Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 72 of 155|Showing 3551-3600 of 7749
diyhrt.wiki favicon

Private by Design, LLC

diyhrt.wiki

60
HealthcareUnited StatessmallMEDIUM

The website diyhrt.wiki serves as an informational resource dedicated to providing guidance on DIY Hormone Replacement Therapy (HRT) primarily for transgender individuals. It offers various guides including Transfem and Transmasc hormone therapy, blood testing information, injection supplies, and telehealth resources. The site positions itself as a niche community resource addressing accessibility challenges faced by transgender people in obtaining HRT. The business model is non-commercial, focusing solely on education and support without selling products or services. Technically, the site is built with standard HTML5 and CSS3, leveraging Google Fonts and Cloudflare DNS services. The website demonstrates moderate performance and good mobile optimization with clear navigation and consistent branding. However, it lacks advanced frameworks or CMS platforms and does not implement DNSSEC or visible security headers, which are areas for improvement. From a security perspective, the site uses HTTPS and has domain registration protections in place, but it lacks privacy and cookie policies, security headers, and incident response information. No analytics or tracking scripts were detected, indicating minimal user tracking. The WHOIS data is consistent and transparent, with no privacy protection, aligning with the site's small-scale informational nature. Overall, the security posture is moderate but could be enhanced by implementing DNSSEC, security headers, and compliance documentation. The content is adult-oriented, with an age verification banner restricting access to users 18 or older, but it does not contain explicit or NSFW material. The site is trustworthy for its intended audience but would benefit from improved privacy compliance and security best practices to enhance user trust and regulatory adherence.

25
35
2
85
75
85
100
diyhrttransgenderhormonereplacementtherapyhealthcare+1 more
HTML5CSS3Google Fonts (Comfortaa, Poppins)Cloudflare DNS
2025-07-27T03:21:57.803Z
R

Ezio's webpage

reimu.info

54
TechnologyCanadasmallMEDIUM

The website reimu.info is a personal hobbyist site titled "Ezio's webpage" that hosts various files useful for outdated operating systems and shares personal interests such as anime reviews and VR Google Earth pictures. It targets a niche audience of technology enthusiasts and hobbyists rather than commercial customers. The site is small in scale, with no evident business model or commercial intent, and was registered in 2022 with privacy protection enabled. Technically, the site is simple, built with basic HTML and CSS, and uses Cloudflare for DNS hosting without DNSSEC enabled. There is no evidence of a CMS or advanced frameworks. The site performance is moderate with basic mobile optimization and accessibility. SEO optimization is minimal, and no analytics or tracking services are detected. From a security perspective, the site lacks HTTPS confirmation in the provided data, has no security headers, and does not implement privacy or cookie policies. No forms or data collection mechanisms are present, reducing attack surface but also indicating minimal user engagement features. The WHOIS data shows privacy protection, which is justified given the personal nature of the site. No vulnerabilities or suspicious patterns were detected. Overall, the site is low risk but also low in professionalism and compliance. Strategic recommendations include enabling HTTPS with strong TLS, adding security headers, publishing privacy and cookie policies, and improving technical SEO and accessibility to enhance user experience and trust.

15
40
17
65
65
80
100
personalhobbytechnologyfilehostinganime+1 more
HTMLCSSCloudflare DNS
2025-07-27T03:21:12.454Z
drewsh.com favicon

Drew Jose

drewsh.com

57
TechnologyN/asmallMEDIUM

Drew's blogsite is a personal blog focused on technology and writing, authored by Drew Jose. The site provides content primarily in the form of blog articles covering development setups, programming examples, and personal opinions on software tools. The business model is content publishing with a niche audience interested in tech and writing topics. The site is small scale, newly founded in 2024, and does not appear to be commercial or enterprise in nature. Technically, the website is built using the Pelican static site generator, leveraging Font Awesome for icons and Cloudflare for DNS services. The site is served over HTTPS with a moderate performance profile and good mobile optimization. SEO and accessibility are basic to good, with proper meta tags and structured data present. However, no advanced frameworks or CMS platforms are detected beyond Pelican. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and security headers such as Content-Security-Policy or X-Frame-Options. There are no visible forms or data collection mechanisms, reducing attack surface. Privacy and cookie policies are absent, which is a compliance gap. No incident response or vulnerability disclosure information is provided, limiting transparency. Overall, the website is low risk with safe content and moderate trustworthiness. Strategic improvements include adding privacy and cookie policies, enabling DNSSEC, implementing security headers, and providing contact and incident response information to enhance compliance and trust.

