Skip to main content

High-risk security reports

Browse 44,242 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

150709
Websites
130
Industries
113
Countries
52
Avg Score
Page 477 of 885|Showing 23801-23850 of 44242
crimilano.it favicon

Croce Rossa Milano

crimilano.it

42
HealthcareItalymediumHIGH

Croce Rossa Milano is a well-established humanitarian organization operating as the local committee of the Italian Red Cross in Milan, Italy. The organization focuses on providing emergency medical assistance, health services, social support, training, and volunteer engagement. Their website reflects a professional and comprehensive digital presence, targeting the general public, volunteers, donors, and beneficiaries. The site is well-branded, consistent, and provides clear navigation and relevant content about their mission and services. Technically, the website is built on Joomla CMS with modern frameworks such as Bootstrap 5 and Astroid Framework, incorporating smooth scrolling and user engagement tools like a chat widget. The site is mobile-optimized and uses standard SEO and accessibility practices, although accessibility could be improved further. Performance is moderate, with no critical technical issues detected. From a security perspective, the website enforces HTTPS with excellent SSL configuration and DNSSEC enabled, indicating strong domain security. Security headers are present, and forms use CSRF tokens, enhancing protection against common web attacks. However, the site lacks a dedicated security policy or incident response page, and no vulnerability disclosure mechanism is found, which are areas for improvement. Overall, the website is trustworthy, secure, and compliant with GDPR, featuring clear contact information and privacy policies. The domain's WHOIS data aligns with the organization's identity and history, reinforcing legitimacy. Strategic recommendations include publishing a security policy, adding incident response contacts, and enhancing accessibility and vulnerability disclosure practices.

20
68
2
70
32
60
-
humanitarianhealthcarenon-profitemergencyservicesvolunteering+2 more
Joomla CMSBootstrap 5jQueryFontAwesome+3

Partner Domains:

dona.crimilano.it
partner
2025-07-28T07:12:38.400Z
techschools.in favicon

CyberMedia India Limited

techschools.in

45
EducationIndiamediumHIGH

T-School, operated by CyberMedia India Limited, is a specialized platform focusing on technology education in India. It provides a range of services including digital and employability index reports, conferences, webinars, and blog series aimed at educational institutions, students, and industry stakeholders. The website demonstrates a solid market position within the niche of technology education research and events, supported by a consistent brand presence and professional content offerings. The platform leverages external resources such as dqindia.com and Google Drive for hosting reports and webinars, indicating a collaborative ecosystem. From a technical perspective, the website employs a modern frontend stack including Bootstrap, jQuery, and various UI libraries, ensuring good mobile optimization and user experience. However, the site lacks advanced SEO and accessibility features and does not appear to use a CMS or advanced backend frameworks. Performance is moderate, with room for improvement in technical modernization and infrastructure transparency. Security posture is basic; HTTPS is enabled but critical security headers are missing, and no privacy or cookie policies are present, which poses compliance risks especially under GDPR. No forms or data collection mechanisms are evident, reducing immediate data protection concerns but also limiting user engagement features. The WHOIS data aligns well with the business identity, supporting legitimacy and trustworthiness. Overall, the website is functional and professional but would benefit from enhanced security practices, privacy compliance measures, and improved technical SEO and accessibility to strengthen its digital maturity and trustworthiness.

15
50
2
60
62
75
20
educationtechnologyconferencereportswebinars+2 more
BootstrapjQueryOwl CarouselMagnific Popup+6

Partner Domains:

dqindia.com
partner
resources.dqindia.com
partner
2025-07-28T06:09:44.675Z
equalitymaine.org favicon

EqualityMaine

equalitymaine.org

45
Non-profitUnited StatesmediumHIGH

EqualityMaine is a well-established non-profit organization dedicated to securing full equality for LGBTQ+ individuals in Maine since 1984. The website reflects a strong commitment to advocacy, community building, education, and political engagement, targeting the LGBTQ+ community and allies within the state. The organization offers various programs including youth initiatives and training resources, positioning itself as a key player in the regional equality movement. Technically, the website is built on WordPress using the Kadence theme and integrates modern SEO tools such as Yoast SEO and Google Analytics via MonsterInsights. The site is mobile-optimized and demonstrates good design and navigation clarity, although some accessibility features could be enhanced. Performance is moderate, with no critical technical issues detected. From a security perspective, the site enforces HTTPS and includes basic best practices such as Google Analytics opt-out mechanisms. However, it lacks explicit security headers and formal privacy or cookie policies, which are important for compliance and user trust. The absence of WHOIS data limits domain trust verification, but the website content and branding strongly suggest legitimacy. Overall, EqualityMaine's website is professional, content-rich, and trustworthy, though improvements in privacy compliance and security hardening are recommended to enhance user confidence and regulatory adherence.

