Skip to main content

High-risk security reports

Browse 43,500 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 47 of 870|Showing 2301-2350 of 43500
blueskytravel.hu favicon

Blue Sky Travel

blueskytravel.hu

0
HospitalityHungarymediumHIGH

Blue Sky Travel is a Hungarian travel agency established in 2018, specializing in air and bus travel packages primarily to Greek islands and various exotic destinations. The company offers competitive pricing, last-minute deals, and comprehensive travel organization services targeting Hungarian-speaking travelers. Their website features a professional design with clear navigation, mobile optimization, and integrated booking forms, reflecting a medium-sized business with a solid market presence. Technically, the website leverages modern web technologies including Bootstrap, jQuery, and popular analytics and marketing tools such as Google Tag Manager, Hotjar, Microsoft Clarity, and Tawk.to live chat. Hosting is provided via a CDN, ensuring moderate performance and good mobile responsiveness. SEO and accessibility are adequately addressed, though some improvements are possible. From a security perspective, the site enforces HTTPS and employs consent-based loading of tracking scripts, demonstrating a privacy-aware approach. However, it lacks several important security headers and does not publish a security policy or incident response contacts. No critical vulnerabilities or suspicious activities were detected, and WHOIS data confirms domain legitimacy and consistency with the business claims. Overall, the website presents a trustworthy and professional travel service with room for improvement in privacy policy transparency and security hardening. The risk level is moderate with no immediate threats identified.

20
25
2
85
72
75
20
travelholidayvacationpackagetoursgreekislands+3 more
BootstrapjQuerySlick CarouselGoogle Fonts+4
2025-10-30T14:15:44.112Z
valfrigo.com favicon

Valfrigo

valfrigo.com

0
EnergyKosovosmallHIGH

Valfrigo is a Kosovo-based company specializing in the sale of thermal pumps for central heating, ventilation, air conditioning, and related services such as filtering and degassing of oil transformers. The company markets products from well-known brands like NIBE, TOSHIBA, CARRIER, and CLIVET, positioning itself as a specialized provider in the green energy sector. The website reflects a small-sized business with a clear focus on green energy heating solutions, targeting both businesses and consumers interested in sustainable energy technologies. The domain age of 20 years supports a mature business presence. Technically, the website is built on WordPress using popular plugins such as WPBakery Page Builder and Slider Revolution. It employs modern web technologies including jQuery and Google Fonts, and integrates Google Maps API. The site is mobile optimized with good design quality and navigation clarity, although SEO and accessibility features are basic. Hosting appears to be managed via Name.com, consistent with the domain registrar information. From a security perspective, the site uses HTTPS, ensuring encrypted communications. However, no DNSSEC is enabled, and no security headers were detected in the provided data, which are areas for improvement. The absence of privacy and cookie policies, as well as incident response contacts, indicates gaps in compliance and security transparency. No evidence of tracking or advertising scripts was found, suggesting minimal user tracking. Overall, the website is professional and trustworthy with moderate security posture and limited privacy compliance. Strategic improvements in security headers, DNSSEC, and privacy documentation would enhance the site's security and compliance standing.

15
35
2
70
62
70
20
greenenergythermalpumpsheatingventilationairconditioning+2 more
WordPressWPBakery Page BuilderSlider RevolutionjQuery+2
2025-10-30T14:12:41.402Z
V

VTD

vtd.se

0
TransportationSwedenmediumHIGH

VTD is a Swedish logistics and distribution company specializing in parcel, newspaper, and mail delivery services primarily in the Västsverige region. Established in 2001, the company operates a strong distribution chain reaching approximately 700,000 to 800,000 households daily. Their business model focuses on sustainable and reliable delivery using various transport modes including walking, cycling, mopeds, and cars. The website reflects a medium-sized regional player with a clear market position and a professional digital presence. Technically, the website is built on WordPress using the Divi theme and leverages Yoast SEO for optimization. Hosting appears to be on Oracle Cloud infrastructure. The site is moderately performant with good mobile optimization and basic accessibility features. SEO practices are well implemented with proper meta tags and structured data. However, some technical improvements such as enabling DNSSEC and adding security headers could enhance security posture. From a security perspective, the site uses HTTPS with a good SSL configuration but lacks advanced security headers and explicit security policies. No incident response or vulnerability disclosure information is publicly available. Privacy compliance is partially met with a privacy policy present, but no cookie consent mechanism was detected, which is a GDPR compliance gap. Contact information is clearly provided, enhancing business credibility. Overall, VTD's website is professional, trustworthy, and business-focused with room for improvement in privacy compliance and security best practices. The risk profile is low with no critical vulnerabilities detected. Strategic recommendations include implementing cookie consent, enabling DNSSEC, adding security headers, and publishing security policies to strengthen trust and compliance.

