Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157333
Websites
130
Industries
113
Countries
52
Avg Score
Page 446 of 800|Showing 22251-22300 of 39982
S

Shrecknt

shrecked.dev

57
TechnologyN/asmallMEDIUM

Shrecknt's Silly Site is a personal technology-focused website serving as a blog and portfolio for the individual known as Shrecknt. The site features links to various social media profiles including Discord, GitHub, and Matrix, as well as a collection of partner and related sites. The content is primarily personal and technical in nature, targeting a general audience interested in technology and programming. The site does not appear to represent a commercial business entity but rather a personal project or hobbyist presence. Technically, the website is built with standard HTML5, CSS3, and JavaScript, utilizing Font Awesome icons for visual elements. There is no evidence of a CMS or complex frameworks, indicating a lightweight and straightforward implementation. The site appears to be mobile-optimized with good navigation clarity, though accessibility features are basic. No analytics or tracking scripts were detected, suggesting minimal user tracking and a privacy-conscious approach. From a security perspective, the site lacks visible security headers and does not provide privacy or cookie policies, which are important for compliance and user trust. No contact emails or phone numbers are provided, limiting direct communication channels. The domain uses privacy protection for WHOIS data, which is common for personal sites but reduces transparency. No vulnerabilities or malicious content were detected, and the site content is safe for general audiences. Overall, the site scores moderately on content quality and business credibility but scores lower on security posture and privacy compliance. Strategic improvements in security headers, privacy policies, and contact information would enhance trust and compliance. The site is suitable as a personal portfolio but lacks features expected from professional or commercial websites.

15
50
2
70
75
75
100
personaltechnologyblogportfolioopensource
HTML5CSS3JavaScriptFont Awesome icons
2025-07-27T04:29:19.943Z
matdoes.dev favicon

matdoesdev

matdoes.dev

47
TechnologyN/asmallHIGH

The website matdoes.dev is a personal portfolio site for a full-stack software developer named mat. It serves as a platform to showcase blog posts and projects, targeting a general audience interested in software development. The site uses modern web technologies, specifically the SvelteKit framework, ensuring a fast and responsive user experience. External links to GitHub, Matrix, and Ko-fi provide social and donation channels, enhancing community engagement. However, the site lacks formal privacy, cookie, and terms of service policies, which limits its compliance posture. From a technical perspective, the site demonstrates good implementation with module preloading and modern JavaScript frameworks, contributing to fast performance and good mobile optimization. Accessibility is basic but functional. Security measures such as HTTPS are assumed but not explicitly confirmed in the provided data, and no security headers were detected. There are no forms or data collection mechanisms present, reducing exposure to common web vulnerabilities. Security posture is moderate but could be improved by adding security headers, formal privacy and cookie policies, and explicit contact information for incident response. No vulnerabilities or suspicious patterns were detected. The domain uses privacy protection for WHOIS data, which is appropriate for a personal portfolio. Overall, the site is safe, professional, and suitable for general audiences. Strategic recommendations include implementing privacy and cookie policies, enhancing security headers, providing clear contact information, and improving accessibility features to strengthen compliance and trustworthiness.

15
50
2
73
75
90
-
portfoliodeveloperfull-stackblogprojects+1 more
SvelteKitJavaScriptCSSSVG
2025-07-27T04:29:09.916Z
E

erin @ e2.pm

e2.pm

60
OtherN/asmallMEDIUM

The website e2.pm is a small, informal personal webpage primarily featuring humorous and casual content without any clear business or professional focus. The site lacks formal business information, contact details, privacy policies, or terms of service, indicating it is not intended for commercial or enterprise use. The domain was registered in late 2019 and remains active, consistent with the site's informal nature. Technically, the website uses basic HTML, CSS, and JavaScript with external resources such as Google Fonts and a cookie consent library. Hosting and DNS are managed via Cloudflare, providing standard performance and security benefits. The site is moderately optimized for mobile and accessibility but lacks advanced SEO and security headers. From a security perspective, the site uses HTTPS and includes a cookie consent banner, showing some privacy awareness. However, it lacks explicit security policies, incident response contacts, and vulnerability disclosure mechanisms. No forms or data collection points are present, reducing attack surface but also limiting user engagement. Overall, the website poses low risk but also offers limited trust and professionalism. Strategic improvements include adding privacy and security policies, contact information, and enhancing technical and security best practices to improve credibility and compliance.

