Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 41 of 67|Showing 2001-2050 of 3338
rba.gov.au favicon

Reserve Bank of Australia

rba.gov.au

70
GovernmentAustralialargeMEDIUM

The Reserve Bank of Australia (RBA) is the nation's central bank responsible for conducting monetary policy, maintaining financial system stability, issuing currency, and providing banking services to the government. The website serves a broad audience including the Australian public, financial institutions, government entities, researchers, and educators. It provides authoritative content on economic conditions, policy decisions, and financial infrastructure. The RBA holds a dominant market position as the sole central bank in Australia, with a large organizational size and a history dating back to 1959. Technically, the website employs modern JavaScript libraries and trusted analytics tools such as Microsoft Clarity, Google Tag Manager, and LinkedIn Insight Tag. The site is well-optimized for performance, mobile responsiveness, and accessibility, with a professional and consistent design. However, it uses a custom or undisclosed CMS and does not explicitly declare some security headers, which could be improved. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. It uses secure forms and trusted third-party scripts but lacks explicit security policies and incident response contacts. The WHOIS data is limited due to Australian domain registry policies but aligns with the official government entity status, supporting legitimacy. No WAF or blocking mechanisms were detected, and no vulnerabilities were found in the content. Overall, the RBA website demonstrates a high level of professionalism, security, and compliance with minor gaps in privacy consent mechanisms and explicit security headers. It is a trustworthy and authoritative source of information for its stakeholders.

50
53
17
85
90
75
100
governmentcentralbankmonetarypolicyfinancialstabilitybanknotes+3 more
JavaScriptGoogle Tag ManagerMicrosoft ClarityYouTube API+1

Partner Domains:

banknotes.rba.gov.au
partner
museum.rba.gov.au
partner

+3 more partners

2025-07-27T12:57:27.032Z
syftdata.com favicon

Syft Data, Inc.

syftdata.com

10
TechnologyN/asmallCRITICAL

Syft Data, Inc. operates a sophisticated AI-powered SaaS platform designed to identify high-intent person-level leads from inbound website traffic and LinkedIn engagements. Their solution enables marketing and growth teams to uncover anonymous visitors, enrich signups, and orchestrate multi-channel outreach campaigns in real time, thereby maximizing revenue opportunities. Positioned as a lean and fast-moving technology provider, Syft emphasizes automation and data-driven decision-making to accelerate pipeline growth. Technically, the website is built on a modern Next.js framework with React, leveraging third-party services such as Cookiebot for consent management and Google Tag Manager for analytics. The site is well-optimized for mobile devices, features good SEO practices, and integrates multiple marketing and tracking tools. Performance is moderate with a clean, professional design and clear navigation. From a security perspective, the site enforces HTTPS and uses consent management to comply with GDPR. However, it lacks explicit security headers and a public security policy or incident response page. No vulnerabilities or exposed sensitive data were detected in the HTML content. The absence of WHOIS data for the domain is a notable gap, raising questions about domain registration transparency. Overall, Syft presents a credible and professional online presence with strong business and privacy compliance indicators. The main risk lies in the missing WHOIS information, which should be investigated further to confirm domain legitimacy and ownership. Strategic improvements in security policy transparency and header implementation would enhance trust and security posture.

-
-
-
-
-
-
-
aileadgenerationmarketingautomationb2bsaas+3 more
Next.jsReactCookiebotGoogle Tag Manager+1

Partner Domains:

getsyft.app
partner
2025-07-27T12:51:24.313Z
fitt.co favicon

Fitt.co

fitt.co

63
HealthcareUnited StatesmediumMEDIUM

Fitt.co is a US-based unified holding company focused on the health and wellness industry. Founded in 2015 and led by experienced operators, it creates, acquires, and invests in next-generation health brands. The company operates multiple branded subsidiaries including media, recruiting, consulting, capital investment, and event platforms, positioning itself as a distribution-first platform embedded in the wellness ecosystem. The website targets executives, founders, operators, and investors seeking knowledge, connections, and resources in health and wellness. Technically, the site is built on WordPress with common plugins like Contact Form 7 and Yoast SEO, and uses Google Tag Manager and LinkedIn Insight for analytics and tracking. The site is mobile optimized and professionally designed, with good SEO practices. Security posture is moderate with HTTPS enabled but lacks DNSSEC and some security headers, and uses an outdated jQuery version which poses risks. Privacy compliance is basic with a privacy policy found but no cookie consent mechanism or explicit GDPR compliance indicators. Contact information is limited to a web form with no direct emails or phone numbers publicly listed. Overall, the site is credible and professional but could improve security and privacy practices.

