Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157325
Websites
130
Industries
113
Countries
52
Avg Score
Page 33 of 34|Showing 1601-1650 of 1656
ooegkk.at favicon

Österreichische Gesundheitskasse

ooegkk.at

40
HealthcareAustriaenterpriseHIGH

The Österreichische Gesundheitskasse (ÖGK) operates as a major public health insurance provider in Austria, delivering comprehensive health insurance services and support to insured individuals, employers, and contract partners. The website serves as an official portal offering information, appointment scheduling, customer service, and career opportunities, targeting Austrian residents and stakeholders in the healthcare sector. The digital presence is supported by a modern technology stack including Apache, Jakarta Faces, and jQuery, managed via a Gentics CMS platform, and hosted within the Austrian social insurance infrastructure. Despite a professional and content-rich website, the absence of a valid SSL certificate and HTTPS support significantly undermines the security posture. The site implements a strong Content Security Policy and cookie consent mechanisms, reflecting good privacy compliance, but the lack of HTTPS and TLS protocols is a critical vulnerability. Social media integration and clear contact information enhance trust and user engagement. Overall, the website is functional and credible but requires urgent security improvements to protect user data and comply with modern standards.

50
-
5
50
-
85
100
healthcaresocialinsurancepublicserviceaustriahealthinsurance
ApachejQuery 3.6.0Jakarta Faces (JSF)Slick Carousel+1

Partner Domains:

sozialversicherung.at
partnerpending
meineoegk.at
partnerpending

+1 more partners

2025-06-15T21:53:35.354Z
wgkk.at favicon

Österreichische Gesundheitskasse

wgkk.at

40
HealthcareAustriaenterpriseHIGH

The Österreichische Gesundheitskasse (ÖGK) operates as a major public healthcare insurance provider in Austria, offering a broad range of health-related services and information to insured individuals, employers, and contract partners. The website serves as a comprehensive portal for health facilities, health services, customer support, appointment scheduling, and career opportunities, targeting Austrian residents and stakeholders in the healthcare sector. The organization maintains a consistent and professional online presence with clear branding and trust signals, including official government domain usage and social media engagement. Technically, the website is built on a mature infrastructure utilizing Apache, Jakarta Faces (JSF), jQuery 3.6.0, and Gentics CMS. It integrates advanced features such as a content slider and Piwik PRO analytics for user behavior tracking. However, performance metrics appear incomplete, and the site shows moderate loading characteristics. Accessibility and SEO optimizations are well addressed, with good mobile responsiveness and clear navigation. From a security perspective, the site implements several best practices including a detailed Content-Security-Policy and HttpOnly, Secure cookie flags. Nevertheless, the absence of a valid SSL certificate and HTTPS support is a critical vulnerability, severely impacting the security posture. Other SSL/TLS features such as modern protocol support, OCSP stapling, and session resumption are missing. Privacy compliance is strong, with GDPR-aligned cookie consent mechanisms and clear privacy policies. Overall, the website is trustworthy and professionally managed but requires urgent security improvements to enable HTTPS and strengthen SSL/TLS configurations. Addressing these issues will enhance user trust, data protection, and compliance with modern security standards.

50
-
5
50
-
85
100
healthcarepublicservicegovernmentsocialinsuranceaustria
ApachejQuery 3.6.0Jakarta Faces (JSF)Slick Carousel+1

Partner Domains:

sozvers.at
partnerpending
gesundheitskasse.at
partnerpending

+1 more partners

2025-06-15T21:50:56.149Z
pensionsversicherung.at favicon

PV - Pensionsversicherung Österreich

pensionsversicherung.at

39
GovernmentAustriaenterpriseHIGH

The website pensionsversicherung.at represents the official online presence of the Austrian Pensionsversicherung (PV), the largest pension insurance carrier in Austria, serving approximately 5.6 million insured persons. It provides comprehensive information and services related to pensions, care allowances, rehabilitation, and health prevention. The site is well-structured, professionally designed, and targets insured workers, pensioners, and caregivers in Austria. The business model is that of a government social insurance provider, with a strong market position as a key public institution in Austria's social security system. Technically, the website uses a mature technology stack including Apache server, jQuery 3.6, Jakarta Faces framework, and Piwik PRO for analytics. The content is rich and well-optimized for SEO and accessibility, with good mobile responsiveness. However, performance data is missing, and the site is currently served without a valid SSL certificate, resulting in no HTTPS availability, which is a critical security flaw. From a security perspective, the site implements several security headers including a detailed Content Security Policy and uses secure cookie flags. Despite this, the lack of a valid SSL certificate and absence of modern TLS protocols severely degrade the security posture. No DMARC record is found, and session resumption and OCSP stapling are not enabled. Privacy compliance is strong, with clear privacy and cookie policies and consent mechanisms in place. Overall, the site is trustworthy and authoritative in its domain but must urgently address SSL/TLS issues to ensure secure communications and maintain user trust. Strategic recommendations include obtaining a valid SSL certificate, enabling modern TLS protocols, and enhancing email security with DMARC. The site demonstrates a high level of professionalism and business credibility but is currently limited by its security shortcomings.

50
-
5
50
-
75
100
pensionpflegegeldrehabilitationsozialversicherungaustria+2 more
ApachejQuery 3.6.0Jakarta Faces (JavaServer Faces)Slick Carousel+2
2025-06-15T21:50:11.769Z
I

IT-Services der Sozialversicherung GmbH

itsv.at

39
TechnologyAustriamediumHIGH

IT-Services der Sozialversicherung GmbH (ITSV) is a specialized technology company focused on managing and coordinating IT activities for the Austrian social insurance sector. The company plays a pivotal role in driving digital transformation and efficiency improvements within the healthcare and social insurance ecosystem in Austria. Their key services include IT coordination, digitalization of social insurance services, and SAP support through a dedicated Customer Center of Expertise. The website reflects a professional and consistent brand presence targeting social insurance entities and insured individuals in Austria. Technically, the site uses a modern tech stack including Apache, Jakarta Faces, and jQuery, supported by a Gentics CMS platform. However, performance appears slow and SSL/TLS security is critically lacking, with no valid certificate or secure protocols enabled. Security headers such as Content Security Policy are well implemented, but the absence of HTTPS and TLS protocols represents a significant risk. Privacy compliance is strong, with clear cookie consent mechanisms and a comprehensive privacy policy. Overall, the site is content-rich and trustworthy but requires urgent security improvements to protect user data and maintain trust.

50
-
5
50
-
75
100
technologyhealthcaredigitalizationsocialinsuranceitservices+1 more
ApachejQuery 3.6.0Jakarta FacesPiwik PRO analytics+1

Partner Domains:

sozvers.at
partnerpending
sozialversicherung.at
partnerpending

+1 more partners

2025-06-15T21:49:21.154Z
B

BE Semiconductor Industries N.V.

besi.com

40
TechnologyNetherlandslargeHIGH

BE Semiconductor Industries N.V. (Besi) is a leading technology company specializing in the development and manufacturing of advanced semiconductor assembly equipment and processes. Their product portfolio includes solutions for die attach, packaging, plating, and cleaning, serving diverse markets such as electronics, automotive, industrial, and renewable energy sectors. The website reflects a mature business with a strong investor relations presence and comprehensive corporate governance disclosures, indicating a well-established market position. Technically, the website is built on the TYPO3 CMS platform, utilizing jQuery and Google Tag Manager for analytics and tracking. While the site has a professional design and clear navigation, it lacks a valid SSL certificate, which significantly impacts its security posture. The absence of HTTPS and modern TLS protocols exposes the site to potential risks and undermines user trust. Additionally, no cookie consent mechanism or detailed privacy compliance features are present, which may pose compliance challenges. From a security perspective, the site implements several security headers and restricts device permissions, but the invalid SSL configuration and lack of session resumption or OCSP stapling reduce overall security effectiveness. No incident response or vulnerability disclosure policies are publicly available, limiting transparency in security management. Overall, the website demonstrates solid business credibility and content quality but requires urgent improvements in security infrastructure and privacy compliance to enhance trustworthiness and protect user data effectively.

