Skip to main content

High-risk security reports

Browse 46,426 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

156013
Websites
130
Industries
113
Countries
52
Avg Score
Page 29 of 929|Showing 1401-1450 of 46426
netherhall.org.uk favicon

Netherhall Educational Association

netherhall.org.uk

42
EducationUnited KingdomsmallHIGH

Netherhall Educational Association (NEA) is a UK-based registered charity and company limited by guarantee focused on providing formational and educational activities grounded in Christian principles. Their services target boys, men, and families, aiming to nurture character and inspire purpose. The organization operates multiple centres across the UK, including London, Oxford, Birmingham, Glasgow, and East Grinstead, reflecting a well-established presence in the non-profit education sector. The website is professionally designed using WordPress and the BeTheme theme, offering clear navigation and relevant content about their mission, centres, and ways to engage or donate. Technically, the website leverages modern web technologies such as WordPress 7.0.1, jQuery, and Contact Form 7 for forms. The site is mobile-optimized and uses HTTPS, though explicit security headers and advanced security configurations are not evident. Privacy and cookie policies are not explicitly presented, indicating room for improvement in compliance and transparency. No analytics or tracking scripts were detected, suggesting a privacy-conscious approach or minimal data collection. From a security perspective, the site shows no signs of WAF or blocking mechanisms and does not expose sensitive data. However, the absence of security headers and privacy policies reduces the overall security posture. The WHOIS lookup for the subdomain nea.netherhall.org.uk failed due to domain naming rules, which is expected for subdomains and does not indicate suspicious activity. The domain is consistent with the organization's main domain netherhall.org.uk. Overall, NEA's website is a credible, well-maintained platform for a small non-profit educational organization. Strategic recommendations include implementing comprehensive privacy and cookie policies, enhancing security headers, and maintaining regular updates to WordPress and plugins to ensure ongoing security and compliance.

-
60
85
47
50
2
15
educationnon-profitcharitychristianprinciplesretreats+1 more
WordPress 7.0.1jQuery 3.7.1Contact Form 7 pluginBeTheme WordPress theme+1

Partner Domains:

www.netherhall.org.uk
partner
kelston.org.uk
partner

+3 more partners

2026-07-11T07:12:56.781Z
J

John Henshall (Fruit Salesmen) Limited

johnhenshalls.co.uk

40
RetailUnited KingdomsmallHIGH

John Henshall (Fruit Salesmen) Limited operates as a wholesale importer and supplier of fresh fruits and vegetables primarily serving the Manchester and North West England region. The company claims a long history dating back to 1928 and operates from the New Smithfield Market in Manchester. Their business model focuses on wholesale distribution to retailers and businesses within a defined geographic area. The website content is basic but relevant, providing information about their products, delivery areas, and company background. Technically, the website uses legacy technology such as jQuery 1.12.3 and lacks modern security features like HTTPS enforcement and security headers. The site is mobile responsive at a basic level but lacks advanced SEO and accessibility features. There is no evidence of a CMS or advanced frameworks, indicating a simple static or lightly scripted site. From a security perspective, the absence of HTTPS and security headers, combined with the use of outdated JavaScript libraries, exposes the site to potential vulnerabilities. The WHOIS data reveals that the domain name 'www.johnhenshalls.co.uk' is invalid and cannot be registered under Nominet UK rules, which raises significant concerns about the legitimacy and trustworthiness of the domain. No privacy, cookie, or terms of service policies are present, and no contact emails or phone numbers are provided, limiting transparency and compliance. Overall, the website presents a moderate risk profile due to domain registration issues and lack of security best practices. Strategic improvements in domain registration, security hardening, and compliance documentation are recommended to enhance trust and operational security.

57
55
65
20
50
25
2
fruitsvegetablessuppliersimporterswholesalers+4 more
jQuery 1.12.3
2026-07-11T07:10:32.659Z
mysonpages.com favicon

MYSON CONSULTING LTD.

