Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157331
Websites
130
Industries
113
Countries
52
Avg Score
Page 320 of 800|Showing 15951-16000 of 39982
senq-cyber.com favicon

Senq

senq-cyber.com

65
FinanceUnited StatesenterpriseMEDIUM

Senq is an enterprise-focused cybersecurity company specializing in advanced threat intelligence and breach detection services. Their offerings include dark web monitoring, takedown services, vendor breach monitoring, strategic threat reports, disinformation monitoring, and bespoke threat content. The company targets financial institutions and large enterprises globally, with a presence in the United States, UAE, and Europe. The website demonstrates a professional and consistent brand image with modern design and clear navigation. Technically, the site uses modern front-end technologies such as Tailwind CSS and Font Awesome, ensuring good mobile responsiveness and accessibility. However, there is no evidence of CMS or hosting provider details. Performance is moderate, and SEO practices are adequately implemented. Security-wise, HTTPS is implied but no explicit security headers were detected, and no incident response or vulnerability disclosure policies are published. The absence of WHOIS data for the domain raises concerns about domain legitimacy. Overall, Senq presents a strong security posture with recognized certifications (SOC 2 Type II, GDPR, NIC2, ISO 27001) and a comprehensive service portfolio. The lack of privacy and cookie policies and missing WHOIS data are notable gaps. The site is safe for general audiences and does not contain any adult or questionable content.

80
80
64
70
37
75
40
cybersecuritythreatintelligencebreachdetectiondarkwebmonitoringenterprisesecurity+1 more
Tailwind CSSFont AwesomeJavaScript
2025-10-02T20:11:43.615Z
J

Visitor anti-robot validation

jak.lv

46
TechnologyN/asmallHIGH

The website jekabpils.jak.lv serves as a security validation gateway powered by BitNinja, designed to block IP addresses suspected of violating server security policies and to prevent automated bot access. Visitors are required to complete a CAPTCHA challenge to proceed, indicating the site functions primarily as a protective layer rather than a traditional business or content site. The page includes multilingual support and integrates Google reCAPTCHA and Google Analytics for bot mitigation and visitor tracking. Technically, the site uses legacy CMS meta tags referencing Joomla 1.5 and WordPress 2.5, though the actual content is minimal and focused on security validation. The presence of Google Analytics and Tag Manager scripts indicates moderate tracking capabilities. However, the site lacks modern security headers and explicit privacy or cookie policies, which limits its compliance posture. From a security perspective, the site demonstrates basic bot mitigation practices but shows potential risks due to outdated CMS references and absence of advanced security headers. The domain WHOIS data is privacy protected, which is typical for security-related services but limits transparency. Overall, the site is a security checkpoint rather than a business-facing website, with limited content and no direct business or contact information. Strategically, the site should enhance its security posture by updating CMS components, implementing modern security headers, and publishing clear privacy and cookie policies to improve trust and compliance. Given its role as a security gateway, maintaining robust bot mitigation and clear user guidance is critical.

20
10
17
70
57
65
100
securitycaptchabotmitigationbitninjaanti-robot+1 more
HTML5CSS3JavaScriptGoogle Analytics+3
2025-09-30T11:17:51.801Z
vilksgroup.com favicon

VILKS Group

vilksgroup.com

50
TransportationLatviamediumMEDIUM

VILKS Group is a Latvia-based transportation company specializing in international road freight services with a focus on temperature-controlled cargo across Europe. Established in 2007 as a successor to MULTILOG, VILKS leverages over 14 years of industry experience and a dedicated team to provide groupage, full cargo transportation, warehousing, local deliveries, and express freight services. Their market position is that of a reliable and specialized logistics partner serving businesses requiring temperature-sensitive transport solutions, particularly in the Baltic region and Finland. Technically, the website is built on WordPress with standard plugins such as Contact Form 7 and integrates modern tracking and marketing tools including Google Analytics, Facebook Pixel, and LinkedIn Insight Tag. The site is mobile-optimized with good navigation and content quality, reflecting a mature digital presence. Hosting and domain registration are consistent with professional standards, though DNSSEC is not enabled. From a security perspective, the site uses HTTPS and implements Google reCAPTCHA on forms, along with a cookie consent mechanism, indicating compliance with GDPR. However, there is room for improvement in security headers and explicit security policies. No incident response or vulnerability disclosure information is provided, which could be enhanced to improve trust and readiness. Overall, the website and business demonstrate a solid risk posture with no critical vulnerabilities detected. Strategic recommendations include enabling DNSSEC, adding security headers, publishing security policies, and enhancing incident response transparency to further strengthen security and compliance.