15
53
17
85
72
85
100
healthwellnessinvestmentconsultingmedia+3 more
WordPressContact Form 7Google Tag ManagerLinkedIn Insight Tag+2

Partner Domains:

insider.fitt.co
subsidiary
wellworthy.com
subsidiary

+3 more partners

2025-07-27T11:48:25.716Z
stack-ai.com favicon

Stack AI

stack-ai.com

71
TechnologyUnited StatessmallMEDIUM

Stack AI operates as a no-code AI platform enabling users to build AI-powered applications and agents tailored for education, healthcare, and enterprise workflows. The company positions itself as a versatile and powerful enterprise AI solution provider with a drag-and-drop interface, targeting organizations seeking to deploy AI without extensive coding expertise. The website reflects a professional and consistent brand presence with active social media channels on LinkedIn, Twitter (X), and YouTube, supporting its market positioning. Technically, the website is built using Framer, a modern web design and CMS platform, and integrates multiple analytics and tracking tools including Google Analytics, PostHog, Ahrefs Analytics, and LinkedIn Insight Tag. The site is mobile-optimized with good SEO practices and moderate performance. However, there is no explicit hosting provider or backend technology disclosed. The absence of privacy and cookie policies indicates a gap in privacy compliance. From a security perspective, the site uses HTTPS but lacks visible security headers and formal security or incident response policies. No vulnerabilities or exposed sensitive data were detected in the HTML content. The WHOIS data is missing or indicates the domain may not be registered, which raises concerns about domain legitimacy and trustworthiness. This discrepancy between an active professional website and absent WHOIS data suggests the need for further verification. Overall, Stack AI presents a credible business front with solid technical implementation but requires improvements in privacy compliance, security transparency, and domain registration legitimacy to enhance trust and reduce risk.

40
70
47
85
72
90
100
aienterpriseno-codeeducationhealthcare+1 more
Google AnalyticsGoogle Tag ManagerLinkedIn Insight TagPostHog+2
2025-07-27T11:48:20.707Z
creativedestructionlab.com favicon

Creative Destruction Lab

creativedestructionlab.com

58
TechnologyCanadamediumMEDIUM

Creative Destruction Lab (CDL) is a well-established nonprofit organization founded in 2012 at the Rotman School of Management, University of Toronto. It operates a global accelerator program focused on seed-stage, science- and technology-based companies, offering mentorship and objectives-based support across multiple streams and international locations. The website reflects a mature digital presence with strong academic partnerships and a professional brand image. The content is rich, relevant, and targeted at entrepreneurs and innovators in technology sectors. Technically, the website is built on WordPress with a modern tech stack including Yoast SEO, Google Analytics, and various marketing and tracking tools. Hosting is via DigitalOcean, and the site is mobile-optimized with good accessibility and SEO practices. However, some security enhancements such as enabling DNSSEC and implementing HTTP security headers are recommended to strengthen the security posture. Security-wise, the site uses HTTPS and employs multiple third-party analytics and marketing scripts, indicating extensive user tracking. While no critical vulnerabilities or exposed sensitive data were found, the absence of cookie consent mechanisms and explicit security policies suggests room for improvement in privacy compliance. The WHOIS data is consistent and trustworthy, supporting the legitimacy of the domain and organization. Overall, CDL's website demonstrates a strong business credibility and digital maturity, with minor technical and security improvements recommended to enhance trust and compliance.

25
53
2
75
47
80
100
nonprofitacceleratortechnologystartupentrepreneurship+3 more
WordPressYoast SEOjQueryIsotope.js+9

Partner Domains:

rotman.utoronto.ca
partner
sauder.ubc.ca
partner

+3 more partners

2025-07-27T10:37:43.697Z
incard.co favicon

Incard Ltd

incard.co

49
FinanceUnited KingdomsmallHIGH

Incard Ltd operates a specialized financial platform tailored for ecommerce businesses, offering multi-currency business accounts, corporate Visa Platinum cards with cashback and rewards, expense management, accounting automation, and financial analytics. Positioned as a fintech innovator, Incard targets ecommerce entrepreneurs seeking streamlined financial operations and enhanced visibility into their cash flow and advertising spend. The company leverages partnerships with Currency Cloud, Visa, and TrueLayer to provide regulated payment and account information services, reinforcing its credibility in the financial sector. Technically, the website is built on a modern React and Next.js stack, hosted on Vercel, and integrates multiple analytics and marketing tools such as Google Tag Manager, Facebook Pixel, Hotjar, and Intercom. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, contributing to a professional user experience. Security posture is strong with HTTPS enforcement, comprehensive security headers, and no visible vulnerabilities or exposed sensitive data. Privacy compliance is supported by detailed privacy and cookie policies, though an explicit cookie consent mechanism is not detected. WHOIS data is privacy protected, which is justified for a fintech company, though it limits direct registrant verification. Overall, Incard presents a trustworthy and professional digital presence with a solid foundation for ecommerce financial services.

