Skip to main content

High-risk security reports

Browse 46,998 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157371
Websites
130
Industries
113
Countries
52
Avg Score
Page 313 of 940|Showing 15601-15650 of 46998
heilmasseure.com favicon

BUNDESVERBAND DER HEILMASSEURE UND MEDIZINISCHEN MASSEURE ÖSTERREICHS (BHÖ)

heilmasseure.com

49
HealthcareAustriasmallHIGH

The website represents the Austrian Federal Association of Medical and Healing Masseurs (BHÖ), a professional non-profit organization founded in 2002 to represent and support the interests of medical masseurs in Austria. The site provides member services, therapist search functionality, news updates, and job postings, targeting healthcare professionals and the general public seeking therapeutic massage services. The business model is focused on professional representation and member engagement within the healthcare sector in Austria. Technically, the website is built on Microsoft ASP.NET WebForms using the STYRIAWEB CMS platform, with client-side technologies including jQuery 1.8.3 and Google Analytics for visitor tracking. The site shows moderate performance and basic mobile optimization. Privacy and cookie policies are implemented, indicating awareness of GDPR compliance, though some modern security practices such as updated libraries and security headers are lacking. From a security perspective, the site uses HTTPS and has a cookie consent mechanism, but lacks visible security headers and uses an outdated jQuery version, which could expose it to vulnerabilities. The absence of WHOIS data for the domain raises concerns about domain legitimacy and registration transparency, which impacts trustworthiness. No explicit incident response or security policies are publicly available. Overall, the website is functional and professional but would benefit from technical and security improvements. The domain registration inconsistency is a notable risk factor. Strategic recommendations include updating technology stack components, enhancing security headers, and clarifying domain registration details to improve trust and compliance.

15
68
17
70
62
75
20
healthcareprofessionalassociationmedicalmassageaustrianon-profit
jQuery 1.8.3ASP.NET WebFormsAJAXGoogle Analytics (ga.js)
2025-10-12T06:18:03.917Z
ltbl.fr favicon

Let There Be Light

ltbl.fr

46
TechnologyFrancesmallHIGH

Let There Be Light is a French creative multimedia studio specializing in interactive and immersive installations using light, video, and kinetics. Founded in 2016 and based in Lyon, the company serves an international clientele including artists, museums, and cultural events. Their business model combines artistic creation with technological expertise, positioning them as a creative technology studio with a strong presence in the art and digital scenography sectors. The website reflects a professional and consistent brand image with good content quality and clear navigation. Technically, the website is built using the Hugo static site generator and leverages modern web components and custom JavaScript modules. Hosted by OVH, a reputable French hosting provider, the site demonstrates moderate performance and good mobile optimization. SEO and accessibility are basic but adequate for the site's scope. No major technical issues or vulnerabilities were detected in the provided content. From a security standpoint, the site uses HTTPS and does not expose sensitive data or vulnerable libraries. However, it lacks visible security headers, cookie consent mechanisms, and detailed privacy or security policies, which are important for GDPR compliance and user trust. No incident response or vulnerability disclosure information is provided. The WHOIS data is consistent with the business claims, showing a domain age appropriate for the company's founding date and no privacy protection, which aligns with transparency expectations. Overall, the website is safe, professional, and credible but could improve its privacy compliance and security posture by adding cookie consent, detailed privacy policies, and security headers. Contact information visibility could also be enhanced to improve user trust and engagement.

15
10
2
70
85
70
40
creativemultimediainteractivearttechnology+3 more
Hugo 0.122.0Web Components (webcomponents-bundle.js)Custom JS modulesCSS with custom fonts (Lato, Gibson)

Partner Domains:

plan-valley.com
partner
2025-10-12T05:13:00.122Z
drv-netzwerkstatt.de favicon

Deutscher Reiseverband

drv-netzwerkstatt.de

42
HospitalityGermanysmallHIGH

The DRV-Netzwerkstatt website represents a professional event platform affiliated with the Deutscher Reiseverband, focused on networking and knowledge exchange within the tourism industry. The site targets industry professionals and offers biannual events to foster cross-sector collaboration. The business model centers on event hosting and community building, supported by a small but consistent team with clear contact channels and social media presence. Technically, the website is built on TYPO3 CMS, hosted by Schlund Technologies, and incorporates modern web standards including responsive design and Google Tag Manager for analytics. The site performs moderately well with good SEO and accessibility basics, though some improvements in security headers and explicit policies could enhance its posture. Security-wise, the site enforces HTTPS and provides cookie consent mechanisms, indicating GDPR awareness. However, it lacks publicly visible security policies, incident response contacts, or vulnerability disclosure information. No critical vulnerabilities or suspicious elements were detected, and the WHOIS data aligns well with the business identity, supporting legitimacy. Overall, the website is trustworthy, professionally maintained, and compliant with basic privacy standards. Strategic improvements in security transparency and policy publication would further strengthen its risk profile and user trust.

