Skip to main content

High-risk security reports

Browse 46,998 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157371
Websites
130
Industries
113
Countries
52
Avg Score
Page 331 of 940|Showing 16501-16550 of 46998
hfsjg.ch favicon

High Altitude Research Stations Jungfraujoch and Gornergrat

hfsjg.ch

49
EducationSwitzerlandsmallHIGH

The High Altitude Research Stations Jungfraujoch and Gornergrat operate as a Swiss international foundation dedicated to supporting scientific research at high altitude locations. The foundation provides infrastructure and facilitates research projects primarily in the fields of atmospheric, environmental, and astronomical sciences. Their market position is specialized and niche, serving academic and research communities with unique facilities. The website reflects a professional and consistent brand image, targeting researchers and scientific institutions. Technically, the website is built on WordPress 6.4.7 with modern JavaScript libraries such as jQuery 3.7.1 and uses optimization plugins like Autoptimize. The site demonstrates moderate performance and good mobile optimization, with basic accessibility and SEO practices in place. However, there is room for improvement in security headers and cookie consent mechanisms. From a security perspective, the site enforces HTTPS and uses nonce tokens for AJAX requests, indicating some security awareness. However, the absence of explicit security headers and published security policies limits the overall security posture. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is partial, with a privacy policy present but lacking cookie consent mechanisms. Overall, the website is trustworthy and professionally maintained, with a strong legitimacy score based on WHOIS data and business consistency. Strategic recommendations include implementing cookie consent, enhancing security headers, publishing incident response policies, and maintaining regular updates to WordPress and plugins to ensure ongoing security and compliance.

15
50
2
65
72
85
20
researchsciencehighaltitudefoundationswitzerland+2 more
jQuery 3.7.1WordPress 6.4.7PHP (implied by WordPress)Autoptimize plugin for CSS and JS optimization
2025-10-08T21:44:51.700Z
bolden.nl favicon

Bolden

bolden.nl

43
MediaNetherlandssmallHIGH

Bolden is an independent creative agency based in Amsterdam, specializing in brand strategy, brand identity, digital experiences, and e-commerce design since 2010. The company has established a strong market position with multiple industry awards such as the FONK150 Best Small Design Agency. Their target audience includes brands and businesses seeking professional digital and branding services. The website reflects a high level of professionalism, excellent design quality, and clear navigation, supporting their market reputation. Technically, the website employs modern web technologies including JavaScript ES modules, lazy loading with Lozad.js, and Google Analytics with IP anonymization, indicating a mature digital infrastructure. The site is mobile-optimized and performs well, with good SEO and accessibility features. However, the CMS and hosting provider are not explicitly identified. From a security perspective, the site uses HTTPS with strong SSL configuration and includes standard security headers. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is partial; while a privacy policy and terms of service exist (in Dutch), there is no cookie consent mechanism or explicit GDPR compliance details. Incident response and security policy pages are absent. Overall, the website presents a low risk profile with strong business credibility and technical implementation. Strategic improvements in privacy compliance and security transparency would enhance trust and regulatory adherence.

65
10
2
70
-
75
40
digitaldesignwebdesignbrandingagency+5 more
JavaScript ES ModulesGoogle Analytics (gtag.js)Lozad.js (lazy loading)SVG graphics+1
2025-10-08T21:44:26.647Z
S

SofaSurfer

sofasurfer.org

48
TechnologySwitzerlandsmallHIGH

SofaSurfer.org is a personal portfolio and blog website operated by Kilian Bohnenblust, a digital artist and web developer active since 1999. The site showcases various web development projects and digital art, targeting digital art enthusiasts and potential clients seeking web design and development services. The business model is that of a freelance or individual professional offering services and sharing knowledge through a blog. The website is hosted on Hostpoint AG infrastructure and uses modern web technologies including jQuery, Masonry.js, and Piwik/Matomo analytics. The site is mobile optimized and has good SEO practices, although accessibility features are basic. From a security perspective, the website uses HTTPS with a good SSL configuration but lacks DNSSEC and security headers such as Content-Security-Policy or X-Frame-Options. No sensitive data exposure or vulnerable libraries were detected. Privacy compliance is partial; a privacy policy is present but no cookie consent mechanism is implemented. Contact information is minimal, with no explicit emails or phone numbers provided on the homepage, which may impact user trust and compliance. Overall, the website presents a moderate security posture with room for improvement in privacy compliance and security headers. The domain is long-standing and consistent with the claimed business history, enhancing trustworthiness. The site content is safe for general audiences with no adult or questionable material detected.

