Skip to main content

High-risk security reports

Browse 46,998 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157371
Websites
130
Industries
113
Countries
52
Avg Score
Page 315 of 940|Showing 15701-15750 of 46998
ethicaltrade.org favicon

Ethical Trading Initiative

ethicaltrade.org

48
Non-profitN/amediumHIGH

The Ethical Trading Initiative (ETI) is a well-established non-profit alliance comprising trade unions, NGOs, and businesses focused on promoting ethical trade and human rights in global supply chains. The website positions ETI as a leading organization in this space, offering membership, training, transparency frameworks, and resources to support responsible business practices. The presence of major retail and NGO members underscores its market position and credibility. Technically, the website is built on Drupal 10, leveraging modern web technologies including Google Analytics with IP anonymization, CookiesJSR for cookie consent management, and Vimeo for video content. The site demonstrates good mobile optimization, accessibility, and SEO practices, though some security headers are missing which could be improved. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms aligned with GDPR requirements. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not present, representing areas for enhancement. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website is professional, trustworthy, and safe for general audiences. The lack of WHOIS data due to privacy protection is justified given the non-profit nature of the organization. Strategic recommendations include enhancing security headers, publishing security and incident response policies, and providing direct security contact information to strengthen trust and compliance.

40
68
17
40
27
70
40
ethicaltradehumanrightscorporatetransparencynon-profitsupplychain+2 more
Drupal 10Google AnalyticsCookiesJSRVimeo Player+1

Partner Domains:

community.ethicaltrade.org
partner
etibd.org
partner

+3 more partners

2025-10-11T20:02:02.456Z
eutraveltech.eu favicon

EU Travel Tech

eutraveltech.eu

36
TransportationBelgiummediumHIGH

EU Travel Tech is a European travel technology organization that serves as a collaborative platform for travel tech companies and stakeholders. The organization focuses on industry advocacy, policy engagement, research, and hosting events to advance travel technology in Europe. The website reflects a medium-sized organization based in Belgium, established around 2019, with a clear focus on the transportation and technology sectors. The site features membership logos of prominent travel companies, indicating a strong market position within the travel tech industry. Technically, the website is built on WordPress with modern plugins such as All in One SEO and uses Google Analytics for tracking. The site is mobile-optimized with good SEO practices and moderate performance. Security-wise, HTTPS is enforced, and cookie consent mechanisms are in place, but there is a lack of advanced security headers and no visible incident response or vulnerability disclosure policies. Overall, the security posture is solid but could be improved by adding security headers and formalizing incident response contacts. The website is professional, trustworthy, and compliant with GDPR basics, making it a credible source for its target audience. No adult or questionable content is present, and the site is fully accessible without WAF or blocking mechanisms.

15
25
2
70
-
75
20
traveltechnologyeumembershippolicy+2 more
WordPress 6.8.3All in One SEO pluginGoogle Analytics (gtag.js)Barba.js (page transitions)+1

Partner Domains:

atelierdesign.be
partner
2025-10-11T20:01:47.374Z
zifera.io favicon

Zifera

zifera.io

47
TechnologyNetherlandssmallHIGH

Zifera is a small, Netherlands-based company specializing in green web development and digital carbon footprint analytics. Their business model focuses on providing sustainable web and e-commerce development services alongside a SaaS application that helps organizations monitor, optimize, and compensate their digital carbon emissions. The company is positioned as a niche player with a strong emphasis on environmental sustainability and digital responsibility, supported by client testimonials and media features. Technically, the website is built using modern frameworks such as Astro, hosted with Cloudflare DNS services, and employs privacy-friendly analytics via Simple Analytics. The site demonstrates excellent design quality, mobile responsiveness, and SEO optimization, reflecting a mature digital presence for a small company. However, some security best practices like DNSSEC and security headers are not yet implemented. From a security perspective, the site uses HTTPS and avoids exposing sensitive data, but lacks explicit security policies, incident response contacts, and vulnerability disclosure mechanisms. Privacy compliance is partially met with a comprehensive privacy policy but no cookie consent mechanism. The absence of direct contact emails or phone numbers slightly reduces business credibility. Overall, Zifera presents a trustworthy and professional online presence with a clear business focus on sustainability in technology. Strategic improvements in security headers, cookie consent, and incident response transparency would enhance their security posture and compliance standing.

