Skip to main content

Low-risk security reports

Browse 2,868 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155884
Websites
130
Industries
113
Countries
52
Avg Score
Page 3 of 58|Showing 101-150 of 2868
cssf.lu favicon

Commission de Surveillance du Secteur Financier

cssf.lu

76
FinanceLuxembourgmediumLOW

The Commission de Surveillance du Secteur Financier (CSSF) is a public institution responsible for supervising professionals and products within the Luxembourg financial sector. It serves both professionals and consumers by providing regulatory frameworks, publications, and guidance. The CSSF holds a key market position as Luxembourg's financial regulatory authority, offering services such as supervision of financial entities and dissemination of financial data. The website targets financial sector stakeholders and consumers seeking authoritative information and regulatory updates. Technically, the website is built on WordPress, utilizing modern web technologies including jQuery and Font Awesome, and integrates Matomo for analytics. The site demonstrates good digital maturity with responsive design, accessibility features, and a cookie consent mechanism compliant with GDPR. Performance is moderate with room for optimization. From a security perspective, the site enforces HTTPS and employs cookie-based security measures. However, explicit HTTP security headers are not detected, and no public security or incident response policies are found. No vulnerabilities or exposed sensitive data are evident. The absence of WHOIS data limits domain trust verification, but the official nature and content quality support legitimacy. Overall, the CSSF website is a professional, secure, and compliant platform serving as a trusted source for financial regulation in Luxembourg. Strategic recommendations include enhancing HTTP security headers, publishing security policies, and improving WHOIS transparency to strengthen trust and security posture.

80
83
17
85
77
85
100
financeregulationluxembourgfinancialsupervisioncssf+1 more
WordPressjQueryFont Awesome 6Matomo Analytics
2025-11-01T04:59:38.453Z
nice.org.uk favicon

National Institute for Health and Care Excellence

nice.org.uk

78
HealthcareUnited KingdomlargeLOW

The National Institute for Health and Care Excellence (NICE) is a UK government agency providing authoritative guidance and standards for the NHS and wider health and care system. The website serves healthcare practitioners, commissioners, policymakers, patients, and industry stakeholders by offering comprehensive health guidance, standards, formularies, and knowledge resources. The site is well-positioned as a trusted source in the healthcare sector with a large audience and a strong market presence. Technically, the website is built on modern frameworks such as Next.js and uses a headless CMS (Storyblok), integrating various analytics and marketing tools like Google Analytics, Hotjar, and Google Optimize. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS, uses cookie consent mechanisms, and shows good security practices, though explicit security policies and vulnerability disclosure mechanisms are not publicly documented. No critical vulnerabilities or suspicious indicators were found. Overall, the website demonstrates a high level of professionalism, trustworthiness, and compliance with privacy regulations, making it a reliable resource for its target audience.

95
88
17
93
77
70
100
healthcaregovernmentnhshealthguidancemedicalstandards+1 more
React (Next.js)YouTube iframe APIGoogle Tag ManagerGoogle Analytics+4
2025-10-31T21:04:48.604Z
globusmedical.com favicon

Globus Medical

globusmedical.com

78
HealthcareUnited StateslargeLOW

Globus Medical is a leading healthcare company specializing in the development, manufacturing, and distribution of musculoskeletal device solutions. The company targets healthcare professionals, surgeons, and hospitals with a broad portfolio of implants and surgical products. Their market position is strong as an innovator in musculoskeletal solutions, supported by certifications such as ISO 13485 and a professional digital presence. Technically, the website is built on WordPress with modern plugins and SEO tools, delivering a good user experience with mobile optimization and accessibility features. The site employs standard security headers and enforces HTTPS, reflecting a mature security posture. However, the absence of a public security policy and incident response contact information suggests room for improvement in transparency and readiness. Overall, the security posture is solid with no detected vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. The WHOIS data is missing, which slightly reduces trustworthiness but does not outweigh the professional presentation and business legitimacy evident on the site. Strategically, Globus Medical should enhance its security transparency by publishing incident response and vulnerability disclosure information. This will strengthen trust and align with best practices for healthcare organizations handling sensitive data.

