Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

150477
Websites
130
Industries
113
Countries
52
Avg Score
Page 2700 of 3010|Showing 134951-135000 of 150477
gothru.co favicon

GoThru Media Inc.

gothru.co

58
TechnologyCanadasmallMEDIUM

GoThru Media Inc. operates gothru.co, a specialized platform providing comprehensive 360 virtual tour software solutions tailored for businesses in real estate, tourism, architecture, and related sectors. The company offers tools for creating, editing, and publishing immersive virtual tours, including integration with Google Street View and VR platforms such as Meta Quest. Their product suite includes a Virtual Tour Creator, Street View Moderator, 360 Video Creator, and VR applications, positioning them as a niche leader in the virtual tour technology market. The website content is professionally presented, with clear navigation and multilingual support, targeting business users seeking advanced 360 imaging solutions. Technically, the website is built on a modern JavaScript stack leveraging Vue.js, Axios, and jQuery, hosted on Amazon AWS infrastructure. It integrates analytics and user engagement tools such as Google Analytics, Microsoft Clarity, and Chatwoot live chat. The site demonstrates good mobile optimization and SEO practices, though accessibility features are basic. Performance is moderate, with asynchronous loading of scripts enhancing user experience. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data in its HTML content. However, it lacks important security headers like Content-Security-Policy and X-Frame-Options, and DNSSEC is not enabled on the domain. No explicit security policies or incident response contacts are published, and cookie consent mechanisms are absent despite the use of tracking scripts, indicating partial privacy compliance. WHOIS data is consistent with the business identity, showing a domain registered since 2015 under GoThru Media Inc. in Canada, supporting legitimacy. Overall, gothru.co presents a credible and professional business platform with solid technical foundations but could improve its security posture and privacy compliance to enhance trust and regulatory adherence. Strategic enhancements in security headers, cookie consent, and published security policies are recommended to mitigate risks and align with best practices.

40
53
2
70
52
65
100
virtualtour360softwaregooglestreetviewvrrealestate+2 more
JavaScriptVue.jsAxiosjQuery+4
2025-06-23T09:14:07.621Z
tvn24.pl favicon

TVN S.A. / TVN Media Sp. z o.o.

tvn24.pl

75
MediaPolandlargeMEDIUM

TVN24.pl is a leading Polish news portal operated by TVN S.A. and TVN Media Sp. z o.o., providing comprehensive national and international news coverage, live streaming, and multimedia content. The site targets Polish-speaking audiences interested in current affairs, business, health, technology, and regional news. The business model is primarily advertising-supported with premium subscription offerings under TVN24+. Technically, the website employs a modern tech stack including React-based components, OneTrust for cookie consent, Google Tag Manager, and advanced analytics platforms such as Gemius and Permutive. It uses service workers for performance and supports both desktop and mobile platforms with good accessibility and SEO practices. From a security perspective, the site enforces HTTPS, integrates GDPR-compliant consent mechanisms, and uses reputable third-party services for analytics and advertising. No critical vulnerabilities or exposed sensitive data were detected. However, enabling DNSSEC and additional security headers would enhance the security posture. Overall, TVN24.pl demonstrates a mature digital presence with strong business credibility, good privacy compliance, and a robust technical foundation. Strategic improvements in security headers and incident response visibility are recommended to maintain and enhance trust.

65
85
17
85
72
85
100
newsmediapolandtvn24journalism+5 more
React (implied by island components)OneTrust (cookie consent)Google Tag ManagerGemius (analytics)+7

Partner Domains:

kup.tvn24.pl
partner
kontakt24.tvn24.pl
partner

+3 more partners

2025-06-23T09:13:00.568Z
lursoft.lv favicon

Lursoft IT

lursoft.lv

59
Real EstateLatviamediumMEDIUM

Lursoft IT is a well-established Latvian company founded in 1993, specializing in providing comprehensive business and real estate data services across the Baltic region. Their offerings include extensive company registries, financial reports, insolvency data, commercial pledge registers, real estate databases, sanction lists, and monitoring services. The company targets businesses, government entities, and professionals requiring reliable and up-to-date data for decision-making and compliance. Lursoft IT operates a subscription and pay-per-use business model, positioning itself as a leading data provider in its market niche. Technically, the website employs a modern and stable technology stack including jQuery and Bootstrap, ensuring good mobile responsiveness and user experience. The site features a cookie consent mechanism compliant with GDPR, multiple language support, and integrates advertising via OpenX. Performance is moderate with room for optimization, and SEO practices are adequately implemented. Accessibility is basic but functional. From a security perspective, the site enforces HTTPS and uses security-related cookies such as CSRF tokens and session identifiers. However, it lacks explicit security headers and a published security policy or incident response contacts. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with clear policies and consent mechanisms. Overall, Lursoft IT demonstrates a mature digital presence with solid business credibility and privacy practices. Recommendations include enhancing security headers, publishing a security policy, improving accessibility, and maintaining regular audits of third-party scripts to further strengthen security and compliance posture.