15
53
2
85
75
60
-
greenwebdevelopmentcarbonanalyticssustainabilitye-commercedigitalcarbonfootprint+4 more
AstroCloudflare DNSSVG graphicsSimple Analytics
2025-10-11T18:49:52.279Z
creditpass.de favicon

creditPass GmbH

creditpass.de

43
FinanceGermanymediumHIGH

creditPass GmbH is a well-established German FinTech company specializing in payment security, risk management, and compliance solutions for business customers. Operating since 2003, it offers a modular platform connecting merchants with payment service providers, credit agencies, and identity providers. The company provides a broad range of services including credit checks, SEPA direct debit payment processing, Buy Now Pay Later modules, and cloud integration services. With over 1,500 customers and active participation in industry associations, creditPass holds a strong market position in the European FinTech sector. Technically, the website is built on WordPress using modern plugins such as Yoast SEO, LayerSlider, and Contact Form 7, with Google reCAPTCHA v3 implemented for form security. The site is mobile-optimized and SEO-friendly, though some improvements in accessibility and performance could be made. Security posture is solid with HTTPS enforced and no visible sensitive data exposure, but lacks explicit security headers and a formal security policy or vulnerability disclosure page. Overall, creditPass demonstrates a mature digital presence with good business credibility and trust indicators. However, the absence of cookie consent mechanisms and explicit contact emails or phone numbers slightly reduce privacy compliance and user trust. No WAF or blocking mechanisms were detected, allowing full content access and analysis. Strategic recommendations include implementing cookie consent for GDPR compliance, adding security headers, publishing a security.txt file, and enhancing contact transparency to improve user trust and compliance posture.

15
28
17
75
62
65
-
fintechpaymentsecurityb2bcreditchecksepa+4 more
WordPressPHPYoast SEOLayerSlider+7

Partner Domains:

interlake.net
partner
bdoa.de
partner

+3 more partners

2025-10-11T17:45:27.610Z
v-i-r.de favicon

Verband Internet Reisevertrieb e.V. (VIR)

v-i-r.de

47
TechnologyGermanymediumHIGH

The Verband Internet Reisevertrieb e.V. (VIR) is a German industry association focused on advancing digital technologies in the tourism sector. It serves as a platform for companies and experts in digital tourism, advocating for members in media, politics, and consumer relations. The association emphasizes innovation, startup support, sustainability, and market research, positioning itself as a key player in the digital travel market in Germany. The website reflects a mature digital presence with comprehensive content, events, and partnerships that reinforce its industry leadership. Technically, the website is built on WordPress with modern plugins such as Elementor, Yoast SEO, and Borlabs Cookie for privacy compliance. It uses Matomo for analytics, indicating a preference for privacy-conscious tracking. The site is hosted on kasserver.com and employs HTTPS with good SSL configuration. Performance and mobile optimization are adequate, though accessibility could be improved. From a security perspective, the site follows best practices with HTTPS and cookie consent mechanisms but lacks explicit security headers and published security policies. No vulnerabilities or exposed sensitive data were detected. The WHOIS data aligns well with the website's business claims, indicating legitimacy and trustworthiness. Overall, the site is professional, secure, and compliant with privacy norms, though it could enhance transparency by publishing privacy policies and security incident response information.

15
43
17
85
62
70
-
digitaltourismtourismassociationonlinetravelmarketstartupssustainability+3 more
WordPress 6.8.3Enfold Theme 7.1.2Elementor 3.32.4Yoast SEO 26.1.1+3

Partner Domains:

chain4travel.com
partner
drsf.reise
partner

+3 more partners

2025-10-11T17:44:21.419Z
zifera.nl favicon

Zifera

zifera.nl

47
TechnologyNetherlandssmallHIGH

Zifera is a small, Netherlands-based company specializing in green web development and digital carbon footprint analytics. Their services focus on helping organizations develop energy-efficient websites and applications, with additional offerings in e-commerce sustainability and digital carbon analytics. The company provides customized dashboards to monitor and optimize the carbon footprint of digital assets, positioning itself as a niche player in the sustainability technology sector. The website is professionally designed, mobile-optimized, and features clear navigation and relevant content targeted at businesses seeking sustainable digital solutions. Technically, the website leverages modern frameworks such as Astro and is hosted with Cloudflare DNS services. It employs privacy-friendly analytics via Simple Analytics, indicating a commitment to user privacy. The site performs well in terms of speed and accessibility, with good SEO practices evident. However, there is no detected cookie consent mechanism, which is a gap in privacy compliance given the use of analytics scripts. From a security perspective, the site uses HTTPS and shows no signs of exposed sensitive data or vulnerable libraries. However, no explicit security headers or published security policies were found, and there is no visible incident response or vulnerability disclosure information. These gaps suggest room for improvement in formalizing security posture and transparency. Overall, Zifera's website reflects a credible and professional business with a strong focus on sustainability and technology. The domain registration data aligns well with the business claims, supporting legitimacy. Strategic recommendations include implementing cookie consent, publishing security policies, adding security headers, and providing clear security incident contacts to enhance trust and compliance.

