Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157326
Websites
130
Industries
113
Countries
52
Avg Score
Page 65 of 101|Showing 3201-3250 of 5032
odesli.co favicon

Linktree Pty Ltd

odesli.co

63
TechnologyAustraliamediumMEDIUM

Songlink/Odesli is a technology service operated by Linktree Pty Ltd, specializing in automated, on-demand smart links for songs, albums, podcasts, and related media content. The platform targets artists and fans, providing a free service that aggregates links across major platforms to facilitate sharing and promotion. The business operates from Australia and was founded in 2019, positioning itself as a niche player in the music and podcast link aggregation market. The website demonstrates consistent branding and a clear business description, supporting its market position. Technically, the website is built using modern web technologies including React and Next.js, hosted on AWS infrastructure. The site is performant, mobile-optimized, and includes SEO best practices such as meta tags and Open Graph data. Accessibility is basic but present. No CMS is explicitly detected, indicating a custom or framework-based implementation. The technical stack and hosting choices reflect a mature digital infrastructure suitable for scalable web services. From a security perspective, the site enforces HTTPS and has domain registration protections enabled. However, it lacks DNSSEC and does not publish privacy, cookie, or security policies on the main page, which are important for compliance and user trust. No security headers were detected in the HTML content, and no incident response or vulnerability disclosure information is provided. No tracking or advertising scripts were found, indicating a privacy-conscious approach but also a lack of transparency on data collection. Overall, the website is safe, professional, and functional with a moderate trustworthiness rating. The absence of explicit privacy and cookie policies and security disclosures lowers compliance scores. The domain WHOIS data is consistent and trustworthy, supporting the legitimacy of the business. Strategic improvements in privacy compliance and security transparency would enhance the site's credibility and user trust.

45
35
2
85
72
85
100
musicpodcastsmartlinkslinkaggregationtechnology
ReactNext.jsAWS (Amazon Web Services)Google Fonts
2025-07-27T14:02:19.542Z
L

Lulu Press, Inc.

lulu.com

65
E-commerceUnited StateslargeMEDIUM

Lulu Press, Inc. operates a leading online self-publishing and print-on-demand platform that enables authors and publishers to create, print, and sell books globally. The company offers a comprehensive suite of services including custom book printing, ebook creation, ecommerce integrations with platforms like Shopify, Wix, and WooCommerce, and global retail distribution reaching over 40,000 retailers. Their business model focuses on eliminating inventory risk through print-on-demand technology, catering primarily to self-publishers, small publishers, and businesses. Technically, the website is built using modern web technologies including React and Next.js, ensuring fast performance, mobile responsiveness, and good SEO practices. The site is well-structured with comprehensive metadata, Open Graph tags, and JSON-LD structured data enhancing discoverability and social sharing. Accessibility and user experience are strong, with clear navigation and professional design. From a security perspective, the site enforces HTTPS with strong SSL configuration and includes standard security headers. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of a visible cookie consent mechanism and explicit security or incident response policies represent minor compliance gaps. The WHOIS data confirms the legitimacy of the domain with consistent registration details matching the business identity. Overall, Lulu.com presents a trustworthy, professional, and technically sound platform with a strong market position in the self-publishing industry. Strategic improvements in privacy compliance and security transparency would further enhance trust and regulatory adherence.

30
53
2
85
75
85
100
self-publishingprint-on-demandebooksbookprintingecommerce+2 more
ReactNext.jsJavaScriptGoogle Fonts

Partner Domains:

lulujr.com
subsidiary
shopify.com
partner

+2 more partners

2025-07-27T12:54:12.148Z
syftdata.com favicon

Syft Data, Inc.

