Skip to main content

High-risk security reports

Browse 46,997 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 5 of 940|Showing 201-250 of 46997
triflesolutions.co.uk favicon

Trifle Solutions

triflesolutions.co.uk

48
TelecommunicationsUnited KingdomsmallHIGH

Trifle Solutions is a UK-based telemarketing company specializing in B2B lead generation and appointment setting services. Founded in 2004 by Shahida Afzal, a recognized telephone sales expert, the company emphasizes quality data, persistent outreach, and consultative selling to connect clients with senior decision makers. The website reflects a professional and consistent brand image, targeting businesses seeking outsourced telemarketing solutions primarily in Reading and across the UK. The company leverages a structured employee development program to maintain low staff turnover and high-quality service delivery. Technically, the website is built on WordPress using the Elementor page builder and Yoast SEO plugin, indicating a modern and maintainable infrastructure. It employs common marketing and analytics tools such as Google Tag Manager, Facebook Pixel, and LinkedIn Insight Tag, enabling moderate user tracking and campaign measurement. The site is mobile optimized with good SEO practices but lacks explicit privacy and cookie policies, which is a compliance gap. From a security perspective, the site uses HTTPS with a good SSL configuration and includes some security best practices. However, it lacks explicit security headers and incident response information, which could be improved to enhance trust and resilience. No vulnerabilities or suspicious patterns were detected in the visible content or WHOIS data. The domain is long-established and consistent with the business history, enhancing legitimacy. Overall, the website presents a trustworthy and professional telemarketing service with room for improvement in privacy compliance and security transparency. Strategic recommendations include adding comprehensive privacy and cookie policies, implementing security headers, and publishing incident response contacts to strengthen compliance and user trust.

15
58
17
85
57
70
-
telemarketingleadgenerationb2boutsourcedtelemarketingreading+1 more
WordPressElementorYoast SEOjQuery+1
2026-08-09T07:04:45.881Z
C

www.chsservices.com

chsservices.com

49
OtherN/asmallHIGH

The domain chsservices.com currently hosts a parked page courtesy of GoDaddy.com, indicating no active business or website content. The page contains minimal information, primarily advertising the availability of the domain for purchase. The presence of a Trustpilot widget links to GoDaddy reviews rather than any business-specific reputation. The domain WHOIS query returned no registration data, suggesting the domain may be unregistered, expired, or privacy-protected with no public data available. This lack of registration data combined with the parked page status indicates the domain is not currently in active use by a legitimate business. From a technical perspective, the site uses basic JavaScript and CSS assets served by GoDaddy's parking platform. There is no evidence of a CMS or advanced frameworks beyond the parking system's own scripts. The site is mobile-optimized to a basic degree but lacks meaningful content, SEO optimization, or accessibility features. No security headers or HTTPS information were detected, which is typical for parked domains but represents a security risk if the domain were to be used actively. Security posture is minimal with no visible security best practices implemented. The absence of HTTPS and security headers, combined with no contact or incident response information, results in a low security score. Privacy compliance is also minimal, with only a basic privacy policy link present but no cookie consent or GDPR indicators. Business credibility is low due to the lack of company information, contact details, or certifications. Overall, the domain appears to be inactive and not currently used for any legitimate business purpose. The risk level is low in terms of active threats but high in terms of trust and legitimacy. Strategic recommendations include registering the domain properly, deploying a secure website with HTTPS, adding comprehensive privacy and security policies, and providing clear business contact information to impro…

25
53
2
60
57
75
100
parkeddomainparkinggodaddytrustpilotplaceholder
JavaScriptReact (inferred from JSX-like div id=root)Trustpilot widget
2026-08-09T07:01:50.431Z
mannwilliams.co.uk favicon