40
65
2
70
75
70
100
personalinformalhumorcookie-consentcloudflare
HTML5CSSJavaScriptGoogle Fonts+2
2025-07-27T04:28:49.665Z
clue.media favicon

evan clue's media portfolio

clue.media

50
MediaUnited StatessmallMEDIUM

The website clue.media serves as a personal media portfolio for Evan Clue, showcasing a variety of creative works including graphic design, video production, web design, merchandising, and a self-published music label. The site highlights several projects such as 'planet clue', 'kayboards', and 'yesclip', demonstrating a niche but consistent presence primarily in the media and creative content space. The business model is centered around personal branding, content creation, and merchandising with a small but engaged audience, particularly on social media platforms like YouTube and TikTok. From a technical perspective, the website is built using standard web technologies including HTML5, CSS, and JavaScript, hosted on Amazon AWS infrastructure. The site is moderately optimized for performance and mobile use, with a clean and consistent design that supports good user experience and navigation clarity. However, there is no detected use of advanced frameworks or CMS, and SEO and accessibility features are basic. Security posture is minimal; no security headers or advanced configurations are present, and DNSSEC is not enabled. The domain is secured with HTTPS (assumed from domain and modern hosting), but no privacy or cookie policies are published, indicating low compliance maturity. No forms or data collection mechanisms are present, reducing attack surface but also limiting user engagement features. The WHOIS data shows a domain age consistent with the portfolio's timeline and a registrant country matching the website's language and contact domain, supporting legitimacy. Overall, the site is a well-maintained personal portfolio with good content quality and business credibility but lacks formal privacy, security, and compliance features. Strategic improvements in security headers, privacy policies, and incident response information would enhance trust and compliance posture.

85
35
2
40
57
70
40
portfoliographicdesignvideowebdesignmedia+2 more
HTML5CSSJavaScript
2025-07-27T04:27:48.025Z
L

Leslie O'Bray

leslieobray.com

49
TechnologyN/asmallHIGH

Leslie O'Bray's website serves as a personal academic and professional portfolio highlighting her PhD research in Machine Learning at ETH Zürich, with a focus on graph machine learning models and bioinformatics. The site also references her prior experience at Google and academic background in statistics. The website targets academics, researchers, and professionals interested in machine learning and related fields. It is a small-scale personal site without commercial business operations. Technically, the website is built using the Hugo static site generator with the Coder theme, hosted with domain registration via Squarespace Domains and DNS managed by Google Cloud DNS. The site is well-structured, mobile-optimized, and uses modern web technologies including FontAwesome icons. Performance is moderate with good SEO and accessibility basics. From a security perspective, HTTPS is enabled and domain status protections are in place. However, no advanced security headers or DNSSEC are implemented. There are no privacy or cookie policies, no contact emails or phone numbers, and no analytics or advertising scripts detected, indicating minimal data collection and tracking. The site is safe for general audiences with no adult or questionable content. Overall, the website is professional and trustworthy as an academic portfolio but lacks formal privacy and security policies. Strategic improvements could enhance compliance and security posture.

15
35
17
60
72
75
40
blogdeveloperpersonalmachinelearningacademic+1 more
Hugo static site generatorCSSJavaScriptFontAwesome icons
2025-07-27T04:27:02.741Z
sdf-eu.org favicon

Super Dimension Fortress EU

sdf-eu.org

38
EducationGermanysmallHIGH

The Super Dimension Fortress EU (SDF-EU) operates as a non-profit community based in Falkenstein, Germany, offering free UNIX shell accounts and a variety of computing resources aimed at educators, students, researchers, and hobbyists. The organization is an independent subsidiary of the SDF Public Access UNIX System and focuses on providing remote computing facilities for education, cultural enrichment, and recreation. The website serves as a portal for account creation and community interaction, leveraging the DokuWiki CMS platform. From a technical perspective, the website employs standard web technologies including HTML, CSS, JavaScript, and jQuery, with DokuWiki as the content management system. The site is moderately optimized with basic mobile responsiveness and accessibility features. Performance is average, and SEO practices are minimal but present. The hosting provider is not explicitly identified beyond the registrar information. Security posture is basic; HTTPS is enabled ensuring encrypted communications, but no advanced security headers or DNSSEC are implemented. The absence of privacy and cookie policies, as well as incident response contacts, indicates compliance and security maturity gaps. No vulnerabilities or malware indicators were detected, but improvements are recommended to enhance security and privacy compliance. Overall, the website is functional and trustworthy for its niche community audience but would benefit from enhanced security measures, formalized privacy documentation, and clearer contact information to improve compliance and user trust.

