Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149091
Websites
130
Industries
113
Countries
52
Avg Score
Page 7 of 1021|Showing 301-350 of 51023
socialcatnip.com favicon

SocialCatnip

socialcatnip.com

55
TechnologyN/asmallMEDIUM

SocialCatnip is a specialized Webflow development and digital marketing agency focusing on marketing technology, conversion tracking, GA4, and Google Tag Manager. The company targets B2B SaaS businesses and offers a comprehensive suite of services including marketing tech integrations, technical SEO, tracking and analytics, webflow development, paid media, web design, and local services ads. The website reflects a mature, professional business with a decade of experience and a strong client base, supported by positive testimonials and notable client logos. Technically, the website is built on Webflow and leverages modern marketing and analytics tools such as Google Analytics, Google Tag Manager, Hotjar, and Microsoft Clarity. The site is well-optimized for performance, mobile responsiveness, and SEO, with a clean and professional design. Security practices include HTTPS enforcement and use of reCAPTCHA, but lack explicit security headers and published security policies. The security posture is solid but could be improved by adding formal privacy and cookie policies, incident response information, and vulnerability disclosure mechanisms. The absence of WHOIS data for the domain is a concern, suggesting either recent registration or privacy protection, which slightly reduces trustworthiness. Overall, the website is professional and trustworthy but would benefit from enhanced transparency and compliance documentation.

30
35
2
75
57
60
100
webdesignmarketingtechconversiontrackingseoanalytics+2 more
WebflowGoogle Tag ManagerGoogle Analytics (GA4)jQuery+10
2025-11-01T15:50:57.477Z
broadcastmed.com favicon

Conexiant

broadcastmed.com

63
HealthcareN/amediumMEDIUM

Conexiant is a well-established healthcare content and education platform, founded in 2001, positioning itself as a leading global destination for trusted clinical content and healthcare education. The website targets healthcare professionals and organizations, offering a broad library of educational resources and audience engagement services. Technically, the site employs a modern technology stack including Bootstrap, Google Tag Manager, Matomo, Hotjar, Microsoft Clarity, and Cookiebot for analytics and privacy compliance. Hosting appears to be on Amazon AWS infrastructure, with a CMS likely based on Umbraco. The website demonstrates good mobile optimization and SEO practices, though accessibility could be improved. Security posture is solid with HTTPS enforced and domain status protections, but DNSSEC is not enabled and no explicit security or incident response policies are published. Privacy compliance is strong with a comprehensive cookie consent mechanism and GDPR-aligned privacy policy. However, contact information and terms of service are not clearly presented, which could impact user trust and legal compliance. Overall, the website is professional, trustworthy, and safe for general audiences.

15
83
17
75
57
80
100
healthcareclinicalcontenteducationanalyticscookieconsent+1 more
Google Tag ManagerMatomo AnalyticsHotjarMicrosoft Clarity+4

Partner Domains:

broadcastmed.com
partner
physicianresources.baptisthealth.net
partner

+1 more partners

2025-11-01T15:50:32.396Z
S

Sihlcity

sihlcity.ch

69
RetailSwitzerlandlargeMEDIUM

Sihlcity is a prominent urban entertainment and shopping center located in Zurich, Switzerland. The website presents a well-structured digital presence with a focus on retail, dining, and entertainment services targeting the general public and visitors in Zurich. The business model revolves around providing a comprehensive shopping and leisure experience in a large-scale urban environment. The site is professionally designed with consistent branding and good content quality, supporting its market position as a major retail hub. Technically, the website leverages modern JavaScript frameworks, notably Vue.js, and is managed via Magnolia CMS. It integrates Cookiebot for cookie consent management and Google Tag Manager for analytics, indicating a moderate level of digital maturity. The site is mobile-optimized and performs moderately well, with good SEO practices observed. From a security perspective, the website enforces HTTPS and implements cookie consent mechanisms, but lacks explicit security headers and published security policies such as incident response or vulnerability disclosure. No critical vulnerabilities or suspicious content were detected. Privacy compliance is basic, with no visible privacy policy or terms of service on the homepage, which is a notable gap. Overall, the website is trustworthy and professional, with a solid business credibility score. Strategic improvements in privacy policy publication, security header implementation, and incident response transparency would enhance the security posture and compliance standing.

