Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

148819
Websites
130
Industries
113
Countries
52
Avg Score
Page 2925 of 2977|Showing 146201-146250 of 148819
postbillpay.com.au favicon

Australia Post

postbillpay.com.au

0
payment servicesAustralialargeMEDIUM

The website demonstrates a solid foundation in network, email, and SSL/TLS security, indicating good baseline protections. However, significant gaps exist in security headers, GDPR compliance, and adherence to NIS2 cybersecurity frameworks, which together expose the business to legal, reputational, and operational risks. Missing critical headers like Content-Security-Policy and X-Frame-Options leave the site vulnerable to cross-site scripting and clickjacking attacks. The absence of privacy and cookie policies, along with no cookie consent mechanism, poses compliance risks under data protection laws such as GDPR, potentially leading to fines and loss of customer trust. Lack of documented security policies, incident response procedures, and business continuity planning increases the risk of inadequate response to cyber incidents, threatening business operations. DNSSEC is not enabled, which could allow DNS spoofing attacks. Addressing these issues will significantly strengthen security posture, reduce compliance risks, and protect the organization from both cyber threats and regulatory penalties. Immediate focus on privacy policies, security headers, and incident response frameworks is recommended. Overall, the current posture requires urgent remediation to align with industry standards and legal requirements.

25
25
25
100
95
90
100
AngularJS (ng-app, ng-bind, ng-strict-di, ng-cloak)Adobe DTM (adobedtm script)jQueryMoment.js+5

Partner Domains:

auspost.com.au
partner70
bpay.com.au
paymentanalyzing...
2025-06-13T20:21:40.291Z
rednoseday.co.nz favicon

Cure Kids

rednoseday.co.nz

0
Charity / Non-profitNew ZealandmediumMEDIUM

The website demonstrates a moderate overall security posture with no critical issues detected; however, there are multiple high and medium severity gaps that present significant risk to business operations and compliance. Key vulnerabilities include lack of foundational security headers and insufficient email authentication, which increase exposure to web-based attacks and phishing risks. Compliance with GDPR and NIS2 regulations is notably weak, with missing cookie consent mechanisms, security policies, and incident response procedures that could lead to regulatory penalties and reputational damage. While network and DNS security are relatively strong, the absence of core security policies and frameworks undermines the organization's resilience against cyber threats. Immediate remediation is critical to protect sensitive customer data, ensure regulatory compliance, and maintain business continuity. Addressing these issues will also improve customer trust and reduce the likelihood of data breaches. Prioritizing security governance and visibility should be central to the remediation roadmap. Overall, the organization must advance beyond technical fixes to establish a robust security culture aligned with regulatory expectations.

65
43
25
65
87
85
100
charityfundraisingchild healthresearchnon-profit+1 more
Google Tag ManagerJavaScriptFlickity (carousel)Lazy loading images+4

Partner Domains:

curekidsventures.co.nz
subsidiarypending
2025-06-13T20:21:27.408Z
realpagecares.com favicon

RealPage

realpagecares.com

0
housing and community servicesUSAlargeMEDIUM

The website's overall security posture reveals significant gaps, particularly in governance and compliance areas such as GDPR and NIS2 frameworks, exposing the business to regulatory and reputational risks. Critical email security misconfigurations pose a high risk of phishing and spoofing attacks, potentially undermining customer trust. Missing key security headers like Content-Security-Policy and X-Frame-Options increase vulnerability to cross-site scripting and clickjacking attacks, threatening data integrity. Although network security and DNS health are relatively strong, foundational SSL/TLS and header configurations require improvement to safeguard data in transit. The absence of documented incident response and business continuity plans limits the organization's ability to effectively respond to cyber incidents, increasing potential downtime and financial loss. Lack of a cookie policy and consent mechanisms places the company at risk of non-compliance with privacy laws, which could result in fines and legal challenges. Immediate attention to these areas will reduce attack surfaces, ensure compliance, and strengthen overall resilience. Prioritizing governance frameworks and critical technical controls will deliver the greatest business impact.

35
43
25
75
77
85
100
housingcommunityaffordable housingnonprofitrealpage
SquarespaceGoogle AnalyticsjQueryShareThis+1

Partner Domains:

realpage.com
subsidiary74
2025-06-13T20:20:56.088Z
profisee.com favicon

Profisee

profisee.com

0
Enterprise Software / Data ManagementmediumMEDIUM

The website demonstrates a moderate overall security posture with no critical issues but multiple high and medium risk findings that could expose the business to significant operational, reputational, and regulatory risks. Key weaknesses exist in security headers, GDPR compliance, and adherence to NIS2 cybersecurity framework requirements, reflecting gaps in privacy protection, incident preparedness, and information security governance. SSL/TLS configurations show vulnerabilities including weak key lengths and impending certificate expiration, which threaten secure communications. While email security and network security measures score well, foundational security controls such as Content Security Policy and proper cookie management are missing. Failure to implement GDPR-required cookie consent and policies exposes the business to potential regulatory penalties and loss of customer trust. The absence of incident response and business continuity plans significantly heightens risk from cyber incidents. Immediate remediation will reduce attack surface, improve compliance, and strengthen customer confidence. Overall, addressing these gaps is essential to align with industry standards and regulatory obligations, protecting both the business and its customers.

