Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149092
Websites
130
Industries
113
Countries
52
Avg Score
Page 604 of 624|Showing 30151-30200 of 31160
cartflows.com favicon

CartFlows

cartflows.com

65
TechnologyN/amediumMEDIUM

CartFlows is a mature and well-established WordPress sales funnel builder platform, founded in 2018, with a strong market position and a large user base exceeding 223,000 users. The company offers a comprehensive suite of funnel-building tools including one-click upsells, order bumps, A/B split testing, and conversion-optimized templates, targeting WooCommerce store owners, online course creators, agencies, and consultancies. The website is professionally designed with excellent content quality and clear navigation, optimized for mobile and SEO. Technically, the site is built on WordPress with Elementor and integrates multiple marketing and analytics tools, but suffers from slow load times and lacks a valid SSL certificate, which is a critical security concern. Security posture is basic with HSTS enabled but no valid TLS protocols or OCSP stapling, and malformed CAA records. Privacy compliance is partially met with a clear privacy policy but no cookie consent mechanism detected. Business credibility is strong with testimonials and trust signals, but contact information is limited to forms without direct emails or phone numbers. Overall, the site is functional and professional but requires urgent security improvements to ensure trust and compliance.

65
43
25
75
97
80
100
wordpresswoocommercesalesfunnele-commercemarketing+2 more
WordPressWooCommerceElementorUltimate Addons for Gutenberg+6

Partner Domains:

my.cartflows.com
service
2025-06-15T05:51:24.108Z
pandadoc.com favicon

PandaDoc Inc.

pandadoc.com

61
TechnologyUnited StatesenterpriseMEDIUM

PandaDoc Inc. is a mature, enterprise-level technology company founded in 2013, specializing in document workflow automation, e-signature solutions, and CPQ software. The company holds a strong market position with over 50,000 clients and offers a comprehensive suite of services including document generation, deal rooms, smart content, automations, and analytics. Their platform integrates with major CRM and payment systems, enhancing business efficiency and customer experience. Technically, PandaDoc employs a modern tech stack with JavaScript, HubSpot forms, Google Tag Manager, and various marketing and analytics tools. The website is hosted on AWS and uses WordPress CMS with WPML for multilingual support. Despite rich content and good mobile optimization, the website suffers from critical security issues due to an invalid SSL certificate and lack of TLS protocols, which significantly impacts its security posture. Security-wise, PandaDoc demonstrates strong compliance with SOC 2, HIPAA, GDPR, E-SIGN, and UETA standards, reflecting a robust security framework. However, the absence of a valid SSL certificate and modern TLS support exposes the site to potential risks. The domain is well-protected and mature, indicating a legitimate and trustworthy business. Overall, while PandaDoc excels in business credibility, content quality, and privacy compliance, it must urgently address its SSL/TLS configuration to improve security and maintain trust. Strategic improvements in SSL deployment and security best practices are recommended to enhance the company's digital security posture.

85
25
25
100
50
85
100
documentmanagemente-signaturecpqworkflowautomationcompliance+2 more
JavaScriptHubSpot formsGoogle Tag ManagerOneTrust (cookie consent)+7

Partner Domains:

hubspot.com
partner73
salesforce.com
partner67

+3 more partners

2025-06-15T05:41:16.962Z
ab180.co favicon

주식회사 에이비일팔공

ab180.co

66
TechnologySouth KoreamediumMEDIUM

AB180 is a Korean technology company specializing in data-driven marketing solutions and consulting services. The company offers a full funnel marketing platform including proprietary and partner solutions such as Airbridge for mobile marketing attribution, Braze for marketing automation, and Amplitude for product analytics. Positioned as a leading marketing technology provider in South Korea, AB180 serves top domestic enterprises and emphasizes comprehensive consulting from data collection to strategy execution. The website is professionally designed, content-rich, and targets marketing professionals and enterprises seeking advanced marketing analytics and automation tools. Technically, the site leverages modern web technologies including Webflow CMS, Google Analytics, Facebook Pixel, and various JavaScript libraries. While the site uses HTTPS with modern TLS protocols and has valid SPF and DMARC DNS records, it lacks some security headers and HSTS, which could be improved to enhance security posture. Privacy compliance is partial, with a clear privacy policy but no visible cookie consent mechanism. The domain is mature and registered via privacy protection, which is common for tech companies but slightly reduces transparency. Overall, AB180 presents a credible, professional, and technically competent online presence with room for security and privacy enhancements.