30
83
25
85
72
75
100
shoppingcenterretailentertainmentzurichurbancenter
JavaScriptVue.js (implied by .vue components and hydration)CookiebotGoogle Tag Manager+1
2025-11-01T15:32:42.793Z
zukunft-wettingen.ch favicon

Gemeinde Wettingen

zukunft-wettingen.ch

54
GovernmentSwitzerlandmediumMEDIUM

Zukunft Wettingen is the official municipal website for the community of Wettingen in the canton of Aargau, Switzerland. It serves as a transparent platform to inform residents and stakeholders about ongoing and upcoming community projects aimed at sustainable development and maintaining the quality of life. The site emphasizes proactive communication and engagement with its audience, primarily local residents and interested parties. The business model is centered on providing accessible, clear information about municipal initiatives and fostering community involvement. Technically, the website is built on the TYPO3 CMS platform, a reputable open-source content management system. It integrates modern web technologies including embedded Vimeo videos and Google Analytics via Google Tag Manager for performance and user behavior insights. The site is mobile-optimized, accessible, and SEO-friendly, with a moderate performance profile. Cookie consent is implemented with an opt-in mechanism, reflecting good privacy practices. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms, but lacks publicly available formal security policies or incident response contacts. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data aligns well with the municipal identity, confirming legitimacy and trustworthiness. Overall, the site demonstrates a solid security posture with room for improvement in formal security documentation and headers. The overall risk assessment is low, with the site presenting a trustworthy, professional, and privacy-conscious presence. Strategic recommendations include publishing a security policy, adding incident response contacts, enhancing security headers, and continuous monitoring of third-party scripts to maintain security and compliance standards.

35
68
2
65
72
85
20
governmentmunicipalitycommunityprojectstransparency+3 more
TYPO3 CMSVimeo (video embedding)Google Tag ManagerGoogle Analytics

Partner Domains:

wettingen.ch
partner
bahnhofquartier-wettingen.ch
partner

+1 more partners

2025-11-01T15:31:57.492Z
karriere-wettingen.ch favicon

Gemeinde Wettingen

karriere-wettingen.ch

54
GovernmentSwitzerlandmediumMEDIUM

The website karriere-wettingen.ch serves as the official career portal for the municipal government of Wettingen, Switzerland. It provides job listings, apprenticeship opportunities, benefits information, and insights into the community and its workforce. The site targets job seekers and residents interested in municipal employment and training. The business model is centered on public sector employment and community service, positioning the municipality as a regional employer with a focus on service quality and workforce development. Technically, the website is built on TYPO3 CMS, a robust open-source content management system, and integrates Google Analytics and Google Tag Manager for visitor analytics. The site employs a modern cookie consent mechanism compliant with GDPR, ensuring user privacy and transparency. The design is responsive and accessible, with good SEO and navigation clarity, supporting a positive user experience. From a security perspective, the site enforces HTTPS and uses cookie consent opt-in mechanisms, but lacks explicit published security policies, incident response contacts, or vulnerability disclosure information. No critical vulnerabilities or exposed sensitive data were detected. The WHOIS data is privacy protected, which is reasonable for a municipal site, and no suspicious patterns were found. Overall, the security posture is solid but could be improved by publishing formal security and incident response policies. The overall risk assessment is low, with the site demonstrating professionalism, compliance, and trustworthiness. Strategic recommendations include enhancing transparency around security policies, incident response, and vulnerability disclosure to further strengthen user trust and security maturity.

35
73
2
65
72
85
20
governmentcareerseducationmunicipalityjobs+3 more
TYPO3 CMSGoogle Tag ManagerGoogle AnalyticsDP Wired Cookie Consent
2025-11-01T15:31:46.839Z
ecocampus.global favicon

