Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 70 of 155|Showing 3451-3500 of 7749
derg.rest favicon

Private by Design, LLC

derg.rest

43
EnergyUnited StatessmallHIGH

The website derg.rest is a personal site representing an aspiring master electrician named Tom Darsonian based in Michigan, USA. The site serves primarily as a personal portfolio or presence with minimal content focused on personal interests and updates. The business is small-scale and newly established, as indicated by the domain registration date in early 2024. The site lacks formal business contact information, privacy policies, and terms of service, which limits its professional and compliance posture. Technically, the site is simple, built with basic HTML and CSS, and uses Cloudflare for DNS services. There is no evidence of a CMS or advanced frameworks. Mobile optimization and accessibility are basic but functional. Performance is moderate with no visible errors or broken elements. However, security measures are minimal; no security headers or DNSSEC are enabled, and HTTPS enforcement is not confirmed from the data provided. From a security perspective, the domain registration is consistent and legitimate with appropriate domain status protections. The absence of privacy and cookie policies, contact information, and security headers reduces the overall security and privacy compliance score. No vulnerabilities or malicious content were detected. The site content is safe for general audiences with no adult or explicit material. Overall, the site scores moderately on AI evaluation, with strengths in business credibility due to consistent WHOIS data and weaknesses in privacy compliance and security posture. Strategic improvements in security headers, privacy policies, and contact information would enhance trust and compliance.

15
35
2
60
52
80
40
personalelectricianmichiganportfoliosmallbusiness
HTML5CSS3Cloudflare DNS
2025-07-27T14:01:54.136Z
jamsharp.net favicon

JamSharp

jamsharp.net

57
TechnologyN/asmallMEDIUM

JamSharp.net is a personal website serving as a blog and project portfolio for the individual or entity known as JamSharp. The site aggregates blog posts, social media links, and open source projects primarily hosted on GitHub. The business model is personal branding and content sharing within the technology sector, targeting a general audience interested in software development and related topics. The website is relatively new, with the domain registered in 2022, and is hosted on Cloudflare with modern web technologies such as SvelteKit, indicating a moderate level of digital maturity. From a technical perspective, the site uses a modern JavaScript framework (SvelteKit) and benefits from Cloudflare's DNS and hosting services, providing good performance and HTTPS security. The site is mobile optimized and has basic accessibility and SEO features. However, it lacks advanced security headers and DNSSEC, which could be improved to enhance security posture. Security-wise, the website enforces HTTPS and has domain transfer protections but lacks published privacy, cookie, or security policies. No forms or data collection mechanisms are present, reducing attack surface but also limiting user engagement features. No vulnerability disclosure or incident response information is provided, which is a gap for security transparency. Overall, the security posture is moderate but could be improved with better policy disclosures and security headers. The overall risk assessment is low given the site's personal and informational nature, but strategic recommendations include enabling DNSSEC, publishing privacy and cookie policies, adding security headers, and establishing a vulnerability disclosure process to improve trust and compliance.

15
35
2
70
75
90
100
personalblogtechnologyopensourceprojectssocialmedia
JavaScriptSvelteKitCloudflare DNS
2025-07-27T14:01:08.267Z
brutecat.com favicon

skull's blog

brutecat.com

59
TechnologyN/asmallMEDIUM

The website brutecat.com is a personal cybersecurity research blog titled "skull's blog" that publishes technical articles focused on hacking techniques, vulnerability disclosures, and security research related to Google and YouTube user data. It targets security researchers, hackers, and tech enthusiasts interested in advanced security topics. The business model is content publishing without commercial or e-commerce elements, positioning it as a niche blog in the cybersecurity domain. Technically, the site is built using modern web technologies including SvelteKit and is hosted on Cloudflare Pages, ensuring fast performance and excellent mobile optimization. The domain is registered with Cloudflare, Inc. with a long 10-year expiry, indicating commitment to the domain. The site uses HTTPS with a good SSL configuration but lacks DNSSEC and security headers, which are recommended for enhanced security. From a security posture perspective, the site enforces HTTPS and has domain transfer protection but lacks published privacy, cookie, or security policies, and no contact or incident response information is provided. Minimal tracking is present via Cloudflare analytics. No vulnerabilities or malware indicators were found, but the absence of DNSSEC and security headers are notable gaps. Overall, brutecat.com is a technically sound, niche cybersecurity blog with good content quality and performance but limited privacy and security policy disclosures. Strategic improvements include adding privacy and cookie policies, enabling DNSSEC, implementing security headers, and publishing incident response contacts to enhance trust and compliance.