15
68
17
75
47
80
20
transportationlogisticstemperature-controlledfreighteurope+2 more
WordPressPHPJavaScriptjQuery+4
2025-09-29T09:38:35.140Z
ublockorigin.com favicon

uBlock Origin

ublockorigin.com

59
TechnologyN/asmallMEDIUM

uBlock Origin is a well-established open-source browser extension focused on ad and content blocking with an emphasis on CPU and memory efficiency. It enjoys a strong market position with millions of active users across major browsers including Chrome, Firefox, Edge, Opera, and Safari (prior to version 13). The project is led by founder Raymond Hill and maintained actively with a transparent development process hosted on GitHub. The website reflects a professional, clean, and user-friendly design with multilingual support and clear calls to action for downloading the extension. Technically, the website uses modern web standards including HTML5, CSS3, JavaScript, and jQuery, hosted behind Cloudflare DNS services. It is optimized for performance and mobile responsiveness, with good SEO and accessibility features. However, some security best practices such as DNSSEC and security headers are not implemented, and no explicit privacy or cookie policies are published, which could be improved to enhance compliance and user trust. From a security perspective, the site enforces HTTPS and has domain registration protections in place, but lacks formal incident response or vulnerability disclosure mechanisms. No tracking or advertising scripts are present, aligning with the privacy-centric nature of the product. Overall, the security posture is solid but could benefit from additional transparency and technical enhancements. The overall risk assessment is low given the open-source nature, transparent domain registration, and absence of suspicious indicators. Strategic recommendations include publishing privacy and cookie policies, enabling DNSSEC, adding security headers, and providing clear vulnerability reporting channels to further strengthen trust and compliance.

15
53
2
75
60
80
100
adblockeropensourceprivacycontentblockerbrowserextension+1 more
HTML5CSS3JavaScriptjQuery 3.5.1+1
2025-09-26T13:48:20.568Z
landkreis-aurich.de favicon

Landkreis Aurich

landkreis-aurich.de

44
GovernmentGermanymediumHIGH

Landkreis Aurich operates as a local government authority in Germany, providing a wide range of public services including social welfare, health, environmental management, and administrative support to residents. The website serves as an official portal for information dissemination, citizen engagement, and access to government services. It targets local residents, businesses, and stakeholders within the district. The business model is that of a public sector entity focused on governance and community services. Technically, the website is built on TYPO3 CMS, leveraging Bootstrap for responsive design and various JavaScript libraries such as jQuery, Swiper.js, and DataTables to enhance user experience. The site demonstrates moderate performance and good mobile optimization, with a clear navigation structure and professional design. Cookie consent is implemented with user choice, reflecting GDPR compliance. From a security perspective, the site uses HTTPS and has implemented cookie consent mechanisms, but lacks visible security headers and explicit security or incident response policies. No vulnerabilities or exposed sensitive data were detected in the provided content. The WHOIS data is minimal but consistent with the domain's purpose, supporting legitimacy. Social media presence and external partnerships further reinforce trust. Overall, the website is a well-maintained government portal with good content quality and technical implementation. Strategic improvements in security headers and transparency around security policies would enhance its security posture and trustworthiness.

15
55
2
70
52
60
20
governmentlocalauthoritypublicservicesgermantypo3+5 more
HTML5CSS3JavaScriptBootstrap+5

Partner Domains:

mkw-grossefehn.de
partner
anevita.de
partner

+2 more partners

2025-09-23T09:44:34.612Z
C

Carsten Röpkes | Straßen- und Tiefbau

carsten-roepkes.de

23
TransportationGermanysmallCRITICAL

Carsten Röpkes | Straßen- und Tiefbau is a small local construction business specializing in road and civil engineering services in the Ostfriesland region of Germany. The company offers a range of services including street and deep construction, paving with natural and concrete stones, driveway and terrace construction, and pipeline construction. The website serves as an informational portal targeting local customers and businesses seeking specialized construction and landscaping services. Technically, the website is built with basic HTML, CSS, and JavaScript, incorporating Google Analytics for visitor tracking. The site is hosted on servers associated with kasserver.com, consistent with the domain's WHOIS data. The website lacks modern CMS frameworks and shows basic mobile and accessibility optimization. SEO is reasonably addressed through meta tags and structured navigation. From a security perspective, the website lacks HTTPS, which is a critical vulnerability for user data protection and trust. No security headers are present, and there are no visible privacy or cookie policies, indicating non-compliance with GDPR requirements. The use of Google Analytics without a consent mechanism further highlights privacy compliance gaps. Contact information is clearly provided, but no incident response or security policies are disclosed. Overall, the website is functional and informative but requires significant improvements in security, privacy compliance, and technical modernization to enhance trustworthiness and protect user data. Strategic implementation of HTTPS, security headers, privacy policies, and consent mechanisms is recommended to align with best practices and regulatory requirements.