Foundation for Environmental Education

ecocampus.global

62
EducationDenmarkmediumMEDIUM

EcoCampus is a non-profit environmental education initiative operated by the Foundation for Environmental Education, focused on empowering students globally to lead sustainability efforts. The website promotes international conferences, educational programs, and research collaborations, positioning itself as a key player in environmental education. The business model centers on education, community engagement, and sustainability advocacy, targeting students, educators, and environmental professionals worldwide. The organization maintains a consistent brand presence and leverages partnerships with related environmental programs to enhance its reach. Technically, the website is built on the Squarespace platform, utilizing modern web technologies including Google Tag Manager for analytics and Typekit for fonts. The site is mobile-optimized with good navigation and SEO practices, though accessibility features are basic. Performance is moderate, typical for CMS-based sites. From a security perspective, the site enforces HTTPS with HSTS, employs standard security headers, and avoids exposing sensitive data. However, it lacks a published security policy, incident response information, and vulnerability disclosure mechanisms such as security.txt. Privacy compliance is well addressed with GDPR and cookie policies present and consent mechanisms implemented. Overall, the website demonstrates a strong and trustworthy presence with a good security posture and privacy compliance. The lack of detailed WHOIS data is mitigated by consistent business information and domain update recency. Strategic recommendations include enhancing security transparency, adding vulnerability disclosure, and improving accessibility to further strengthen trust and compliance.

50
50
17
60
62
75
100
environmenteducationsustainabilitynon-profitconference+1 more
Squarespace CMSjQueryGoogle Tag ManagerTypekit Fonts+1

Partner Domains:

fee.global
parent
blueflag.global
partner

+3 more partners

2025-11-01T15:31:26.763Z
hopin.com favicon

RingCentral Events (formerly Hopin)

hopin.com

69
TechnologyUnited StatesenterpriseMEDIUM

RingCentral Events, formerly known as Hopin, is a leading SaaS platform specializing in virtual events and webinars. The company offers a comprehensive suite of services including custom branding, engagement features, virtual event venues, and high-quality streaming capabilities. Positioned strongly in the technology sector, RingCentral Events targets businesses and marketing teams seeking to create engaging online event experiences. The platform benefits from RingCentral's acquisition, enhancing its market position and expanding its product ecosystem with subsidiaries like Session and StreamYard. Technically, the website is built on modern web technologies including Webflow CMS, Google Tag Manager, and various JavaScript libraries such as Swiper.js and AOS for animations. Hosting and DNS services are managed via Cloudflare, ensuring fast performance and reliable uptime. The site is mobile-optimized with good accessibility and SEO practices, providing an excellent user experience. From a security perspective, the website enforces HTTPS and employs domain status protections to prevent unauthorized changes. However, DNSSEC is not enabled, and there is no visible security policy or incident response contact information published. Tracking scripts from Google and LinkedIn are present without an explicit cookie consent mechanism, indicating room for improvement in privacy compliance. Overall, the website demonstrates high professionalism, trustworthiness, and business credibility. The domain registration data aligns well with the company's history and branding, supporting legitimacy. Strategic recommendations include enabling DNSSEC, publishing security and incident response policies, and implementing a clear cookie consent banner to enhance compliance and user trust.

60
53
2
100
57
90
100
virtualeventswebinarseventplatformringcentralhopin+3 more
Google Tag ManagerjQuerySwiper.jsAOS (Animate On Scroll)+3

Partner Domains:

ringcentral.com
parent
session.com
subsidiary

+1 more partners

2025-11-01T15:30:43.667Z
leaps.org favicon

Upworthy

leaps.org

70
MediaN/amediumMEDIUM

Upworthy is a media company focused on sharing positive and uplifting stories that inspire a general audience. The website positions itself as a niche media outlet emphasizing heartwarming and thought-provoking content. Its business model revolves around content publishing supported by advertising and affiliate marketing, particularly through partnerships with ad networks like AdThrive and Amazon Affiliates. The site maintains a consistent brand presence across multiple social media platforms, enhancing its reach and engagement. Technically, Upworthy employs a modern JavaScript-based infrastructure with integrations of Google Analytics, Google Tag Manager, and ad-serving technologies. The site uses the RebelMouse CMS platform, which supports dynamic content delivery and advertising management. Performance and mobile optimization are good, though accessibility features are basic. SEO practices are well implemented with proper meta tags and structured data. From a security perspective, the site enforces HTTPS and uses a consent management platform for cookie compliance. However, some security headers such as Content-Security-Policy and X-Frame-Options are not explicitly present, indicating room for improvement. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is partial, with cookie consent mechanisms present but no explicit privacy policy found in the analyzed content. Overall, the website is professionally designed and trustworthy in content and user experience. However, the WHOIS data is missing or indicates the domain is unregistered, which is inconsistent with the active website presence. This discrepancy warrants further investigation to confirm domain legitimacy. Strategic recommendations include enhancing security headers, publishing a clear privacy policy, and verifying domain registration details to improve trust and compliance.

