Skip to main content

High-risk security reports

Browse 43,809 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149561
Websites
130
Industries
113
Countries
52
Avg Score
Page 675 of 877|Showing 33701-33750 of 43809
luwi.ee favicon

Luwi OÜ

luwi.ee

45
EducationEstoniasmallHIGH

Luwi OÜ operates as a specialized training center in Estonia, providing a broad range of educational services including group and individual training courses, psychological and addiction counseling, and supervision services. The company is recognized as a partner of the Estonian Unemployment Insurance Fund's training card program, which enhances its credibility and market position. The website is professionally designed, multilingual, and offers clear navigation to various training categories and services, targeting individuals and organizations seeking professional development in Estonia. Technically, the website is built on WordPress with a modern technology stack including Bootstrap, jQuery, and several optimization and security plugins. It employs Google reCAPTCHA v3 for form protection and uses cookie consent mechanisms to comply with privacy regulations. The site is hosted by Zone Media OÜ, a known Estonian hosting provider, and demonstrates moderate performance and good mobile optimization. From a security perspective, the site enforces HTTPS and uses reCAPTCHA to protect forms, but lacks explicit security headers and published security policies or incident response contacts. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is basic but present, with a privacy policy and cookie consent banner. Business credibility is strong with clear contact information, company registration details, and trust signals such as partnerships and certifications. Overall, Luwi OÜ's website presents a trustworthy and professional online presence with room for improvement in security header implementation and formal security policies. The risk level is moderate with no critical issues detected, making it a reliable platform for its users.

15
10
25
70
72
70
20
educationtrainingestoniacontactformmultilingual+2 more
WordPressPHPjQueryBootstrap+8

Partner Domains:

tootukassa.ee
partner
reiting.ee
partner

+3 more partners

2025-06-26T15:29:46.361Z
drahanp.cz favicon

Dráha národního parku

drahanp.cz

44
TransportationCzech RepublicsmallHIGH

Dráha národního parku operates as a specialized regional tourism and transportation information platform focused on the Czech and Saxon Switzerland national parks and surrounding protected areas. The website provides comprehensive travel information including railway routes, bus connections, trip recommendations, ticketing, and timetables, targeting tourists and visitors interested in exploring these natural regions. The business model centers on promoting sustainable travel experiences by train and bus, supported by partnerships with regional transport and tourism organizations. Technically, the website is built on WordPress with common plugins such as LayerSlider, Contact Form 7, and Yoast SEO, and integrates Google Tag Manager for analytics and marketing. The site is mobile-optimized and SEO-friendly, with structured data enhancing search visibility. Security posture is solid with HTTPS enforced and cookie consent implemented, though security headers and explicit privacy and incident response policies are absent. Overall, the website is professional and trustworthy, though it would benefit from enhanced privacy documentation and security best practices to improve compliance and user trust.

15
25
2
55
75
80
20
transportationtourismnationalparkrailwayczechrepublic+5 more
WordPress 5.4.16LayerSlider pluginContact Form 7Yoast SEO plugin+3

Partner Domains:

ceskesvycarsko.cz
partner
cd.cz
partner

+3 more partners

2025-06-26T14:24:37.211Z
inado.org favicon

Institute of National Anti-Doping Organisations

inado.org

46
Non-profitGermanysmallHIGH

The Institute of National Anti-Doping Organisations (iNADO) is a non-profit international membership organization dedicated to supporting National Anti-Doping Organisations (NADOs) and Regional Anti-Doping Organisations (RADOs). It promotes best practices, fosters community collaboration, and serves as a global voice advocating for clean sport. The website reflects a professional and well-structured platform that provides resources, news, and event information relevant to anti-doping experts and stakeholders. Technically, the website is built on the TYPO3 CMS platform, integrating modern tools such as Google Tag Manager for analytics and Usercentrics for consent management, indicating a mature digital infrastructure. The site is mobile-optimized, accessible, and SEO-friendly, with good performance metrics. However, some security headers are missing, and there is no publicly visible security policy or incident response information. From a security perspective, the site enforces HTTPS and employs consent mechanisms for privacy compliance, aligning with GDPR requirements. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data is privacy protected, which is typical for organizations of this nature, and does not raise immediate concerns. Overall, the site demonstrates a solid security posture but could improve transparency around security policies and incident response. The overall risk assessment is low, with recommendations focusing on enhancing security headers, publishing security policies, and adding vulnerability disclosure mechanisms to further strengthen trust and compliance.