-
-
-
52
72
80
100
fintechecommercebusinessaccountscorporatecardsfinancialanalytics+2 more
ReactNext.jsVercel hostingGoogle Tag Manager+4

Partner Domains:

currencycloud.com
partner
visa.com
partner

+1 more partners

2025-07-27T09:20:29.572Z
S

Stfalcon LLC

stfalcon.com

69
TransportationEstoniamediumMEDIUM

Stfalcon LLC is a well-established software development company specializing in custom solutions for the transportation and logistics sector. With over 15 years of experience, the company offers a broad range of services including mobile and web app development, AI-powered workflows, blockchain, IoT, and cybersecurity. Their market position is strong, supported by a portfolio of major clients such as Ecolines and Nova Poshta, and an ISO 9001:2015 certification that underscores their commitment to quality. The company targets transportation and logistics businesses globally, providing scalable and tailored technology solutions. Technically, the website demonstrates a mature digital infrastructure with modern JavaScript libraries, multiple analytics and marketing integrations, and hosting on AWS infrastructure. The site is fast, mobile-optimized, and SEO-friendly, reflecting a high level of digital maturity. However, there is room for improvement in security headers and DNSSEC implementation. From a security perspective, the company shows good practices including HTTPS enforcement, ISO certification, and cookie consent mechanisms. No critical vulnerabilities or exposed sensitive data were detected. The absence of a security.txt file and explicit incident response contacts suggests an opportunity to enhance transparency and readiness. Overall, the security posture is solid but could be strengthened with additional headers and formal vulnerability disclosure policies. The overall risk assessment is low, with a trustworthy domain registration history and consistent business information. Strategic recommendations include implementing security headers, publishing a security.txt file, and enhancing incident response communication to further improve trust and compliance.

25
68
47
75
72
80
100
transportationlogisticssoftwaredevelopmentcustomsoftwaremobileapps+2 more
JavaScriptjQueryGoogle Tag ManagerGoogle Analytics+4
2025-07-27T09:02:35.294Z
mlh.io favicon

Major League Hacking

mlh.io

66
EducationN/alargeMEDIUM

Major League Hacking (MLH) operates as the official collegiate hackathon league, providing a comprehensive platform for students and organizers to engage in hackathons globally. The organization offers key services including hackathon event management, job and internship opportunities, educational resources, and community-building events such as Global Hack Week. MLH holds a strong market position as a leading entity in the student hackathon ecosystem, supported by a large, active community and partnerships with major technology companies. The website reflects a mature digital presence with professional design, clear navigation, and extensive content relevant to its target audience of students and tech enthusiasts. Technically, the website employs a modern technology stack including JavaScript frameworks, Google Charts, and multiple analytics and marketing tools such as Facebook Pixel and LinkedIn Insight Tag. It is hosted behind Cloudflare DNS and CDN services, ensuring good performance and availability. The site is mobile-optimized and accessible, with SEO best practices observed through proper meta tags and structured content. The use of Ruby on Rails components is inferred from CSRF tokens and High Voltage gem usage. From a security perspective, MLH enforces HTTPS and uses CSRF tokens to protect forms, indicating a solid baseline security posture. However, the absence of DNSSEC and explicit security headers such as Content Security Policy or HSTS represents areas for improvement. Privacy compliance is partially addressed with a clear privacy policy and terms of service, but the lack of a cookie consent mechanism may pose GDPR compliance risks. No vulnerability disclosure or incident response information is publicly available, suggesting an opportunity to enhance transparency and security culture. Overall, MLH presents a trustworthy and professional online presence with strong business credibility and community trust. Strategic recommendations include enabling DNSSEC, implementing security headers, adding a cookie consent mechanism, and publishing vulnerability disclosure policies to further strengthen security and compliance posture.

55
53
17
75
65
80
100
hackathoneducationtechnologystudentcommunity+3 more
JavaScriptGoogle ChartsFacebook PixelGoogle Tag Manager+3

Partner Domains:

digitalocean.com
partner
mongodb.com
partner
2025-07-27T05:38:12.637Z
runforsomething.net favicon

Run For Something

runforsomething.net

58
Non-profitN/amediumMEDIUM

Run For Something is a non-profit political action committee focused on recruiting and supporting young progressive leaders to run for state and local offices. The organization provides candidate recruitment, support systems, volunteer coordination, fundraising, and educational resources to build long-term political power. Their market position is niche and specialized within the progressive political landscape. The website is built on WordPress with a modern tech stack including Gravity Forms, Yoast SEO, and multiple analytics and marketing tools such as Google Analytics, Facebook Pixel, LinkedIn Insight Tag, and Mixpanel. Hosting and DNS services are managed via Cloudflare, providing good performance and security. The security posture is generally good with HTTPS enforced and domain transfer protections in place, but lacks DNSSEC and security headers, and does not have a published security or incident response policy. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism despite extensive tracking. Contact information is available primarily via email and web forms, with no phone numbers or physical addresses listed. Overall, the website is professional, trustworthy, and well-branded, serving its target audience effectively.