35
50
2
70
-
85
-
freeunixshelleducationnon-profitcommunityopensource+1 more
HTMLCSSJavaScriptjQuery
2025-07-27T04:26:47.690Z
D

dimden

nekoweb.org

72
TechnologyUkrainesmallMEDIUM

Nekoweb.org is a niche technology platform offering free static website hosting with a strong emphasis on user freedom, ad-free experience, and community engagement. Founded in 2023 by a group of coders and artists, it targets individuals and small creators who prefer personal websites over social media. The platform supports advanced features such as FTP and Git for donators, custom domains, and API automation, positioning itself as a flexible and user-centric hosting service. The business model relies on donations and optional paid upgrades, fostering a community-driven ecosystem. Technically, Nekoweb.org utilizes modern web standards including HTML5, CSS3, and JavaScript, with Cloudflare providing DNS and registrar services. The site is mobile-optimized with good navigation and basic accessibility features. Security measures include HTTPS enforcement and Cloudflare Turnstile CAPTCHA to mitigate bot traffic, though DNSSEC is not enabled and security headers are minimal. The platform blocks generative AI crawlers to protect user content, reflecting a proactive approach to content security. From a security perspective, the site demonstrates a moderate security posture with room for improvement in DNS security and explicit security policies. Privacy compliance is basic, with a privacy policy and terms of service present but lacking cookie consent mechanisms. Contact information is clearly provided, enhancing business credibility. No adult or questionable content is detected, making the site safe for general audiences. Overall, Nekoweb.org presents a trustworthy and well-maintained service with a clear community focus. Strategic recommendations include enabling DNSSEC, enhancing security headers, publishing a security policy, and implementing cookie consent to improve compliance and security posture. These steps will strengthen user trust and align the platform with best practices in web security and privacy.

55
53
47
85
75
85
100
statichostingcommunityad-freetechnologypersonalwebsites+2 more
HTML5CSS3JavaScriptCloudflare DNS and registrar+1
2025-07-27T03:25:14.120Z
S

selic.re

selic.re

42
TechnologyN/asmallHIGH

The website selic.re is a personal portfolio and project showcase for an individual developer and artist known as Selicre. The site highlights the owner's skills in software development, particularly in Rust, as well as graphic design and generative art. The target audience includes developers, learners, and art enthusiasts. The business model is primarily personal branding and sharing of projects and contact via social media. The domain is registered since 2019 and hosted on Hetzner infrastructure, indicating a stable and consistent technical setup. Technically, the website uses standard web technologies including HTML5, CSS3, JavaScript, and SVG for visual effects. There is no evidence of a CMS or third-party frameworks. The site is moderately optimized for performance and mobile devices, with basic accessibility and SEO features. No analytics or advertising scripts are present, indicating minimal user tracking. From a security perspective, the site lacks published privacy, cookie, or security policies, and no security headers were detected. There are no forms or data collection points, reducing attack surface but also limiting user interaction. The WHOIS data is consistent and transparent, with no privacy protection or suspicious patterns. Overall, the security posture is basic but without critical vulnerabilities detected. The overall risk is low given the personal nature of the site and lack of sensitive data handling. Strategic recommendations include adding privacy and cookie policies, implementing security headers, and providing direct contact information for security or business inquiries to enhance trust and compliance.