30
35
2
70
75
85
100
cybersecuritysecurityresearchtechnicalbloghackinggoogle+2 more
SvelteKitCloudflare PagesCloudflare DNSJavaScript ES Modules
2025-07-27T12:56:11.093Z
T

TwitterDB

twitterdb.com

44
TechnologyN/asmallHIGH

TwitterDB is a small technology project focused on aggregating and providing historical data on Twitter tags and hashtags. The website offers search and statistical analysis of over 96 million unique tags and 20 million hashtags, processing more than 1.8 billion tweets over approximately one year. However, the project is archived and no longer updated due to changes in Twitter's API, with all data frozen as of April 1, 2023. The site targets researchers, social media analysts, and data enthusiasts interested in Twitter trends. Technically, the website is built using Angular 12, hosted by Hetzner Online GmbH, and uses Cloudflare DNS without DNSSEC. The site has moderate performance and basic mobile optimization. SEO and accessibility are basic, with no advanced compliance or security headers detected. No privacy or cookie policies are present, and no contact or incident response information is provided, limiting transparency and compliance. From a security perspective, the site lacks DNSSEC, security headers, and visible incident response contacts. The SSL configuration is unknown but presumed present due to Cloudflare DNS usage. No vulnerabilities or exposed sensitive data were detected in the HTML content. The WHOIS data is consistent and legitimate, with domain registration dating back to 2021, matching the site's operational timeline. Overall, the website scores moderately on business credibility and technical implementation but scores low on privacy compliance and security posture. The absence of privacy policies and contact information, combined with minimal security controls, suggests areas for improvement. The site content is safe for general audiences, with no adult or explicit material detected.

15
35
2
70
72
60
40
twitterstatisticshistorygraphtrends+3 more
Angular 12Google Fonts (Poppins)Cloudflare DNS
2025-07-27T12:55:25.921Z
N

Niko's Webpage

nikolan.net

58
TechnologyN/asmallMEDIUM

The website 'Niko's Webpage' is a personal hobbyist site created by an individual named Niko, focusing on interests such as IT, coding, computing, radio, gaming, and programming projects. The site serves as a personal portfolio and social hub linking to various related hobbyist and friend sites. The domain is very new, registered in August 2024, and consistent with the personal nature of the content. The site does not represent a commercial business entity and lacks formal business information or contact details. Technically, the website is built with basic HTML and CSS, hosted behind Cloudflare DNS but without advanced security headers or CMS frameworks. The site has moderate performance and basic mobile optimization but lacks SEO and accessibility enhancements. No analytics or advertising technologies are detected, indicating minimal tracking or marketing efforts. From a security perspective, the site lacks privacy and cookie policies, security headers, and vulnerability disclosure mechanisms. The domain does not use DNSSEC, and SSL/TLS configuration details are not provided, which may indicate basic or incomplete HTTPS implementation. No forms or data collection points are present, reducing attack surface but also limiting user interaction. Overall, the website is safe for general audiences, with no adult or explicit content. The risk profile is low given the personal nature and limited functionality, but improvements in security posture and privacy compliance are recommended to enhance trust and protection.

30
50
2
70
75
75
100
personaltechnologygamingprogrammingradio+1 more
HTML5CSSCloudflare DNS
2025-07-27T12:54:45.608Z
accomplice.co favicon

Accomplice

accomplice.co

60
TechnologyUnited StatessmallMEDIUM

Accomplice is a specialized venture capital firm and contemporary family office focused on high conviction investments in technology startups. The firm has a strong market position, evidenced by its involvement in the early stages of numerous successful companies such as AngelList, DraftKings, and Patreon. Their business model centers on concentrated, patient investments and includes initiatives like Accomplice Blockchain and the Spearhead operator-angel movement. The website reflects a professional and consistent brand image targeting investors and entrepreneurs in the technology sector. Technically, the website is built on the PageCloud platform, utilizing jQuery and hosted with Cloudflare DNS services. The site is mobile optimized and performs moderately well, though it lacks advanced SEO and accessibility features. The absence of DNSSEC and security headers indicates room for improvement in technical security hardening. From a security perspective, the site uses HTTPS and has domain transfer locks in place, which are positive indicators. However, it lacks visible security policies, incident response information, and vulnerability disclosure mechanisms. No privacy or cookie policies were found, which is a compliance gap. No analytics or tracking scripts were detected, suggesting minimal user tracking. Overall, the website presents a low risk profile with a solid business credibility but requires enhancements in privacy compliance and security best practices to improve trust and regulatory adherence. Strategic recommendations include implementing privacy and cookie policies, enabling DNSSEC, adding security headers, and publishing incident response and vulnerability disclosure information.