15
10
17
70
72
65
-
logisticsdistributionswedentransportationparceldelivery+2 more
WordPressDivi ThemejQueryMediaElement.js
2025-10-30T14:12:36.392Z
O

Welcome to Craft CMS

origin-point.de

0
TechnologyN/asmallHIGH

The website origin-point.de currently hosts a default Craft CMS installation placeholder page, indicating that the site is under initial setup or development. There is no custom content, business information, or contact details presented. The site targets developers or site builders preparing to build the actual website. The technical infrastructure is based on Craft CMS with standard HTML and CSS, hosted on generic servers indicated by the nameservers. Mobile optimization is basic but present, and the site is accessible without any WAF or blocking mechanisms. From a security perspective, the site lacks visible security headers, privacy policies, cookie consent mechanisms, and contact information for incident response. SSL configuration details are not provided, but HTTPS is assumed given the URL scheme. No analytics or advertising scripts are detected, indicating minimal tracking or marketing activity. The WHOIS data is minimal and generic, with no registrant details to verify legitimacy fully. Overall, the security posture is basic with room for significant improvement. The overall risk is low given the placeholder nature of the site and lack of sensitive data or active services. However, the absence of privacy and security policies, contact information, and custom content limits trust and business credibility. Strategic recommendations include replacing the placeholder content with a professional website, implementing privacy and cookie policies, adding security headers, and providing clear contact and incident response information to improve compliance and trust.

15
25
2
70
72
45
20
craftcmscmsplaceholderdefaultinstallation
HTML5CSS3
2025-10-30T14:09:13.683Z
zuzanasmatanova.sk favicon

Zuzana Smatanová

zuzanasmatanova.sk

0
MediaSlovakiasmallHIGH

The website zuzanasmatanova.sk serves as the official online presence for Slovak singer Zuzana Smatanová. It provides comprehensive information about her music, concerts, videos, and merchandise, targeting fans and the general public interested in Slovak music. The site is professionally designed with consistent branding and clear navigation, supporting a small-sized media business model focused on artist promotion and fan engagement. Technically, the site is built on WordPress with common libraries such as jQuery and Bootstrap, hosted likely by a Slovak provider (Euronet). The performance and mobile optimization are good, though accessibility features are basic. SEO is well addressed with proper meta tags and Open Graph data. From a security perspective, the site uses HTTPS but lacks visible security headers like CSP or HSTS. No forms collecting sensitive data are present on the homepage, reducing immediate risk. Privacy compliance is limited as no privacy policy or terms of service pages are found, though a cookie policy page exists without an explicit consent mechanism. Contact information is clearly provided, enhancing business credibility. Overall, the site is trustworthy and professional but would benefit from improved security headers and privacy documentation to enhance compliance and user trust.

15
25
2
65
62
70
20
musicartistslovakiaentertainmentofficial+3 more
jQueryBootstrap 3.3.7Font Awesome 4.7.0Google Analytics+2
2025-10-30T14:05:55.495Z
radmold.sk favicon