syftdata.com

10
TechnologyN/asmallCRITICAL

Syft Data, Inc. operates a sophisticated AI-powered SaaS platform designed to identify high-intent person-level leads from inbound website traffic and LinkedIn engagements. Their solution enables marketing and growth teams to uncover anonymous visitors, enrich signups, and orchestrate multi-channel outreach campaigns in real time, thereby maximizing revenue opportunities. Positioned as a lean and fast-moving technology provider, Syft emphasizes automation and data-driven decision-making to accelerate pipeline growth. Technically, the website is built on a modern Next.js framework with React, leveraging third-party services such as Cookiebot for consent management and Google Tag Manager for analytics. The site is well-optimized for mobile devices, features good SEO practices, and integrates multiple marketing and tracking tools. Performance is moderate with a clean, professional design and clear navigation. From a security perspective, the site enforces HTTPS and uses consent management to comply with GDPR. However, it lacks explicit security headers and a public security policy or incident response page. No vulnerabilities or exposed sensitive data were detected in the HTML content. The absence of WHOIS data for the domain is a notable gap, raising questions about domain registration transparency. Overall, Syft presents a credible and professional online presence with strong business and privacy compliance indicators. The main risk lies in the missing WHOIS information, which should be investigated further to confirm domain legitimacy and ownership. Strategic improvements in security policy transparency and header implementation would enhance trust and security posture.

-
-
-
-
-
-
-
aileadgenerationmarketingautomationb2bsaas+3 more
Next.jsReactCookiebotGoogle Tag Manager+1

Partner Domains:

getsyft.app
partner
2025-07-27T12:51:24.313Z
cure51.com favicon

Cure51

cure51.com

53
HealthcareFrancesmallMEDIUM

Cure51 is a specialized TechBio company focused on cancer research and drug discovery by leveraging a unique database of cancer survivors known as Outliers. The company collaborates with leading international oncology centers and renowned scientific leaders to develop precision medicine tools and novel therapeutic targets. Their market position is that of an innovative and credible player in the healthcare and biotechnology sectors, with a strong emphasis on scientific rigor and partnerships. Technically, the website is built on a modern React and Next.js stack, hosted and registered via Cloudflare, and uses Matomo for privacy-conscious analytics. The site is well-optimized for performance, mobile responsiveness, and SEO, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS and has domain transfer protections but lacks DNSSEC and published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR indicators. Overall, Cure51 presents a trustworthy and professional online presence with minor security and compliance improvements recommended to enhance trust and resilience.

15
68
17
70
52
75
40
canceroncologyprecisionmedicinebiotechresearch+3 more
ReactNext.jsMatomo AnalyticsCloudflare DNS and registrar

Partner Domains:

gustaveroussy.fr
partner
vhio.net
partner

+3 more partners

2025-07-27T11:47:48.771Z
havenenergy.com favicon

Haven

havenenergy.com

66
EnergyUnited StatesmediumMEDIUM

Haven Energy is a California-based company specializing in residential solar and battery backup systems, leveraging state rebate programs such as the SGIP Equity rebate to offer no-cost or reduced-cost installations to qualifying homeowners. Their market position is focused on providing reliable, clean energy solutions that reduce electric bills and protect against power outages. The company demonstrates a strong brand presence with clear trust indicators including BBB accreditation and industry association memberships. Technically, the website is built on modern frameworks such as Next.js and React, hosted on AWS infrastructure, and integrates advanced analytics and marketing tools like Google Tag Manager, PostHog, and HubSpot, reflecting a mature digital infrastructure with good performance and mobile optimization. Security posture is solid with HTTPS enforced and no visible vulnerabilities, though the absence of security headers and published security policies suggests room for improvement. Privacy compliance is basic, lacking explicit cookie consent mechanisms and GDPR compliance indicators. Overall, the website is professional, trustworthy, and well-structured, supporting the company’s credibility in the energy sector.