75
-
5
50
-
85
100
semiconductortechnologymanufacturinginvestor-relationscorporate-governance
jQuery 3.6.0Google Tag ManagerTYPO3 CMS
2025-06-15T21:49:13.493Z
evolaris.net favicon

evolaris next level GmbH

evolaris.net

37
TechnologyAustriasmallHIGH

evolaris next level GmbH is a technology-focused company specializing in mobile communication and digital innovation services. Their website highlights their role as a bridge between science and business, offering digital assistance systems, customized solutions, software engineering, user experience design, and research activities. The company targets enterprises seeking to enhance their digital capabilities and innovation potential. The website is professionally designed, with clear navigation and relevant content, supporting their market position as an established innovation center in Austria. Technically, the website runs on WordPress CMS with common plugins such as NextGEN Gallery and EvoSlider, and uses Apache server hosting likely provided by Hetzner. While the site includes Google Analytics for user tracking, performance metrics are not optimal, and mobile optimization is good. However, a critical technical shortfall is the lack of a valid SSL certificate and HTTPS support, exposing users to security risks. From a security perspective, the site lacks HTTPS, HSTS, and modern TLS protocol support, which are fundamental for secure communications. No advanced security headers or incident response contacts are found. The absence of cookie consent mechanisms and limited privacy policy details indicate partial GDPR compliance. The WHOIS data aligns well with the website's business information, supporting legitimacy. Overall, the website presents a moderate risk profile primarily due to missing HTTPS and security best practices. Strategic improvements in SSL configuration, security headers, and privacy compliance would significantly enhance trust and security posture.

15
18
-
50
-
85
100
technologydigitalinnovationmobilecommunicationsoftwareengineeringuserexperience+1 more
Apache 2.4.62PHP (WordPress 5.8.10)jQuery 3.6.0Google Analytics (MonsterInsights plugin)+5
2025-06-15T21:47:46.729Z
sgkk.at favicon

Österreichische Gesundheitskasse

sgkk.at

40
HealthcareAustrialargeHIGH

The Österreichische Gesundheitskasse (ÖGK) operates as a major public healthcare insurance provider in Austria, offering a broad range of health-related services to insured individuals, employers, and partners. The website serves as an information and service portal, providing access to appointment scheduling, customer service, health information, and career opportunities. The target audience primarily includes Austrian residents and healthcare stakeholders. The organization holds a strong market position as a government-affiliated entity with consistent branding and trust indicators such as official social media presence and comprehensive privacy policies. Technically, the website is built on a custom CMS likely based on Gentics Content Server, utilizing Jakarta Faces (JSF) framework and jQuery 3.6.0. It integrates Piwik PRO for analytics and employs a detailed Content Security Policy. However, the site currently lacks a valid SSL certificate and does not support HTTPS, which significantly impacts its security posture. Performance data is limited but suggests slower load times. Accessibility and SEO optimizations are well implemented. From a security perspective, the absence of HTTPS and modern TLS protocols is a critical vulnerability. While security headers like CSP and HSTS are present, the lack of a valid certificate and secure transport reduces overall security. No explicit incident response or vulnerability disclosure mechanisms are found. Privacy compliance is strong, with clear cookie consent and privacy policies aligned with GDPR. Overall, the website is professional and trustworthy in content and business credibility but requires urgent improvements in SSL/TLS implementation to enhance security and user trust. Strategic recommendations include immediate SSL certificate deployment, enabling modern TLS protocols, and enhancing security header configurations to protect user data and comply with best practices.

50
-
5
50
-
85
100
healthcarepublicservicegovernmentaustriahealthinsurance
ApachejQuery 3.6.0Jakarta Faces (JSF)Slick Carousel+1

Partner Domains:

sozialversicherung.at
partnerpending
meineoegk.at
partnerpending

+2 more partners

2025-06-15T21:47:06.196Z
bcskoolitus.ee favicon

BCS Koolitus AS

bcskoolitus.ee

40
EducationEstoniamediumHIGH

BCS Koolitus AS is a well-established Estonian company specializing in IT training and certification services for both IT specialists and general computer users. The company offers a broad range of courses including Microsoft Office, IT infrastructure management, programming languages, and e-learning platforms. Their market position is strong within Estonia, supported by extensive project experience and recognized quality certifications such as the HAKA quality mark. The website reflects a professional and consistent brand image with detailed service descriptions and active client engagement through testimonials and project showcases. Technically, the site is built on WordPress with modern technologies and includes multilingual support, though performance optimization is needed due to slow load times and large page size. Security posture is generally good with HTTPS and OCSP stapling, but improvements are recommended in DNS and email security configurations. Privacy compliance is basic with cookie consent mechanisms and privacy policies present, but GDPR compliance could be enhanced. Overall, the company demonstrates credible business operations with clear contact information and a moderate level of digital maturity.