15
50
2
65
65
80
100
technologyblogwritingpersonalopensource
PelicanFont AwesomeCloudflare DNS
2025-07-27T03:21:07.444Z
git.gay favicon

Private by Design, LLC

git.gay

50
TechnologyUnited StatessmallMEDIUM

git.gay is a niche collaboration platform designed to empower queer developers by providing Git hosting, continuous integration, and static site hosting services. Operated by the collective 'besties', it emphasizes community values, open source software, and privacy by avoiding ads and third-party trackers. The platform leverages a fork of Forgejo, ensuring open source transparency and configurability. The website presents a professional and consistent brand image targeting queer and neurodiverse developers, positioning itself as a community-centric alternative to corporate platforms. Technically, git.gay uses modern web technologies including Forgejo, Cloudflare DNS, and custom JavaScript for enhanced user experience and error handling. The site is mobile optimized with good SEO practices and minimal user tracking, reflecting a mature digital infrastructure. However, DNSSEC is not enabled, and security headers are not visibly implemented, indicating areas for improvement in security hardening. From a security perspective, the site enforces HTTPS and employs CSRF tokens, with no detected vulnerabilities or exposed sensitive data. Privacy policies and terms of service are present but basic, and no explicit incident response or vulnerability disclosure policies are published. The absence of cookie consent mechanisms despite script usage suggests a potential compliance gap. Overall, the security posture is solid but could benefit from enhanced transparency and technical controls. The domain registration is transparent and consistent with the business profile, registered to Private by Design, LLC in the US, matching the website's operational claims. The domain age aligns with the platform's founding date, supporting legitimacy. No suspicious WHOIS patterns or privacy protections obscure ownership, enhancing trustworthiness. The platform's focus on community and open source principles further supports a positive risk profile. Strategic recommendations include enabling DNSSEC, implementing comprehensive security headers, publishing detailed security and incident response policies, adding cookie consent mechanisms, and establishing a vulnerability disclosure process. These steps will strengthen security, compliance, and user trust, supporting git.gay's mission as a safe and empowering platform for queer developers.

45
53
2
70
75
75
-
gitforgeforgejoqueeropensource+2 more
Forgejo (fork of Gitea)Cloudflare DNSJavaScriptHTML5+1

Partner Domains:

besties.house
partner
2025-07-27T03:20:27.350Z
sugrstrz.com favicon

The Barkzone

sugrstrz.com

56
OtherUnited StatessmallMEDIUM

SugrStrz.com is a personal website and blog maintained by an individual gamer and technology enthusiast. The site focuses on sharing personal interests including gaming, music, and social media engagement. It serves a niche audience of gaming and retro game fans as well as followers of the owner's social profiles. The business model is non-commercial, primarily a hobby/personal branding platform with no direct revenue streams or commercial services. The website is hosted on Neocities with DNS managed by Cloudflare and domain registration through GoDaddy, reflecting a modest but stable technical infrastructure. The site uses basic HTML, CSS, and JavaScript with some outdated elements such as the deprecated marquee tag, indicating room for modernization. Security posture is basic with no DNSSEC enabled and no visible security headers or HTTPS enforcement in the HTML content, though the domain registration status includes protective flags. Privacy and cookie policies are absent, and no contact or incident response information is provided, limiting compliance and trust signals. Overall, the site is safe for general audiences with no adult content detected. Recommendations include improving security configurations, adding privacy and cookie policies, and enhancing mobile and accessibility features to improve user experience and compliance.

40
35
2
60
75
75
100
personalgamingblogretrogamesmusic+1 more
HTML5CSSJavaScriptCloudflare DNS
2025-07-27T02:14:01.574Z
C

Creative Commons

licensebuttons.net

57
TechnologyN/amediumMEDIUM

The website licensebuttons.net serves as an official resource for Creative Commons license buttons, badges, and icons. It supports content creators and website owners in marking their works under Creative Commons licenses by providing visual assets and linking to the license chooser tool. The site is part of the broader Creative Commons ecosystem, a well-established non-profit organization focused on open licensing. The business model is non-commercial, aiming to promote open culture and legal sharing of creative works. Technically, the website uses a simple Bootstrap CSS framework and is hosted behind Cloudflare DNS services. The site is lightweight, with basic mobile optimization and accessibility features. There are no detected CMS or complex backend technologies, indicating a static or minimally dynamic site. Performance is moderate, with no advanced SEO or analytics scripts detected in the provided content. From a security perspective, the site uses HTTPS (implied by Cloudflare DNS and domain status), but lacks DNSSEC and security headers, which are recommended for enhanced protection. No forms or user input fields are present, reducing attack surface. Privacy compliance is partially addressed through links to comprehensive Creative Commons policies, but no cookie consent mechanism is implemented. No contact information or incident response details are provided on the site, limiting direct communication channels. Overall, the website is trustworthy and serves its purpose well but could improve in security hardening and privacy transparency. The domain registration is consistent and legitimate, supporting the site's credibility. There are no signs of malicious content or adult material, making it safe for general audiences.