15
53
2
75
62
75
100
non-profitpoliticscandidaterecruitmentprogressivepoliticalactioncommittee+3 more
WordPressGravity FormsYoast SEOGoogle Tag Manager+4

Partner Domains:

secure.actblue.com
partner
runforsomething.medium.com
related

+2 more partners

2025-07-26T22:48:28.316Z
donorperfect.com favicon

SofterWare, Inc.

donorperfect.com

67
Non-profitUnited StateslargeMEDIUM

DonorPerfect, operated by SofterWare, Inc., is a leading provider of fundraising software tailored for nonprofit organizations. The company offers a comprehensive suite of tools including donor management, online donation forms, payment processing, event management, and marketing automation. Trusted by over 75,000 nonprofit professionals, DonorPerfect holds a strong market position with a focus on enabling nonprofits to raise more funds efficiently. The website reflects a mature digital presence with integrated marketing and analytics technologies, professional design, and extensive customer support resources. Technically, the site is built on WordPress with modern integrations such as Gravity Forms and various tracking pixels, ensuring a robust and scalable platform. Security posture is solid with HTTPS and spam protection via hCaptcha, though some security headers and explicit incident response policies are not evident. Privacy compliance is partially addressed with a comprehensive privacy policy and GDPR indications, but lacks a visible cookie consent mechanism. Overall, the domain WHOIS data is unavailable, which slightly impacts transparency but does not detract from the site's legitimacy given its professional presentation and business consistency.

15
65
47
70
77
80
100
fundraisingnonprofitdonormanagementcrmonlinedonations+2 more
WordPressGravity FormsjQueryGoogle Tag Manager+7

Partner Domains:

pardot.donorperfect.com
partner
softerware.my.site.com
partner
2025-07-26T19:11:31.912Z
talentegy.com favicon

Talentegy, Inc.

talentegy.com

68
TechnologyN/amediumMEDIUM

Talentegy, Inc. operates a specialized Talent Experience Management platform designed to optimize recruiting and talent management processes by providing actionable insights across the employee lifecycle. The company targets HR professionals and organizations seeking to enhance candidate and employee experiences through data-driven analytics and engagement metrics. Recognized with industry awards, Talentegy positions itself as an innovative leader in recruitment marketing technology. Technically, the website is built on the HubSpot CMS platform, leveraging modern JavaScript libraries and marketing automation tools such as Google Analytics and LinkedIn Insight. The site demonstrates good mobile optimization, clear navigation, and professional design, supporting a positive user experience. Privacy and cookie policies are present and indicate GDPR compliance, enhancing trust and regulatory adherence. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms but lacks visible security headers and published security policies or incident response contacts. The absence of WHOIS domain registration data raises concerns about domain legitimacy, although the website content and external references suggest a legitimate business entity. Overall, the security posture is moderate with room for improvement in transparency and technical safeguards. Strategically, Talentegy should prioritize publishing comprehensive security policies, implementing standard security headers, and resolving domain registration visibility issues to strengthen trustworthiness. Enhancing incident response readiness and vulnerability disclosure practices will further improve the security culture and compliance posture, supporting sustainable growth and customer confidence.

45
83
17
70
75
75
100
talentanalyticshrtechnologycandidateexperienceemployeeexperiencetalentmanagement+2 more
HubSpot CMSjQueryFontAwesomeIsotope Layout+6

Partner Domains:

www.employinc.com
parent
2025-07-26T19:10:05.780Z
evensi.com favicon

Events.com Inc.

evensi.com

67
OtherUnited StateslargeMEDIUM

Events.com Inc. operates a large-scale global event discovery and ticketing platform, offering users access to over 186 million events worldwide. The platform targets a broad audience interested in music, culture, business networking, nightlife, sports, and leisure activities. Key services include event discovery by location and category, ticket sales, event promotion, and calendar integration. The company maintains a consistent brand presence and provides clear contact information, enhancing user trust. Technically, the website employs a modern tech stack including Google Tag Manager, Google Analytics, Facebook Pixel, and other marketing and tracking tools. It uses Vue.js for frontend interactivity and integrates Google Maps API for location services. The site is mobile-optimized, fast-loading, and SEO-friendly, with good accessibility features. From a security perspective, the site uses HTTPS with secure cookie settings and implements consent management via Usercentrics. While explicit security headers are not fully visible in the HTML, best practices such as nonce usage in OAuth2 SSO flows are observed. No critical vulnerabilities or exposed sensitive data were detected. Privacy policies and terms of service are present and comprehensive, indicating good compliance with GDPR and related regulations. Overall, the website presents a low-risk profile with strong business credibility and technical maturity. Recommendations include enhancing visible security headers, publishing a security policy and incident response contacts, and establishing a vulnerability disclosure program to further strengthen security posture.