mysonpages.com

47
TechnologyUnited KingdomsmallHIGH

Myson Consulting Ltd., operating under the brand Myson Pages, is a managed IT service provider based in the Northwest of England. The company offers a comprehensive range of IT services including support, cyber security, backup and disaster recovery, Office 365 solutions, hardware supply, and hosted telephony. Their award-winning helpdesk supports over 200 clients ranging from single users to multi-site businesses and third sector organizations. The website reflects a professional and client-focused approach, emphasizing technology partnership and customer understanding. Technically, the website is built on WordPress 7.0.1 with modern JavaScript libraries such as Swiper.js, Splide.js, and GSAP for interactive elements. SEO is enhanced using the Yoast SEO plugin. The site is mobile-optimized and performs moderately well, though accessibility features are basic. Security is enforced via HTTPS, but explicit security headers are not detected, and no cookie consent mechanism is present, indicating areas for improvement in compliance and security hardening. The security posture is generally good with no visible vulnerabilities or exposed sensitive data. However, the absence of WHOIS data for the domain raises concerns about domain registration transparency and legitimacy. Privacy policies and GDPR compliance are addressed, but cookie consent and incident response information are lacking. Overall, the site is trustworthy and professional but would benefit from enhanced security headers, cookie consent implementation, and verified domain registration information. Strategically, Myson Consulting Ltd. should focus on improving transparency around domain registration, enhancing security policies on the website, and implementing cookie consent to strengthen GDPR compliance. These steps will improve trustworthiness and reduce potential compliance risks.

65
57
70
20
65
15
10
managedittechnologyitsupportcybersecuritybackup+5 more
WordPress 7.0.1Yoast SEO pluginContact Form 7Swiper.js+4
2026-07-10T07:26:27.694Z
P

Polar Heating & Hot Water Ltd

polarheating.co.uk

39
EnergyUnited KingdomsmallHIGH

Polar Heating & Hot Water Ltd is a small, local plumbing and heating service provider based in Radcliffe, Bury, UK. The company offers a wide range of services including boiler installation, repair, servicing, central heating, radiators, and gas appliance installation. With over 20 years of experience and accreditations such as Gas Safe registration and Worcester Bosch and Baxi approvals, the business positions itself as a reliable and professional service provider in the local market. The website content is focused on informing potential domestic and commercial clients about their services and contact options. From a technical perspective, the website uses basic HTML, CSS, and JavaScript without modern frameworks or CMS detected. The site lacks HTTPS and security headers, which negatively impacts its security posture. Mobile optimization and accessibility are basic, and SEO practices are minimal. There is no evidence of analytics or tracking technologies, and no privacy or cookie policies are present, indicating low privacy compliance. Security-wise, the absence of HTTPS and security headers, along with no visible incident response or vulnerability disclosure policies, suggests a low security maturity level. The website does not expose sensitive data but lacks modern security best practices. The WHOIS lookup failed due to an invalid query for the 'www' subdomain, limiting domain registration verification and reducing trustworthiness from a domain perspective. Overall, the website is functional and provides relevant business information but requires significant improvements in security, privacy compliance, and technical modernization to enhance trust and protect users. Strategic recommendations include implementing HTTPS, adding security headers, publishing privacy and cookie policies, and improving mobile and accessibility features.

47
65
55
20
15
50
2
plumbingheatingboilergassafelocalbusiness+2 more
JavaScriptCSSHTML
2026-07-10T07:22:43.679Z
swishbp.co.uk favicon

Swish Building Products

swishbp.co.uk

42
ManufacturingUnited KingdommediumHIGH

Swish Building Products is a UK-based manufacturer specializing in UPVC fascias, soffits, gutters, cladding, and window boards primarily serving social housing, newbuild, and trade construction markets. The company operates under Specialist Building Products Limited, a subsidiary of the Epwin Group, and emphasizes environmentally responsible manufacturing practices, including the use of Octyl Tin stabilizers and multiple Environmental Product Declarations (EPDs). Their website provides comprehensive product information, technical support, and installer locator services, targeting construction professionals and industry stakeholders. Technically, the website is built on the Concrete5 CMS platform, utilizing modern frontend technologies such as jQuery, Foundation CSS, and Font Awesome. The site is mobile-optimized with good navigation and SEO practices. Security measures include HTTPS enforcement and CAPTCHA on forms, though explicit security headers are not detected. Privacy compliance is well addressed with clear privacy and cookie policies, including consent mechanisms. From a security perspective, the site shows a moderate security posture with no visible vulnerabilities or exposed sensitive data. However, the WHOIS lookup for the domain failed due to a domain naming error, which raises concerns about domain registration legitimacy. Despite this, the website content and business information align with a legitimate, established company. Overall, the site scores well on content quality, technical implementation, and business credibility but is slightly penalized for WHOIS inconsistencies and missing security headers. Strategically, Swish Building Products should focus on enhancing security headers, publishing explicit security and incident response policies, and resolving domain registration issues to strengthen trust and compliance. These improvements will support their market position and digital maturity while mitigating potential risks.

