Skip to main content

High-risk security reports

Browse 46,998 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157371
Websites
130
Industries
113
Countries
52
Avg Score
Page 637 of 940|Showing 31801-31850 of 46998
F

First Place Internet, Inc.

sba.org

45
OtherN/asmallHIGH

The website sba.org is an informational and search platform focused on Small Business Administration (SBA) related topics, operated by First Place Internet, Inc. It provides users with search capabilities for SBA business loans, grants, business plans, and related services. The site appears to be monetized primarily through advertising, leveraging Google Ads and tracking technologies. The content is basic and targeted towards small business owners and entrepreneurs seeking SBA-related information. Technically, the site uses a modest technology stack including jQuery, Google Analytics, Google Tag Manager, and Google Ads Domains CAF scripts. The site is moderately optimized for performance and mobile use but lacks advanced SEO and accessibility features. There is no detected CMS or hosting provider information. Security measures are minimal, with no explicit security headers or HTTPS enforcement details visible, though CSRF tokens are present in meta tags. From a security perspective, the site lacks comprehensive security policies, incident response contacts, and vulnerability disclosure mechanisms. Privacy compliance is basic with a privacy policy and cookie consent banner present, but GDPR compliance is not clearly demonstrated. WHOIS data is unavailable or privacy-protected, which reduces trustworthiness but is somewhat justified given the site's informational nature. Overall, the site is functional but basic, with moderate trustworthiness and security posture. Strategic improvements in security headers, HTTPS enforcement, contact transparency, and privacy compliance would enhance its credibility and user trust.

55
53
2
80
-
70
40
smallbusinesssbabusinessloanssearchdirectory+1 more
jQuery 3.3.1Google AnalyticsGoogle Tag ManagerGoogle Ads Domains CAF+1
2025-07-07T03:13:01.687Z
T

TAMUS.org on WPMU Dev Network

tamus.org

47
OtherN/asmallHIGH

The website www.tamus.org serves as a primary multi-site WordPress development network for TAMUS-related sites, hosting multiple live and test sites. It functions primarily as a platform for managing and cloning WordPress sites within the TAMUS ecosystem. The business model centers on multi-site WordPress hosting and development, targeting internal users or affiliated entities rather than the general public. The site has been active since at least 2015, indicating a stable presence in its niche. Technically, the site leverages a modern WordPress stack including Elementor, Yoast SEO, and the Kadence theme, hosted on the WPMU Dev network with CDN support. The infrastructure supports responsive design and basic SEO optimization, though accessibility and advanced SEO features are limited. Performance is moderate, with external dependencies on common libraries and services such as AddThis for sharing. From a security perspective, the site enforces HTTPS with a valid SSL certificate but lacks visible security headers and public security policies. No contact or incident response information is provided, and WHOIS data is unavailable, which reduces trustworthiness. There are no indications of vulnerabilities or exposed sensitive data in the HTML content. Privacy and cookie policies are absent, indicating compliance gaps. Overall, the site is functional and serves its intended purpose within the TAMUS network but requires improvements in privacy compliance, security best practices, and transparency to enhance trust and regulatory adherence.

15
35
2
60
85
70
40
wordpressmulti-sitetamusdevelopmentwpmudev+2 more
WordPress 6.8.1Elementor 3.30.0Elementor Pro 3.29.2Yoast SEO 25.4+5

Partner Domains:

reynagas.com
partner
glennlea.com
partner
2025-07-07T03:10:56.390Z
shipway.in favicon

Shipway Technology Pvt. Ltd.

shipway.in

48
E-commerceIndiamediumHIGH

Shipway Technology Pvt. Ltd. operates the Shipway Experience platform, a SaaS solution focused on enhancing the post-purchase experience for eCommerce and D2C brands by providing advanced shipment and package tracking services. The platform supports over 500 couriers worldwide and offers features such as branded tracking pages, real-time delivery updates, NPS measurement, and integrations with popular eCommerce platforms like Shopify. The company positions itself as a trusted partner for thousands of brands, emphasizing automation and customer satisfaction. Technically, the website employs modern web technologies including Bootstrap, jQuery, and integrates multiple analytics and marketing tools such as Google Analytics, Facebook Pixel, and Segment Analytics. The site is mobile optimized and provides a professional user experience with clear navigation and structured content. Security measures include HTTPS enforcement and Google reCAPTCHA on forms, though some security headers are missing and no explicit cookie consent mechanism is present. From a security perspective, the site demonstrates good practices with encrypted connections and spam prevention but lacks published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the content. The WHOIS data for the subdomain is unavailable, which is normal, and the main domain likely holds proper registration. Overall, the site is trustworthy and professionally maintained. The overall risk is low, but improvements in privacy compliance and security header implementation are recommended to enhance trust and regulatory adherence.