75
53
17
60
72
75
100
eventsticketingeventdiscoverymusicculture+5 more
Google Tag ManagerGoogle AnalyticsFacebook PixelSnapchat tracking+6

Partner Domains:

eventsdotcomhelp.zendesk.com
service
org.events.com
partner

+3 more partners

2025-07-26T18:02:02.328Z
abr.ge favicon

Airbridge

abr.ge

69
TechnologyN/amediumMEDIUM

Airbridge is a technology SaaS company specializing in marketing attribution and analytics, providing a unified platform to measure conversions, link multiple platforms, and deliver full-funnel insights without paywalls. The company targets digital marketers, app developers, and advertisers, offering key services such as web and app attribution, ROAS measurement, iOS SKAN support, fraud protection, and AI-driven marketing insights. The website demonstrates a strong market position with partnerships including Facebook, Google, and TikTok, and features comprehensive case studies and resources to support customers. Technically, the website is built on Webflow CMS and leverages a modern technology stack including Google Tag Manager, Google Analytics, Amplitude, Hotjar, Intercom, and Cloudflare Turnstile for security. The site is well-optimized for performance, mobile responsiveness, accessibility, and SEO, reflecting a mature digital infrastructure. From a security perspective, Airbridge employs HTTPS with excellent SSL configuration, implements multiple security headers, and integrates CAPTCHA and cookie consent mechanisms. While no critical vulnerabilities were detected, the site could improve transparency by publishing incident response contacts and a vulnerability disclosure policy. Overall, the website is professional, trustworthy, and secure, with a high AI-assessed quality score. The lack of public WHOIS data is mitigated by the company's evident legitimacy and strong trust signals. Strategic recommendations include enhancing incident response visibility, formalizing vulnerability disclosures, and clarifying data retention policies to further strengthen security and compliance posture.

15
100
47
50
72
80
100
marketingattributionanalyticsdeeplinkingfraudprotection+3 more
Webflow CMSGoogle Tag ManagerGoogle AnalyticsAmplitude Analytics+6
2025-07-26T18:01:17.180Z
datastax.com favicon

DataStax

datastax.com

70
TechnologyN/aenterpriseMEDIUM

DataStax is an enterprise technology company specializing in AI-optimized database platforms and cloud-native solutions. Their flagship product, Astra DB, is designed for ultra-low latency and scalability, targeting developers and enterprises building production-ready AI applications. The website reflects a mature digital presence with a focus on AI and cloud technologies, positioning DataStax as a leader in the technology sector. The company leverages modern web frameworks and integrates multiple analytics and marketing tools to optimize user engagement and business intelligence. Technically, the website is built on Next.js and React, indicating a modern and performant infrastructure. The site is well-optimized for mobile and accessibility, with comprehensive SEO and metadata implementation. Security best practices are evident through HTTPS enforcement and multiple security headers, although explicit security policies and incident response details are not publicly disclosed. The absence of WHOIS data limits domain registration trust analysis, but the overall site professionalism and security posture suggest a legitimate and trustworthy enterprise. Security-wise, the site demonstrates strong HTTPS and header configurations, uses secure forms with consent mechanisms, and avoids exposing sensitive data. However, the lack of publicly available security policies and vulnerability disclosure programs indicates areas for improvement. Privacy compliance is well addressed with clear privacy and cookie policies, including GDPR considerations. Overall, DataStax's website presents a high-quality, secure, and professional digital front that supports its enterprise business model. Strategic recommendations include publishing detailed security and incident response policies, establishing a vulnerability disclosure program, and enhancing transparency around certifications and compliance frameworks to further strengthen trust and security posture.

65
53
2
85
87
85
100
aidatabasecloudenterprisetechnology+3 more
ReactNext.jsGoogle Tag ManagerSegment Analytics+6
2025-07-26T17:58:17.904Z
realdirtonfarming.ca favicon