15
53
2
70
90
60
20
digitalartwebdevelopmentportfolioblogtechnology
jQueryMasonry.jsVanilla LazyLoadGoogle Code Prettify+1
2025-10-08T21:41:25.942Z
fidoalliance.org favicon

FIDO Alliance

fidoalliance.org

49
TechnologyUnited StatesmediumHIGH

FIDO Alliance is a well-established non-profit organization founded in 2011, dedicated to developing and promoting open authentication standards to reduce reliance on passwords globally. The organization holds a strong market position as a leader in passwordless authentication technologies, serving technology companies, developers, and enterprises. Their key services include standard development, certification programs, and fostering industry collaboration. The website reflects a professional and consistent brand image with good content quality and clear messaging focused on authentication standards. Technically, the website is built on WordPress with modern technologies such as jQuery, Google reCAPTCHA, and Google Tag Manager. It is hosted with Cloudflare DNS services, ensuring good performance and security. The site implements cookie consent mechanisms and uses SEO best practices, although accessibility features could be improved. The technical infrastructure supports a moderate to good user experience with mobile optimization. From a security perspective, the site enforces HTTPS, uses security headers, and integrates CAPTCHA for form protection. However, it lacks publicly available security policies, incident response contacts, and vulnerability disclosure mechanisms such as security.txt. No critical vulnerabilities or exposed sensitive data were detected. The domain registration data aligns well with the organization's history, supporting legitimacy and trust. Overall, the website presents a low-risk profile with strong business credibility and a solid security posture. Strategic improvements include publishing comprehensive privacy and security policies, enabling DNSSEC, and enhancing accessibility and compliance transparency.

-
-
-
75
62
75
100
authenticationsecuritypasswordlessfidotechnology+2 more
WordPressjQueryGoogle reCAPTCHAGoogle Tag Manager+2
2025-10-08T20:38:02.521Z
digitalidentity.nz favicon

Digital Identity New Zealand

digitalidentity.nz

49
TechnologyNew ZealandsmallHIGH

Digital Identity New Zealand is a membership-funded organization established in 2018, focused on advancing digital identity and trust ecosystems within New Zealand. The organization provides a platform for collaboration, knowledge sharing, and advocacy through events such as the Digital Trust Hui Taumata, working groups, and educational resources. Their market position is that of a leading entity in the digital identity space in New Zealand, targeting businesses and organizations interested in digital identity innovation and trust economy development. Technically, the website is built on WordPress with modern frameworks like Bootstrap and uses common libraries such as jQuery and Owl Carousel. It integrates Google Tag Manager and Facebook Pixel for analytics and marketing. The site demonstrates moderate performance and good mobile optimization, with basic accessibility features and good SEO practices. From a security perspective, the site uses HTTPS and secure login forms but lacks DNSSEC and important security headers, which are recommended for enhanced protection. Privacy compliance is partial, with a privacy policy present but located at an unusual URL and no cookie consent mechanism detected. No incident response or security policy documents are published. Overall, the website is professional and trustworthy with a good business credibility score. However, improvements in privacy compliance, security headers, and DNS security would strengthen its security posture and regulatory adherence.