15
35
17
55
62
75
20
lgbtqnon-profitadvocacymaineequality+2 more
WordPressYoast SEO pluginKadence themeGoogle Analytics (MonsterInsights)+2
2025-07-28T06:08:18.572Z
falacosagiusta.org favicon

Fa' la cosa giusta!

falacosagiusta.org

47
OtherItalymediumHIGH

Fa' la cosa giusta! is a prominent Italian event organizer hosting the largest fair in Italy focused on organic products, km0, critical fashion, sustainable mobility, responsible tourism, and conscious consumption. The website promotes the upcoming event scheduled for March 13-15, 2026, targeting a general audience interested in sustainability and ethical consumption. The company maintains a consistent brand presence across multiple social media platforms, enhancing its market reach and engagement. Technically, the website is built on WordPress with popular plugins such as Yoast SEO, Smart Slider 3, and Slider Revolution, indicating a mature digital infrastructure. It employs standard analytics and marketing tools including Google Analytics, Google Tag Manager, and Facebook Pixel. The site is mobile-optimized and demonstrates good SEO practices, although accessibility features are basic. From a security perspective, the site uses HTTPS with a good SSL configuration but lacks several important security headers. No sensitive data exposure or vulnerable libraries were detected. However, the absence of privacy and cookie policies, as well as incident response information, indicates gaps in compliance and security transparency. Overall, the website presents a trustworthy and professional image aligned with its business goals but would benefit from enhanced privacy compliance and security hardening to improve user trust and regulatory adherence.

35
53
17
70
62
65
-
eventsustainabilityorganickm0criticalfashion+4 more
WordPressYoast SEO pluginSmart Slider 3Slider Revolution+4
2025-07-28T06:02:45.091Z
readandwritekzoo.org favicon

Read and Write Kalamazoo

readandwritekzoo.org

44
Non-profitUnited StatessmallHIGH

Read and Write Kalamazoo is a small nonprofit organization founded in 2012, dedicated to celebrating and amplifying youth voices through creative writing workshops, summer camps, in-school programs, and after school tutoring in Kalamazoo, Michigan. The organization focuses on equity, access, and trauma-informed approaches to nurture youth intellectual and creative confidence. The website reflects a well-structured and professionally designed platform that effectively communicates the mission and services of the nonprofit. The presence of donation links and community partnership information supports its nonprofit business model. Technically, the website is built on WordPress using modern plugins such as WPBakery Page Builder, Slider Revolution, and Ultimate VC Addons. It employs Google Analytics and Google reCAPTCHA for analytics and security respectively. The site is mobile optimized and uses HTTPS with good SSL configuration, though some security headers are missing. The website lacks explicit privacy and cookie policies, which is a compliance gap. From a security perspective, the site shows good practices like HTTPS enforcement and CAPTCHA on forms but could improve by adding security headers and publishing privacy and cookie policies. No vulnerabilities or suspicious domains were detected. WHOIS data is unavailable or protected, which is typical for nonprofits, and does not raise immediate concerns. Overall, the site is safe, professional, and trustworthy with room for compliance improvements.

15
35
17
40
72
70
20
nonprofiteducationyouthwritingcommunity+3 more
WordPressPHPjQueryGoogle Analytics+4

Partner Domains:

www.gifttool.com
partner
allegraportage.com
partner
2025-07-28T05:01:18.238Z
voxprima.com favicon