15
15
25
70
82
60
100
ittrainingeducatione-learningcertificationestonia
WordPress 6.0.9jQuery 3.6.0Google reCAPTCHA v3Owl Carousel+5

Partner Domains:

thinkific.com
partner60
itcrafters.eu
partnerpending

+1 more partners

2025-06-15T16:55:58.839Z
crediweb.lv favicon

CREDITREFORM Rating SIA

crediweb.lv

40
FinanceLatviamediumHIGH

CrediWeb.lv is a Latvian-based business information platform operated by CREDITREFORM Rating SIA, providing comprehensive credit and business reports for companies primarily in Latvia, Europe, and China. The platform targets businesses and registered users seeking detailed company and private person credit information, offering services such as company reports, family trees, monitoring, and foreign credit reports. The website demonstrates a professional design with consistent branding and clear navigation, supporting multiple languages and user authentication methods including bank link authentication. Technically, the site uses modern JavaScript libraries like jQuery, Flatpickr, Tippy.js, and Chart.js, and integrates Google Tag Manager for analytics. However, the site suffers from critical security shortcomings, notably the absence of a valid SSL certificate and HTTPS support, which severely impacts user security and trust. Privacy and cookie policies are present and GDPR compliant, with consent mechanisms implemented. WHOIS data confirms the domain is actively maintained and consistent with the business's Latvian operations, though domain protection locks are not enabled. Overall, while the business model and content quality are strong, the security posture requires urgent improvement to protect users and enhance credibility.

80
-
25
70
100
50
100
businessinformationcreditreportscompanydatafinancialrisklatvia+1 more
jQuery 3.6.0Flatpickr datepickerTippy.js for tooltipsChart.js for charts+3
2025-06-15T09:57:29.528Z
ivansinsurance.com favicon

Ivans

ivansinsurance.com

69
TechnologyUnited StatesenterpriseMEDIUM

Ivans is a leading technology company specializing in digital insurance software that connects carriers, MGAs, and agencies. Positioned as an industry network, Ivans offers streamlined workflows and connectivity solutions to drive business growth for insurance professionals. The company operates under the parent organization Applied Systems, Inc., and serves primarily the US market with enterprise-level solutions. Their offerings include digital distribution platforms, claims communications, and industry insights, targeting insurance agents and brokers. The website reflects a strong market position with clear branding, comprehensive content, and multiple trust signals such as awards and customer testimonials. Technically, the website employs modern web technologies including jQuery, Bootstrap, and Marketo forms, hosted behind Cloudflare with robust SSL/TLS configurations supporting TLS 1.3 and OCSP stapling. Performance is fast with good mobile optimization and accessibility features. SEO is enhanced by structured data (JSON-LD) and proper meta tags. However, there is room for improvement in security headers (lack of HSTS) and DNS security (no DNSSEC or CAA records). From a security perspective, the site demonstrates good practices with secure cookies, no known SSL vulnerabilities, and no exposed sensitive data. The absence of a cookie consent mechanism and explicit GDPR compliance indicators suggests partial privacy compliance. No security policy or incident response information is publicly available, which could be a gap for enterprise clients. Overall, the security posture is strong but could be enhanced with additional headers and transparency. The overall risk assessment is low with a well-maintained, professional website that supports Ivans' business credibility and digital maturity. Strategic recommendations include implementing cookie consent for privacy compliance, enabling HSTS, adding DNS security records, and publishing security and incident response policies to further build trust and compliance.

