Skip to main content

High-risk security reports

Browse 46,998 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157371
Websites
130
Industries
113
Countries
52
Avg Score
Page 343 of 940|Showing 17101-17150 of 46998
viet-thai.com favicon

Viet Thai Plastchem Joint Venture Company Limited

viet-thai.com

48
ManufacturingVietnamsmallHIGH

Viet Thai Plastchem Joint Venture Company Limited is a Vietnam-based manufacturer specializing in PVC compound production and distribution of raw materials and chemicals for the plastics industry. Established in 2015, the company targets industrial sectors such as electric cable, bottle, shoe sole, and plumbing industries. The website reflects a focused business model with clear product offerings and company information, positioning itself as a niche manufacturer within the Vietnamese market. Technically, the website employs a modern frontend stack including Bootstrap, jQuery, Swiper, and Google reCAPTCHA for form security. The site is mobile-optimized with moderate performance and basic SEO and accessibility features. Hosting appears local to Vietnam, consistent with the business location. However, no CMS or advanced analytics tools are detected, indicating a relatively simple technical infrastructure. From a security perspective, the site uses HTTPS and Google reCAPTCHA, but lacks DNSSEC and important security headers, which could improve its security posture. No incident response or security policy information is provided, and privacy compliance is basic with only a cookie notice and privacy page. The WHOIS data is consistent with the business claims, showing a legitimate domain registration with no privacy protection. Overall, the website presents a moderate risk profile with good business credibility but room for improvement in security and privacy compliance. Strategic recommendations include enhancing security headers, enabling DNSSEC, publishing detailed security and incident response policies, and improving privacy compliance to align with GDPR standards.

20
68
2
70
52
75
20
pvcmanufacturingplasticsvietnamchemical+1 more
BootstrapjQuerySwiperLightbox+1
2025-10-03T15:56:38.588Z
C

CÔNG TY CỔ PHẦN BAO BÌ TÍN THÀNH

batico.com

45
ManufacturingVietnammediumHIGH

BATICO is a Vietnamese packaging manufacturing company established in 2004, operating as a member of SCG Packaging. The company offers a variety of packaging products emphasizing quality, aesthetics, fast delivery, and sustainable packaging solutions. Their market presence spans domestic and international sectors, targeting businesses requiring packaging solutions. The website reflects a medium-sized enterprise with consistent branding and good content quality. Technically, the website uses legacy technologies such as jQuery 1.7.1 and Nivo Slider, with a custom or unknown CMS. Hosting and DNS are managed by local providers, with HTTPS enabled but lacking advanced security headers. Performance and mobile optimization are moderate to basic, with room for improvement in accessibility and SEO. Security posture is moderate; HTTPS is enforced, and domain registration is stable and consistent with business claims. However, the absence of security headers, privacy and cookie policies, and incident response contacts indicate compliance and security gaps. No vulnerabilities or malicious content were detected. Overall, the website is professional and trustworthy but would benefit from enhanced security practices, privacy compliance, and modernization of technical infrastructure to reduce risks and improve user trust.

15
50
17
70
62
70
-
packagingmanufacturingvietnambusinessindustrial
jQuery 1.7.1Nivo SliderJavaScriptCSS

Partner Domains:

scgpackaging.com
partner
2025-10-03T15:56:28.561Z
viedtelevizija.lv favicon

LMT

viedtelevizija.lv

39
TelecommunicationsLatvialargeHIGH

LMT Viedtelevīzija is a Latvian smart television service operated by LMT, a major telecommunications provider in Latvia. The website serves as a digital platform for their smart TV offerings, targeting Latvian consumers interested in digital television and streaming services. The business model appears to be subscription-based, leveraging LMT's established telecommunications infrastructure. The website's market position is consistent with a large telecommunications company expanding into digital media services. Technically, the website employs modern JavaScript ES modules and standard web assets such as CSS and manifest files, indicating a contemporary web development approach. However, the provided HTML content is minimal and lacks visible user-facing content, which limits the assessment of user experience and content richness. Mobile optimization and accessibility are basic, with no advanced SEO or accessibility features detected in the snapshot. From a security perspective, the website lacks visible security headers and does not expose privacy or cookie policies, which are critical for GDPR compliance. No contact or incident response information is provided, and no vulnerability disclosure mechanisms are evident. The domain WHOIS data aligns well with the LMT brand, using LMT name servers and showing no suspicious patterns, supporting the legitimacy of the site. Overall, the website is functional but basic, with room for improvement in content richness, privacy compliance, and security posture. Strategic recommendations include implementing comprehensive privacy and cookie policies, enhancing security headers, providing clear contact and incident response information, and improving content quality and accessibility to better serve users and comply with regulations.