15
35
2
60
42
75
40
personalportfoliosoftwaredevelopmentgraphicdesignrustprogramminggenerativeart
HTML5CSS3JavaScriptSVG
2025-07-27T03:24:48.832Z
notnite.com favicon

notnite

notnite.com

54
TechnologyN/asmallMEDIUM

The website notnite.com is a personal portfolio and blog site belonging to Jules, an 18-year-old student and programmer. The site serves as a hub for personal projects, social media links, and community engagement. It targets a general audience interested in programming, modding, and internet culture. The business model is non-commercial, focusing on personal expression and community presence. Technically, the site is built using the Astro static site generator (version 5.11.1) and is hosted with Cloudflare DNS services. The site uses modern web technologies including CSS custom properties and SVG icons, delivering fast performance and good mobile optimization. However, accessibility and SEO optimizations are basic. From a security perspective, the site enforces HTTPS and has domain registration protections such as clientDeleteProhibited and clientTransferProhibited statuses. However, DNSSEC is not enabled, and no security headers were detected. There are no published security policies or incident response contacts. Privacy and cookie policies are absent, which impacts compliance. Overall, the site is safe, trustworthy, and well-maintained for a personal website but lacks formal privacy and security documentation. Strategic improvements in privacy compliance and security headers would enhance trust and protection.

15
35
2
65
52
85
100
personalportfolioblogtechnologyprogramming+1 more
Astro v5.11.1Cloudflare DNSJavaScriptCSS custom properties+1
2025-07-27T03:24:28.727Z
deerz.one favicon

Privacy service provided by Withheld for Privacy ehf

deerz.one

45
TechnologyIcelandsmallHIGH

The website deerz.one is a personal site operated by an individual known as ida deerz, focusing on creative outputs such as music, blog posts, and technical resources. The site serves a niche audience interested in music production, web development, and personal insights. The business model is primarily content sharing and community engagement without commercial sales directly on the site. The domain is relatively new, registered in April 2024, and uses privacy protection services, which aligns with the personal nature of the site. Technically, the site is built on a custom content management system called Deer Text Format, utilizing standard web technologies including HTML, CSS, JavaScript, and PHP. Hosting is provided by DreamHost, and the site is served over HTTPS with a moderate performance profile. Mobile optimization and accessibility are basic but functional. SEO practices are minimal but present. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and security headers such as Content-Security-Policy. There are no visible vulnerabilities or exposed sensitive data. However, the absence of privacy and cookie policies, as well as incident response information, indicates room for improvement in compliance and security posture. Overall, the site is safe, trustworthy, and well-maintained for a personal project, but it lacks formal privacy and security documentation. Strategic recommendations include implementing privacy and cookie policies, enabling DNSSEC, adding security headers, and providing incident response contacts to enhance trust and compliance.

15
35
17
70
62
70
20
personalblogmusictechnologycreative+2 more
HTML5CSS3JavaScriptPHP+4
2025-07-27T03:24:23.686Z
openpgp.org favicon

OpenPGP

openpgp.org

66
TechnologyN/asmallMEDIUM

OpenPGP.org is the official website for the OpenPGP standard, the most widely used email encryption protocol. The site provides information about the standard, its history, and software implementations across all major operating systems. It positions itself as a trusted, community-driven resource with a long-standing presence in the encryption technology space since 1997. The website is professionally designed with clear navigation and good mobile optimization, reflecting a mature digital presence. However, it lacks explicit privacy, cookie, and terms of service policies, which are important for compliance and user trust. Technically, the site uses modern web technologies including HTML5, CSS3, JavaScript, and the Jekyll static site generator with the Minimal Mistakes theme. It employs HTTPS for secure communication but does not implement advanced security headers or disclose security policies. No tracking or advertising technologies are detected, indicating a privacy-respecting approach. The absence of WHOIS data transparency limits the ability to fully verify domain legitimacy, though the open source presence on GitHub and RFC standard references support authenticity. From a security perspective, the site demonstrates good baseline practices such as HTTPS and no exposed sensitive data. However, it lacks published security policies, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for improving security posture and user confidence. Overall, the website is safe, professional, and trustworthy but could benefit from enhanced transparency and compliance documentation. Strategically, the site should prioritize publishing privacy and cookie policies, adding security headers, and providing clear contact information for security incidents. These steps will strengthen compliance with regulations like GDPR and improve overall trustworthiness in the security community.