25
35
2
70
72
60
20
anti-dopingnon-profitsportsintegritycommunityadvocacy+1 more
TYPO3 CMSGoogle Tag ManagerUsercentrics Consent Management

Partner Domains:

www.wada-ama.org
partner
2025-06-26T14:22:31.914Z
T

Tady chutná

tadychutna.cz

41
HospitalityCzech RepublicmediumHIGH

Tady Chutná is a hospitality business operating four distinct restaurants in the heart of Prague, specializing in traditional Czech and Austro-Hungarian cuisine. The brand emphasizes quality food, regional wines, and a rich historical ambiance, targeting both locals and tourists seeking authentic dining experiences. The parent company, Husičky s.r.o., manages these establishments with a focus on culinary heritage and customer satisfaction. The website serves as a central hub linking to each restaurant's dedicated site and provides daily menu offerings and contact information. Technically, the website is built on WordPress 6.8.1, utilizing modern JavaScript libraries such as jQuery and Slick Carousel for interactive elements. It integrates Google Tag Manager and Facebook Pixel for analytics and marketing, alongside Cookiebot for GDPR-compliant cookie consent management. Hosting is provided by Webglobe, consistent with the domain's WHOIS data. The site is mobile-optimized and SEO-friendly, with structured data enhancing search engine visibility. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms, but lacks explicit security headers and published security policies. No forms are present for direct data collection, reducing attack surface, but the absence of privacy and terms of service documents represents a compliance gap. No incident response or vulnerability disclosure information is available, which could be improved to enhance trust and preparedness. Overall, the website presents a professional and trustworthy front for a medium-sized hospitality business, with good technical implementation and moderate privacy compliance. Strategic improvements in policy transparency and security posture would further strengthen its risk profile and customer confidence.

15
25
2
70
62
75
-
hospitalityrestaurantpraguefoodwine+2 more
jQuery 3.6.0Slick CarouselGoogle Tag ManagerFacebook Pixel+1

Partner Domains:

restauracemincovna.cz
partner
restauracetiskarna.cz
partner

+1 more partners

2025-06-26T14:22:01.848Z
citadeleleasing.ee favicon

Citadele pank

citadeleleasing.ee

46
FinanceEstonialargeHIGH

Citadele pank is a well-established financial institution in Estonia offering leasing services primarily focused on vehicle financing. The website provides detailed leasing options, including a calculator and a dedicated leasing portal for customers to manage their contracts and applications. The business targets private individuals seeking flexible leasing solutions with personalized interest rates and competitive terms. The company is part of the larger Citadele Group, indicating a strong market position in the Baltic financial sector. Technically, the website employs modern web technologies such as jQuery, Bootstrap, and Google Tag Manager, with a CMS likely being October CMS. The site is mobile-optimized, accessible, and SEO-friendly, providing a good user experience. Security-wise, the site enforces HTTPS, uses security headers, and implements cookie consent mechanisms, though explicit security and incident response policies are not publicly available. WHOIS data confirms the domain's legitimacy and consistency with the business identity. Overall, the website reflects a professional and trustworthy financial service provider with room for improvement in transparency around security policies and incident response.

-
25
2
87
-
70
100
leasingbankingfinancevehiclefinancingestonia
jQueryBootstrapnoUiSliderGoogle Tag Manager+2

Partner Domains:

www.citadeleleasing.ee
subsidiary
portal.klix.app
partner

+2 more partners

2025-06-26T14:21:21.762Z
restauracemincovna.cz favicon

Restaurace Mincovna

restauracemincovna.cz

45
HospitalityCzech RepublicmediumHIGH

Restaurace Mincovna is a well-established restaurant located in the prestigious Staroměstské náměstí in Prague, offering traditional Czech cuisine with a modern twist and a selection of wines and Pilsner tank beer. The business targets both tourists and local patrons, leveraging its historic ambiance and prime location to maintain a strong market position in the hospitality sector. The website reflects a professional digital presence with clear branding and comprehensive business information. Technically, the website is built on WordPress with modern analytics and marketing tools integrated, including Google Analytics 4 and Google Tag Manager. The site implements a robust cookie consent mechanism aligned with GDPR requirements, enhancing privacy compliance. Performance and mobile optimization are good, though accessibility features are basic. No significant technical vulnerabilities were detected, but security headers could be improved. From a security perspective, the site uses HTTPS and employs cookie consent management, but lacks visible security headers and a public security or incident response policy. The absence of WHOIS data limits domain trust verification, though the website content and business details appear legitimate. Overall, the site demonstrates a moderate to good security posture with room for enhancement in transparency and technical security controls. Strategically, the business should focus on improving security headers, publishing incident response and vulnerability disclosure policies, and obtaining verifiable WHOIS data to enhance trust. Continued investment in privacy compliance and user experience will support sustained market credibility and customer trust.