65
70
17
75
82
75
100
medianewspositivestoriesupliftingadvertising+1 more
JavaScriptGoogle AnalyticsGoogle Tag ManagerAdThrive Ads+3
2025-11-01T15:30:23.602Z
illuminagenomicsforum.com favicon

Illumina

illuminagenomicsforum.com

11
HealthcareUnited StatesenterpriseCRITICAL

Illumina, Inc. is a leading enterprise in the genomics and healthcare technology sector, specializing in genomic sequencing and precision medicine solutions. The website analyzed promotes a genomics forum event, targeting healthcare professionals, researchers, and industry leaders. Illumina holds a strong market position with a comprehensive portfolio of genomic technologies and services. The website content is professionally curated, with clear branding and a focus on industry events and innovation in healthcare. Technically, the website employs modern web technologies including Adobe Experience Manager as CMS, Bootstrap 4 framework, and integrates marketing and analytics tools such as Google Tag Manager and Adobe Launch. The site is mobile optimized, accessible, and SEO friendly, reflecting a mature digital infrastructure. Performance is moderate, with room for optimization. From a security perspective, the site enforces HTTPS, uses standard security headers, and implements cookie consent mechanisms compliant with GDPR. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not publicly available, representing areas for improvement. The WHOIS data is privacy protected, which is justified for a large healthcare technology company. Overall, Illumina's website demonstrates a high level of professionalism, security, and compliance suitable for an enterprise in the healthcare technology domain. Strategic recommendations include publishing detailed security policies, incident response information, and vulnerability disclosure to enhance trust and security posture.

-
-
-
-
-
-
-
genomicshealthcareconferenceprecisionmedicinetechnology+1 more
JavaScriptjQueryAdobe LaunchGoogle Tag Manager+1
2025-11-01T15:30:13.536Z
xpeer.app favicon

Xpeer Medical education

xpeer.app

50
HealthcareSpainmediumMEDIUM

Xpeer Medical education is a Spain-based company providing accredited medical education videos accessible globally through a mobile app and online platform. It holds unique accreditation by the European Union of Medical Specialists (UEMS), offering free courses in multiple languages and specialties to healthcare professionals worldwide. The platform supports continuing medical education (CME/CPD) credits and serves a community of over 100,000 users across 40 countries. The business model includes free access for individuals and tailored business solutions for organizations seeking to distribute accredited content. Technically, the website is built on WordPress with Elementor, leveraging modern analytics tools such as Google Analytics and PostHog, and implements Google reCAPTCHA Enterprise for bot protection. The site is mobile-optimized, SEO-friendly, and includes cookie consent mechanisms compliant with GDPR. Performance is moderate with good accessibility and professional design. From a security perspective, the site enforces HTTPS, uses multiple security headers, and avoids exposing sensitive data. However, it lacks a dedicated security policy and incident response contact information, and does not publish a vulnerability disclosure program. Overall, the security posture is strong but could be enhanced with additional transparency and formal policies. The overall risk assessment is low, with no signs of malicious activity or vulnerabilities. Strategic recommendations include publishing a security policy, establishing incident response contacts, and implementing a vulnerability disclosure program to further enhance trust and compliance.

15
58
17
85
52
85
-
medicaleducationhealthcareaccreditationcontinuingmedicaleducationuems+2 more
WordPressElementorGoogle Tag ManagerGoogle Analytics+3