15
-
-
70
-
45
-
straenbautiefbaupflasterarbeitennatursteinrohrleitungsbau+2 more
HTMLCSSJavaScriptGoogle Analytics
2025-09-22T07:40:26.832Z
sparkasse-aurich-norden.de favicon

Sparkasse Aurich-Norden

sparkasse-aurich-norden.de

68
FinanceGermanymediumMEDIUM

Sparkasse Aurich-Norden is a regional German savings bank providing a broad range of financial services including retail banking, loans, investments, insurance, and digital banking solutions. The website targets both private and business customers with a strong emphasis on secure online banking and local presence in Aurich and Norden. The bank is part of the well-established Sparkassen-Finanzgruppe, which enhances its market credibility and trustworthiness. The site features comprehensive product information, legal disclosures, and customer support channels, reflecting a mature digital presence. Technically, the website is built on a modern web stack likely supported by Adobe Experience Manager or a similar CMS, with React components and standard web technologies. It is mobile-optimized, accessible, and integrates analytics and marketing tools such as Google Analytics and PAYBACK. The site uses HTTPS exclusively and shows good security practices, although explicit security policies and incident response information are not publicly disclosed. From a security perspective, the site demonstrates a solid posture with secure login forms, cookie consent mechanisms, and no visible vulnerabilities or suspicious content. WHOIS data aligns well with the website's claims, showing consistent registration and no privacy protection masking, supporting high legitimacy. No WAF or blocking mechanisms were detected, allowing full content access. Overall, the website is professional, trustworthy, and compliant with GDPR and other relevant regulations. It effectively supports the bank's business model and customer engagement strategies while maintaining a good security and privacy standard.

90
68
2
55
74
65
100
bankingfinanceonline-bankingsparkassegirokonto+4 more
JavaScriptCSSHTML5jQuery (implied by $ usage)+3
2025-09-19T08:31:03.403Z
indodax.com favicon

PT Indodax Nasional Indonesia

indodax.com

70
FinanceIndonesialargeMEDIUM

PT Indodax Nasional Indonesia operates INDODAX, Indonesia's largest and most trusted cryptocurrency exchange platform, offering trading services for Bitcoin and various other cryptocurrencies. With over 8.5 million members, the platform provides 24/7 trading, OTC services, and educational resources through its Academy. The company is regulated and supervised by Indonesian authorities including OJK, CFX, and KOMDIGI, and holds ISO 9001 and ISO 27001 certifications, underscoring its commitment to quality and information security. Technically, INDODAX employs modern web technologies including Nuxt.js and integrates multiple analytics and marketing tools such as Google Analytics, TikTok Pixel, and Facebook Pixel. The website is mobile-optimized and hosted behind Cloudflare DNS services, ensuring good performance and availability. However, DNSSEC is not enabled, and some security headers are not explicitly detected. From a security perspective, the platform enforces HTTPS, maintains domain transfer protections, and demonstrates strong compliance with recognized security standards. Nonetheless, there is room for improvement in publishing explicit incident response contacts and implementing cookie consent mechanisms to enhance privacy compliance. No critical vulnerabilities or exposed sensitive data were identified. Overall, INDODAX presents a high level of professionalism, trustworthiness, and technical maturity suitable for its large user base and critical role in Indonesia's crypto market. Strategic enhancements in privacy and security transparency would further solidify its market position and regulatory compliance.

65
53
17
80
75
80
100
cryptocurrencyexchangebitcointradingfinance+1 more
JavaScriptVue.js (implied by Nuxt.js usage)Google AnalyticsGoogle Tag Manager+3
2025-09-07T14:13:18.290Z
southxchange.com favicon

SouthXChange

southxchange.com

56
FinanceN/amediumMEDIUM

SouthXChange operates as a cryptocurrency exchange platform offering real-time trading services for bitcoin and other digital currencies. The website positions itself as a fast and secure platform targeting cryptocurrency traders and investors. However, the content is minimal and primarily serves as a gateway to the main exchange platform hosted on a related domain. The business model focuses on providing exchange services with additional features like crypto games, though details are sparse. Technically, the site uses modern frontend technologies including Vue.js and Vuetify, indicating a contemporary web development approach. The site loads moderate content with basic mobile optimization and accessibility features. However, there is a lack of comprehensive SEO and performance optimization indicators. No CMS or hosting provider information is discernible from the provided data. From a security perspective, the site lacks visible security headers and does not provide privacy, cookie, or terms of service policies, which are critical for compliance and user trust. No contact or incident response information is available, limiting transparency. The WHOIS data for the subdomain is unavailable, which is typical for subdomains but reduces domain registration transparency. No WAF or blocking mechanisms are detected, and the site is accessible. Overall, the website presents a basic but functional front for a cryptocurrency exchange service. Key improvements are needed in privacy compliance, security best practices, and business transparency to enhance trust and regulatory adherence.