25
43
2
55
72
60
-
tourismnetworkingeventdrvtypo3+1 more
TYPO3 CMSBootstrapGoogle Tag Manager

Partner Domains:

www.drv.de
partner
2025-10-12T05:09:59.381Z
S

SEMRUSH INC

seoab.io

43
TechnologyCyprusmediumHIGH

The website seoab.io appears to be a technical or internal resource associated with SEMRUSH INC, a technology company registered in Cyprus since 2020. The site content is minimal, consisting primarily of embedded JavaScript code without user-facing content, metadata, or structured data. There are no visible privacy, cookie, or terms of service policies, nor any contact information or social media links. The domain registration is consistent and legitimate, with professional DNS hosting via Google Cloud DNS. However, the lack of visible content and policies limits the ability to fully assess the site’s business and security posture. From a technical perspective, the site uses JavaScript heavily but lacks detectable frameworks or CMS. No security headers or SSL configuration details were found in the provided data, indicating potential gaps in security best practices. No forms or data collection mechanisms were identified, suggesting limited user interaction. The site does not appear to use advertising or analytics services. Security posture is weak due to missing security headers, lack of DNSSEC, and no visible SSL information. Privacy compliance is also lacking with no privacy or cookie policies detected. The domain WHOIS data is transparent and consistent with a legitimate business entity, supporting moderate trust in the domain’s legitimacy. Overall, the site scores low on content quality and security but has a solid domain registration foundation. Recommendations include implementing HTTPS with a valid SSL certificate, adding security headers, publishing privacy and cookie policies, and providing clear contact information to improve trust and compliance. Enhancing visible content and metadata would also improve SEO and user experience.

15
50
2
60
-
75
100
JavaScript
2025-10-12T04:05:27.622Z
aicpcorp.com favicon

American International Concession Products, Corp. (AICP)

aicpcorp.com

49
RetailUnited StatesmediumHIGH

American International Concession Products, Corp. (AICP) is a well-established broker and distributor specializing in concession products, premium merchandise, packaging, and crowd control equipment primarily serving the entertainment and hospitality industries. With over 35 years of experience, AICP positions itself as a leading provider in its niche, offering curated solutions to enhance guest experiences and operational efficiency. The website reflects a professional business model targeting entertainment venues, concession operators, and related clients. Technically, the website is built on WordPress with modern front-end libraries such as Bootstrap 5 and Swiper.js, ensuring a responsive and user-friendly experience. SEO is supported by Yoast SEO plugin, and performance is moderate with good mobile optimization. Hosting appears to be managed via GoDaddy, consistent with the domain registrar information. From a security perspective, the site uses HTTPS and Google reCAPTCHA on its contact forms, which are positive indicators. However, the absence of DNSSEC, security headers, and explicit security or incident response policies suggests room for improvement. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism detected. WHOIS data confirms domain legitimacy and consistency with the business claims. Overall, the website presents a credible and professional front for AICP Corp., with moderate technical maturity and basic security posture. Strategic enhancements in security headers, privacy compliance, and incident response transparency would strengthen trust and resilience.

20
53
2
75
42
80
40
concessionsnacksmerchandisepackagingcrowdcontrol+2 more
WordPressBootstrap 5jQuerySwiper.js+1

Partner Domains:

ogrelogic.com
partner
2025-10-12T04:01:42.425Z
phuket.surgery favicon

Phuket Surgery

phuket.surgery

45
HealthcareThailandsmallHIGH

Phuket Surgery is a specialized online platform established in 2017 that facilitates medical tourism in Thailand, focusing on connecting patients with reputable medical providers in locations such as Phuket and Bangkok. The platform offers services including procedure search, personalized quotes, and booking assistance, positioning itself as a trusted marketplace for international patients seeking healthcare services in Thailand. The website is professionally designed with good content quality, clear navigation, and consistent branding, targeting medical tourists and patients interested in cosmetic and other medical procedures. Technically, the website is built on WordPress using Elementor and several modern web technologies including jQuery, Bootstrap, and Google reCAPTCHA for form security. SEO is well implemented with Yoast SEO plugin and structured data in JSON-LD format. The site is mobile optimized and performs moderately well, though some accessibility features could be improved. From a security perspective, the site uses HTTPS with good SSL configuration and employs Google reCAPTCHA to protect forms. However, explicit security headers like Content-Security-Policy and X-Frame-Options are not detected, and privacy compliance mechanisms such as cookie consent banners are missing. WHOIS data is unavailable or privacy protected, which is common but reduces transparency. No critical vulnerabilities or suspicious content were found. Overall, Phuket Surgery presents a credible and professional online presence for medical tourism services in Thailand, with recommendations to enhance security headers, privacy compliance, and transparency to further strengthen trust and compliance.