85
50
2
70
75
70
100
encryptionemailsecurityopenpgpprivacy+1 more
HTML5CSS3JavaScriptFontAwesome
2025-07-27T03:23:28.386Z
wmflabs.org favicon

Wikimedia Foundation

wmflabs.org

68
TechnologyUnited StateslargeMEDIUM

Wikitech is a technical wiki platform operated by the Wikimedia Foundation, providing detailed documentation and information about Wikimedia's cloud services infrastructure. It serves as a collaborative resource for Wikimedia technical contributors, developers, and system administrators. The platform supports the Wikimedia ecosystem by offering transparent and accessible technical knowledge, reinforcing Wikimedia's position as a leading open knowledge organization. The website is built on the MediaWiki framework, leveraging modern web technologies such as JavaScript, CSS, and HTML5. It is hosted on Wikimedia's own infrastructure, ensuring fast performance, good mobile optimization, and accessibility. The technical maturity of the platform is high, with a focus on usability and clear navigation for its target technical audience. Security posture is strong, with HTTPS enforced and multiple security headers implemented. No vulnerabilities or exposed sensitive data were detected in the analyzed content. Privacy compliance is moderate on this specific page due to the absence of explicit privacy or cookie policies, but Wikimedia Foundation's overall privacy practices are known to be robust. Overall, the website is trustworthy, professional, and well-maintained, supporting Wikimedia's mission through high-quality technical documentation. Strategic recommendations include enhancing privacy policy visibility on all pages and maintaining rigorous security audits to uphold the platform's integrity.

40
68
17
75
75
85
100
overviewscloudserviceswikimediatechnicaldocumentation
MediaWikiJavaScriptCSSHTML5
2025-07-27T03:22:58.185Z
wmcloud.org favicon

Wikimedia Foundation

wmcloud.org

68
TechnologyUnited StateslargeMEDIUM

The website wikitech.wikimedia.org is a technical documentation platform maintained by the Wikimedia Foundation, focusing on cloud services and infrastructure supporting Wikimedia projects. It serves as a resource for developers and technical contributors within the Wikimedia community, providing detailed information about cloud service usage and architecture. The site is part of the broader Wikimedia ecosystem, which is a globally recognized non-profit organization dedicated to free knowledge dissemination. Technically, the site is built on the MediaWiki platform, leveraging standard web technologies such as HTML5, CSS, and JavaScript. The infrastructure is hosted and managed by the Wikimedia Foundation, ensuring reliable performance and security. The website demonstrates good mobile optimization, accessibility, and SEO practices, contributing to a positive user experience. From a security perspective, the site enforces HTTPS, implements key security headers, and shows no signs of vulnerabilities or exposed sensitive data. While no explicit privacy or cookie policies were found on this specific page, the Wikimedia Foundation generally maintains comprehensive privacy practices across its domains. The absence of contact information and policy pages on this particular page slightly reduces privacy compliance scores but does not significantly impact overall trust. Overall, the website is trustworthy, professionally maintained, and aligned with the Wikimedia Foundation's mission. It poses minimal risk and serves as a valuable technical resource. Strategic recommendations include adding clear links to privacy and cookie policies on all pages and providing contact information to enhance transparency and compliance.

40
68
17
75
75
85
100
overviewscloudserviceswikimediatechnicaldocumentation
MediaWikiJavaScriptCSSHTML5
2025-07-27T03:22:53.148Z
skwodo.com favicon

Skwodo's website

skwodo.com

57
TechnologyPolandsmallMEDIUM

The website skwodo.com is a personal portfolio site belonging to a beginner programmer from Poland named Skwodo. The site primarily serves as a personal presence and a showcase of programming interests, focusing on frontend development. It includes links to friends' websites and the source code repository on GitHub. The business model is minimal and personal, with no commercial or enterprise features. The market position is niche and informal, targeting general visitors interested in the author's programming journey. Technically, the site is built using the Zola static site generator, served with HTML, CSS, and JavaScript, and hosted behind Cloudflare DNS servers. The site is basic in design and functionality, with moderate performance and basic mobile optimization. No advanced CMS or analytics tools are detected, indicating a simple and lightweight infrastructure. From a security perspective, the site lacks several best practices such as security headers, privacy and cookie policies, and contact information for incident response. DNSSEC is not enabled, and no vulnerability disclosure or security policy information is present. However, no critical vulnerabilities or blocking mechanisms are detected, and the domain registration details are consistent and appropriate for a personal site. Overall, the site is low risk but also low in professionalism and compliance. Strategic improvements in privacy compliance, security headers, and contact information would enhance trust and security posture.

