedia+3 more
ReactTheoplayer (video player)Plausible AnalyticsGoogle Cast SDK+2

Partner Domains:

www.berliner-philharmoniker.de
partner
www.berliner-philharmoniker-recordings.com
partner

+1 more partners

2025-10-23T03:00:08.659Z
N

ne16.com

ne16.com

60
OtherN/asmallMEDIUM

The website at app.ne16.com/Analytics/Home is a minimal login portal likely serving as an internal or customer-facing analytics application. The site uses modern frontend technologies such as React and integrates third-party services like Appcues and Segment for user experience and analytics tracking. However, the site lacks publicly accessible business information, privacy policies, cookie consent mechanisms, and contact details, limiting transparency and trust. The absence of WHOIS data for the subdomain further complicates legitimacy verification, suggesting this is a private or internal application rather than a public-facing commercial website. Technically, the site employs modern JavaScript frameworks and asynchronous loading of scripts, indicating a contemporary tech stack. Performance and mobile optimization appear basic but functional. Security posture is weak due to missing HTTPS confirmation, lack of security headers, and no visible security or privacy policies. The login form collects email and password but no visible security measures like CAPTCHA or multi-factor authentication are evident. Overall, the security posture is minimal with significant gaps in privacy compliance and transparency. The lack of WHOIS data and business information reduces trustworthiness. There are no indications of malicious content or adult material, but the site’s limited content and lack of policies suggest it is not intended for broad public use. Strategic improvements in security headers, HTTPS enforcement, privacy disclosures, and contact information are recommended to enhance trust and compliance. The risk assessment indicates a low to moderate risk primarily due to limited transparency and security best practices. The site is suitable for authenticated users but should improve compliance and security to meet enterprise standards.

65
50
2
70
77
75
100
loginanalyticsappreactsecurity
ReactAppcuesSegment
2025-10-23T01:18:45.207Z
zt-archiv.at favicon

zt:archiv

zt-archiv.at

63
GovernmentAustriasmallMEDIUM

The zt:archiv website serves as the official digital archive platform for civil engineers (Ziviltechniker:innen) in Austria, enabling secure storage, qualified electronic signing, and public access to official documents. The platform is government-authorized and targets professionals in the civil engineering sector, as well as authorities and project partners. The business model revolves around providing a legally compliant, secure, and efficient digital archiving service, supporting the professional responsibilities and legal obligations of its users. Technically, the website employs a modern React-based frontend with PDF.js integration for document handling. The site is mobile-optimized and demonstrates good performance and usability, although some accessibility features could be enhanced. The content is well-structured and professionally presented, with consistent branding and clear navigation. From a security perspective, the site enforces HTTPS and uses qualified digital signatures to ensure document authenticity. However, explicit security headers are not evident, and no incident response or security policy information is publicly available. Privacy compliance is strong, with a clear privacy policy and cookie consent mechanism. No analytics or advertising scripts were detected, indicating a privacy-conscious approach. Overall, the website is trustworthy and professionally managed, with a strong alignment between WHOIS data and business claims. Recommendations include enhancing security headers, publishing incident response contacts, and improving accessibility to further strengthen the security posture and user trust.

70
28
2
70
77
75
100
governmentdigitalarchivecivilengineersaustriaelectronicsignature+1 more
ReactPDF.jsJavaScriptCSS
2025-10-23T00:08:38.757Z
stape.net favicon

Stape, Inc.

stape.net

82
TechnologyUnited StatesmediumLOW

Stape, Inc. is a US-based technology company specializing in server-side tracking solutions, primarily leveraging Google Tag Manager and various API gateways for platforms like Meta, TikTok, and Snapchat. Positioned as an industry leader with over 200,000 customers, Stape offers a SaaS platform that simplifies server-side tracking setup, improves data quality, and enhances marketing ROI. Their business model focuses on providing cloud-hosted server infrastructure, integrations, and power-ups to marketers and businesses seeking advanced tracking capabilities. The company maintains a strong market presence with comprehensive customer support, certifications, and a robust online community. Technically, Stape utilizes modern web technologies including React and Next.js, hosted on Google Cloud Platform with Kubernetes for secure and scalable infrastructure. The website is fast, mobile-optimized, and SEO-friendly, reflecting a mature digital presence. Security-wise, Stape enforces HTTPS, employs recommended security headers, and holds multiple certifications such as SOC 2, ISO 27001, HIPAA, and GDPR compliance. They implement privacy best practices including cookie consent and anonymization features. No critical vulnerabilities or suspicious patterns were detected, though enabling DNSSEC and publishing a security.txt file would enhance security posture. Overall, Stape demonstrates a high level of professionalism, trustworthiness, and compliance, making it a reliable service provider in the server-side tracking domain.

80
95
47
85
75
85
100
server-sidetrackinggoogletagmanagermetaconversionsapitiktokeventsapisnapchatconversionsapi+5 more
ReactNext.jsGoogle Kubernetes EngineGoogle Cloud Platform+1
2025-10-22T23:11:48.634Z