Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 5 of 22|Showing 201-250 of 1071
pico-interactive.com favicon

PICO

pico-interactive.com

62
TechnologyGermanylargeMEDIUM

PICO is a leading virtual reality company specializing in all-in-one VR headsets and immersive interactive experiences. Founded in 2015, PICO has established a strong market presence, particularly in China and globally, offering a range of consumer and enterprise VR products. Their business model includes hardware sales, software platforms, developer support, and community engagement, targeting both end consumers and enterprise clients. The website reflects a mature digital presence with comprehensive product information, localized content, and active marketing efforts. Technically, the website is built on modern frameworks such as React and leverages advanced analytics and marketing tools including Google Analytics, TikTok Pixel, and Facebook Pixel. The hosting infrastructure appears to be managed by ByteDance-related services, ensuring fast performance and good mobile optimization. SEO and accessibility practices are well implemented, contributing to a positive user experience. From a security perspective, the site enforces HTTPS, employs standard security headers, and integrates cookie consent mechanisms aligned with GDPR requirements. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of WHOIS domain registration data raises concerns about domain legitimacy and registration transparency, which should be further investigated. Overall, PICO's website demonstrates a high level of professionalism, security, and privacy compliance, supporting its position as a reputable VR technology provider. Strategic recommendations include enhancing transparency around security policies, incident response, and vulnerability disclosure to further strengthen trust and compliance.

20
68
7
70
62
85
100
virtualrealityvrheadsetall-in-onevrpicotechnology+2 more
ReactGoogle Tag ManagerGoogle AnalyticsTikTok Pixel+3

Partner Domains:

store-global.picoxr.com
partner
community.picoxr.com
partner

+2 more partners

2025-10-26T04:25:20.572Z
novartis.at favicon

Novartis Österreich

novartis.at

69
HealthcareAustriaenterpriseMEDIUM

Novartis Österreich is the Austrian branch of the global healthcare leader Novartis AG, focusing on innovative pharmaceutical research and therapies. The website serves as an official portal providing information about their products, research, sustainability efforts, and career opportunities, targeting healthcare professionals, patients, and job seekers in Austria. The site is well-branded, professionally designed, and localized in German, reflecting the company's commitment to the Austrian market. Technically, the website is built on Drupal CMS and integrates modern analytics and marketing tools such as Google Tag Manager, Crazy Egg, and TikTok Pixel, with appropriate cookie consent mechanisms ensuring GDPR compliance. Security posture is strong with HTTPS enforced and no visible vulnerabilities or exposed sensitive data, although explicit security headers could be improved. The WHOIS data for the domain is unavailable, which limits domain registration trust analysis, but the strong brand presence and consistent content mitigate concerns. Overall, the website demonstrates a mature digital presence with good privacy and security practices, supporting Novartis's reputation as a trusted healthcare provider.

65
88
2
85
47
85
100
healthcarepharmaceuticalnovartisaustriagdpr+3 more
Drupal CMSGoogle Tag ManagerCrazy EggTikTok Pixel

Partner Domains:

fachkreise.novartis.at
partner
gemeinsamgesund.novartis.at
partner
2025-10-25T18:54:22.782Z
columbusenergy.pl favicon

Columbus Energy S.A.

columbusenergy.pl

53
EnergyPolandlargeMEDIUM

Columbus Energy S.A. is a well-established Polish company specializing in renewable energy solutions for residential and business customers. Their offerings include photovoltaic installations, energy storage systems, heat pumps, intelligent energy management (Columbus Intelligence), and related services such as thermal modernization and electric vehicle charging stations. The company positions itself as a leading provider in Poland with a strong focus on eco-friendly and cost-saving technologies. The website is professionally designed, multilingual, and provides comprehensive information tailored to various customer segments including homeowners, businesses, farmers, and public institutions. Technically, the website is built on WordPress with modern frameworks and integrates multiple analytics and marketing tools such as Google Tag Manager, Facebook Pixel, LinkedIn Insight, TikTok Pixel, Microsoft Clarity, and SalesManago. It employs a cookie consent mechanism compliant with GDPR and provides detailed privacy policies. The site is mobile-optimized, SEO-friendly, and performs moderately well. From a security perspective, the site uses HTTPS and implements best practices such as asynchronous loading of scripts and cookie consent. However, DNSSEC is not enabled, and there is no visible security policy or vulnerability disclosure page. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data is consistent with the business claims, showing a domain registered since 2014, supporting the company's legitimacy. Overall, Columbus Energy's website demonstrates a mature digital presence with strong business credibility and good security posture. Recommendations include enabling DNSSEC, publishing a security policy, and adding a vulnerability disclosure mechanism to further enhance trust and security.

