Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149091
Websites
130
Industries
113
Countries
52
Avg Score
Page 61 of 61|Showing 3001-3048 of 3048
refinitiv.com favicon

LSEG

refinitiv.com

52
FinanceN/aenterpriseMEDIUM

LSEG Data & Analytics, part of the London Stock Exchange Group, is a leading global provider of financial market data, analytics, and workflow solutions serving a broad range of financial institutions worldwide. The company leverages strategic partnerships, such as with Microsoft, and exclusive access to Reuters News to deliver comprehensive and actionable financial insights. Their offerings span data feeds, analytics platforms, and specialized workflow tools designed for asset managers, investment bankers, traders, and wealth managers. Technically, the website is built on Adobe Experience Manager and integrates multiple modern technologies including Adobe Launch, Google Analytics, and OneTrust for privacy compliance. However, the site suffers from critical SSL/TLS misconfigurations, lacking a valid certificate and secure protocols, which severely impacts its security posture. Performance is moderate to slow, with a large page size and load time. Security-wise, while the site implements DMARC with a strict reject policy and uses cookie consent mechanisms, the absence of proper HTTPS and presence of a subdomain takeover vulnerability on ftp.refinitiv.com present significant risks. The site uses extensive analytics and marketing tools, indicating a mature digital marketing strategy but also raising privacy considerations. Overall, the website is professionally designed with excellent content quality and strong business credibility but requires urgent remediation of its SSL/TLS and subdomain security issues to improve trust and security compliance.

70
25
25
50
50
65
100
financedataanalyticsfinancialtechnologylsegrefinitiv
Adobe Launch (Adobe DTM)Google Analytics (gtag.js)Kaltura video playerDemandbase+2

Partner Domains:

lseg.com
parentpending
microsoft.com
partner69
2025-06-14T19:24:36.772Z
ritzcarlton.com favicon

The Ritz-Carlton Hotel Company, L.L.C.

ritzcarlton.com

74
HospitalityUnited StatesenterpriseMEDIUM

The Ritz-Carlton website represents a leading luxury hospitality brand under Marriott International, offering a comprehensive portfolio of hotels, resorts, residences, and unique experiences such as yachts and curated journeys. The site is designed with a strong focus on user experience, featuring rich content, multi-language support, and detailed navigation to assist luxury travelers in planning their stays. Technically, the site leverages Adobe Experience Manager as its CMS, integrates Brightcove for video content, and uses Akamai for hosting and service worker management. While the site exhibits a slow load time due to its large resource count and page size, it maintains good mobile optimization and accessibility standards. Security-wise, the website enforces HTTPS with modern TLS protocols, implements SPF and DMARC for email security, and uses OneTrust for cookie consent management, reflecting a mature security posture. However, there is room for improvement in enabling HSTS and certificate transparency. Overall, the site is highly professional, secure, and compliant with privacy regulations, making it a trustworthy platform for its target audience.

50
25
25
85
97
85
100
luxuryhospitalityhotelsresortstravel+2 more
Adobe Experience Manager (AEM)Brightcove Video PlayerjQueryGlide.js carousel+4

Partner Domains:

marriott.com
parent47
ritzcarltonyachtcollection.com
subsidiarypending

+2 more partners

2025-06-14T19:04:27.444Z
commercetools.com favicon

commercetools GmbH

commercetools.com

67
E-commerceGermanyenterpriseMEDIUM

commercetools GmbH is a leading enterprise-grade commerce platform provider specializing in versatile solutions for B2B, B2C, and omnichannel commerce. The company offers a comprehensive suite of services including commerce platform capabilities, solution hubs, payment and AI hubs, premium support, and expert services. Recognized by top analyst firms such as Gartner and IDC, commercetools holds a strong market position with a global enterprise customer base and a robust partner ecosystem. Their platform is designed to empower enterprises with flexibility, scalability, and innovation acceleration. Technically, commercetools leverages modern JavaScript frameworks, cloud hosting on Amazon AWS, and integrates advanced marketing and analytics tools such as Google Tag Manager, VWO, and OneTrust for cookie consent management. The website demonstrates good performance and mobile optimization, with a consistent and professional design that supports a seamless user experience. The technical infrastructure supports extensive tracking and analytics while maintaining compliance with privacy regulations. From a security perspective, commercetools employs a valid SSL certificate, SPF and DMARC email authentication policies, and uses OneTrust for managing cookie consent, indicating a mature approach to data privacy and security. However, there is room for improvement in enabling HSTS, DNSSEC, and additional security headers to enhance protection against common web threats. No critical vulnerabilities or subdomain takeover risks were detected. Overall, commercetools presents a strong digital presence with a secure and compliant infrastructure, well-aligned with enterprise needs. Strategic recommendations include enhancing transport security with HSTS, implementing DNSSEC, and publishing a vulnerability disclosure policy to further strengthen trust and security posture.