55
25
17
65
59
70
100
businessdatarealestatebalticregioncompanyregistryfinancialreports+3 more
jQuery 3.5.1Bootstrap CSS and JSCustom JavaScriptOpenX ad server

Partner Domains:

news.lv
partner
zo.lv
partner

+2 more partners

2025-06-23T09:12:50.840Z
laliga.es favicon

LALIGA

laliga.es

70
MediaSpainlargeMEDIUM

LALIGA is a prominent Spanish professional football league organization that manages multiple football competitions including LALIGA EA SPORTS, LALIGA HYPERMOTION, and Liga F. The website serves as a comprehensive platform providing schedules, results, standings, news, statistics, and multimedia content to a global audience of football fans and sports professionals. It maintains a strong market position as a leading football league with extensive partnerships and fan engagement initiatives. Technically, the website is built on modern frameworks such as Next.js and React, utilizing advanced features like lazy loading, video embedding, and responsive design to ensure fast performance and excellent user experience across devices. The presence of Google Tag Manager and other tracking tools indicates a mature digital marketing and analytics infrastructure. From a security perspective, the site employs HTTPS with strong SSL configuration and includes essential security headers, content security policies, and cookie consent mechanisms, reflecting a good security posture. However, the absence of visible incident response contacts and security policy pages suggests areas for improvement. Overall, the website is professional, content-rich, and well-structured, supporting LALIGA's business objectives effectively. The lack of WHOIS data is a notable anomaly but does not detract significantly from the site's credibility given its extensive external references and branding consistency.

65
68
2
75
90
80
100
sportsfootballsoccerlaligaspanishfootball+4 more
ReactNext.jsGoogle Tag ManagerYouTube embeds+2
2025-06-23T09:11:55.120Z
realsociedad.eus favicon

Real Sociedad de Fútbol S.A.D.

realsociedad.eus

73
OtherSpainlargeMEDIUM

Real Sociedad de Fútbol S.A.D. is a professional football club based in Spain, operating an official website that serves as a hub for club news, match information, ticket sales, and fan engagement. The website targets football fans and supporters of the club, providing content primarily in Spanish with multiple language alternatives. The business model centers on sports entertainment and merchandising, positioning the club as a well-established entity in the Spanish football market. The website branding is consistent and professional, reinforcing the club's identity and trustworthiness. Technically, the website employs modern web technologies including Google Tag Manager, Cookiebot for cookie consent management, and Google DoubleClick for advertising. The site is mobile-optimized and includes SEO best practices such as Open Graph and Twitter Card metadata. Performance is moderate, with good mobile responsiveness and basic accessibility features. Hosting and CMS details are not explicitly identified but the infrastructure supports a professional online presence. From a security perspective, the website enforces HTTPS with strong SSL configuration and includes security headers inferred from scripts. Cookie consent mechanisms comply with GDPR, and no exposed sensitive data or vulnerable libraries were detected in the analyzed HTML. However, the site lacks explicit security policy pages, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for enhanced security posture. Overall, the website is legitimate and professionally maintained, with privacy-protected WHOIS data typical for such organizations. The absence of public WHOIS details does not detract from the site's credibility given the consistent branding and security practices. Strategic recommendations include publishing clear security and incident response policies, improving accessibility, and providing explicit contact information for security and abuse reporting to further strengthen trust and compliance.