75
88
47
75
72
85
100
healthcaremedicaldevicesmusculoskeletalsurgicalimplantswordpress+1 more
WordPressjQuerySmart Slider 3Yoast SEO+2
2025-10-31T20:55:52.887Z
I

Industrie- und Handelskammer Lüneburg-Wolfsburg

ihk-lueneburg.de

77
GovernmentGermanylargeLOW

The Industrie- und Handelskammer Lüneburg-Wolfsburg (IHK Lüneburg-Wolfsburg) is a regional chamber of commerce serving approximately 70,000 businesses across several districts in Germany. The website provides comprehensive information and services including business consulting, education, networking, and support for startups. It targets businesses and entrepreneurs in the Lüneburg-Wolfsburg region, positioning itself as a key regional economic facilitator. Technically, the website is built on the CoreMedia CMS platform and integrates modern web technologies including JavaScript, CSS, and HTML5. It employs third-party services such as eTracker for analytics, CCM19 for cookie consent management, and Userlike for chat support. The site is mobile-optimized, accessible, and SEO-friendly, with a moderate performance profile. From a security perspective, the site enforces HTTPS, uses CSRF tokens in forms, and provides a granular cookie consent mechanism. However, it lacks publicly visible security policies, incident response contacts, and security headers which could enhance its security posture. No vulnerabilities or exposed sensitive data were detected. Overall, the website is professional, trustworthy, and compliant with GDPR requirements. It effectively serves its audience with relevant content and clear contact information. Strategic improvements in security transparency and incident response readiness are recommended to further strengthen trust and resilience.

90
95
17
85
77
70
100
ihkchamberofcommercebusinessconsultingeducationnetworking+2 more
JavaScriptCSSHTML5Userlike chat widget+2
2025-10-31T19:25:58.562Z
macmon.eu favicon

Belden

macmon.eu

76
ManufacturingUnited StatesenterpriseLOW

Belden is a global enterprise specializing in the design, manufacture, and marketing of networking, connectivity, and cable products primarily serving industrial automation, smart buildings, and broadcast markets. The company positions itself as a leader in these sectors, offering comprehensive solutions and customer innovation centers to support client needs. The website reflects a mature digital presence with professional design, clear navigation, and multi-language support, targeting industrial and commercial customers, system integrators, and distributors. Technically, the website employs modern web technologies including jQuery, Bootstrap 4, and integrates advanced search capabilities via Coveo. It uses Google Tag Manager and OneTrust for analytics and cookie consent management, indicating a commitment to privacy compliance and user experience. The site is mobile optimized and accessible, with good SEO practices. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms. However, explicit security headers like Content-Security-Policy and X-Frame-Options are not evident in the HTML source. There is no visible security policy or incident response contact information, which could be improved. The absence of WHOIS data limits full trust assessment, but the professional site and privacy policies suggest legitimacy. Overall, Belden's website demonstrates a strong business and technical foundation with good privacy compliance. Strategic improvements in security transparency and WHOIS data availability would enhance trust and security posture.

80
85
88
100
55
60
57
networkingconnectivitycableindustrialautomationsmartbuildings+2 more
jQuery 3.7.1jQuery UI 1.14.0Bootstrap 4 gridCoveo search+2

Partner Domains:

edesk.belden.com
partner
my.belden.com
partner

+2 more partners

2025-10-31T18:43:28.666Z
showpad.com favicon

Showpad

showpad.com

86
TechnologyN/aenterpriseLOW

Showpad is a well-established enterprise SaaS company founded in 2005, specializing in sales enablement solutions that combine content management, sales readiness, buyer engagement, and AI-powered intelligence. The recent merger with Bigtincan positions Showpad as a leader in the revenue effectiveness platform market, serving over 2,000 sales organizations globally. Their platform integrates with over 75 third-party services, enhancing workflow flexibility and customer engagement. Technically, the website is built on WordPress and leverages modern marketing and analytics technologies such as Google Tag Manager, Marketo, Microsoft Clarity, and Cloudflare Bot Management. The site is well optimized for performance, mobile responsiveness, accessibility, and SEO, reflecting a mature digital infrastructure. From a security perspective, Showpad employs HTTPS with strong SSL configuration, security headers, bot management, and cookie consent mechanisms. While DNSSEC is not enabled, the overall security posture is strong with no visible vulnerabilities or exposed sensitive data. The company maintains a responsible disclosure page, indicating incident response readiness. Overall, Showpad demonstrates a high level of business credibility, technical sophistication, and privacy compliance. The website content is professional, trustworthy, and safe for general audiences, with strong trust signals including customer testimonials and industry awards. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, and enhancing visibility of incident response contacts to further strengthen security and compliance.

85
95
65
80
82
90
100
salesenablementaicontentmanagementtrainingcoaching+4 more
WordPressGoogle Tag ManagerMarketoGoogle Analytics+3

Partner Domains:

ecosystem.showpad.com
partner
www.showpad.biz
partner

+1 more partners

2025-10-31T17:00:22.691Z
tomshardware.com favicon

Tom's Hardware

tomshardware.com

78
TechnologyN/alargeLOW

Tom's Hardware is a well-established technology media brand focused on providing in-depth reviews, news, and guides related to PC hardware and technology enthusiasts. The website targets hardcore PC enthusiasts, gamers, and technology consumers seeking expert advice on hardware purchases and PC builds. The business model primarily revolves around advertising and content publishing, supported by a strong digital presence and social media engagement. Technically, the website employs modern web technologies including JavaScript frameworks, Google Tag Manager, and a content delivery network (Future CDN). The site is mobile-optimized and demonstrates good SEO and accessibility practices. Performance is moderate with room for optimization. The CMS appears proprietary or custom, inferred from CDN URLs. From a security perspective, the site enforces HTTPS and uses common third-party scripts responsibly. However, explicit security headers like Content-Security-Policy and X-Frame-Options are not clearly present, which could be improved. No direct incident response or security policy information is publicly available, which is a gap for transparency. WHOIS data is not publicly available, likely due to privacy protection, which slightly reduces trust but is common for media companies. Overall, Tom's Hardware presents a professional, trustworthy, and content-rich platform with a solid technical foundation. Strategic improvements in security header implementation and public security policy disclosure would enhance its security posture and trustworthiness.

65
85
47
85
72
85
100
technologypchardwarereviewsnewsgaming+1 more
JavaScriptGoogle Tag ManagerMarfeel SDKVanilla JS framework+2
2025-10-31T05:48:29.349Z
burst-statistics.com favicon

Burst Statistics B.V.

burst-statistics.com

76
TechnologyNetherlandssmallLOW

Burst Statistics B.V. is a small technology company based in the Netherlands specializing in privacy-friendly analytics solutions for WordPress websites. Their flagship products, Burst Statistics and Burst Pro, provide website owners with real-time, GDPR-compliant insights without relying on third-party tracking or cookies. Positioned as a privacy-first alternative to Google Analytics, Burst targets bloggers, businesses, and agencies seeking transparent and local data ownership. The company is part of the reputable Team Updraft Family, enhancing its market credibility. Technically, the website is built on WordPress using modern plugins such as Gravity Forms and Easy Digital Downloads, with SEO optimized by Yoast SEO Premium. Hosting is managed via TransIP, and the site employs HTTPS with good SSL configuration. The site demonstrates good mobile optimization, accessibility, and performance, though DNSSEC is not enabled. The technical infrastructure reflects a mature digital presence suitable for a SaaS business model. From a security perspective, the site enforces HTTPS and avoids third-party tracking, aligning with its privacy claims. However, it lacks some security headers and does not publicly disclose a security policy or incident response plan. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong in practice but lacks explicit policy documentation and cookie consent mechanisms. Overall, Burst Statistics presents a trustworthy and professional online presence with a strong focus on privacy and user data protection. Strategic improvements in policy transparency and security headers would further enhance trust and compliance.