15
53
2
75
62
65
40
digitalidentitynewzealandtechnologymembershiptrust+2 more
WordPressjQueryBootstrapOwl Carousel+3

Partner Domains:

digitaltrusthui.co.nz
partner
techalliance.nz
partner
2025-10-08T20:37:52.494Z
ndstudio.gov favicon

Cybersecurity and Infrastructure Security Agency

ndstudio.gov

44
GovernmentRedacted For PrivacymediumHIGH

The National Design Studio website represents an official U.S. government initiative led by the Cybersecurity and Infrastructure Security Agency. It focuses on modernizing government interfaces and improving citizen experiences through the America by Design initiative. The site is positioned as a government entity with a clear mission and target audience of American citizens and government service users. The business model is non-commercial, centered on public service and design innovation within government frameworks. Technically, the website employs modern web technologies including Next.js and React, hosted and secured via Cloudflare services. Performance and mobile optimization are good, with a clean and professional design. However, accessibility features are basic and could be improved. The site uses Cloudflare Turnstile for bot protection but lacks DNSSEC and some security headers. From a security perspective, the site benefits from HTTPS and Cloudflare protections but lacks published privacy, cookie, and security policies. No contact information for incident response or data protection officers is provided. The domain WHOIS data aligns well with the government entity, showing consistency and legitimacy. No vulnerabilities or malicious content were detected, but enabling DNSSEC and publishing security policies would enhance trust. Overall, the website is trustworthy and professional but could improve privacy compliance and security transparency. Strategic recommendations include enabling DNSSEC, publishing privacy and cookie policies, adding security headers, and providing clear contact channels for security incidents.

15
35
2
40
-
80
100
governmentdesignusgovamericabydesignnationaldesignstudio
Next.jsReactCloudflare DNS and hostingCloudflare Turnstile (captcha)+1
2025-10-08T20:37:21.535Z
nicolepfister.ch favicon

Nicole Pfister

nicolepfister.ch

46
MediaSwitzerlandsmallHIGH

Nicole Pfister's website serves as a portfolio platform showcasing her work as a filmmaker, illustrator, art director, and photographer. The site targets a general audience interested in creative media and artistic projects. The business operates as a small independent creative professional entity based in Switzerland, focusing on visual and media arts. The website content is primarily image-based, highlighting various projects without extensive textual content or interactive features. Technically, the website is built with basic HTML and CSS, lacking modern frameworks, CMS, or advanced scripting. There are no detected analytics, tracking, or advertising technologies, indicating a minimalistic digital footprint. Mobile optimization and accessibility are basic, and SEO practices are minimal but present through meta tags. Performance is moderate given the image-heavy content. From a security perspective, the site lacks visible security headers and does not provide privacy or cookie policies, which are important for GDPR compliance. No forms or data collection mechanisms are present, reducing some risk vectors. The WHOIS data aligns well with the website content, showing consistency and legitimacy. However, the absence of HTTPS confirmation and security best practices lowers the security posture. Overall, the website is a straightforward portfolio with moderate technical maturity and limited security measures. Strategic improvements in security headers, HTTPS enforcement, and privacy compliance would enhance trust and protection for visitors.

15
50
2
70
72
75
20
portfoliofilmmakerillustratorartdirectorphotographer+2 more
HTMLCSS
2025-10-08T20:36:05.116Z
deinmagazin.ch favicon

deinmagazin.ch

deinmagazin.ch

49
TechnologySwitzerlandsmallHIGH

deinmagazin.ch operates as a specialized online editorial system platform designed to facilitate the creation and publication of digital magazines. The service targets organizations and businesses seeking flexible, multi-device optimized digital magazine solutions, positioning itself as a niche SaaS provider within the technology sector in Switzerland. The website presents a professional and consistent brand image with clear navigation and relevant content describing its offerings. Technically, the website employs modern web technologies including Google Tag Manager, Google Analytics, and Vimeo for video embedding. The site is mobile optimized and demonstrates good SEO practices. However, no explicit CMS or hosting provider details are evident. Performance is moderate with room for improvement in accessibility and security headers. From a security perspective, the site enforces HTTPS and includes cookie consent mechanisms, indicating basic compliance with privacy regulations such as GDPR. However, there is a lack of visible security policies, incident response contacts, or vulnerability disclosure information. No critical vulnerabilities or exposed sensitive data were detected, but security headers could be enhanced to improve the security posture. Overall, deinmagazin.ch presents a trustworthy and professional online presence with a solid foundation in privacy compliance and technical implementation. Strategic improvements in security transparency and contact information disclosure would further strengthen its risk profile and user trust.