15
10
17
75
57
65
100
renewableenergyphotovoltaicsenergystorageheatpumpscolumbusintelligence+4 more
WordPressjQueryGoogle Tag ManagerFacebook Pixel+5

Partner Domains:

columbusenergy.com
partner
columbusenergy.cz
partner

+2 more partners

2025-10-25T17:27:23.137Z
flatironschool.com favicon

Flatiron School

flatironschool.com

69
EducationUnited StateslargeMEDIUM

Flatiron School is a well-established coding bootcamp founded in 2012, offering comprehensive on-campus and online courses in software engineering, data science, cybersecurity, AI, and game design. The company targets individuals seeking career advancement in technology fields and maintains a strong market position with over 20,000 alumni and partnerships with major tech companies. The website reflects a professional and modern digital presence with excellent content quality and user experience. Technically, the website is built on WordPress hosted likely on AWS infrastructure, utilizing a broad range of modern marketing and analytics tools including Google Tag Manager, Facebook Pixel, TikTok Pixel, Marketo, and Hotjar. The site is mobile-optimized, accessible, and SEO-friendly, though performance is moderate. Security posture is good with HTTPS enforced and domain registration protections in place, but could be improved by enabling DNSSEC and publishing explicit security policies. The security evaluation shows no critical vulnerabilities or exposed sensitive data. Privacy compliance is strong with visible cookie consent mechanisms and a comprehensive privacy policy. Business credibility is high with clear contact information, structured data, and trust indicators such as alumni network size and corporate partnerships. No adult or questionable content is present, making the site safe for general audiences. Overall, Flatiron School’s website demonstrates a mature digital infrastructure supporting its educational mission, with room for minor security enhancements. The domain registration data aligns well with the company’s history, reinforcing legitimacy and trustworthiness.

15
85
60
70
52
80
100
educationcodingbootcampsoftwareengineeringdatasciencecybersecurity+4 more
Google Tag ManagerGoogle AnalyticsFacebook PixelTikTok Pixel+10
2025-10-25T16:19:34.319Z
reflu.ch favicon

Reformierte Kirche Kanton Luzern

reflu.ch

62
GovernmentSwitzerlandmediumMEDIUM

The website www.reflu.ch serves as the official online presence of the Reformed Church of the Canton of Luzern, Switzerland. It provides information about church services, pastoral care, community events, and regional church congregations. The site targets local German-speaking community members seeking spiritual support and church-related activities. The business model is non-profit and government-affiliated, focusing on community and religious services. The website is well-branded and consistent with the church's identity, featuring event calendars and news updates that demonstrate active engagement with its audience. Technically, the site employs modern web technologies including HTML5, CSS3, JavaScript, and integrates tracking pixels from TikTok, Facebook, and Google Tag Manager. The site is mobile-optimized and offers a good user experience with clear navigation and relevant content. However, it lacks explicit privacy and cookie policies, which is a notable compliance gap. Security posture is generally good with HTTPS enforced, but the absence of security headers and explicit incident response contacts reduces the overall security maturity. From a security and compliance perspective, the site does not present critical vulnerabilities or exposed sensitive data. The WHOIS data aligns well with the website's claims, showing consistent registrant information appropriate for a regional church organization. No WAF or blocking mechanisms were detected, allowing full content access. The site does not contain any adult or NSFW content, making it safe for general audiences. Overall, the website is credible and professionally maintained but would benefit from enhanced privacy compliance measures and improved security headers. Adding clear contact information for security incidents and a vulnerability disclosure policy would further strengthen trust and compliance.