30
53
25
75
72
85
100
solarbatterybackupenergyrenewableenergycalifornia+2 more
ReactNext.jsClerk.jsWebpack+4

Partner Domains:

haven-energy.rippling-ats.com
partner
havenenergy.referralrock.com
partner
2025-07-27T11:47:28.267Z
flathub.org favicon

Flathub

flathub.org

75
TechnologyUnited StatesmediumMEDIUM

Flathub is a prominent app store platform dedicated to Linux users, providing a centralized repository for discovering, installing, and updating Linux applications packaged as Flatpaks. Established in 2016, it serves a global audience of Linux enthusiasts and developers, offering hundreds of apps including popular titles like Firefox, Telegram, and GIMP. The platform emphasizes ease of use and broad compatibility across Linux distributions, positioning itself as the primary app distribution channel in the Linux ecosystem. Technically, Flathub employs modern web technologies including React and Next.js, delivering a fast, responsive, and accessible user experience optimized for both desktop and mobile devices. The site is hosted with reputable providers and uses HTTPS with strong SSL configurations, ensuring secure communications. Analytics are handled via Matomo, reflecting a moderate level of user tracking with some privacy considerations. From a security perspective, Flathub demonstrates good practices such as HTTPS enforcement and domain transfer protection. However, it lacks explicit published privacy, cookie, security, and incident response policies on the main site, which are important for compliance and user trust. The domain registration is consistent and stable, reinforcing the legitimacy of the platform. Overall, Flathub presents a professional, trustworthy, and technically mature platform with room for improvement in privacy compliance and security transparency. Strategic enhancements in these areas would further strengthen user confidence and regulatory adherence.

95
58
25
70
100
70
100
linuxappstoreflatpakopensourcesoftwaredistribution
ReactNext.jsJavaScriptMatomo Analytics
2025-07-27T11:41:02.512Z
lihe.org.uk favicon

London Institute for Healthcare Engineering

lihe.org.uk

57
HealthcareUnited KingdommediumMEDIUM

The London Institute for Healthcare Engineering (LIHE) is a pioneering MedTech venture builder based in the UK, affiliated with King's College London. It focuses on accelerating medical technology innovations from research to market, supporting entrepreneurs, SMEs, and industry partners. The institute offers executive support, collaborative physical space, and educational programs such as an MSc in MedTech Innovation and Entrepreneurship. LIHE is well-positioned in the MedTech ecosystem with strong partnerships and funding from reputable organizations. Technically, the website is built on modern frameworks including Next.js and React, leveraging Prismic CMS for content management. It demonstrates excellent performance, mobile optimization, and SEO practices. Security posture is strong with HTTPS, security headers, and no visible vulnerabilities, though it lacks a visible cookie consent mechanism and dedicated security policy pages. Overall, LIHE's digital presence reflects a professional, trustworthy, and credible organization with a clear mission and strong ecosystem connections. The website is safe, accessible, and well-structured, supporting its business objectives effectively.

40
53
2
60
52
60
100
medtechhealthcareinnovationventurebuildereducation+1 more
ReactNext.jsPrismic CMSGoogle Tag Manager

Partner Domains:

kcl.ac.uk
parent
siemens-healthineers.com
partner

+1 more partners

2025-07-27T10:37:18.584Z
incard.co favicon

Incard Ltd

incard.co

49
FinanceUnited KingdomsmallHIGH

Incard Ltd operates a specialized financial platform tailored for ecommerce businesses, offering multi-currency business accounts, corporate Visa Platinum cards with cashback and rewards, expense management, accounting automation, and financial analytics. Positioned as a fintech innovator, Incard targets ecommerce entrepreneurs seeking streamlined financial operations and enhanced visibility into their cash flow and advertising spend. The company leverages partnerships with Currency Cloud, Visa, and TrueLayer to provide regulated payment and account information services, reinforcing its credibility in the financial sector. Technically, the website is built on a modern React and Next.js stack, hosted on Vercel, and integrates multiple analytics and marketing tools such as Google Tag Manager, Facebook Pixel, Hotjar, and Intercom. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, contributing to a professional user experience. Security posture is strong with HTTPS enforcement, comprehensive security headers, and no visible vulnerabilities or exposed sensitive data. Privacy compliance is supported by detailed privacy and cookie policies, though an explicit cookie consent mechanism is not detected. WHOIS data is privacy protected, which is justified for a fintech company, though it limits direct registrant verification. Overall, Incard presents a trustworthy and professional digital presence with a solid foundation for ecommerce financial services.