15
35
2
80
75
85
100
cryptocurrencyexchangefinancevuejsvuetify
Vue.jsVuetifyMaterial Design IconsGoogle Fonts (Roboto)+1

Partner Domains:

market.southxchange.com
service
southxchange.gorgias.help
service
2025-09-07T14:13:03.242Z
ecashconference.com favicon

Electronic Cash Conference 2025 | Barcelona

ecashconference.com

56
TechnologySpainsmallMEDIUM

The Electronic Cash Conference 2025 website serves as an informational and ticketing platform for a specialized event focused on digital cash and decentralized finance, scheduled in Barcelona. The site targets developers, researchers, and advocates in the blockchain and digital currency space, offering talks, panels, and workshops. The business model revolves around event organization and community engagement within a niche technology sector. The domain is newly registered in 2025, consistent with the event timeline, and hosted with reputable infrastructure. Technically, the website is built using modern frameworks such as Next.js and React, ensuring good performance, mobile optimization, and accessibility. The site is well-structured with clear navigation and professional design, enhancing user experience. However, it lacks some standard compliance elements such as privacy and cookie policies, and no contact information is provided, which limits user trust and regulatory compliance. From a security perspective, the site uses HTTPS and has domain transfer protections but lacks DNSSEC and security headers, which are recommended to enhance security posture. No vulnerability disclosures or incident response contacts are published, which could be improved to increase transparency and readiness. No tracking or analytics scripts were detected, indicating minimal user data collection. Overall, the website is professional and trustworthy for its purpose but would benefit from adding privacy and cookie policies, contact information, and enhanced security headers to improve compliance and user trust. The domain registration is appropriate and consistent with the event's nature, supporting legitimacy.

40
50
2
70
52
55
100
conferencedigitalcashblockchaindecentralizedfinanceevent+2 more
ReactNext.jsJavaScriptCSS

Partner Domains:

tixtown.com
partner
nh-hotels.com
partner
2025-09-07T14:12:47.790Z
cashtab.com favicon

Cashtab — The official web wallet for eCash (XEC)

cashtab.com

53
TechnologyN/asmallMEDIUM

Cashtab is an open source, non-custodial web wallet designed for the eCash (XEC) cryptocurrency ecosystem. It offers users a fast and secure way to manage their eCash and eTokens via a web interface and browser extensions for Chrome and Brave. The website positions itself as the official wallet for eCash, targeting cryptocurrency users seeking a reliable and open source wallet solution. The business model centers around providing free, open source wallet software without custodial control, appealing to privacy-conscious users and developers. Technically, the website is built using modern web technologies including React and JavaScript, with a focus on web and browser extension platforms. The site is hosted under a reputable registrar and uses HTTPS for secure communications. However, the site lacks advanced security headers and DNSSEC is not enabled, which are areas for improvement. Performance and mobile optimization are basic but functional, with moderate SEO and accessibility features. From a security perspective, the site demonstrates basic good practices such as HTTPS usage and domain registration protections. However, the absence of privacy and cookie policies, lack of contact information, and missing security headers reduce its compliance and trustworthiness. Google Analytics and Tag Manager are used for user tracking, but no explicit privacy compliance mechanisms are evident. No forms or sensitive data inputs are present on the main page, reducing immediate risk exposure. Overall, Cashtab presents a legitimate and functional cryptocurrency wallet service with a solid domain history and open source transparency. To enhance trust and compliance, the site should implement privacy and cookie policies, improve security headers, and provide clear contact and incident response information. These steps will strengthen its security posture and user confidence.