30
43
25
95
72
85
100
EnterpriseMaster Data ManagementMDMData GovernanceMicrosoft Fabric+2 more
WordPressYoast SEOWP RocketElementor+9

Partner Domains:

microsoft.com
partner69
2025-06-13T20:20:03.297Z
yieldstar.com favicon

RealPage

yieldstar.com

0
Real Estate SoftwareUnited StateslargeMEDIUM

The website demonstrates a moderate security posture with no critical vulnerabilities detected but several high and medium-severity issues that could expose the business to regulatory risks and cyber threats. Notably, the absence of essential security headers and weak encryption practices increase susceptibility to common web attacks such as clickjacking and data interception. GDPR compliance gaps, including missing cookie consent and incomplete privacy policies, pose significant legal and reputational risks, especially in markets regulated by data protection laws. The lack of a formal information security framework, policy documentation, and incident response procedures highlights a critical deficiency in organizational security governance. While network security and email security perform relatively well, weaknesses in SSL key strength and DNS configurations undermine overall trustworthiness. Addressing these issues promptly will not only enhance security resilience but also support regulatory compliance and customer confidence. A prioritized, strategic approach focusing on governance, encryption, and compliance will provide the most business value. Continuous monitoring and improvement are essential to maintaining and advancing the security posture over time.

65
58
35
85
80
85
100
Real EstateAsset ManagementSoftwareOptimizationAnalytics
Google Tag ManagerGoogle AnalyticsPardotCookieLaw.org (OneTrust)+4

Partner Domains:

realpage.com
subsidiary74
realpagecares.com
subsidiarypending
2025-06-13T20:19:55.435Z
freddiemac.com favicon

Freddie Mac

freddiemac.com

0
housing financeUnited StatesenterpriseMEDIUM

The website demonstrates a generally solid technical security foundation with no critical vulnerabilities detected and strong scores in email security, network security, SSL/TLS, and DNS health. However, significant gaps exist in regulatory compliance and governance, particularly regarding GDPR and NIS2 mandates, which present substantial legal and operational risks. The absence of essential policies such as cookie consent, incident response, and security frameworks exposes the organization to potential regulatory penalties and undermines customer trust. Missing key security headers and mixed content issues indicate areas where the website’s resilience against common web attacks can be improved. While foundational network and protocol configurations are strong, the low scores in compliance reflect a need for urgent attention to documentation, privacy, and incident management. Overall, the security posture is functional but incomplete, with business-critical exposure due to compliance shortcomings. Addressing these gaps will enhance legal compliance, customer confidence, and incident readiness, thereby reducing potential financial and reputational damage.

70
43
25
100
87
85
100
housing financemortgagehomeownershipfinancial servicesgovernment-sponsored enterprise+3 more
DrupalGoogle Tag ManagerVisual Website Optimizer (VWO)Cloudflare Email Protection+3

Partner Domains:

gcs-web.com
serviceanalyzing...
onetrust.com
service72
2025-06-13T20:19:09.744Z
briscoes.co.nz favicon

Briscoes

briscoes.co.nz

0
RetailNew ZealandlargeMEDIUM

The website's security posture is currently weak, exposing the business to significant cyber risks and potential regulatory non-compliance. Numerous critical and high-severity issues exist, especially in network security where multiple critical services such as Telnet, SMB, MSSQL, and databases are openly exposed, significantly increasing the risk of unauthorized access and data breaches. Key security controls including essential HTTP security headers and GDPR compliance measures like cookie policies and consent banners are missing, elevating legal and reputational risks. The absence of formal information security frameworks, incident response plans, and security policies further undermines the organization's resilience to cyber incidents. While email security and DNS health show relatively better scores, weaknesses remain in SSL/TLS configurations that could allow interception or downgrade attacks. Immediate remediation is required to protect sensitive data, maintain customer trust, and comply with regulations such as GDPR and NIS2. Failure to address these gaps could result in financial loss, legal penalties, and damage to brand reputation. Strengthening foundational security controls and network defenses should be prioritized to reduce the attack surface and improve overall risk posture.

30
43
25
85
65
85
-
homewareretailecommerceNew ZealandBriscoes+3 more
jQueryGoogle AnalyticsCloudflare

Partner Domains:

briscoes.com.au
subsidiaryanalyzing...
briscoegroup.co.nz
parent companypending

+3 more partners

2025-06-13T20:18:46.187Z