90
25
17
80
82
90
100
enterprisecommerceb2bcommerceb2ccommercecomposablecommerceomnichannel+3 more
JavaScriptAmazon AWSGoogle Tag ManagerOneTrust Cookie Consent+5

Partner Domains:

qualified.com
partnerpending
cookielaw.org
partner69
2025-06-14T18:39:49.333Z
vanillareply.com favicon

Reply

vanillareply.com

65
E-commerceGermanymediumMEDIUM

Vanilla Reply, a part of the Reply group, specializes in tailored e-commerce, CMS, and PIM solutions primarily serving the German market. The company leverages strong partnerships with leading technology providers such as Shopware, Sylius, Akeneo, Storyblok, and TYPO3 to deliver integrated and agile digital experiences. Their business model focuses on consulting, custom software development, and cloud-based operations, positioning them as a trusted medium-sized player in the e-commerce sector. Technically, the website employs modern web technologies including Google Tag Manager, reCAPTCHA, OneTrust for cookie consent, and Google Maps API. The hosting is managed via register.it with a valid SSL certificate supporting TLS 1.3 and 1.2, and OCSP stapling enabled. However, performance is somewhat slow with a page load time of over 8 seconds, indicating potential optimization opportunities. The site is well-optimized for mobile and accessibility, with good SEO practices. From a security perspective, the site demonstrates good practices such as strong TLS protocols and no known SSL vulnerabilities. However, it lacks DNSSEC, CAA records, and DMARC, which are recommended for enhanced DNS and email security. The cookie consent mechanism is robust and GDPR compliant, but no explicit security policy or incident response information is publicly available. Overall, Vanilla Reply presents a professional and trustworthy digital presence with strong business and technical foundations. Strategic improvements in DNS security, email authentication, and performance optimization would further enhance their security posture and user experience.

80
43
25
70
72
75
100
e-commercecontentmanagementdigitalexperienceakeneocelum+5 more
Google Tag ManagerGoogle reCAPTCHAOneTrust Cookie ConsentGoogle Maps API+2

Partner Domains:

shopware.com
partner56
sylius.com
partnerpending

+3 more partners

2025-06-14T18:20:05.966Z
koelnmesse.com favicon

Koelnmesse GmbH

koelnmesse.com

63
OtherGermanylargeMEDIUM

Koelnmesse GmbH is a leading trade fair and event organizer based in Cologne, Germany, with a century-long history since its founding in 1924. The company operates over 80 trade fairs and exhibitions both locally and in key global markets, serving a diverse audience including exhibitors, visitors, and trade fair organizers. Koelnmesse has a strong market position, recognized for its sustainability efforts and industry leadership, including recent awards such as 'Company of the Year' 2025 and 'Pioneer in Sustainability 2024'. Technically, the website employs a modern tech stack including jQuery, OneTrust for privacy management, Google Tag Manager, and various third-party integrations for social media and advertising. Hosting is provided via Amazon AWS infrastructure. Performance is moderate with good mobile optimization and basic accessibility features. SEO practices are good, supporting the company's digital presence. From a security perspective, while email security is well managed with valid SPF and DMARC records, the absence of a valid SSL certificate and lack of modern TLS protocols represent significant vulnerabilities. The site lacks HSTS, OCSP stapling, and other advanced security headers, lowering its overall security posture. No vulnerability disclosure or security.txt files were found, indicating limited transparency in security incident handling. Overall, Koelnmesse presents a professional and trustworthy online presence with strong business credentials but requires urgent improvements in its SSL/TLS configuration and security best practices to protect user data and maintain compliance with modern security standards.

