Skip to main content

High-risk security reports

Browse 46,998 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157371
Websites
130
Industries
113
Countries
52
Avg Score
Page 633 of 940|Showing 31601-31650 of 46998
rsi-vereniging.nl favicon

RSI-Vereniging

rsi-vereniging.nl

41
HealthcareNetherlandssmallHIGH

RSI-Vereniging is a Dutch non-profit organization dedicated to supporting individuals affected by Repetitive Strain Injury (RSI). The website serves as an informational and community hub, offering resources on RSI causes, symptoms, prevention, treatment, coaching, and events. The organization has a long-standing presence since 2000, reinforcing its credibility and market position within the healthcare and non-profit sectors in the Netherlands. The site targets individuals seeking RSI-related support and education, leveraging a membership and coaching model to engage its audience. Technically, the website is built on WordPress with a modern plugin ecosystem including WPBakery, Events Manager, and UserFeedback Premium. It employs HTTPS, Google Tag Manager, and reCAPTCHA for security and analytics. The site demonstrates good mobile optimization and SEO practices, though performance is moderate. Hosting is provided by Hosting Secure, and the domain is well-established with consistent WHOIS data. From a security perspective, the site uses HTTPS and has implemented cookie consent mechanisms, but lacks DNSSEC and explicit security headers such as CSP or HSTS. There is no visible security policy or incident response information, which could be improved. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with clear policies and GDPR adherence. Overall, RSI-Vereniging presents a trustworthy, professional, and user-friendly online presence with solid business credibility and privacy compliance. Strategic improvements in security headers, DNSSEC, and incident response transparency would enhance its security posture and trust further.

15
28
2
75
62
65
-
healthcarenon-profitrsipreventionsupport+2 more
WordPressjQueryWPBakery Page BuilderEvents Manager plugin+6
2025-07-07T22:51:03.354Z
dwarslaesie.nl favicon

Dwarslaesie Organisatie Nederland

dwarslaesie.nl

36
HealthcareNetherlandssmallHIGH

Dwarslaesie Organisatie Nederland (DON) is a Dutch non-profit organization dedicated to supporting individuals with spinal cord injuries and cauda equina syndrome, along with their families. The organization provides valuable information, facilitates peer contact, and advocates for the interests of its members. The website serves as a comprehensive resource hub with sections on medical care, lifestyle, rehabilitation, assistive devices, and personal experiences. It also offers newsletters, podcasts, and a webshop, positioning itself as a trusted community and information source within the healthcare sector in the Netherlands. Technically, the website employs a modern JavaScript stack including jQuery, SlickNav, WOW.js, and Select2, ensuring a responsive and user-friendly experience across devices. The site is secured with HTTPS and uses CSRF tokens in forms, indicating attention to security best practices. However, there is room for improvement in implementing security headers and publishing explicit security policies. The cookie consent mechanism is present and functional, supporting GDPR compliance. From a security perspective, the site shows a solid posture with no detected vulnerabilities or exposed sensitive data. The absence of a terms of service page and security incident response information are gaps that could be addressed to enhance trust and compliance. WHOIS data aligns well with the website's claims, showing consistent registration details without privacy protection, supporting legitimacy. Overall, the website is professionally designed, content-rich, and trustworthy, serving its target audience effectively. Strategic recommendations include enhancing security headers, publishing terms of service and security policies, and expanding transparency around data protection and incident response to further strengthen compliance and user trust.