75
88
17
85
65
75
100
sportsfootballrealsociedadcookieconsentgdpr+3 more
Google Tag ManagerCookiebotDoubleClick GPTFacebook Pixel
2025-06-23T09:11:24.932Z
R

RCD Mallorca

rcdmallorca.es

66
HospitalitySpainmediumMEDIUM

RCD Mallorca's official website serves as the primary digital platform for the professional football club based in Mallorca, Spain. It offers comprehensive information about the club, including team rosters, schedules, ticket sales, merchandise, and fan engagement opportunities. The site targets football fans and stakeholders interested in the club's activities and events. The business model revolves around sports entertainment, fan engagement, and e-commerce through ticketing and merchandise sales. Technically, the website is built using modern web technologies such as React and Next.js, ensuring a responsive and dynamic user experience. Integration with multiple analytics and marketing platforms like Google Tag Manager, TikTok Pixel, and Facebook Pixel indicates a mature digital marketing strategy. The site includes a cookie consent mechanism compliant with EU regulations, although explicit privacy and terms of service pages are not clearly identified. From a security perspective, the site enforces HTTPS and uses cookie consent tools, but lacks visible security headers and explicit security policies or incident response contacts. No critical vulnerabilities or exposed sensitive data were detected. WHOIS data is unavailable due to registry restrictions, which is common for .es domains and does not detract from the site's legitimacy. Overall, the website presents a professional and trustworthy front for RCD Mallorca, with room for improvement in security headers, privacy disclosures, and contact transparency to enhance compliance and user trust.

60
40
17
70
90
80
100
sportsfootballclubmallorcaofficial+4 more
ReactNext.jsGoogle Tag ManagerOneTrust Cookie Consent+3

Partner Domains:

estadimallorcasonmoix.es
partner
tienda.rcdmallorca.es
subsidiary

+1 more partners

2025-06-23T09:11:09.795Z
rccelta.es favicon

RC Celta

rccelta.es

66
MediaSpainmediumMEDIUM

RC Celta's official website serves as the primary digital platform for the professional football club, providing fans with news, ticket purchasing options, and club-related services. The site targets supporters and stakeholders interested in the club's activities and offerings. The business model centers on fan engagement and service provision through digital channels, positioning RC Celta as a recognized entity in the sports media sector within Spain. Technically, the website is built on WordPress CMS, leveraging popular plugins such as Yoast SEO and WPBakery Page Builder to enhance content management and SEO performance. Integration with Google Tag Manager, Google Analytics, and Cookiebot demonstrates a mature approach to analytics and privacy compliance. The site is mobile-optimized and exhibits good design and navigation clarity, supporting a positive user experience. From a security perspective, the website enforces HTTPS and includes several security headers, alongside the use of Google reCAPTCHA to mitigate bot activity. Cookie consent mechanisms comply with GDPR requirements, reflecting a commitment to privacy. However, the absence of explicit terms of service, security policy, and incident response contact information represents gaps in the security posture that could be addressed to enhance trust and compliance. Overall, the website is professional, trustworthy, and well-structured, with minor areas for improvement in security transparency and contact availability. The domain registration aligns with the club's identity, reinforcing legitimacy. Strategic recommendations include publishing comprehensive legal and security policies, enhancing accessibility, and establishing clear incident response channels.

50
83
17
55
65
80
100
sportsfootballclubofficialticketsales+4 more
WordPress 5.4Yoast SEO pluginWPBakery Page BuilderGoogle Tag Manager+2
2025-06-23T09:10:59.749Z
athletic-club.eus favicon

Athletic Club

athletic-club.eus

68
OtherSpainlargeMEDIUM

Athletic Club operates a comprehensive official website serving as the primary digital presence for the historic football club based in Bilbao, Spain. The site offers extensive content including latest news, team rosters, ticket sales for matches and tours, official merchandise stores, and membership information. It targets football fans, club members, and tourists interested in the club's activities and heritage. The business model revolves around fan engagement, ticketing, merchandising, and exclusive experiences, positioning Athletic Club as a prominent sports entity with a large and loyal audience. Technically, the website leverages modern web technologies such as the Astro framework, Google Tag Manager, Microsoft Clarity, and Cookiebot for analytics and privacy compliance. The site is well-optimized for mobile devices, features good accessibility practices, and maintains strong SEO fundamentals. Performance is fast, and the site structure supports multilingual content in Spanish, Basque, and English, enhancing its reach. From a security perspective, the site enforces HTTPS with excellent SSL configuration and implements multiple security headers to protect users. Privacy compliance is robust with clear cookie consent mechanisms and a comprehensive privacy policy. However, there is a lack of publicly available security policies or incident response contacts, which could be improved to enhance transparency and trust. Overall, Athletic Club's website demonstrates a mature digital presence with strong business credibility and security posture. The domain is privacy protected, which is typical and justified for this type of organization. The site is trustworthy, professional, and well-maintained, supporting the club's brand and operational goals effectively.