15
68
2
70
72
80
-
onlinemagazineeditorialsystemdigitalpublishingsaasswitzerland
Google Tag ManagerGoogle AnalyticsVimeo embedGoogle Fonts (Montserrat)+1
2025-10-08T20:34:49.415Z
medhyg.ch favicon

Coopérative Médecine et Hygiène

medhyg.ch

49
HealthcareSwitzerlandmediumHIGH

Médecine et Hygiène is a well-established cooperative media group based in Switzerland, specializing in health information for both professionals and the general public in the French-speaking region. The group operates several complementary brands including a leading medical journal, a public health media outlet, a specialized publisher, and a communication service provider. Their market position is strong as the number one health information group in their region, supported by professional editorial boards and a clear business focus. Technically, the website is built on the eZ Platform CMS powered by Netgen, utilizing modern web technologies and standard analytics tools such as Google Analytics and Google Tag Manager. The site is mobile optimized and well-structured, though some accessibility features could be improved. Performance is moderate with good SEO practices evident. From a security perspective, the site uses HTTPS and does not expose sensitive data or vulnerable libraries. However, it lacks visible security headers and published security or incident response policies. Privacy compliance is weak due to the absence of privacy and cookie policies or consent mechanisms. No vulnerability disclosure or security.txt files are present. Overall, the website is professional and trustworthy with good business credibility but requires improvements in privacy compliance and security best practices to enhance user trust and regulatory adherence.

15
35
2
70
67
85
40
healthcaremediapublishingmedicalswitzerland+1 more
Google AnalyticsGoogle Tag ManagerJW Player

Partner Domains:

planetesante.ch
partner
revmed.ch
partner

+2 more partners

2025-10-08T20:33:33.927Z
science-et-cite.ch favicon

Stiftung Science et Cité

science-et-cite.ch

49
EducationSwitzerlandsmallHIGH

Stiftung Science et Cité is a Swiss non-profit foundation dedicated to fostering dialogue between science and society through various projects including citizen science, educational initiatives, and public events. The organization targets a broad audience including the general public, children, and youth, positioning itself as a key player in science communication within Switzerland. The website reflects a professional and consistent brand image with comprehensive content and multilingual support. Technically, the website is built on TYPO3 CMS and leverages modern JavaScript libraries such as jQuery, Tobii lightbox, and Plyr for media handling. Google Analytics is used with IP anonymization to track user engagement. The site is mobile-optimized, accessible, and SEO-friendly, though performance is moderate. No hosting provider details were identified. From a security perspective, the site uses HTTPS with good SSL configuration and secure form handling via Mailchimp. However, it lacks explicit security headers and formal security or incident response policies. Privacy compliance is addressed with a comprehensive privacy and cookie policy, though no explicit cookie consent mechanism is present. Contact information is clearly provided, enhancing business credibility. Overall, the website is trustworthy, professionally maintained, and aligned with the foundation's mission. Security posture is adequate but could be improved with additional headers and policies. Privacy compliance is good but could benefit from explicit consent mechanisms. No critical vulnerabilities or suspicious elements were detected.

30
53
2
70
72
80
-
scienceeducationnon-profitsciencecommunicationcitizenscience+1 more
TYPO3 CMSjQuery 3.7.1Google Analytics (gtag.js)Tobii lightbox+1
2025-10-08T19:24:41.877Z
outline4.ch favicon