15
40
2
70
95
80
100
personalportfolioprogrammingstaticsitebeginner+1 more
HTML5CSSJavaScript
2025-07-27T03:22:22.968Z
L

Welcome to my website! ~ lemonsh's website

lemonsh.moe

60
TechnologyPolandsmallMEDIUM

The website lemonsh.moe is a personal portfolio and blog site operated by an individual named lemonsh, a technology enthusiast from Poland. The site focuses on topics such as *nix operating systems, networking, programming, and retro-computing, with additional interests in music, cycling, photography, and graphic design. The site serves as a platform to showcase projects, share blog content, and provide contact information for community engagement. It is positioned as a niche personal tech presence rather than a commercial business. Technically, the website is built using the Zola static site generator and hosted with Cloudflare DNS services. The tech stack includes Rust, C, C#, Java, HTML/CSS, Bash, and some JavaScript, reflecting the owner's programming skills. The site is served over HTTPS with a good SSL configuration but lacks DNSSEC and security headers. Performance and mobile optimization are moderate to basic, with no detected analytics or tracking scripts, indicating a privacy-conscious approach. From a security perspective, the site benefits from HTTPS and WHOIS privacy protection, which is justified for a personal site. However, it lacks formal privacy, cookie, or terms of service policies, and no incident response or vulnerability disclosure information is provided. No security headers are detected, and no forms or data collection mechanisms are present, reducing attack surface but also limiting user interaction. The site content is safe for general audiences with no adult or questionable material. Overall, the website demonstrates a good level of professionalism and technical competence for a personal project. The main risks relate to missing privacy and security policies and the absence of security headers. Strategic improvements in these areas would enhance trust and compliance. The domain registration is legitimate and consistent with the site’s nature, with no suspicious indicators.

30
50
2
70
95
60
100
technologyprogrammingnetworkingpersonalblogportfolio
RustC#JavaHTML+5

Partner Domains:

famfo.xyz
partner
skwodo.com
partner

+2 more partners

2025-07-27T03:22:17.946Z
haskell.org favicon

Haskell.org, Inc.

haskell.org

51
TechnologyN/asmallMEDIUM

Haskell.org is the official home page for the Haskell programming language, a purely functional, statically typed language widely used in academia and industry. The site serves as a comprehensive resource hub offering documentation, downloads, community engagement, and educational tools such as an interactive playground. It is maintained by Haskell.org, Inc., a non-profit organization, and supported by reputable sponsors and partners including Fastly, Status.io, Scarf, DreamHost, and Digital Ocean. The website targets developers and programmers interested in functional programming paradigms and aims to promote the adoption and understanding of Haskell. Technically, the website is well-constructed using modern web technologies including Bootstrap, jQuery, and Glider.js for UI components. It leverages CDN and cloud hosting providers to ensure fast and reliable access globally. The site is mobile-optimized, accessible, and SEO-friendly, providing a smooth user experience. However, explicit privacy and cookie policies are not present, and no contact emails or phone numbers are listed, which could be improved for transparency and compliance. From a security perspective, the site uses HTTPS and has a dedicated security page, but lacks explicit security headers and a published security.txt file for vulnerability disclosure. No obvious vulnerabilities or exposed sensitive data were detected. The WHOIS data for the domain is incomplete or unavailable, which slightly reduces trustworthiness but is mitigated by the site's professional appearance, community trust, and sponsorships. Overall, Haskell.org is a high-quality, trustworthy resource for the Haskell community with strong technical foundations and good security posture. Enhancements in privacy compliance, security header implementation, and WHOIS transparency would further strengthen its credibility and user trust.