Farm & Food Care

realdirtonfarming.ca

58
EducationCanadamediumMEDIUM

The Real Dirt on Farming website is an educational platform operated by Farm & Food Care, focusing on informing Canadians about food production, farming sustainability, food safety, and agricultural careers. The site targets the general Canadian public interested in understanding the origins and impacts of their food. It provides well-structured content including articles, current issues, and career profiles, supported by a consistent brand identity and partner organizations. Technically, the website is built on WordPress with WooCommerce and uses modern SEO and analytics tools such as Yoast SEO, Google Analytics, Hotjar, and Facebook Pixel. The site is mobile-optimized and performs moderately well, though there is room for improvement in accessibility and performance tuning. The use of structured data enhances search engine visibility. From a security perspective, the site uses HTTPS with good SSL configuration but lacks visible security headers and a formal privacy or cookie policy on the homepage. No WHOIS data was retrievable for the domain, which is unusual and reduces trust slightly, though the site’s professional presentation and organizational backing mitigate concerns. There is no visible incident response or vulnerability disclosure information. Overall, the website is a credible, professional educational resource with moderate technical maturity and a good security baseline. Strategic improvements in privacy compliance, security headers, and WHOIS transparency would enhance trust and compliance.

30
35
2
85
65
75
100
agricultureeducationcanadianfarmssustainabilityfoodsafety+1 more
WordPress 6.8.2WooCommerce 10.0.4Yoast SEO pluginGoogle Tag Manager+5

Partner Domains:

www.farmfoodcareon.org
partner
www.farmfood360.ca
partner

+1 more partners

2025-07-26T17:57:17.534Z
crowdchange.ca favicon

CrowdChange

crowdchange.ca

71
TechnologyN/amediumMEDIUM

CrowdChange is a professional fundraising software provider focused on delivering advanced technology solutions to nonprofits, fraternities, sororities, academic institutions, and athletic programs. Their platform offers a comprehensive suite of fundraising tools including peer-to-peer campaigns, event ticketing, online donations, and integrations with third-party payment and donation services. Positioned as a market leader in North America, CrowdChange emphasizes customer support and ease of campaign setup to maximize fundraising success. Technically, the website is built on the Duda platform, leveraging modern web technologies such as service workers for offline support, and integrates multiple analytics and marketing tools including Google Analytics, Facebook Pixel, LinkedIn Insight Tag, and ZoomInfo Pixel. The site is mobile optimized with good SEO and accessibility basics, though some security headers could be improved. From a security perspective, the site enforces HTTPS and uses secure forms with CAPTCHA, but lacks visible security policies, incident response contacts, and vulnerability disclosure mechanisms. The absence of a cookie consent banner may pose privacy compliance risks. WHOIS data is unavailable due to privacy protection, which is common but reduces transparency. Overall, CrowdChange presents a trustworthy and professional online presence with strong business credibility and technical maturity. Strategic improvements in privacy compliance and security headers would enhance their security posture and regulatory adherence.

70
53
2
100
72
85
100
fundraisingnonprofitsoftwaredonationspeer-to-peer+5 more
Google AnalyticsFacebook PixelLinkedIn Insight TagZoomInfo Pixel+4
2025-07-26T16:52:02.106Z
greetinghr.com favicon

그리팅

greetinghr.com

59
TechnologySouth KoreamediumMEDIUM

GreetingHR is a Korean technology company operating under the legal name (주)두들린, founded in 2020. It provides SaaS solutions focused on recruitment management (ATS) and talent relationship management (TRM), serving over 7,000 corporate clients. The website is professionally designed, primarily in Korean, targeting businesses seeking to enhance their hiring processes with innovative recruitment tools. The company maintains an active presence on social media platforms such as Facebook and LinkedIn, and operates a company blog to engage its audience. Technically, the website leverages modern tracking and analytics technologies including Google Tag Manager, Facebook Pixel, LinkedIn Insight Tag, Microsoft Clarity, and Google Analytics. It is built using the Framer platform, which supports responsive design and good SEO practices. The site is served over HTTPS, ensuring secure communication, though explicit security headers and policies are not evident in the provided data. From a security perspective, the website demonstrates basic best practices such as HTTPS usage and absence of exposed sensitive data. However, it lacks visible security policies, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for enhanced trust and compliance. The WHOIS data for the domain is unavailable, indicating privacy protection or unregistered status, which slightly reduces domain trustworthiness despite the professional web presence. Overall, GreetingHR presents a credible and professional business front with solid technical implementation but would benefit from improved transparency in domain registration and enhanced security and privacy disclosures to strengthen user trust and compliance posture.