45
35
2
75
65
80
100
venturecapitalinvestmenttechnologyfamilyofficeblockchain+1 more
jQueryPageCloud platformCloudflare DNS

Partner Domains:

spearhead.co
partner
accompliceblockchain.co
subsidiary

+3 more partners

2025-07-27T12:50:13.759Z
divriots.com favicon

‹div›RIOTS

divriots.com

9
TechnologyN/asmallCRITICAL

‹div›RIOTS is a small technology company specializing in the development of innovative Figma plugins designed to enhance design workflows. Their product suite includes a variety of plugins that convert HTML, PDFs, images, and other formats into Figma designs, as well as tools for removing backgrounds, upscaling images, and more. The company targets designers and developers who use Figma as their primary design tool. The website reflects a professional and modern digital presence with a focus on showcasing their plugin offerings. Technically, the website is built using modern web technologies including Astro framework, JavaScript, and CSS, with hosting and DNS services provided by Cloudflare and domain registration via Squarespace. The site includes minimal tracking via Fathom Analytics and uses Sendinblue for form submissions. Performance and mobile optimization are good, though accessibility features are basic. From a security perspective, the site uses HTTPS and has domain status protections to prevent unauthorized changes. However, DNSSEC is not enabled, and no security headers or vulnerability disclosure policies are present. Privacy and cookie policies are absent, indicating gaps in compliance with GDPR and related regulations. No direct contact information or incident response contacts are provided. Overall, the website is trustworthy and professional but would benefit from enhanced privacy compliance, security best practices, and clearer contact and policy disclosures to improve user trust and regulatory adherence.

-
-
-
-
-
-
-
figmapluginsdesignsoftwaretechnology
JavaScriptCSSHTMLCloudflare DNS+1
2025-07-27T11:49:01.608Z
sylvie.lol favicon

home - sylvie.lol

sylvie.lol

57
TechnologyN/asmallMEDIUM

Sylvie.lol is a personal portfolio and blog website belonging to Sylvia (aka sylvxa), a full-stack software developer and programming enthusiast. The site serves as a platform to share programming knowledge, open source projects, and personal interests such as speedrunning and cats. It targets a niche audience of developers and tech hobbyists. The website is newly created in 2024 and reflects a small-scale personal brand rather than a corporate entity. Technically, the website uses standard modern web technologies including HTML5, CSS3, and JavaScript, with Cloudflare providing DNS and likely CDN services. The site is well-structured with good mobile optimization and SEO meta tags. However, it lacks advanced frameworks or CMS platforms, indicating a lightweight and custom-built approach. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and security headers such as Content-Security-Policy. There are no visible forms or data collection mechanisms, reducing attack surface but also limiting user interaction. Privacy and cookie policies are absent, which is a compliance gap. No incident response or vulnerability disclosure information is provided. Overall, sylvie.lol is a safe, well-maintained personal website with moderate trustworthiness. To improve, the owner should consider adding privacy and cookie policies, security headers, and contact information to enhance compliance and user trust.

15
50
2
70
75
70
100
personalportfoliosoftwaredevelopmentblogopensource
HTML5CSS3JavaScriptCloudflare DNS
2025-07-27T10:39:20.453Z
lona.moe favicon

Lonaasan

lona.moe

53
TechnologyGermanysmallMEDIUM

Lona.moe is a personal website belonging to Lonaasan, a 22-year-old software engineer from Germany. The site serves as a portfolio and community hub featuring programming projects, blog content, photography, and social links. It targets a general audience interested in cats, blahaj, and programming. The website is small scale, with a niche market position focused on personal branding and community engagement. Technically, the site uses standard web technologies including HTML5, CSS3, and JavaScript, with Cloudflare DNS hosting. The site is mobile optimized and accessible, with good SEO practices. However, DNSSEC is not enabled, and no advanced security headers are detected. The site uses a minimal tracking script (umami) for analytics, indicating a low level of user tracking. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and security headers. There is a potential XSS vulnerability in the citation block due to unsanitized HTML content. No privacy or cookie policies are present, which impacts compliance. The domain registration is privacy protected but consistent with the personal nature of the site. Overall, the security posture is moderate but could be improved with standard best practices. The overall risk is low given the personal and non-commercial nature of the site, but improvements in security headers, privacy policies, and content sanitization are recommended to enhance trust and compliance.