30
40
17
75
90
80
100
tradefairseventsexhibitionskoelnmessecologne+7 more
jQueryAdobe Illustrator SVGsOneTrust Cookie ConsentGoogle Tag Manager+5

Partner Domains:

koelncongress.de
subsidiarypending
softgarden.io
servicepending
2025-06-14T18:18:34.128Z
if.lt favicon

If P&C Insurance AS filialas

if.lt

55
FinanceLithuanialargeMEDIUM

If P&C Insurance AS filialas operates the website if.lt, providing a wide range of insurance products including automobile, home, pet, travel, personal, and business insurance primarily targeting private individuals and businesses in Lithuania. The company is positioned as a leading insurance provider in the Baltic region, offering online services and customer self-service portals. The website is well-branded and provides comprehensive information about insurance products and customer support. Technically, the site uses a mix of technologies including jQuery, Microsoft Application Insights, OneTrust for cookie consent, and Google Tag Manager, hosted on Microsoft Azure DNS infrastructure. However, the website suffers from a critical security issue due to the absence of a valid SSL certificate and lack of modern TLS protocol support, which undermines secure communications and user trust. The site demonstrates good GDPR compliance with detailed privacy and cookie policies and active consent mechanisms. Performance is slow with a high page load time and large page size, but mobile optimization and accessibility are well addressed. Overall, the security posture requires urgent improvement to protect user data and maintain trust.

-
-
25
85
50
85
100
insuranceinsuranceproductsprivacycookieconsentgdpr+2 more
jQueryMicrosoft Application InsightsOneTrust Cookie ConsentGoogle Tag Manager+1

Partner Domains:

if.ee
sister68
if.lv
sister63
2025-06-14T17:37:00.728Z
L

LexisNexis Risk Solutions

zetx.com

73
GovernmentUnited StatesenterpriseMEDIUM

LexisNexis Risk Solutions, operating the Accurint® TraX™ platform, provides advanced investigative solutions primarily targeting law enforcement and government agencies. Their platform integrates call detail records with law enforcement and identity data to enable efficient device geolocation investigations. The company is positioned as a trusted, enterprise-level provider with a comprehensive suite of services including investigative support, training, and single sign-on capabilities with related products. The website reflects a mature digital presence with extensive content, strong branding, and a focus on compliance and privacy. Technically, the website employs a robust technology stack including JavaScript frameworks, VWO for optimization, Adobe DTM for tag management, and OneTrust for cookie consent management. Hosting is on Amazon AWS with a valid SSL certificate, though some TLS protocol support appears limited. Performance is moderate to slow due to large page size and resource count, but mobile optimization and accessibility are well addressed. From a security perspective, the site implements key best practices such as HSTS and valid SSL, but lacks DNSSEC and CAA records, which are recommended for enhanced security. No explicit security policy or incident response information is publicly available, indicating an area for improvement. The site demonstrates good privacy compliance with clear policies and consent mechanisms. Overall, LexisNexis Risk Solutions maintains a high level of professionalism and trustworthiness in its online presence, supporting its role as a critical provider of investigative and risk management solutions. Strategic enhancements in security posture and transparency could further strengthen its market position and customer confidence.

80
40
30
85
97
85
100
accurinttraxlexisnexisrisksolutionslawenforcementdevicegeolocationcalldetailrecords+7 more
JavaScriptjQueryBootstrapVWO (Visual Website Optimizer)+7

Partner Domains:

lexisnexis.com
partneranalyzing...
accurint.com
partner60
2025-06-14T13:03:35.492Z
L

LexisNexis

nexis.com

69
OtherUnited StatesenterpriseMEDIUM

LexisNexis operates as a leading provider of legal, regulatory, and business information services, targeting primarily legal professionals and researchers. The website analyzed is a secure sign-in portal for accessing their research services, reflecting a mature enterprise-level business model with a strong market position. The company provides comprehensive customer support with multiple international phone numbers and maintains clear links to privacy and terms of service policies, demonstrating regulatory awareness and user transparency. Technically, the site employs standard web technologies including jQuery and OneTrust for cookie consent management. While the SSL certificate is valid and issued by a reputable CA, the absence of modern TLS protocols and security headers indicates room for improvement in security hardening. Performance is moderate to slow, and mobile optimization is basic, suggesting potential areas for technical enhancement. From a security perspective, the site shows good foundational practices such as valid SSL and cookie consent but lacks advanced security headers, DNSSEC, and CAA records. No explicit security policies, incident response contacts, or vulnerability disclosure mechanisms were found, which could be addressed to improve security posture and user trust. Overall, the website is professional and trustworthy but would benefit from technical and security upgrades to align with best practices and compliance standards.

