Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149319
Websites
130
Industries
113
Countries
52
Avg Score
Page 711 of 775|Showing 35501-35550 of 38748
medbank.lt favicon

Urbo

medbank.lt

70
FinanceLithuaniamediumMEDIUM

Urbo is a Lithuanian bank established in 2023, offering a comprehensive range of banking services to private individuals and business clients. Their services include housing and consumer loans, business financing, deposits, payment services, insurance, and digital banking solutions. The website is professionally designed, mobile-optimized, and provides clear navigation and relevant content tailored to their target audience in Lithuania. The company maintains an active online presence with social media links and multiple service subdomains for internet banking, document management, loan applications, and API access. Technically, the website leverages modern JavaScript frameworks such as Alpine.js and Livewire, is hosted behind Cloudflare, and integrates Google Tag Manager and Facebook Pixel for analytics and marketing. Security posture is strong with HTTPS enforced, appropriate security headers, and no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with accessible privacy and cookie policies and a consent mechanism. However, explicit security policies and incident response contacts are not found, representing an area for improvement. Overall, Urbo presents a trustworthy and professional digital presence consistent with a modern financial institution.

60
68
17
85
75
75
100
bankingfinanceloansdepositsinsurance+2 more
JavaScriptAlpine.jsLivewireCloudflare+2

Partner Domains:

ibs.urbo.lt
service
mano.urbo.lt
service

+2 more partners

2025-06-24T16:44:59.399Z
tripcheck.com favicon

Oregon Department of Transportation

tripcheck.com

56
TransportationUnited StateslargeMEDIUM

TripCheck is an official Oregon Department of Transportation website providing comprehensive traveler information including road conditions, weather forecasts, traffic cameras, and commercial vehicle restrictions. The site serves as a critical resource for travelers and commercial operators within Oregon, offering real-time data and various travel-related services. The business model is government-operated, focusing on public service and transportation safety. The website is well-branded and consistent with state government standards, targeting a broad audience of Oregon travelers and transport professionals. Technically, the site employs modern JavaScript frameworks such as Dojo Toolkit and jQuery, along with Esri's ArcGIS API for mapping functionalities. The infrastructure appears to be hosted on state government servers, ensuring reliability and alignment with public sector standards. The site is moderately optimized for performance and mobile devices, with good SEO practices and basic accessibility features. From a security perspective, the domain is well-protected with registrar-level domain status locks, but lacks DNSSEC implementation and visible security headers. No privacy or cookie policies are present, indicating compliance gaps with GDPR and other privacy regulations. There is no exposed sensitive data or vulnerable libraries detected, but the absence of incident response contacts and security policies reduces the overall security posture. Overall, the website is trustworthy and professional, serving its public service mission effectively. However, improvements in privacy compliance, security headers, and incident response transparency are recommended to enhance user trust and regulatory adherence.

15
35
17
60
67
75
100
transportationtravelroadconditionsweathergovernment+2 more
JavaScriptDojo ToolkitjQueryEsri ArcGIS API+2
2025-06-24T16:06:55.218Z
T

Twofold Health

trytwofold.com

61
HealthcareN/asmallMEDIUM

Twofold Health operates a specialized AI-driven medical scribe platform designed to automate and streamline clinical documentation for healthcare professionals such as therapists, physicians, and nurses. The company positions itself as a leading ambient AI solution trusted globally, offering a SaaS model with free, personal, and group subscription plans. Their platform emphasizes accuracy, compliance, and ease of use, targeting clinicians seeking to reduce administrative burden and improve patient care. Technically, the website is built using modern frameworks like Astro, hosted on Microsoft Azure with a strong focus on security and compliance. The site integrates advanced analytics tools including PostHog, Google Tag Manager, and social media pixels to monitor user engagement and optimize marketing efforts. The site is mobile-optimized, fast-loading, and well-structured for SEO. Security posture is robust with HIPAA and HITECH compliance, encrypted data handling, and no storage of audio recordings. The company maintains a formal Business Associate Agreement with Microsoft Azure and enforces internal security practices such as background checks and training. However, there is room for improvement in explicit security headers and cookie consent mechanisms. Overall, the website and business demonstrate a high level of professionalism and trustworthiness, though the absence of WHOIS domain registration data raises some concerns about domain legitimacy. Strategic recommendations include enhancing privacy compliance with cookie consent, publishing vulnerability disclosure policies, and improving transparency on incident response.