Mann Williams Limited

mannwilliams.co.uk

47
Real EstateUnited KingdommediumHIGH

Mann Williams Limited is a UK-based consulting structural and civil engineering firm specializing in both conservation and new build projects. The company emphasizes a flexible and innovative approach to engineering within the construction process, targeting clients in the construction and real estate sectors. Their expertise includes digital engineering and they hold a notable position with the most CARE registered engineers in the UK. The website presents a professional portfolio of projects and company information, supporting their market position as a reputable medium-sized engineering consultancy. Technically, the website employs modern web technologies including JavaScript, CSS, and SVG graphics, with performance and mobile optimization rated as good. However, there is no detected CMS or hosting provider information. The site lacks explicit privacy and cookie policies, and no security headers were detected, indicating room for improvement in security posture. The WHOIS data is unavailable due to a domain registration error, which raises concerns about domain legitimacy despite the professional website content. Security-wise, the site uses HTTPS as implied by canonical URLs but lacks visible security headers and formal security or incident response policies. No vulnerabilities or exposed sensitive data were found, but the absence of privacy and cookie policies and WHOIS transparency are notable gaps. Overall, the site is safe for general audiences and professionally presented but would benefit from enhanced security and compliance measures. The overall risk assessment suggests the website is legitimate and professional but requires attention to domain registration legitimacy, privacy compliance, and security best practices to strengthen trust and reduce potential risks.

25
35
2
85
57
60
40
engineeringstructuralengineeringcivilengineeringconsultingconstruction+2 more
JavaScriptCSSHTML5SVG+2
2026-08-08T07:23:48.583Z
elliottmortlockbusby.co.uk favicon

Elliott Mortlock Busby and Co

elliottmortlockbusby.co.uk

47
FinanceUnited KingdomsmallHIGH

Elliott Mortlock Busby and Co is a UK-based chartered certified accountancy firm offering a comprehensive range of financial services including accountancy, tax, payroll, bookkeeping, and cloud accounting. The company targets small to medium-sized businesses and individuals, providing tailored solutions and expert consultation. The website reflects a professional and trustworthy business with clear service offerings and positive client testimonials, positioning it as a reputable local accountancy practice. Technically, the website is built on WordPress with modern plugins such as WPBakery Page Builder and Slider Revolution, leveraging Google Fonts and Cloudinary for optimized content delivery. The site is mobile-optimized and includes essential SEO and accessibility features, though some accessibility aspects could be improved. Performance is moderate, with caching and lazy loading implemented. Security posture is solid with HTTPS enforced and Google reCAPTCHA protecting contact forms. However, security headers like Content-Security-Policy and X-Frame-Options are not explicitly detected, and no vulnerability disclosure or incident response information is provided. The WHOIS data is unavailable due to domain registration issues, which slightly impacts trust but the website content and business information appear legitimate. Overall, the site presents a low-risk profile with good business credibility and technical implementation. Strategic improvements in security headers and privacy compliance could further enhance trust and protection.

15
53
17
85
47
60
20
accountingtaxpayrollbookkeepingcloudaccounting+4 more
WordPressPHPjQueryGoogle reCAPTCHA+4
2026-08-08T07:23:37.979Z
principalforensicservices.com favicon

Principal Forensic Services (PFS) Ltd

principalforensicservices.com

46
GovernmentUnited KingdomsmallHIGH

Principal Forensic Services (PFS) Ltd is a UK-based independent forensic science company established following the closure of the UK's Forensic Science Service. The company is led by experts with over 300 years of combined experience, providing expert witness services and forensic consultancy to solicitors, police forces, companies, and private individuals. Their market position is strong within the forensic science sector, offering a comprehensive range of forensic disciplines and bespoke training services. The website is professionally designed, well-structured, and targets legal and law enforcement professionals as well as private clients. Technically, the website is built on WordPress using the Pro Cornerstone theme and employs modern technologies such as Yoast SEO and Google reCAPTCHA for spam protection. The site is mobile-optimized with good SEO practices and moderate performance. However, some security best practices such as security headers are missing, and there is no cookie consent mechanism, which could be improved. From a security perspective, the site uses HTTPS and reCAPTCHA, which are positive indicators. The absence of security headers and lack of published security or incident response policies are areas for improvement. The WHOIS data is missing or inaccessible, which raises some concerns about domain registration transparency, although the professional nature of the site and consistent branding support legitimacy. Overall, the website presents a credible and professional business with room for technical and security enhancements. Strategic recommendations include implementing security headers, adding cookie consent, publishing security policies, and resolving WHOIS transparency issues to enhance trust and compliance.

