Skip to main content

High-risk security reports

Browse 46,998 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157371
Websites
130
Industries
113
Countries
52
Avg Score
Page 335 of 940|Showing 16701-16750 of 46998
insurekidsnow.gov favicon

Centers for Medicare & Medicaid Services

insurekidsnow.gov

39
GovernmentUnited StateslargeHIGH

InsureKidsNow.gov is an official U.S. government website managed by the Centers for Medicare & Medicaid Services (CMS), providing comprehensive information and resources about Medicaid and the Children's Health Insurance Program (CHIP) for children and teens. The site targets parents and caregivers seeking free or low-cost health and dental coverage options, offering tools such as a dentist locator, outreach materials, and mental health resources. It holds a strong market position as a trusted government resource with authoritative content and consistent branding. Technically, the website is built on Drupal 10 with integration of modern frameworks like Bootstrap and USWDS, ensuring mobile responsiveness, accessibility, and good SEO practices. The site uses various analytics and performance monitoring tools such as Tealium and Boomerang, and loads content securely over HTTPS. While the site lacks explicit cookie consent mechanisms and some security headers, it follows best practices for secure forms and data handling. From a security perspective, the site benefits from the inherent trust of the .gov domain and HTTPS encryption. No vulnerabilities or exposed sensitive data were detected in the content. However, improvements could be made by adding security headers, publishing a vulnerability disclosure policy, and providing incident response contacts. The WHOIS data is not publicly available, consistent with .gov domain privacy policies, but the domain expiry and usage align with legitimate government operations. Overall, InsureKidsNow.gov demonstrates a high level of professionalism, trustworthiness, and compliance with privacy standards. It effectively serves its mission to inform and assist families in accessing health coverage for children, with a solid technical foundation and secure environment.

65
58
2
-
-
-
100
governmenthealthcaremedicaidchipchildren+4 more
Drupal 10Bootstrap 4.3.1jQuery 3.7.1Popper.js+5

Partner Domains:

medicaid.gov
partner
www.hhs.gov
partner

+3 more partners

2025-10-08T06:13:00.080Z
providata.de favicon

providata

providata.de

41
EnergyGermanymediumHIGH

providata GmbH is a medium-sized German company specializing in process and data management solutions for the energy sector. With over 30 years of experience and strong partnerships with regional energy companies such as Thüga, badenova, and WEMAG, providata offers a comprehensive portfolio of services including billing, energy data management, customer service, and robotic process automation. The company positions itself as an innovative and reliable partner for energy providers and heat suppliers, emphasizing sustainable and efficient energy management solutions. The website reflects a professional and modern digital presence, optimized for SEO and mobile devices, and includes active news updates and certifications that enhance trust. Technically, the website is built on WordPress with modern plugins such as Yoast SEO and a cookie management system from Digitale Werke, ensuring compliance with GDPR and user privacy. The site is fast, accessible, and well-structured, with no detected blocking or security challenges. Security posture is good with HTTPS enforced and cookie consent implemented, though some security headers and explicit incident response policies are absent. Contact information is comprehensive, including multiple phone numbers, email, physical addresses, and social media channels. Overall, providata demonstrates a mature digital infrastructure and a strong market position in the energy sector. Security and privacy compliance are well addressed, though improvements could be made by publishing incident response and vulnerability disclosure policies. The domain registration data aligns well with the company's claims, supporting legitimacy and trustworthiness.