30
53
2
70
72
80
100
aimedicalscribehealthcaretechnologyhipaacompliantclinicaldocumentationmentalhealth+2 more
JavaScriptPostHog analyticsGoogle Tag ManagerFacebook Pixel+1
2025-06-24T16:05:24.890Z
manchesterpaintballarena.co.uk favicon

manchesterpaintballarena.co.uk

manchesterpaintballarena.co.uk

50
OtherUnited KingdomsmallMEDIUM

The website manchesterpaintballarena.co.uk ostensibly represents a paintball arena business located in Manchester, UK, offering recreational paintball services. However, the actual website content is minimal and primarily consists of a domain parking or monetization page with advertising blocks and limited business information. The domain was registered recently in August 2023 by a registrant associated with domain reselling, which raises questions about the direct ownership and legitimacy of the site as a business platform. Technically, the site uses basic HTML5, CSS3, and JavaScript with integrations for Google Tag Manager and Google AdSense for advertising and tracking. The site lacks advanced frameworks or CMS platforms and shows only basic mobile optimization and SEO features. There are no forms or interactive elements, and no visible contact or social media links, which limits user engagement and trust. From a security perspective, the site uses HTTPS but lacks important security headers and policies. There is no visible privacy or cookie consent mechanism compliant with GDPR, and no incident response or security policy information is provided. The domain registration details suggest the domain may be parked or monetized by a third party rather than directly owned by the paintball business, which reduces trustworthiness and business credibility. Overall, the website presents a low-risk but low-value profile with limited business presence and security posture. Strategic recommendations include improving business content and contact information, implementing comprehensive privacy and security policies, enhancing technical infrastructure, and clarifying domain ownership to build trust and compliance.

20
53
2
60
52
70
100
paintballmanchesterrecreationaldomainparkingadvertising
Google Tag ManagerGoogle AdSenseBodis (domain parking/monetization)HTML5+2
2025-06-24T16:04:14.581Z
A

adidas

adidas.co.uk

55
RetailUnited KingdomenterpriseMEDIUM

The website for adidas.co.uk is currently inaccessible due to a security block that triggers a HTTP 403 Forbidden response. This block is part of a bot protection mechanism during high-traffic product releases to ensure fair access to customers. Due to this, the site content is minimal and does not provide typical metadata, contact information, or business details. The WHOIS lookup for the subdomain 'www.adidas.co.uk' failed because it is not a valid registrable domain under Nominet UK rules, indicating the query was made incorrectly on a subdomain rather than the base domain. This limits the ability to verify domain registration details. Technically, the site uses JavaScript and references a tag management script that is commented out, indicating some level of digital marketing infrastructure, but no active scripts or external resources are loaded on this blocked page. No privacy, cookie, or terms of service policies are present on this page, and no contact or security policy information is available. The security posture cannot be fully assessed due to lack of data, but the presence of a WAF or bot protection system is confirmed. Overall, the site is enterprise-level retail focused on sportswear and sneaker sales, targeting consumers in the UK. However, the current page state prevents a full security, compliance, or business analysis. The lack of accessible content and WHOIS data results in a very low AI score and indicates the need for direct access or alternative data sources for comprehensive evaluation.