30
25
25
75
87
80
100
marketingdataanalyticstechnologykoreanb2b+1 more
Google AnalyticsGoogle Tag ManagerFacebook PixelAirbridge SDK+7
2025-06-15T05:40:05.920Z
zip.lv favicon

Zip.lv

zip.lv

40
Real EstateLatviamediumHIGH

Zip.lv is a well-established Latvian online classified ads platform, operating since 2008, offering a wide range of categories including transport, real estate, jobs, and various goods and services. The website targets Latvian-speaking users seeking a centralized marketplace for buying, selling, and exchanging items and services. It maintains a consistent brand presence and provides clear contact information and comprehensive privacy and cookie policies, demonstrating good compliance with GDPR requirements. Technically, the site utilizes a variety of modern web technologies and third-party services such as jQuery, Google Fonts, FontAwesome, Google Analytics, Facebook SDK, and Stripe for payments. It is hosted behind Cloudflare, indicating a robust hosting infrastructure. However, the site suffers from a critical security issue: the absence of a valid SSL certificate and lack of HTTPS support, which severely impacts its security posture and user trust. The security posture is weak due to missing HTTPS, no HSTS, no security headers, and no DMARC or DNSSEC configurations. Despite this, the site employs a detailed consent management platform with extensive vendor disclosures, reflecting a strong commitment to privacy compliance and transparency. The site integrates numerous advertising and analytics vendors, indicating extensive user tracking and data collection practices. Overall, while the business and privacy compliance aspects are strong, the lack of HTTPS and related security measures present a significant risk. Addressing these security gaps is critical to improving user trust and safeguarding data. The site’s performance is slow, likely due to large page size and numerous resources, suggesting opportunities for optimization.

20
-
25
70
90
75
40
classifiedsadvertisingrealestatejobstransport+4 more
jQueryGoogle FontsFontAwesomeGoogle Analytics+7
2025-06-15T05:00:39.213Z
momentingroup.com favicon

Momentin Group Oy

momentingroup.com

57
HospitalityFinlandmediumMEDIUM

Momentin Group Oy is a Finnish holding company fully owned by the Lehdon family, operating primarily in the hospitality sector with a focus on beverage products and restaurant services. The group comprises approximately 150 experts and leverages over 30 years of industry experience. Their subsidiaries include Brew Seeker, Restaurants, Mallaskoski, eDrinks, Momentin Baltics, and various minority ownerships. The website presents a professional and consistent brand image with good content quality and clear navigation, targeting both B2B and B2C audiences within the hospitality industry in Finland. Technically, the website is built on WordPress with WooCommerce and uses modern frontend technologies such as Bootstrap and jQuery. Hosting is provided via WP Engine with Cloudflare as a CDN and security proxy. SEO is supported by structured data (JSON-LD) and Yoast SEO plugin. However, performance metrics are unavailable, and accessibility is basic. The site is mobile optimized and includes cookie consent mechanisms. From a security perspective, the website has critical deficiencies. There is no valid SSL certificate detected, and no TLS protocols are enabled, resulting in a lack of HTTPS protection. Security headers are partially implemented but could be improved. DNS security features such as DNSSEC and CAA records are missing, and no DMARC record is present for email protection. These issues expose the site to potential interception and phishing risks. Overall, the site scores moderately on content and business credibility but poorly on security posture. Strategic improvements in SSL/TLS deployment, DNS security, and privacy compliance are recommended to enhance trust and protect user data.