Deneme Bonusu Veren Siteler 2024 - Deneme Bonusu 2024

voxprima.com

49
OtherTurkeysmallHIGH

The website feminnem.com operates as an affiliate marketing platform specializing in promoting betting sites that offer trial bonuses for 2024. It targets Turkish-speaking users interested in gambling and betting bonuses, providing curated lists of popular, reliable, and bonus-offering betting platforms with affiliate referral links. The business model is primarily commission-based affiliate marketing within the gambling sector, a niche with moderate competition and regulatory scrutiny. Technically, the site is built using the AMP framework to ensure fast loading and excellent mobile optimization. It leverages Google Analytics for user tracking and employs modern AMP components for interactive content. The site appears to be hosted on a platform supporting AMP but lacks visible security headers and comprehensive privacy or cookie policies, which are important for compliance and user trust. From a security perspective, the site uses HTTPS, ensuring encrypted communication. However, the absence of security headers and lack of contact or incident response information limit its security posture. The missing WHOIS data for the domain raises concerns about domain registration legitimacy and transparency, which impacts overall trustworthiness. Overall, feminnem.com is a functional affiliate site with basic content quality and technical implementation but requires improvements in privacy compliance, security best practices, and business transparency to enhance credibility and user trust.

15
35
2
40
65
70
100
bettinggamblingaffiliatebonusturkish+2 more
AMP HTMLGoogle Analytics (gtag)AMP AnalyticsAMP Bind+3
2025-07-28T03:51:53.897Z
thewritersblock.org favicon

The Writers' Block

thewritersblock.org

49
RetailUnited StatessmallHIGH

The Writers' Block is a small, independent bookstore located in downtown Las Vegas, established in 2013. It offers a combination of retail book sales, free creative-writing classes for K–12 students, community events, book clubs, and a coffee shop, positioning itself as a community hub for literary and educational activities. The business targets local residents, students, and families interested in literature and creative writing. The website reflects this community-oriented business model with clear navigation and relevant content focused on its services and events. Technically, the website is built on a modern stack including React and Ant Design UI framework, hosted on Asmallorange servers, and powered by the Bookmanager e-commerce platform. It integrates payment processing via Clearent and uses Leaflet for map display. The site is moderately optimized for performance and mobile devices, with basic accessibility features. SEO and analytics implementations appear minimal or absent based on the provided data. From a security perspective, the site uses HTTPS and has domain transfer protections enabled, but lacks DNSSEC and explicit security headers. There are no visible vulnerabilities or exposed sensitive data, but the absence of privacy and cookie policies indicates compliance gaps, especially regarding GDPR. No incident response or security policy information is provided. Overall, the security posture is moderate but could be improved with standard best practices. The overall risk assessment is low to moderate. The site is legitimate, well-branded, and trustworthy for its business purpose but should address privacy compliance and enhance security headers. Strategic recommendations include implementing privacy and cookie policies, enabling DNSSEC, adding security headers, and publishing incident response contacts to improve trust and compliance.

15
50
2
85
72
75
20
bookstoreeducationcommunitylasvegasindependent+1 more
jQueryAnt Design UI frameworkLeaflet (for maps)Clearent payment processing scripts

Partner Domains:

bookmanager.com
partner
clearent.net
partner
2025-07-28T03:51:13.341Z
826boston.org favicon

826 Boston

826boston.org

46
EducationUnited StatessmallHIGH

826 Boston is a well-established nonprofit organization focused on youth literacy, writing, tutoring, and publishing in the Boston area. The organization operates with a clear mission to empower students through hands-on literacy projects and community engagement. Their website reflects a professional and consistent brand image, with clear calls to action for donations and volunteer involvement. The target audience includes students, volunteers, donors, and community members interested in educational support. The business model relies on donations, volunteer support, and partnerships with organizations such as AmeriCorps and the Massachusetts Service Alliance. Technically, the website is built on WordPress with a modern tech stack including jQuery, Bootstrap components, and integrations with Google Tag Manager, Facebook SDK, and Mailchimp for marketing and analytics. Hosting is inferred to be via GoDaddy, consistent with the domain's WHOIS data. The site performs moderately well with good mobile optimization and basic accessibility features. However, SEO and accessibility could be further enhanced. From a security perspective, the site enforces HTTPS and uses security-related plugins like Jetpack and Akismet. There are no visible vulnerabilities or exposed sensitive data. However, the absence of security headers and lack of published privacy, cookie, or incident response policies represent compliance and security gaps. The domain registration is privacy protected but consistent with a legitimate nonprofit entity, with a domain age appropriate for the organization's history. Overall, 826 Boston's website is a credible and professional platform supporting its nonprofit mission. Strategic improvements in privacy compliance, security headers, and incident response transparency would enhance trust and regulatory adherence. The site is safe for general audiences with no adult or questionable content detected.

