Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149091
Websites
130
Industries
113
Countries
52
Avg Score
Page 67 of 67|Showing 3301-3331 of 3331
credit-agricole.com favicon

Crédit Agricole

credit-agricole.com

52
bankingFranceenterpriseMEDIUM

The website exhibits serious security deficiencies, particularly the complete absence of HTTPS encryption, which critically exposes data in transit and undermines user trust. Compliance with GDPR and NIS2 regulations is severely lacking, with missing cookie policies, consent mechanisms, and essential security governance documentation, posing significant legal and operational risks. While network security and email security demonstrate relatively strong postures, foundational issues around encryption and policy frameworks significantly elevate the organization's exposure to data breaches and regulatory penalties. Security headers and DNS configurations are suboptimal but less urgent relative to the critical gaps. Immediate remediation is necessary to protect customer data, maintain regulatory compliance, and uphold the organization's reputation. Without urgent action, the business remains vulnerable to interception, data leakage, and potential loss of customer confidence. Prioritizing HTTPS implementation alongside privacy and incident response policies will substantially improve the security stance. Overall, the current posture demands urgent attention to align with industry best practices and regulatory mandates.

80
18
5
85
-
85
100
bankingfinanceCrédit AgricoleFrancefinancial services+2 more
JavaScriptGoogle Maps APIAT Internettarteaucitron.js+3

Partner Domains:

credit-agricole.fr
subsidiarypending
2025-06-13T18:10:50.379Z
hoozin.com favicon

Hoozin

hoozin.com

40
software / digital workplace solutionsUSAmediumHIGH

The website's overall security posture is critically weak, exposing the business to significant risks including data breaches, regulatory non-compliance, and operational disruptions. The absence of HTTPS encryption is a critical vulnerability that undermines data confidentiality and trust, while missing essential security headers leave the site open to common web attacks such as clickjacking and cross-site scripting. GDPR compliance is severely lacking, with no cookie policy or consent mechanisms, creating legal exposure and reputational damage risks. Network security is compromised by the exposure of high-risk services like FTP and MySQL without adequate protections, increasing the attack surface. The lack of incident response, security policies, and business continuity planning under the NIS2 framework indicates immature security governance. Although email security and DNS health score relatively well, these strengths do not offset the critical deficiencies elsewhere. Immediate remediation is required to protect customer data, maintain regulatory compliance, and safeguard business continuity. Without urgent action, the organization risks financial penalties, loss of customer trust, and potential service outages.

15
18
5
85
-
85
50
digital workplaceworkflowssocial intranetemployee collaborationintegration+1 more
WordPress 6.8.1W3 Total CacheRodller BlocksContact Form 7+8

Partner Domains:

rodller.com
partnerpending
2025-06-13T18:10:49.566Z
wyser-search.com favicon

Wyser

wyser-search.com

47
recruitment and human resourcesmultiple including Brazil, Bulgaria, Chile, China, France, Hungary, Italy, Poland, Portugal, Romania, Serbia, Spain, TurkeymediumHIGH

The website's current security posture is critically weak, with multiple severe vulnerabilities exposing it to significant risk. The absence of HTTPS encryption is a fundamental flaw, affecting data confidentiality and trust, and violates GDPR and NIS2 requirements. Key security headers such as Strict-Transport-Security and Content-Security-Policy are missing, increasing exposure to common web attacks like XSS and protocol downgrade attacks. GDPR compliance is notably poor, lacking essential elements like a cookie policy and consent mechanisms, which can lead to regulatory fines and reputational damage. The absence of documented information security frameworks, security policies, and incident response procedures indicates immature organizational security governance. While email security and network security are relatively strong, this does not compensate for the critical gaps in web application and data protection. Immediate remediation is necessary to protect customer data, maintain regulatory compliance, and preserve business reputation. Without swift action, the organization risks data breaches, regulatory penalties, and loss of customer trust.

30
18
-
90
-
85
100
recruitmentsearch and selectionsenior managementhuman resourcesglobal+4 more
WordPressYoast SEO pluginWP RocketElementor+10

Partner Domains:

gigroupholding.com
subsidiarypending
2025-06-13T18:10:49.545Z
optimat.be favicon

OptimaT

optimat.be

46
industrial supplyBelgiummediumHIGH

The website's security posture is currently at high risk, with multiple critical and high-severity issues that directly impact business operations and regulatory compliance. Notably, the absence of HTTPS encryption exposes sensitive data to interception, undermining user trust and violating legal requirements such as GDPR and NIS2. Missing key security headers (Strict-Transport-Security, X-Frame-Options, Content-Security-Policy) increases vulnerability to common web attacks. The lack of GDPR compliance elements, including privacy and cookie policies and consent mechanisms, poses significant legal and reputational risks, especially for EU customers. Additionally, the organization lacks foundational information security frameworks, incident response procedures, and business continuity plans, indicating immature security governance. Although email security and network security show moderate to good standing, critical gaps in SSL/TLS and GDPR compliance drastically overshadow these positives. Immediate remediation is essential to protect customer data, maintain regulatory compliance, and secure business operations. The overall security readiness score reflects urgent need for comprehensive security improvements and policy implementations.

55
-
5
85
-
85
100
industrial supplyISO9001ISO14001custom manufacturingprofessional services+2 more
Google Tag ManagerGoogle Analytics (gtag)Google Maps APIOwl Carousel v2+7

Partner Domains:

jobtoolz.com
servicepending
2025-06-13T18:10:49.509Z
johnsoncontrols.com favicon

Johnson Controls

johnsoncontrols.com

68
Building Automation and ControlsUnited StatesenterpriseMEDIUM

The website demonstrates a moderate security posture with no critical vulnerabilities found; however, several high and medium-risk issues significantly impact compliance and risk management. Key deficiencies exist in GDPR compliance, including the absence of privacy and cookie policies and lack of user consent mechanisms, exposing the business to regulatory penalties and reputational damage. The absence of a documented information security framework, incident response procedures, and security policies under NIS2 guidance further increases organizational risk and may hinder regulatory adherence. Security headers are inconsistently implemented, reducing protection against common web threats like XSS and content sniffing. SSL/TLS configurations are generally strong but require timely certificate renewal and elimination of mixed content to maintain secure communications. DNS settings are mostly healthy but can be improved by enabling DNSSEC to prevent domain spoofing. Positively, email and network security postures are robust, mitigating some external attack vectors. Overall, urgent attention to compliance and governance-related controls is critical to safeguard the business and maintain trust with users and regulators.

60
25
25
100
80
85
100
OpenBlueArtificial IntelligenceHealthy BuildingsAI in Building ManagementNet Zero Buildings+4 more
jQueryBootstrap 4Coveo SearchGoogle Maps API+15
2025-06-13T18:10:48.990Z