Skip to main content

High-risk security reports

Browse 46,998 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157371
Websites
130
Industries
113
Countries
52
Avg Score
Page 316 of 940|Showing 15751-15800 of 46998
lumentrgovina.hr favicon

Lumen trgovina d.o.o.

lumentrgovina.hr

39
RetailCroatiamediumHIGH

Lumen trgovina d.o.o. is a Croatian wholesale and retail company specializing in decorative products such as candles, lanterns, wedding invitations, and floral supplies. It operates under the umbrella of LUMEN d.o.o., a well-established manufacturer with over 35 years of experience in candle and lamp production. The company targets retailers, florists, and event planners, providing a broad product range for various decorative needs. The website reflects a medium-sized business with consistent branding and a professional online presence. Technically, the website uses a traditional tech stack including jQuery, Owl Carousel, and Google Analytics, but relies on outdated JavaScript libraries which may pose security risks. The site is moderately optimized for performance and mobile use, with basic SEO and accessibility features. No CMS or advanced frameworks were detected, indicating a custom or static site approach. From a security perspective, the site lacks visible security headers and explicit privacy or cookie policies, which lowers its compliance posture. The use of HTTPS is implied but not explicitly confirmed in the provided data. Tracking via Google Analytics and Facebook SDK is present, but privacy compliance is minimal. Contact information is clearly provided, enhancing business credibility. Overall, the website is functional and professional but would benefit from updates to its security practices, privacy compliance, and modernization of its technical stack. These improvements would enhance trustworthiness and reduce potential vulnerabilities.

15
10
2
70
62
80
-
decorationswholesalecandlesweddingsretail+2 more
jQuery 1.9.1jQuery UI 1.10.4Owl CarouselMagnific Popup+2
2025-10-11T14:15:34.849Z
crealia.org favicon

Créalia Occitanie

crealia.org

44
FinanceFrancesmallHIGH

Créalia Occitanie is a regional financial organization specializing in innovation funding for businesses in the Occitanie region of France. The company offers key services such as zero-interest loans up to 100,000 euros and support for strengthening company equity. The website positions itself as a trusted partner for innovative enterprises seeking financial assistance. The business is well-established with a domain age of over 18 years, indicating stability and credibility in its market niche. Technically, the website is built on WordPress using Elementor and Yoast SEO plugins, indicating a modern and maintainable infrastructure. Hosting is provided by OVH, a reputable provider. The site demonstrates good performance and mobile optimization, with Google Analytics integrated for user tracking. However, accessibility features are basic, and some security best practices like DNSSEC and security headers are not implemented. From a security perspective, the site uses HTTPS with a good SSL configuration and domain status protections to prevent unauthorized domain changes. However, it lacks published privacy and cookie policies, incident response information, and vulnerability disclosure mechanisms, which are important for compliance and trust. No security headers were detected, and no explicit contact information was found in the provided content, which could impact user trust and regulatory compliance. Overall, the website is professional and functional with a moderate security posture. Strategic improvements in privacy compliance, security policy publication, and enhanced security headers would strengthen its trustworthiness and regulatory adherence.

15
35
2
60
62
80
20
financeinnovationloanbusinessoccitanie+2 more
WordPressElementorYoast SEOGoogle Analytics+1
2025-10-11T14:13:51.196Z
haspa-musik-stiftung.de favicon

HASPA Musik Stiftung

haspa-musik-stiftung.de

46
Non-profitGermanysmallHIGH

The HASPA Musik Stiftung website serves as an informational platform for a Hamburg-based non-profit foundation dedicated to supporting children and youth in their musical development. The foundation partners with various local music projects and institutions to foster musical talent and enrich the cultural landscape of Hamburg. The website content is well-structured, professionally presented, and primarily targets local community members, music enthusiasts, and potential donors. Technically, the site is built on the TYPO3 CMS platform, leveraging custom JavaScript for email obfuscation and standard CSS for styling. The site demonstrates good mobile optimization and basic accessibility features, though there is room for improvement in security headers and cookie consent mechanisms. Hosting appears professional with DNS managed by reputable providers. From a security perspective, the site uses HTTPS (implied by canonical URL), but lacks explicit security headers and cookie consent banners, which are important for GDPR compliance. No forms or direct contact emails are exposed in raw form, reducing spam risk. No vulnerability disclosures or incident response policies are published, indicating a potential area for enhancement. Overall, the website is trustworthy and professional, with a solid business credibility score. Strategic improvements in privacy compliance and security posture would enhance user trust and regulatory adherence.