45
35
17
60
52
75
40
haskellfunctionalpureprogramminglazy
HTML5CSSJavaScriptBootstrap+5

Partner Domains:

fastly.com
partner
status.io
partner

+3 more partners

2025-07-27T03:21:27.614Z
git.gay favicon

Private by Design, LLC

git.gay

50
TechnologyUnited StatessmallMEDIUM

git.gay is a niche collaboration platform designed to empower queer developers by providing Git hosting, continuous integration, and static site hosting services. Operated by the collective 'besties', it emphasizes community values, open source software, and privacy by avoiding ads and third-party trackers. The platform leverages a fork of Forgejo, ensuring open source transparency and configurability. The website presents a professional and consistent brand image targeting queer and neurodiverse developers, positioning itself as a community-centric alternative to corporate platforms. Technically, git.gay uses modern web technologies including Forgejo, Cloudflare DNS, and custom JavaScript for enhanced user experience and error handling. The site is mobile optimized with good SEO practices and minimal user tracking, reflecting a mature digital infrastructure. However, DNSSEC is not enabled, and security headers are not visibly implemented, indicating areas for improvement in security hardening. From a security perspective, the site enforces HTTPS and employs CSRF tokens, with no detected vulnerabilities or exposed sensitive data. Privacy policies and terms of service are present but basic, and no explicit incident response or vulnerability disclosure policies are published. The absence of cookie consent mechanisms despite script usage suggests a potential compliance gap. Overall, the security posture is solid but could benefit from enhanced transparency and technical controls. The domain registration is transparent and consistent with the business profile, registered to Private by Design, LLC in the US, matching the website's operational claims. The domain age aligns with the platform's founding date, supporting legitimacy. No suspicious WHOIS patterns or privacy protections obscure ownership, enhancing trustworthiness. The platform's focus on community and open source principles further supports a positive risk profile. Strategic recommendations include enabling DNSSEC, implementing comprehensive security headers, publishing detailed security and incident response policies, adding cookie consent mechanisms, and establishing a vulnerability disclosure process. These steps will strengthen security, compliance, and user trust, supporting git.gay's mission as a safe and empowering platform for queer developers.

45
53
2
70
75
75
-
gitforgeforgejoqueeropensource+2 more
Forgejo (fork of Gitea)Cloudflare DNSJavaScriptHTML5+1

Partner Domains:

besties.house
partner
2025-07-27T03:20:27.350Z
ezri.pet favicon

Private by Design, LLC

ezri.pet

9
TechnologyUnited StatessmallCRITICAL

The website ezri.pet represents a personal and academic online presence of a 21-year-old computer science student based in New York City. The individual operates a small internet hosting service with its own ASN and is involved in academic research in computer systems and networking. The site serves as a portfolio and contact point, featuring links to various social media and communication platforms, and showcases personal projects and interests. The business model is small-scale and niche, focusing on personal hosting and academic collaboration rather than commercial enterprise. Technically, the website is built with standard HTML5 and CSS using Pure.css for styling, with some JavaScript for interactive elements. It is hosted under a domain registered with Porkbun LLC and uses DNS services from Hurricane Electric and kjsl.com. The site is mobile responsive and well-structured, though it lacks advanced SEO and accessibility features. No CMS or major frameworks are detected, indicating a custom or static site approach. From a security perspective, the site uses domain status flags to prevent unauthorized transfer or deletion but lacks DNSSEC and security headers such as CSP or HSTS. There is no privacy or cookie policy, and no incident response or vulnerability disclosure information is provided. No analytics or advertising scripts are present, indicating minimal tracking and good privacy by default. The domain registration is transparent and consistent with the website's stated purpose, enhancing trustworthiness. Overall, the site is safe, professional, and trustworthy for its intended audience but would benefit from implementing basic privacy and security policies, enabling DNSSEC, and adding security headers to improve its security posture and compliance. The lack of privacy and cookie policies currently limits its privacy compliance score.

-
-
-
-
-
-
-
personalacademictechnologyhostingstudent+1 more
HTML5CSS (Pure.css)JavaScript
2025-07-27T03:19:21.892Z
msx.gay favicon

Private by Design, LLC

msx.gay

56
OtherUnited StatessmallMEDIUM

The website msx.gay is a personal portfolio and social presence site belonging to an individual known as msxdotgay, a neurodivergent young adult from rural Iowa. The site serves as a platform to share personal projects, photography, writings, and interests including LGBTQ+ identity and cats. The business model is non-commercial and focused on personal expression and community engagement. The domain is registered under Private by Design, LLC, a privacy-focused registrar, consistent with the personal nature of the site. Technically, the site is hosted on Neocities, uses basic HTML, CSS, and JavaScript, and includes a small external script for a cat animation. The site is served over HTTPS but lacks advanced security headers and modern CMS or frameworks. Performance and mobile optimization are basic but functional. No analytics or tracking scripts are present, indicating a privacy-conscious approach. From a security perspective, the site benefits from HTTPS and domain transfer protections but lacks DNSSEC and security headers. There are no forms or data collection points, reducing attack surface. However, the absence of privacy and cookie policies, security.txt, and vulnerability disclosure mechanisms indicates room for improvement in compliance and security transparency. Overall, the site is safe, family-friendly, and trustworthy as a personal website. Strategic recommendations include adding privacy and cookie policies, enabling DNSSEC, implementing security headers, and publishing a security.txt file to enhance security posture and compliance.