30
25
2
40
-
60
100
telecommunicationssmart-tvdigital-televisionlatvialmt
JavaScript ES ModulesCSSManifest JSONBrowserconfig XML
2025-10-03T15:43:24.406Z
listedcompany.com favicon

AlphaInvest Holdings Pte Ltd

listedcompany.com

49
FinanceSingaporemediumHIGH

The website www.listedcompany.com operates as a financial newsletter platform branded as 'FOCUS - By AlphaInvest', providing weekly updates and performance reviews of listed companies primarily in Singapore, Malaysia, and Thailand. It targets investors and market watchers interested in Southeast Asian stock markets. The business model revolves around subscription-based newsletter distribution, with a long archive of newsletters dating back to 2005, indicating sustained operations. The parent company is AlphaInvest Holdings Pte Ltd, a Singapore-based entity. Technically, the website employs standard web technologies including jQuery, Fancybox, Google Fonts, and Google Analytics for tracking. The site is mobile responsive and well-structured, offering a good user experience and clear navigation. However, the absence of a cookie policy and consent mechanism is a privacy compliance gap. Security posture is moderate; HTTPS is assumed but no explicit security headers were detected, and no incident response or security policies are published. The WHOIS data for the domain is missing or unavailable, which raises concerns about domain legitimacy and registration status. Overall, the website is professional and content-rich but would benefit from enhanced security and privacy compliance measures.

60
35
2
65
77
80
-
listedcompaniesnewsletterfinancesingaporemalaysia+2 more
jQuery 1.10.1Fancybox 2.1.5Google AnalyticsGoogle Fonts (Noto Sans)

Partner Domains:

alphainvestholdings.com
parent
2025-10-03T15:39:02.655Z
alaloush.com favicon

Survy QR

alaloush.com

46
TechnologyN/asmallHIGH

The website www.alaloush.com hosts a portal named 'Survy QR', which appears to be a login interface for a survey or event management platform leveraging QR codes. The site targets users who require authenticated access to surveys or event-related data. The business model is web-based service delivery with user authentication but lacks publicly available business or contact information, limiting transparency. Technically, the site employs a variety of common frontend libraries including jQuery, Bootstrap 4, FontAwesome, and several plugins for UI enhancements. The performance is moderate with basic mobile optimization and accessibility features. However, SEO optimization is minimal, and no CMS or hosting provider details are evident. The site uses HTTP in the base URL, but HTTPS usage is not confirmed, which is a concern. From a security perspective, the site lacks visible security headers such as CSP or HSTS, and no anti-CSRF tokens are evident in the login form. The absence of WHOIS data for the domain raises legitimacy concerns, as the domain appears unregistered or privacy-protected without clear justification. No privacy, cookie, or terms of service policies are present, indicating poor privacy compliance. No contact or incident response information is provided. Overall, the site presents a low trust profile with basic content and technical implementation. The lack of transparency in domain registration and absence of security best practices suggest a need for significant improvements to enhance security posture and business credibility.

35
35
2
70
-
80
100
surveyqrlogineventportal
jQueryjQuery UIFontAwesomeTempusdominus Bootstrap 4+10
2025-10-02T15:57:58.321Z
J

Visitor anti-robot validation

jak.lv

46
TechnologyN/asmallHIGH

The website jekabpils.jak.lv serves as a security validation gateway powered by BitNinja, designed to block IP addresses suspected of violating server security policies and to prevent automated bot access. Visitors are required to complete a CAPTCHA challenge to proceed, indicating the site functions primarily as a protective layer rather than a traditional business or content site. The page includes multilingual support and integrates Google reCAPTCHA and Google Analytics for bot mitigation and visitor tracking. Technically, the site uses legacy CMS meta tags referencing Joomla 1.5 and WordPress 2.5, though the actual content is minimal and focused on security validation. The presence of Google Analytics and Tag Manager scripts indicates moderate tracking capabilities. However, the site lacks modern security headers and explicit privacy or cookie policies, which limits its compliance posture. From a security perspective, the site demonstrates basic bot mitigation practices but shows potential risks due to outdated CMS references and absence of advanced security headers. The domain WHOIS data is privacy protected, which is typical for security-related services but limits transparency. Overall, the site is a security checkpoint rather than a business-facing website, with limited content and no direct business or contact information. Strategically, the site should enhance its security posture by updating CMS components, implementing modern security headers, and publishing clear privacy and cookie policies to improve trust and compliance. Given its role as a security gateway, maintaining robust bot mitigation and clear user guidance is critical.

