Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149318
Websites
130
Industries
113
Countries
52
Avg Score
Page 36 of 153|Showing 1751-1800 of 7628
M

MoodleMoot Global

moodlemoot.org

10
EducationUnited KingdommediumCRITICAL

MoodleMoot Global 2025 is a well-established international education conference focused on the Moodle learning platform, scheduled to be held in Edinburgh, UK. The website serves as the main portal for event information, ticket sales, agenda, and sponsorship opportunities. It targets educators, developers, and education technology professionals globally. The business model centers on event organization and ticketing, supported by partnerships with payment processors and marketing platforms. Technically, the site is built on WordPress with a modern plugin ecosystem, including WooCommerce and Tickera for e-commerce and ticket management. The infrastructure leverages Cloudflare DNS and integrates analytics and marketing tools such as HubSpot, Google Tag Manager, and Facebook Pixel. Security posture is solid with HTTPS enforced and cookie consent implemented, though DNSSEC is not enabled and some advanced security headers are missing. Privacy compliance is good, with a clear cookie consent mechanism and a basic privacy policy. No contact emails or phone numbers are explicitly published, which is a minor gap in business credibility. Overall, the site is professional, trustworthy, and suitable for its audience, with no signs of malicious activity or content safety concerns.

-
-
-
-
-
-
-
educationconferencemoodleeventticketing+2 more
WordPressPHPWooCommerceTickera (ticketing plugin)+5

Partner Domains:

stripe.com
partner
calendly.com
partner

+1 more partners

2025-10-11T10:49:32.329Z
moodle.com favicon

Moodle Pty Ltd

moodle.com

77
EducationN/alargeLOW

Moodle Pty Ltd operates the website moodle.com, providing the world's most popular Learning Management System (LMS) and related educational technology solutions. The company targets educators, trainers, and institutions across K-12, higher education, and workplace learning sectors. Moodle offers a range of products including Moodle LMS, Moodle Workplace, MoodleCloud, and the Moodle App, supported by a global network of certified partners and integrations. The website reflects a mature, well-established business with a strong market position and a commitment to open source principles and educational equity. Technically, the website is built on WordPress with modern web technologies such as jQuery, Google Tag Manager, and Intercom for customer engagement and analytics. Hosting and DNS services leverage Cloudflare, ensuring reliable performance and security. The site is mobile-optimized, accessible, and SEO-friendly, with comprehensive metadata and structured data enhancing search visibility. From a security perspective, the site enforces HTTPS, employs domain transfer and update protections, and integrates cookie consent mechanisms compliant with GDPR. However, DNSSEC is not enabled, and explicit security policies or incident response contacts are not published, representing areas for improvement. No vulnerabilities or exposed sensitive data were detected. Overall, moodle.com demonstrates a high level of professionalism, trustworthiness, and compliance, making it a reliable platform for educational technology services. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, and providing clearer security policy disclosures to further enhance trust and security posture.

50
88
47
82
75
85
100
lmseducationopensourcee-learningtraining+3 more
jQueryGoogle Tag ManagerIntercomCloudflare DNS+1
2025-10-11T09:38:02.261Z
J

Jscrambler

jscrambler.com

84
TechnologyN/amediumLOW

Jscrambler is a technology company specializing in client-side protection platforms, offering advanced JavaScript obfuscation and third-party tag protection solutions. Established in 2010, it serves enterprises and businesses seeking to secure their web applications and comply with regulations such as PCI DSS. The company positions itself as a leader in client-side security with a comprehensive suite of services tailored to various industries including finance, e-commerce, and healthcare. The website reflects a professional and consistent brand image with detailed product information and resources to support customer engagement. Technically, the website leverages modern web technologies including JavaScript frameworks, HubSpot for marketing and analytics, and Cloudflare for DNS and security. The site is mobile-optimized and demonstrates good SEO practices, although accessibility features are basic. Performance is moderate, with multiple third-party scripts for analytics and marketing, indicating a mature digital infrastructure. From a security perspective, the site enforces HTTPS and uses Cloudflare DNS, but lacks visible advanced security headers and explicit security policies on the site. No vulnerability disclosure or incident response information is provided, which could be improved to enhance trust. The domain WHOIS data is consistent and transparent, supporting the legitimacy of the business. Overall, Jscrambler presents a secure and professional online presence with room for improvement in privacy compliance transparency and security policy disclosures. The risk profile is low, with no critical vulnerabilities detected in the analysis.