60
40
2
40
75
70
100
creativecommonslicenseopenlicensecopyrightbadge+1 more
Bootstrap CSSCloudflare DNS
2025-07-27T02:10:02.442Z
P

Private by Design, LLC

noe.sh

58
TechnologyUnited StatessmallMEDIUM

The website noe.sh is a personal and creative project launched in early 2024 by Private by Design, LLC, a US-based entity. It features a unique chat-like interface with references to 'doll' and 'owner' interactions and links to various creative and technical projects such as dollcode transcoder, shader art, and Planetside 2 population stats. The site targets a general audience interested in niche technology and creative coding projects. The business model and market position are not clearly defined, indicating a small-scale or hobbyist operation. Technically, the site is built with basic HTML and CSS, hosted behind Cloudflare DNS services, but lacks modern frameworks or CMS platforms. Performance is moderate with basic mobile optimization and accessibility. SEO optimization is minimal, and no analytics or advertising tools are detected, indicating limited data collection and tracking. From a security perspective, the site uses HTTPS and has domain status protections to prevent unauthorized changes. However, DNSSEC is not enabled, and no security headers are present, which could be improved. There are no visible privacy, cookie, or incident response policies, and no contact information is provided, limiting compliance and trust signals. Overall, the site is safe with no adult or explicit content, but it lacks professional business and security practices. The domain registration is transparent and consistent with the site's nature. Strategic improvements in privacy compliance, security headers, and contact information would enhance trust and security posture.

15
50
17
70
75
75
100
personalcreativetechnologychatdollcode+2 more
HTML5CSS3Cloudflare DNS
2025-07-27T01:06:50.358Z
appfutura.com favicon

Appfutura

appfutura.com

58
TechnologyN/amediumMEDIUM

Appfutura.com is a website that has been acquired and integrated into Clutch.co, a leading global marketplace for B2B business service providers. The site currently serves as a redirect or informational placeholder directing users to Clutch's platform for finding and listing business service providers. The business model focuses on connecting buyers with providers in a global marketplace environment. The website content is minimal and primarily serves to inform visitors of the acquisition and redirect them accordingly. From a technical perspective, the site uses Google Tag Manager for analytics and Google Fonts for typography, with DNS hosted on Cloudflare. The website lacks advanced SEO optimization and accessibility features, and the content is minimal with no interactive forms or direct contact information. The site uses a meta robots tag to prevent indexing, indicating it is not intended for organic search traffic. Security posture is basic; the domain is registered with GoDaddy and uses Cloudflare DNS but does not have DNSSEC enabled. No security headers or explicit security policies are present on the page. The site uses HTTPS (implied by Cloudflare DNS and modern standards) but lacks visible cookie consent mechanisms despite using tracking scripts. No incident response or vulnerability disclosure information is available. Overall, the website is low risk but limited in content and security maturity. It functions primarily as a redirect to the parent company Clutch.co. Strategic recommendations include enabling DNSSEC, adding security headers, implementing cookie consent, and improving transparency with contact and security policies.

30
53
2
70
75
75
100
b2bmarketplacebusinessservicesclutchappfutura
Google Tag ManagerGoogle FontsCloudflare DNS

Partner Domains:

clutch.co
parent
2025-07-27T00:59:19.222Z
leaderswedeserve.com favicon

Leaders We Deserve

leaderswedeserve.com

62
GovernmentUnited StatessmallMEDIUM

Leaders We Deserve is a grassroots political action committee focused on electing young progressive candidates to Congress and State Legislatures across the United States. Founded by David Hogg and Kevin Lata, the organization aims to counter far-right agendas and promote progressive policies. The website serves as a platform for voter engagement, fundraising, and candidate promotion, targeting young progressives and donors interested in political change. The business model revolves around grassroots campaigning and donation-driven support for progressive candidates. Technically, the website is built on WordPress with Yoast SEO plugin, leveraging modern web technologies including jQuery, Google Tag Manager, Hotjar, and Facebook Pixel for analytics and marketing. Hosting and domain registration are managed through Squarespace Domains and Cloudflare DNS services, ensuring reliable infrastructure. The site is mobile-optimized with good SEO practices but lacks some advanced accessibility features. From a security perspective, the site enforces HTTPS and uses domain status locks to prevent unauthorized changes. However, DNSSEC is not enabled, and no advanced security headers are detected, indicating room for improvement. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism or detailed GDPR compliance statements. The site collects personal data via multiple signup forms with explicit SMS consent, integrating with ActionKit and ActBlue for campaign management and donations. Overall, the website is professionally designed, trustworthy, and aligned with its political advocacy mission. Security posture is adequate but could be enhanced with additional controls and transparency. Privacy compliance should be improved to meet evolving regulatory standards. The domain registration is consistent and legitimate, supporting the organization's credibility.