15
28
2
55
42
65
-
healthcarenon-profitspinalcordinjurypatientsupportadvocacy+1 more
jQuerySlickNavWOW.jsSlick Slider+1
2025-07-07T22:48:42.705Z
T

Attention Required! | Cloudflare

tecnosinergia.com

45
OtherN/asmallHIGH

The website tecnosinergia.com is currently inaccessible due to a Cloudflare Web Application Firewall (WAF) block, which prevents access to any meaningful content. As a result, no direct information about the company's business, services, or contact details can be extracted from the site. The domain is registered since 2006 with eNom, LLC and uses Cloudflare DNS services, indicating a mature domain with a stable registration history. However, the lack of accessible content severely limits the ability to assess the company's market position, technical infrastructure, or security posture. From a technical perspective, the site is protected by Cloudflare, which provides security and performance benefits but currently restricts access, possibly due to triggered security rules. No metadata, scripts, or analytics tools are detectable due to the block. The absence of visible security headers or SSL configuration details in the HTML content further limits security assessment. Security-wise, the presence of a Cloudflare block indicates active protection against potential threats, but also means that no internal security policies, incident response contacts, or certifications can be verified. The domain's WHOIS data shows consistent registration without privacy protection, which is typical for established businesses. Overall, the risk assessment is constrained by the lack of accessible data, but no immediate red flags are evident from the domain registration information. Strategically, it is recommended to resolve the access block to enable full analysis and to ensure that legitimate users can access the site without triggering security mechanisms. Enhancing transparency by publishing privacy policies, contact information, and security disclosures would improve trust and compliance posture.

30
35
2
40
75
60
100
Cloudflare
2025-07-07T22:46:47.083Z
nlg.org favicon

National Lawyers Guild

nlg.org

47
Non-profitUnited StatesmediumHIGH

The National Lawyers Guild (NLG) is a well-established non-profit organization founded in 1937, focused on legal advocacy, human rights, and social justice. The organization operates a network of chapters, committees, and projects across the United States, providing legal support and education to activists, law students, and legal professionals. Their key services include legal observer programs, mass defense support, and educational resources. The website reflects a mature digital presence with consistent branding and a clear mission statement emphasizing "Human rights over property interests." The target audience includes legal professionals, activists, and students engaged in social justice causes. Technically, the website is built on WordPress 6.8.1 with a modern tech stack including jQuery, SiteOrigin Panels, Caldera Forms, and Jetpack. It uses HTTPS with good SSL configuration and integrates Google reCAPTCHA v3 for form security. The site is mobile optimized and has good SEO practices, though accessibility features are basic. Social media integration is present via a Facebook page embed. Performance is moderate, with no major technical issues detected. From a security perspective, the site employs HTTPS and spam protection but lacks visible security headers and explicit privacy or cookie policies, which are important for compliance and user trust. WHOIS data is unavailable or privacy protected, which is common for non-profits but reduces transparency. No vulnerabilities or exposed sensitive data were found in the HTML content. Overall, the security posture is solid but could be improved with better policy disclosures and security headers. The overall risk assessment is low, with the site appearing legitimate and professionally maintained. Strategic recommendations include publishing comprehensive privacy and cookie policies, implementing security headers, enhancing accessibility, and providing clear incident response contacts. These steps would improve compliance, user trust, and security maturity.

30
35
2
75
42
75
40
lawhumanrightslegaladvocacynon-profitactivism+3 more
WordPress 6.8.1jQuery 3.7.1SiteOrigin PanelsCaldera Forms+3

Partner Domains:

nationalimmigrationproject.org
partner
nlg-npap.org
partner
2025-07-07T22:46:11.992Z
scale-up-vaud.ch favicon

Innovaud

scale-up-vaud.ch

48
TechnologySwitzerlandmediumHIGH

Scale Up Vaud is a regional initiative powered by Innovaud, the innovation and investment agency of Canton de Vaud, Switzerland. The website serves as a community and support platform for scale-up companies, focusing on fostering growth, recruitment, and internationalization. The initiative aims to strengthen the local innovation ecosystem by connecting stakeholders and catalyzing economic development. The site presents clear business information, including contact details and social media channels, enhancing its credibility. Technically, the website is built on the DotNetNuke CMS platform and utilizes common web technologies such as jQuery, Bootstrap 4, and Font Awesome. It implements HTTPS with a good SSL configuration and includes a cookie consent mechanism via tarteaucitron.js, indicating attention to privacy compliance. The site is moderately performant and mobile-optimized, with good SEO practices and basic accessibility features. From a security perspective, the website enforces HTTPS but lacks explicit security headers and published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the content. The WHOIS data aligns well with the business entity and location, supporting legitimacy. Overall, the security posture is solid but could be improved by adding security headers and formal policies. The overall risk assessment is low, with no blocking or WAF detected, no suspicious domains linked, and no adult or questionable content. Strategic recommendations include enhancing security headers, publishing a security policy, and maintaining regular audits of third-party libraries to ensure ongoing security and compliance.