40
-
2
70
85
85
100
personallgbtqphotographyprojectscats+4 more
Pop!_OSFedoraWindows 2000/XP/7 (mentioned)HTML5+3
2025-07-27T03:18:34.717Z
dimden.dev favicon

dimden

dimden.dev

57
TechnologyUkrainesmallMEDIUM

The website dimden.dev is a personal portfolio and blog of a Ukrainian programmer known as dimden. It serves as a platform to showcase open source projects, share blog posts, and engage with a community primarily through Discord and Patreon. The site targets programmers, tech enthusiasts, and followers of the author's work. The business model is centered around personal branding, community engagement, and open source contributions, with no direct commercial sales evident. The market position is niche, focusing on a dedicated audience interested in programming and retro-inspired web culture. Technically, the website employs a modern JavaScript-based stack with custom scripts and uses HTTPS with Google Analytics and Tag Manager for tracking. The site is hosted on platforms like Neocities and Nekoweb, with some projects leveraging µWebSockets. Performance is moderate, with basic mobile optimization and accessibility features. SEO is basic but functional, with proper meta tags and Open Graph images. From a security perspective, the site benefits from HTTPS and lacks exposed sensitive data or vulnerable libraries. However, it lacks important security headers such as Content-Security-Policy and Strict-Transport-Security, and does not provide privacy or cookie policies, which impacts compliance. No vulnerability disclosure or incident response information is available. Overall, the security posture is moderate but could be improved with standard best practices. The overall risk is low given the personal nature of the site and absence of sensitive transactions or user data collection. Strategic recommendations include implementing security headers, adding privacy and cookie policies, and establishing a vulnerability disclosure process to enhance trust and compliance.

15
35
2
85
65
75
100
personalblogprogrammingjavascriptopensource+2 more
JavaScriptHTML5CSS3Google Analytics+2

Partner Domains:

ourworldofpixels.com
partner
discord.gg
partner

+3 more partners

2025-07-27T03:18:24.648Z
F

Lea's Game Archive • /

futacockinside.me

55
OtherGermanysmallMEDIUM

The website futacockinside.me operates as a personal game archive titled "Lea's Game Archive". It hosts various directories of game files across multiple platforms, accessible only after password authentication. The site is clearly intended for personal use rather than commercial purposes, with no evident business or contact information provided. The domain is relatively new, registered in 2022, and the hosting setup includes suspicious nameservers that may pose security concerns. The site uses a custom analytics script but lacks standard privacy and cookie policies, which impacts its compliance posture. Technically, the site is built with basic HTML, CSS, and JavaScript, including Google Fonts for styling. It is moderately optimized for mobile devices but lacks advanced SEO and accessibility features. No CMS or major frameworks are detected. The hosting provider is not clearly identified beyond the registrar and suspicious DNS configuration. Performance appears moderate with no major errors or broken elements. From a security perspective, the site lacks DNSSEC, security headers, and visible HTTPS enforcement details, which lowers its security posture. The use of suspicious nameservers and absence of privacy or security policies further reduce trustworthiness. However, no WAF or blocking mechanisms are detected, and the content is safe with no adult or explicit material. Overall, the site is functional but has significant gaps in security and compliance best practices. The overall risk assessment suggests caution due to DNS and security configuration concerns. Strategic recommendations include improving DNS security, implementing HTTPS and security headers, adding privacy and cookie policies, and providing clear contact information to enhance trust and compliance.

45
35
2
70
52
85
100
gamearchivepersonalusepasswordprotectedgamefilesanalytics
HTML5CSS3JavaScriptGoogle Fonts (Fira Mono)
2025-07-27T03:18:19.638Z