20
50
17
85
80
70
100
e-commercesportswearsecurity-blockbot-protection403-forbidden
JavaScript
2025-06-24T16:03:24.453Z
nflpa.com favicon

National Football League Players Association

nflpa.com

65
GovernmentUnited StateslargeMEDIUM

The National Football League Players Association (NFLPA) is the official union representing professional football players in the NFL. The organization focuses on player advocacy, collective bargaining, licensing, marketing, and providing resources for players and related stakeholders. The website reflects a mature and authoritative presence with comprehensive content tailored to players, agents, financial advisors, marketing representatives, media, and partners. The NFLPA maintains a strong market position as the recognized players' union with a large audience and extensive services including public dashboards and storytelling content. Technically, the website employs modern web technologies including JavaScript and Google Tag Manager, hosted with Azure DNS services. The site is mobile optimized, accessible, and SEO friendly with structured data enhancing search visibility. Performance is moderate with good design and navigation clarity. Security posture is solid with HTTPS enforced and domain transfer protections, though DNSSEC is not enabled and security headers could be improved. Privacy compliance is well addressed with clear policies and cookie consent mechanisms. Overall, the NFLPA website demonstrates a high level of professionalism, trustworthiness, and digital maturity. Security practices are good but could benefit from enhancements such as DNSSEC and a published security policy. The domain registration data aligns well with the organization's identity, reinforcing legitimacy. The site is free from blocking or WAF challenges, allowing full content access and analysis.

55
53
2
75
67
85
100
sportsunionnflplayersassociation+4 more
JavaScriptGoogle Tag ManagerAzure DNSSVG graphics

Partner Domains:

playerstrust.com
partner
yourpaf.com
partner

+3 more partners

2025-06-24T16:03:19.443Z
regprog.com favicon

Regular Programming

regprog.com

60
TechnologyN/asmallMEDIUM

The website 'Regular Programming' is a podcast platform focused on delivering conversations about programming topics, hosted by Lars Wikman and Andreas Ekeroot, and funded by Underjord.io. The site targets programmers and software developers interested in technology discussions. It operates primarily as a content distribution platform for podcast episodes, leveraging Transistor.fm for hosting and media delivery. The website presents a clean, consistent brand with good content quality and user experience, though it lacks comprehensive business and contact information. From a technical perspective, the site uses modern JavaScript frameworks such as Alpine.js and integrates with Transistor.fm's platform. The performance and mobile optimization are adequate, with basic accessibility features. However, the site lacks visible security headers and formal privacy or cookie policies, which are important for compliance and user trust. Security posture is moderate; no critical vulnerabilities or exposed sensitive data were detected, but the absence of security headers and incident response information indicates room for improvement. The lack of WHOIS data for the domain is a notable concern, reducing trustworthiness and raising questions about domain registration legitimacy. Overall, the site is functional and professional but would benefit from enhanced security practices, privacy compliance, and transparent business information to improve trust and compliance posture.

80
50
2
70
57
55
100
technologyprogrammingsoftwaredeveloperscode+5 more
JavaScriptAlpine.jsTransistor.fm podcast hosting
2025-06-24T16:03:04.414Z
K

Koentopp Guitars

koentoppguitars.com

60
OtherN/asmallMEDIUM

Koentopp Guitars is a small artisanal business specializing in handcrafted guitars by luthier Dan Koentopp. The website serves as a showcase for their custom guitar offerings, testimonials, and blog content, targeting musicians and guitar enthusiasts seeking high-quality custom instruments. The business appears well-established with a domain age consistent with its founding year, positioning itself as a niche player in the custom guitar market. Technically, the website uses a basic but functional technology stack including HTML5, CSS3, jQuery 1.9.1, and Bootstrap for UI components like the carousel. Hosting is provided by GoDaddy. The site shows moderate performance and basic mobile optimization but lacks advanced SEO and accessibility features. No CMS is detected, suggesting a custom or static site build. From a security perspective, the site uses HTTPS but lacks important security headers such as Content-Security-Policy and HSTS. DNSSEC is not enabled, and no privacy or cookie policies are present, indicating compliance gaps with GDPR and other privacy regulations. Forms exist for newsletter subscription but no explicit security controls are visible. Contact information is clearly provided, enhancing trust. Overall, the website is functional and professional but could improve significantly in privacy compliance and security posture. Strategic improvements in these areas would reduce risk and enhance user trust.