15
40
2
70
57
60
-
energysoftwareprocessmanagementb2biso9001+3 more
WordPress 6.7.1Yoast SEO pluginSwiper.js (for sliders)Digitale Werke Cookie Manager+2

Partner Domains:

thuega-solutions.de
partner
2025-10-08T05:09:58.187Z
conword.io favicon

conword.io - Webseitenübersetzungen in Echtzeit

conword.io

47
TechnologyGermanysmallHIGH

Conword.io is a German-based technology company specializing in real-time website translation services. Their core offering enables website operators, especially in the public sector and large organizations, to easily integrate a language selector that translates content into up to 33 languages automatically and in compliance with GDPR. The company positions itself as a privacy-focused alternative to global translation widgets, emphasizing data protection and ease of integration via a simple JavaScript snippet. Their market presence is supported by partnerships with recognized entities such as DeepL and references from multiple German municipalities. Technically, the website is built on a modern WordPress CMS platform using Elementor and various contemporary JavaScript libraries. The site is well-optimized for performance, mobile responsiveness, and SEO, with clear navigation and professional design. Security practices include HTTPS enforcement and SSL encryption, though some improvements are recommended in security headers and incident response transparency. From a security and compliance perspective, Conword.io demonstrates strong GDPR adherence and data protection focus, but lacks explicit cookie consent mechanisms and published vulnerability disclosure policies. The domain registration is privacy protected but consistent with the business profile and age. Overall, the website and business exhibit a high level of professionalism and trustworthiness. Strategically, Conword.io should enhance its security posture by implementing security headers, publishing incident response and vulnerability disclosure policies, and adding cookie consent mechanisms to fully comply with EU regulations and improve user trust.

15
70
2
55
72
75
-
translationmultilingualgdprwebsitetechnology+3 more
WordPress 6.8.3Elementor 3.30.3Yoast SEO pluginGoogle Tag Manager+7

Partner Domains:

www.benefit-consult.de
partner
www.deepl.com
partner

+3 more partners

2025-10-08T01:40:44.367Z
P

Potential Health Development

phd-health.com

46
HealthcareIndiasmallHIGH

Potential Health Development is a small healthcare service provider specializing in health and performance optimization through personalized diagnostics, fitness, nutrition, and lifestyle programs. Their website presents a professional and consistent brand image targeting health-conscious individuals seeking advanced health services. The company maintains partnerships with multiple healthcare-related organizations, enhancing its market position. Technically, the website uses standard web technologies including HTML5, CSS, JavaScript, and jQuery, with Google Analytics for user tracking. The site is mobile optimized and offers a moderate performance experience. However, it lacks advanced SEO and accessibility features and does not use a CMS or modern frameworks. From a security perspective, the site uses HTTPS but lacks visible security headers and privacy/cookie policies, indicating compliance gaps and potential vulnerabilities. Forms are present but lack anti-bot protections. The WHOIS data aligns well with the business claims, supporting domain legitimacy. Overall, the website is functional and professional but requires improvements in privacy compliance, security best practices, and transparency to enhance trust and reduce risk.

15
35
2
85
62
75
20
healthperformanceoptimizationnutritionfitnesspersonalizedhealth+4 more
HTML5CSSJavaScriptjQuery+1

Partner Domains:

primagenics.com
partner
rejoov.in
partner

+3 more partners

2025-10-08T00:32:49.355Z
C

Connect Ventures

connect-ventures.com

47
HealthcareIndiamediumHIGH

Connect Ventures is a collaborative network of companies focused on advancing health, performance, and sustainability initiatives primarily in India. The organization operates as an integrated ecosystem with multiple subsidiaries specializing in holistic health, functional foods, performance labs, sustainability solutions, and design. Their market position is that of a niche integrator leveraging synergies across these domains to unlock human potential and environmental benefits. The website content is professionally presented with clear branding and consistent messaging, targeting businesses and individuals interested in these sectors. Technically, the website uses modern web fonts and JavaScript but lacks advanced frameworks or CMS indications. Performance is moderate with good mobile optimization and basic accessibility. SEO optimization is basic with minimal meta information. No analytics or tracking scripts were detected, indicating a privacy-conscious approach but also a lack of marketing insights. No forms are present, limiting direct user data collection. From a security perspective, the site lacks visible security headers, privacy policies, cookie consent mechanisms, and incident response information. The absence of these elements reduces the overall security posture and compliance with GDPR or similar regulations. The domain uses privacy protection in WHOIS, which is justified for this business type. No WAF or blocking mechanisms were detected, and the site content is fully accessible. Overall, the website is professional and trustworthy but would benefit from enhanced security practices, privacy compliance documentation, and improved technical SEO and accessibility to strengthen its digital maturity and risk posture.