20
50
2
85
72
80
40
personalprogrammingblogcommunitycats+1 more
HTML5CSS3JavaScriptCloudflare DNS
2025-07-27T10:39:15.444Z
funtimes909.xyz favicon

Private by Design, LLC

funtimes909.xyz

61
TechnologyUnited StatessmallMEDIUM

The website funtimes909.xyz is a personal site operated by Amy, an 18-year-old technology and privacy enthusiast. The site serves as a platform to share personal interests, projects, and contact information, targeting a niche audience of tech and privacy advocates. The business model is non-commercial, focusing on hobbyist and community engagement with open source and privacy tools. The domain is registered under a privacy protection service, consistent with the personal and privacy-focused nature of the site. Technically, the site is built with basic HTML and CSS, hosted behind Cloudflare DNS services, and uses HTTPS for secure communication. The site lacks advanced frameworks or CMS and has moderate performance and basic mobile optimization. SEO and accessibility features are minimal but functional. No analytics or tracking scripts are present, reflecting a strong privacy orientation. From a security perspective, the site benefits from HTTPS and domain transfer protections but lacks security headers and formal policies such as privacy or cookie policies. No vulnerability disclosure or incident response information is provided. The absence of these elements suggests room for improvement in security posture and compliance. Overall, the site is safe, trustworthy, and suitable for general audiences. The risk level is low given the personal nature and limited scope of the site. Strategic recommendations include enabling DNSSEC, adding security headers, publishing privacy and cookie policies, and establishing vulnerability disclosure mechanisms to enhance trust and security maturity.

15
50
47
60
75
75
100
technologyprivacyopensourcepersonalblog+1 more
HTML5CSSCloudflare DNS
2025-07-27T10:39:10.432Z
damcraft.de favicon

Private by Design, LLC

damcraft.de

58
TechnologyUnited StatessmallMEDIUM

Lina.sh is a personal website of Lina, an 18-year-old developer from Germany, known for her work exposing wrongful ISP domain blocking in Germany. The site serves as a portfolio, blog, and community hub with donation support and secure communication via PGP. The business model is primarily personal branding and community engagement, targeting developers and privacy-conscious users. The domain is registered under Private by Design, LLC in the US, consistent with the website's privacy-focused ethos. Technically, the site is built with clean HTML and CSS without JavaScript, emphasizing privacy and performance. It uses Cloudflare DNS but lacks DNSSEC. The site is mobile optimized and accessible, with fast performance and basic SEO. No CMS or analytics tools are detected, reflecting a minimalist and privacy-first approach. Security posture is solid with HTTPS enforced and domain status protections, but lacks advanced security headers and incident response information. No privacy or cookie policies are published, representing compliance gaps. No tracking or advertising scripts are present, enhancing user privacy. Overall, the site is trustworthy and professional for a personal developer portfolio, but could improve compliance and security transparency. Strategic recommendations include adding privacy and cookie policies, enabling DNSSEC, publishing security.txt, and enhancing security headers.

40
50
2
100
65
85
40
developerprivacyblogopensourcedonations+2 more
HTML5CSS3No JavaScript (explicitly stated)Cloudflare DNS

Partner Domains:

paypal.com
partner
ko-fi.com
partner

+1 more partners

2025-07-27T10:38:30.351Z
callmebymygender.top favicon

Call me by my gender

callmebymygender.top

54
OtherN/asmallMEDIUM

The website 'Call me by my gender' is a small educational platform focused on promoting respectful and inclusive language regarding gender identity. It provides detailed explanations on why certain terms like “female” or “male” can be problematic and offers alternatives for respectful communication. The site targets a general audience interested in gender inclusivity and language sensitivity. The business model is informational without commercial transactions or services. Technically, the site uses standard web technologies including HTML5, CSS3, JavaScript, and Google Fonts. It is hosted with DNS services provided by Cloudflare and uses Plausible Analytics for privacy-conscious visitor tracking. The site is mobile optimized with good SEO practices but lacks advanced accessibility features. Performance is moderate with no CMS detected. From a security perspective, the site uses HTTPS and has domain transfer protections enabled. However, it lacks DNSSEC and security headers such as Content-Security-Policy or X-Frame-Options, which are recommended for enhanced security. There are no privacy or cookie policies present, representing compliance gaps. The domain registration is recent (2023) and privacy protected, which is reasonable for this type of small educational site. Overall, the website is safe, professional, and trustworthy for its niche educational purpose. Key recommendations include adding privacy and cookie policies, implementing security headers, enabling DNSSEC, and considering a vulnerability disclosure policy to improve security posture and compliance.

15
35
17
60
65
70
100
genderinclusivitylanguagenonbinaryeducation
HTML5CSS3JavaScriptGoogle Fonts+1
2025-07-27T10:35:38.284Z
pronoms.fr favicon

Le collectif du « Conseil du Langage Neutre »

pronoms.fr

30
OtherFrancesmallHIGH

Pronoms.fr is a French-based, volunteer-driven, open-source project focused on promoting inclusive and non-binary language through examples of personal pronouns and neutral language usage. It offers users the ability to create and share personalized pronoun cards, supports multiple languages, and fosters community engagement through social media and a dedicated queer calendar. The project is positioned as a niche educational and social inclusion resource within the LGBTQ+ community and language activism space. Technically, the website is built using modern frameworks such as Nuxt.js and Vue.js, with integration of Shopify for e-commerce functionalities. It leverages Cloudflare for DNS and possibly CDN services, uses Google Fonts and Font Awesome for UI, and employs Plausible Analytics for privacy-respecting visitor tracking. The site is well-optimized for mobile devices, accessible, and SEO-friendly, reflecting a mature digital infrastructure for a small community project. From a security perspective, Pronoms.fr enforces HTTPS, implements key security headers, and avoids exposing sensitive data. However, it lacks a visible cookie consent mechanism and formal security or incident response policies, which are recommended for compliance and transparency. No vulnerabilities or suspicious activities were detected, indicating a strong security posture for its scale. Overall, Pronoms.fr presents a trustworthy, professional, and community-oriented platform with excellent content quality and technical implementation. Strategic improvements in privacy compliance and formal security documentation would further enhance its credibility and user trust.

50
50
50
50
-
50
100
pronounsinclusivelanguagelgbtqnon-binarygenderneutrality+3 more
Nuxt.jsVue.jsShopify Buy SDKCloudflare DNS+4

Partner Domains:

pronouns.page
partner
shop.pronouns.page
partner

+2 more partners

2025-07-27T09:07:34.797Z
pronomen.net favicon

Das „Rat für neutrale Sprache“ Kollektiv

pronomen.net

10
OtherN/asmallCRITICAL

Pronomen.net is a community-driven, multilingual platform dedicated to providing information and resources about non-binary and gender-neutral language, focusing on pronouns and inclusive communication. The website serves a niche audience interested in gender inclusivity and offers tools such as pronoun cards, cultural examples, and a queer calendar. It operates as a non-profit public source project supported by volunteers and offers merchandising to support its activities. Technically, the site is built on modern frameworks like Nuxt.js and Vue.js, hosted with Cloudflare DNS and uses Shopify's Buy SDK for merchandising. The site is well-optimized for mobile and accessibility, with good SEO practices and fast performance. Security-wise, the site enforces HTTPS and has domain transfer protections but lacks DNSSEC and some security headers. Privacy compliance is good with a clear privacy policy and GDPR adherence, though no cookie consent mechanism is present despite using Plausible Analytics. Contact information is available via multiple company emails, and the project maintains an active presence on Mastodon, Bluesky, Discord, and GitLab. Overall, the site is trustworthy, professional, and serves its community well, though it could improve security headers and cookie consent to enhance compliance and security posture.

