Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149091
Websites
130
Industries
113
Countries
52
Avg Score
Page 3 of 4|Showing 101-50 of 50
dlang.org favicon

D Language Foundation

dlang.org

42
TechnologyN/amediumHIGH

The D Language Foundation operates the official website for the D programming language, a general-purpose, statically typed language with systems-level access and C-like syntax. The foundation supports the language's development, community engagement, and ecosystem growth. The website serves as a comprehensive resource hub offering documentation, tutorials, community forums, package management, and downloadable compiler binaries. It targets software developers and technology enthusiasts interested in efficient and modern programming languages. The foundation is a non-profit entity coordinating volunteer efforts and sponsorships to sustain the language's evolution. Technically, the website is well-structured, leveraging modern web technologies such as HTML5, CSS3, JavaScript, jQuery, and CodeMirror for interactive code examples. It uses Cloudflare for DNS and likely CDN services, ensuring fast performance and good mobile optimization. The site is accessible, SEO-friendly, and provides a rich user experience with clear navigation and relevant content. However, it lacks some modern security headers and DNSSEC is not enabled. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data or vulnerable libraries. There are no forms collecting sensitive personal data, reducing attack surface. However, the absence of a privacy policy, cookie consent mechanism, security policy, and incident response contact information represents compliance and transparency gaps. No vulnerability disclosure or security.txt files were found, which could hinder responsible vulnerability reporting. Overall, the website is professional, trustworthy, and technically sound but could improve privacy compliance and security transparency. Strategic recommendations include publishing privacy and cookie policies, enabling DNSSEC, adding security headers, and providing clear security and incident response information to enhance user trust and regulatory compliance.

30
35
27
75
62
5
20
programmingtechnologyopen-sourcedeveloperdlanguage+2 more
HTML5CSS3JavaScriptjQuery 1.7.2+2
2025-11-01T12:20:50.518Z
erixx.de favicon

erixx GmbH

erixx.de

56
TransportationGermanymediumMEDIUM

erixx GmbH is a regional passenger rail service provider operating in Niedersachsen and northern Germany, focusing on routes through Harz, Heide, and Wendland. The company is positioned as a trusted regional transportation operator with a clear business model centered on passenger rail services. The website provides comprehensive travel information, live schedules, ticketing options, and customer support, targeting regional train passengers. The parent company is Netinera, a known transportation group, which adds to erixx's market credibility. Technically, the website employs modern web technologies including HTML5, CSS3, JavaScript, and integrates a Progressive Web App manifest for enhanced user experience. Hosting and DNS are managed via Cloudflare, ensuring reliable performance and security. The site is mobile-optimized, accessible, and SEO-friendly, with embedded third-party widgets for timetable and route planning. From a security perspective, the website enforces HTTPS and follows several best practices, though explicit security headers like X-Frame-Options and X-Content-Type-Options are not clearly visible in the HTML. No vulnerabilities or exposed sensitive data were detected. However, the absence of a published security policy or incident response contact limits transparency in security governance. Overall, the website is professional, trustworthy, and compliant with GDPR, featuring clear privacy and cookie policies. The risk profile is low with no signs of malicious activity or content safety concerns. Strategic recommendations include enhancing security header implementation, publishing a security.txt file, and providing explicit incident response contacts to improve security posture and trust.

55
33
2
70
47
60
100
regionaltraintransportationpublictransitgermanyniedersachsen+3 more
HTML5CSS3JavaScriptCloudflare DNS+2

Partner Domains:

www.netinera.de
parent
www.lnvg.de
partner

+2 more partners

2025-11-01T10:50:58.881Z
akz.hr favicon

Hrvatski Telekom d.d.

akz.hr

52
TransportationCroatiamediumMEDIUM

The website www.akz.hr serves as the official online platform for the Zagreb Bus Station, providing extensive bus ticketing services across Croatia and neighboring countries. It offers users the ability to search for bus schedules, purchase tickets online up to 15 minutes before departure, and access real-time status updates for arrivals and departures. The platform supports mobile app integration, enhancing accessibility for travelers. The business is positioned as a key transportation service provider in the region, backed by Hrvatski Telekom d.d., a reputable Croatian telecommunications company. Technically, the website employs standard web technologies including HTML5, CSS3, and JavaScript, with integrations of Google Tag Manager and Google Analytics for marketing and analytics purposes. Hosting is managed by Hrvatski Telekom with Cloudflare DNS services, ensuring reliable domain resolution. The site demonstrates moderate performance and good mobile optimization, though accessibility features are basic. SEO practices are adequately implemented with proper meta tags and Open Graph data. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks explicit security headers such as Content Security Policy and HSTS, which are recommended for enhanced protection. Privacy compliance is limited due to the absence of a visible privacy policy and terms of service, representing a compliance gap especially under GDPR. No incident response or vulnerability disclosure information is provided. Overall, the website is trustworthy and professionally maintained, with a strong business credibility score. Strategic improvements in privacy policy publication, security header implementation, and comprehensive compliance documentation would elevate its security posture and user trust.