15
25
17
75
72
80
-
restauranthospitalityczechcuisinepraguefood+5 more
WordPressjQueryGoogle Tag ManagerGoogle Analytics 4+3

Partner Domains:

www.tadychutna.cz
partner
utelleru.cz
partner

+1 more partners

2025-06-26T13:17:35.012Z
utelleru.cz favicon

VeKaPa s.r.o.

utelleru.cz

48
HospitalityCzech RepublicsmallHIGH

Restaurant U Tellerů is a small hospitality business located in Prague, Czech Republic, specializing in modern Czech cuisine and charcoal-grilled steaks. The restaurant emphasizes quality dining experiences with a focus on local specialties and beverages such as Pilsner Urquell beer. The website supports reservations and offers gift vouchers, targeting local and tourist diners seeking authentic Czech culinary experiences. The business maintains an active presence on social media platforms including Facebook, Instagram, Pinterest, and TripAdvisor, enhancing its market visibility and customer engagement. Technically, the website is built on WordPress CMS, utilizing common plugins for analytics, cookie consent, and responsive design. It integrates Google Analytics 4, Facebook Pixel, and Google Tag Manager for marketing and tracking purposes, with a compliant cookie consent mechanism in place. The site is mobile-optimized and demonstrates good SEO practices, although accessibility features are basic. Performance is moderate, with room for improvement in loading speed and security headers. From a security perspective, the site enforces HTTPS and employs cookie consent with opt-in features, reflecting a good privacy posture. However, the absence of security headers and a published privacy policy or incident response information indicates areas for enhancement. The WHOIS data is unavailable, which raises concerns about domain registration transparency but does not directly impact the website's operational legitimacy. Overall, the website presents a professional and trustworthy front for the restaurant business, with recommendations to improve security practices, publish comprehensive privacy and security policies, and verify domain registration details to strengthen trust and compliance.

15
25
17
75
95
80
-
hospitalityrestaurantczechcuisinesteakhouseprague+4 more
WordPressjQueryGoogle Tag ManagerGoogle Analytics 4+3

Partner Domains:

www.tadychutna.cz
partner
www.restauracemincovna.cz
partner

+1 more partners

2025-06-26T13:17:30.005Z
bloomrobbins.si favicon

Bloom Robbins SI

bloomrobbins.si

47
E-commerceSloveniasmallHIGH

Bloom Robbins SI is a Slovenian e-commerce business specializing in vitamins and supplements aimed at supporting hair health and growth. The company operates primarily through a Shopify-based online store, targeting consumers interested in hair care products. The website is professionally designed with consistent branding and good content quality, focusing on product benefits and customer engagement. The business appears to be relatively new, with domain registration dating from early 2023, and is part of a broader network of regional sister sites serving multiple European countries. Technically, the website leverages modern e-commerce technologies including Shopify's Dawn theme, Google Tag Manager, Facebook Pixel, and Klaviyo for marketing automation and analytics. Hosting is managed via Cloudflare, ensuring good performance and security. The site includes GDPR-compliant cookie consent mechanisms and a clear privacy policy, reflecting a mature approach to privacy and data protection. However, some standard legal pages such as terms of service and security policies are missing, and no direct contact information is readily available on the site. From a security perspective, the site enforces HTTPS and employs consent management for tracking and marketing scripts. While no critical vulnerabilities or exposed sensitive data were detected, the absence of explicit security headers and incident response information suggests room for improvement. The domain registration is consistent and transparent, with no privacy protection masking registrant details, which supports legitimacy. Overall, Bloom Robbins SI presents a solid e-commerce presence with good technical and privacy compliance foundations. Strategic enhancements in security policies, contact transparency, and legal documentation would further strengthen trust and compliance posture.

75
25
25
55
75
65
100
e-commercehealthsupplementsgdprshopifycookieconsent+2 more
ShopifyJavaScriptGoogle Tag ManagerFacebook Pixel+3