-
-
-
52
72
80
100
fintechecommercebusinessaccountscorporatecardsfinancialanalytics+2 more
ReactNext.jsVercel hostingGoogle Tag Manager+4

Partner Domains:

currencycloud.com
partner
visa.com
partner

+1 more partners

2025-07-27T09:20:29.572Z
bday.quest favicon

bday.quest (beta)

bday.quest

57
TechnologyN/asmallMEDIUM

bday.quest is a small, beta-stage online platform focused on creating and sharing virtual birthday cards. The service allows users to create a card, collect personalized birthday wishes via a shared link, and celebrate together by revealing the card on the special day. The website targets a general audience interested in digital greeting solutions and leverages modern web technologies such as Next.js and Clerk.js for authentication and frontend rendering. The platform is positioned as a niche player in the virtual greeting card market with a simple and user-friendly interface. From a technical perspective, the website employs a modern React-based framework (Next.js) and integrates Clerk.js for user authentication. The site shows moderate performance and good mobile optimization but lacks advanced SEO and accessibility features. There is no evidence of a CMS or specific hosting provider from the data provided. The site does not appear to use analytics or advertising technologies, indicating a minimal tracking approach. Security posture is weak due to the absence of visible security headers, lack of privacy and cookie policies, and no contact or incident response information. The domain WHOIS data is privacy protected, which is common for small startups but reduces transparency. No critical vulnerabilities or exposed sensitive data were detected in the HTML content. Overall, the site is safe for general audiences but requires improvements in security and compliance to enhance trustworthiness. The overall risk is moderate with recommendations to implement security best practices, add privacy and cookie policies, and provide clear contact and incident response information to improve compliance and user trust.

35
50
2
60
72
75
100
virtualbirthdaycardsgreetingcardsonlinecardsbirthdaywishesbeta
ReactNext.jsClerk.js
2025-07-27T07:52:56.548Z
cnrad.dev favicon

Conrad Crawford

cnrad.dev

59
TechnologyN/asmallMEDIUM

The website cnrad.dev serves as a personal portfolio and professional presence for Conrad Crawford, a self-taught frontend-focused software engineer. The site highlights his experience with various companies, contract work, and open source projects, positioning him as a skilled individual contributor in the technology sector. The business model centers on personal branding and showcasing technical expertise to potential employers or collaborators. Technically, the site is built using modern web technologies including Next.js and TypeScript, delivering fast performance and excellent mobile optimization. The design is professional and user-friendly, with clear navigation and relevant content. Security posture is solid with HTTPS enforced and no visible vulnerabilities, though the absence of security headers and formal security policies suggests room for improvement. Privacy compliance is minimal, lacking privacy and cookie policies, which is typical for personal sites but may limit trust for some users. Overall, the domain registration data aligns well with the website content, supporting legitimacy and trustworthiness. Strategic recommendations include adding privacy and security policies, implementing security headers, and establishing a vulnerability disclosure process to enhance security and compliance.

30
35
2
70
75
75
100
softwareengineerportfoliofrontendtypescriptnextjs+2 more
TypeScriptReactNext.jsCSS

Partner Domains:

cside.dev
partner
incard.co
partner

+1 more partners

2025-07-27T06:48:07.818Z
m6.wtf favicon

m6.wtf

m6.wtf

61
OtherCanadasmallMEDIUM

The website m6.wtf currently serves as a placeholder with minimal content, displaying only a 'SOON™️' message and a brief description stating 'srry, nothing here yet'. There is no substantive business information, contact details, or policies available, indicating that the site is either under development or inactive. The domain is registered through Porkbun LLC with a Canadian registrant and uses Cloudflare DNS services, suggesting a basic level of infrastructure readiness. The technical stack includes Next.js and React frameworks, which are modern and capable of supporting a robust web presence once fully developed. From a security perspective, the site lacks critical security headers and DNSSEC is not enabled, which are areas for improvement. No forms or data collection mechanisms are present, reducing immediate privacy risks but also indicating a lack of user engagement features. The absence of privacy, cookie, or terms of service policies means the site is currently non-compliant with GDPR and other privacy regulations. No contact or incident response information is provided, limiting transparency and trust. Overall, the site scores low on content quality, security posture, privacy compliance, and business credibility due to its placeholder status and lack of substantive information. There are no indications of malicious content or adult material, and the site is accessible without WAF or security challenges. Strategic recommendations include enabling DNSSEC, adding standard security headers, publishing privacy and cookie policies, and providing clear contact information to improve trust and compliance.