20
43
25
50
92
80
100
insurancetechnologysoftwaredigitaldistributioninsuranceconnectivity+4 more
jQuery 3.6.0jQuery UI 1.12.1Bootstrap 4.6.0Marketo Forms+1

Partner Domains:

appliedsystems.com
parent50
2025-06-14T22:32:18.748Z
appliedsystems.com favicon

Applied Systems, Inc.

appliedsystems.com

50
TechnologyUnited StatesenterpriseMEDIUM

Applied Systems, Inc. is a leading enterprise technology company specializing in insurance software and agency management solutions for independent insurance agencies and brokers. The company offers a comprehensive suite of cloud-based products including agency management platforms, marketing automation, digital payments, and business intelligence tools. With a strong market position evidenced by adoption among top insurance brokerages and multiple industry awards, Applied Systems serves a primarily US-based audience with a focus on innovation and digital transformation in the insurance sector. The company was founded in 1983 and operates several subsidiaries such as EZLynx, Ivans, Indio, and Tarmika, enhancing its product ecosystem. Technically, the website employs modern JavaScript libraries like jQuery and Bootstrap, integrates marketing tools such as Marketo Forms, and uses Google Tag Manager for analytics. Hosting is via Cloudflare, but a critical security gap exists due to the absence of a valid SSL certificate and disabled TLS protocols, severely impacting the security posture. The site is well-structured with comprehensive metadata, JSON-LD structured data, and good SEO practices, providing a professional and trustworthy user experience. Security-wise, the lack of HTTPS and TLS support is a major vulnerability, exposing users to risks and undermining trust. While privacy and cookie policies are present and GDPR compliant, no explicit incident response or vulnerability disclosure mechanisms were found. Overall, the site demonstrates strong business credibility and content quality but requires urgent security improvements to meet modern standards and protect user data effectively.

20
43
25
50
50
90
100
insurancetechnologysoftwareagencymanagementcloud+1 more
jQuery 3.6.0Bootstrap 4.6.0Marketo FormsCeros iframe embed+2
2025-06-14T22:27:40.452Z
veteransunited.com favicon

Veterans United Home Loans

veteransunited.com

60
FinanceUnited StateslargeMEDIUM

Veterans United Home Loans is a leading mortgage lender specializing in VA home loans, serving veterans and military families across the United States. The company holds a strong market position as the top VA purchase lender by volume for multiple consecutive years, offering a comprehensive suite of services including VA loans, refinancing, realty, insurance, and credit building. Their website reflects a professional and user-friendly digital presence with extensive educational content, customer reviews, and interactive tools such as mortgage calculators and eligibility forms. Technically, the site leverages a modern JavaScript stack with jQuery, Google Tag Manager, and custom form frameworks, hosted on AWS infrastructure. However, the security posture is currently weak due to the absence of a valid SSL certificate and disabled TLS protocols, which poses a significant risk to user data confidentiality and trust. Privacy policies and cookie consent mechanisms are well implemented, supporting compliance with general privacy standards. Overall, the site demonstrates strong business credibility and digital maturity but requires urgent remediation of its SSL/TLS configuration to ensure secure user interactions.

55
43
17
50
90
90
100
valoansmortgageveteranshomeloansfinance+1 more
PHP 7.4.33jQuery 3.6.0Tiny SliderMoment.js+4

Partner Domains:

mortgageresearchcenter.com
subsidiary53
neighborsbank.com
partner54

+2 more partners

2025-06-14T22:11:25.753Z
vu.com favicon

Veterans United Home Loans

vu.com

67
Real EstateUnited StateslargeMEDIUM

Veterans United Home Loans is a leading mortgage lender specializing in VA home loans, serving veterans and military families across the United States. The company holds the position as the nation's #1 VA lender by volume for multiple consecutive years, demonstrating strong market leadership and trust within its target audience. Their website offers comprehensive services including VA home loans, refinancing options, mortgage calculators, and additional services such as credit building and insurance. The site features extensive customer testimonials and a robust multi-step lead form designed to capture detailed mortgage-related information securely. Technically, the website employs a modern technology stack including jQuery, Formocity forms, and various analytics and tracking tools such as Google Tag Manager and TrustedForm. Hosting is provided via Amazon AWS, ensuring scalability and reliability. While the site is mobile-optimized and accessible with good SEO practices, performance is somewhat slow with a high load time and large page size, indicating potential areas for optimization. From a security perspective, the site uses valid SSL certificates supporting TLS 1.2 and 1.3, but lacks advanced security headers and HSTS enforcement, which are recommended to enhance security posture. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with clear privacy and cookie policies and consent mechanisms in place. Contact information is prominently displayed, enhancing business credibility. Overall, Veterans United Home Loans presents a professional, trustworthy, and secure online presence with minor technical and security improvements recommended to further strengthen their digital maturity and user experience.