15
10
17
70
47
75
100
busticketstransportationonlineticketingzagrebbusstationtravel
HTML5CSS3JavaScriptGoogle Tag Manager+2
2025-11-01T08:56:59.436Z
H

Heylab AB

motels-near.me

50
HospitalitySwedensmallMEDIUM

Motels Near Me is a niche hospitality website operated by Heylab AB, a Swedish company founded in 2017. The site provides a location-based motel search service, helping travelers find motels with available rooms near their current location, emphasizing best price guarantees. The business model centers on facilitating motel discovery and potentially bookings, targeting travelers seeking convenient and affordable lodging options. The website is professionally designed with a clear user interface and good mobile optimization, leveraging modern web technologies including Vue.js, Google Analytics, and Google Maps API. Hosting and DNS services are provided via Cloudflare, ensuring reliable performance and security at the infrastructure level. Security posture is moderate with HTTPS enforced and domain transfer protections in place; however, the absence of DNSSEC and security headers like CSP and HSTS represent areas for improvement. Privacy compliance is weak due to missing privacy and cookie policies and lack of consent mechanisms, which could expose the business to regulatory risks. Contact information is minimal, limited to personal links in the about section, with no direct company emails or phone numbers disclosed. Overall, the website is functional and trustworthy but would benefit from enhanced security and privacy practices to improve compliance and user trust.

55
35
2
60
62
70
40
motelstravelhospitalitylocation-basedbooking+1 more
Google AnalyticsGoogle Tag ManagerjQueryGoogle Maps API+1
2025-11-01T08:55:59.067Z
ronigame.com favicon

Roni

ronigame.com

50
TechnologyN/asmallMEDIUM

Roni is a small technology business focused on delivering a multiplayer and single-player word game available on iOS and Android platforms. The website serves as a promotional portal providing game descriptions, screenshots, and download links to app stores. The business targets casual and word game enthusiasts, offering features such as multiplayer challenges, daily games, and chat functionality. The domain has been registered since 2013, indicating a stable presence in the market. Technically, the website uses standard web technologies including HTML5, CSS, and JavaScript, with Google Analytics for user tracking and Cloudflare for DNS services. The site is mobile optimized and provides a good user experience with clear navigation and relevant content. However, it lacks advanced security headers and cookie consent mechanisms, which are important for privacy compliance and security hardening. From a security perspective, the site enforces HTTPS and has domain transfer protections, but does not enable DNSSEC or publish security policies or incident response contacts. No WAF or blocking mechanisms are detected, and no vulnerabilities or suspicious content were found. Privacy compliance is basic, with a privacy policy present but no cookie consent banner. Overall, the website is professional and trustworthy for its purpose but could improve its security posture and privacy compliance to better protect users and enhance trust. Strategic recommendations include enabling DNSSEC, implementing security headers, adding cookie consent, and publishing security and incident response information.

30
53
2
70
72
55
40
wordgamemobileappmultiplayerpuzzlegaming
HTML5CSSJavaScriptGoogle Analytics+1
2025-11-01T08:41:32.052Z
H

HeyWeb

heyweb.com

55
TechnologyN/asmallMEDIUM

HeyWeb was a technology-focused SaaS platform designed to enable small business owners to rapidly create websites by converting their Facebook pages into fully functional websites. The service automated content updates from social media and provided features such as custom domains and newsletter signups. The website is currently closed, indicating the service is no longer active. The domain is well-established, registered since 2007, and uses reputable registrar and DNS providers, supporting its legitimacy. Technically, the website uses a modest tech stack including jQuery, typed.js, and Google Analytics for tracking. It is hosted with Cloudflare DNS and uses Gandi SAS as the registrar. The site is mobile optimized and has a good design and user experience, but lacks advanced accessibility features and comprehensive SEO optimization. No CMS or major frameworks were detected. From a security perspective, the site lacks DNSSEC, security headers, and visible privacy or cookie policies, which are critical for compliance and user trust. The domain is protected against unauthorized transfers but could improve DNS security. No WAF or blocking mechanisms were detected, and no sensitive data exposure was found. Overall, the security posture is moderate but requires improvements to meet modern standards. The overall risk is moderate with no critical vulnerabilities detected. Strategic recommendations include implementing DNSSEC, publishing privacy and cookie policies, adding security headers, and providing clear contact and incident response information to enhance trust and compliance.