50
95
65
98
100
85
100
javascriptobfuscationpcidsscompliancesecuritycompliancetechnology
JavaScriptHubSpot analyticsGoogle Tag ManagerHotjar+1
2025-10-11T09:36:27.609Z
floriankarsten.com favicon

Florian Karsten Studio

floriankarsten.com

50
TechnologyCzech RepublicsmallMEDIUM

Florian Karsten Studio is a small creative technology business based in Brno, Czech Republic, specializing in graphic design, UX, and development services. The studio emphasizes open-source projects, peer-to-peer networks, and automation, targeting clients interested in independent and functional digital systems. The website presents a professional portfolio with clear branding and a focus on design and technology integration. Technically, the website uses modern web technologies including HTML5, CSS, JavaScript, and libraries such as jQuery and Slick Carousel. Hosting and DNS are managed via Cloudflare and NameCheap, ensuring reliable performance and security. The site is mobile optimized and includes privacy-respecting analytics via Plausible. However, there is room for improvement in accessibility and security headers. From a security perspective, the site enforces HTTPS and uses domain transfer protection, but lacks DNSSEC and security headers which are recommended for enhanced protection. No privacy or cookie policies are present, indicating compliance gaps with GDPR and other privacy regulations. No forms or sensitive data collection mechanisms reduce risk exposure. Overall, the security posture is moderate but could be strengthened with additional policies and technical controls. The overall risk is low given the nature of the business and website content, but strategic improvements in privacy compliance and security best practices are advised to enhance trust and regulatory adherence.

25
50
2
55
72
75
40
graphicdesignuxdevelopmentopen-sourcepeer2peer+2 more
HTML5CSSJavaScriptjQuery+3

Partner Domains:

fonts.floriankarsten.com
service
karsten.systems
service
2025-10-11T08:30:12.365Z
smegstore.us favicon

Smeg S.p.A.

smegstore.us

74
E-commerceItalymediumMEDIUM

SMEG USA operates as an e-commerce platform retailing stylish and high-quality kitchen appliances under the SMEG brand. The website targets general consumers seeking modern, energy-efficient kitchen products and offers a variety of appliances including major and small appliances, retro refrigerators, and kitchen accessories. The business is positioned as a medium-sized entity with a focus on design and quality, leveraging the established SMEG brand from Italy. Technically, the site is built on Shopify, utilizing modern JavaScript frameworks and integrations with marketing and analytics tools such as Google Analytics, Facebook Pixel, and Klaviyo. The site demonstrates good mobile optimization and accessibility features. Security posture is solid with HTTPS enforced and use of CAPTCHA and fraud filtering apps, though DNSSEC is not enabled and some security headers are not explicitly present. Privacy compliance is weak due to the absence of visible privacy and cookie policies, and no explicit contact information is provided for customer or security inquiries. Overall, the domain registration data aligns well with the SMEG brand and the website content, indicating legitimacy despite the domain's recent creation. Strategic improvements in privacy disclosures and security header implementation would enhance trust and compliance.

75
73
25
80
75
85
100
e-commercekitchenappliancessmegshopifyretail+2 more
ShopifyCloudflare DNSGoogle Tag ManagerFacebook Pixel+6
2025-10-11T08:28:11.653Z
G