-
-
-
-
-
-
-
pronounsgender-neutrallanguagenon-binarylgbtqcommunity+2 more
Nuxt.jsVue.jsCloudflare DNSShopify Buy SDK

Partner Domains:

pronouns.page
partner
shop.pronouns.page
partner

+3 more partners

2025-07-27T09:07:14.642Z
kweak.org favicon

Kweak.org - Main

kweak.org

63
OtherIcelandsmallMEDIUM

Kweak.org is a personal website operated by an individual known as Shakalitsa. The site hosts a variety of content including file storage, media such as music and videos, software downloads for Android and Windows, pictures, Minecraft skins, and community features like a guest book and blog. The website targets general internet users interested in personal and miscellaneous content sharing. The business model is non-commercial and primarily serves as a personal project or hobby site. The domain is relatively new, registered in late 2022, and uses privacy protection services, which is consistent with the nature of the site. Technically, the website uses standard HTML, CSS, and JavaScript with Cloudflare DNS services and NameCheap as the registrar. The site is moderately optimized with basic mobile responsiveness and accessibility. No advanced frameworks or CMS platforms are detected. Performance is moderate with no significant technical issues noted. However, the site lacks modern security headers and DNSSEC is not enabled, which could be improved. From a security perspective, the site uses HTTPS and has domain transfer protections enabled. There are no visible vulnerabilities or exposed sensitive data. However, the absence of privacy and cookie policies, security headers, and contact information reduces the overall security posture and compliance level. No incident response or vulnerability disclosure information is provided. The site does not use analytics or tracking technologies, which limits privacy concerns but also reduces business intelligence capabilities. Overall, the website is a small-scale personal project with basic technical and security implementations. It is safe for general audiences with no adult or explicit content. Strategic recommendations include adding privacy and cookie policies, implementing security headers, enabling DNSSEC, and providing contact and incident response information to improve trust and compliance.

50
50
17
80
65
80
100
personalfilestoragemediasoftwareblog+1 more
HTML5CSS3JavaScriptCloudflare DNS
2025-07-27T09:06:24.203Z
motionarium.top favicon

motionarium.

motionarium.top

55
OtherRussiasmallMEDIUM

The website motionarium.top is a personal hobby portfolio site created by an individual named Брокля from Russia, focusing on UI/UX design and website layout as a hobby. The site showcases various versions of personal projects and links to social media and code repositories. It is a small-scale, non-commercial site with no evident business operations or commercial intent. Technically, the site is a simple static HTML/CSS/JavaScript implementation hosted with DNS services via Cloudflare and registered through Dynadot LLC with privacy protection. The site lacks advanced frameworks or CMS and shows basic mobile optimization and accessibility. No analytics or advertising technologies are detected, indicating minimal tracking and data collection. From a security perspective, the site does not present advanced security features such as security headers or DNSSEC, and no privacy or cookie policies are provided. The domain is privacy protected, which is appropriate for a personal hobby site. No vulnerabilities or malicious content are detected, but the security posture is basic. Overall, the site is safe and functional as a personal portfolio but lacks professional business and compliance features. Strategic recommendations include adding privacy and cookie policies, improving security headers and HTTPS enforcement, and providing contact information to enhance trust and compliance.

25
35
2
85
65
70
100
personalportfoliouiuxhobbyrussian+1 more
HTML5CSSJavaScriptCloudflare DNS
2025-07-27T09:06:14.169Z
D

Daniel Myslivets

myslivets.com

58
TechnologyN/asmallMEDIUM

The website myslivets.com serves as a personal portfolio and content hub for Daniel Myslivets, a young content creator focused on technology, photography, and digital media. The site highlights his YouTube channel, photography hobby, short video content, and contributions to open-source social network design. The business model is personal branding with a niche audience primarily interested in technology and creative content. The website is small-scale and consistent with a personal brand rather than a corporate entity. Technically, the site is built with standard HTML, CSS, and JavaScript, leveraging Cloudflare for DNS and analytics. The site performs well with good mobile optimization and basic SEO. However, it lacks advanced security headers and privacy compliance mechanisms such as privacy and cookie policies. Analytics usage is moderate with custom and Cloudflare tracking scripts but without clear user consent. From a security perspective, the site uses HTTPS and has domain status protections but does not enable DNSSEC or implement security headers. There are no visible vulnerabilities or exposed sensitive data. The absence of privacy policies and cookie consent represents a compliance gap. The WHOIS data is consistent with the website content, showing a recently registered domain appropriate for the personal brand timeline. Overall, the site is safe, professional, and trustworthy for general audiences but would benefit from improved privacy compliance and enhanced security headers. Strategic recommendations include enabling DNSSEC, adding privacy and cookie policies, implementing security headers, and publishing a security.txt file to improve transparency and security posture.