35
58
25
85
75
85
100
legalresearchsigninlexisnexisprivacy+2 more
jQueryOneTrust Cookie ConsentHTML5CSS3+1

Partner Domains:

relxgroup.com
parentpending
2025-06-14T13:03:35.484Z
H

Honda

honda.fr

61
TransportationFranceenterpriseMEDIUM

Honda France operates as a major enterprise in the transportation and manufacturing sectors, offering a diverse range of products including automobiles, motorcycles, marine engines, industrial equipment, garden tools, and snow throwers. The website serves as a portal to various product divisions and regional Honda sites, targeting French consumers and related markets. The business model focuses on manufacturing and retail with a strong brand presence and consistent branding across multiple languages and regions. Technically, the website is built on a modern infrastructure likely powered by Adobe Experience Manager CMS, hosted on Amazon CloudFront CDN, and uses ES6 JavaScript modules. Performance is inferred to be fast with good mobile optimization and basic accessibility and SEO. The site integrates Google Tag Manager for analytics and OneTrust for cookie consent, indicating a moderate level of digital maturity. From a security perspective, the site employs a valid DigiCert SSL certificate with strong security headers including HSTS and X-Frame-Options. However, no TLS protocols are currently enabled, which is a critical issue. The site lacks explicit privacy, terms of service, security policies, or incident response information. DNSSEC is not enabled, and no vulnerability disclosure or security.txt files are present. Overall, the security posture is good but could be significantly improved by enabling TLS, enforcing CSP, and publishing clear security and privacy documentation. The overall risk is moderate due to missing compliance documentation and TLS configuration gaps. Strategic recommendations include enabling TLS 1.2+, enforcing CSP, publishing privacy and security policies, and enhancing incident response readiness to improve trust and compliance.

70
-
25
70
97
85
100
hondaautomobilesmotorcyclesmarineindustrial+4 more
JavaScript ES6 modulesGoogle Tag ManagerOneTrust Cookie ConsentCloudFront CDN

Partner Domains:

industrie.honda.fr
partner
jardin.honda.fr
partner

+3 more partners

2025-06-14T12:59:47.899Z
fieldedge.com favicon

FieldEdge

fieldedge.com

68
TechnologyUnited StatesmediumMEDIUM

FieldEdge is a medium-sized technology company specializing in field service management software tailored for contractors in HVAC, plumbing, electrician, locksmith, and appliance repair industries. The company operates under the parent company Xplor Technologies and offers a comprehensive SaaS platform that integrates scheduling, dispatching, payments, and marketing tools to streamline field operations and increase profitability. Their market position is strong, supported by customer testimonials and SOC 2 certification, indicating a focus on trust and compliance. Technically, the website is built on WordPress with Elementor and uses modern marketing and analytics tools such as Google Tag Manager, Pardot, and OneTrust for cookie consent. The site is optimized for performance and mobile use, with good SEO practices in place. Security-wise, the site has a valid SSL certificate but lacks modern TLS protocol support and HSTS enforcement, which are areas for improvement. The presence of security headers like CSP (report-only), X-Content-Type-Options, and X-Frame-Options indicates some security awareness, but incident response and vulnerability disclosure policies are not publicly available. Overall, FieldEdge demonstrates a solid digital presence with room to enhance security posture and transparency.

50
43
25
95
70
85
100
field service managementsoftwareHVACplumbingelectrician+6 more
WordPressElementorjQueryGoogle Tag Manager+6

Partner Domains:

site.com
partner67
xplortechnologies.com
parentpending
2025-06-14T12:55:46.090Z
victorops.com favicon

Splunk LLC

victorops.com

66
TechnologyUnited StatesenterpriseMEDIUM

Splunk LLC operates the VictorOps platform now branded as Splunk On-Call, providing incident management and on-call scheduling solutions for developers, DevOps, and operations teams. The company is positioned as a leading technology provider in observability, security, and IT operations, offering a broad portfolio of products including Splunk Observability Cloud, Enterprise Security, and AppDynamics. The website reflects a mature digital presence with comprehensive content, multi-language support, and strong branding consistency. Technically, the site leverages modern web technologies including Adobe Experience Manager CMS, Akamai CDN, and multiple analytics and monitoring tools, ensuring good performance and user experience across devices. Security posture is strong with robust HTTP security headers, valid SSL certificates, and no detected major vulnerabilities, although TLS 1.2 and 1.3 protocols are not enabled which is a notable gap. Privacy and cookie policies are present and GDPR compliant, with consent mechanisms implemented. However, explicit incident response contacts and vulnerability disclosure mechanisms are not found, representing an area for improvement. Overall, the site demonstrates high professionalism, trustworthiness, and technical maturity suitable for an enterprise technology company.

65
25
25
75
92
85
100
SplunkVictorOpsSplunk On-CallObservabilitySecurity+3 more
JavaScriptjQueryAdobe Helix RUMGoogle Analytics+6

Partner Domains:

signalfx.com
partner70
appdynamics.com
subsidiaryanalyzing...