55
43
17
50
82
85
100
valoansmortgageveteranshomeloansfinance+1 more
jQuery 3.6.0Formocity form frameworkTiny SliderMoment.js+7

Partner Domains:

neighborsbank.com
partnerpending
mortgageresearchcenter.com
partnerpending

+3 more partners

2025-06-14T22:02:07.083Z
hotelsathome.com favicon

Hotels At Home Worldwide, Inc.

hotelsathome.com

56
HospitalityN/amediumMEDIUM

Hotels At Home Worldwide, Inc. is a global leader in hospitality retail services, specializing in developing and managing branded e-commerce solutions for hotel guests. Their business model focuses on providing turnkey retail programs that include e-commerce technology, concierge-level service, sourcing, creative design, marketing, and logistics. The company serves major hospitality brands worldwide, positioning itself as a key partner in enhancing guest loyalty and brand presence through retail extensions. Technically, the website is built on ASP.NET with jQuery and integrates Google Analytics and Typekit fonts. Hosting is via AWS CloudFront. However, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical security and trust issue. Performance metrics are unavailable, but indications suggest slow loading. Mobile optimization and accessibility are basic but present. From a security perspective, while several security headers are implemented, the absence of HTTPS and modern TLS protocols severely undermines the site's security posture. No incident response or security policy information is available, and cookie consent mechanisms are missing, indicating partial privacy compliance. Overall, the site presents a professional business front with good content and clear contact information but suffers from critical security shortcomings that impact trust and compliance. Strategic improvements in SSL deployment, privacy compliance, and security policies are recommended to enhance the site's security and user trust.

75
43
25
50
50
85
100
hospitalitye-commerceretailbrandedretailguestloyalty+1 more
jQuery 3.6.0Google AnalyticsTypekit FontsASP.NET 4.0.30319
2025-06-14T19:34:20.920Z
ritzcarltonshops.com favicon

The Ritz-Carlton Shops

ritzcarltonshops.com

77
RetailUnited StatesmediumLOW

The Ritz-Carlton Shops website is a premium e-commerce platform offering luxury home products branded under The Ritz-Carlton name, including bedding, linens, fragrances, and exclusive hotel amenities. The site targets luxury consumers and hospitality enthusiasts, leveraging the strong brand equity of The Ritz-Carlton and Marriott. It operates within the retail and hospitality sectors, providing a curated shopping experience aligned with the luxury hotel lifestyle. The business model is focused on direct-to-consumer online sales with integration into Marriott's broader ecosystem. Technically, the website employs a modern technology stack including jQuery, Adobe Launch, Google Tag Manager, Salesforce integrations, and advanced tracking and analytics tools. Hosting is on AWS infrastructure with multiple IPs and a robust DNS setup, though DNSSEC and CAA records are absent. The site is mobile optimized, accessible, and SEO friendly, but performance is somewhat slow due to large page size and resource count. From a security perspective, the site enforces HTTPS with valid SSL certificates, uses DMARC with a reject policy, and has OCSP stapling enabled. However, it lacks DNSSEC and CAA records, and HSTS is not enabled, which are areas for improvement. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with clear policies, cookie consent mechanisms, and GDPR indicators. Overall, the website presents a professional, trustworthy, and secure online presence for The Ritz-Carlton Shops. Strategic recommendations include enhancing DNS security, enabling HSTS, improving performance, and maintaining vigilance on third-party scripts to sustain security and privacy standards.

75
43
25
85
92
85
100
luxurye-commercehospitalityhomedecorritz-carlton+2 more
jQuery 3.6.0Adobe Launch (Adobe DTM)Google Tag ManagerGoogle Analytics (gtag.js)+8

Partner Domains:

marriott.com
partner47
hotelsathome.com
partnerpending
2025-06-14T19:24:56.238Z
banibis.com favicon