25
28
2
60
72
65
40
musicfoundationhamburgnon-profitculture+2 more
TYPO3 CMSJavaScriptCSS
2025-10-11T13:07:53.139Z
korint.com favicon

Korint Design Studio

korint.com

41
OtherBosnia and HerzegovinasmallHIGH

Korint Design Studio is a small design agency based in Bosnia and Herzegovina, established in 2002. The company offers a range of creative services including graphic design, web design, visual identity, SEO optimization, and mobile application development. Their website showcases recent projects and targets businesses seeking modern and professional design solutions. The market position appears to be local or regional with a focus on small to medium-sized clients. Technically, the website uses a traditional tech stack with jQuery, Bootstrap, and various UI plugins for sliders and carousels. The site is moderately optimized for performance and mobile devices but lacks modern CMS or frameworks. SEO and accessibility features are basic. No CMS or hosting provider details are explicitly found beyond the registrar information. From a security perspective, the site lacks visible security headers and DNSSEC is not enabled, which are areas for improvement. There is no evidence of HTTPS enforcement or privacy and cookie policies, indicating compliance gaps with GDPR and general data protection best practices. No forms or data collection mechanisms were detected, reducing immediate data exposure risks but also limiting user engagement. Overall, the website is functional and moderately professional but requires enhancements in privacy compliance, security hardening, and contact transparency to improve trust and regulatory adherence.

15
50
2
70
62
75
-
designgraphicdesignwebdesignseomobileapplications+1 more
jQueryBootstrapSuperfishCamera Slider+4
2025-10-11T13:03:47.027Z
bosch-press.nl favicon

Robert Bosch GmbH

bosch-press.nl

43
TechnologyNetherlandsenterpriseHIGH

The Bosch Media Service website serves as the official corporate media portal for Robert Bosch GmbH in the Netherlands, providing press releases, media content, and corporate news to journalists and business partners. The site reflects Bosch's strong market position as a leading global technology and engineering company, focusing on sectors such as energy, transportation, and technology. The platform supports Bosch's communication strategy by offering well-structured, relevant content with consistent branding and a professional design. Technically, the website employs modern web technologies including HTML5, CSS3, JavaScript, and Google Tag Manager for analytics and marketing. It features a custom cookie consent mechanism compliant with GDPR, ensuring user privacy and consent management. The site is mobile-optimized with good SEO practices and basic accessibility features, although some enhancements could improve compliance and user experience. From a security perspective, the site enforces HTTPS and implements cookie consent but lacks some advanced security headers and explicit incident response contacts. No vulnerabilities or exposed sensitive data were detected. The domain registration aligns well with Bosch's corporate identity, indicating high legitimacy and trustworthiness. Overall, the website presents a low-risk profile with strong business credibility and privacy compliance. Strategic recommendations include enhancing security headers, adding incident response information, and publishing terms of service to improve legal completeness and security posture.

15
28
2
40
-
75
100
boschmediaservicepressreleasescorporatetechnology+1 more
HTML5CSS3JavaScriptWebFont Loader+2
2025-10-11T13:03:01.847Z
vwcanarias.com favicon

Volkswagen Canarias

vwcanarias.com

48
TransportationSpainlargeHIGH

Volkswagen Canarias operates as the official Volkswagen dealership and service provider in the Canary Islands, offering a comprehensive range of automotive products and services including new vehicle sales, financing, after-sales support, and accessories. The website is professionally designed, well-structured, and targets consumers in the Canary Islands interested in Volkswagen vehicles, including electric and hybrid models. The company is part of the larger Volkswagen AG group and is supported by the Domingo Alonso Group, indicating a strong market position and reputable backing. Technically, the website leverages modern web technologies such as Adobe Experience Manager CMS, React-based components, and advanced lazy loading techniques to deliver a performant and accessible user experience. Security posture is robust with HTTPS enforcement, security headers, and client-side guards against unauthorized content loading. Privacy compliance is well addressed with comprehensive privacy and cookie policies and consent mechanisms. However, the absence of publicly available WHOIS data and lack of explicit security policy or incident response contacts slightly reduce trust. Overall, the site demonstrates a mature digital presence aligned with corporate standards and regional market needs.

