Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 37 of 37|Showing 1801-1844 of 1844
l-tike.com favicon

株式会社ローソンエンタテインメント

l-tike.com

62
OtherJapanlargeMEDIUM

株式会社ローソンエンタテインメント operates l-tike.com, a leading Japanese ticket sales and reservation platform specializing in concerts, sports, theater, and various entertainment events. The website serves a broad audience of entertainment consumers and event attendees, offering services including ticket sales, electronic ticket delivery, fan club memberships, and travel-related bookings. The company is a subsidiary of Lawson, a major Japanese retail group, positioning it strongly in the domestic entertainment market. Technically, the site employs common web technologies such as jQuery, Swiper, and Flatpickr, with multi-language support via WOVN.io and is hosted on Akamai's CDN network. However, the SSL certificate is currently invalid, and no modern TLS protocols are supported, which significantly impacts the security posture. Security headers are partially implemented, but critical improvements are needed to secure user data and communications. The site integrates marketing and advertising tools including Google Tag Manager and Facebook SDK, with moderate user tracking but lacks a cookie consent mechanism. Overall, the website is professionally designed with good content relevance and navigation, but security and privacy compliance require urgent attention.

35
25
25
75
90
85
100
チケットライブコンサートスポーツ演劇+3 more
jQuerySwiperFlatpickrUnderscore.js+2

Partner Domains:

lawson.co.jp
parent90
unitedcinemas.jp
relatedpending
2025-06-14T12:31:58.617Z
postbillpay.com.au favicon

Australia Post

postbillpay.com.au

68
payment servicesAustralialargeMEDIUM

The website demonstrates a solid foundation in network, email, and SSL/TLS security, indicating good baseline protections. However, significant gaps exist in security headers, GDPR compliance, and adherence to NIS2 cybersecurity frameworks, which together expose the business to legal, reputational, and operational risks. Missing critical headers like Content-Security-Policy and X-Frame-Options leave the site vulnerable to cross-site scripting and clickjacking attacks. The absence of privacy and cookie policies, along with no cookie consent mechanism, poses compliance risks under data protection laws such as GDPR, potentially leading to fines and loss of customer trust. Lack of documented security policies, incident response procedures, and business continuity planning increases the risk of inadequate response to cyber incidents, threatening business operations. DNSSEC is not enabled, which could allow DNS spoofing attacks. Addressing these issues will significantly strengthen security posture, reduce compliance risks, and protect the organization from both cyber threats and regulatory penalties. Immediate focus on privacy policies, security headers, and incident response frameworks is recommended. Overall, the current posture requires urgent remediation to align with industry standards and legal requirements.

25
25
25
100
95
90
100
AngularJS (ng-app, ng-bind, ng-strict-di, ng-cloak)Adobe DTM (adobedtm script)jQueryMoment.js+5

Partner Domains:

auspost.com.au
partner70
bpay.com.au
paymentanalyzing...
2025-06-13T20:21:40.291Z
barclayscorporate.com favicon

Barclays Bank PLC

barclayscorporate.com

70
bankingUnited KingdomenterpriseMEDIUM

The website exhibits a concerning security posture with no critical issues but multiple high and medium severity vulnerabilities, particularly in security headers, GDPR compliance, and NIS2 regulatory adherence. The absence of key security headers like Content-Security-Policy and X-Frame-Options exposes the site to clickjacking and content injection attacks, increasing the risk of data breaches and reputational damage. GDPR compliance gaps, including missing privacy and cookie policies along with the lack of a consent banner, expose the business to regulatory fines and customer trust erosion. NIS2-related deficiencies such as missing security frameworks, incident response procedures, and security documentation highlight significant operational risks and non-compliance with important EU cybersecurity regulations. While email security, SSL/TLS, DNS health, and network security are relatively strong, the overall low scores in governance and protective controls indicate urgent attention is needed. Addressing these issues will not only enhance security but also ensure regulatory compliance and protect the business’s brand reputation. Immediate remediation will reduce legal risks and improve stakeholder confidence in the company’s cybersecurity maturity.

35
40
30
85
97
90
100
bankingfinancial servicescorporate bankinginvestmentprivate banking
Adobe Helix RUM JSjQueryAdobe DTM (Dynamic Tag Manager)Modernizr+3

Partner Domains:

barclays.co.uk
subsidiarypending
barclayscard.co.uk
subsidiarypending

+3 more partners

2025-06-13T18:12:28.978Z
johnsoncontrols.com favicon

Johnson Controls

johnsoncontrols.com

68
Building Automation and ControlsUnited StatesenterpriseMEDIUM

The website demonstrates a moderate security posture with no critical vulnerabilities found; however, several high and medium-risk issues significantly impact compliance and risk management. Key deficiencies exist in GDPR compliance, including the absence of privacy and cookie policies and lack of user consent mechanisms, exposing the business to regulatory penalties and reputational damage. The absence of a documented information security framework, incident response procedures, and security policies under NIS2 guidance further increases organizational risk and may hinder regulatory adherence. Security headers are inconsistently implemented, reducing protection against common web threats like XSS and content sniffing. SSL/TLS configurations are generally strong but require timely certificate renewal and elimination of mixed content to maintain secure communications. DNS settings are mostly healthy but can be improved by enabling DNSSEC to prevent domain spoofing. Positively, email and network security postures are robust, mitigating some external attack vectors. Overall, urgent attention to compliance and governance-related controls is critical to safeguard the business and maintain trust with users and regulators.

60
25
25
100
80
85
100
OpenBlueArtificial IntelligenceHealthy BuildingsAI in Building ManagementNet Zero Buildings+4 more
jQueryBootstrap 4Coveo SearchGoogle Maps API+15
2025-06-13T18:10:48.990Z