15
35
2
80
75
85
100
personaltechnologycontent-creatorphotographyyoutube+1 more
HTML5CSSJavaScriptCloudflare DNS+2
2025-07-27T09:06:09.047Z
P

Private by Design, LLC

bam.moe

55
OtherUnited StatessmallMEDIUM

The website bam.moe is a minimalistic site with no substantive content or business information. The domain is registered through a privacy protection service, Private by Design, LLC, based in the US, with a creation date in 2020. The site appears to be static and decorative, featuring multiple CSS stylesheets and SVG graphics but lacking textual content, contact details, or any business description. There are no forms, external links, or social media profiles present. The technical infrastructure includes Cloudflare DNS but no DNSSEC or security headers are detected from the provided data. No HTTPS status was confirmed, and no analytics or tracking scripts are present. From a security perspective, the site lacks fundamental security best practices such as visible HTTPS enforcement, security headers, and privacy or cookie policies. The absence of contact information and incident response channels further reduces transparency and trustworthiness. The domain registration privacy protection is common for small or personal projects but without business context, it lowers legitimacy. Overall, the site scores low on content quality, technical implementation, security posture, privacy compliance, and business credibility. Strategically, the site requires significant improvements in content provision, transparency, and security to be considered trustworthy or business-ready. Adding clear business information, contact details, privacy and cookie policies, and implementing HTTPS with security headers would greatly enhance its posture. Without these, the site remains minimal and of limited business value.

15
50
2
70
95
85
100
minimalprivacy-protectedstaticdecorative
Cloudflare DNS
2025-07-27T08:00:45.207Z
L

LavaTech

a3.pm

52
TechnologyN/asmallMEDIUM

LavaTech operates a public XMPP server under the domain a3.pm, providing a compliant and moderated messaging platform with features such as multi-user chat, OMEMO encryption, and audio/video call support. The service targets XMPP users seeking a reliable and privacy-conscious communication server. The business model is based on free public access with controlled registration to maintain moderation and service quality. The domain is stable and appropriately aged, supporting the legitimacy of the service. Technically, the website uses ejabberd 23.04 as the XMPP server software and Cloudflare for DNS services, indicating a modern and reliable infrastructure. The presence of converse.js allows browser-based chat access. However, the website's technical implementation is basic with limited SEO, accessibility, and mobile optimization features. No CMS or advanced frameworks are detected. From a security perspective, the site demonstrates good practices such as disabling in-band registration to reduce abuse and providing clear contact channels for complaints and support. However, it lacks formal security policies, vulnerability disclosure mechanisms, and explicit security headers, which are areas for improvement. Privacy compliance is weak due to the absence of privacy and cookie policies. Overall, the website is trustworthy and serves a niche community effectively but would benefit from enhanced security and privacy documentation, improved technical features, and formalized policies to strengthen compliance and user trust.

15
50
2
70
95
70
40
xmppejabberdmessagingcomplianceopensource+2 more
ejabberd 23.04Cloudflare DNSconverse.js
2025-07-27T07:59:49.974Z
mcsrvstat.us favicon

Anders G. Jørgensen

mcsrvstat.us

68
TechnologyDenmarksmallMEDIUM

Minecraft Server Status is a niche technology service providing quick and reliable information about Minecraft servers, supporting both Java and Bedrock editions. The website is operated by Anders G. Jørgensen, based in Denmark, with a domain registered since 2015, indicating a stable and mature service. The business model is ad-free and supported by donations, targeting Minecraft players and server administrators seeking server status information and API access. Technically, the website uses modern frontend technologies including Bootstrap 5 and Cloudflare for DNS and CDN services, ensuring good performance, mobile optimization, and accessibility. The site is well-structured with clear navigation and a professional design, although it lacks some compliance documentation such as privacy and cookie policies. From a security perspective, the domain benefits from Cloudflare's infrastructure and has domain transfer protections enabled. However, DNSSEC is not enabled, and no explicit security headers were detected in the provided data. There is no published incident response or vulnerability disclosure information, which could be improved to enhance trust and compliance. Overall, the website is functional, trustworthy, and well-positioned within its niche but would benefit from enhanced privacy compliance, security headers, and contact transparency to improve its security posture and user trust.