90
35
2
40
72
75
40
ecashxeccryptocurrencywalletopensource+1 more
ReactJavaScriptCSS
2025-09-07T14:12:42.527Z
potterybarnkids.co.uk favicon

Williams-Sonoma Inc.

potterybarnkids.co.uk

56
RetailUnited KingdomlargeMEDIUM

Pottery Barn Kids UK is a well-established e-commerce retailer specializing in children's and baby furniture, bedding, toys, and home décor. The website is professionally designed and targets parents and caregivers in the UK market. It operates under the parent company Williams-Sonoma Inc., a reputable large enterprise in retail. The site offers a broad catalog with clear navigation and a consistent brand presence, supported by active social media channels. Technically, the website is built on the SuiteCommerce Advanced platform, leveraging modern JavaScript frameworks and integrations such as Google Tag Manager and Searchspring for analytics and search functionality. The site is mobile-optimized with good SEO practices and moderate performance. However, some accessibility features could be improved. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data in its HTML content. While no explicit security headers were detected in the provided data, the overall security posture is solid with no visible vulnerabilities. Privacy compliance is well addressed with clear privacy and cookie policies, though a consent mechanism for cookies is not explicitly implemented. Contact information is limited to a web form, with no direct emails or phone numbers published. The WHOIS data could not be retrieved due to a domain naming rules error, likely caused by querying the subdomain rather than the base domain. Despite this, the website's association with Williams-Sonoma Inc. and its professional presentation support its legitimacy. Strategic recommendations include enhancing security headers, publishing incident response information, and implementing explicit cookie consent to improve compliance and trust.

25
68
2
70
72
30
100
e-commercechildrenfurnituretoysretail+2 more
JavaScriptXMLHttpRequestGoogle Tag ManagerSearchspring+1

Partner Domains:

ehac.fa.us6.oraclecloud.com
partner
2025-09-07T14:11:41.809Z
web3ads.net favicon

Ad Network & Creative Agency in Web3 - web3ads

web3ads.net

62
TechnologyN/asmallMEDIUM

web3ads.net operates as a specialized advertising network and creative agency focused on the Web3 ecosystem, targeting advertisers and publishers seeking innovative marketing solutions in blockchain and decentralized technologies. The website presents a professional and modern design with clear navigation and relevant content describing their services, including advertising, creative agency offerings, referral programs, and media kits. The business appears to be relatively young, founded in 2021, and positioned within the technology and media sectors, catering to a niche market in Web3 advertising. From a technical perspective, the website employs a modern tech stack including HTML5, CSS3, JavaScript, and integrates multiple marketing and analytics tools such as Google Tag Manager, Microsoft Clarity, LinkedIn Insight, Facebook Pixel, and Bing Ads. Hosting and DNS services are managed via Cloudflare, providing performance and security benefits. The site is mobile-optimized and SEO-friendly, though accessibility features are basic. Security posture is adequate with HTTPS enabled and domain transfer protections in place. However, the absence of DNSSEC, security headers, and explicit security policies indicates room for improvement. No privacy or cookie policies were found, which impacts privacy compliance negatively. The extensive use of third-party tracking scripts suggests a moderate to extensive user tracking level, but without clear user consent mechanisms. Overall, the website is legitimate and professionally maintained with a moderate risk profile. Strategic recommendations include implementing comprehensive privacy and cookie policies, enabling DNSSEC, adding security headers, and publishing incident response and vulnerability disclosure information to enhance trust and compliance.

15
58
22
85
75
70
100
web3advertisingcreativeagencyblockchainmarketing
HTML5CSS3JavaScriptGoogle Tag Manager+5
2025-09-07T14:07:10.755Z
afac.com.au favicon

Australasian Fire and Emergency Service Authorities Council (AFAC)

afac.com.au

62
GovernmentAustraliamediumMEDIUM

AFAC (Australasian Fire and Emergency Service Authorities Council) is a key national organization supporting fire and emergency services across Australia and New Zealand. It operates as a member-based non-profit entity focused on enhancing emergency management capabilities through collaboration, training, knowledge sharing, and national coordination. The organization holds a strong market position as a leader in emergency management, providing critical services such as the National Resource Sharing Centre, National Aerial Firefighting Centre, and the Australian Institute for Disaster Resilience. The website reflects a professional and authoritative presence with clear messaging targeted at emergency management professionals and organizations. Technically, the website is built on modern web technologies including React and Next.js, hosted on Azure, and integrates Google Tag Manager and Google Analytics for tracking. The site is well-optimized for performance, mobile responsiveness, and accessibility, demonstrating a mature digital infrastructure. However, there is room for improvement in security headers and privacy compliance mechanisms such as cookie consent. From a security perspective, the site uses HTTPS and shows no signs of exposed sensitive data or vulnerable libraries. The absence of explicit security policies or incident response contacts is a gap that could be addressed to enhance trust and readiness. The domain registration details align well with the organization's profile, supporting legitimacy and trustworthiness. Overall, AFAC's website is a high-quality, professional platform that effectively serves its target audience. Strategic improvements in privacy compliance and security policy transparency would further strengthen its security posture and regulatory alignment.