+1 more partners

2025-06-14T12:24:06.631Z
T

Telia Company

nebula.fi

61
TelecommunicationsFinlandenterpriseMEDIUM

Telia.fi is the corporate website for Telia Company’s business segment in Finland, offering a broad range of telecommunications and ICT services tailored for enterprises and public sector customers. The site highlights key offerings such as mobile subscriptions, devices, IT services, network solutions, security, cloud, IoT, and consulting services, positioning Telia as a leading and comprehensive ICT partner in the Finnish market. The website is professionally designed with consistent branding and good content quality, targeting Finnish-speaking business customers with language options for English and Swedish. Technically, the site uses Magnolia CMS, is hosted on Sonera/Telia infrastructure, and employs modern analytics and marketing tools including Datadog RUM, Google Tag Manager, OneTrust for cookie consent, and AddSearch for search functionality. Security headers are implemented, but TLS protocols are outdated and HSTS is not fully enabled, indicating room for improvement in transport security. Privacy and cookie policies are present and GDPR compliant, with consent mechanisms in place. Contact information is primarily via web forms, with no direct emails or phone numbers visible on the main page. Overall, the site demonstrates a mature digital presence with strong business focus but could enhance security posture and incident response transparency.

85
-
25
75
85
85
100
telecommunicationsbusiness servicesICTsecuritycloud+3 more
jQueryDatadog RUMGoogle Tag ManagerOneTrust Cookie Consent+1

Partner Domains:

inmicsnebula.fi
partnerpending
teliacygate.fi
partnerpending
2025-06-14T12:16:03.677Z
C

Cvent

lanyon.com

74
event management technologyUSenterpriseMEDIUM

The overall security posture of the website reflects a solid foundation in network security, email security, and SSL/TLS configurations, with scores above 85 in these areas. However, significant gaps exist in regulatory compliance and governance, particularly around GDPR and NIS2 requirements, with scores of 43 and 25 respectively, indicating high risk in legal and operational domains. The absence of a cookie policy, consent banner, and incomplete privacy documentation expose the business to potential non-compliance penalties and reputational damage under data protection laws. Critical governance frameworks such as incident response procedures, security policies, and vulnerability disclosure mechanisms are missing, increasing the risk of unresolved security incidents. Medium-level issues like missing permissions-policy headers, DNSSEC not being enabled, and DMARC not fully enforced suggest areas where attack surfaces could be reduced. Low-risk issues, including sensitive data caching and missing CAA records, should be addressed to enhance overall security hygiene. Immediate focus on compliance and formal security documentation will mitigate regulatory and operational risks while maintaining strong technical defenses. This balanced approach supports business continuity and builds customer trust in the website's security posture.

85
43
25
90
90
85
100
event managementevent marketingwebinarsvenue sourcingattendee engagement+3 more
Drupal 10Adobe DTM Tag ManagerMarketo MunchkinMarketo RTP+13

Partner Domains:

cvent.com
subsidiary94
cventconnect.com
subsidiarypending
2025-06-13T21:15:08.022Z
covidien.com favicon

Medtronic

covidien.com

45
Healthcare TechnologyUSAenterpriseHIGH

The website's security posture is critically weak, exposing the business to significant risks including data breaches, regulatory non-compliance, and reputational damage. The absence of HTTPS encryption is a severe vulnerability impacting data confidentiality and integrity, affecting customer trust and legal compliance, especially under GDPR and NIS2 regulations. Key security headers like Strict-Transport-Security and Content-Security-Policy are missing, increasing susceptibility to man-in-the-middle and cross-site scripting attacks. The lack of GDPR compliance elements such as a Privacy Policy, Cookie Policy, and Consent Banner exposes the company to potential fines and customer distrust. The organization also lacks foundational information security documentation, including security policies and incident response procedures, which undermines its ability to effectively manage and respond to security incidents. While network security and DNS health show some strengths, they do not compensate for fundamental flaws in encryption and governance. Immediate remediation is essential to protect sensitive data, ensure regulatory compliance, and safeguard business continuity. Overall, the current state presents a critical risk to both operational security and legal standing.

50
-
5
85
-
85
100
healthcaremedical devicestechnologyprivacycompliance+1 more
EloquaOneTrust Cookies ConsentCoveo AnalyticsAdobe DTM+8

Partner Domains:

medtronic.com
subsidiarypending
diabetes.shop
subsidiarypending
2025-06-13T18:10:49.514Z