20
35
2
70
62
80
20
nonprofiteducationyouthliteracytutoring+3 more
WordPressjQueryGoogle Tag ManagerFacebook SDK+3

Partner Domains:

give.826boston.org
service
americorps.gov
partner

+3 more partners

2025-07-28T03:50:17.926Z
C

C-Command Software, LLC

c-command.com

48
TechnologyN/asmallHIGH

C-Command Software, LLC is a small, specialized software company focused on developing utilities and productivity applications for macOS. Founded in 2002, the company offers a suite of products including DropDMG, EagleFiler, SpamSieve, ToothFairy, and others, targeting Mac users seeking efficient software solutions. The website presents clear product information, free trial downloads, and purchase options, positioning the company as a niche player in the Mac software market. The business model is direct sales with trial offerings, supported by a consistent and professional web presence. Technically, the website is built with basic HTML and CSS, hosted on DreamHost with DNS managed by DreamHost name servers. The site lacks modern CMS or frameworks and shows basic mobile optimization with a fixed viewport width. No advanced analytics or tracking scripts are detected, indicating a privacy-conscious approach. However, the absence of DNSSEC and security headers suggests room for improvement in technical security hardening. From a security perspective, the site uses HTTPS but lacks important security headers and DNSSEC, which lowers its security posture. There is no published security policy or incident response information, and no cookie or terms of service policies are present, indicating potential compliance gaps. The WHOIS data is consistent and trustworthy, with a long domain age and registrar status flags that protect against unauthorized transfers. Overall, the security risk is moderate but manageable. The overall risk assessment is moderate with a good business credibility score but some technical and compliance gaps. Strategic recommendations include enabling DNSSEC, implementing security headers, adding cookie and terms of service policies, and publishing security and incident response information to enhance trust and compliance.

15
53
2
65
62
70
40
macsoftwareutilitiesproductivitysoftwaremacos
HTMLCSS
2025-07-28T02:41:56.491Z
ctrlaltspeech.com favicon

Ctrl-Alt-Speech: A Podcast About The Latest In Online Speech

ctrlaltspeech.com

46
MediaN/asmallHIGH

Ctrl-Alt-Speech is a niche podcast focused on the latest news in online speech, hosted by recognized figures Mike Masnick and Ben Whitelaw. The website serves primarily as a portal to access podcast episodes and sponsorship information, linking to multiple popular podcast platforms. The business model centers on content production and sponsorship funding, supported by the Future of Online Trust & Safety Fund. The site is relatively new, consistent with the domain registration date in early 2024, and targets listeners interested in technology and online speech topics. Technically, the website uses standard web technologies including HTML5, CSS, JavaScript, and integrates the Buzzsprout podcast player. Hosting is provided by NameCheap, with a basic but functional HTTPS setup. The site is mobile optimized and has good SEO metadata but lacks advanced security headers and accessibility features. No CMS or complex frameworks are detected, indicating a lightweight, straightforward implementation. From a security perspective, the site benefits from HTTPS but lacks DNSSEC and security headers, which are recommended for enhanced protection. No privacy or cookie policies are present, which is a compliance gap. No contact information or incident response details are provided, limiting transparency. No vulnerabilities or suspicious content were detected, and the domain registration is consistent with the business timeline. Overall, the website is professionally presented with good content relevance and user experience but would benefit from improved security practices, privacy compliance, and contact transparency to enhance trust and regulatory adherence.

15
35
2
70
77
75
20
podcastonlinespeechmediatechnologynews
HTML5CSSJavaScriptBuzzsprout podcast player+1
2025-07-28T02:41:16.132Z
mijnselekthuis.nl favicon