90
80
28
85
57
80
100
privacyanalyticswordpressgdprcompliance+2 more
WordPressGravity FormsEasy Digital DownloadsYoast SEO Premium+4

Partner Domains:

updraftplus.com
partner
wpoptimize.com
partner

+2 more partners

2025-10-31T05:46:48.923Z
basf.eu favicon

BASF SE

basf.eu

79
ManufacturingGermanyenterpriseLOW

BASF SE is a leading global chemical company headquartered in Germany, with a long history dating back to 1865. The company focuses on profitable growth and creating value for society by providing innovative chemical solutions that support sustainability. Their website reflects a mature digital presence with comprehensive content aimed at industrial clients, partners, and stakeholders worldwide. The site is well-structured, professionally designed, and optimized for mobile devices, demonstrating a high level of digital maturity. Technically, the website uses modern frameworks such as Angular and a CMS platform (Magnolia), with good performance and accessibility standards. Security-wise, BASF employs HTTPS, robust security headers, and follows recognized standards like ISO 27001, indicating a strong security posture. Privacy and cookie policies are clearly presented with consent mechanisms, supporting GDPR compliance. Despite the absence of WHOIS registration details, the overall trustworthiness and legitimacy of the website are high, supported by consistent branding, certifications, and contact information. Strategic recommendations include maintaining regular security assessments, enhancing incident response automation, and continuing to improve privacy transparency to sustain trust and compliance.

60
73
45
98
82
85
100
chemicalsmanufacturingsustainabilitycorporatebasf
JavaScriptCSSHTML5

Partner Domains:

basf-corporation.com
subsidiary
blackberry.basf.com
partner
2025-10-31T05:43:07.966Z
sonderborgkommune.dk favicon

Sønderborg Kommune

sonderborgkommune.dk

76
GovernmentDenmarklargeLOW

Sønderborg Kommune operates as the official municipal government website for the Sønderborg region in Denmark, providing a comprehensive range of public services to its citizens. The site targets residents and visitors seeking information on personal affairs, health and care, construction, education, traffic, employment, and environmental issues. It holds a strong market position as a local government authority with a well-established digital presence since 1997. Technically, the website leverages Drupal CMS, integrates privacy-focused analytics via Matomo, and employs Cookiebot for GDPR-compliant cookie consent management. The site demonstrates good mobile optimization, accessibility, and SEO practices, reflecting a mature digital infrastructure suitable for public sector needs. From a security perspective, the site enforces HTTPS and uses cookie consent mechanisms to comply with privacy regulations. However, it lacks explicit security headers and a public security policy or incident response contact, which are areas for improvement. No critical vulnerabilities or WAF blocking were detected, indicating a stable security posture. Overall, Sønderborg Kommune's website is a trustworthy, professional, and privacy-conscious platform that effectively serves its public audience. Strategic enhancements in security policy transparency and DNS security could further strengthen its risk profile and compliance stature.

70
87
95
100
17
80
77
governmentmunicipalitypublicservicesdanishcookieconsent+3 more
Matomo AnalyticsCookiebot Consent ManagementFontAwesomeAOS (Animate On Scroll)
2025-10-31T05:39:22.169Z
bdosecurity.de favicon

BDO Cyber Security GmbH

bdosecurity.de

79
TechnologyGermanymediumLOW

BDO Cyber Security GmbH is a specialized cybersecurity consulting and training company operating under the reputable BDO brand in Germany. The company offers services including Cyber Incident Response, Offensive Security, Cyberstrategy consulting, and cybersecurity education through its Cyber Academy. The website targets businesses and organizations seeking professional cybersecurity solutions and training. The market position is that of a focused cybersecurity service provider leveraging the BDO brand's trust and recognition. Technically, the website is built on Kentico CMS, uses modern JavaScript libraries like jQuery, and integrates Google Tag Manager, Cookiebot for consent management, and Microsoft Application Insights for telemetry. The hosting infrastructure appears to be managed by Deutsche Telekom AG, indicating a reliable hosting environment. Security-wise, the site enforces HTTPS with strong security headers and implements a comprehensive cookie consent mechanism aligned with GDPR requirements. No critical vulnerabilities or exposed sensitive data were detected. However, the site lacks a public security policy, incident response contact details, and a vulnerability disclosure policy, which are recommended for enhanced transparency and trust. Overall, the website is professional, secure, and compliant with privacy regulations, making it a trustworthy platform for cybersecurity services.

