Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149091
Websites
130
Industries
113
Countries
52
Avg Score
Page 41 of 42|Showing 2001-2050 of 2069
bcbssc.com favicon

BlueCross BlueShield of South Carolina

bcbssc.com

52
HealthcareUnited StateslargeMEDIUM

BlueCross BlueShield of South Carolina is a major regional health insurance provider offering a wide range of health insurance products including individual, family, Medicare, and group health plans. The company serves individuals, families, employers, healthcare providers, and agents primarily in South Carolina. The website reflects a well-structured and professionally branded digital presence consistent with its market position as an independent licensee of the Blue Cross Blue Shield Association. Key services include member management, provider resources, employer services, and agent support. The site integrates multiple external partners and resources to support its offerings. Technically, the website employs modern JavaScript frameworks such as Vue.js and Bootstrap Vue, hosted on IBM WebSphere Portal infrastructure with DNS hosted by Level3. Despite the modern tech stack, the site suffers from slow performance with a page load time exceeding 8 seconds and a large page size. Mobile optimization is good, and SEO practices are adequately implemented. However, the site lacks a valid SSL certificate and does not enable HTTPS, which is a critical security flaw. Security headers are absent, and no advanced TLS protocols or HSTS are configured, exposing the site to potential risks. From a security perspective, the site has strong email authentication with valid SPF and DMARC policies, but the absence of HTTPS and security headers significantly lowers its security posture. No vulnerability disclosure or incident response information is publicly available. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism detected. The site uses multiple analytics and marketing tools including Google Analytics, Adobe Launch, and Qualtrics, indicating moderate user tracking. Overall, the website is professionally designed and content-rich but requires urgent security improvements, especially regarding SSL/TLS implementation and security headers. Enhancing privacy compliance and adding explicit cookie consent would further improve trust. Strategic recommendations include immediate SSL certificate installation, enabling modern TLS protocols, implementing security headers, and publishing a vulnerability disclosure policy to strengthen security culture and compliance.

65
25
25
50
50
75
100
healthinsurancemedicaregrouphealthplansbluecrossblueshieldsouthcarolina+1 more
Vue.jsBootstrap VueAxiosAdobe Launch+5

Partner Domains:

benefitfocus.com
partneranalyzing...
express-scripts.com
partner74

+3 more partners

2025-06-14T20:50:13.007Z
hostinger.com.br favicon

Hostinger

hostinger.com.br

63
TechnologyBrazillargeMEDIUM

Hostinger is a well-established global web hosting and domain registration provider founded in 2004, serving over 3 million users worldwide. The company offers a comprehensive suite of services including shared hosting, VPS, cloud hosting, WordPress optimized hosting, domain registration, and AI-powered website builders. Their market position is strong, supported by numerous trust indicators such as WordPress.org recommendation, Trustpilot reviews, and a 30-day refund policy. Technically, Hostinger employs modern web technologies including Nuxt.js and Vue.js, with integrations for Google Tag Manager, Microsoft Clarity, and Bing Ads, indicating a mature digital infrastructure. Security measures include valid SSL certificates, SPF and DMARC records with strict policies, though improvements can be made by enabling HSTS and DNSSEC. Overall, Hostinger demonstrates a solid security posture with no evident vulnerabilities and a good compliance level. The website is professionally designed, optimized for mobile, and provides a seamless user experience with clear navigation and comprehensive content. Strategic recommendations include enhancing security headers, implementing DNSSEC, and maintaining regular audits of third-party scripts to further strengthen security and trust.

60
25
25
80
67
90
100
webhostingdomainregistrationcloudhostingvpswebsitebuilder+4 more
CloudflareGoogle Tag ManagerGoogle AnalyticsBing Ads+7

Partner Domains:

hostinger.com
partnerpending
reclameaqui.com.br
partnerpending
2025-06-14T18:26:37.520Z
amalytix.com favicon

AMALYTIX GmbH

amalytix.com

54
E-commerceGermanysmallMEDIUM

AMALYTIX GmbH operates a specialized SaaS platform focused on providing Amazon sellers and vendors with comprehensive business intelligence and monitoring tools. Positioned as an official Amazon Software Partner and Amazon Ads Software Partner, AMALYTIX offers a suite of services including Amazon BI dashboards, intelligent alerts, content monitoring, and agency tools. The company targets Amazon marketplace participants primarily in Germany and offers a 14-day free trial to attract users. Their digital presence is robust, featuring bilingual content, extensive knowledge bases, and customer testimonials that reinforce trust and professionalism. Technically, the website leverages modern frameworks such as Nuxt.js and Vue.js, hosted on Netlify Edge, with TailwindCSS for styling and Umami Analytics for privacy-focused user tracking. While the site demonstrates good SEO, mobile optimization, and user experience, performance metrics are moderate, and accessibility is basic. The SSL configuration is notably deficient, with no valid certificate and no modern TLS protocols enabled, posing a significant security risk. From a security perspective, the site implements some best practices such as HSTS headers but lacks a valid SSL certificate, OCSP stapling, session resumption, and certificate transparency compliance. There is no visible security policy or incident response information, which could impact trust and compliance. Cookie consent mechanisms are implemented and appear GDPR compliant, supported by a comprehensive privacy policy. Overall, AMALYTIX presents a professional and trustworthy e-commerce SaaS offering with strong market positioning but requires urgent improvements in SSL/TLS security to protect user data and maintain compliance. Strategic enhancements in security posture and incident response readiness will further strengthen their market credibility and operational resilience.