Partner Domains:

landing.xpeer.app
service
2025-11-01T15:29:53.490Z
A

American Association for the Advancement of Science (AAAS)

science.org

71
EducationUnited StatesenterpriseMEDIUM

The website www.science.org is the official online presence of the American Association for the Advancement of Science (AAAS), a leading global scientific publisher and association. It offers peer-reviewed journals, scientific news, expert commentary, and career resources targeted at researchers, academics, and science professionals. The site supports a subscription and membership business model, providing exclusive content and community access to members. The brand is well-established with consistent and professional presentation, reflecting its enterprise-level stature in the education and media sectors. Technically, the site employs a modern technology stack including JavaScript frameworks, Google Tag Manager, Adobe DTM, and Cloudflare Insights for performance and analytics. It is hosted likely behind Cloudflare, ensuring fast loading and robust security. The site is mobile-optimized, accessible, and SEO-friendly, with structured data enhancing search engine understanding. From a security perspective, the site enforces HTTPS, implements multiple security headers, and uses cookie consent mechanisms aligned with GDPR compliance. No critical vulnerabilities or exposed sensitive data were detected. However, explicit security policies and incident response information are not publicly detailed, representing an area for improvement. Overall, the website demonstrates a strong security posture, excellent content quality, and good privacy compliance. The lack of WHOIS data is attributed to privacy protection and does not detract from the site's legitimacy given its well-known institutional backing. Strategic recommendations include publishing detailed security policies, vulnerability disclosure mechanisms, and enhancing security contact information to further strengthen trust and compliance.

65
100
47
40
57
70
100
scienceacademicresearchjournalsaaas+3 more
JavaScriptReact (likely)Google Tag ManagerAdobe DTM+4

Partner Domains:

promo.aaas.org
partner
spj.science.org
partner
2025-11-01T15:29:48.477Z
schule-baden.ch favicon

Volksschule Baden

schule-baden.ch

45
EducationSwitzerlandmediumHIGH

Volksschule Baden is a public educational institution serving the Baden community in Switzerland, providing comprehensive kindergarten, primary, and secondary education services. The website is professionally designed using TYPO3 CMS and offers detailed information about school organization, educational offers, agendas, and contact details. The target audience includes parents, students, educators, and local residents. The institution holds a stable market position as a local government education provider with key services including school social work, youth projects, and extracurricular activities. Technically, the website employs a modern CMS (TYPO3) and integrates Google Analytics and Google Tag Manager for user tracking. The site is mobile-optimized with good navigation and design quality. However, it lacks visible privacy and cookie policies and does not implement a consent mechanism, which impacts privacy compliance. Security posture is good with HTTPS enforced and secure form handling, but no advanced security headers or vulnerability disclosure policies are present. Overall, the website is trustworthy and professionally maintained, with clear contact information and consistent branding. The absence of privacy and cookie policies and security headers are notable gaps. There are no signs of malicious content or blocking mechanisms, and the domain registration data aligns well with the website's public education purpose. Strategic recommendations include implementing comprehensive privacy and cookie policies with consent mechanisms, adding security headers, publishing a vulnerability disclosure policy, and enhancing accessibility features to improve compliance and security posture.

35
35
2
70
62
75
-
educationpublicschooltypo3switzerlandvolksschule+1 more
TYPO3 CMSGoogle AnalyticsGoogle Tag ManagerFoundation CSS framework+2
2025-11-01T15:28:42.871Z
carteblanche.ch favicon

Tamedia AG

carteblanche.ch

61
MediaSwitzerlandlargeMEDIUM

The website www.carteblanche.ch serves as a customer loyalty platform for subscribers of Tamedia AG's newspapers and magazines, offering exclusive discounts, contests, and cultural event benefits. It is well integrated into the Tamedia media ecosystem, reflecting a strong market position in the Swiss media sector. The site targets subscribers interested in cultural, sports, and travel offers, leveraging a digital customer card model to enhance subscriber engagement. Technically, the site is built on modern web technologies including Next.js and React, supported by a robust content management system (UnityCMS). It employs industry-standard analytics and advertising tools such as Google Analytics, DoubleClick, and OneTrust for cookie consent, ensuring compliance and performance. The site is mobile-optimized and accessible, with good SEO practices. From a security perspective, the website enforces HTTPS, uses multiple security headers, and integrates CAPTCHA on contact forms to mitigate abuse. While no explicit security policy or incident response contacts are published, the overall security posture is strong with no evident vulnerabilities. Privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanism. Overall, the website is professional, trustworthy, and aligned with the business identity of Tamedia AG. It demonstrates a mature digital presence with good security and privacy practices, supporting its role as a customer engagement platform within the media industry.