20
53
17
70
52
50
40
shipwayexperienceshipmenttrackingecommerced2cbrandspostpurchaseexperience+2 more
BootstrapjQueryGoogle AnalyticsGoogle Tag Manager+5

Partner Domains:

theconvertway.com
partner
2025-07-07T02:09:51.753Z
lammersmakelaars.nl favicon

Lammers NVM Makelaars

lammersmakelaars.nl

46
Real EstateNetherlandssmallHIGH

Lammers NVM Makelaars is a well-established real estate agency based in Zoetermeer, Netherlands, operating since 1998. The company specializes in residential property sales, purchases, and valuations, focusing on local expertise and personalized service. Their market position is strong within the local community, supported by high customer ratings on platforms like Funda and membership in the NVM professional association. The website reflects a professional business model targeting homeowners and buyers in the Zoetermeer area. Technically, the website uses a modern but somewhat dated tech stack including Bootstrap 3 and jQuery, with integrations for Google Tag Manager and marketing platforms. The site is mobile responsive at a basic level and SEO optimized with proper meta tags and structured navigation. Security posture is good with HTTPS enforced and no visible sensitive data exposure, but lacks advanced security headers and explicit incident response or security policies. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism detected. Overall, the site is trustworthy and professional, with room for improvement in security and privacy transparency.

25
40
2
70
72
60
20
realestatemakelaarzoetermeernvmwoning+3 more
jQueryBootstrap 3.3.4Font AwesomeGoogle Tag Manager+2

Partner Domains:

waarderapport.lammersmakelaars.nl
partner
www.nvm.nl
partner

+2 more partners

2025-07-07T02:08:56.608Z
hillshornetstouch.com favicon

Hills Hornets Touch Football

hillshornetstouch.com

40
HospitalityAustraliasmallHIGH

Hills Hornets Touch Football is a community sports club based in New South Wales, Australia, specializing in touch football. The club positions itself as a leading touch football organization in NSW, with accolades such as NSW Touch Affiliate of the Year 2022 and multiple Junior State Cup Southern Conference Championships. The website serves as a hub for players, coaches, referees, and community members, offering information on competitions, coaching resources, representative teams, and a merchandise shop. The club maintains an active social media presence and partnerships with local businesses and sponsors, enhancing its community engagement and visibility. Technically, the website is built on WordPress with WooCommerce for e-commerce functionality, utilizing popular plugins such as WPBakery Page Builder and Slider Revolution. It employs modern web technologies including Bootstrap and jQuery, and integrates Google Analytics for visitor tracking. The site is secured with HTTPS and has a moderate performance profile with good mobile optimization. However, it lacks some security headers and cookie consent mechanisms, which are recommended for improved security and compliance. From a security perspective, the site demonstrates basic best practices such as secure login forms and SSL encryption. There are no visible vulnerabilities or exposed sensitive data. The absence of WHOIS domain registration data is a concern, as it limits the ability to verify domain legitimacy fully. Privacy compliance is basic, with a privacy policy present but no explicit cookie consent or GDPR indicators. The site does not provide detailed security policies or incident response contacts. Overall, Hills Hornets Touch Football presents a professional and trustworthy online presence for a small community sports club. Strategic improvements in security headers, privacy compliance, and domain registration transparency would enhance trust and security posture. The website effectively supports the club's business model and community engagement goals.