50
25
25
85
75
75
100
wordpresswoocommercebootstrapcloudflarecookieconsent+3 more
WordPressPHPjQueryBootstrap+4
2025-06-14T22:42:29.219Z
paddioinsurance.com favicon

Paddio Insurance

paddioinsurance.com

49
OtherUnited StatessmallHIGH

Paddio Insurance is a small insurance agency operating primarily in the United States, offering a broad range of insurance products including home, auto, renters, and specialty insurance lines. The company partners with major insurance carriers and provides customers with competitive quotes and personalized service. Their website reflects a professional and consistent brand image, targeting individuals and families seeking insurance coverage. The business model relies on partnerships and referral programs to expand its market reach. Technically, the website is built on a traditional stack using nginx, Bootstrap 3, jQuery, and integrates third-party marketing and analytics tools such as Google Analytics and Marketo Munchkin. Hosting is on AWS infrastructure. While the site is mobile responsive and SEO optimized with structured data, performance metrics are missing, and some accessibility features are basic. The site uses embedded forms for lead capture but lacks modern CMS indications. From a security perspective, the website has significant weaknesses. It lacks a valid SSL certificate and does not serve content over HTTPS, exposing users to potential interception risks. Security headers are minimal or absent, and no advanced SSL features like HSTS or OCSP stapling are enabled. Privacy compliance is partial, with a privacy policy and terms of use present but no cookie consent mechanism or GDPR compliance indicators. Contact information is clearly provided, but no incident response or security policy details are available. Overall, the website is functional and professional but requires urgent improvements in security posture, especially enabling HTTPS and implementing security headers. Privacy compliance should be enhanced with cookie policies and consent mechanisms. These steps will improve user trust, regulatory compliance, and reduce risk exposure.

15
43
25
50
50
85
100
insurancehomeinsuranceautoinsuranceinsurancequotesinsuranceagency+1 more
nginxPleskLinBootstrap 3jQuery+5

Partner Domains:

policygenius.com
partnerpending
ezlynx.com
partnerpending
2025-06-14T22:22:36.582Z
shiftboard.com favicon

Shiftboard, Inc.

shiftboard.com

51
ManufacturingUnited StatesenterpriseMEDIUM

Shiftboard, Inc. is an enterprise-level SaaS provider specializing in employee scheduling software tailored for mission-critical industries such as manufacturing, energy, and corrections. The company operates as a subsidiary of UKG and offers products like SchedulePro and ScheduleFlex to streamline workforce management, improve scheduling efficiency, and enhance employee engagement. The website demonstrates strong branding, customer trust signals, and comprehensive content targeting workforce managers in shift-based operations. Technically, the website is built on WordPress with performance optimizations via WP Rocket and hosted on AWS infrastructure using S3 and CloudFront. It integrates multiple marketing and analytics tools including Google Analytics, Google Ads, HubSpot, and social media platforms. The site is mobile-optimized and SEO-friendly with structured data and Open Graph metadata. From a security perspective, the site lacks a valid SSL certificate and does not serve content over HTTPS, which is a critical vulnerability. While some security headers like HSTS are present, the absence of TLS protocols and secure cipher suites significantly lowers the security posture. Privacy compliance is well addressed with visible privacy and cookie policies and consent mechanisms. Overall, the website is professional and content-rich but requires urgent remediation of SSL/TLS issues to ensure secure user interactions and maintain trust.

30
25
25
50
50
90
100
employeeschedulingworkforcemanagementmanufacturingenergycorrections+2 more
WordPress 6.8.1WP Rocket (performance optimization)jQuery 3.7.1Google Fonts (Lato)+10

Partner Domains:

ukg.com
parent62
2025-06-14T22:17:29.915Z
veteransunited.com favicon

Veterans United Home Loans

veteransunited.com

60
FinanceUnited StateslargeMEDIUM

Veterans United Home Loans is a leading mortgage lender specializing in VA home loans, serving veterans and military families across the United States. The company holds a strong market position as the top VA purchase lender by volume for multiple consecutive years, offering a comprehensive suite of services including VA loans, refinancing, realty, insurance, and credit building. Their website reflects a professional and user-friendly digital presence with extensive educational content, customer reviews, and interactive tools such as mortgage calculators and eligibility forms. Technically, the site leverages a modern JavaScript stack with jQuery, Google Tag Manager, and custom form frameworks, hosted on AWS infrastructure. However, the security posture is currently weak due to the absence of a valid SSL certificate and disabled TLS protocols, which poses a significant risk to user data confidentiality and trust. Privacy policies and cookie consent mechanisms are well implemented, supporting compliance with general privacy standards. Overall, the site demonstrates strong business credibility and digital maturity but requires urgent remediation of its SSL/TLS configuration to ensure secure user interactions.