15
35
17
70
72
75
20
healthperformancesustainabilitycollaborativenetworksubsidiaries+3 more
HTML5CSS3JavaScriptGoogle Web Fonts (Typekit)+2

Partner Domains:

phd-health.com
subsidiary
invictusperformancelab.com
subsidiary

+3 more partners

2025-10-08T00:32:44.344Z
S

Error 404 (Not Found)!!1

syndicatedsearch.goog

48
OtherN/asmallHIGH

The website syndicatedsearch.goog is currently inaccessible, serving a standard 404 Not Found error page with minimal HTML content. There is no business-related content, metadata, or structured data available to analyze. The site appears to be hosted on Google infrastructure, as indicated by image URLs referencing google.com domains. Due to the lack of accessible content, no meaningful business overview, services, or market positioning can be determined. The absence of privacy policies, contact information, or security details further limits the assessment. From a technical perspective, the site lacks any detectable modern web technologies, frameworks, or CMS platforms. There are no scripts, analytics, or tracking mechanisms present. The page is minimally mobile optimized but offers no SEO or accessibility features. Security posture cannot be evaluated due to missing HTTPS and security headers information. Security evaluation is constrained by the lack of content and metadata. No vulnerabilities, incident response contacts, or certifications are found. The site does not provide any privacy or cookie policies, nor does it disclose any data protection officer or vulnerability disclosure information. Overall, the website is non-functional for end users and lacks any business or security credibility. It is recommended to resolve the 404 error and provide comprehensive content, including privacy and security policies, to enable a full assessment and improve trustworthiness.

20
40
2
60
75
80
100
404errornotfoundgoogle
2025-10-08T00:32:19.273Z
G

German Accreditation Body (DAkkS)

dakks.de

43
GovernmentGermanymediumHIGH

The German Accreditation Body (DAkkS) operates as the national accreditation authority for Germany, providing accreditation services to a wide range of conformity assessment bodies including laboratories, inspection and certification bodies. It holds a strong market position as a government-mandated entity, recognized internationally through memberships and multilateral agreements. The website clearly targets organizations seeking accreditation, accredited bodies, assessors, and international partners, offering comprehensive information and services related to accreditation processes and standards. Technically, the website is built on the Contao CMS platform and utilizes modern JavaScript libraries such as jQuery, Slick Carousel, and TweenMax to deliver a responsive and accessible user experience. The site is well-optimized for mobile devices and includes accessibility features. Privacy compliance is robust, with a clear privacy policy, cookie consent mechanism via Usercentrics, and use of Matomo analytics configured with privacy in mind. From a security perspective, the site enforces HTTPS and employs digital seals for certificates, enhancing trust and integrity. While explicit security headers are not detected in the HTML content, the overall security posture is strong with no visible vulnerabilities or exposed sensitive data. The absence of explicit incident response or vulnerability disclosure policies suggests an area for improvement. Overall, the website demonstrates high professionalism, trustworthiness, and compliance with relevant regulations, making it a reliable source for accreditation-related information and services in Germany and internationally.

65
28
17
70
-
75
-
accreditationdakksgermanaccreditationbodyqualityinfrastructurecertification+3 more
jQueryjQuery UISlick CarouselTweenMax+1
2025-10-07T23:20:46.909Z
U