65
35
17
60
62
80
100
churchreligioncommunitypastoralcareevents+3 more
HTML5CSS3JavaScriptGoogle Tag Manager+4

Partner Domains:

refhorw.ch
partner
2025-10-25T11:15:42.520Z
D

DISCO S WAVE, INC.

disco.ac

65
MediaN/amediumMEDIUM

DISCO S WAVE, INC. operates the website disco.ac, providing an all-in-one music management platform designed to help artists, rights holders, brands, and music supervisors organize, share, and discover music tracks efficiently. The company positions itself as a trusted SaaS provider in the media industry with a strong customer base and a focus on simplifying music catalog management and collaboration. The platform leverages AI-powered discovery tools and offers mobile applications on iOS and Android, reflecting a modern and accessible digital infrastructure. Technically, the website is built using modern frameworks such as React and Next.js, hosted likely on Cloudflare infrastructure, and integrates various analytics and marketing tools including Google Tag Manager, TikTok Pixel, Facebook Pixel, and Intercom for customer engagement. The site demonstrates excellent performance, mobile optimization, and SEO practices, contributing to a high-quality user experience. From a security perspective, the site enforces HTTPS, implements key security headers, and provides a cookie consent mechanism aligned with GDPR compliance. However, it lacks publicly available security policies, incident response details, and vulnerability disclosure information, which are areas for improvement. The WHOIS data is not publicly available, indicating privacy protection, which is common for commercial SaaS businesses but slightly reduces transparency. Overall, the website presents a professional, trustworthy, and well-structured digital presence with moderate risk due to limited public registrant information and absence of explicit security disclosures. Strategic enhancements in transparency and security communication would further strengthen trust and compliance.

30
68
2
85
75
80
100
musicmanagementsaasmediamusicindustryplatform+3 more
ReactNext.jsCloudflare StreamIntercom+3
2025-10-25T09:11:47.152Z
direct-volley.fr favicon

Direct-Volley : chaussures, ballons, vêtements et équipements de volleyball

direct-volley.fr

57
RetailFrancemediumMEDIUM

Direct-Volley.fr is a specialized e-commerce retailer focused on volleyball equipment, apparel, and accessories, serving primarily the French market with multiple localized European domains indicating a broader regional presence. The website offers a comprehensive catalog including shoes, balls, protective gear, club equipment, and lifestyle products related to volleyball. The business appears well-established with a domain age of nearly 9 years and uses reputable hosting and CDN services via Cloudflare. The technical infrastructure is based on Magento (OpenMage), supported by modern analytics and marketing tools such as Google Analytics, Facebook Pixel, TikTok Pixel, and Criteo, reflecting a mature digital marketing strategy. Security posture is solid with HTTPS enforced, security headers present, and domain registration practices consistent with a legitimate retail business. However, the site lacks explicit privacy policy and terms of service pages, which are critical for GDPR compliance and user trust. Contact information and incident response details are also missing, limiting transparency. Overall, the site is professional, secure, and functional but would benefit from enhanced privacy and compliance documentation.

35
10
17
85
62
70
100
volleyballsportsequipmente-commerceretailsportswear+4 more
Magento (OpenMage variant)Cloudflare DNS and CDNGoogle Tag ManagerGoogle Analytics+6

Partner Domains:

direct-volley.nl
sister
direct-volley.pt
sister

+3 more partners

2025-10-24T18:38:06.488Z
basket-center.fr favicon

Basket-Center

basket-center.fr

57
RetailFrancemediumMEDIUM

Basket-Center is a well-established French e-commerce retailer specializing in basketball equipment and accessories, including official NBA merchandise and products from major brands such as Adidas, Nike, Wilson, and Mitchell & Ness. The company targets basketball players and fans primarily in France and Europe, offering a broad catalog with fast shipping and secure payment options. The website demonstrates a strong market position as an official distributor with a professional and consistent brand presence. Technically, the website is built on modern technologies including SvelteKit and is hosted behind Cloudflare, ensuring good performance and security. It employs multiple tracking and marketing tools such as Google Analytics, Facebook Pixel, TikTok Pixel, and a consent management platform to comply with GDPR. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS, implements security headers, and manages cookie consent effectively. No critical vulnerabilities or exposed sensitive data were detected. However, explicit security policies and incident response contacts are not publicly available, which could be improved to enhance trust and compliance. Overall, Basket-Center presents a low-risk profile with a strong business and technical foundation. Strategic recommendations include publishing a dedicated security policy, incident response information, and a vulnerability disclosure policy to further strengthen security posture and transparency.

15
10
17
85
75
70
100
e-commercesportsbasketballretailfashion+5 more
JavaScriptSvelteKitCloudflareGoogle Tag Manager+4

Partner Domains:

boulevard-du-golf.fr
partner
direct-running.fr
partner

+3 more partners

2025-10-24T18:37:56.434Z
gold.ac.uk favicon

Goldsmiths, University of London

gold.ac.uk

59
EducationUnited KingdomlargeMEDIUM

Goldsmiths, University of London is a well-established higher education institution specializing in creative, cultural, and social disciplines. The website reflects a strong market position as a leading university in South East London, offering degree programs, research opportunities, and community engagement. The target audience includes prospective and current students, academics, and researchers. The business model focuses on education and research services with a large institutional size and a history dating back to 1904. Technically, the website employs a modern technology stack including multiple analytics and advertising pixels managed through Google Tag Manager, and uses TerminalFour CMS. The site is mobile-optimized, accessible, and SEO-friendly, with good performance. Cookie consent and privacy mechanisms are robust, reflecting GDPR compliance. Security posture is solid with HTTPS enforced and no visible vulnerabilities or exposed sensitive data. However, the absence of explicit security headers and a public security policy or incident response page suggests room for improvement. The WHOIS data is unavailable or privacy protected, which is common for UK academic domains and justified in this context. Overall, the website is professional, trustworthy, and secure with minor recommendations to enhance security transparency and header implementation. The risk level is low, and the site effectively supports the university's digital presence and business objectives.

15
50
2
75
77
70
100
educationuniversityhighereducationlondoncreativearts+2 more
JavaScriptGoogle Tag ManagerGoogle AnalyticsTikTok Pixel+5
2025-10-24T17:02:58.262Z
lexrocket.de favicon

Haufe-Lexware GmbH & Co. KG

lexrocket.de

66
OtherGermanylargeMEDIUM

Haufe-Lexware GmbH & Co. KG is a well-established German software company specializing in business and accounting software solutions for self-employed individuals, freelancers, and small to medium-sized enterprises. Operating since 1993 as part of the Haufe Group, Lexware holds a strong market position in Germany, offering a range of products including accounting, payroll, and business management software, complemented by educational content and tools for entrepreneurs. The website content is professionally curated, targeting entrepreneurs and business owners with relevant knowledge and practical advice on business formation and management. Technically, the website is built on the TYPO3 CMS platform and integrates modern technologies such as Usercentrics for consent management, Econda for analytics, and Kameleoon for marketing optimization. The hosting infrastructure is managed by the Haufe Group, ensuring reliable performance and security. The site demonstrates good mobile optimization, accessibility, and SEO practices, contributing to a positive user experience. From a security perspective, the site enforces HTTPS and employs consent management to comply with privacy regulations. While explicit security headers are not visible in the provided data, no vulnerabilities or exposed sensitive data were detected. The company maintains comprehensive privacy and cookie policies, indicating a mature approach to data protection and GDPR compliance. However, the absence of a public security policy or incident response information suggests areas for improvement. Overall, Haufe-Lexware's website reflects a mature, trustworthy, and professional digital presence with strong business credibility and compliance posture. Strategic enhancements in security transparency and header implementation could further strengthen its security stance and user trust.