15
53
2
70
75
75
-
greenwebdevelopmentcarbonanalyticssustainabilitydigitalcarbonfootprinteco-friendlyweb+3 more
AstroCloudflare DNSSimple Analytics
2025-10-11T17:41:49.343Z
T

taxatiemoduleonline.nl

taxatiemoduleonline.nl

49
OtherNetherlandssmallHIGH

The website taxatiemoduleonline.nl/admin/login serves as a secure login portal for an administrative module related to property or asset valuation services. Access is restricted exclusively to users with a PowerKraut Google Account, indicating a controlled and limited user base, likely internal staff or authorized partners. The site employs Tailwind CSS for styling and presents a minimalistic, functional design focused on authentication rather than marketing or public information. The domain is registered with a Dutch registrar and has been active since late 2020, consistent with a small or medium-sized enterprise operating in the Netherlands. From a technical perspective, the site uses modern CSS frameworks but lacks visible SEO metadata, structured data, or comprehensive accessibility features. There is no evidence of analytics or tracking scripts, which aligns with the site's restricted access nature. Security posture is moderate; while login is restricted to Google authentication, no security headers or explicit HTTPS enforcement details were found in the provided data. Privacy and cookie policies are absent, which is a compliance gap. Overall, the security posture is basic but functional for an internal admin portal. The lack of public-facing business information, contact details, and compliance documentation limits the site's transparency and trust signals. The domain registration data is consistent and legitimate, with no suspicious patterns detected. Strategic improvements should focus on adding security headers, privacy and cookie policies, and incident response information to enhance compliance and trust.

15
25
2
60
72
60
100
adminloginpropertyvaluationgoogleauthenticationtailwindcss
Tailwind CSS
2025-10-11T17:39:29.010Z
smartcom.de favicon

SmartCom GmbH

smartcom.de

40
TechnologyGermanymediumHIGH

SmartCom GmbH is a German-based company specializing in hyperpersonalized dialog marketing solutions leveraging programmatic printing and e-mailing technologies. Their services enable businesses to deliver highly targeted 1:1 marketing campaigns with relevant content at optimal times, enhancing customer engagement and conversion rates. The company positions itself as a specialized provider in the marketing technology sector, targeting businesses seeking advanced personalization in their customer communications. Technically, the website is built on WordPress using the Blocksy theme and integrates modern plugins such as Yoast SEO and Matomo Analytics. The site demonstrates good mobile optimization, SEO practices, and a moderate performance profile. Multimedia content including videos and client logos enhance the user experience. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks explicit security headers, privacy and cookie policies, and incident response information, which are areas for improvement. No vulnerabilities or malicious content were detected. Overall, the website is professional, trustworthy, and content-rich, but would benefit from enhanced privacy compliance and security transparency to improve user trust and regulatory adherence.

15
28
2
70
62
60
-
marketingprogrammaticprintinge-mailinghyperpersonalizationdialogmarketing+2 more
WordPressYoast SEO pluginjQueryYouTube Embed Plus plugin+1
2025-10-11T16:29:12.591Z
underscores.me favicon

Automattic, Inc.

underscores.me

48
TechnologyUnited StateslargeHIGH

Underscores.me is a website offering a starter theme for WordPress developers, maintained by Automattic, Inc., a reputable company in the WordPress ecosystem. The site provides a minimal, well-structured theme framework designed for developers to build custom WordPress themes efficiently. The business model is open source and community-driven, targeting WordPress theme developers globally. The website is technically built on WordPress CMS with modern web technologies including HTML5, CSS3, JavaScript, and jQuery, and uses WordPress.com nameservers for hosting. The site is mobile-optimized and provides a good user experience with clear navigation and professional design. From a security perspective, the website enforces HTTPS and has domain registration protections in place, but lacks DNSSEC and explicit security headers, which are recommended for enhanced security. No privacy or cookie policies are present, and Google Analytics is installed but not configured, indicating minimal user tracking. There is no visible incident response or vulnerability disclosure information, which could be improved to enhance trust and compliance. The domain WHOIS data is consistent with the business, showing a long-standing registration by Automattic, Inc., supporting the legitimacy of the site. Overall, the website is safe, professional, and trustworthy, with a strong business credibility and technical foundation. However, it would benefit from improved privacy compliance, security headers, and transparency regarding data protection and incident response. These enhancements would strengthen the site's security posture and regulatory compliance, aligning with best practices for modern web services.