15
80
17
40
-
85
40
medicaltourismthailandphukethealthcareplasticsurgery+4 more
WordPressPHPjQueryElementor+6
2025-10-12T03:57:57.386Z
B

BF Invest Ingatlanhasznosító Kft.

bfinvest.hu

45
Real EstateHungarysmallHIGH

BF Invest Ingatlanhasznosító Kft. is a Hungarian real estate company specializing in harbor development and management, particularly the Balatonfüredi Hajógyári kikötő. The company has a long-standing presence since 2005 and offers services including boat storage, boat lifting, and harbor facilities with conference and business rooms. Their market position is that of a local, established player in the real estate and harbor services sector, targeting boating enthusiasts and local businesses. Technically, the website is built on WordPress 6.8.3 with older JavaScript libraries such as jQuery 1.7, bxSlider, and Fancybox 1.3.4. The site is moderately optimized for performance and mobile devices but lacks advanced SEO and accessibility features. No analytics or tracking tools are detected, indicating minimal user tracking. From a security perspective, the site uses HTTPS but lacks important security headers and uses outdated libraries that may expose it to vulnerabilities. There are no visible privacy or cookie policies, which is a compliance gap under GDPR. No incident response or vulnerability disclosure information is provided. Overall, the website is functional and professional but requires improvements in security, privacy compliance, and technical modernization to reduce risks and enhance trustworthiness.

50
10
2
70
62
60
40
realestateharborboatstoragedevelopmenthungary
jQuery 1.7bxSliderFancybox 1.3.4WordPress 6.8.3+1
2025-10-12T02:55:55.521Z
drv-seminare.de favicon

DRV-Seminare

drv-seminare.de

46
EducationGermanysmallHIGH

DRV-Seminare is a German-based educational service provider specializing in seminars and training courses. The website is built on TYPO3 CMS and leverages a variety of JavaScript libraries to enhance user experience, including jQuery, FontAwesome, and Slick Carousel. The site targets professionals seeking educational seminars, positioning itself as a niche provider within the education sector in Germany. The business model revolves around offering paid training sessions and seminars, with a small company size and consistent branding. Technically, the website demonstrates moderate digital maturity with a modern CMS and common frontend libraries. Hosting is provided by SchlundTech, a reputable German hosting provider. Performance and mobile optimization are basic but functional. SEO and accessibility features are present but could be improved. The site uses Google Analytics for user tracking but lacks a cookie consent mechanism. From a security perspective, the site uses HTTPS and does not expose sensitive data. However, no advanced security headers or explicit security policies are published. Privacy compliance is partially addressed with a privacy policy page in German, but cookie consent and terms of service are missing. No incident response or vulnerability disclosure information is available. Overall, the security posture is moderate but could benefit from enhancements. The overall risk assessment is low, with no signs of malicious activity or suspicious content. Strategic recommendations include implementing security headers, adding cookie consent, publishing security and incident response policies, and improving accessibility and SEO. These steps will enhance trust, compliance, and user experience.

25
28
2
60
95
60
20
educationseminarstrainingtypo3germany
jQueryFontAwesomeSlick CarouselVegas Background Slider+4
2025-10-12T02:53:54.744Z
S

Schmetterling Support

schmetterling-support.de

45
OtherN/asmallHIGH

The website schmetterling.de/support/ presents a minimalistic and nearly empty page with only a title and a heading indicating 'Schmetterling Technologie Support'. There is no substantive content, metadata, or contact information available, which severely limits the ability to assess the business or its services. The domain WHOIS data is heavily restricted by DENIC, providing no registrar, creation, or expiry dates, and no registrant information, which further complicates trust evaluation. The lack of HTTPS confirmation and absence of security or privacy policies indicate a low security posture and poor compliance with modern web standards. Technically, the website lacks any detectable frameworks, scripts, or CMS, and no external links or social media presence are found. The site appears to be either a placeholder or under development, with poor design, accessibility, and SEO characteristics. Security headers and SSL configuration details are missing, suggesting potential vulnerabilities or at least a lack of security hardening. From a security perspective, the absence of HTTPS and security headers, combined with no visible privacy or cookie policies, results in a very low security score. The WHOIS data's lack of transparency and minimal website content reduce the domain's legitimacy score. No signs of adult or unsafe content are present, and the site is accessible without WAF or blocking mechanisms. Overall, the site is not currently suitable for professional or customer-facing use. Strategic recommendations include implementing HTTPS, adding comprehensive privacy and cookie policies, providing clear contact and business information, and improving website content and technical SEO to enhance trust and security posture.

15
15
2
70
72
65
100
supporttechnologyplaceholder
2025-10-12T02:51:59.211Z