70
88
72
70
77
70
100
cybersecurityconsultingtrainingincidentresponseoffensivesecurity+3 more
jQuery 3.5.1Google Tag ManagerCookiebotMicrosoft Application Insights+1

Partner Domains:

www.bdo.de
partner
2025-10-31T04:22:51.352Z
vestas.com favicon

Vestas

vestas.com

76
EnergyDenmarkenterpriseLOW

Vestas is a globally recognized leader in the renewable energy sector, specializing in the design, manufacture, installation, and servicing of wind turbines worldwide. The company targets businesses and governments seeking sustainable energy solutions, positioning itself as a key player in the energy industry with a comprehensive portfolio of wind energy services. The website reflects this stature with professional design, clear branding, and detailed service descriptions, catering to an enterprise-level audience. Technically, the website leverages a modern technology stack including Adobe Experience Manager as its CMS, Adobe Experience Cloud for marketing, Google Tag Manager, and multiple analytics platforms such as Google Analytics, Piwik PRO, and Hotjar. Hosting and security are supported by Cloudflare, ensuring fast performance and robust SSL configurations. The site is mobile-optimized and accessible, with a strong focus on privacy compliance demonstrated by a comprehensive cookie consent mechanism and GDPR-aligned policies. From a security perspective, the site enforces HTTPS and employs reputable third-party services for analytics and performance monitoring. However, explicit security headers are not clearly visible in the HTML content, and no public security or incident response policies are found, which could be areas for improvement. The absence of WHOIS data is noted but likely due to privacy protection, common for large enterprises. Overall, the website presents a low-risk profile with strong business credibility and technical maturity. Strategic recommendations include enhancing visible security policies, publishing vulnerability disclosure information, and providing clearer contact channels for security incidents to further strengthen trust and compliance.

70
83
17
85
82
85
100
renewableenergywindturbinessustainableenergycookieconsentprivacypolicy+2 more
Adobe Experience CloudGoogle Tag ManagerFacebook PixelLinkedIn Insight Tag+5

Partner Domains:

www.vestas.de
subsidiary
www.vestas.cn
subsidiary

+3 more partners

2025-10-30T23:19:40.623Z
orsted.com favicon

Ørsted

orsted.com

80
EnergyDenmarkenterpriseLOW

Ørsted is a leading global renewable energy company focused on driving the transition to green energy through wind and solar solutions. The company operates a professional, well-structured website that clearly communicates its mission, sustainability priorities, and corporate governance. The technical infrastructure leverages modern web technologies including AngularJS, Sitecore CMS, and advanced analytics tools such as Piwik PRO and Google Tag Manager, indicating a mature digital presence. The website is mobile-optimized, accessible, and SEO-friendly, supporting a positive user experience. From a security perspective, the site enforces HTTPS and employs domain transfer protections, but lacks DNSSEC and explicit security policies or incident response contacts. The cookie consent mechanism is robust and GDPR-compliant, with detailed categorization and third-party disclosures. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of a vulnerability disclosure policy and security.txt file suggests room for improvement in transparency and security culture. Overall, Ørsted's website reflects a high level of professionalism, trustworthiness, and compliance with privacy regulations. The domain registration data aligns well with the company's history and business profile, reinforcing legitimacy. Strategic recommendations include enabling DNSSEC, publishing security policies, and enhancing security headers to further strengthen the security posture.