20
10
17
70
57
65
100
securitycaptchabotmitigationbitninjaanti-robot+1 more
HTML5CSS3JavaScriptGoogle Analytics+3
2025-09-30T11:17:51.801Z
landkreis-aurich.de favicon

Landkreis Aurich

landkreis-aurich.de

44
GovernmentGermanymediumHIGH

Landkreis Aurich operates as a local government authority in Germany, providing a wide range of public services including social welfare, health, environmental management, and administrative support to residents. The website serves as an official portal for information dissemination, citizen engagement, and access to government services. It targets local residents, businesses, and stakeholders within the district. The business model is that of a public sector entity focused on governance and community services. Technically, the website is built on TYPO3 CMS, leveraging Bootstrap for responsive design and various JavaScript libraries such as jQuery, Swiper.js, and DataTables to enhance user experience. The site demonstrates moderate performance and good mobile optimization, with a clear navigation structure and professional design. Cookie consent is implemented with user choice, reflecting GDPR compliance. From a security perspective, the site uses HTTPS and has implemented cookie consent mechanisms, but lacks visible security headers and explicit security or incident response policies. No vulnerabilities or exposed sensitive data were detected in the provided content. The WHOIS data is minimal but consistent with the domain's purpose, supporting legitimacy. Social media presence and external partnerships further reinforce trust. Overall, the website is a well-maintained government portal with good content quality and technical implementation. Strategic improvements in security headers and transparency around security policies would enhance its security posture and trustworthiness.

15
55
2
70
52
60
20
governmentlocalauthoritypublicservicesgermantypo3+5 more
HTML5CSS3JavaScriptBootstrap+5

Partner Domains:

mkw-grossefehn.de
partner
anevita.de
partner

+2 more partners

2025-09-23T09:44:34.612Z
V

403 Forbidden

visualfactory.net

49
OtherN/asmallHIGH

The website support.visualfactory.net is currently inaccessible, returning a 403 Forbidden error page with no meaningful content. This indicates that access is blocked either by server configuration or security mechanisms such as a firewall or access control rules. Due to the lack of accessible content, no metadata, scripts, or business information could be extracted. The WHOIS lookup for this subdomain failed to return any registration data, suggesting that it is either not separately registered or the data is not publicly available. This lack of transparency and accessibility severely limits the ability to assess the business or technical posture of the site. From a technical perspective, the site shows no evidence of modern web technologies, security headers, or SSL configuration. The absence of privacy policies, contact information, or terms of service further reduces trustworthiness and compliance posture. The domain's legitimacy is questionable due to missing WHOIS data and blocked access, which may be typical for internal or restricted support portals but is not suitable for public-facing services. Security-wise, the site currently exhibits a poor posture with no visible security best practices or protections. The 403 error may be intentional to restrict unauthorized access, but it also prevents legitimate users or analysts from verifying the site's integrity or compliance. Overall, the risk assessment is high due to lack of transparency, accessibility, and security indicators. Strategic recommendations include enabling secure and controlled access with proper authentication, publishing essential compliance documents, implementing HTTPS with valid certificates, and ensuring WHOIS data is accurate and publicly available if the domain is intended for public use.

15
40
17
75
62
75
100
403forbiddenblockedno-contentsecurity
2025-09-08T14:17:23.917Z
aimmonitor.sk favicon

IAB Slovakia

aimmonitor.sk

47
MediaSlovakiasmallHIGH

IAB Slovakia is a professional association dedicated to the internet advertising industry in Slovakia, providing market data, education, and standards through initiatives like the IAB Monitor. The website is well-structured, primarily in Slovak, targeting marketing professionals, advertisers, and publishers within the Slovak digital advertising ecosystem. The business model is non-profit and focused on industry support and development. Technically, the website is built on WordPress and integrates modern tools such as Google Tag Manager, Cookiebot for consent management, Hotjar for user behavior analytics, and Google reCAPTCHA for bot protection. The site demonstrates good mobile optimization and SEO practices, with structured data enhancing search engine understanding. From a security perspective, the site enforces HTTPS and uses consent management to comply with GDPR. While explicit security headers are not fully visible in the HTML, the overall posture is solid with no evident vulnerabilities or exposed sensitive data. The use of third-party scripts is standard for analytics and marketing but should be regularly audited. Overall, the website presents a low-risk profile with strong compliance to privacy regulations and a professional digital presence. Strategic recommendations include enhancing security headers, ensuring all forms have CSRF protection, and maintaining regular security audits of third-party integrations.