75
50
2
65
75
85
100
placeholdercomingsoonminimalcontentnextjscloudflare
Next.jsReactCloudflare DNS
2025-07-27T06:46:52.310Z
svgrepo.com favicon

SVG Repo LLC

svgrepo.com

63
TechnologyN/asmallMEDIUM

SVG Repo LLC operates a comprehensive online platform offering over 500,000 free, open-licensed SVG vectors and icons. The website targets designers, developers, and businesses seeking high-quality vector graphics for commercial use. It emphasizes community contributions and provides tools for searching, editing, and remixing SVG assets without requiring design software. The platform holds a strong market position as a large, free SVG repository with a user-friendly interface and modern web technologies. Technically, the website is built using React and Next.js frameworks, ensuring fast performance, mobile optimization, and good SEO practices. It integrates Google Analytics and Tag Manager for user tracking and marketing insights. The site employs HTTPS with excellent SSL configuration, though security headers are not explicitly detected in the provided data. No vulnerabilities or exposed sensitive data were found in the analysis. From a security perspective, the site maintains a good posture with encrypted connections and no visible security flaws. However, it lacks explicit cookie consent mechanisms and published security policies or incident response contacts. The absence of WHOIS domain registration data is a concern for domain legitimacy verification, though the website content and branding appear professional and trustworthy. Overall, SVG Repo presents a low-risk profile with strong content quality and technical implementation. Strategic improvements in security headers, privacy compliance, and domain registration transparency would enhance trust and compliance.

50
53
17
70
57
75
100
svgvectorsiconsfreeopen-license+2 more
ReactNext.jsGoogle AnalyticsTinySVG compressor
2025-07-27T06:44:05.611Z
royalhackaway.com favicon

Royal Hackaway

royalhackaway.com

58
EducationUnited KingdomsmallMEDIUM

Royal Hackaway is an annual hackathon event organized by Royal Holloway's Computing Society, targeting university students aged 18 and above from the UK and worldwide. The event spans 24 hours and includes workshops, talks, mini-events, and a project fair, supported by multiple sponsors including academic departments and tech companies. The website is professionally designed with clear navigation, mobile optimization, and rich content relevant to the event. Technically, the site is built using modern web technologies such as Next.js and React, with embedded Google Maps and Font Awesome icons enhancing user experience. Performance and accessibility are strong, with no detected broken elements or errors. However, explicit privacy and cookie policies are absent, and no security.txt or vulnerability disclosure mechanisms are present. Security posture is moderate; HTTPS is used, but security headers are not detected, and no incident response contacts are provided. The lack of WHOIS data for the domain raises some concerns about domain legitimacy, though the website content and sponsorships suggest a legitimate educational event. Overall, the site is safe, trustworthy, and well-positioned for its target audience. Recommendations include publishing comprehensive privacy and cookie policies, implementing security headers, adding vulnerability disclosure information, and verifying domain registration details to enhance trust and compliance.

30
35
2
70
75
70
100
hackathoneducationuniversitytechnologyevent+4 more
Next.jsReactFont Awesome 6Google Maps Embed
2025-07-27T04:32:51.565Z
S