banibis GmbH

banibis.com

57
TechnologyAustriasmallMEDIUM

banibis GmbH is a small Austrian technology company specializing in modular ERP software solutions tailored for small and medium-sized enterprises, particularly in the trade and service sectors. Their cloud-based ERP system offers comprehensive features including CRM, project management, purchasing and sales, and accounting, with a strong emphasis on customization and customer-centric support. The company maintains a professional online presence with clear contact information, social media integration, and compliance with GDPR and cookie consent regulations. Technically, the website is built on WordPress using the Divi theme, enhanced with various plugins for performance optimization, analytics, and user interaction. The infrastructure is hosted via domaintechnik.at, with a moderate performance profile and good mobile optimization. However, the absence of a valid SSL certificate and lack of modern TLS protocols represent significant security shortcomings that could impact user trust and data protection. From a security perspective, while the site implements SPF records and avoids common vulnerabilities like Heartbleed and POODLE, the lack of HTTPS and missing DMARC records are critical gaps. No explicit security or incident response policies are publicly available, which may affect the company's security posture and compliance readiness. Overall, banibis GmbH demonstrates a solid business and technical foundation with room for improvement in security practices. Addressing these vulnerabilities will enhance trust, compliance, and user confidence in their digital offerings.

15
43
25
70
75
75
75
erpcloudcrmbusinesssoftwaresmallbusiness+6 more
WordPress 5.9.10Divi Theme 4.22.0jQuery 3.6.0WP Rocket (performance optimization)+9
2025-06-14T18:20:05.651Z
fordheritagevault.com favicon

The Ford Motor Company

fordheritagevault.com

61
TransportationUnited StatesenterpriseMEDIUM

The Ford Heritage Vault website serves as an official digital archive for The Ford Motor Company, showcasing a century-long collection of brochures, photographs, and historical automotive content from 1903 to 2003. It targets automotive enthusiasts, historians, and researchers by providing advanced search and filtering tools to access a rich repository of Ford, Lincoln, Mercury, and Edsel heritage materials. The platform positions itself as an authoritative source for Ford's historical assets, reinforcing brand legacy and customer engagement. Technically, the website is built on Microsoft IIS with ASP.NET backend, leveraging modern JavaScript libraries such as jQuery, Axios, and AOS for enhanced user experience. Hosting appears to be on Amazon AWS infrastructure. While the site demonstrates good mobile optimization and performance, it lacks some modern security configurations such as enabled TLS protocols and HSTS, which are critical for secure communications. From a security perspective, the site employs a valid GlobalSign SSL certificate and anti-clickjacking measures but does not enable modern TLS versions or security headers like Content-Security-Policy. No explicit security or incident response policies are published, and no vulnerability disclosure or security.txt files are found. Privacy policies and terms of service are linked to official Ford corporate domains, indicating compliance with GDPR and other regulations. Overall, the website is professionally designed with consistent branding and trustworthy content. However, security posture can be improved by enabling modern TLS protocols, implementing HSTS, and adding comprehensive security headers. Enhancing accessibility and cookie consent mechanisms would also strengthen compliance and user trust.

15
43
9
75
80
85
100
fordheritagearchiveautomotivebrochures+5 more
ASP.NETMicrosoft-IIS/10.0jQuery 3.6.0FontAwesome+7
2025-06-14T13:02:55.547Z
eversign.com favicon

Xodo

eversign.com

73
Electronic Signature / Business ApplicationNot explicitly statedmediumMEDIUM

The website currently exhibits a moderate to low overall security posture, with critical issues notably absent but several high and medium severity vulnerabilities present. Key deficiencies exist in security header implementations, GDPR compliance, and adherence to NIS2 regulatory frameworks, indicating significant gaps in both technical and organizational security controls. The absence of fundamental headers such as Strict-Transport-Security and Content-Security-Policy increases risk exposure to common web attacks like man-in-the-middle and cross-site scripting. GDPR-related shortcomings, including lack of a cookie consent banner and incomplete privacy policies, expose the business to regulatory penalties and undermine customer trust. The failure to establish an information security framework, incident response procedures, and security documentation highlights weaknesses in governance and risk management. However, strengths are noted in email security, SSL/TLS configurations, DNS health, and network security, which provide a solid foundation for secure communications and infrastructure. Addressing the highlighted issues will substantially reduce risk, improve compliance, and safeguard brand reputation. Immediate focus on regulatory compliance and security policy development is crucial for sustainable business operations.

30
58
25
100
85
90
100
eSignaturedigital signaturesbusiness applicationonline signingdocument automation+1 more
256-bit SSL encryptionjQuery 3.6.0Google Tag ManagerGoogle Consent Mode+8

Partner Domains:

xodo.com
subsidiaryanalyzing...
2025-06-13T21:34:53.118Z