-
68
17
60
82
75
100
mediacustomerloyaltyeventsdiscountsculture+2 more
ReactNext.jsJavaScriptOneTrust Cookie Consent+8

Partner Domains:

abo-digital.carteblanche.ch
service
www.carteb.ch
partner
2025-11-01T15:27:32.520Z
pentagen.cz favicon

PentaGen s.r.o.

pentagen.cz

56
HealthcareCzech RepublicsmallMEDIUM

PentaGen s.r.o. is a specialized Czech company founded in 2006, focused on the supply and distribution of products for laboratory diagnostics and in vitro fertilization (IVF). The company targets laboratories, medical professionals, and IVF clinics primarily in the Czech Republic and Slovakia. Their business model is B2B distribution of specialized medical and genetic diagnostic products, supported by technical services and product expertise. The website reflects a professional and consistent brand image with clear navigation and relevant content for their niche market. Technically, the website employs modern JavaScript frameworks such as Vue.js and uses Google Tag Manager for analytics. It is hosted on Czech hosting infrastructure (Forpsi) and shows good mobile optimization and SEO practices. The site uses HTTPS with strong SSL configuration and implements cookie consent mechanisms aligned with GDPR requirements. However, explicit security headers and a published security policy are absent. From a security perspective, the site demonstrates good practices including secure forms with captcha and GDPR consent, no exposed sensitive data, and minimal user tracking. The absence of a vulnerability disclosure policy or incident response contact limits transparency in security management. No WAF or blocking mechanisms were detected, and the WHOIS data is consistent with the business claims, indicating a trustworthy domain. Overall, the website scores well in content quality, technical implementation, security posture, privacy compliance, and business credibility. Recommendations include adding security headers, publishing a security policy, and establishing a vulnerability disclosure channel to enhance trust and security posture further.

85
40
2
90
52
80
20
healthcarelaboratorydiagnosticsivfmedicalsuppliesgenetics+1 more
JavaScriptVue.jsGoogle Tag ManagerSwiper.js+1
2025-11-01T15:26:02.267Z
medplus.cz favicon

Medplus

medplus.cz

71
HealthcareCzech RepublicmediumMEDIUM

Medplus.cz is a Czech Republic-based e-commerce platform specializing in healthcare and dental supplies. The website offers a broad catalog of over 6,390 products catering to both specialists and the general public, supported by expert advice and customer service via dedicated phone lines. The business model focuses on direct online sales with benefits such as free shipping over a certain order value and customer registration advantages. The site is well-positioned in the Czech healthcare supply market with a medium-sized operational scale. Technically, the website employs modern web technologies including Google Tag Manager, Microsoft Clarity, and Persoo personalization tools, indicating a mature digital infrastructure. The site is mobile-optimized with good SEO practices and uses secure HTTPS connections with appropriate security headers. The presence of secure login forms and cookie consent mechanisms reflects attention to privacy and security compliance. From a security perspective, Medplus.cz demonstrates a solid posture with HTTPS enforcement, security headers, and no visible vulnerabilities in the HTML content. However, the absence of a publicly available security policy or vulnerability disclosure page suggests room for improvement in transparency and incident response readiness. The WHOIS data is unavailable, which limits domain trust assessment, but the professional website presentation and business information mitigate concerns. Overall, Medplus.cz is a trustworthy and professionally managed e-commerce site with good technical and security standards. Strategic recommendations include publishing a formal security policy, implementing a vulnerability disclosure program, and enhancing accessibility features to further strengthen compliance and user trust.

80
73
2
70
72
85
100
healthcaredentalsuppliese-commercemedicalequipmentczechrepublic
Google Tag ManagerMicrosoft ClaritySmartsupp ChatHeureka Widget+2
2025-11-01T15:25:57.252Z
fee.global favicon