15
50
2
60
62
75
40
wordpressstarterthemeopensourceautomatticwebdevelopment+1 more
HTML5CSS3JavaScriptjQuery+1
2025-10-11T16:28:17.348Z
lafrenchtechlemans.com favicon

La French Tech Lemans

lafrenchtechlemans.com

46
OtherN/asmallHIGH

La French Tech Lemans operates a French-language website providing a comprehensive step-by-step guide on creating and optimizing a Google My Business profile to enhance local business visibility and SEO. The site targets local business owners and entrepreneurs seeking to improve their online presence through Google My Business. The business model is informational, focusing on content delivery rather than direct commercial services. The website uses Sitecore CMS and includes standard web technologies such as jQuery and FontAwesome, but some libraries are outdated. The site is moderately optimized for mobile and SEO but lacks advanced accessibility features. From a security perspective, the website lacks visible security headers and there is no explicit evidence of HTTPS enforcement in the provided data. The WHOIS lookup failed to return any registration data, which is a significant concern regarding domain legitimacy and trustworthiness. No contact information or social media links are provided, limiting business credibility and user trust. Privacy and cookie policies are minimal, with no consent mechanisms detected, indicating potential GDPR compliance gaps. Overall, the website presents useful content with good design and user experience but suffers from technical and security shortcomings, including missing WHOIS data, lack of security headers, and absence of privacy compliance features. These issues reduce the overall trust and security posture of the site. Strategic improvements in security, privacy compliance, and transparency are recommended to enhance credibility and user confidence.

15
50
17
40
72
75
40
googlemybusinessseolocalbusinessfrenchtechbusinessguide
jQuery 1.12.4jQuery Migrate 1.4.1FontAwesome
2025-10-11T16:28:02.302Z
carsale24.com favicon

carsale24

carsale24.com

49
TransportationGermanymediumHIGH

carsale24 operates as a professional online platform facilitating the sale of used cars primarily in Germany, Austria, and Switzerland. The company connects private sellers with a network of verified dealers, offering a streamlined, secure, and convenient car selling experience. Their business model is commission-based, funded by dealers, and includes value-added services such as premium vehicle appraisals and personalized customer support. The website demonstrates strong market positioning with trust signals including customer testimonials, media endorsements, and certification badges. Technically, the website is built on WordPress with a modern tech stack including the Enfold theme, WP Rocket for performance optimization, and Usercentrics for consent management. The site is well-optimized for SEO and mobile responsiveness, ensuring a high-quality user experience. Analytics and marketing tools such as Google Tag Manager are employed with privacy compliance in mind. From a security perspective, the site enforces HTTPS and integrates consent management, but lacks explicit HTTP security headers and incident response contact details. No vulnerabilities or exposed sensitive data were detected. The absence of WHOIS data for the domain is a concern but does not currently undermine the site's legitimacy given the professional content and business presence. Overall, carsale24 presents a trustworthy and mature online service with strong business credibility and technical implementation. Strategic improvements in security headers and transparency around incident response would further enhance their security posture and user trust.

15
73
2
60
62
75
20
carsalesonlinemarketplaceautomotivegermanytrustedservice+3 more
WordPress 6.8.3Enfold ThemejQuery 3.7.1WP Rocket+3
2025-10-11T15:20:07.708Z
formetal.biz favicon

Formetal d.o.o.

formetal.biz

39
ManufacturingCroatiasmallHIGH

Formetal d.o.o. is a Croatian manufacturing company specializing in the production of galvanized cold-formed profiles and distribution of reinforcements for PVC joinery. Established in 2005, the company targets the Croatian market with a focus on supplying metal profiles for construction and manufacturing sectors. The website serves primarily as an informational portal showcasing the company’s products and brands (Formetal and Tehnometal). Technically, the website uses legacy technologies such as jQuery 1.x and Google Analytics for tracking. The site is basic in design and functionality, with minimal interactive elements and no visible forms or contact details on the homepage. Mobile optimization and accessibility are basic, and SEO practices are minimal but present through meta tags. From a security perspective, the site lacks modern security headers and does not have DNSSEC enabled. The use of an outdated jQuery version introduces potential vulnerabilities. No privacy or cookie policies are present, and no consent mechanisms are implemented, indicating compliance gaps with GDPR and related regulations. The domain registration data is consistent and legitimate, supporting the business’s authenticity. Overall, the website is functional but basic, with moderate business credibility but notable security and compliance weaknesses. Strategic improvements in security posture, privacy compliance, and technical modernization are recommended to enhance trust and protect business operations.

15
35
2
70
62
75
-
manufacturingmetalgalvanizedprofilespvcreinforcementscroatia
jQuery 1.xGoogle Analytics (ga.js)jquery.simplyscroll plugin
2025-10-11T14:16:14.508Z