47
-
70
65
53
2
20
buildingproductsupvcfasciassoffitsgutterscladding+4 more
jQueryFoundation CSS frameworkFont AwesomeGoogle Fonts (Open Sans)+1

Partner Domains:

epwin.co.uk
parent
kayflow.co.uk
partner

+2 more partners

2026-07-10T07:20:52.948Z
carlainproperty.co.uk favicon

Carlain Student Houses

carlainproperty.co.uk

41
Real EstateUnited KingdomsmallHIGH

Carlain Student Houses operates as a specialist provider of student accommodation in Cheltenham, Gloucestershire, and Oxford. The company focuses on renting quality student houses located near college campuses, targeting students seeking convenient and comfortable living arrangements. Their market position is that of a niche real estate letting agency with a strong local presence and a portfolio of properties tailored to student needs. The website reflects a professional business model centered on property lettings and management services, supported by social media engagement and certifications that enhance trust. Technically, the website employs a moderately modern infrastructure including jQuery, Google Tag Manager, Google Analytics, and Google reCAPTCHA v3 for form security. The CMS appears to be CMS Made Simple, which is a common but somewhat dated platform. The site is mobile-optimized with good navigation and SEO practices, though some technical improvements could be made, such as updating libraries and adding security headers. From a security perspective, the site benefits from HTTPS and anti-bot measures on forms but lacks visible security headers and formal privacy or cookie policies, which are important for GDPR compliance. The absence of WHOIS data and domain registration details is a notable concern, potentially indicating domain registration irregularities. However, the website content and business information are consistent and professional, mitigating some trust concerns. Overall, the site presents a low to moderate risk profile with room for improvement in privacy compliance and security best practices. Strategic recommendations include implementing comprehensive privacy and cookie policies, enhancing security headers, updating technical components, and clarifying domain registration information to strengthen legitimacy and trust.

70
20
55
37
35
2
35
studentaccommodationlettingsrealestatecheltenhamgloucester+2 more
jQuery 1.12.4Google Tag ManagerGoogle Analytics (gtag.js)Google reCAPTCHA v3+1

Partner Domains:

www.clickandlet.co.uk
partner
2026-07-10T07:20:47.631Z
adaptdesign.com favicon

Adapt Design and Advertising Limited

adaptdesign.com

45
OtherJerseysmallHIGH

Adapt Design and Advertising Limited is a small creative agency based in Jersey, Channel Islands, specializing in design, advertising, brand identity, print, and website development. Established in 1997, the company serves startups, large businesses, and marketing teams with a comprehensive suite of creative services. Their market position is strengthened by a long-standing local presence and referrals extending beyond Jersey. The website reflects a professional and consistent brand image with extensive service offerings and client testimonials, indicating a trustworthy and credible business. Technically, the website employs common industry tools such as Google Analytics, Google Tag Manager, jQuery, Owl Carousel, and Revolution Slider. The site is moderately performant with good mobile optimization and basic accessibility features. SEO practices are adequately implemented with proper meta tags and structured navigation. However, no CMS or hosting provider details are evident, and some modern security best practices like security headers are missing. From a security perspective, the website uses HTTPS (implied by external scripts loaded over HTTPS), but lacks visible security headers and explicit incident response or security policy information. The absence of WHOIS data for the domain raises concerns about domain legitimacy and registration transparency, which impacts trustworthiness. Privacy and cookie policies exist but lack active consent mechanisms, indicating partial GDPR compliance. Overall, the website presents a professional and content-rich experience with moderate technical maturity and some security gaps. The missing WHOIS data and limited security policies suggest areas for improvement to enhance trust and compliance. Strategic recommendations include implementing security headers, enforcing cookie consent, clarifying domain registration details, and enhancing incident response readiness.