20
53
2
70
57
75
20
forensicforensicscienceexpertwitnessukconsultancy+2 more
WordPressYoast SEO pluginGoogle reCAPTCHAjQuery
2026-08-08T07:23:16.700Z
F

Robot Challenge Screen

ferpay.com

46
OtherN/asmallHIGH

The website www.ferpay.com currently serves a security challenge page designed to block automated access, likely implemented via a proof-of-work captcha mechanism. This indicates the presence of a Web Application Firewall (WAF) or similar security control that restricts direct content access. Due to this blocking, no substantive business information, contact details, or user-facing content is accessible for analysis. The domain WHOIS data is unavailable, suggesting the domain may be unregistered, privacy-protected, or otherwise inaccessible, which further complicates trust and legitimacy assessments. From a technical perspective, the site uses JavaScript-based cryptographic challenges and is hosted behind Amazon Cloudfront CDN. However, no information about SSL/TLS configuration or security headers is available. The lack of privacy, cookie, or terms of service policies indicates poor compliance with common web standards and regulations. The site’s content quality and user experience are minimal due to the blocking mechanism. Security posture is limited by the inability to fully assess the site behind the WAF challenge. While the proof-of-work captcha is a positive security control against bots, the absence of visible security headers and policies is a concern. The domain’s legitimacy is questionable given the missing WHOIS data and lack of business presence. Overall, the site is currently inaccessible for meaningful analysis, resulting in a low AI score. Strategic recommendations include verifying domain registration, implementing transparent privacy and cookie policies, improving accessibility, and ensuring proper security headers and HTTPS configuration once the blocking mechanism is adjusted to allow legitimate user access.

20
50
2
60
37
70
100
securitycaptchabot-protectionwaf
JavaScriptWeb Crypto APISHA1Base64
2026-08-08T07:21:29.969Z
zoomcom.tv favicon

Zoom Communications

zoomcom.tv

44
MediaIndiamediumHIGH

Zoom Communications is a well-established broadcast services company specializing in outside broadcast solutions, flypacks, OB trucks, system integration, and content creation primarily serving the South Asian and Southeast Asian markets. The company has a strong market position with deployments in over 21 countries and notable involvement in major sporting events such as the Indian Premier League and Commonwealth Games. Their website reflects a professional and consistent brand image with good content quality and clear navigation. Technically, the website uses a modern frontend stack including Bootstrap 5 and Owl Carousel, with some legacy jQuery usage. The site is mobile optimized and performs moderately well, though accessibility and SEO could be improved. No CMS or hosting provider details were detected. Security posture is moderate with no HTTPS or security headers explicitly confirmed, and no forms collecting sensitive data, reducing immediate risk exposure. The absence of WHOIS data suggests privacy protection for domain registration, which is common for media companies but reduces transparency. The website lacks privacy and cookie policies, which is a compliance gap. Contact information is clearly provided, including a company email and phone number, and a verified YouTube channel link enhances trust. Overall, the website is professional and trustworthy with moderate technical and security maturity. Strategic improvements in privacy compliance, security headers, and WHOIS transparency would enhance trust and reduce risk.

