Skip to main content

High-risk security reports

Browse 46,997 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 42 of 940|Showing 2051-2100 of 46997
C

cteg.org.uk | 526: Invalid SSL certificate

cteg.org.uk

44
OtherN/asmallHIGH

The website www.cteg.org.uk is currently inaccessible due to an invalid SSL certificate on the origin server, as indicated by the Cloudflare error 526 page. The domain WHOIS lookup failed with an error from Nominet UK stating that the domain cannot be registered because it violates naming rules, suggesting the domain is not legitimately registered or active. No business, contact, or policy information is available on the site, and the content is limited to a technical error message. The technical infrastructure relies on Cloudflare as a proxy, but the origin server is misconfigured with respect to SSL, preventing secure access. From a security perspective, the site lacks a valid SSL certificate, exposing it to trust and confidentiality issues. No security headers or best practices are observed, and no incident response or data protection information is provided. The absence of privacy and cookie policies indicates poor compliance with data protection regulations. The overall security posture is weak, and the domain legitimacy is questionable due to WHOIS data unavailability and registrar error. Given the blocked content and lack of accessible information, the risk assessment is high. The site cannot be reliably analyzed for business credibility or compliance. Strategic recommendations include immediate SSL certificate installation, domain registration validation, and implementation of standard security and privacy policies to restore trust and accessibility.

60
60
100
42
35
-
2
errorsslcloudflareinvalid-certificateblocked
Cloudflare
2026-07-10T07:15:15.553Z
directvehicleglass.co.uk favicon

Direct Vehicle Glass

directvehicleglass.co.uk

46
TransportationUnited KingdommediumHIGH

Direct Vehicle Glass is a well-established UK-based company specializing in mobile windscreen repair and replacement services, primarily serving Liverpool, Warrington, Manchester, and the wider North West region. The company positions itself as a leading independent automotive glazing provider with a focus on quality and responsiveness. Their key services include private and commercial vehicle glass repair, fleet cover, and advanced driver assistance system (ADAS) calibration. The website reflects a medium-sized business with a professional online presence and multiple insurance partnerships that enhance trustworthiness. Technically, the website is built on WordPress and utilizes modern web technologies such as jQuery, Slick Carousel, and Google Analytics for tracking. The site is mobile-optimized with good SEO practices implemented via Yoast SEO. Performance is moderate, and accessibility is basic but functional. The site uses HTTPS with an excellent SSL configuration, though it lacks some security headers that could improve its security posture. From a security perspective, the site demonstrates good baseline practices such as HTTPS and no visible sensitive data exposure. However, it lacks published security policies, incident response information, and a cookie consent mechanism, which are important for GDPR compliance and user trust. No vulnerabilities or suspicious content were detected. The domain registration data aligns well with the business claims, indicating legitimacy and a strong trust foundation. Overall, the website is professional, credible, and secure enough for its business purpose but would benefit from enhanced privacy compliance and security transparency to improve user trust and regulatory adherence.

70
65
20
47
53
17
15
windscreenrepairvehicleglassmobileserviceadascalibrationfleetcover+4 more
jQuerySlick CarouselGoogle AnalyticsYoast SEO
2026-07-10T07:07:53.481Z
directeng.co.uk favicon

403 - Forbidden

directeng.co.uk

41
OtherN/asmallHIGH

The website www.directeng.co.uk is currently inaccessible, returning a 403 Forbidden error page that blocks access to any meaningful content. The domain WHOIS lookup failed with an error indicating the domain name is invalid under Nominet UK naming rules, suggesting the domain may not be properly registered or is misconfigured. Due to the lack of accessible content, no business information, contact details, or policies are available for analysis. The technical infrastructure appears minimal with only Google Fonts loaded externally, and no security headers or HTTPS information is present in the provided data. This results in a very low confidence in the website's operational status and legitimacy. From a security perspective, the absence of HTTPS, security headers, and privacy compliance measures indicates a poor security posture. The lack of contact or incident response information further limits trust and compliance assessment. Overall, the site appears either offline, blocked, or misconfigured, and the domain registration issues raise legitimacy concerns. Strategically, the business should address domain registration compliance, ensure the website is accessible with proper HTTP status codes, implement HTTPS with valid SSL certificates, and publish essential policies and contact information to improve trust and compliance. Until these issues are resolved, the website cannot be reliably assessed or trusted.