Giant Panda LLC

giantpanda.com

60
TechnologyN/asmallMEDIUM

Giant Panda LLC operates a specialized domain monetization platform focused on helping domain investors and registrars maximize revenue from organic domain traffic. The company combines technology with human review to optimize domain monetization, offering advanced analytics, smarter domain sales tools, and comprehensive traffic revenue extraction. The website presents a professional and consistent brand image with clear service descriptions targeting domain owners and registrars. Technically, the website uses modern web standards including HTML5, CSS3, JavaScript, and Google Fonts, with DNS managed by Cloudflare. The site is mobile optimized and has good SEO practices, though no CMS or major frameworks are detected. Performance is moderate with room for improvement in accessibility and security headers. No analytics or advertising scripts are embedded in the main HTML content. From a security perspective, the domain is well-registered with GoDaddy since 2015 and protected by multiple EPP status locks. However, DNSSEC is not enabled, and no security headers or incident response policies are published. Privacy compliance is partial with a privacy policy and terms of service present but lacking cookie consent mechanisms. No contact information or security contact channels are provided. Overall, the website is trustworthy and professional but could improve security posture and privacy compliance. There are no signs of malicious activity or adult content, making it safe for general audiences.

15
53
2
85
75
75
100
domainmonetizationtechnologyanalyticsdomainsalesdigitalmarketing
HTML5CSS3JavaScriptGoogle Fonts+1
2025-10-11T06:42:49.957Z
tvrplus.ro favicon

Televiziunea Română

tvrplus.ro

53
MediaRomanialargeMEDIUM

TVR+ is the official video portal of Televiziunea Română, Romania's national public broadcaster. The website offers live streaming and recorded content from multiple TVR channels, targeting a general audience with a focus on cultural, news, and entertainment programming. The platform is well-branded and consistent with the parent organization's identity, serving as a key digital extension of TVR's broadcast services. Technically, the site employs modern web technologies including Bootstrap, jQuery, Flowplayer for video streaming, and HLS.js for adaptive streaming. Hosting and DNS services leverage Cloudflare and a CDN for video delivery, ensuring moderate performance and good mobile optimization. SEO and accessibility are basic but functional. From a security perspective, the site uses HTTPS and implements some best practices like frame busting. However, it lacks DNSSEC, explicit security headers, and formal privacy or cookie policies, which are important for compliance and user trust. No vulnerability disclosure or incident response information is provided, indicating room for improvement in security transparency. Overall, TVR+ presents a professional and trustworthy digital presence aligned with a large public media entity. The main risks relate to privacy compliance and security hardening, which should be addressed to enhance user trust and regulatory adherence.

15
10
2
85
67
70
100
tvrromaniantvlivestreamingpublicbroadcastervideoportal
HTML5CSS3BootstrapjQuery+5

Partner Domains:

tvr.ro
partner
stiri.tvr.ro
partner

+3 more partners

2025-10-11T06:42:19.376Z
tally.so favicon

Tally BV

tally.so

64
TechnologyBelgiummediumMEDIUM

Tally BV operates a modern, privacy-conscious online form builder platform accessible globally. Founded in 2020 and headquartered in Belgium, Tally offers a freemium SaaS model with a strong emphasis on unlimited free forms and submissions, advanced features like conditional logic, e-signatures, payments, and extensive integrations with popular productivity tools. The company positions itself as a user-friendly and GDPR-compliant alternative to traditional form builders, targeting creators, product teams, marketers, HR, and office users. The website is professionally designed, mobile-optimized, and rich in content, including testimonials and social proof, reinforcing its market credibility. Technically, the platform leverages modern web technologies including React and Next.js, hosted with Cloudflare DNS and integrated with Stripe for payments and automation platforms like Zapier, Make, and Pipedream. The site demonstrates good SEO, accessibility, and performance characteristics. Security practices are robust with HTTPS enforced, data encryption in transit and at rest, and hosting within the EU to comply with GDPR. However, there is room for improvement in publishing explicit security policies, incident response information, and enabling DNSSEC. The security posture is strong with standard security headers and privacy-friendly design, but lacks a dedicated vulnerability disclosure program and cookie consent mechanism. The WHOIS data aligns well with the business claims, showing consistent domain registration and no privacy protection, indicating transparency. Overall, the risk profile is low with no detected vulnerabilities or suspicious patterns. Strategic recommendations include enabling DNSSEC, publishing a formal security policy and incident response page, implementing a cookie consent banner, and establishing a vulnerability disclosure program to further enhance trust and compliance.