25
53
2
85
75
75
100
politicalprogressivegrassrootsdonationcampaign+2 more
WordPressYoast SEO pluginjQueryCloudflare DNS+4

Partner Domains:

secure.actblue.com
partner
middleseat.co
partner
2025-07-26T22:48:33.340Z
hookshot.media favicon

Hookshot Media Ltd

hookshot.media

64
MediaUnited KingdommediumMEDIUM

Hookshot Media Ltd is a UK-based digital media company specializing in publishing popular video game content through multiple well-known brands including Nintendo Life, Push Square, Pure Xbox, Time Extension, and Nintendo News. The company targets a global audience of video game enthusiasts and operates as a medium-sized business with a strong market position in the gaming media sector. Their business model focuses on content creation, community engagement, and digital publishing across multiple platforms. Technically, the website is built on a custom CMS (dgpCMS) using PHP and JavaScript, hosted via Cloudflare DNS services. The site demonstrates modern web practices including responsive design, fast performance, and SEO optimization. Google Analytics is used for visitor tracking, and the site employs HTTPS with good SSL configuration. However, DNSSEC is not enabled, and some security headers are not explicitly detected. From a security perspective, the website follows good practices such as HTTPS enforcement and domain transfer protection. No critical vulnerabilities or exposed sensitive data were found. Privacy compliance is partially addressed with published privacy and cookie policies, though no explicit cookie consent mechanism is present. Incident response and security policy information are not published, representing an area for improvement. Overall, Hookshot Media presents a professional, trustworthy, and well-maintained digital presence with strong business credibility. Strategic recommendations include enhancing security headers, enabling DNSSEC, implementing cookie consent mechanisms, and publishing security and incident response policies to improve compliance and trust further.

15
68
2
85
75
85
100
gamingmediavideogamesnintendoplaystation+4 more
PHPJavaScriptGoogle AnalyticsCloudflare DNS

Partner Domains:

nintendolife.com
subsidiary
pushsquare.com
subsidiary

+3 more partners

2025-07-26T21:32:32.321Z
sciencedaily.com favicon

ScienceDaily

sciencedaily.com

63
MediaN/alargeMEDIUM

ScienceDaily is a well-established online platform providing breaking news and articles on the latest scientific research across multiple disciplines including health, environment, technology, and social sciences. Founded in 1995, it serves a broad audience ranging from the general public to researchers and educators, offering daily updated content sourced from leading universities and research organizations. The website maintains a strong market position as a trusted science news aggregator with a professional and consistent brand presence. Technically, the site employs modern web technologies such as Bootstrap, jQuery, and Font Awesome, hosted behind Cloudflare DNS and CDN services. It integrates Google Analytics for user tracking and uses a consent management platform to comply with GDPR regulations. The website is mobile-optimized, accessible, and SEO-friendly, providing a good user experience with clear navigation and professional design. From a security perspective, the site enforces HTTPS, uses clientTransferProhibited domain status, and implements consent management for privacy compliance. However, DNSSEC is not enabled, and explicit security policies or incident response contacts are not publicly available. No vulnerabilities or suspicious activities were detected. The WHOIS data confirms the domain's legitimacy and long-standing presence. Overall, ScienceDaily demonstrates a mature digital infrastructure, strong content quality, and good privacy compliance, making it a trustworthy source for scientific news. Strategic improvements could include enabling DNSSEC, publishing detailed security policies, and providing incident response contacts to enhance transparency and security posture.