70
-
57
80
35
2
70
403forbiddenerrorblockednoindex
2026-07-10T07:07:05.556Z
D

Security Verification

dmburgess.co.uk

46
OtherN/asmallHIGH

The website www.dmburgess.co.uk currently serves a security verification page that employs Google reCAPTCHA v3 to prevent automated access. This indicates the presence of a Web Application Firewall (WAF) or bot protection mechanism restricting normal user access. Due to this, no meaningful business content, contact information, or company details are accessible for analysis. The domain WHOIS lookup failed due to domain naming rules violations, providing no registrar or registrant data, which raises concerns about domain legitimacy and registration status. Technically, the site uses Bootstrap 5.3.3 for styling and Google reCAPTCHA for bot mitigation. However, there is no evidence of HTTPS enforcement or security headers in the provided data. The absence of privacy, cookie, or terms of service policies further indicates a lack of compliance with common data protection regulations such as GDPR. The site’s content quality and user experience are poor due to the blocking mechanism and minimal content. From a security perspective, the site shows basic bot protection but lacks comprehensive security best practices such as HTTPS, security headers, and clear privacy policies. The inability to access the actual website content and the lack of WHOIS data significantly limit trust and credibility assessments. Overall, the site’s risk profile is elevated due to these factors, and it is recommended to verify domain registration and improve transparency and security posture. Strategic recommendations include implementing HTTPS, publishing privacy and cookie policies, providing verifiable business contact information, enhancing security headers, and reviewing domain registration status to ensure legitimacy and compliance.

57
100
60
60
2
15
50
securitycaptchabotprotectionverification
Bootstrap 5.3.3Google reCAPTCHA v3
2026-07-09T07:27:21.226Z
elfrida.com favicon

The Elfrida Society

elfrida.com

48
Non-profitUnited KingdomsmallHIGH

The Elfrida Society is a well-established non-profit organization dedicated to supporting individuals with learning disabilities, autism, and learning difficulties. With over 100 years of history, it provides advocacy, community engagement, inclusive sports, and various support services primarily in Islington and London. The website reflects a professional and community-focused charity with clear mission, vision, and values. The organization maintains active social media channels and offers multiple ways for the public to engage, donate, or volunteer. Technically, the website employs a modern tech stack including Bootstrap, jQuery, and various UI and animation libraries. It is mobile-optimized with good SEO and accessibility basics, though some accessibility features could be enhanced. The site uses HTTPS with a strong SSL configuration and implements cookie consent mechanisms, reflecting good privacy compliance. However, security headers are missing, and no explicit security policy or incident response contact is provided. From a security perspective, the site shows a mature posture with no visible vulnerabilities or exposed sensitive data. The absence of WHOIS registration data is a concern, as it reduces transparency and trust, though the website content and business information appear legitimate and consistent with a reputable charity. No signs of WAF blocking or security challenges were detected, allowing full content access. Overall, the site scores well on content quality, technical implementation, and security posture, with minor penalties for missing WHOIS data and security headers. Strategic improvements in security headers, incident response transparency, and WHOIS data clarity would enhance trust and compliance.

-
75
85
57
15
17
53
non-profitlearningdisabilitiesautismsupportcommunityadvocacy+2 more
BootstrapjQueryAOS (Animate On Scroll)Font Awesome+8
2026-07-09T07:27:05.064Z
kscleaning.com favicon

KS Cleaning Contractors Ltd

kscleaning.com

48
OtherUnited KingdommediumHIGH

KS Cleaning Contractors Ltd is a well-established commercial cleaning service provider based in Somerset, UK, with over 45 years of experience since its founding in 1980. The company offers a broad range of cleaning services including office, school, healthcare, retail, hospitality, and builders cleans. Their business model emphasizes directly employed, DBS-checked teams and a proprietary client portal that provides audit trails with photo evidence and GPS check-ins, enhancing transparency and client trust. The website is professionally designed with clear navigation and strong local market positioning, targeting property managers, facilities managers, and developers in Somerset and the wider South West region. Technically, the website employs modern web technologies including Google Tag Manager for analytics and tracking, uses SVG graphics for branding, and is mobile-optimized with fast performance. However, no CMS or hosting provider details were detected. The site lacks visible security headers and cookie consent mechanisms, which are areas for improvement. The absence of WHOIS registration data for the domain is a notable anomaly that affects trustworthiness, although the website content and business information appear consistent and professional. From a security perspective, the site enforces HTTPS and does not expose sensitive data or vulnerable libraries. The client portal's audit features indicate a mature approach to operational security and accountability. However, the lack of published security policies, incident response contacts, and vulnerability disclosure mechanisms suggests room for enhancement in security posture and compliance. Overall, the website scores well in content quality and business credibility but is moderately impacted by privacy compliance and WHOIS inconsistencies. Strategically, KS Cleaning should address the WHOIS registration anomaly, implement standard security headers, introduce cookie consent to comply with GDPR, and publish…