30
68
2
72
100
70
100
grndungbusinessentrepreneurshipaccountingsoftwaresmallbusiness+2 more
TYPO3 CMSJavaScriptUsercentrics Consent ManagerEconda Analytics+3

Partner Domains:

haufegroup.com
parent
lexbizz.de
subsidiary

+3 more partners

2025-10-24T16:12:05.799Z
fibbl.com favicon

Fibbl

fibbl.com

56
TechnologyN/amediumMEDIUM

Fibbl is a technology platform specializing in delivering 3D product experiences and content aimed at enhancing B2B sales, go-to-market strategies, and eCommerce efficiency. The company offers services including 3D viewers, virtual try-on solutions, and augmented reality experiences, positioning itself as a key player in the digital product experience market. Founded in 2015, Fibbl has established a medium-sized business presence with a focus on innovative technology solutions for brands. The website infrastructure is built on WordPress, leveraging modern JavaScript libraries such as Swiper.js and integrating multiple marketing and analytics tools including HubSpot, Google Tag Manager, TikTok Pixel, Facebook Pixel, LinkedIn Insight Tag, Dreamdata Analytics, and Hotjar. Cookie consent is managed via Cookiebot, ensuring compliance with cookie regulations and providing users with granular control over cookie preferences. From a security perspective, the site enforces HTTPS and employs a cookie consent mechanism, but lacks explicit security policy documentation and incident response contact information. No critical vulnerabilities or exposed sensitive data were detected in the HTML content. The domain registration is consistent with the business age and shows no suspicious patterns, enhancing trustworthiness. Overall, Fibbl demonstrates a solid technical and business foundation with good privacy compliance and marketing transparency. Strategic improvements include publishing comprehensive privacy and security policies, incident response details, and enhancing security headers to further strengthen the security posture.

15
83
2
87
72
85
20
3dproductexperienceb2becommerceaugmentedreality+3 more
WordPress 6.8.3jQuerySwiper.jsHubSpot scripts+7
2025-10-24T14:32:15.665Z
kuppel-basel.ch favicon

Kuppel Basel / Stiftung Kuppel

kuppel-basel.ch

45
HospitalitySwitzerlandsmallHIGH

Kuppel Basel is a small cultural event venue located in Basel, Switzerland, specializing in concerts, parties, and various cultural events. The website serves as a platform to showcase upcoming events, provide ticketing links, and share organizational information. The business targets a general audience interested in local cultural and nightlife activities. The market position is that of a local cultural hub with a focus on live music and community events. Technically, the website employs modern JavaScript libraries and tracking technologies including Google Tag Manager, Facebook Pixel, and TikTok Analytics. The site is mobile optimized with good navigation and design quality. However, there is room for improvement in accessibility and security headers implementation. Performance is moderate, and SEO practices are adequately addressed through meta tags. From a security perspective, the site uses HTTPS with an excellent SSL configuration but lacks important security headers and published security policies. There is no visible privacy or cookie policy, which impacts GDPR compliance negatively. The extensive use of third-party tracking scripts without a consent mechanism raises privacy concerns. No incident response or vulnerability disclosure information is provided. Overall, the website is professionally presented and trustworthy for its business purpose but requires enhancements in privacy compliance and security best practices to reduce risk and improve user trust.

15
35
2
55
95
80
-
kuppelbaseleventsconcertsculture+2 more
JavaScriptGoogle Tag ManagerFacebook PixelTikTok Pixel+3

Partner Domains:

tickets.kuppel-basel.ch
service
2025-10-24T11:31:42.047Z
aftral.com favicon

AFTRAL

aftral.com

64
TransportationFrancelargeMEDIUM

AFTRAL is a leading French organization specializing in professional training and education in the transport and logistics sectors. The website offers a comprehensive catalog of courses ranging from CAP to BAC+6 levels, supported by a network of over 120 training centers and multiple campuses. The business targets professionals and students seeking qualifications and certifications in transport, logistics, and supply chain management. The site is well-structured, with clear navigation and a professional design consistent with its market position. Technically, the website is built on Drupal 7 with a variety of contributed modules and libraries such as jQuery UI and Apache Solr for search functionality. It integrates modern tracking and consent management tools including Google Tag Manager, TikTok Pixel, and Cookiebot, indicating a moderate level of digital maturity. Performance and mobile optimization are adequate, though some technical debt is implied by the use of older jQuery versions. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms, but lacks visible advanced security headers and explicit security or incident response policies. The absence of WHOIS domain registration data raises concerns about domain legitimacy, though the website content and branding strongly suggest a legitimate and established entity. No critical vulnerabilities or exposed sensitive data were detected. Overall, AFTRAL's website presents a professional and trustworthy front for its educational services, but would benefit from enhanced transparency in privacy policies, contact information, and domain registration details to strengthen trust and compliance.