Foundation for Environmental Education

fee.global

63
EducationDenmarkmediumMEDIUM

The Foundation for Environmental Education (FEE) is a well-established non-profit organization focused on environmental education and sustainable development with a global presence spanning over 110 member organizations in 85 countries. Their core activities include managing internationally recognized sustainability certification programs such as Blue Flag and Green Key, youth empowerment initiatives like Eco-Schools and Young Reporters for the Environment, and global campaigns addressing climate action and ecosystem restoration. The website reflects a professional and consistent brand image aligned with their mission. Technically, the website is built on the Squarespace platform, leveraging modern web technologies including Google Tag Manager and Mailchimp for analytics and marketing. The site is mobile-optimized and performs moderately well, though accessibility features could be enhanced. Security posture is strong with HTTPS enforced and HSTS enabled, but the absence of visible privacy and cookie policies indicates room for improvement in compliance. Overall, the security posture is solid with no evident vulnerabilities or exposed sensitive data. However, the lack of explicit privacy and cookie policies, as well as missing contact information for security incidents, represents compliance and transparency gaps. The domain WHOIS data is privacy protected, which is common for non-profits, and no suspicious patterns were detected. The website is safe for general audiences and free from adult or questionable content. Strategically, the organization should prioritize publishing comprehensive privacy and cookie policies with consent mechanisms, establish a vulnerability disclosure process, and improve accessibility to enhance trust and compliance. These steps will strengthen their security culture and align with global data protection standards.

35
50
25
75
62
80
100
environmenteducationsustainabilitynon-profitenvironmental-education+2 more
Squarespace CMSGoogle Tag ManagerMailchimpTypekit Fonts+3

Partner Domains:

blueflag.global
partner
greenkey.global
partner

+3 more partners

2025-11-01T14:59:24.249Z
heks.ch favicon

HEKS - Hilfswerk der Evangelisch-reformierten Kirche Schweiz

heks.ch

64
Non-profitSwitzerlandlargeMEDIUM

HEKS is a well-established Swiss non-profit organization affiliated with the Evangelical Reformed Church of Switzerland. It focuses on humanitarian aid, development projects, and social integration, with key thematic areas including climate justice, land and food rights, migration, and inclusion. The organization targets a broad audience including donors, partners, and beneficiaries, operating both nationally and internationally. The website reflects a mature digital presence with multilingual support and clear calls to action for donations and engagement. Technically, the website is built on Drupal 10 with Commerce 2, integrating modern analytics and marketing tools such as Google Tag Manager, Facebook Pixel, and Crazy Egg. The site is mobile-optimized, accessible, and SEO-friendly, demonstrating good digital maturity. Security measures include HTTPS enforcement and standard security headers, though there is room for improvement in publishing explicit security policies and incident response information. The security posture is solid with no detected vulnerabilities or exposed sensitive data. Privacy compliance is strong, with a comprehensive privacy and cookie policy and consent mechanisms in place. Business credibility is high, supported by transparent contact information, certifications like ZEWO, and trust signals such as a whistleblowing platform and ACT Alliance membership. Overall, HEKS presents a trustworthy, professional, and secure online presence suitable for its non-profit mission. Strategic recommendations include enhancing security transparency and incident response readiness to further strengthen stakeholder confidence.

55
53
2
65
72
80
100
non-profithumanitariancharityclimatejusticemigration+3 more
Drupal 10Commerce 2Google Tag ManagerFacebook Pixel+4
2025-11-01T14:58:19.010Z
museumaargau.ch favicon

Museum Aargau

museumaargau.ch

57
GovernmentSwitzerlandmediumMEDIUM

Museum Aargau is a prominent cultural institution in Switzerland, managing a network of 10 museum locations including castles, monasteries, and Roman heritage sites. It offers a wide range of services such as exhibitions, educational programs, guided tours, and digital access to its collections. The museum holds a strong market position as one of the largest historical museums in the country, targeting a broad audience interested in history and culture. Technically, the website is built on TYPO3 CMS and leverages modern web technologies including jQuery, Bootstrap, and various multimedia integrations like Wistia for video content. The site is mobile-optimized, accessible, and SEO-friendly, providing a professional and engaging user experience. From a security perspective, the site enforces HTTPS and implements a comprehensive cookie consent mechanism aligned with GDPR requirements. While no critical vulnerabilities were detected, there is room for improvement in security headers and formal security policies. Analytics tools such as Google Analytics and Hotjar are used with appropriate privacy controls. Overall, the website demonstrates a mature digital presence with strong business credibility and compliance posture. The risk level is low, with recommendations focusing on enhancing security policies and headers to further strengthen the security posture.

30
88
2
75
72
80
20
museumhistorycultureswitzerlandeducation+3 more
TYPO3 CMSjQueryBootstrapSlick Carousel+6
2025-11-01T14:58:08.987Z