40
53
10
75
72
65
100
firefightingemergencymanagementbushfiresaustralianewzealand+3 more
ReactNext.jsJavaScriptGoogle Tag Manager+1

Partner Domains:

nafc.org.au
partner
aidr.org.au
partner

+3 more partners

2025-09-07T13:01:27.027Z
macmillan.com favicon

Macmillan Publishers

macmillan.com

61
EducationN/alargeMEDIUM

Macmillan.com represents a major global publishing and education company with a strong market position as part of the Holtzbrinck Publishing Group. The website serves as a portal linking to its three main business units: Macmillan Publishers, Macmillan Learning, and Macmillan Education, each targeting readers, educators, and institutions worldwide. The business model focuses on publishing a wide range of literary genres and providing educational content and tools to improve learning outcomes. Technically, the website employs modern web technologies such as Bootstrap 5 and Popper.js, hosted on AWS infrastructure as indicated by DNS servers. The site is mobile optimized with good design and navigation, though it lacks advanced SEO and accessibility features. No analytics or tracking scripts were detected in the provided HTML, indicating minimal user tracking. From a security perspective, the site uses HTTPS (implied by external CDN links with integrity attributes), but lacks visible security headers and DNSSEC is not enabled. No privacy or cookie policies are present, and no contact or incident response information is provided, which limits compliance with GDPR and best security practices. The domain WHOIS data is consistent with a legitimate, long-established business, enhancing trustworthiness. Overall, the website is professional and safe, but improvements in privacy compliance, security headers, and transparency of contact information are recommended to strengthen security posture and user trust.

15
50
17
80
67
85
100
publishingeducationbookslearningmacmillan
Bootstrap 5Popper.jsJavaScript

Partner Domains:

us.macmillan.com
subsidiary
www.macmillanlearning.com
subsidiary

+1 more partners

2025-09-07T12:59:24.717Z
medicines.org.uk favicon

Datapharm

medicines.org.uk

66
HealthcareUnited KingdommediumMEDIUM

The website www.medicines.org.uk/emc serves as the Electronic Medicines Compendium (emc), a trusted and regulated source of medicines information in the UK. Operated by Datapharm, a leading UK medicines information provider, the platform offers comprehensive, up-to-date prescribing and patient information targeted primarily at healthcare professionals and patients. The business model focuses on providing technology-enabled solutions to support life sciences and healthcare sectors, with a strong market position as a key information provider in the UK healthcare ecosystem. Technically, the website employs modern web technologies including JavaScript frameworks, Google Tag Manager, Microsoft Clarity for analytics, and FingerprintJS for visitor identification. The site is hosted behind Cloudflare, ensuring good performance and security. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS and uses cookie consent mechanisms, but lacks explicit security headers and published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected. The WHOIS data for the subdomain is unavailable due to UK domain naming rules, but the parent domain medicines.org.uk is reputable and consistent with the website's healthcare focus. Overall, the website presents a low-risk profile with strong business credibility and technical maturity. Strategic recommendations include enhancing security headers, publishing a formal security policy and incident response contacts, and establishing a vulnerability disclosure program to further strengthen trust and compliance.

15
83
17
75
90
65
100
healthcaremedicinespharmaceuticalregulatoryuk+2 more
JavaScriptCSSHTML5Google Tag Manager+3

Partner Domains:

www.datapharm.com
partner
yellowcard.mhra.gov.uk
partner

+2 more partners

2025-09-07T12:58:29.489Z
B

Bundesamt für Gesundheit (BAG) - Swiss Federal Office of Public Health

spezialitaetenliste.ch

58
HealthcareSwitzerlandmediumMEDIUM

The website spezialitaetenliste.ch is an official Swiss government platform managed by the Bundesamt für Gesundheit (BAG) that provides authoritative pharmaceutical specialty lists (Spezialitätenliste and Geburtsgebrechen-Spezialitätenliste) for healthcare stakeholders in Switzerland. It serves healthcare professionals, insurers, and pharmaceutical companies by offering searchable databases and downloadable data files related to medication reimbursement and regulation. The site is positioned as a trusted government resource with consistent branding and relevant content. Technically, the website is built on a classic ASP.NET Web Forms framework with JavaScript for interactivity. While functional, the site shows basic mobile optimization and accessibility features, with moderate performance. There is no evidence of modern CMS or advanced SEO techniques. Security-wise, the site uses HTTPS but lacks visible security headers and explicit privacy or cookie policies, which are areas for improvement. The security posture is moderate with no detected vulnerabilities or blocking mechanisms. Contact information is limited to an official email address, with no phone or physical address provided. No tracking or advertising scripts were found, indicating minimal user tracking. Overall, the site is safe, professional, and trustworthy but could enhance privacy compliance and security best practices. Recommendations include implementing comprehensive privacy and cookie policies, adding security headers, improving mobile responsiveness, and providing incident response contacts to strengthen trust and compliance.