55
43
17
50
90
90
100
valoansmortgageveteranshomeloansfinance+1 more
PHP 7.4.33jQuery 3.6.0Tiny SliderMoment.js+4

Partner Domains:

mortgageresearchcenter.com
subsidiary53
neighborsbank.com
partner54

+2 more partners

2025-06-14T22:11:25.753Z
emilemagazine.fr favicon

Sciences Po Alumni

emilemagazine.fr

40
MediaFrancesmallHIGH

Émile Magazine is a French non-profit media publication operated by Sciences Po Alumni, targeting the alumni community and readers interested in political and social analysis. The website serves as an online extension of the quarterly print magazine, offering articles, interviews, and portfolios contributed by journalists, researchers, and alumni. The business model focuses on community engagement and content dissemination without evident commercial sales or e-commerce. Technically, the website is built on the Squarespace platform, leveraging its CMS and hosting services. The site uses Google Analytics and Tag Manager for visitor tracking and Typekit for fonts. However, the site suffers from slow performance due to a large page size and many resources. Mobile optimization is good, but accessibility features are basic. From a security perspective, the site lacks a valid SSL certificate and does not serve content securely over HTTPS. No security headers or email authentication DNS records (DMARC, SPF) are configured, exposing the site to potential risks. Privacy and cookie policies are absent, indicating poor compliance with GDPR and related regulations. Overall, the site is content-rich and professionally designed but requires urgent improvements in security and privacy compliance to enhance trust and protect user data.

35
-
25
50
50
75
100
alumnimagazinesciencespofrenchmedia+1 more
Squarespace CMSGoogle AnalyticsTypekit FontsSquarespace JavaScript libraries+1
2025-06-14T22:08:34.615Z
transdevna.jobs favicon

Transdev North America, Inc.

transdevna.jobs

40
TransportationUnited StateslargeHIGH

Transdev North America, Inc. operates a comprehensive career portal focused on transportation jobs across North America. As the largest private-sector provider of multiple transportation modes including transit, rail, and on-demand services, the company targets job seekers interested in diverse roles such as drivers, management, safety, and technical positions. The website provides detailed information about career opportunities, benefits, and hiring processes, supported by a consistent brand presence and trust indicators such as an EEO statement and a Code of Business Conduct. Technically, the site is built on modern frameworks like Nuxt.js and Vue.js, with integrations for Google Analytics, Facebook Pixel, and other marketing tools. However, performance is slow and accessibility is basic. Security posture is weak due to the absence of a valid SSL certificate, lack of security headers, and missing DNS security records, which poses significant risks to user data and trust. Privacy compliance is basic with a cookie consent mechanism and a privacy policy, but GDPR compliance is not clearly demonstrated. Overall, the site is functional and professional but requires urgent security improvements to protect users and enhance credibility.

80
43
25
60
50
75
100
transportationcareersjobstransdevnorthamerica+4 more
Nuxt.jsGoogle Tag ManagerGoogle AnalyticsFacebook Pixel+3

Partner Domains:

icims.com
partnerpending
bcbsil.com
partnerpending
2025-06-14T22:04:02.940Z
vu.com favicon

Veterans United Home Loans

vu.com

67
Real EstateUnited StateslargeMEDIUM

Veterans United Home Loans is a leading mortgage lender specializing in VA home loans, serving veterans and military families across the United States. The company holds the position as the nation's #1 VA lender by volume for multiple consecutive years, demonstrating strong market leadership and trust within its target audience. Their website offers comprehensive services including VA home loans, refinancing options, mortgage calculators, and additional services such as credit building and insurance. The site features extensive customer testimonials and a robust multi-step lead form designed to capture detailed mortgage-related information securely. Technically, the website employs a modern technology stack including jQuery, Formocity forms, and various analytics and tracking tools such as Google Tag Manager and TrustedForm. Hosting is provided via Amazon AWS, ensuring scalability and reliability. While the site is mobile-optimized and accessible with good SEO practices, performance is somewhat slow with a high load time and large page size, indicating potential areas for optimization. From a security perspective, the site uses valid SSL certificates supporting TLS 1.2 and 1.3, but lacks advanced security headers and HSTS enforcement, which are recommended to enhance security posture. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with clear privacy and cookie policies and consent mechanisms in place. Contact information is prominently displayed, enhancing business credibility. Overall, Veterans United Home Loans presents a professional, trustworthy, and secure online presence with minor technical and security improvements recommended to further strengthen their digital maturity and user experience.