30
43
25
50
50
85
100
amazonbimonitoringsellervendor+3 more
Nuxt.jsVue.jsNetlify EdgeTailwindCSS+3
2025-06-14T13:53:38.191Z
fim-europe.eu favicon

FIM Europe

fim-europe.eu

54
TransportationN/amediumMEDIUM

FIM Europe operates an official results website dedicated to motorcycle racing events across Europe, covering multiple disciplines such as motocross, enduro, supermoto, track racing, trial, vintage, e-bike, drag racing, and snowcross. The platform serves as a centralized information hub for race results, event schedules, and championship standings, targeting motorcycle racing enthusiasts, participants, and officials. The website demonstrates a consistent brand presence and provides comprehensive event data, supporting the organization's role as a key governing body in European motorcycle sports. Technically, the site is built using modern frontend technologies including Vue.js and the Quasar framework, hosted on DigitalOcean infrastructure. While the site is mobile-optimized and accessible at a basic level, performance is suboptimal with a slow load time and a relatively large page size. The SSL certificate is valid but lacks support for modern TLS protocols, and DNS security features like DNSSEC and CAA records are not enabled, indicating room for improvement in the security infrastructure. From a security and compliance perspective, the website includes a cookie consent mechanism and links to a comprehensive privacy policy that appears GDPR compliant. However, no explicit security policies, incident response contacts, or vulnerability disclosure mechanisms are found. Security headers are minimal, with only HSTS enabled, and there is no evidence of advanced security frameworks or certifications. Overall, the security posture is moderate but could benefit from enhancements to encryption protocols, DNS security, and transparency around incident response. The overall risk to the business from the website is moderate, primarily due to technical and security gaps that could impact user trust and data protection compliance. Strategic recommendations include upgrading TLS support, enabling DNSSEC and CAA records, implementing additional security headers, and establishing clear incident response and vulnerability disclosure policies to strengthen the security culture and compliance stance.

25
-
25
75
87
85
85
motorcycleracingresultsfimeuropemotocross+8 more
Vue.jsQuasar FrameworkGoogle FontsGoogle Tag Manager+1
2025-06-14T13:53:22.055Z

亚马逊财务管理有限公司

amzcfo.com

60
E-commerceChinamediumMEDIUM

AMZCFO is a specialized Chinese company focused on providing comprehensive cross-border e-commerce financial and tax compliance services. It positions itself as an industry leader offering a wide range of services including tax planning, VAT handling, domestic and overseas financial services, equity incentives, and professional training courses. The company targets cross-border e-commerce businesses and financial professionals, leveraging a professional team and partnerships to deliver integrated solutions. Technically, the website is built on modern web technologies including Express and Vue.js frameworks, with Element UI components enhancing user experience. The site is hosted on a dedicated IP with nginx and uses a valid SSL certificate, although it lacks support for modern TLS protocols, which is a security concern. Security headers like HSTS are enabled, but the presence of the 'x-powered-by' header could be reduced to improve security posture. Privacy and cookie policies are present but basic, with no explicit GDPR compliance mechanisms or consent management. Contact information is comprehensive, including phone, email, physical addresses in multiple cities, and a contact form. Overall, the website demonstrates good professionalism and trustworthiness but could improve in security and privacy compliance.

30
40
25
75
82
85
60
跨境电商财税合规税务筹划VAT财务培训+1 more
nginxExpressVue.js (implied by router-link classes and el-carousel components)Element UI (el-carousel, el-button, el-form)+3

Partner Domains:

sypost.com
partnerpending
eccang.com
partnerpending

+2 more partners

2025-06-14T12:57:50.427Z
dekra-certification.es favicon

DEKRA Certificación

dekra-certification.es

71
OtherSpainlargeMEDIUM

DEKRA Certificación is a leading European certification body accredited by ENAC, specializing in audits and certifications across quality, environmental management, occupational health and safety, sustainability, and cybersecurity sectors. The company offers a broad portfolio of certifications including ISO 9001, ISO 14001, ISO 45001, and industry-specific certifications such as SERMI and TISAX, targeting businesses aiming to improve compliance and operational excellence. Their market position is strong, supported by recognized accreditations and a comprehensive service offering tailored to various industries in Spain and beyond. Technically, the website is built on modern frameworks like Nuxt.js and Vue.js, hosted on Azure, and integrates multiple analytics and marketing tools such as Matomo, Hotjar, and Google Tag Manager. The site demonstrates good performance, mobile optimization, and accessibility, reflecting a mature digital infrastructure. However, the SSL/TLS configuration shows no enabled TLS protocols, which is unusual and should be addressed for secure communications. From a security perspective, the site implements robust HTTP security headers including HSTS, CSP, and X-Frame-Options, but the lack of TLS 1.2 or higher and the disabled X-XSS-Protection header indicate areas for improvement. No explicit security policy or incident response information is publicly available, which could be a gap in transparency and readiness. The site complies with GDPR, featuring comprehensive privacy and cookie policies with consent mechanisms. Overall, DEKRA Certificación presents a professional and trustworthy online presence with strong business credentials and technical maturity. Addressing the TLS configuration and enhancing security transparency would further strengthen their security posture and user trust.

80
58
25
55
100
85
100
certificationauditsENACISO 9001ISO 14001+6 more
Nuxt.jsVue.jsTailwind CSSAzure Application Insights+9

Partner Domains:

e-spirit.hosting
partner67
2025-06-14T12:46:39.956Z