40
53
2
70
52
80
100
ats
Google Tag ManagerFacebook PixelLinkedIn Insight TagMicrosoft Clarity+3
2025-07-26T16:49:05.439Z
hemophilia.ca favicon

Canadian Hemophilia Society

hemophilia.ca

51
HealthcareCanadamediumMEDIUM

The Canadian Hemophilia Society website serves as a digital platform for a non-profit organization dedicated to supporting individuals affected by hemophilia and other bleeding disorders in Canada. The site provides educational resources, advocacy information, and support services aimed at patients, families, and healthcare professionals. The organization positions itself as a trusted national entity in the healthcare non-profit sector, focusing on improving quality of life through awareness and community engagement. Technically, the website is built on WordPress using the Avada theme, incorporating modern web technologies and multiple analytics and tracking tools such as Google Analytics, Facebook Pixel, and LinkedIn Insight Tag. The site demonstrates good mobile optimization and SEO practices, although some accessibility features could be enhanced. Performance is moderate, with asynchronous loading of scripts to improve user experience. From a security perspective, the site enforces HTTPS and uses standard security practices but lacks visible security headers and a published security or incident response policy. No vulnerabilities or exposed sensitive data were detected in the analyzed content. Privacy compliance is basic, with no explicit privacy or cookie policies found in the provided content, which could be improved to meet GDPR and other regulations. Overall, the website presents a professional and trustworthy front for the Canadian Hemophilia Society, with a solid business credibility score. However, improvements in privacy disclosures, security headers, and incident response transparency are recommended to enhance trust and compliance.

15
80
25
85
62
70
-
healthcarenon-profithemophiliaadvocacyeducation+1 more
WordPressAvada ThemePHPJavaScript+4
2025-07-26T13:25:54.559Z
D

Diabetes Canada

diabetes.ca

70
HealthcareCanadalargeMEDIUM

Diabetes Canada is a well-established non-profit organization dedicated to diabetes research, advocacy, education, and support within Canada. The website reflects a professional and consistent brand presence targeting individuals affected by diabetes, healthcare professionals, and researchers. The organization operates with a long-standing domain registered since 2000, indicating stability and trustworthiness. Technically, the website employs a variety of modern marketing and analytics technologies including Google Tag Manager, Google Analytics, Facebook Pixel, and others, indicating a mature digital infrastructure. The site is hosted under a Canadian registrar and uses HTTPS, but lacks DNSSEC and explicit security headers based on the provided data. Mobile optimization and accessibility appear to be good, enhancing user experience. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks visible security policies, incident response contacts, and vulnerability disclosure mechanisms. Privacy compliance is weak due to the absence of explicit privacy and cookie policies or consent mechanisms. The extensive use of third-party tracking scripts suggests a moderate to extensive user tracking level, which may raise privacy concerns. Overall, the website is professional and trustworthy but would benefit from improved privacy compliance and enhanced security practices. Strategic recommendations include publishing comprehensive privacy and cookie policies, enabling DNSSEC, implementing security headers, and establishing clear incident response and vulnerability disclosure channels.

60
65
17
85
77
80
100
healthcarenon-profitdiabeteseducationresearch+1 more
Google Tag ManagerGoogle AnalyticsFontAwesomeUserWay accessibility widget+8
2025-07-26T13:25:44.450Z
thepmcf.ca favicon

The Princess Margaret Cancer Foundation

thepmcf.ca

65
HealthcareCanadamediumMEDIUM

The Princess Margaret Cancer Foundation is a well-established Canadian non-profit organization dedicated to raising funds for cancer research and treatment. The foundation supports the Princess Margaret Cancer Centre through various fundraising events such as the home lottery and the Ride to Conquer Cancer. The website reflects a professional and consistent brand image targeting donors, patients, and the healthcare community. The domain age and registration details align with the organization's history and location, reinforcing legitimacy. Technically, the website is built on the Kentico CMS platform and integrates multiple modern marketing and analytics technologies including Google Tag Manager, Facebook Pixel, LinkedIn Insight Tag, and Cookiebot for consent management. The site demonstrates good mobile optimization, accessibility, and SEO practices, although performance is moderate. Hosting appears to be linked to University Health Network infrastructure, consistent with the healthcare focus. From a security perspective, the website employs HTTPS with good SSL configuration and uses cookie consent mechanisms to comply with privacy regulations. Security headers and CSRF protections are present, but DNSSEC is not enabled, which is a recommended improvement. No critical vulnerabilities or exposed sensitive data were detected. However, the site lacks explicit security policies, incident response contacts, and vulnerability disclosure information. Overall, the website presents a low-risk profile with strong business credibility and privacy compliance. Strategic recommendations include enabling DNSSEC, publishing terms of service and security policies, and enhancing transparency around incident response and vulnerability disclosures to further strengthen trust and security posture.