Partner Domains:

bloomrobbins.sk
sister
bloomrobbins.cz
sister

+3 more partners

2025-06-26T13:17:19.990Z
T

tokoblog.net | 526: Invalid SSL certificate

tokoblog.net

47
OtherN/asmallHIGH

The website tokoblog.net is currently inaccessible due to an invalid SSL certificate on the origin server, resulting in a Cloudflare Error 526. This prevents any meaningful content or business information from being accessed or analyzed. The domain is registered with NameCheap, Inc. since 2021 and uses Cloudflare DNS services, but lacks DNSSEC and a valid SSL certificate, which significantly impacts its security posture and trustworthiness. No privacy, cookie, or terms of service policies are present, and no contact information or business details are available on the error page. The technical infrastructure relies on Cloudflare as a CDN and security provider, but the SSL misconfiguration undermines the site's availability and security. From a security perspective, the primary concern is the invalid SSL certificate that blocks user access and may expose visitors to risks if bypassed. The absence of security headers and policies further weakens the site's security maturity. Business credibility and privacy compliance cannot be assessed due to lack of accessible content. Overall, the site scores very low on content quality, privacy compliance, and business credibility, with a moderate score on security posture limited by the SSL issue. Strategic recommendations include immediate installation of a valid SSL certificate on the origin server, enabling DNSSEC, and implementing standard security headers. Additionally, publishing privacy and cookie policies and providing clear contact information would improve compliance and trust. Monitoring and maintaining SSL certificates and security configurations will enhance availability and user confidence.

-
35
2
70
75
70
100
errorsslcloudflaresecurityblocked
Cloudflare
2025-06-26T13:14:44.425Z
weglot.eu favicon

Nameshift.com

weglot.eu

49
TechnologyNetherlandssmallHIGH

The website weglot.eu currently serves as a domain sales landing page operated by Nameshift.com, a domain brokerage and escrow service based in the Netherlands. The platform offers domain purchase services with an emphasis on safe, fast, and fee-free domain transfers for buyers. The business model focuses on domain resale with escrow facilitation to ensure secure transactions. The target audience includes domain investors and buyers seeking a trusted intermediary for domain acquisitions. The website content is minimal and primarily transactional, reflecting its purpose as a domain sales portal rather than a full business site. Technically, the site is built using modern web technologies including SvelteKit and JavaScript, hosted on a CDN associated with Nameshift.com. The site demonstrates moderate performance and basic mobile optimization. However, SEO and accessibility features are basic, and there is no evidence of a CMS or extensive platform integrations. The site uses external scripts for analytics and Trustpilot reviews, indicating some level of marketing and trust-building efforts. From a security perspective, the site uses HTTPS and does not expose sensitive data in the HTML. However, it lacks explicit security headers such as Content Security Policy or HSTS, and no privacy or cookie policies are present, which are critical for GDPR compliance. There is no visible incident response or security contact information. The domain registration data is consistent with the business purpose, registered via a known registrar without privacy protection, supporting legitimacy. Overall, the site presents a low-risk profile but has significant gaps in privacy compliance and security best practices. Strategic improvements in policy disclosures, security headers, and contact transparency would enhance trust and compliance. The site’s limited content and basic design reflect its narrow business focus but also limit user engagement and SEO potential.

55
25
2
65
72
75
40
domainsalesescrowdomaintransfernameshifttrustpilot
SvelteKitJavaScriptCSSSVG

Partner Domains:

nameshift.com
partner
2025-06-26T13:12:44.174Z
S

SPWeb s.r.o.

spweb.cz

48
TechnologyCzech RepublicsmallHIGH

SPWeb s.r.o. is a well-established Czech technology company specializing in custom web development, e-commerce solutions, SEO, PPC marketing, and IT infrastructure services primarily serving the Brno region. The company has a strong market position supported by over a decade of experience, positive client testimonials, and Google Partner certification. Their website reflects a professional and modern digital presence with comprehensive service offerings and clear contact information. Technically, the website employs a modern technology stack including Bootstrap, jQuery, Google Fonts, and multiple analytics and marketing tools such as Google Tag Manager, Facebook Pixel, Microsoft Clarity, and Smartlook. The site is mobile-optimized, fast-loading, and SEO-friendly, demonstrating a mature digital infrastructure. Hosting and DNS services are managed via Cloudflare, enhancing performance and security. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms aligned with GDPR requirements. However, it lacks explicit security policies, incident response contacts, and security headers, which are recommended to enhance its security posture. No vulnerabilities or exposed sensitive data were detected, indicating a generally secure environment. Overall, SPWeb s.r.o. presents a credible, trustworthy, and professional business with a strong online presence. The website scores highly on content quality, technical implementation, security, privacy compliance, and business credibility, making it a reliable partner for clients seeking web and IT services.