55
35
2
60
52
75
20
scale-upinnovationstartupstechnologybusinesssupport+2 more
jQueryjQuery UIBootstrap 4Font Awesome 4.7+1

Partner Domains:

www.innovaud.ch
parent
vaud-economie.ch
partner

+2 more partners

2025-07-07T21:34:35.971Z
L

Lausanne Olympic Capital

olympiccapital.ch

49
OtherSwitzerlandmediumHIGH

Lausanne Olympic Capital is a key hub for international sports organisations, including the International Olympic Committee and nearly 50 other international sports federations and related entities. The organization provides support services such as office space, event planning, seminars, and networking opportunities to help these organisations grow and increase their visibility. The website reflects a professional and consistent brand image aligned with its mission and target audience. Technically, the website uses modern web technologies including jQuery, Google Maps API, and Google Tag Manager, hosted by Infomaniak. The site is mobile optimized with good SEO practices, though accessibility features are basic. Performance is moderate, with no major technical issues detected. From a security perspective, the site uses HTTPS with good SSL configuration but lacks visible security headers and does not provide public security policies or incident response information. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is weak due to the absence of privacy and cookie policies and no explicit GDPR compliance indicators. Overall, the website is trustworthy and professional but would benefit from improved privacy compliance and enhanced security transparency to strengthen its security posture and regulatory adherence.

30
35
2
70
85
75
20
olympiccapitalinternationalsportlausanneinternationalfederationssportsorganisations+2 more
jQueryGoogle Maps APIGoogle Tag ManagerHTML5+1

Partner Domains:

lausanne.ch
partner
vaud.ch
partner

+2 more partners

2025-07-07T21:34:20.902Z
F

Freeparking Limited t/a DiscountDomains

shedcreator.co.nz

47
ManufacturingNew ZealandsmallHIGH

ShedCreator.co.nz is an online platform based in New Zealand that provides custom shed and building design services primarily targeting individuals and businesses seeking tailored building solutions. The platform offers user account management, guest access for building design, and a selection of building types including sheds, covers, arenas, heritage barns, cow houses, and mono pitch buildings. The website is built on ASP.NET WebForms using DevExpress controls and integrates Google Analytics for user tracking. The domain is registered with a reputable New Zealand registrar since 2014, indicating an established presence in the market. Technically, the website employs legacy technologies such as jQuery 1.9.1 and lacks modern SEO and accessibility optimizations. The site uses HTTPS but does not explicitly present security headers like CSP or HSTS, which could enhance security posture. Privacy and cookie policies are absent, and no contact information or social media links are provided on the login page, limiting transparency and user trust. The site includes a browser compatibility warning for HTML5 Canvas support, indicating some reliance on modern browser features. From a security perspective, the site uses standard ASP.NET mechanisms for form validation and event handling but lacks advanced security headers and vulnerability disclosure information. The absence of privacy and cookie policies suggests non-compliance with GDPR and related regulations. The overall security score is moderate, with recommendations to improve header implementation, update libraries, and add compliance documentation. Overall, ShedCreator.co.nz presents a niche, regionally focused business with a functional but basic online presence. Strategic improvements in privacy compliance, security best practices, and technical modernization would enhance trust and user experience.