-
-
-
70
65
70
100
automotivevolkswagencardealerelectricvehiclesspanish+5 more
Adobe Helix RUMReact (implied by react-helmet meta tags)LazySizes (lazy loading images)MutationObserver+3

Partner Domains:

domingoalonsogroup.com
partner
vwcomerciales.com
partner

+1 more partners

2025-10-11T11:58:52.496Z
r-produkt.com favicon

R-Produkt d.o.o.

r-produkt.com

42
ManufacturingBosnia and HerzegovinasmallHIGH

R-Produkt d.o.o. is a small manufacturing company based in Bosnia and Herzegovina, specializing in the production and sales of steel chains, ropes, and hydraulic equipment. The website serves as a basic informational portal with minimal content and navigation, linking to subdomains for production and salon business segments. The company has an established domain since 2009, indicating a stable presence in its market niche. Technically, the website uses legacy HTML practices with IE8 compatibility and includes jQuery as a JavaScript library. The site lacks modern security features such as HTTPS confirmation, DNSSEC, and security headers, which limits its security posture. Mobile optimization and accessibility are basic, and SEO practices are minimal. Analytics are implemented via Clicky, indicating moderate user tracking without visible privacy compliance mechanisms. From a security perspective, the absence of HTTPS and security headers, combined with no visible privacy or cookie policies, presents compliance and security risks. No contact information or forms are provided, limiting user engagement and transparency. The domain registration data is consistent and trustworthy, but the website itself requires significant improvements in security and privacy compliance. Overall, the website scores low to moderate in content quality, technical implementation, and security posture, with critical issues around HTTPS absence and privacy compliance. Strategic improvements are needed to enhance trust, security, and user experience.

15
50
2
70
62
70
20
manufacturingsaleschainsropeshydraulic+1 more
jQuery

Partner Domains:

proizvodnja.r-produkt.com
subsidiary
salon.r-produkt.com
subsidiary
2025-10-11T11:52:34.369Z
design-zentrum-hamburg.de favicon

Design Zentrum Hamburg

design-zentrum-hamburg.de

40
OtherGermanysmallHIGH

Design Zentrum Hamburg is a prominent non-profit initiative dedicated to supporting and promoting the design industry in Hamburg. It serves as a hub for events, exhibitions, workshops, and funding programs aimed at fostering creativity and professional growth within the local design community. The organization operates under the umbrella of the Hamburg Kreativ Gesellschaft, positioning itself as a key player in Hamburg's creative ecosystem. The website reflects a professional and well-structured digital presence, offering clear navigation and comprehensive information about its services and initiatives. Technically, the site leverages modern web technologies including Matomo for analytics, Google Maps API, and PrivacyWire for cookie consent management, all hosted on a CMS platform identified as ProcessWire. Security posture is strong with HTTPS enforced, security headers present, and no visible vulnerabilities or exposed sensitive data. Privacy compliance is robust, featuring a comprehensive privacy policy, cookie consent mechanisms, and GDPR adherence. However, the site lacks a publicly available security policy or incident response contact details, which could enhance trust and preparedness. Overall, the domain registration data is limited but consistent with the business identity, supporting the legitimacy of the website. The site is safe for general audiences, with no adult or questionable content detected.