85
35
2
85
75
85
100
minecraftserverstatusgamingtechnologyapi
Bootstrap 5.3.3Bootstrap Icons 1.11.3Cloudflare DNSJavaScript
2025-07-27T07:58:09.366Z
A

aagaming

aagaming.me

50
TechnologyIcelandsmallMEDIUM

The website aagaming.me is a personal hobby developer portfolio primarily focused on reverse engineering projects. The site owner, known as 'aa', showcases various projects and references work on decky.xyz, indicating a niche presence within the developer and reverse engineering community. The business model is informal and hobbyist, with no commercial or enterprise scale operations evident. The site targets hobby developers and technology enthusiasts interested in reverse engineering and software development. Technically, the website is built using the Astro framework and utilizes Cloudflare for DNS services. The site demonstrates moderate performance and good mobile optimization but lacks advanced SEO and accessibility features. There are no detected CMS platforms or third-party analytics or advertising tools, indicating a lightweight and privacy-conscious setup. From a security perspective, the site lacks critical security headers and does not enable DNSSEC, which could improve domain security. No privacy or cookie policies are present, and no contact or incident response information is provided, limiting compliance with GDPR and other privacy regulations. The domain is privacy protected via a service in Iceland, which is consistent with the personal nature of the site. Overall, the security posture is basic with room for improvement. The overall risk is low given the non-commercial nature and safe content, but the site would benefit from adding privacy policies, security headers, and contact information to enhance trust and compliance. Strategic recommendations include enabling DNSSEC, implementing security headers, publishing privacy and cookie policies, and providing clear contact and incident response details.

15
50
2
85
72
80
40
technologydeveloperreverseengineeringportfoliohobby
AstroCloudflare DNS
2025-07-27T07:56:17.997Z
lewisakura.moe favicon

Private by Design, LLC

lewisakura.moe

71
TechnologyUnited StatessmallMEDIUM

The website lewisakura.moe is a personal site belonging to Lewis, a young software engineer and aspiring content creator specializing in backend development and game development on platforms such as Roblox. The site serves as a portfolio and contact point, showcasing various projects and placements, both paid and volunteer. The business model is primarily freelance and team-based development with future plans for content creation as a VTuber. The site targets technology enthusiasts and potential collaborators. Technically, the site is built using the Astro framework, leveraging modern web technologies and hosted with Cloudflare DNS services. It is well optimized for performance and mobile devices, with good SEO metadata and clear navigation. No CMS or analytics tools are detected, indicating a lightweight and privacy-conscious approach. From a security perspective, the site uses HTTPS and has domain transfer and deletion protections enabled. However, DNSSEC is not enabled, and no security headers are detected, which are areas for improvement. No privacy or cookie policies are published, which impacts compliance posture. Contact information is clearly provided via email and Discord, but no formal incident response or security policies are present. Overall, the site is safe, professional, and trustworthy for its intended personal and freelance use. Strategic recommendations include adding privacy and cookie policies, enabling DNSSEC, implementing security headers, and considering incident response documentation to enhance security and compliance.

50
35
47
95
75
85
100
personalsoftwareengineeringgamedevelopmentcontentcreationportfolio+2 more
Astro v5.2.5JavaScript (ES Modules)Cloudflare DNSCSS
2025-07-27T07:55:47.935Z
P

Private by Design, LLC

env.fail

59
TechnologyUnited StatessmallMEDIUM

env.fail is a small, US-based information security blog operated by Private by Design, LLC. The site features multiple contributors who publish content focused on web security and infosec topics. The business model centers on content publishing aimed at security professionals and enthusiasts. The website is relatively new, with domain registration in March 2024, consistent with the recent blog post dates. Technically, the website uses standard web technologies including HTML5, CSS, and JavaScript, with Cloudflare providing DNS services. The site appears to be custom-built or uses an unknown CMS. Performance and mobile optimization are moderate to good, though accessibility and SEO optimizations are basic. No advanced frameworks or analytics services are detected. From a security perspective, the site benefits from HTTPS and domain status protections but lacks DNSSEC and security headers. There are no visible vulnerabilities or exposed sensitive data. However, the absence of privacy, cookie, and terms of service policies, as well as contact information and vulnerability disclosure mechanisms, indicates room for improvement in compliance and incident response readiness. Overall, the website is professional and relevant to its niche audience but would benefit from enhanced security practices and compliance documentation to improve trust and legal standing.

30
50
2
70
72
75
100
infosecwebsecurityblogsecurityresearchtechnology
HTML5CSSJavaScriptCloudflare DNS
2025-07-27T07:54:01.676Z