15
35
2
50
72
35
100
buildingdesignshedcustomshedsnewzealandconstruction+1 more
ASP.NET WebFormsJavaScriptjQuery 1.9.1DetectRTC.js+1
2025-07-07T19:23:01.520Z
sictic.ch favicon

SICTIC

sictic.ch

43
TechnologySwitzerlandmediumHIGH

SICTIC is a leading Swiss angel investor network that connects smart money investors with seed and early-stage technology startups in Switzerland. The organization facilitates investment opportunities through matchmaking events, educational programs, and a strong community presence. Their market position is well-established as a key player in the Swiss startup ecosystem, providing valuable services to investors and startups alike. Technically, the website is built on WordPress with modern plugins such as Yoast SEO, MonsterInsights, and Google Analytics integrations. It employs best practices in performance, mobile optimization, and accessibility, ensuring a professional and user-friendly digital presence. The use of structured data and SEO optimization further enhances discoverability. From a security perspective, the site enforces HTTPS, uses security headers, and integrates Google reCAPTCHA for form protection. Cookie consent mechanisms and comprehensive privacy policies demonstrate good compliance with GDPR. However, there is no explicit security policy or incident response information published, which could be improved. Overall, the website presents a low-risk profile with strong business credibility, good technical implementation, and solid privacy compliance. Strategic recommendations include publishing a dedicated security policy, adding incident response contacts, and considering a vulnerability disclosure policy to further enhance trust and security posture.

80
50
17
70
-
35
-
angelinvestingstartupsswitzerlandtechnologyinvestors+3 more
WordPressYoast SEO pluginGoogle AnalyticsGoogle Tag Manager+5

Partner Domains:

fondation-fit.ch
partner
innovaud.ch
partner

+3 more partners

2025-07-07T18:15:43.780Z
swissfinte.ch favicon

Swiss FinTech Association

swissfinte.ch

45
FinanceSwitzerlandmediumHIGH

The Swiss FinTech Association is a well-established non-profit organization dedicated to fostering the development of the Swiss FinTech ecosystem. It serves as a neutral hub connecting various stakeholders including startups, corporates, investors, and professionals in finance and technology. The association offers key services such as advocacy, mentoring, marketplace access, and organizes networking events to strengthen the FinTech community in Switzerland. The website reflects a strong market position as the leading FinTech hub in the country, with a clear focus on community engagement and ecosystem development. Technically, the website is built on WordPress using a modern stack of plugins and frameworks including Yoast SEO, WPBakery Page Builder, and Mailchimp integration for newsletter subscriptions. The site demonstrates good mobile optimization, SEO practices, and a moderate performance profile. The technical infrastructure supports a professional and user-friendly experience for visitors. From a security perspective, the site enforces HTTPS and shows no signs of exposed sensitive data or vulnerabilities in the visible content. However, it lacks some advanced security headers and does not provide explicit security policies or incident response information. Privacy compliance is mostly addressed with a comprehensive privacy policy, but the absence of a cookie consent mechanism is a notable gap. Overall, the website presents a low-risk profile with strong business credibility and professional content. Strategic recommendations include implementing cookie consent, publishing security and incident response policies, and enhancing security headers to further strengthen the security posture.

30
53
2
50
85
55
-
fintechswitzerlandfinancetechnologynon-profit+3 more
WordPressYoast SEO pluginWPBakery Page BuilderjQuery+6
2025-07-07T18:15:38.772Z
dyndnsservices.com favicon