slice.zone

slice.zone

53
TechnologyUnited StatessmallMEDIUM

The website skip.house is a personal site belonging to an individual named Skip, a computer programmer from California. The site appears to serve as a personal portfolio or blog, focusing on interests such as electronic music, UI design, rhythm games, and languages. The domain is newly registered in March 2024 and hosted via Cloudflare, using a modern React and Next.js technology stack. However, the site currently displays an application error page, limiting content accessibility and analysis. From a technical perspective, the site uses contemporary web frameworks but lacks advanced SEO, accessibility, and performance optimizations. There are no detected privacy, cookie, or terms of service policies, nor any contact information or security policies published. Security posture is basic, with no DNSSEC enabled and no security headers detected, which could expose the site to certain risks. Overall, the security posture is weak, with no incident response or vulnerability disclosure mechanisms evident. The domain registration is consistent with the personal nature of the site, and no suspicious patterns were found. The site does not contain any adult or questionable content and targets a general audience. The lack of policies and contact information, combined with the application error, reduces trustworthiness and business credibility. Strategic recommendations include fixing the application error to restore site functionality, implementing privacy and cookie policies, enabling DNSSEC and security headers, and publishing security and incident response information to improve trust and compliance.

30
35
2
70
72
70
100
personalprogrammertechnologyreactnextjs+1 more
ReactNext.jsCloudflare
2025-07-27T04:30:25.343Z
breq.dev favicon

Application error: a client-side exception has occurred

breq.dev

59
TechnologyN/asmallMEDIUM

The website breq.dev serves as a personal portfolio and project showcase primarily focused on software development, hardware projects, and open source contributions. It targets developers and technology enthusiasts interested in programming, hardware tinkering, and web applications. The site hosts numerous projects with demos and repositories, reflecting a strong technical background and active development. However, the main page currently suffers from a client-side application error, which significantly impacts user experience and accessibility. Technically, the site is built using modern web technologies including Next.js, React, Python, Flask, and Node.js, and is hosted on Vercel. The technology stack is diverse and up-to-date, supporting a variety of programming languages and frameworks. Despite this, the site lacks important security headers and privacy compliance elements, and the frontend error suggests some technical debt or deployment issues. From a security perspective, the site does not present explicit vulnerabilities but lacks essential security best practices such as HTTPS verification, security headers, and privacy policies. No incident response or vulnerability disclosure information is provided, which limits trust and compliance with data protection regulations. Analytics usage is minimal and limited to Cloudflare Insights, with no aggressive tracking or advertising. Overall, the site is a technically competent personal portfolio with good content relevance but suffers from poor user experience due to errors and missing compliance/security features. Strategic improvements in frontend stability, privacy compliance, and security hardening are recommended to enhance trustworthiness and professionalism.

30
50
2
85
72
80
100
technologyportfolioopensourceprojectshardware+5 more
Next.jsReactJavaScriptPython+8
2025-07-27T04:29:55.203Z
rattle.com favicon

Rattle Foundation

rattle.com

62
MediaUnited StatessmallMEDIUM

Rattle.com is the official website of Rattle Poetry, an independent poetry magazine published by the Rattle Foundation, a 501(c)3 non-profit organization. Established in 1995, it serves the poetry community by offering literary content, poetry contests, chapbook publications, workshops, and community engagement. The website targets poets, poetry readers, educators, and literary enthusiasts, positioning itself as a respected and long-standing publication in the poetry media sector. Technically, the website employs a modern tech stack including React and Next.js for the frontend, with WordPress as the backend CMS and WooCommerce for e-commerce functionalities. Hosting and DNS are managed via Vercel and Network Solutions respectively. The site is well-optimized for mobile devices, has good SEO practices, and delivers fast performance with a professional design and clear navigation. From a security perspective, the site uses HTTPS with a domain status that prevents unauthorized transfers, but lacks DNSSEC and explicit security headers. There is no visible security policy or incident response information, and no cookie consent mechanism is present, which are areas for improvement. The WHOIS data confirms the domain's legitimacy and long-term operation, consistent with the organization's claims. Overall, Rattle.com is a credible, professional, and content-rich website serving a niche literary audience. Strategic improvements in security headers, privacy compliance, and incident response transparency would enhance its security posture and user trust.

30
58
17
55
72
85
100
poetryliterarymagazinenon-profitindependentpublicationpoetrycontests+2 more
ReactNext.jsVercel DNSWordPress (backend)+2
2025-07-26T23:54:11.198Z