15
83
17
70
72
80
100
princessmargaretcancerresearchconquercancercancercharityfundraising
Kentico CMSCookiebotGoogle Tag ManagerFacebook Pixel+4
2025-07-26T12:19:10.678Z
lumalabs.ai favicon

Luma AI

lumalabs.ai

68
TechnologyIcelandsmallMEDIUM

Luma AI is a technology startup founded in 2021 specializing in AI-driven video generation and animation tools. Their flagship products include Ray2, a large-scale video generative model, and Dream Machine, a platform enabling creators to generate and modify videos using AI. The company targets creators, developers, and enterprises seeking next-generation storytelling tools leveraging AI. Their market position is that of an innovative provider with proprietary AI models and a growing presence in the AI creative tools space. Technically, the website is built on a modern stack including Next.js and React, hosted on Vercel, and integrates multiple analytics and marketing tools such as HubSpot, Google Tag Manager, Apollo.io, and social media pixels. The site is fast, mobile-optimized, and SEO-friendly, reflecting a mature digital infrastructure for a startup. From a security perspective, the site enforces HTTPS, employs standard security headers, and uses domain privacy protection. However, it lacks publicly available security policies, incident response contacts, and vulnerability disclosure mechanisms. No critical vulnerabilities or exposures were detected. Privacy compliance is strong with clear privacy and cookie policies and consent mechanisms. Overall, Luma AI presents a professional and trustworthy online presence with strong technical and privacy practices. The absence of direct contact information and security policy details are minor gaps. Strategic recommendations include enabling DNSSEC, publishing security and incident response policies, and adding vulnerability disclosure information to enhance trust and security posture.

50
68
17
75
72
75
100
aivideogenerationtechnologymachinelearningcreativetools
Next.jsReactVercel AnalyticsHubSpot Analytics+4
2025-07-26T11:10:36.852Z
lttr.ai favicon

1357356 B.C. LTD.

lttr.ai

64
TechnologyCanadasmallMEDIUM

Missinglettr.com is a well-established SaaS platform founded in 2014, specializing in social media marketing automation. The company, legally registered as 1357356 B.C. LTD., offers a comprehensive suite of tools including automated drip campaigns, content curation, social media calendar, and analytics to help content creators and marketing teams grow their brand presence efficiently. The platform targets content-focused teams and creators, positioning itself as a competitive alternative to other social media management tools. The website demonstrates a high level of professionalism with excellent content quality, clear navigation, and strong branding consistency. Technically, the website employs a modern technology stack including jQuery, Bootstrap, and integrates multiple analytics and marketing tools such as Google Analytics, Facebook Pixel, Hotjar, and FullStory. It is hosted behind Cloudflare DNS and CDN services, ensuring good performance and security. The site is mobile-optimized and SEO-friendly, although some accessibility features could be enhanced. Security practices include HTTPS enforcement, CSRF protection on forms, and a cookie consent mechanism, but could benefit from additional security headers and a published security.txt file. The security posture is solid with no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with comprehensive privacy and cookie policies, GDPR compliance indicators, and user consent mechanisms. Business credibility is high, supported by clear company information, testimonials, and trust signals such as Product Hunt recognition. No suspicious or malicious activity was detected. Overall, Missinglettr.com presents a low-risk profile with a mature digital presence and strong business credibility. Strategic recommendations include enhancing security headers, enabling DNSSEC, publishing vulnerability disclosure information, and improving accessibility to further strengthen trust and compliance.

30
95
2
70
72
55
100
socialmediamarketingautomationsaascontentmarketing+1 more
jQueryGoogle Tag ManagerGoogle AnalyticsFacebook Pixel+5
2025-07-26T11:06:05.828Z
webnamescorporate.com favicon

Webnames Corporate

webnamescorporate.com

67
TechnologyCanadamediumMEDIUM

Webnames Corporate is a specialized division of Webnames.ca Inc., providing expert corporate domain management, SSL lifecycle management, DNS hosting, brand protection, and cybersecurity threat mitigation services. With over 25 years of experience and a strong Canadian market presence, they serve leading corporations, governments, and legal professionals. Their business model focuses on delivering fully managed, secure, and cost-effective domain and security solutions supported by expert account managers. The company holds certifications such as CAMSC, WBE, and ClimateSmart, reinforcing their commitment to quality and responsible business practices. Technically, the website is built on WordPress using the GeneratePress theme, leveraging modern web technologies including lazy loading, Google Fonts, and multiple analytics and marketing tools like Google Analytics, LinkedIn Insight Tag, and Zoho SalesIQ. The site is mobile-optimized, accessible, and SEO-friendly, providing a professional user experience. Security-wise, the site enforces HTTPS, uses domain transfer locks, and provides a cookie consent mechanism. However, DNSSEC is not enabled, and some security headers are missing, representing areas for improvement. Overall, the security posture is solid with good privacy compliance and business credibility. The domain registration details are consistent with the business claims, enhancing trustworthiness. No critical vulnerabilities or suspicious content were detected. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, and enhancing security headers to further strengthen the security posture.

20
68
47
70
77
70
100
domainmanagementbrandsecuritysslmanagementdnshostingcybersecurity+3 more
WordPressGeneratePress themeGoogle FontsZoho SalesIQ+6

Partner Domains:

webnames.ca
parent
2025-07-26T09:57:12.021Z