75
20
37
70
2
68
15
designagencyadvertisingbrandingwebdevelopmentcreativeagency+2 more
Google AnalyticsGoogle Tag ManagerjQueryOwl Carousel+2
2026-07-10T07:20:36.987Z
essex-commercial.co.uk favicon

Essex Commercial

essex-commercial.co.uk

49
TransportationUnited KingdomsmallHIGH

Essex Commercial is a UK-based small business specializing in commercial vehicle body repairs and resprays, serving clients primarily in Essex and surrounding areas. The company offers services for lorries, trucks, vans, and horse boxes, positioning itself as a local specialist with a focus on quality and customer satisfaction. The website reflects a professional and consistent brand image with clear contact details and client trust indicators such as logos from recognized brands. Technically, the website employs a modern JavaScript stack including jQuery, Modernizr, Google reCAPTCHA, and Google Tag Manager for analytics and spam protection. The site is mobile-optimized with good SEO practices but lacks visible advanced security headers and explicit cookie consent mechanisms. Performance is moderate, and accessibility is basic. From a security perspective, the site uses HTTPS and Google reCAPTCHA but does not show evidence of comprehensive security headers or incident response policies. The WHOIS lookup failed due to domain naming rules violation, raising concerns about domain registration legitimacy. However, the website content and contact information suggest a legitimate business operation. Overall, the website scores moderately well in content quality, technical implementation, and business credibility but has room for improvement in security posture and privacy compliance. Strategic recommendations include enhancing security headers, implementing cookie consent, verifying domain registration, and publishing clear security and privacy policies.

20
60
57
85
68
30
2
commercialvehiclerepairbodyworkresprayessexvehiclerepair+1 more
jQuery 3.6.0Modernizr 3.11.2Google reCAPTCHAGoogle Tag Manager+4
2026-07-10T07:20:31.666Z
C

CAMB Machine Knives International Limited

camb-knives.co.uk

46
ManufacturingUnited KingdomsmallHIGH

CAMB Machine Knives International Limited is a UK-based manufacturer specializing in high-quality machine knives with over 25 years of experience. The company serves a global industrial audience, exporting to over 20 countries and providing additional services such as regrinding and re-sharpening of blades. Their website reflects a professional business with a clear product range and international agent network, positioning them as an established player in the manufacturing sector. Technically, the website is built on the concrete5 CMS platform and employs common web technologies including jQuery and Google Analytics. While the site is functional and moderately optimized for mobile, it uses an older CMS version and lacks some modern security headers and accessibility features. Security posture is adequate with HTTPS enabled and no visible vulnerabilities, but the absence of a published security policy and incident response contact reduces transparency. The WHOIS data for the domain is unavailable and indicates the domain name is invalid under Nominet UK rules, which raises concerns about domain legitimacy despite the professional website presence. Overall, the site is safe, business-focused, and trustworthy in content but would benefit from improved privacy compliance and security transparency.

57
70
65
20
50
30
2
manufacturingmachineknivesindustrialbladesukexport+1 more
jQueryNivo SliderGoogle AnalyticsGoogle Translate+3
2026-07-10T07:19:54.332Z
groupfinancesolutions.com favicon

Group Finance Solutions Consulting

groupfinancesolutions.com

45
GovernmentUnited KingdomsmallHIGH

Group Finance Solutions Consulting (GFSC) is a specialist ERP advisory consultancy focused on supporting UK public sector and enterprise organizations. They provide independent, client-side advisory services across the full ERP program lifecycle, including ERP selection, implementation advisory, transformation, and Oracle Cloud expertise. The company positions itself as a trusted advisor helping organizations adopt best-practice cloud solutions and successfully deliver complex ERP programs. The website content is professional, well-structured, and targets UK public sector and enterprise clients. Technically, the website is built on WordPress using the Kadence theme and Kadence blocks, with modern web technologies such as lazy loading and Google Fonts. While the site is mobile-optimized and SEO-friendly, some technical improvements are possible, including configuring analytics properly and adding security headers. The site uses HTTPS, ensuring secure communication. From a security perspective, the site shows good basic practices but lacks visible security headers and formal privacy or cookie policies. The WHOIS data is missing or unavailable, which is a significant concern regarding domain legitimacy and trust. No signs of WAF or blocking mechanisms were detected, and the site content is fully accessible and safe for general audiences. Overall, the site is a credible business presence with room for improvement in privacy compliance and security hardening. The missing WHOIS data warrants further investigation to confirm domain registration legitimacy.

62
75
70
-
25
35
17
erporaclecloudconsultingukpublicsectorenterprise+2 more
WordPress 6.9.4Kadence ThemeKadence Blocks pluginGoogle Fonts (Inter)+2
2026-07-10T07:18:59.482Z