45
85
25
85
-
85
100
onlineformsformbuilderno-codefreeformsgdprcompliant+4 more
ReactNext.jsCloudflare DNSStripe+3

Partner Domains:

stripe.com
partner
zapier.com
partner

+3 more partners

2025-10-11T06:41:30.689Z
efe.com favicon

Agencia EFE

efe.com

58
MediaSpainlargeMEDIUM

Agencia EFE operates as the leading Spanish language news agency, distributing millions of news items annually across multiple media formats including text, photography, video, and audio. The website efe.com serves as a comprehensive digital platform for news dissemination, targeting a broad general audience primarily in Spain and Spanish-speaking regions. The business model centers on media content distribution and thematic news services, supported by a network of related domains and specialized content sites. The company is well-established with a domain age dating back to 1998, reinforcing its market position and credibility. Technically, the website is built on WordPress CMS, leveraging modern SEO tools such as Yoast SEO Premium and interactive elements like Smart Slider 3. The infrastructure includes integrations with Google Tag Manager, Microsoft Clarity, and other analytics and marketing tools, indicating a mature digital presence. Hosting and DNS services utilize Cloudflare, though DNSSEC is not enabled, representing a minor security gap. The site is mobile optimized with good performance and accessibility features, though some improvements are possible. From a security perspective, the site enforces HTTPS and includes standard security headers, contributing to a solid security posture. However, the absence of explicit privacy and terms of service pages, as well as lack of a published security policy or incident response contacts, suggests areas for compliance and transparency enhancement. The cookie consent mechanism is present and functional, indicating GDPR awareness. Overall, efe.com presents a professional, trustworthy, and content-rich platform with a strong business foundation. Strategic improvements in privacy documentation, DNS security, and security policy transparency would further strengthen its security and compliance posture.

30
50
17
75
42
65
100
newsmediaspanishagencymultimedia+1 more
WordPressYoast SEO PremiumSmart Slider 3Google Tag Manager+4

Partner Domains:

efs.efeservicios.com
partner
efecomunica.efe.com
partner

+3 more partners

2025-10-11T04:24:26.180Z
matrix.org favicon

Matrix.org Foundation

matrix.org

67
TechnologyN/amediumMEDIUM

Matrix.org operates as the foundation and hub for the Matrix open protocol, which enables secure, decentralized communication across chat, VoIP, and data transfer. The organization positions itself as a leading open communication protocol with a strong community and open source ecosystem, offering clients, servers, bridges, SDKs, and hosting solutions. The website reflects a mature, well-established technology entity with a medium-sized footprint and a focus on transparency and security. Technically, the website is well-constructed with modern HTML5, CSS, and JavaScript technologies, hosted behind Cloudflare DNS services. It demonstrates excellent design quality, mobile optimization, and accessibility. The use of privacy-conscious analytics (Plausible) and absence of intrusive advertising reflects a privacy-aware digital maturity. However, the lack of DNSSEC and cookie consent mechanisms are areas for improvement. From a security perspective, the site enforces HTTPS, maintains domain transfer restrictions, and publishes a security disclosure policy and hall of fame, indicating a proactive security posture. No critical vulnerabilities or exposed sensitive data were detected. The absence of security headers and a security.txt file are minor gaps. Overall, the security posture is strong but could be enhanced with additional DNS and header configurations. The overall risk assessment is low, with the website demonstrating high professionalism, trustworthiness, and compliance with GDPR principles, though cookie consent implementation is recommended. Strategic recommendations include enabling DNSSEC, adding cookie consent, publishing security.txt, and providing explicit DPO contact information to further strengthen compliance and trust.