90
95
25
80
72
90
100
renewableenergygreenenergysustainabilitywindenergysolarenergy+1 more
jQueryAngularJSAppDynamicsGoogle Tag Manager+2
2025-10-30T23:19:05.214Z
nvent.com favicon

nVent Electric plc

nvent.com

77
EnergyGermanyenterpriseLOW

nVent Electric plc is a global leader in electrical connection and protection solutions, serving industrial and commercial sectors with innovative products and services. Their website reflects a mature digital presence with a focus on sustainability and electrification, targeting engineers, contractors, and businesses in the energy and transportation sectors. The company positions itself as a trusted partner offering comprehensive electrical solutions worldwide. Technically, the website is built on Drupal 10 CMS, leveraging modern analytics and A/B testing tools such as Visual Website Optimizer and Google Tag Manager. The site demonstrates good mobile optimization, SEO practices, and moderate performance. Security best practices are observed with HTTPS enforcement and security headers, although explicit security policies and incident response contacts are not publicly disclosed. The security posture is strong with no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms, aligning with GDPR requirements. The absence of WHOIS data reduces domain trust slightly but does not detract significantly from the overall legitimacy given the professional content and branding. Overall, nVent's website presents a professional, secure, and compliant digital front that supports its enterprise business model and global market position.

90
73
17
80
82
90
100
electricalsolutionsindustrialenergymanufacturingb2b+3 more
Drupal 10 CMSGoogle Tag ManagerGoogle AnalyticsJavaScript libraries (jQuery)
2025-10-30T14:08:43.589Z
agorapulse.com favicon

Agorapulse

agorapulse.com

82
TechnologyN/amediumLOW

Agorapulse is a leading social media management SaaS platform designed to help businesses, agencies, and marketers streamline their social media workflows. The platform offers a comprehensive suite of tools including inbox management, publishing, listening, reporting, and social ROI measurement. Positioned as an industry leader, Agorapulse boasts strong customer support and is trusted by over 31,000 social media managers worldwide. The website reflects a mature digital presence with professional design, clear navigation, and extensive integrations with major social networks and marketing tools. Technically, the website employs a modern tech stack with analytics and marketing tools such as Google Tag Manager, Segment, Heap Analytics, and CookieYes for consent management. The site is well-optimized for performance and mobile responsiveness, ensuring a positive user experience. Security posture is solid with HTTPS enforced and bot management via Cloudflare, although explicit security headers and policies could be more transparent. From a security and compliance perspective, the site includes a comprehensive privacy and cookie policy with GDPR compliance indicators and a consent mechanism. However, no explicit security policy or incident response contacts were found, and WHOIS data is unavailable likely due to privacy protection, which is common for SaaS businesses. No vulnerabilities or exposed sensitive data were detected. Overall, Agorapulse presents a trustworthy and professional online presence with strong business credibility and technical maturity. Strategic recommendations include enhancing security header transparency, publishing a security policy, and adding vulnerability disclosure information to further strengthen trust and compliance.

85
100
17
98
82
85
100
socialmediamanagementsaasmarketinganalyticscustomersupport+2 more
Google Tag ManagerSegment AnalyticsVisual Website OptimizerHeap Analytics+5
2025-10-30T14:04:45.259Z
pensketruckrental.com favicon

Penske Truck Rental

pensketruckrental.com

76
TransportationUnited StateslargeLOW

Penske Truck Rental operates as a large, established transportation company specializing in moving truck rentals across the United States. The company offers services through a network of over 2,500 rental locations, targeting both consumers and businesses requiring truck rental solutions. Their website reflects a professional brand presence with consistent branding and a clear focus on their core services. Technically, the website employs a modern technology stack including Google Tag Manager, Google Analytics, OneTrust for cookie consent, and the RebelMouse CMS platform. The site is mobile optimized, accessible, and uses HTTPS with a good SSL configuration. However, some security best practices such as explicit security headers and published security policies are missing. From a security perspective, the site demonstrates a solid baseline with HTTPS and cookie consent mechanisms. Yet, the absence of a privacy policy, terms of service, incident response contacts, and vulnerability disclosure information indicates gaps in compliance and transparency. The WHOIS data is notably missing, which raises concerns about domain registration legitimacy despite the professional appearance of the site. Overall, the website is functional, trustworthy, and well-branded but would benefit from enhanced transparency in privacy and security policies, as well as verification of domain registration details to strengthen trust and compliance.

75
100
17
70
82
85
100
truckrentalmovingtruckstransportationpenskevehiclerental
Google Tag ManagerGoogle AnalyticsOneTrust Cookie ConsentGoogle Maps API+4
2025-10-30T11:36:30.183Z