-
-
-
75
95
65
-
designeventsnetworkingworkshopsfunding+3 more
Matomo AnalyticsGoogle Maps APIPrivacyWire (cookie consent)Lottie animations+1

Partner Domains:

kreativgesellschaft.org
partner
nextmedia-hamburg.de
partner

+1 more partners

2025-10-11T10:49:02.260Z
bosch-home.by favicon

ООО "БСХ Бытовые Приборы"

bosch-home.by

43
RetailRussiamediumHIGH

ООО "БСХ Бытовые Приборы" operates as the official service provider for household appliances of major brands Bosch, Siemens, Neff, and Gaggenau in Russia. The website serves as a customer support portal offering repair order placement, spare parts ordering, service center locations, and user manuals. It targets Russian consumers seeking authorized after-sales service for these brands. The business model focuses on service and maintenance, positioning itself as a trusted intermediary between customers and the global BSH group brands. Technically, the website employs modern web standards including HTML5, CSS3, JavaScript, and Bootstrap for responsive design. The site is accessible, well-structured, and optimized for mobile devices. However, no CMS or hosting provider details are evident. The site lacks visible analytics or tracking scripts, indicating a privacy-conscious approach. Performance is moderate with good SEO and accessibility basics. From a security perspective, the site uses HTTPS (implied by external image URLs), but no explicit security headers were detected in the provided data. Cookie consent is implemented with a clear mechanism, and a comprehensive privacy policy is available, indicating GDPR compliance. No incident response or security policy pages were found. No vulnerabilities or exposed sensitive data were identified in the HTML content. Overall, the website presents a professional and trustworthy front for the official appliance service business in Russia. The lack of WHOIS data limits domain registration insights but does not detract from the site's legitimacy. Strategic improvements in security headers and incident response transparency would enhance the security posture and trust further.

15
53
2
40
72
60
20
applianceserviceboschsiemensneffgaggenau+3 more
HTML5CSS3JavaScriptBootstrap
2025-10-11T10:43:10.764Z
gruener-beschaffen.de favicon

Initiative Pro Recyclingpapier

gruener-beschaffen.de

34
GovernmentGermanysmallHIGH

The website 'Grüner beschaffen' is operated by the Initiative Pro Recyclingpapier, a German non-profit organization dedicated to promoting sustainable paper procurement using recycled paper certified with the Blue Angel eco-label. The initiative targets public sector entities, educational institutions, municipalities, SMEs, and associations, encouraging them to adopt environmentally responsible paper purchasing practices. The site offers educational content, campaigns, recognition programs, and practical resources to support climate and resource protection efforts. Technically, the website is built on WordPress 6.8.3 with jQuery and uses the Easy Fancybox plugin for media display. It is hosted on servers associated with kasserver.com and employs Matomo analytics configured to disable cookies, reflecting a privacy-conscious approach. The site is mobile-optimized with good navigation and SEO practices, though accessibility features are basic. Performance is moderate, with no critical technical issues detected. From a security perspective, the site enforces HTTPS and uses minimal necessary cookies with user consent. However, it lacks explicit security headers and published security or incident response policies. No vulnerabilities or exposed sensitive data were found. The domain WHOIS data is consistent with the website's purpose and hosting, indicating legitimacy. Overall, the security posture is solid but could be improved with additional headers and formal policies. The website content is safe for general audiences, focusing on environmental sustainability without any adult or questionable material. Contact information including email, phone, and physical address is clearly provided, enhancing trust. The site maintains partnerships with reputable organizations such as the German Environment Agency and the Kompetenzstelle für nachhaltige Beschaffung, reinforcing its credibility.

15
28
2
55
42
50
-
sustainabilityrecyclingenvironmentpaperblue-angel+3 more
WordPress 6.8.3jQuery 3.7.1Easy Fancybox pluginMatomo Analytics

Partner Domains:

papiernetz.de
partner
umweltbundesamt.de
partner

+1 more partners

2025-10-11T09:41:43.407Z
M

MediaMarkt

mediamarkt.de

46
RetailGermanylargeHIGH

MediaMarkt is a leading German consumer electronics retailer with a strong market presence in Germany and Europe. The company operates both physical stores and an online platform offering a wide range of electronic products and related services. The website analyzed is currently inaccessible due to a Cloudflare security challenge page, which prevents direct access to the main content and business information. This limits the ability to fully assess the website's technical and security posture. Technically, the site uses Cloudflare's WAF and Akamai DNS services, indicating a mature infrastructure designed to protect against attacks and ensure availability. However, the presence of a security challenge page without visible privacy, cookie, or contact information reduces transparency and user experience. No analytics or marketing scripts were detected beyond the security challenge mechanisms. From a security perspective, the site benefits from enterprise-grade DNS and WAF protection but lacks visible security headers or policies on the challenge page. The absence of accessible privacy and cookie policies and contact information limits compliance assessment. The domain WHOIS data is consistent with a legitimate enterprise, showing no suspicious patterns. Overall, the website's risk is low given the brand and infrastructure, but the current blocking by Cloudflare WAF significantly restricts analysis and user access. Strategic recommendations include allowing access to main content for analysis, publishing clear privacy and cookie policies, and improving transparency to enhance trust and compliance.

70
10
2
87
100
70
-
retailelectronicscloudflaresecurity-challenge
CloudflareAkamai DNS
2025-10-11T09:41:33.385Z
fahrlehrerverbaende.de favicon

Bundesvereinigung der Fahrlehrerverbände e. V.

fahrlehrerverbaende.de

41
TransportationGermanymediumHIGH

The Bundesvereinigung der Fahrlehrerverbände e. V. (BVF) is a German national association representing 18 regional driving instructor associations, covering the entire country. The organization serves the majority of German driving school owners and employed driving instructors. The website provides information about the association, its tasks, projects, and events, targeting driving instructors and related stakeholders in Germany. The business model is non-profit and focused on advocacy, information dissemination, and member services. Technically, the website uses a moderate technology stack including Bootstrap 4, Google Tag Manager, and SixCMS as the content management system. Hosting is provided by Hetzner, a reputable German hosting provider. The site is mobile-optimized with good SEO practices and structured navigation, although accessibility features are basic. Performance is moderate with no critical technical issues detected. From a security perspective, the website uses HTTPS but lacks visible security headers and explicit cookie consent mechanisms. No security or incident response policies are published, and no vulnerability disclosure or security.txt files are found. Google Tag Manager is used for analytics, indicating moderate user tracking. Overall, the security posture is adequate but could be improved by implementing security headers, cookie consent, and publishing security policies. The overall risk assessment is low, with no signs of malicious content or suspicious domain registration. Strategic recommendations include enhancing privacy compliance, adding security headers, publishing security policies, and improving transparency around data protection and incident response.

25
28
2
60
72
60
-
drivinginstructorsgermanyassociationtransportationeducation
Bootstrap 4.0.0Google Tag ManagerFonts.googleapis.com
2025-10-11T09:40:38.154Z
deginvest-investments.de favicon

DEG - Deutsche Investitions- und Entwicklungsgesellschaft

deginvest-investments.de

47
FinanceGermanylargeHIGH

DEG - Deutsche Investitions- und Entwicklungsgesellschaft operates as a development finance institution focused on financing, promoting, and supporting companies investing in developing and emerging countries. The website presents a professional investment database with extensive filtering options by region, country, sector, year, and customer, indicating a mature and data-driven business model. The target audience includes investors and companies seeking development financing in emerging markets. The company is positioned as a key player in development finance with a strong focus on emerging economies. Technically, the website is built on TYPO3 CMS, a robust open-source content management system, and integrates Usercentrics for cookie consent management, reflecting compliance with privacy regulations. The site uses HTTPS and SVG-based interactive maps for data visualization. Performance and mobile optimization are moderate to good, with basic accessibility features. From a security perspective, the site enforces HTTPS and uses a consent management platform, but lacks visible security headers and published privacy or terms of service documents. No contact information or incident response contacts are found, which could be improved. No WAF or blocking mechanisms are detected, and no vulnerabilities are apparent from the provided data. Overall, the website is professional and trustworthy but would benefit from enhanced privacy compliance documentation, security header implementation, and clearer contact information to improve user trust and regulatory adherence.

30
25
17
70
62
70
20
investmentdevelopmentfinanceemergingmarketstypo3usercentrics+1 more
TYPO3 CMSUsercentrics CMPSVG mapsJavaScript
2025-10-11T09:38:57.486Z