30
35
2
85
52
70
100
websitecreationfacebookintegrationsmallbusinesssaastechnology
jQuery 2.2.4typed.jsGoogle AnalyticsGoogle Tag Manager+1

Partner Domains:

christoffersblommor.se
partner
knackeriet.se
partner

+3 more partners

2025-11-01T08:41:22.024Z
I

imrmbb.site

imrmbb.site

46
OtherN/asmallHIGH

The website at imrmbb.site currently contains no accessible content beyond a minimal placeholder message 'Not found'. There is no metadata, structured data, forms, or business information available to analyze. The domain is newly registered in November 2024 with a two-year expiry and uses Cloudflare DNS servers without DNSSEC enabled. No privacy, cookie, or terms of service policies are present, and no contact or security incident response information is provided. The lack of content and transparency significantly limits the ability to assess the business or security posture meaningfully. From a technical perspective, the site appears to be hosted behind Cloudflare but lacks modern security headers and DNS security features. The absence of HTTPS status information and security headers suggests a basic or incomplete security configuration. No analytics, advertising, or tracking technologies are detected, indicating minimal digital maturity or possibly an inactive site. Security posture is weak due to the lack of visible security best practices and policies. No vulnerabilities can be assessed due to the absence of content. The domain registration is transparent and consistent but the lack of business information and website content reduces trustworthiness. Overall, the site presents a high risk for users due to the lack of information and transparency. Strategic recommendations include enabling DNSSEC, publishing privacy and cookie policies, implementing HTTPS with strong TLS, adding security headers, and providing clear contact and incident response information to improve trust and compliance.

15
40
17
60
42
70
100
Cloudflare DNS
2025-11-01T07:19:49.679Z
athero.org favicon

International Atherosclerosis Society

athero.org

10
HealthcareN/amediumCRITICAL

The International Atherosclerosis Society (IAS) operates a professional, global network website focused on atherosclerotic cardiovascular disease education, research, and clinical practice. Established in 1979, the IAS provides educational resources, fellowships, webinars, and organizes international meetings to support clinicians worldwide. The website reflects a mature, well-branded organization with consistent messaging and a clear target audience of healthcare professionals specializing in cardiovascular disease. Technically, the website is built on WordPress with modern plugins such as Gravity Forms and Rank Math SEO, hosted behind Cloudflare DNS. It employs Google Analytics for traffic monitoring and uses Cloudflare Turnstile CAPTCHA for form security. The site is mobile-optimized, accessible, and SEO-friendly, though performance is moderate. Security posture is good with HTTPS enforced and no exposed sensitive data, but lacks DNSSEC and explicit security headers. No direct contact emails or phone numbers are publicly listed, but a subscription form is available. Privacy compliance is partial with a privacy policy present but no cookie consent mechanism detected. No vulnerability disclosure or incident response policies are published. Social media presence is active on major platforms. Overall, the IAS website is a professional, trustworthy resource for clinicians with a solid technical foundation and good security practices. Improvements in privacy compliance and security headers would enhance trust and regulatory adherence.

-
-
-
-
-
-
-
healthcareeducationatherosclerosisprofessionalsocietymedicalresearch
WordPressGravity FormsCloudflare DNSGoogle Analytics+4
2025-11-01T07:07:14.305Z
pythonsummit.org favicon