outline4

outline4.ch

41
TechnologySwitzerlandsmallHIGH

outline4 is a small, specialized web design agency based in Bern, Switzerland, founded in 2003. The company focuses on creating beautiful, user-friendly, and responsive websites with a strong emphasis on CMS solutions such as Craft CMS and Expressionengine, as well as SEO optimization. They maintain a local market presence with partnerships with other Bern-based agencies and offer a portfolio of diverse web design projects. The website is well-structured, professionally designed, and optimized for mobile devices, reflecting a mature digital presence. Technically, the website uses a modern albeit slightly outdated technology stack including jQuery 1.11.1, Modernizr for SVG detection, and Google Analytics for tracking. The site is served over HTTPS with no visible security issues in the HTML content. However, there is a lack of security headers and the use of an outdated jQuery version poses a potential security risk. The site does not implement privacy or cookie policies, which is a compliance gap especially under GDPR regulations. From a security perspective, the site demonstrates good baseline practices such as HTTPS and no exposed sensitive data, but lacks advanced security headers and incident response information. No forms are present, reducing attack surface. The WHOIS data is consistent with the business claims, showing a domain age appropriate for the company's founding date and no privacy protection, which is suitable for this type of business. Overall, the website is professional, trustworthy, and safe for general audiences. Strategic improvements in privacy compliance, security headers, and updating JavaScript libraries would enhance the security posture and regulatory compliance. The business is credible and well-positioned locally with a clear service offering and partner ecosystem.

15
35
2
55
72
65
-
webdesignresponsivewebdesigncmsseoe-commerce+2 more
jQuery 1.11.1Modernizr (SVG detection)Google Analytics (gtag.js)Colorbox (lightbox plugin)+3

Partner Domains:

achtung.ch
partner
efentwell.ch
partner

+3 more partners

2025-10-08T19:21:30.481Z
teachcyber.org favicon

Teach Cyber

teachcyber.org

45
EducationN/asmallHIGH

Teach Cyber is a specialized non-profit organization focused on empowering high school instructors to deliver cybersecurity curricula. The organization provides a comprehensive suite of educational resources, including curriculum frameworks, professional development courses, teaching modules, and assessment tools. Their market position is that of a niche educational resource provider dedicated to secondary cybersecurity education, supported by partnerships and a clear mission to enhance cybersecurity literacy at the secondary level. Technically, the website is built on a modern WordPress platform using Elementor and WooCommerce for content management and e-commerce capabilities. The site employs Google reCAPTCHA v2 for form security and is hosted by Bluehost Inc. Performance and mobile optimization are good, though some accessibility features are basic. SEO practices are adequately implemented with proper meta tags and structured content. From a security perspective, the site benefits from HTTPS encryption and domain transfer protection but lacks DNSSEC and explicit security headers, which are recommended for enhanced security. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism or GDPR compliance indicators. Incident response and vulnerability disclosure information are absent, representing an area for improvement. Overall, the website is trustworthy and professional, with a strong focus on educational content and community engagement. The risk profile is low, but improvements in security headers, privacy compliance, and incident response transparency would strengthen the security posture and regulatory adherence.

15
58
47
70
-
70
20
educationcybersecuritynon-profitteachingcurriculum+1 more
WordPressWooCommerceElementorjQuery+2

Partner Domains:

cybersupply.org
partner
2025-10-08T18:20:59.394Z
mfe-standpunkte.ch favicon

mfe Haus- und Kinderärzte Schweiz

mfe-standpunkte.ch

49
HealthcareSwitzerlandsmallHIGH

The website mfe-standpunkte.ch serves as the official online magazine for mfe Haus- und Kinderärzte Schweiz, a professional association representing general practitioners and pediatricians in Switzerland. It provides timely articles, policy updates, and resources aimed at healthcare professionals within this niche. The site offers downloadable content such as PDFs and e-books and supports user engagement through newsletter subscriptions and social media channels. The content is well-curated, relevant, and professionally presented, targeting medical practitioners concerned with healthcare provision and policy in Switzerland. Technically, the website employs modern web technologies including Google Analytics for traffic analysis, Bootstrap for responsive design, and custom JavaScript for interactive features. The site is hosted securely with HTTPS and includes secure forms with CSRF protection. While the site lacks explicit security headers and a published security policy, it demonstrates good baseline security practices and moderate performance with good mobile optimization. From a security and compliance perspective, the site includes a privacy policy and cookie consent banner compliant with GDPR principles. However, it lacks a formal security policy, incident response contact, and vulnerability disclosure mechanisms. WHOIS data confirms the legitimacy of the domain registration, matching the business entity and location, enhancing trustworthiness. Overall, mfe-standpunkte.ch is a credible, professionally maintained healthcare publication with solid technical and security foundations. Strategic improvements in security transparency and policy publication would further enhance its trust and compliance posture.