R&D MOLD MACHINING

radmold.sk

0
ManufacturingSlovakiamediumHIGH

R&D MOLD MACHINING is a Slovak manufacturing company specializing in the production of molds, tooling, and composite parts primarily for the automotive, aerospace, engineering, energy, food, and pharmaceutical industries. Founded in 2008, the company has grown from a start-up to a medium-sized enterprise with a strong international client base including premium brands such as Bentley, Porsche, BMW, Jaguar, and Boeing. Their business model focuses on providing comprehensive engineering and manufacturing services from design through production and maintenance, emphasizing quality and efficiency. Technically, the company operates a modern WordPress-based website using Elementor and Yoast SEO, with GDPR-compliant cookie consent mechanisms and Google Analytics for tracking. The site is well-optimized for SEO and mobile devices, reflecting a mature digital presence. Security posture is good with HTTPS enforced and standard security headers present, although explicit security policies and incident response contacts are not publicly disclosed. Overall, the website and business demonstrate a high level of professionalism and trustworthiness, supported by client testimonials and partnerships with reputable companies. The absence of privacy and terms of service pages is a minor compliance gap. No WAF or blocking mechanisms were detected, and the domain registration data aligns well with the company's stated history and location. Strategic recommendations include enhancing privacy and security policy transparency, publishing incident response contacts, and improving accessibility features to further strengthen compliance and user trust.

15
40
17
70
62
60
20
manufacturinginjectionmoldingcarbonfiberengineeringservicesautomotive+5 more
WordPressElementorYoast SEOjQuery+2

Partner Domains:

nanogate.com
partner
bakerhughes.com
partner

+3 more partners

2025-10-30T14:05:45.402Z
erfurt-tourismus.de favicon

Erfurt Tourismus & Marketing GmbH

erfurt-tourismus.de

0
HospitalityGermanymediumHIGH

Erfurt Tourismus & Marketing GmbH operates the official tourism website for the city of Erfurt, Germany, providing comprehensive information on city tours, accommodation, events, and cultural highlights. The website serves as a central hub for tourists and event planners, offering online booking capabilities and detailed guides. The company holds a strong market position as the official tourism promoter for the region, targeting a broad audience including families, groups, and individual travelers. Technically, the website is built on TYPO3 CMS with Bootstrap for responsive design, hosted on AWS infrastructure. It employs modern web technologies and privacy-conscious analytics tools such as Matomo alongside Google and Facebook tracking pixels. The site is well-optimized for SEO, mobile use, and accessibility, with clear navigation and multilingual support. From a security perspective, the site enforces HTTPS and uses cookie consent mechanisms compliant with GDPR. However, explicit security headers are not visibly implemented, and no dedicated security or incident response policies are published. No vulnerabilities or exposed sensitive data were detected. Overall, the security posture is solid but could be enhanced with additional headers and transparency. The website content is safe for general audiences, focusing on tourism and cultural promotion without any adult or questionable content. Contact information is comprehensive and clearly presented, supporting business credibility and trust. The domain registration and DNS setup are consistent with a legitimate public entity, reinforcing the site's authenticity. Strategic recommendations include implementing explicit security headers, publishing a security policy or incident response contact, and continuing to maintain GDPR compliance and transparency to enhance user trust and security maturity.

25
83
2
55
27
65
20
tourismtravelerfurtcitytoursevents+3 more
TYPO3 CMSBootstrap 3jQueryMatomo Analytics+3

Partner Domains:

www.erfurt-marketing.de
partner
www.petersberg-erfurt.de
partner

+2 more partners

2025-10-30T13:23:53.329Z
erfurt-klingt-gut.de favicon

Team Stadt Erfurt

erfurt-klingt-gut.de

0
GovernmentGermanylargeHIGH

The website 'Team Stadt Erfurt – Klingt gut.' serves as a public sector employment and training portal for the city of Erfurt, Germany. It targets job seekers interested in municipal jobs, apprenticeships, and internships, positioning itself as one of the largest employers in the region with approximately 3,700 employees. The site promotes a diverse range of job opportunities within the city administration, emphasizing job variety and security. Technically, the website is built on the TYPO3 CMS platform, utilizing the UIkit CSS framework for responsive design. The site demonstrates good mobile optimization and SEO practices, with structured data and Open Graph tags enhancing search engine visibility. Hosting appears to be managed via domaincontrol.com nameservers, commonly associated with GoDaddy services. Performance is moderate, with no critical technical issues detected in the provided content. From a security perspective, the site uses HTTPS as indicated by canonical URLs, and implements a cookie consent mechanism, reflecting basic privacy compliance. However, no explicit privacy policy, terms of service, security policy, or incident response contacts were found in the analyzed content. Security headers and vulnerability disclosures are absent, suggesting room for improvement in security posture. No signs of WAF or content blocking were detected, and the content is safe for general audiences. Overall, the website is professionally designed and credible as a municipal employment portal. Strategic recommendations include publishing comprehensive privacy and security policies, implementing security headers, and providing clear contact information for data protection and incident response to enhance trust and compliance.