40
40
60
52
60
53
2
commercialcleaningsomersetcleaningservicesdbs-checkedclientportal+3 more
Google Tag ManagerCustom client portal softwareSVG graphicsCSS stylesheets+1
2026-07-09T07:26:16.976Z
ghekko.com favicon

Ghekko

ghekko.com

47
TelecommunicationsUnited KingdommediumHIGH

Ghekko Group is a medium-sized, established telecommunications hardware supplier and service provider with a global reach through facilities in the UK, Ireland, and the USA. The company specializes in supplying, buying back, repairing, and providing technical services for telecom equipment including phones, headsets, networking, and optical transmission hardware. Their market position is strong within the telecommunications sector, targeting business customers requiring cost-effective and efficient communications hardware solutions. Technically, the website is built on WordPress with modern plugins such as Yoast SEO and uses Bootstrap for responsive design. It integrates Google Analytics and Google reCAPTCHA for analytics and security respectively. The site is mobile-optimized and SEO-friendly, though accessibility features are basic. Performance is moderate, with room for improvement in security headers and accessibility. From a security perspective, the site enforces HTTPS and uses reCAPTCHA on forms, indicating good baseline security practices. However, the absence of explicit security policies, incident response information, and missing WHOIS domain registration data reduce overall trustworthiness. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website and business present a professional and trustworthy front with solid technical implementation but would benefit from improved transparency in domain registration and enhanced security documentation to strengthen compliance and trust.

37
20
65
75
15
17
68
telecommunicationshardwarenetworkingtelecomequipmentrepair+2 more
WordPressYoast SEO pluginjQueryBootstrap+2

Partner Domains:

www.ghekkonetworks.com
partner
www.ghekkotechnology.com
partner
2026-07-09T07:25:39.582Z
stratusconsultants.com favicon

Stratus Consultants Ltd

stratusconsultants.com

47
FinanceUnited KingdomsmallHIGH

Stratus Consultants Ltd is a Glasgow-based professional services firm specializing in accounting, finance, software solutions, and artificial intelligence consulting. Established in 2009, the company targets small business owners, private individuals, and startups, offering tailored financial and software services to support business growth and tax optimization. The website reflects a solid market position with clear service offerings and client testimonials, emphasizing local expertise and personalized consulting. Technically, the website is built on WordPress using popular plugins such as Elementor and Slider Revolution, with a moderate performance profile and good mobile optimization. The site uses HTTPS and standard web technologies but lacks advanced security headers and DNSSEC, indicating room for improvement in security hardening. From a security perspective, the site demonstrates basic best practices such as HTTPS and domain transfer protection but lacks published security policies, incident response contacts, and privacy compliance documentation. No WAF or blocking mechanisms are detected, and the site is fully accessible. Overall, the website presents a trustworthy and professional business presence with moderate technical maturity and security posture. Strategic enhancements in privacy compliance, security headers, and DNS security would strengthen the site’s risk profile and user trust.

20
57
75
70
35
15
25
accountingfinancesoftwaresolutionartificialintelligenceconsulting+2 more
WordPressPHPjQuerySlider Revolution+5
2026-07-09T07:23:52.657Z
I

Security Verification

indigogrp.com

49
OtherN/asmallHIGH

The website www.indigogrp.com currently presents only a security verification page employing Google reCAPTCHA v3, indicating that access to the actual site content is blocked or restricted by a Web Application Firewall or similar bot protection mechanism. No business-related content, metadata, or contact information is accessible, preventing a full assessment of the company's operations or services. The WHOIS lookup for the domain returned no registration data, suggesting the domain may be unregistered, expired, or otherwise inactive, which further complicates trust and legitimacy evaluation. From a technical perspective, the site uses modern front-end libraries such as Bootstrap 5.3.3 and integrates Google reCAPTCHA for security verification. However, no information about SSL/TLS configuration, security headers, or hosting provider is available. The lack of accessible content and metadata limits the ability to assess SEO, accessibility, or performance. Security posture is minimal due to the absence of visible HTTPS enforcement and security headers in the provided data. The presence of Google reCAPTCHA indicates some level of bot mitigation, but the overall security maturity cannot be fully evaluated. Privacy compliance is lacking as no privacy or cookie policies are found, and no GDPR indicators are present. Overall, the domain and website present significant risks due to inaccessibility, lack of registration data, and absence of business or security transparency. Strategic recommendations include verifying domain registration status, ensuring HTTPS and security headers are implemented, publishing privacy and cookie policies, and providing clear contact and business information to improve trust and compliance.

57
65
100
80
50
2
15
securityverificationcaptchabotprotection
Bootstrap 5.3.3Google reCAPTCHA v3
2026-07-09T07:23:41.984Z