Fundacja Academic Partners

pythonsummit.org

66
TechnologyPolandsmallMEDIUM

Python Summit is a specialized conference targeting Python developers, data engineers, architects, and DevOps professionals, primarily in Poland but with international reach. It is organized by the Fundacja Academic Partners foundation and associated Python communities such as PyData and PyWaw. The event offers both online and onsite participation, with a comprehensive agenda featuring expert speakers and practical case studies. The conference also includes a job fair and offers multipass tickets granting access to related conferences, enhancing its value proposition. Technically, the website employs modern web technologies including AngularJS, Google Tag Manager, Facebook Pixel, and Swiper.js for UI components. It is hosted with DNS managed by Cloudflare and uses HTTPS, ensuring secure communications. The site is mobile-optimized and provides a good user experience with clear navigation and professional design. Analytics and marketing tools are extensively used, with appropriate cookie consent mechanisms in place. From a security perspective, the site enforces HTTPS and uses clientTransferProhibited domain status to prevent unauthorized transfers. However, DNSSEC is not enabled, and advanced security headers like CSP are not explicitly observed. There is no published security policy or incident response contact, which could be improved. Privacy and cookie policies are present and GDPR compliance is indicated through consent banners. Overall, the website presents a professional and trustworthy image with a solid technical foundation and good privacy practices. The domain is newly registered, consistent with the event timeline, and no suspicious indicators are found. Strategic improvements in security headers, DNSSEC, and incident response transparency would enhance the security posture further.

15
80
47
70
62
75
100
pythonconferencetechnologydevelopersdatascience+4 more
AngularJS (ng-app, ng-scope)Google Tag ManagerGoogle AnalyticsFacebook Pixel+3

Partner Domains:

yavaconf.com
partner
devai.dssconf.pl
partner

+2 more partners

2025-11-01T07:03:33.111Z
yavaconf.com favicon

Fundacja Academic Partners

yavaconf.com

63
TechnologyPolandsmallMEDIUM

Ya!vaConf is a specialized technology conference focusing on the Java stack, organized by Fundacja Academic Partners. It targets developers, architects, DevOps professionals, and testers interested in Java and related technologies. The conference offers both online and onsite participation, with a rich agenda, networking opportunities, and an expo. The event is well-positioned in the Polish tech conference market, emphasizing quality content and community engagement. Technically, the website employs modern web technologies including AngularJS, Google Tag Manager, and various analytics and tracking tools. It uses Cloudflare DNS and is served over HTTPS, ensuring secure access. The site is mobile-optimized and features good SEO practices, although accessibility could be improved. The presence of structured data enhances search engine understanding. From a security perspective, the site enforces HTTPS and uses clientTransferProhibited status in WHOIS to protect domain transfers. However, DNSSEC is not enabled, and no explicit security policy or incident response contacts are published. Privacy compliance is strong with clear cookie consent and a comprehensive privacy policy. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website presents a professional, trustworthy, and well-maintained digital presence for the conference. The main risks relate to minor security enhancements and improving accessibility. Strategic recommendations include enabling DNSSEC, publishing a security policy, and enhancing accessibility features to further strengthen trust and compliance.

15
50
55
60
62
75
100
javaconferencetechnologydevopscloud+4 more
AngularJS (ng-app, ng-controller)Google Tag ManagerGoogle Analytics (gtag.js)Facebook Pixel+5

Partner Domains:

fundacjaap.org.pl
partner
devai.dssconf.pl
partner

+1 more partners

2025-11-01T07:00:54.351Z
experisfrance.fr favicon

Experis France

experisfrance.fr

55
TechnologyFrancelargeMEDIUM

Experis France is a well-established IT talent and solutions provider operating primarily in France, with a business foundation dating back to 2011. The company offers a broad range of IT services including professional resourcing, managed services, consulting, project services, and academy services, targeting IT professionals and businesses seeking specialized IT expertise. As a subsidiary of ManpowerGroup, Experis France benefits from a strong market position and brand recognition in the technology sector. The website reflects a mature digital presence with professional design, multilingual support, and comprehensive content tailored to its audience. Technically, the site is built on WordPress with modern frontend frameworks and integrates multiple marketing and analytics tools such as HubSpot, Google Tag Manager, and Piano Analytics, indicating a high level of digital maturity. Security-wise, the website enforces HTTPS, implements key security headers, and maintains GDPR compliance with cookie consent mechanisms. However, it lacks a dedicated security policy or incident response contact information, and no vulnerability disclosure or security.txt file is present. Overall, the domain registration data aligns well with the business claims, supporting the legitimacy of the entity. Strategic recommendations include publishing explicit security policies, establishing incident response contacts, and enhancing accessibility features to further improve compliance and trust.

57
70
100
85
40
2
-
itservicestalentresourcingcybersecuritycloudconsulting+2 more
WordPressYoast SEOGoogle Tag ManagerHubSpot+1

Partner Domains:

manpowergroup.com
parent
2025-11-01T05:33:17.982Z