15
35
17
85
-
70
20
sportstouchfootballcommunitynswclub+2 more
WordPressWooCommerceWPBakery Page BuilderSlider Revolution+2

Partner Domains:

momentohospitality.com.au
partner
bellavistahotel.com.au
partner

+3 more partners

2025-07-07T02:04:51.032Z
C

403 - Forbidden

cdstaging.com

26
OtherN/asmallHIGH

The website at cdstaging.com currently serves a 403 Forbidden error page, indicating that access to the content is blocked or restricted. No business-related content, contact information, or policies are available on the site, which severely limits the ability to assess the company's operations or market position. The domain is newly registered in early 2025 and uses SiteGround name servers, but no further technical or business details are accessible. The lack of accessible content and policies suggests the site is either under development, restricted, or misconfigured. From a technical perspective, the site does not expose any scripts, analytics, or forms, and no security headers or SSL configuration details are observable. DNSSEC is not enabled, which is a potential area for improvement. The domain registration status flags clientTransferProhibited and clientUpdateProhibited are positive security indicators. However, the newness of the domain and lack of content reduce trustworthiness. Security posture is limited to domain registration protections; no incident response or security policies are found. Privacy compliance is absent, with no privacy or cookie policies detected. The site does not collect user data or provide contact channels, further limiting compliance and business credibility. Overall, the site is inaccessible for meaningful analysis due to the 403 error. It is recommended to resolve access issues, publish relevant business and compliance information, and implement security best practices to improve trust and transparency.

15
35
2
55
-
80
-
error403forbiddenaccessdenied
2025-07-07T02:03:40.859Z
scienna.com favicon

Scienna LLC

scienna.com

47
FinanceN/asmallHIGH

Scienna LLC is a specialized software provider offering custom loan review solutions primarily targeting mortgage due diligence firms, third-party review companies, and financial institutions. Their flagship product, the Andor platform, streamlines loan review processes with customizable workflows, reporting, and integration with industry partners such as ComplianceEase and mTrade. The company has a long-standing presence since 2000, positioning itself as a trusted provider in the mortgage finance sector. Technically, the website is built on WordPress with a modern tech stack including jQuery, Yoast SEO, and Contact Form 7. The site is mobile-optimized and demonstrates good SEO practices. Hosting appears to be via Register.com with no DNSSEC enabled, and the domain is secured with HTTPS. However, there is room for improvement in security headers and privacy compliance disclosures. Security posture is moderate with HTTPS enforced and domain transfer protection enabled. The absence of explicit privacy, cookie, and security policies reduces compliance confidence. No vulnerabilities or suspicious content were detected. Contact information is clearly presented, enhancing business credibility. Overall, the website and business present a professional and trustworthy front with solid technical foundations but would benefit from enhanced privacy and security policy transparency to improve compliance and user trust.

15
35
17
70
72
65
20
loanreviewmortgageduediligencefinancesoftwarecustomsoftware+1 more
WordPressPHPjQueryYoast SEO+5

Partner Domains:

strategicvantage.com
partner
2025-07-07T02:03:20.821Z
wemetbefore.com favicon

We Met Before

wemetbefore.com

43
TechnologyNetherlandssmallHIGH

We Met Before is a small, Amsterdam and Barcelona-based digital design and development studio founded in 2021. It operates as a community of freelance creatives specializing in branding, design, and development services. The company positions itself as a co-creative partner for clients seeking innovative digital identities and web solutions. Their portfolio includes diverse clients across various industries, demonstrating a strong market presence in creative digital services. Technically, the website employs modern JavaScript libraries such as GSAP and Splide.js, and references frameworks like React, Next.js, and Gatsby.js in their service offerings. Hosting is managed via a registrar in the Netherlands, with DNS servers hosted by hoasted domains. The site is moderately optimized for performance and mobile devices, with good SEO practices evident. Security posture is adequate but could be improved by adding security headers, enabling DNSSEC, and publishing privacy and security policies. No forms or direct data collection mechanisms are present on the main page, reducing immediate data protection risks. Overall, the website is professional, trustworthy, and well-branded, but lacks formal privacy and cookie compliance documentation.

15
35
2
70
72
75
-
digitaldesignbrandingwebdevelopmentfreelancecreativesportfolio+2 more
GSAPSplide.jsReact (mentioned in services)Next.js (mentioned in services)+2