30
35
2
75
37
80
20
broadcastoutsidebroadcastflypackscontentcreationmediaservices+1 more
jQuery 2.1.1Bootstrap 5.3.8Owl CarouselGoogle Fonts (League Gothic, Open Sans)
2026-08-08T07:20:52.653Z
P

Robot Challenge Screen

plattreilly.co.uk

46
OtherN/asmallHIGH

The website www.plattreilly.co.uk currently serves a bot challenge screen that blocks direct access to its content. This challenge uses a JavaScript proof-of-work captcha mechanism, indicating the presence of a Web Application Firewall (WAF) or similar security control to prevent automated access. Due to this blocking, no meaningful business content, contact information, or policies are accessible for analysis. The domain WHOIS lookup failed with an error indicating the domain name violates Nominet UK naming rules, suggesting the domain may be invalid or misconfigured. This severely limits the ability to assess the legitimacy or business operations of the entity behind the domain. From a technical perspective, the site uses modern JavaScript features and AWS Cloudfront CDN for hosting static assets, but lacks visible security headers, privacy policies, or SEO optimizations. The security posture is minimal, relying mainly on the bot challenge to prevent abuse. No contact or compliance information is present, and no forms or data collection mechanisms are detected. Overall, the site is inaccessible for normal users without passing the challenge, and the domain registration issues further reduce trustworthiness. The security controls in place are basic and focused on blocking automated access rather than comprehensive security or compliance. The lack of business information and policies indicates the site is either under development, misconfigured, or intended solely as a security gate. Strategic recommendations include resolving domain registration issues, providing clear business and compliance information, improving security headers and HTTPS enforcement, and enhancing user experience by reducing intrusive bot challenges.

20
50
2
75
37
65
100
wafbot-challengecaptchasecurityblocked+1 more
JavaScriptWeb Crypto APIBlobTextEncoder+1
2026-08-08T07:20:36.778Z
ecopakinternational.com favicon

Ecopak International Limited

ecopakinternational.com

43
ManufacturingN/amediumHIGH

Ecopak International Limited operates as a global manufacturer specializing in polythene products with joint venture factories in China and Vietnam. Their product range includes various types of polythene bags, can liners, carrier bags, disposable gloves, and cleaning wipes. The company targets wholesalers, distributors, retailers, and the food service industry worldwide, exporting over 100 containers monthly. The website content is straightforward and business-focused, presenting their manufacturing expertise and product offerings clearly. From a technical perspective, the website employs legacy JavaScript libraries such as jQuery 1.11.1 and uses Google Analytics for visitor tracking. The site lacks modern security headers and visible HTTPS enforcement in the provided data, which raises concerns about secure communications. Mobile optimization and accessibility are basic, and SEO practices appear minimal. No CMS or hosting provider information is discernible from the content. Security posture is weak due to the absence of HTTPS confirmation, missing security headers, and lack of privacy or cookie policies. The WHOIS data is notably absent, with the domain appearing unregistered or WHOIS information unavailable, which is inconsistent with the active website presence and business claims. This discrepancy reduces trust and raises legitimacy concerns. Overall, while the business content is relevant and the website functional, significant improvements in security, privacy compliance, and transparency are recommended to enhance trustworthiness and protect user data.

20
35
2
75
57
80
20
manufacturingpolytheneexportbagsdisposablegloves+1 more
jQuery 1.11.1jQuery Slimbox2jQuery bxSliderGoogle Analytics
2026-08-08T07:19:59.216Z
comskills4health.org.uk favicon