univ-grenoble-alpes.fr

univ-grenoble-alpes.fr

29
OtherN/asmallHIGH

The analyzed content corresponds to a Chrome internal error page (chrome-error://chromewebdata/) which is displayed when the browser cannot load external website content. This page includes embedded JavaScript and CSS for the Chrome offline dinosaur game but contains no actual business or website content. Consequently, no privacy, cookie, or terms of service policies are present, nor is there any contact or business information. The page is purely technical and serves as an offline error indicator within the Chrome browser environment. From a technical perspective, the page uses standard HTML5, CSS3, and JavaScript technologies, specifically Chromium's internal scripts for the offline game. It is optimized for mobile and accessibility but lacks SEO metadata or external links. Security headers and SSL configurations are not applicable as this is not a publicly hosted website. The security posture is minimal due to the nature of the page; no sensitive data or vulnerabilities are present, but also no security policies or incident response information are available. The WHOIS data is not applicable since the domain is internal to the Chrome browser and not registered externally. Overall, this page cannot be considered a legitimate website but rather a browser error page. Therefore, the risk assessment is low for external threats but also indicates no business credibility or privacy compliance. For accurate website analysis, a valid accessible website URL is required.

-
25
-
60
-
25
100
chrome-errorofflineerror-pagechrome-dino-game
JavaScriptHTML5CSS3Canvas API
2025-10-07T21:02:23.048Z
S

403 - Forbidden: Access is denied.

secureallegiance.com

49
OtherN/asmallHIGH

The website secureallegiance.com is currently inaccessible, returning a 403 Forbidden error page that blocks access to any business or security-related content. Due to this restriction, no metadata, structured data, contact information, or policies could be extracted or analyzed. The domain is registered since 2012 with Gandi SAS and uses Microsoft Azure DNS servers, indicating a legitimate and established registration. However, the lack of accessible content and absence of security or privacy disclosures significantly limits the ability to assess the company's business operations, security posture, or compliance status. The website appears to be either misconfigured or intentionally restricted, which severely impacts trust and usability. From a technical perspective, no scripts, frameworks, or CMS platforms were detected, and no performance or SEO indicators are available. The hosting infrastructure is likely on Microsoft Azure given the DNS servers. Security headers and SSL configuration could not be verified due to the blocked content. No analytics or marketing tools were found, and no contact or social media links are present. Security posture evaluation is not possible beyond noting the 403 error, which may be a security control or misconfiguration. No privacy, cookie, or terms of service policies are published, and no incident response or vulnerability disclosure information is available. The domain registration data is consistent and long-term, supporting legitimacy, but the inaccessible website content is a critical issue. Overall, the site scores very low on content quality, technical implementation, security posture, privacy compliance, and business credibility due to the lack of accessible content. Strategic recommendations include resolving access issues, publishing essential policies, enabling HTTPS and security headers, and providing clear contact and business information to improve trust and compliance.

15
50
17
40
82
70
100
2025-10-07T20:59:36.707Z
C

Commanders Act

commander1.com

48
TechnologyFrancemediumHIGH

Commanders Act is a French technology company specializing in digital marketing and data management solutions, particularly focusing on customer journey analytics and tag management. The company appears to target businesses seeking to optimize their digital marketing efforts through data-driven insights. The website is built on WordPress and uses standard web technologies such as jQuery and Google Fonts, hosted on AWS infrastructure. However, the website content is minimal, lacking detailed business descriptions, policies, or contact information, which limits the depth of user engagement and trust signals. From a technical perspective, the website employs HTTPS but lacks advanced security headers and DNSSEC, which are recommended for enhanced security. The use of an outdated jQuery version may pose potential security risks if not regularly updated. No forms or data collection mechanisms are visible, and no privacy or cookie policies are present, indicating potential compliance gaps with GDPR and other privacy regulations. Security posture is moderate with basic HTTPS but missing several best practices such as security headers and DNSSEC. The domain registration is consistent and legitimate, with a stable history since 2013, supporting the business credibility. No signs of WAF or blocking mechanisms were detected, and the content is safe for general audiences with no adult or questionable material. Overall, the website demonstrates a basic digital presence with room for improvement in content richness, privacy compliance, and security hardening to enhance trust and user confidence.

15
35
2
45
77
50
100
technologydigitalmarketingcustomerjourneytagmanagementanalytics+1 more
jQuery 2.1.4Google Fonts (Roboto)WordPress
2025-10-07T19:54:42.242Z