45
43
17
70
72
50
20
governmentjobstrainingerfurtpublicsector+1 more
TYPO3 CMSUIkit CSS frameworkJavaScript
2025-10-30T13:23:48.317Z
sepos.cz favicon

SEPOS, spol. s r. o.

sepos.cz

0
RetailCzech RepublicmediumHIGH

SEPOS, spol. s r. o. is a Czech family-owned company specializing in the manufacturing and retail of interior and entrance doors, door frames, and fittings. With over 30 years of experience, the company serves a diverse clientele including investors, architects, construction firms, and end customers. Their business model combines retail and wholesale sales with comprehensive services such as professional advice, certified installation, and delivery. The company maintains a strong market position in the Czech Republic with multiple design stores nationwide. Technically, the website is built on the INT - JET CMS platform and uses modern web technologies including Foundation CSS framework, jQuery, and integrates analytics and marketing tools such as Google Tag Manager, Facebook Pixel, and Snowplow Analytics. The site is mobile-optimized and demonstrates good SEO and accessibility practices, although some accessibility features could be enhanced. From a security perspective, the website enforces HTTPS and implements cookie consent mechanisms compliant with GDPR. However, it lacks a publicly available security policy, incident response contacts, and security.txt file. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data confirms the domain's legitimacy and long-term registration consistent with the company's stated history. Overall, SEPOS.cz presents a professional and trustworthy online presence with solid business credibility and moderate technical maturity. Strategic improvements in security transparency and accessibility would further strengthen their posture.

20
25
2
87
52
85
20
doorsframesinteriormanufacturingretail+1 more
jQueryGoogle Tag ManagerFacebook PixelCloudfront+1
2025-10-30T13:21:17.933Z
ukwingchun.com favicon

UK Wing Chun Assoc.

ukwingchun.com

0
OtherUnited KingdomsmallHIGH

The UK Wing Chun Association operates as a small, specialized martial arts organization focused on Wing Chun Kung Fu training and community building within the United Kingdom. Founded in 1985 by Master James Sinclair, it holds a respected position in the martial arts community and offers classes, instructor resources, and merchandise through its website. The digital presence is built on a modern WordPress platform utilizing WooCommerce for e-commerce and Elementor for design, indicating a moderate level of digital maturity. The website is well-structured, mobile-optimized, and integrates social media and payment processing via PayPal, supporting a seamless user experience. From a security perspective, the site enforces HTTPS with good SSL configuration and employs Facebook Pixel for marketing and analytics. However, the absence of explicit security headers and a visible privacy policy or terms of service page indicates room for improvement in compliance and security posture. The WHOIS data for the domain is missing, which raises concerns about domain registration legitimacy and trustworthiness, despite the professional appearance and established business history claimed on the site. Overall, the website presents a professional and trustworthy front for its target audience but should address privacy compliance and domain registration transparency to enhance trust and security. Strategic recommendations include publishing comprehensive privacy and terms policies, implementing security headers, and verifying domain registration details to align with best practices and regulatory requirements.

15
73
2
70
67
70
20
martialartswingchunkungfuukwingchunmartialartsassociation+3 more
WordPressWooCommerceElementorjQuery+3