55
43
17
50
82
85
100
valoansmortgageveteranshomeloansfinance+1 more
jQuery 3.6.0Formocity form frameworkTiny SliderMoment.js+7

Partner Domains:

neighborsbank.com
partnerpending
mortgageresearchcenter.com
partnerpending

+3 more partners

2025-06-14T22:02:07.083Z
network-box.com favicon

Network Box Corporation Ltd.

network-box.com

57
TechnologyHong KongmediumMEDIUM

Network Box Corporation Ltd. operates a professional website offering managed cybersecurity services globally, targeting businesses of all sizes. Their core offerings include 24x7x365 managed security services, penetration testing, dark web monitoring, and zero trust endpoint security. The company positions itself as a cost-effective, enterprise-grade MSSP with a strong focus on real-time protection and comprehensive cyber defense. Technically, the website is built on Squarespace with standard web technologies and integrates Google Analytics and Tag Manager for tracking. However, the site lacks a valid SSL/TLS certificate, resulting in an insecure HTTP connection, which is a critical security concern. Security headers are partially implemented but could be improved. Privacy compliance is basic with a cookie banner and privacy policy present, but no explicit GDPR compliance indicators or terms of service are found. The site includes multiple contact forms with CAPTCHA protection and active social media channels, enhancing business credibility. Overall, the website is professional and content-rich but requires urgent security improvements to enable HTTPS and strengthen its security posture.

50
43
55
50
50
85
100
managedsecurityservicescybersecuritymsspnetworksecuritypenetrationtesting+5 more
SquarespacejQueryGoogle Tag ManagerGoogle Analytics+1

Partner Domains:

boxoffice.network-box.com
partner
response.network-box.com
partner
2025-06-14T22:01:41.429Z
lecepe.fr favicon

Ensae-Ensai Formation Continue (Cepe)

lecepe.fr

40
EducationFrancemediumHIGH

Ensae-Ensai Formation Continue (Cepe) is a well-established continuing education center affiliated with the Groupe des écoles nationales d'économie et statistique (Genes) in France. It specializes in providing professional training and certification programs in statistics, data science, finance, and economics. The organization maintains strong partnerships with prestigious institutions such as Ensae Paris, Ensai, Crest, and Institut Polytechnique de Paris, positioning itself as a reputable education provider in its sector. The website reflects a professional and comprehensive approach to education, targeting professionals and learners seeking advanced skills and certifications in quantitative fields. Technically, the website employs modern web technologies including Bootstrap, jQuery, Font Awesome, and integrates third-party services like Google Analytics and Calendly for analytics and scheduling. Hosting is managed through Gandi, and the site uses a valid SSL certificate with strong key length, although some security enhancements such as HSTS and DNSSEC are absent. Performance is moderate to slow due to a large number of resources and page size, but mobile optimization and accessibility are adequately addressed. From a security perspective, the site uses HTTPS with a valid certificate and implements cookie consent mechanisms aligned with GDPR requirements. However, it lacks several security headers and DNS security features that could improve its security posture. No critical vulnerabilities or blocking mechanisms were detected, indicating a stable and secure environment for users. Privacy policies and terms of service are clearly available, enhancing compliance and user trust. Overall, the website demonstrates a strong business credibility and professional presence with room for technical and security improvements. Strategic recommendations include enhancing security headers, enabling DNSSEC and CAA, optimizing performance, and publishing incident response information to further strengthen trust and compliance.

20
-
17
50
82
85
100
educationtrainingdatasciencestatisticsfinance+3 more
BootstrapjQueryFont AwesomeGoogle Analytics+2

Partner Domains:

ensae.fr
partner40
ensai.fr
partner40

+3 more partners

2025-06-14T21:59:29.791Z