65
35
2
70
67
75
100
handmadeguitarsluthiercustomguitarsmusic+1 more
HTML5CSS3JavaScriptjQuery 1.9.1+1
2025-06-24T14:58:50.903Z
nvsos.gov favicon

Nevada Secretary of State

nvsos.gov

55
GovernmentUnited StateslargeMEDIUM

The Nevada Secretary of State website serves as the official digital presence for the state's Secretary of State office, providing comprehensive information and services related to elections, business registration, licensing, and securities regulation. The site targets Nevada residents, businesses, voters, and investors, offering a wide range of resources including forms, news, and online services. The website is positioned as a trusted government resource with a large operational scale and consistent branding. Technically, the site employs AngularJS and jQuery frameworks, running on the Vision CMS platform. It demonstrates good mobile optimization, accessibility, and SEO practices, though performance is moderate. The site enforces HTTPS and includes session timeout mechanisms, indicating a mature security posture. However, explicit security headers are not detected, and there is no cookie consent mechanism, which are areas for improvement. Security-wise, the site shows no visible vulnerabilities or exposed sensitive data. The lack of WHOIS data is typical for government domains and does not detract from the site's legitimacy. Tracking is minimal, limited to Lucky Orange analytics, and privacy policies are present though GDPR compliance indicators are limited. Overall, the website is a professional, secure, and credible government portal with minor gaps in privacy compliance and security header implementation. Strategic enhancements in these areas would further strengthen trust and compliance.

20
58
17
40
57
70
100
governmentbusinessregistrationelectionslicensingsecurities+2 more
AngularJSjQueryJavaScriptCSS+1

Partner Domains:

www.nvsilverflume.gov
partner
nvjobs.nv.gov
partner
2025-06-24T14:57:00.443Z
1xslot946949.top favicon

1xSlots

1xslot946949.top

53
OtherPanamamediumMEDIUM

1xSlots operates as an online gambling and sports betting platform licensed by the Curaçao Gaming Authority and managed by Orakum N.V. The business targets online gamblers and bettors, offering casino games, live casino, and sports betting services. The platform is relatively new under the domain 1xslot946949.top, which is currently blocked in certain countries, limiting user access. The company processes payments through Cyprus-registered entities, indicating a structured payment ecosystem. However, the domain's recent registration and privacy protection reduce transparency and trust. Technically, the website uses modern JavaScript frameworks such as Vue.js and integrates Google reCAPTCHA for bot protection. Despite this, the site lacks visible security headers and comprehensive privacy or cookie policies, which are critical for compliance and user trust. The blocked content and minimal accessible information hinder a full assessment of the platform's user experience and content quality. From a security perspective, the absence of DNSSEC, security headers, and incident response information indicates a low maturity level in security posture. The domain's WHOIS data shows privacy protection and a mismatch between registrant country and license country, which are common but reduce trustworthiness. Overall, the site scores low on content quality, privacy compliance, and business credibility due to these factors. Strategically, the platform should focus on enhancing transparency by publishing privacy and cookie policies, implementing security best practices such as DNSSEC and security headers, and improving accessibility to users in permitted regions. These steps will improve user trust, compliance posture, and overall business credibility.

45
50
17
60
72
55
100
gamblingcasinosportsbettingonlinegamblingrestrictedaccess
JavaScriptreCAPTCHACustom JS APIs (hd-api, captcha-api)

Partner Domains:

1xslot.com
partner
zavbin.com
service

+1 more partners

2025-06-24T14:53:58.232Z
J

Jungle Media Ltd.

luckydays.com

64
OtherMaltamediumMEDIUM

LuckyDays.com is an established online casino platform operated by Jungle Media Ltd., licensed by the Malta Gaming Authority. The website targets Finnish-speaking users offering a wide range of casino games including slots, jackpots, roulette, and blackjack with instant play and no registration required. The business model focuses on online gambling with payment integrations such as Trustly and BankID to facilitate fast deposits and withdrawals. The site demonstrates a consistent brand presence and clear trust indicators including regulatory licensing and payment provider partnerships. Technically, the website is built on modern web technologies including React and uses Cloudflare CDN for hosting and performance optimization. It integrates Google Tag Manager for analytics and tracking, and Fluid Payments for payment processing. The site is mobile-optimized, accessible, and SEO-friendly, providing a good user experience across devices. From a security perspective, the site enforces HTTPS with strong SSL configuration and includes standard security headers. However, it lacks explicit published security policies or incident response contacts, and does not provide a vulnerability disclosure program or security.txt file. Privacy compliance is well addressed with clear privacy and cookie policies and a consent mechanism, aligned with GDPR requirements. Overall, LuckyDays.com presents a trustworthy and professional online casino platform with strong regulatory backing and modern technical infrastructure. Strategic improvements could include publishing detailed security policies and incident response information to enhance transparency and user trust.