15
10
2
75
72
80
40
webdevelopmentseoppchostingitservices+3 more
HTML5CSS3JavaScriptjQuery+10
2025-06-26T13:12:19.127Z
zalohujme.cz favicon

Zalohujme.cz

zalohujme.cz

48
Non-profitCzech RepublicsmallHIGH

Zalohujme.cz is a Czech environmental initiative focused on promoting the implementation of a deposit return system for PET bottles and beverage cans in the Czech Republic. The website provides comprehensive information about the benefits of such a system, its operation, and examples from other European countries. It targets the general public, environmental advocates, municipalities, and beverage producers. The platform serves as an educational and advocacy tool to support legislative changes and increase recycling rates. Technically, the website is built on WordPress and employs common web technologies including jQuery, Google Analytics, Google Tag Manager, Facebook Pixel, and Smartlook for user behavior tracking. The site is mobile-optimized with good SEO practices including structured data and meta tags. Performance is moderate, and accessibility is basic but functional. From a security perspective, the site uses HTTPS with a good SSL configuration but lacks some security headers and explicit security policies. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is limited as no explicit privacy or cookie policies or consent mechanisms were found. Contact information is limited to an email address in the header, with no phone numbers or physical addresses provided. Overall, the website is legitimate and professional in its presentation and content, though the absence of WHOIS data and privacy policies slightly reduces trustworthiness. Strategic improvements in privacy compliance, security headers, and incident response transparency are recommended to enhance the site's security posture and user trust.

30
25
17
80
52
85
20
environmentrecyclingpetbottlesdepositsystemczechrepublic+2 more
jQueryGoogle AnalyticsGoogle Tag ManagerFacebook Pixel+1
2025-06-26T13:10:23.533Z
M

MSC Publishing & Design Limited

aims-worldrunning.org

43
OtherUnited KingdomsmallHIGH

AIMS (Association of International Marathons and Distance Races) operates as a recognized global organization dedicated to the promotion and coordination of marathon and long-distance running events worldwide. The website serves as a comprehensive hub for race calendars, news, results, directories, and publishes the Distance Running magazine, targeting runners, race organizers, and athletics enthusiasts globally. The organization is registered in Great Britain under MSC Publishing & Design Limited, with a domain age consistent with its operational history since 2016. Technically, the website employs a mix of legacy and modern web technologies including jQuery 1.12.4, Cycle2 plugins, Leaflet for mapping, and Google Analytics for user tracking with IP anonymization. The site is mobile responsive with good navigation and content quality, though some technical debt is evident in the use of outdated JavaScript libraries. SEO and accessibility are basic but functional. From a security perspective, the site benefits from HTTPS and domain registration protections but lacks DNSSEC and security headers, and uses an outdated jQuery version with known vulnerabilities. No privacy or cookie policies are present, indicating compliance gaps with GDPR and related regulations. Contact information is limited to a physical address with no emails or phone numbers explicitly provided. No incident response or security policy information is available. Overall, the website is professional and trustworthy with a solid business foundation but requires improvements in privacy compliance, security hardening, and transparency to enhance user trust and regulatory adherence.

15
35
2
70
62
65
20
marathonrunningathleticslongdistancesports+1 more
jQuery 1.12.4Cycle2 jQuery pluginLeaflet 1.6.0Google Analytics+3

Partner Domains:

health1984.com
partner
marathon-photos.com
partner

+3 more partners

2025-06-26T12:08:56.768Z
sphosting.cz favicon

SPHosting s.r.o.

sphosting.cz

46
TechnologyCzech RepublicsmallHIGH

SPHosting s.r.o. is a Czech Republic-based hosting service provider established in 2014, specializing in virtual private servers, dedicated servers, managed servers, and cloud/network services. The company targets small to medium businesses requiring tailored hosting solutions with professional management and 24/7 support. Their market position is supported by positive client testimonials and a perfect aggregate rating, indicating strong customer satisfaction and trust. Technically, the website employs a modern technology stack including Bootstrap, jQuery, FontAwesome, and slick carousel for UI, alongside Google Tag Manager, Facebook Pixel, and Yandex Metrika for analytics and marketing. The site is hosted behind Cloudflare DNS and uses HTTPS with excellent SSL configuration. The cookie consent mechanism is comprehensive and GDPR compliant, reflecting good digital maturity. From a security perspective, the site enforces HTTPS, uses reCAPTCHA v2 for form protection, and provides granular cookie consent options. However, it lacks explicit security policies, incident response information, and a security.txt file, which are areas for improvement. No vulnerabilities or exposed sensitive data were detected, and security headers could be enhanced. Overall, the website presents a professional, trustworthy, and well-maintained digital presence with moderate to good security posture. Strategic improvements in security transparency and header implementation would further strengthen their risk profile and compliance stance.

-
10
10
85
95
85
-
hostingserverrentalvpsdedicatedserversmanagedservers+3 more
jQueryBootstrapFontAwesomeSlick Carousel+4
2025-06-26T12:06:41.154Z