35
65
17
65
100
75
100
sportsfootballclubticketsmerchandise+3 more
Astro frameworkGoogle Tag ManagerMicrosoft ClarityCookiebot+1

Partner Domains:

shop.athletic-club.eus
partner
tienda.athletic-club.eus
partner

+3 more partners

2025-06-23T09:10:14.525Z
morningstar.se favicon

Morningstar, Inc.

morningstar.se

72
FinanceSwedenlargeMEDIUM

Morningstar Sverige is a localized Swedish website of Morningstar, Inc., a global financial services company specializing in investment research, fund data, and portfolio management tools. The website offers comprehensive financial content including fund prices, market news, and investment analysis targeted at both private investors and financial professionals in Sweden. The business model is primarily based on subscription services and advertising revenue, supported by a strong brand presence and consistent content quality. The site is well-established with a domain age dating back to 2000, reflecting a mature market position. Technically, the website employs a modern technology stack including jQuery, Bootstrap, New Relic monitoring, and OneTrust for cookie consent management. It integrates multiple third-party analytics and marketing tools such as Google Analytics, Google Tag Manager, and Qualtrics feedback modules. The site is hosted under a reputable registrar with DNS services from UltraDNS and NS1, though DNSSEC is not enabled. Performance is moderate with good mobile optimization and basic accessibility features. From a security perspective, the site enforces HTTPS and implements several security headers, though some headers like Content-Security-Policy could be more explicitly defined. The cookie consent mechanism is robust and GDPR compliant, providing users with granular control over cookie categories. No critical vulnerabilities or exposed sensitive data were detected. The domain registration data aligns well with the business claims, indicating a legitimate and trustworthy online presence. Overall, Morningstar Sverige demonstrates a strong security posture, good privacy compliance, and a professional digital presence. Recommendations include enabling DNSSEC, enhancing security headers, and maintaining regular audits of third-party scripts to mitigate potential risks. The site provides a reliable and user-friendly platform for investment research and financial data in the Swedish market.

85
83
2
85
72
70
100
financeinvestmentfundsstocksportfolio+3 more
jQuery 3.5.1Bootstrap 3.4.1New Relic monitoringOneTrust cookie consent+5
2025-06-23T09:09:54.437Z
eventsingozo.com favicon

Events in Gozo

eventsingozo.com

73
GovernmentMaltasmallMEDIUM

Events in Gozo is a government-supported digital platform dedicated to promoting and listing events on Gozo Island, Malta. The website offers comprehensive event information ranging from festivals, music concerts, food fairs, arts, sports, to family and kids activities. Supported by the Ministry for Gozo and Planning, the platform serves residents and visitors seeking up-to-date event details and features a mobile app to enhance accessibility and user engagement. The site is professionally designed with clear navigation, mobile optimization, and SEO best practices, reflecting a mature digital presence for a relatively new domain established in 2023. Technically, the website is built on WordPress using modern plugins such as The Events Calendar, Yoast SEO, and Ajax Search Pro, with a responsive design and moderate performance. Hosting appears to leverage Azure DNS services, indicating a reliable infrastructure. Security posture is good with HTTPS enforced and domain status protections in place; however, DNSSEC is not enabled and security headers are not fully implemented, suggesting room for improvement in hardening the site against advanced threats. Privacy compliance is strong, with clear privacy and cookie policies, cookie consent mechanisms, and GDPR adherence. Contact information is transparent and includes official government email and phone contacts. No incident response or vulnerability disclosure policies are found, which is typical for government event platforms but could be enhanced for security maturity. Overall, Events in Gozo presents a trustworthy, well-maintained, and user-friendly platform with solid government backing. Strategic recommendations include enabling DNSSEC, implementing comprehensive security headers, and establishing formal vulnerability disclosure and incident response policies to further strengthen security and trust.