15
53
17
80
75
80
100
sciencenewsresearchhealthtechnology+2 more
Bootstrap 3.4.1jQuery 3.6.0Font AwesomeGoogle Analytics (gtag.js)+5
2025-07-26T21:30:32.263Z
ruptly.agency favicon

Ruptly

ruptly.agency

55
MediaRussiamediumMEDIUM

Ruptly is a media agency specializing in video content distribution, targeting registered users who require access to their services. The website functions primarily as a login portal restricting access to authorized users, with contact provided via email for further inquiries. The business operates in the media sector and appears to be a medium-sized entity based in Russia, although the domain WHOIS data shows privacy protection and an anomalous future creation date, which raises some concerns about registration transparency. Technically, the website employs modern frontend technologies including React, service workers, and Cloudflare DNS hosting. It uses Yandex Metrika for analytics and tracking, indicating moderate user tracking practices. The site is mobile optimized and includes accessibility features, but SEO optimization and content richness are basic. The cookie consent mechanism is present and functional, though no privacy policy or terms of service are visible, which impacts compliance. From a security perspective, HTTPS is enforced and the domain status includes clientTransferProhibited, which are positive indicators. However, no DNSSEC is enabled, no security headers are detected, and there is no published security policy or incident response information. The domain's privacy protection and unusual creation date reduce trustworthiness somewhat. Overall, the security posture is moderate but could be improved with better transparency and security controls. The overall risk assessment suggests a functional but basic media content platform with moderate security and privacy compliance. Strategic recommendations include enabling DNSSEC, publishing privacy and security policies, adding security headers, and clarifying domain registration details to enhance trust and compliance.

15
50
2
60
75
70
100
medialoginvideocontentprivacy+2 more
ReactCloudflare DNSYandex MetrikaService Worker+1
2025-07-26T21:24:39.203Z
pixelfed.ca favicon

Fedecan non-profit organization

pixelfed.ca

59
TechnologyCanadasmallMEDIUM

Pixelfed.ca is a Canadian-hosted, non-profit managed instance of the Pixelfed federated image sharing platform. It offers an ethical alternative to centralized social media platforms by enabling decentralized photo sharing with features such as photo posts, albums, filters, collections, and federation support. The platform targets a general audience and is managed by the Fedecan non-profit organization, emphasizing privacy and community standards. Technically, the website uses modern web technologies including JavaScript frameworks (Vue.js implied), Plyr media player, and Cloudflare DNS services. The site is well-structured with good mobile optimization and SEO practices, though some security headers and DNSSEC are not enabled. The platform supports federation and mobile app integration but does not currently support stories or video content. From a security perspective, the site enforces HTTPS and has no visible vulnerabilities or exposed sensitive data. However, it lacks explicit security policies, incident response contacts, and vulnerability disclosure mechanisms. Privacy compliance is basic with privacy and terms pages present but no cookie consent mechanism. The domain registration is privacy protected but consistent with the business claims and is registered with a reputable Canadian registrar. Overall, Pixelfed.ca presents a trustworthy, well-maintained platform with a clear ethical stance and community guidelines. Strategic improvements in security headers, privacy compliance, and incident response transparency would enhance its security posture and user trust.

40
53
2
70
75
50
100
imagesharingfederationnon-profitcanadianethicalsocialmedia
Pixelfed platformCloudflare DNSJavaScriptVue.js (implied by VueCarousel styles)+1
2025-07-26T20:22:35.956Z
cancovid.ca favicon

CanCOVID

cancovid.ca

60
HealthcareCanadamediumMEDIUM

CanCOVID is a Canadian non-profit network established in 2020 to facilitate multidisciplinary collaboration among researchers, academics, patient partners, decision makers, and industry stakeholders focused on the COVID-19 pandemic response. It provides knowledge products, data trackers, resource libraries, and community engagement platforms to support evidence-informed decision-making and policy development. The organization is government-funded and well-positioned within the Canadian public health ecosystem. Technically, the website is built on WordPress with modern plugins such as Yoast SEO and integrates Google Analytics and Google Maps APIs. The site is hosted behind Cloudflare DNS, uses HTTPS with a good SSL configuration, and demonstrates good mobile optimization and accessibility. SEO practices are well implemented, and the site offers a professional user experience with clear navigation and relevant content. From a security perspective, the site employs HTTPS and domain transfer protection but lacks DNSSEC and explicit security headers. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is partial; a comprehensive privacy policy is present, but no cookie consent mechanism is implemented despite tracking scripts. Incident response and security policies are not publicly disclosed, which could be improved to enhance trust. Overall, CanCOVID presents a high level of business credibility and trustworthiness with a strong focus on public health research collaboration. The website quality is excellent, with minor improvements recommended in security headers and privacy compliance to further strengthen its security posture and regulatory adherence.

25
53
17
85
65
55
100
covid-19researchhealthcarecanadapublichealth+1 more
WordPressYoast SEO pluginjQueryGoogle Analytics+4
2025-07-26T19:13:44.413Z