20
65
2
80
90
80
100
transportlogisticseducationtrainingfrance+2 more
Drupal 7jQuery 1.7jQuery UIColorbox+4

Partner Domains:

isteli.aftral.com
partner
ept.aftral.com
partner

+3 more partners

2025-10-24T11:15:57.303Z
musikhug.ch favicon

Musik Hug

musikhug.ch

73
RetailSwitzerlandmediumMEDIUM

Musik Hug is a well-established Swiss retailer specializing in musical instruments, sheet music, accessories, rental services, and repair workshops. The company operates multiple physical stores across Switzerland and maintains a comprehensive online presence, targeting musicians, students, and music enthusiasts. Their business model combines retail sales, rentals, and music education services, positioning them as a key player in the Swiss music retail sector. Technically, the website leverages modern JavaScript modules, integrates popular analytics and marketing tools such as Google Analytics, Facebook Pixel, TikTok Pixel, and Hotjar, and uses the Opacc e-commerce platform. The site is mobile-optimized and provides a good user experience with clear navigation and professional design. Security-wise, the website enforces HTTPS, implements strong security headers, and includes session timeout mechanisms, reflecting a mature security posture. However, explicit security policies and incident response contacts are not publicly available, and no vulnerability disclosure program is evident. Overall, the site is trustworthy, compliant with GDPR, and demonstrates good privacy practices with cookie consent management. Strategic recommendations include publishing a dedicated security policy, incident response information, and a vulnerability disclosure framework to enhance transparency and trust.

85
53
17
87
72
85
100
musicinstrumentsretailswitzerlande-commerce+3 more
JavaScript ES6 modulesTiny SliderGoogle Tag ManagerGoogle Analytics+5
2025-10-24T05:43:41.938Z
elevatefestival.ca favicon

Elevate Festival

elevatefestival.ca

61
TechnologyCanadamediumMEDIUM

Elevate Festival is a prominent Canadian technology and innovation event held annually in Toronto, designed to connect startups, investors, and tech professionals through immersive experiences, networking, and educational programming. The festival has established a strong market position with notable speakers and founding sponsors such as TD, Moneris, and Interac, reflecting its influence in the Canadian tech ecosystem. The website is professionally designed, mobile-optimized, and leverages a modern technology stack centered on WordPress with extensive analytics and marketing integrations. From a technical perspective, the site uses Cloudflare for DNS and CDN services, employs multiple tracking and analytics tools including Google Analytics, Facebook Pixel, TikTok Pixel, and PostHog, and integrates HubSpot forms for user engagement. While the site is well-structured and SEO optimized, it lacks a visible cookie consent mechanism and DNSSEC is not enabled, which are areas for improvement in privacy and security compliance. Security posture is generally good with HTTPS enforced and domain registration protections in place, but the absence of a published security policy or incident response contact reduces transparency. The WHOIS data shows privacy protection for the registrant, which is justified for this type of event organization. Overall, the site demonstrates a mature digital presence with room to enhance privacy compliance and security best practices. Strategic recommendations include enabling DNSSEC, implementing a clear cookie consent mechanism, publishing security and incident response policies, and conducting regular audits of third-party scripts to mitigate potential vulnerabilities.

75
70
53
100
2
30
75
technologyinnovationfestivalconferencecanada+2 more
WordPressYoast SEOjQuerySwiper.js+9

Partner Domains:

elevate.ca
parent
moneris.com
partner

+2 more partners

2025-10-24T04:49:06.300Z