Adamsland Microsystems

dyndnsservices.com

48
TechnologyUnited StatessmallHIGH

Dynamic.domains is a technology company specializing in dynamic DNS (DDNS) server software and hosted solutions, primarily through their flagship product MintDNS. The company targets security appliance manufacturers and businesses requiring reliable DDNS services, boasting a significant market presence powering 15-20% of the world's IP cameras and DVRs. Their business model includes software licensing, hosted services, and custom development with a strong emphasis on ease of deployment and integration. Technically, the website employs a modern tech stack including .NET, C++, C#, Bootstrap, and jQuery, with integrations for Google Analytics and reCAPTCHA for security and analytics. The site is mobile optimized with good SEO practices and moderate performance. Hosting details are not explicit but mention tier 4 datacenters in the US. From a security perspective, the site uses HTTPS and implements reCAPTCHA on forms with input sanitization, but lacks DNSSEC and explicit security headers, which are recommended for improvement. Privacy compliance is partial with a privacy policy present but no cookie consent mechanism detected. Contact information is comprehensive and trustworthy. Overall, the website is professional, trustworthy, and well-positioned in its niche, with moderate security posture and room for enhancements in security headers and privacy compliance.

15
53
17
60
77
65
20
dynamicdnsddnsmintdnsdnsserversoftwaretechnology+1 more
.NETC++C#Bootstrap CSS+4

Partner Domains:

us.dahuasecurity.com
partner
merivatechnology.com
partner

+3 more partners

2025-07-07T18:12:22.449Z
N

Njalla Okta LLC

tmpfiles.org

40
TechnologySaint Kitts and NevissmallHIGH

The website tmpfiles.org offers a straightforward temporary file hosting service allowing users to upload files up to 100 MB with automatic deletion after 60 minutes. The service targets general users needing ephemeral file sharing without account creation or long-term storage. The business operates under Njalla Okta LLC, registered in Saint Kitts and Nevis since 2015, indicating a stable domain age appropriate for the service maturity. The website's market position is niche, focusing on privacy-conscious temporary file hosting. Technically, the website uses basic web technologies including Google Analytics and Google Tag Manager for tracking, and Google Fonts for typography. Hosting appears to be managed via Njalla's infrastructure. The site is moderately optimized for performance and mobile use but lacks advanced SEO and accessibility features. No CMS or major frameworks are detected, indicating a lightweight custom implementation. From a security perspective, the site uses HTTPS (implied by Google Analytics scripts loaded over HTTPS), but no DNSSEC is enabled and no security headers are detected in the provided data. The domain has transfer and update prohibitions set, which is positive. However, the absence of privacy and cookie policies, lack of contact or incident response information, and moderate user tracking without consent mechanisms represent compliance and security gaps. Overall, the website is functional and serves its purpose but requires improvements in privacy compliance, security hardening, and transparency to enhance trustworthiness and regulatory adherence. Strategic recommendations include enabling DNSSEC, publishing privacy and cookie policies, adding security headers, and providing clear contact channels for security incidents.

15
35
2
40
52
70
40
temporaryfilehostingfileuploadfilesharingprivacysecurity+1 more
Google AnalyticsGoogle Tag ManagerOpen Sans Condensed font
2025-07-07T18:08:46.431Z
T

Service unavailable

txcourts.gov

49
GovernmentN/amediumHIGH

The website txcourts.gov appears to be an official government domain related to Texas courts, established in 2010. However, the current website content is inaccessible due to a blocking mechanism, likely a Web Application Firewall or similar security control, which prevents content analysis. The domain registration is expired by 55 days, which is unusual for a government entity and may indicate administrative oversight or renewal delays. No metadata, contact information, or policies are available for review. The hosting DNS is managed via Microsoft Azure DNS services, but no further technical details are accessible due to the block. From a security perspective, the lack of DNSSEC and expired domain status are concerns. The absence of visible security headers and policies further limits trust and compliance assessment. The website's security posture cannot be fully evaluated due to the blocked content, but the domain's long age and registrar suggest legitimacy. Overall, the site currently presents a high risk of unavailability and potential trust issues until domain renewal and content accessibility are restored. Strategic recommendations include immediate domain renewal, enabling DNSSEC, publishing clear privacy and security policies, and ensuring the website is accessible to legitimate users without unnecessary blocking. These steps will improve trust, compliance, and user experience for this important government resource.

20
50
17
75
77
25
100
2025-07-07T17:02:02.292Z