15
50
2
70
72
80
100
healthcarepharmaceuticalgovernmentswitzerlandspecialtylist+1 more
ASP.NET Web FormsJavaScript
2025-09-07T12:58:09.051Z
erinstead.com favicon

Erin Stead

erinstead.com

58
RetailUnited StatessmallMEDIUM

Erin Stead's website serves as a professional portfolio and e-commerce platform showcasing the artist's works, primarily children's books and related artwork. The site is hosted on Squarespace, leveraging its platform for content management and online sales. The design is clean, visually appealing, and optimized for mobile devices, providing a good user experience for visitors interested in the artist's offerings. However, the site lacks critical business and privacy information such as contact details, privacy policies, and terms of service, which are important for trust and compliance. Technically, the website uses modern web technologies and benefits from Squarespace's secure hosting environment, including HTTPS with HSTS enabled, ensuring encrypted communication and protection against certain attacks. The absence of additional security headers and explicit privacy compliance measures indicates room for improvement in security posture and regulatory adherence. From a security perspective, the site shows no signs of vulnerabilities or malicious content, but the missing WHOIS registration data raises concerns about domain legitimacy and transparency. This discrepancy suggests either privacy protection or an unregistered domain, which could impact trustworthiness. The lack of contact information and security policies further limits the site's credibility from a security and compliance standpoint. Overall, while the website effectively presents the artist's work and facilitates e-commerce, it should address privacy, contact, and security transparency to enhance trust and compliance. Strategic improvements in these areas will strengthen the site's security posture and business credibility, benefiting both the owner and visitors.

35
35
17
65
62
80
100
portfolioartistauthore-commercechildrensbooks+1 more
SquarespaceJavaScriptCSSHTML5
2025-09-07T11:54:09.152Z
W

Williams-Sonoma, Inc.

williams-sonoma.com

56
RetailN/alargeMEDIUM

Williams-Sonoma, Inc. operates a portfolio of well-known retail brands specializing in home furnishings and kitchenware. The website content indicates a strong retail and e-commerce focus with multiple subsidiary brands. However, the current page content is restricted for visitors from the European Union due to regulatory challenges, limiting accessibility and user engagement in that region. The company provides contact phone numbers for customer support across its brands but lacks visible privacy or cookie policies on this page. Technically, the website uses Bootstrap 4.1.1 for styling and basic JavaScript for functionality. The page is minimal and lacks advanced SEO, accessibility, or performance optimizations. No CMS or hosting provider information is discernible. Security headers and SSL configuration details are not available from the provided data, and no forms or data collection mechanisms are present on this page. From a security perspective, the absence of WHOIS registration data raises concerns about domain transparency, although the branding and contact information suggest legitimacy. The website does not display privacy compliance elements such as GDPR notices or cookie consent banners, which is critical given the region-based access restrictions. Overall, the security posture is limited by the lack of visible security best practices and policies. The overall risk assessment indicates moderate trustworthiness but highlights critical issues related to content blocking, missing WHOIS data, and lack of privacy compliance. Strategic recommendations include improving transparency, implementing comprehensive privacy and cookie policies, enhancing security headers, and ensuring full HTTPS coverage to strengthen user trust and regulatory compliance.

35
50
2
70
72
90
100
retaile-commercehomefurnishingsregionrestrictionprivacycompliance
Bootstrap 4.1.1JavaScript

Partner Domains:

www.westelm.co.uk
partner
www.potterybarnkids.co.uk
partner
2025-09-07T11:53:44.096Z
zentiva.hu favicon

Zentiva Pharma Kft.

zentiva.hu

78
HealthcareHungarylargeLOW

Zentiva Pharma Kft. is a significant player in the Hungarian generic pharmaceutical market, providing high-quality, affordable medicines to patients. The company operates as part of the larger Zentiva Group, with a broad presence across Europe and India. The website reflects a professional business model focused on pharmaceutical manufacturing and distribution, targeting patients and healthcare providers in Hungary. The site content is well-structured, with clear branding and consistent messaging about their role in the healthcare sector. Technically, the website employs modern web technologies including JavaScript libraries, Google Tag Manager for analytics, and Cookiebot for GDPR-compliant cookie consent management. The site is mobile-optimized and uses HTTPS with strong SSL configuration, ensuring secure communications. Accessibility features are basic but present, and SEO practices are adequately implemented. From a security perspective, the site demonstrates good practices such as HTTPS enforcement, CSRF protection cookies, and a comprehensive cookie consent mechanism. However, it lacks explicit security policies or incident response contact information, and security headers are not visibly configured. No critical vulnerabilities or suspicious content were detected. Overall, the website is trustworthy, compliant with GDPR, and professionally maintained. Strategic improvements could include publishing a security policy, adding Terms of Service, and enhancing security headers to further strengthen the security posture.