80
35
2
85
75
70
100
opensourcedecentralizedcommunicationmatrixprotocolsecurechattechnology
HTML5CSSJavaScriptCloudflare DNS
2025-10-11T04:19:30.502Z
brave.com favicon

Brave Software Inc

brave.com

68
TechnologyUnited StatesmediumMEDIUM

Brave Software Inc is a technology company specializing in privacy-focused web browsing and search solutions. Their flagship product, the Brave browser, offers users a fast, secure, and private browsing experience by blocking ads and trackers by default. The company also operates Brave Search, an independent and privacy-respecting search engine, and provides additional services such as a VPN, AI assistant, and a digital wallet. Positioned as a strong alternative to major browsers, Brave emphasizes user privacy and control over data. Technically, the website is built using modern web technologies including the Hugo static site generator, JavaScript, and Lottie animations for interactive content. Hosting and DNS services are provided by Cloudflare, ensuring fast performance and security. The site is well-optimized for mobile devices and accessibility, with comprehensive SEO practices in place. Analytics are handled via Matomo, a privacy-conscious analytics platform. From a security perspective, Brave demonstrates strong practices including HTTPS enforcement, a security bug bounty program via HackerOne, and domain registration stability. However, there is room for improvement by enabling DNSSEC and publishing a security.txt file. Privacy compliance is robust, with clear and comprehensive privacy policies and GDPR adherence. Contact information and incident response channels are transparent and accessible. Overall, Brave.com presents a professional, trustworthy, and user-centric digital presence with a strong emphasis on privacy and security. The website and company exhibit a mature security posture and a clear commitment to protecting user data, making it a reliable choice for privacy-conscious users and businesses.

75
58
35
95
-
90
100
privacybrowsersecuritytechnologyopen-source+3 more
Hugo (static site generator)JavaScriptLottie animationsMatomo analytics+1

Partner Domains:

search.brave.com
service
basicattentiontoken.org
related

+1 more partners

2025-10-11T02:01:36.627Z
mmatt.net favicon

Matt Morris

mmatt.net

56
TechnologyN/asmallMEDIUM

mmatt.net is the personal website and blog of Matt Morris, a technologist, student, and open source contributor. The site serves as a portfolio and content hub for his projects, thoughts on technology, gaming, and social media. It targets technology enthusiasts and community members interested in his work and insights. The website is built using modern web technologies including Next.js and React, hosted with Cloudflare DNS, and optimized for mobile and desktop users. The content is well structured and regularly updated, reflecting a good level of digital maturity for a personal brand site. From a security perspective, the site uses HTTPS with domain registration protections such as clientDeleteProhibited and clientTransferProhibited status. However, DNSSEC is not enabled, and no explicit security or incident response policies are published. Privacy and cookie policies are absent, which is a compliance gap. Analytics are implemented via Plausible with minimal tracking, indicating a privacy-conscious approach. The site does not use advertising networks or retargeting services, focusing on content and community engagement. Overall, the website presents a trustworthy and professional personal brand with good technical implementation and content quality. The main areas for improvement include publishing privacy and cookie policies, enabling DNSSEC, and adding security and vulnerability disclosure information to enhance trust and compliance.

30
35
17
35
72
80
100
personalblogtechnologygamingopensourcenextjs+4 more
Next.jsReactDocker (mentioned in blog content)Cloudflare DNS
2025-10-11T00:51:57.836Z
gusto.com favicon

Gusto

gusto.com

66
TechnologyUnited StateslargeMEDIUM

Gusto is a well-established technology company specializing in online payroll and HR solutions targeted primarily at small and medium-sized businesses. The company offers a comprehensive people platform that facilitates employee onboarding, payroll processing, benefits administration, and insurance management. Positioned as a leader in customer satisfaction, Gusto leverages modern SaaS delivery models to serve a large customer base with a focus on ease of use and compliance support. The website reflects a mature digital presence with professional design, clear navigation, and extensive content relevant to its business domain. Technically, the website is built on a modern stack including Next.js and React, hosted with Cloudflare DNS and CDN services. It employs advanced analytics and tracking tools such as Snowplow, FullStory, and Tealium, alongside a robust cookie consent mechanism powered by OneTrust. The site demonstrates excellent performance, mobile optimization, and accessibility features, indicating a high level of digital maturity. From a security perspective, Gusto enforces HTTPS with strong SSL configurations and implements key security headers to protect users. The presence of SOC 2 Type II and ISO 27001 certifications further underscores its commitment to security and compliance. However, there is room for improvement in publishing explicit security policies, incident response procedures, and vulnerability disclosure mechanisms to enhance transparency and trust. Overall, Gusto presents a low-risk profile with strong business credibility, technical sophistication, and privacy compliance. Strategic recommendations include enabling DNSSEC, publishing dedicated security and incident response pages, and providing clear contact information for data protection officers to further strengthen its security posture and regulatory compliance.