15
68
2
70
72
80
-
healthcaremedicalmagazineswissdoctors+2 more
Google AnalyticsjQuery (implied by carousel and fancybox usage)Fancybox (lightbox)Custom CSS and JS

Partner Domains:

www.hausaerzteschweiz.ch
partner
www.deinmagazin.ch
partner
2025-10-08T18:18:58.908Z
static2dynamic.ch favicon

FBIS

static2dynamic.ch

39
TechnologySwitzerlandsmallHIGH

FBIS operates the static2dynamic.ch website, offering a PHP-based Web Application Framework designed as a licensing-free alternative to traditional CMS platforms like TYPO3 and Joomla. With over 20 years of experience, the company targets a broad audience including individuals and agencies seeking flexible web solutions. The website is professionally designed, content-rich, and provides clear navigation and contact information, reflecting a small but established technology business based in Switzerland. Technically, the site leverages a proprietary PHP framework (static2dynamic 5.9), standard web technologies (JavaScript, CSS), and includes modern features such as responsive design and cookie consent mechanisms. While performance is moderate and mobile optimization is good, there is room for improvement in accessibility and security headers. No major vulnerabilities or exposed sensitive data were detected. Security posture is adequate with cookie consent implemented and no visible security flaws, but lacks explicit security policies or incident response information. WHOIS data confirms domain legitimacy and consistency with business claims. Privacy compliance is supported by a privacy policy and cookie banner, though terms of service and vulnerability disclosure policies are absent. Overall, the website presents a trustworthy and professional front for a niche technology provider. Strategic improvements in security headers, incident response transparency, and accessibility would enhance the security posture and user trust.

15
68
2
70
-
75
-
webapplicationframeworkphpcmsopensourcecmscmsalternativestatic2dynamic+2 more
PHPJavaScriptCSSHTML5
2025-10-08T18:13:12.412Z
solemar.de favicon

Kur- und Bäder GmbH Bad Dürrheim

solemar.de

47
HospitalityGermanymediumHIGH

Kur- und Bäder GmbH Bad Dürrheim operates the Solemar wellness and spa center located in Bad Dürrheim, Germany. The website presents a professional and comprehensive digital presence showcasing their wellness services including the Sole-Therme, Schwarzwald-Sauna, Totes-Meer-Salzgrotte, and WellnessCenter. The company targets general wellness and spa visitors, positioning itself as a regional leader in hospitality and health tourism. The site includes detailed information on services, events, and visitor information, supported by certifications such as ISO 9001 and Wellness Stars, enhancing trust and credibility. Technically, the website is built on WordPress with modern plugins for SEO (Yoast), cookie consent (Borlabs Cookie), and user experience enhancements. The site is mobile-optimized, accessible, and SEO-friendly, with a moderate performance profile. Hosting is via a commercial provider consistent with the domain's WHOIS data. Privacy compliance is well addressed with clear policies and consent mechanisms. Security posture is solid with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. However, the site lacks explicit security policies or incident response contacts, which could be improved. No WAF or blocking mechanisms are detected, allowing full content access. Overall, the site is trustworthy, professional, and compliant with relevant regulations. Strategic recommendations include enhancing security headers, publishing a security policy, and adding a vulnerability disclosure mechanism to further strengthen security and compliance posture.

30
55
2
70
77
60
-
wellnessspatourismhealthgermany+2 more
WordPressYoast SEO pluginBorlabs Cookie pluginjQuery+3

Partner Domains:

kurundbaeder.de
partner
bad-duerrheim.info
partner

+3 more partners

2025-10-08T17:11:50.115Z