80
80
17
70
77
75
100
eventsgozomaltagovernmentfestival+5 more
WordPressPHPJavaScriptjQuery+4
2025-06-23T09:09:44.364Z
yaycommerce.com favicon

YAYCOMMERCE COMPANY LIMITED

yaycommerce.com

67
E-commerceN/asmallMEDIUM

YayCommerce is a specialized provider of WooCommerce plugins, serving over 100,000 WordPress websites. The company offers a suite of products designed to enhance e-commerce functionality, including email customization, multi-currency switching, SMTP integration, dynamic pricing, variation swatches, and extra product options. Their market position is that of a trusted, niche player in the WooCommerce ecosystem, targeting online store owners and WordPress users seeking enhanced e-commerce capabilities. The business model is primarily product sales supplemented by an affiliate program to expand reach. Technically, the website is built on a modern WordPress stack utilizing popular plugins such as Elementor for design, Easy Digital Downloads for commerce, and WP Rocket for performance optimization. The site is hosted with domain registration via GoDaddy and DNS managed by Cloudflare, indicating a reliable infrastructure. Performance and mobile optimization are good, with SEO best practices implemented through Yoast SEO. From a security perspective, the site employs HTTPS with good SSL configuration and some security best practices. However, it lacks explicit security headers like Content-Security-Policy and does not publish a dedicated security or incident response policy. No vulnerabilities or exposed sensitive data were detected in the analysis. Overall, YayCommerce presents a professional and trustworthy online presence with solid technical foundations. The main areas for improvement include enhancing privacy compliance by publishing a dedicated privacy and cookie policy with consent mechanisms, and strengthening security posture by adding security headers and incident response information.

45
50
17
85
75
85
100
woocommercewordpresse-commercepluginssaas+1 more
WordPressWooCommerceElementorEasy Digital Downloads+3
2025-06-23T09:09:39.334Z
fondo.se favicon

Fondo Solutions AB

fondo.se

55
FinanceSwedensmallMEDIUM

Fondo Solutions AB is a Swedish fintech company specializing in providing a cloud-native investment platform and API that enables financial and non-financial partners to integrate mutual fund investments seamlessly into their products and user journeys. The company positions itself as a market leader in Sweden with strategic partnerships such as Sharpfin, offering a modern, scalable, and compliant infrastructure for investment services. Their business model focuses on API-first solutions, digital onboarding, automated order execution, and regulatory compliance, targeting wealth managers, banks, fund companies, and other financial service providers. Technically, Fondo employs modern web technologies including htmx.org, Alpine.js, and Flowbite, hosted on Google Cloud infrastructure as indicated by DNS records. The website is well-optimized for performance, mobile responsiveness, and accessibility, reflecting a mature digital presence. SEO practices are solid with comprehensive meta tags and Open Graph data. From a security perspective, the site uses HTTPS and modern libraries without visible vulnerabilities. However, it lacks DNSSEC, security headers, and explicit security or incident response policies, which are areas for improvement. Privacy compliance is good with a clear privacy policy and terms of service, but the absence of a cookie consent mechanism is a notable gap. Overall, Fondo demonstrates a strong business credibility and technical maturity with a high trustworthiness level. Strategic recommendations include enhancing DNS security, implementing security headers, adding cookie consent, and publishing vulnerability disclosure information to further strengthen security posture and compliance.

15
28
2
75
52
80
100
investmentapimutualfundsfinancewealthmanagement+2 more
htmx.orgAlpine.jsFlowbiteLenis (smooth scrolling)+1

Partner Domains:

getdreams.com
partner
sharpfin.com
partner

+3 more partners

2025-06-23T09:09:34.323Z
alpcot.se favicon

alpcot.se

alpcot.se

54
OtherN/asmallMEDIUM

The website www.alpcot.se currently presents minimal accessible content, displaying an error message indicating the page could not be loaded. The site is built using modern technologies such as Blazor server-side framework, Radzen components, and Bootstrap CSS for styling. PostHog analytics is integrated for user behavior tracking. However, the lack of visible business information, contact details, and policy documents significantly limits the ability to assess the company's market position or business model. The domain queried (www.alpcot.se) is a subdomain, with no WHOIS data found, which reduces trustworthiness and raises questions about domain registration consistency. From a technical perspective, the site implements a Content-Security-Policy header and enforces HTTPS, which are positive security indicators. Nevertheless, the absence of privacy and cookie policies, incident response information, and vulnerability disclosure mechanisms highlights compliance gaps. The user experience is poor due to the error page and lack of navigable content, and SEO and accessibility optimizations are minimal. Security posture is moderate with basic best practices in place but lacks comprehensive policies and contact channels for security incidents. Overall, the website's risk profile is elevated due to minimal content, lack of transparency, and incomplete compliance documentation. Strategic improvements are needed to enhance trust, compliance, and user experience.

30
10
17
70
82
75
100
blazorradzenposthogbootstrapanalytics+2 more
BlazorRadzen.BlazorBootstrapPostHog
2025-06-23T09:09:29.293Z