70
88
17
82
-
85
100
payrollhrsaasbusinesstechnology+2 more
Next.jsReactCloudflare DNSOneTrust (cookie consent)+4
2025-10-10T20:19:04.472Z
nationalesautomuseum.de favicon

Nationales Automuseum The Loh Collection

nationalesautomuseum.de

49
TransportationGermanymediumHIGH

The Nationales Automuseum website represents a well-established cultural institution in Germany focused on automotive history and exhibitions. The site offers comprehensive information about permanent and special exhibitions, ticketing, events, and educational programs. It targets a broad audience interested in automotive heritage and cultural tourism. The business model revolves around museum services, ticket sales, and event hosting, positioning itself as a niche but reputable player in the transportation and hospitality sectors. Technically, the website is built on WordPress with a modern theme (Yootheme) and UIkit framework, ensuring good mobile optimization and accessibility. The use of Cloudflare DNS and CDN enhances performance and security. Google Analytics is implemented with privacy-conscious settings, and Cookiebot manages cookie consent effectively, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms aligned with GDPR. However, explicit security headers like Content-Security-Policy and X-Frame-Options are not evident, and no dedicated security or incident response policies are published. No vulnerabilities or suspicious activities were detected in the analysis. Overall, the website demonstrates a strong balance of content quality, technical implementation, privacy compliance, and business credibility. It is trustworthy and professional, with clear contact information and legal policies. Strategic improvements could focus on enhancing security headers and publishing formal security policies to further strengthen trust and compliance.

15
83
2
65
72
70
-
automotivemuseumexhibitiongermanyculture+1 more
WordPress 6.8.3PHPYootheme themeUIkit framework+3

Partner Domains:

ticketshop.nationalesautomuseum.de
partner
2025-10-10T19:08:42.872Z
integritygrc.com favicon

INTEGRITY S.A.

integritygrc.com

74
TechnologyPortugalmediumMEDIUM

IntegrityGRC is a governance, risk, and compliance platform developed by INTEGRITY S.A., a certified information security consulting and auditing company based in Portugal. The company has a strong market position supported by ISO and CREST certifications and serves a diverse client base across multiple industries including banking, healthcare, government, and technology. Their platform offers comprehensive features such as risk management, document management, third-party risk assessment, and compliance self-assessment, targeting organizations seeking structured and robust GRC solutions. The business model combines SaaS offerings with consulting services, positioning the company as a trusted partner in information security and compliance. Technically, the website employs modern web technologies including Bootstrap, jQuery, Google reCAPTCHA, and Google Tag Manager, hosted behind Cloudflare DNS services. The site is well-optimized for mobile devices and demonstrates good SEO and accessibility practices. Security measures include HTTPS enforcement, Content Security Policy headers, and GDPR-compliant consent mechanisms. The contact form is secured with reCAPTCHA and includes explicit user consent for data processing. The security posture is strong with no visible vulnerabilities or exposed sensitive data. However, improvements such as enabling DNSSEC and adding additional security headers could further enhance security. The absence of an incident response contact or vulnerability disclosure policy is noted as an area for improvement. Overall, the domain registration and WHOIS data align well with the business claims, indicating legitimacy and consistent ownership. The overall risk assessment is low, with the company demonstrating a mature security and compliance culture. Strategic recommendations include enhancing DNS security, publishing incident response contacts, and expanding security headers to maintain and improve trust and resilience in the digital environment.

65
80
47
60
77
80
100
grcriskmanagementcomplianceiso27001gdpr+4 more
BootstrapjQueryGoogle reCAPTCHAGoogle Tag Manager+1

Partner Domains:

integrity.pt
partner
2025-10-10T17:57:10.718Z