Partner Domains:

moxiecreatives.com
partner
2025-07-07T00:59:50.337Z
flygainesville.com favicon

Gainesville Regional Airport

flygainesville.com

36
TransportationUnited StatesmediumHIGH

Gainesville Regional Airport operates as a regional transportation hub serving Gainesville, Florida, providing commercial airline services and general aviation amenities. The website presents a professional and consistent brand image, targeting travelers and visitors to the region. The business model focuses on facilitating air travel with key services including flight information, parking, and traveler support. The domain is well-established since 2001, reinforcing the airport's longstanding presence in the community. Technically, the website is built on WordPress with modern plugins such as Yoast SEO and Revolution Slider, hosted by HostGator. The site demonstrates good mobile optimization and SEO practices, though performance is moderate. Accessibility features are basic but present. Analytics tools like Google Analytics and Tag Manager are used for user tracking, indicating moderate data collection. From a security perspective, HTTPS is properly implemented, and domain registration includes protective statuses. However, DNSSEC is not enabled, and no security headers were detected, which are areas for improvement. The absence of privacy and cookie policies reduces privacy compliance scores. No incident response or vulnerability disclosure information is published, which could impact trust. Overall, the website is safe, professional, and trustworthy, with room for enhancements in privacy compliance and security hardening. Strategic improvements in these areas will strengthen the airport's digital presence and user trust.

15
35
17
70
-
75
-
airportregionalairportflightstravelgainesville+2 more
WordPressYoast SEO pluginRevolution SliderjQuery+3

Partner Domains:

gra-gnv.com
partner
cedarkey.org
partner

+3 more partners

2025-07-07T00:56:49.107Z
clubfront.com.au favicon

Clubfront

clubfront.com.au

36
OtherAustraliasmallHIGH

Clubfront is a specialized web design and CMS service provider focused on sports clubs and surf life saving clubs in Australia. The company offers modern, user-friendly websites tailored for clubs with limited budgets, leveraging a customized Umbraco CMS platform. Their market position is niche, targeting sports associations and clubs needing affordable yet quality digital presence. The website demonstrates a professional design with clear navigation, client testimonials, and pricing transparency, supporting a credible business image. Technically, the site uses a modern CMS (Umbraco), integrates Google Analytics and Facebook Pixel for tracking, and employs common web technologies such as Font Awesome and CSS frameworks. The site is mobile optimized and SEO friendly, though accessibility features are basic. Performance is moderate with no major technical issues detected. However, security headers are not evident, and privacy/cookie policies are missing, indicating areas for compliance improvement. From a security perspective, the site uses HTTPS and does not expose sensitive data. The lack of security headers and formal privacy policies are notable gaps. WHOIS data is privacy protected, which is typical for small businesses, and no suspicious patterns were found. Overall, the security posture is moderate but could be enhanced with better policy disclosures and technical hardening. The overall risk is low to moderate. Strategic recommendations include implementing privacy and cookie policies, adding security headers, enhancing accessibility, and establishing a vulnerability disclosure process to improve trust and compliance.

15
35
2
40
62
60
-
sportsclubsurflifesavingwebsitedesigncmsclubwebsites+1 more
Umbraco CMSGoogle AnalyticsFacebook PixelFont Awesome+3

Partner Domains:

muchmedia.com.au
partner
slst.asn.au
partner
2025-07-07T00:54:43.519Z
A

adidas

adidas.com.au

45
RetailAustraliaenterpriseHIGH

The website www.adidas.com.au is currently inaccessible due to a security block resulting in a 403 Forbidden error page. This indicates the presence of a Web Application Firewall or similar security mechanism actively preventing access, likely triggered by bot protection measures during high-traffic product releases. The site is a regional e-commerce platform for adidas, a globally recognized sportswear brand, targeting Australian customers. Due to the blocked content, detailed analysis of the website's content, policies, and technical infrastructure is limited. Technically, the site uses JavaScript tags from Tealium for analytics and tracking, but no other technologies or frameworks are identifiable from the provided HTML. No privacy, cookie, or terms of service policies are detectable in the blocked page content. The WHOIS data for the domain is unavailable or protected, which is typical for large brands to prevent abuse but limits transparency. The domain appears legitimate and consistent with the adidas brand. Security posture is difficult to assess fully due to lack of access, but the presence of a security block page suggests active security management. However, no security headers or SSL configuration details are available from the data provided. The site currently scores low on content quality, technical implementation, and privacy compliance due to the blocked status and missing information. Overall, the site is a major enterprise e-commerce platform with strong brand recognition but currently inaccessible for analysis due to security controls. Strategic recommendations include improving transparency of privacy and cookie policies, ensuring accessibility for legitimate users, and enhancing security header implementation once accessible.

20
50
17
85
-
70
100
e-commercesportswearretailsecurity-blocked403-forbidden
JavaScript
2025-07-06T23:48:07.376Z