70
100
17
85
82
85
100
pharmaceuticalhealthcaregenericmedicinescookieconsentgdprcompliant
JavaScriptGoogle Tag ManagerCookiebotModernizr+2

Partner Domains:

zentiva.com
parent
cookiebot.com
partner
2025-09-07T11:47:25.077Z
e.cash favicon

Bitcoin ABC

e.cash

64
FinanceN/amediumMEDIUM

eCash is a cryptocurrency platform focused on providing fast, secure, and scalable digital cash solutions for the internet. The platform offers key services such as staking, non-custodial wallets, token and NFT creation, and blockchain development tools. Positioned as a future-forward decentralized digital cash solution, eCash targets cryptocurrency users, developers, and investors seeking financial freedom and blockchain innovation. The website is professionally designed, mobile-optimized, and integrates with multiple major cryptocurrency exchanges, enhancing its market presence and accessibility. Technically, the site leverages modern web technologies including React and Next.js, ensuring fast performance and good accessibility. Security best practices are observed with HTTPS enforcement and comprehensive security headers, although explicit privacy and cookie policies are absent. The site integrates analytics and marketing tools such as Google Tag Manager and Facebook Pixel, indicating moderate user tracking. From a security perspective, the platform demonstrates a strong posture with no visible vulnerabilities or exposed sensitive data. However, the lack of published incident response contacts, vulnerability disclosure policies, and data protection officer information suggests areas for improvement in transparency and compliance. The WHOIS data is privacy protected, which is common in the cryptocurrency sector, but limits public verification of registrant details. Overall, eCash presents a credible and professional cryptocurrency platform with strong technical and security foundations. Strategic enhancements in privacy compliance, transparency, and formal security policies would further strengthen trust and regulatory alignment.

85
35
2
55
75
80
100
cryptocurrencyblockchaindigitalcashstakingnft+4 more
ReactNext.jsJavaScriptCSS+1

Partner Domains:

cashtab.com
partner
ecashconference.com
partner

+2 more partners

2025-09-07T10:45:05.949Z
swapspace.co favicon

SWAPSPACE LLC

swapspace.co

76
FinanceUnited StatesmediumLOW

SwapSpace operates as a crypto exchange aggregator, providing users with access to offers from over 43 services for cross-chain swaps involving Bitcoin, Ethereum, Metaverse coins, and more than 3500 altcoins. The company positions itself as a time- and cost-saving platform that ranks exchange offers without charging extra fees, targeting cryptocurrency traders and enthusiasts globally. Founded in 2019 and registered in the US, SwapSpace has established a medium-sized presence with a strong brand and user trust, evidenced by a high aggregate rating and active social media channels. Technically, the website leverages modern JavaScript frameworks such as Vue.js and Nuxt.js, ensuring a responsive and performant user experience across web and mobile platforms. Hosting and DNS services are managed via reputable providers including Cloudflare and GoDaddy, with analytics and user behavior tracking implemented through Google Analytics, Hotjar, and Visual Website Optimizer. The site demonstrates good SEO and accessibility practices, contributing to its professional digital maturity. From a security perspective, SwapSpace enforces HTTPS and employs several security headers, although DNSSEC is not enabled, representing an area for improvement. The domain registration uses privacy protection, which is justified given the nature of the crypto industry. No critical vulnerabilities or exposed sensitive data were detected. Privacy and cookie policies are present and include consent mechanisms, aligning with GDPR compliance requirements. Overall, SwapSpace presents a secure, trustworthy, and professionally managed platform with a solid business model and technical foundation. Strategic recommendations include enabling DNSSEC, publishing explicit security and incident response policies, and maintaining vigilance on third-party script security to further enhance trust and compliance.

80
73
25
80
75
90
100
cryptocurrencycryptoexchangeblockchainfinancecryptoswap+4 more
JavaScriptVue.jsNuxt.jsGoogle Analytics+1
2025-09-07T10:44:55.918Z