comskills4health

comskills4health.org.uk

38
HealthcareUnited KingdomsmallHIGH

ComSkills4Health is a UK-based not-for-profit organization dedicated to improving the health and psycho-social wellbeing of individuals affected by cancer, including patients, their families, carers, and healthcare professionals. The organization offers evidence-based training workshops, educational multimedia materials, and supports conferences aimed at cancer patients. The website reflects a focused niche presence within the healthcare non-profit sector, emphasizing education and support services. The business is small in size and registered as a charity and company limited by guarantee in England and Wales. Technically, the website employs standard HTML5 and CSS3 technologies, leveraging W3.CSS and Font Awesome for styling and icons. The site is mobile-optimized with clear navigation and consistent branding. However, there is no evidence of a CMS or advanced hosting details. Performance is moderate, and accessibility features are basic. No analytics or tracking scripts were detected, indicating a privacy-conscious approach. From a security perspective, the website lacks visible security headers and privacy or cookie policies, which are important for compliance and user trust. The WHOIS lookup failed due to a domain naming rules violation error from Nominet UK, resulting in no registrar or registration date information. This anomaly reduces trustworthiness but does not necessarily indicate malicious intent given the legitimate content and charity registration details on the site. Overall, the security posture is basic, with recommendations to implement HTTPS, security headers, and privacy policies. The overall risk assessment is moderate with no critical vulnerabilities detected in the content or structure. Strategic recommendations include improving security configurations, adding compliance documentation, and resolving WHOIS registration issues to enhance trust and legitimacy.

15
35
2
70
57
60
-
healthcarecancereducationnon-profittraining+1 more
HTML5CSS3W3.CSSFont Awesome 4.3.0
2026-08-08T07:19:53.899Z
G

Greenearth Hydro Limited

greenearthhydro.co.uk

38
EnergyUnited KingdomsmallHIGH

Greenearth Hydro Limited is a small UK-based company specializing in the design and installation of micro-hydro renewable energy systems for domestic and commercial clients primarily in Wales and the West Midlands. Their services include system design, installation, operation, and maintenance, positioning them as a niche player in the renewable energy sector focused on hydropower. The website content is basic but relevant, providing contact details and downloadable resources to support potential customers. Technically, the website is built with simple HTML and CSS without advanced frameworks or CMS detected. There is no evidence of HTTPS or security headers, and no analytics or tracking scripts are present. The site is accessible without WAF or security challenges but lacks modern technical and security best practices, including privacy and cookie policies. From a security perspective, the absence of HTTPS and security headers, combined with the lack of privacy compliance documentation, indicates a low security posture. The WHOIS lookup failed due to domain registration issues, which raises concerns about domain legitimacy despite the professional appearance of the website content and contact information. Overall, the website presents a moderate risk profile with critical recommendations to implement HTTPS, add privacy and cookie policies, and resolve domain registration issues to improve trust and security compliance.

15
50
2
70
47
65
-
greenearthhydromicrohydrorenewableenergyhydropowerfeedintariff
HTMLCSS
2026-08-08T07:19:00.627Z
norfolkdrainservices.co.uk favicon

Norfolk Drain Services Ltd

norfolkdrainservices.co.uk

49
OtherUnited KingdomsmallHIGH

Norfolk Drain Services Ltd is a small, family-run business specializing in domestic and commercial drainage solutions in Norwich and the surrounding Norfolk area. Their services include drain maintenance, installation, repairs, cleaning, and CCTV surveys. The company positions itself as a reliable and professional local expert with a strong reputation, supported by customer testimonials and a trusted trader badge. The website is built on the SilverStripe CMS platform and employs common web technologies such as jQuery and Google Analytics for tracking. The site is well-structured with clear navigation and professional content, targeting homeowners and businesses needing drainage services. However, the WHOIS data for the domain is unavailable due to a domain registration error from Nominet UK, which raises questions about the domain's registration legitimacy, although the website content itself appears legitimate and professional. Security posture is moderate with no visible HTTPS confirmation or security headers, and privacy compliance is basic with a privacy policy present but no cookie consent mechanism. Overall, the website is functional and trustworthy from a business perspective but would benefit from improved security and compliance measures.

20
53
2
40
47
60
100
drainservicesnorfolkblockeddrainsdraincleaningcommercialdrains+2 more
Google AnalyticsGoogle Tag ManagerjQuery 2.1.4
2026-08-08T07:18:44.644Z