55
53
17
70
57
80
100
onlinecasinogaminggamblingfinnishmarketmgalicensed
ReactJavaScriptCloudflare CDNGoogle Tag Manager+1

Partner Domains:

luckydaysaffiliates.com
partner
2025-06-24T13:51:41.436Z
kiwistreasure.com favicon

Kiwi’s Treasure

kiwistreasure.com

56
HospitalityNew ZealandmediumMEDIUM

Kiwi's Treasure is an online casino platform primarily targeting players in New Zealand, offering a wide range of casino games including pokies, live dealer games, blackjack, roulette, and progressive jackpots. The business model revolves around online gambling with promotional offers such as deposit bonuses and loyalty rewards to attract and retain customers. The company operates under the legal entity Baytree (Alderney) Limited, licensed by the Alderney Gambling Control Commission, indicating regulatory compliance and legitimacy within the online gambling sector. From a technical perspective, the website employs modern web technologies including JavaScript frameworks, Google Tag Manager for analytics, and lazy loading for performance optimization. The site is mobile-optimized and includes SEO best practices such as meta tags and structured data. Security measures include HTTPS with SSL encryption, cookie consent management, and responsible gaming tools, although explicit security headers and incident response contacts are not clearly published. The security posture is strong with no evident vulnerabilities or exposed sensitive data. The site demonstrates compliance with privacy regulations, including GDPR, through comprehensive privacy and cookie policies and user consent mechanisms. However, the absence of WHOIS domain registration data raises concerns about domain legitimacy and transparency, which slightly impacts the overall trustworthiness assessment. Overall, Kiwi's Treasure presents as a professional and trustworthy online casino with good technical and security standards. Strategic improvements in publishing security policies, incident response contacts, and ensuring transparent domain registration information would enhance trust and compliance further.

15
83
2
40
57
75
100
onlinecasinonewzealandpokiesgamblingcasinogames+3 more
JavaScriptjQuery 3.6.0Google Tag ManagerSite24x7 RUM+3

Partner Domains:

help.kiwistreasure.com
service
www.buffalopartners.com
partner

+3 more partners

2025-06-24T13:51:26.394Z
hippodromeonline.com favicon

The Hippodrome Casino

hippodromeonline.com

60
HospitalityUnited KingdommediumMEDIUM

The Hippodrome Online is a UK-focused online casino platform offering a wide range of casino games including slots, live casino, jackpots, roulette, blackjack, and poker. The website features promotional offers such as welcome bonuses and free spins, targeting online gamblers in the UK market. The platform leverages modern web technologies including React and Next.js to deliver a responsive and visually appealing user experience. The site is well-structured with clear navigation and a professional design, supporting mobile users effectively. From a security perspective, the website enforces HTTPS and includes standard security headers, indicating a solid baseline security posture. However, there is no visible cookie consent mechanism or explicit privacy compliance banners, which could be improved to enhance GDPR compliance. The absence of direct contact emails or phone numbers in the HTML content limits immediate user support visibility. Additionally, no vulnerability disclosure or security policy pages were found, which are recommended for transparency and incident management. The WHOIS data for the domain is unavailable, which raises concerns about domain registration transparency and legitimacy. While the website content and branding suggest a legitimate and established business, the lack of WHOIS information is a risk factor that should be addressed. Overall, the site scores well in content quality, technical implementation, and security posture but has room for improvement in privacy compliance and business credibility transparency.

40
35
2
87
57
85
100
onlinecasinogamblingslotslivecasinoukcasino+1 more
ReactNext.jsJavaScriptCSS+1
2025-06-24T13:51:21.385Z