MijnSelektHuis

mijnselekthuis.nl

49
OtherN/asmallHIGH

MijnSelektHuis appears to be a small-scale website likely related to real estate or housing services, as suggested by the site title and domain name. The website content is minimal, with no visible business descriptions, contact information, or user-facing content beyond basic HTML structure and JavaScript framework usage. The site uses the Dojo Toolkit for its frontend and is hosted under the registrar Combell B.V., with DNSSEC enabled and HTTPS active, indicating basic security hygiene. However, the lack of privacy policies, cookie consent mechanisms, terms of service, and contact details limits the site's transparency and user trust. From a technical perspective, the site employs modern JavaScript but lacks visible SEO optimization, accessibility features, and performance indicators. Security posture is moderate due to HTTPS and DNSSEC but is weakened by the absence of security headers and visible secure forms. No analytics, advertising, or tracking technologies were detected, suggesting minimal user data collection. Overall, the website presents a low-risk profile with no adult or explicit content detected. However, the lack of comprehensive content, policies, and contact information reduces its credibility and compliance standing. Strategic improvements in transparency, security headers, and user engagement features are recommended to enhance trust and compliance.

15
25
2
70
72
60
100
realestatepropertyhousingdutch
JavaScriptDojo Toolkit
2025-07-28T01:32:20.956Z
W

Wallkit, Inc.

wallkit.net

46
MediaUnited StatessmallHIGH

Wallkit, Inc. operates a sophisticated SaaS platform designed to empower modern media companies with AI-driven paywalls, memberships, and audience monetization tools. The company positions itself as a next-generation solution provider, targeting publishers and content creators seeking to optimize revenue streams through predictive and flexible subscription management. Their platform integrates seamlessly with major CRM and marketing tools, enhancing data-driven decision-making and user engagement. Technically, Wallkit leverages a modern technology stack including Google Analytics, Firebase, Stripe payments, and various JavaScript libraries, optimized primarily for WordPress but adaptable to other CMS platforms. The website demonstrates good performance, mobile responsiveness, and SEO optimization, reflecting a mature digital presence. Security measures include HTTPS enforcement, GDPR and CCPA compliance, and integration of Google reCAPTCHA to protect user data and forms. From a security perspective, Wallkit shows a strong posture with secure payment processing and data protection practices. However, the absence of a publicly available dedicated security policy and incident response information suggests areas for improvement in transparency and readiness. No critical vulnerabilities or suspicious activities were detected, indicating a trustworthy operational environment. Overall, Wallkit presents a credible, professional, and secure platform with a clear business focus and strong market positioning. Strategic enhancements in security documentation and incident response communication would further solidify trust and compliance.

15
65
17
70
-
70
40
mediapaywallmembershipaisubscription+3 more
Google AnalyticsGoogle Tag ManagerGoogle reCAPTCHAStripe Payments+5

Partner Domains:

stripe.com
partner
hubspot.com
partner

+3 more partners

2025-07-28T00:21:27.214Z
fictionalbrandsarchive.com favicon

Fictional Brands Archive

fictionalbrandsarchive.com

49
MediaN/asmallHIGH

Fictional Brands Archive is a niche online platform dedicated to cataloging and researching fictional brands featured across various media including films, series, videogames, and animated content. The website offers a searchable and filterable database with detailed brand information such as sector, category, media type, genre, and touchpoints, catering primarily to researchers, fans, and content creators interested in fictional brand lore. The platform's market position is specialized within the media industry, focusing on content curation rather than commercial services. Technically, the website employs standard web technologies including HTML5, CSS, JavaScript, and jQuery, with Google Analytics integrated for visitor tracking. The site demonstrates moderate performance and basic mobile optimization, with a clear navigation structure and consistent branding. However, it lacks advanced SEO and accessibility features, and no CMS or hosting provider information is evident from the content. From a security perspective, the site uses HTTPS and includes no forms collecting sensitive data, which reduces exposure to common web vulnerabilities. Nevertheless, it lacks visible security headers and formal security policies, and no incident response or vulnerability disclosure information is provided. Privacy compliance is weak, with no privacy or cookie policies found, and no GDPR compliance indicators. The absence of contact information further limits trust and business credibility. Overall, the website is functional and content-rich but requires improvements in privacy, security policies, and contact transparency to enhance trustworthiness and compliance. Strategic recommendations include implementing comprehensive privacy and cookie policies, adding security headers, improving mobile and accessibility features, and providing clear contact and incident response information.

20
35
47
40
95
65
20
fictionalbrandsmediaarchivefilmbrandsvideogamebrandsseriesbrands+1 more
HTML5CSSJavaScriptjQuery+1
2025-07-28T00:21:17.092Z