15
88
2
85
42
45
20
internetadvertisingiabslovakiacookieconsentdigitalmarketing+1 more
WordPressGoogle Tag ManagerCookiebotHotjar+1
2025-09-07T14:07:46.038Z
fireproductsearch.com favicon

Fire Product Search

fireproductsearch.com

44
OtherN/asmallHIGH

Fire Product Search is an online informational platform serving as a leading guide for professional firefighting and rescue equipment. The website targets professionals and enthusiasts in the firefighting and rescue sectors, offering product search capabilities, industry news, and updates. It positions itself as a niche leader with a focused business model centered on providing valuable information and resources related to fire and rescue products. Technically, the website is built on WordPress CMS, utilizing popular plugins such as Yoast SEO for search engine optimization and MonsterInsights for Google Analytics integration. The site is served over HTTPS, ensuring secure communication, and employs modern web fonts and iconography. Performance and mobile optimization are moderate to good, with a clean and professional design that supports user experience. From a security perspective, the site enforces HTTPS but lacks visible security headers and explicit privacy or cookie policies, which are critical for compliance and user trust. No contact information or incident response channels are clearly provided, limiting transparency. The absence of WHOIS registration data raises concerns about domain legitimacy, although the website content itself appears professional and trustworthy. Overall, the site presents a moderate risk profile with room for improvement in privacy compliance, security best practices, and business credibility. Strategic recommendations include implementing security headers, publishing comprehensive privacy and cookie policies, providing clear contact and incident response information, and verifying domain registration details to enhance trustworthiness.

15
53
17
70
62
65
-
firefightingrescueprofessionalguidefireequipmentdirectory+3 more
WordPressYoast SEO pluginGoogle Analytics (MonsterInsights plugin)Google Fonts+1
2025-09-07T13:02:50.664Z
N

names.com

delicious.com

48
TechnologyN/asmallHIGH

Names.com operates as a specialized boutique brokerage firm focusing on premium and category-defining domain names. Established since 1995, it holds a strong market position by emphasizing quality over quantity in domain sales, leasing, and acquisitions. The company targets premium domain buyers and sellers globally, offering expert brokerage and acquisition services with transparent and professional client engagement. The website reflects this positioning with clear domain listings, pricing, and a professional design. Technically, the website employs a modern but somewhat dated tech stack including Bootstrap 3, jQuery 2.1, and integrates third-party services such as Stripe for payments and Escrow.com for secure transactions. Hosting is provided via InMotion Hosting, and the site shows good mobile optimization and SEO practices. However, some technical improvements are possible, including enabling DNSSEC and adding security headers. From a security perspective, the site uses HTTPS and reputable third-party payment and escrow services, which enhance transactional security. However, the absence of DNSSEC, lack of explicit security headers, and missing security or incident response policies represent areas for improvement. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism or GDPR indicators. Overall, the website is trustworthy and professional with a solid business model and credible domain registration data. Strategic improvements in security posture and privacy compliance would further strengthen its risk profile and customer trust.

15
53
17
80
72
70
-
domainsforsalepremiumdomainsdomainbrokerageexactmatchdomainsdomainleasing+1 more
Bootstrap 3.3.6jQuery 2.1.4Font Awesome 4.7.0Google Fonts (Montserrat, Lato, Roboto)+4

Partner Domains:

escrow.com
partner
2025-09-07T12:59:39.758Z
E

emcpi.com | 526: Invalid SSL certificate

emcpi.com

47
OtherN/asmallHIGH

The website emcpi.com is currently inaccessible due to an invalid SSL certificate on the origin server, resulting in a Cloudflare error 526 page being served. This prevents any meaningful content or business information from being accessed or analyzed. The domain is registered with NameCheap since 2019 and uses Cloudflare DNS services, but lacks DNSSEC and proper SSL configuration. No privacy, cookie, or terms of service policies are present, nor are there any contact details or business descriptions visible. The technical infrastructure relies on Cloudflare as a CDN and WAF, but the misconfiguration severely impacts availability and trust. From a security perspective, the invalid SSL certificate is a critical vulnerability that must be addressed immediately to restore secure access. The absence of security headers and policies further weakens the security posture. No analytics or tracking technologies are detected, indicating minimal digital maturity or possibly a placeholder site. The lack of business information and trust indicators limits the ability to assess market position or business credibility. Overall, the site scores very low on content quality, technical implementation, security posture, privacy compliance, and business credibility due to the blocking error and lack of accessible content. Strategic remediation should prioritize fixing the SSL certificate issue, implementing standard security headers, and publishing essential policies and contact information to improve trust and compliance.

-
35
2
70
75
70
100
errorsslcloudflaresecurityblocked
Cloudflare
2025-09-07T12:57:18.901Z