Partner Domains:

paypal.com
partner
2025-10-30T13:20:17.766Z
iapsm.org favicon

Indian Association of Preventive and Social Medicine

iapsm.org

0
HealthcareIndiamediumHIGH

The Indian Association of Preventive and Social Medicine (IAPSM) is a well-established non-profit professional organization founded in 1974, focused on advancing public health in India through education, research, advocacy, and community medicine programs. The website serves as a portal for members and the public to access information about events, publications, membership, and educational resources. The organization targets healthcare professionals, epidemiologists, and medical students in India, positioning itself as a key player in the public health sector. Technically, the website employs legacy JavaScript libraries such as jQuery 1.12.4 and plugins like bxSlider and jcarousel for UI components. Hosting appears to be via a shared hosting provider linked to PublicDomainRegistry.com. The site shows moderate performance and basic mobile optimization but lacks modern CMS or frameworks. SEO and accessibility features are basic, with room for improvement. From a security perspective, the site lacks visible security headers and DNSSEC is not enabled, which are areas of concern. There is no explicit HTTPS enforcement information available, and no privacy or cookie policies are present, indicating compliance gaps. The domain registration is consistent and legitimate, with a long registration period and transfer protections in place. Overall, the website is functional and professional but would benefit from enhanced security measures, privacy compliance improvements, and modernization of its technical stack to improve performance, security, and user trust.

15
35
2
85
62
70
-
publichealthcommunitymedicineprofessionalassociationindiaepidemiology+1 more
jQuery 1.12.4jcarouselbxSliderGoogle Fonts (Open Sans)
2025-10-30T13:19:37.665Z
ceats.org favicon

Centro de Administraciones Tributarias Subnacionales (CeATS)

ceats.org

0
GovernmentArgentinasmallHIGH

Centro de Administraciones Tributarias Subnacionales (CeATS) is a well-established non-profit organization based in Argentina, focused on subnational tax administration collaboration, training, and research. The website reflects a professional presence with clear navigation, relevant content, and active engagement through events and educational programs. The organization partners with universities and government tax agencies, reinforcing its credibility and market position in the government and education sectors. Technically, the website uses a modern but standard technology stack including Bootstrap, jQuery, and various carousel and slider libraries. Hosting is stable with a reputable registrar, and the site is mobile optimized with moderate performance. However, there is room for improvement in accessibility and SEO optimization. From a security perspective, the site uses HTTPS but lacks advanced security headers and DNSSEC, which are recommended to enhance protection. No privacy or cookie policies were found, indicating compliance gaps with GDPR and other privacy regulations. Contact information is clearly provided, supporting business credibility. Overall, the website is trustworthy and functional but would benefit from enhanced privacy compliance and security hardening to align with best practices and regulatory requirements.

15
35
17
85
62
60
-
governmenttaxationeducationnon-profittraining+2 more
jQueryBootstrapNivo SliderOwl Carousel+5

Partner Domains:

www.ciat.org
partner
www.ief.es
partner

+3 more partners

2025-10-30T13:19:27.630Z
hno-aerzte.de favicon

Deutscher Berufsverband der Hals-Nasen-Ohrenärzte e.V.

hno-aerzte.de

0
HealthcareGermanymediumHIGH

The Deutscher Berufsverband der Hals-Nasen-Ohrenärzte e.V. operates as a professional association for ENT (ear, nose, throat) specialists in Germany. The website serves as a comprehensive portal offering information about the association, professional development events, a marketplace for medical equipment and job postings, and patient education resources. It targets medical professionals and practice staff, positioning itself as a leading entity in the German healthcare sector for ENT specialists. Technically, the website is built on TYPO3 CMS, leveraging modern web technologies including Matomo for analytics and responsive design frameworks. The infrastructure is hosted on servers indicated by the agenturserver nameservers, with good mobile optimization and accessibility features. The site implements a cookie consent mechanism compliant with GDPR, and uses HTTPS with a solid SSL configuration. From a security perspective, the site demonstrates good practices such as encrypted connections, cookie consent, and no visible vulnerabilities or exposed sensitive data. However, it lacks explicit security policy documentation and incident response contacts, which are recommended for enhanced trust and compliance. The WHOIS data aligns well with the website's claims, supporting legitimacy. Overall, the website is professional, trustworthy, and well-maintained, with minor areas for improvement in security transparency and policy disclosures.

25
83
2
70
52
60
-
healthcaremedicalassociationhnoprofessionalassociationgermany+3 more
TYPO3 CMSMatomo AnalyticsBootstrap (implied by classes and JS)autoComplete.js
2025-10-30T13:16:30.259Z