Skip to main content

High-risk security reports

Browse 46,997 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157368
Websites
130
Industries
113
Countries
52
Avg Score
Page 736 of 940|Showing 36751-36800 of 46997
pginkasso.ee favicon

PG Inkasso OÜ

pginkasso.ee

49
FinanceEstoniasmallHIGH

PG Inkasso OÜ is an Estonian private company specializing in debt collection and legal consulting services. The company positions itself as one of the largest players in Estonia's debt recovery market, offering both extrajudicial and judicial debt collection, legal advice, and client consultation. Their business model focuses on providing convenient and professional debt recovery services supported by qualified specialists and auditor-controlled financial processes. The website content is professionally presented and targets Estonian businesses and debtors needing collection services. Technically, the website uses a modern tech stack including Bootstrap, jQuery, and Google Analytics, hosted behind Cloudflare DNS and nameservers. The site is mobile optimized and has good SEO practices but lacks advanced accessibility features. The domain is very new (registered in 2024) which contrasts with the company's claimed founding year (2010), suggesting a recent domain acquisition or rebranding. From a security perspective, the site uses HTTPS and does not expose sensitive data or vulnerable libraries. However, it lacks DNSSEC, security headers, and any visible privacy or cookie policies, which are important for GDPR compliance and user trust. No incident response or vulnerability disclosure information is provided. Tracking is implemented via Google Analytics and Tag Manager without a visible consent mechanism. Overall, the website is functional and professional but could improve significantly in privacy compliance, security best practices, and transparency. The domain registration is consistent with the business location but the new domain age is a point to consider. Strategic improvements in security policies, contact information visibility, and compliance documentation are recommended.

15
10
2
60
65
65
100
inkassovladjuriidilineabidebtcollectionlegalservices+1 more
BootstrapjQueryGoogle AnalyticsGoogle Tag Manager+1

Partner Domains:

placetgroup.com
partner
laen.ee
partner

+3 more partners

2025-06-26T23:33:33.809Z
waldur.com favicon

Waldur

waldur.com

46
TechnologyEstoniasmallHIGH

Waldur is a technology company specializing in an open-source hybrid cloud and HPC management platform. Their solution integrates private and public cloud resources, including OpenStack, AWS, and DigitalOcean, offering a self-service portal, billing, helpdesk, and marketplace functionalities. The company targets cloud service providers, enterprises, research institutions, and public sector organizations, positioning itself as a niche player with professional support services and a strong open-source community presence. The website content is well-structured, professionally designed, and provides comprehensive information about the product features, integrations, and documentation. Technically, the website uses a modern tech stack including ReactJS for the frontend, Jekyll for static site generation, and standard libraries like jQuery and Bootstrap. Hosting appears to be on AWS infrastructure. The site is mobile-optimized and SEO-friendly with proper meta tags and structured data. Analytics are implemented via Google Analytics and Google Tag Manager, though privacy compliance mechanisms such as cookie consent banners are missing. From a security perspective, the site enforces HTTPS and does not expose sensitive data or vulnerable libraries. However, it lacks important security headers and does not publish security policies or incident response contacts. The WHOIS data shows a consistent and long-term domain registration with no privacy protection, supporting legitimacy. Overall, the security posture is moderate but could be improved with better policy disclosures and technical hardening. The overall risk is low to moderate. Strategic recommendations include implementing privacy and cookie policies with consent mechanisms, adding security headers, publishing incident response and vulnerability disclosure information, and enabling DNSSEC for domain security. These steps will enhance trust, compliance, and security posture, supporting Waldur's professional market positioning.

15
35
17
40
72
75
40
cloudhybridcloudopensourceopenstackhpc+3 more
ReactJSJekylljQueryBootstrap 4+3
2025-06-26T23:32:28.441Z
glimstedt.lv favicon

Glimstedt

glimstedt.lv

38
FinanceLatvialargeHIGH

Glimstedt is a well-established full-service sworn law firm specializing in business law, with a history dating back to 1935. The firm serves a diverse clientele including large foreign capital companies, medium and small enterprises, and private individuals. With 14 offices in Sweden and 3 in the Baltic states, Glimstedt operates an international team of 250 professionals, emphasizing collaboration and excellence. The website reflects this professional positioning with clear branding and relevant business content. Technically, the website is built on WordPress and uses modern JavaScript libraries such as jQuery and Modernizr. The site is mobile-optimized and performs moderately well, with proper SEO meta tags and Open Graph data. However, accessibility features are basic and could be improved. The site uses HTTPS with a good SSL configuration but lacks explicit security headers and visible privacy or cookie policies. From a security perspective, the site shows a good baseline with HTTPS and no exposed sensitive data. However, the absence of security headers, privacy policies, cookie consent mechanisms, and vulnerability disclosure information indicates room for improvement in compliance and security posture. No critical vulnerabilities or WAF blocking were detected, suggesting a stable but improvable security environment. Overall, the website is professional and trustworthy, reflecting the firm's reputable market position. Strategic recommendations include implementing comprehensive privacy and cookie policies, adding security headers, publishing incident response and vulnerability disclosure information, and enhancing accessibility and compliance features to strengthen trust and security posture.

15
10
2
70
62
70
-
lawfirmbusinesslawlatvialegalservicesprofessionalservices
jQueryModernizr

Partner Domains:

glimstedt.se
partner
glimstedt.ee
partner

+1 more partners

2025-06-26T23:30:43.165Z
blindandroidusers.com favicon

Blind Android Users Podcast

blindandroidusers.com

35
MediaN/asmallHIGH

Blind Android Users Podcast is a niche media platform dedicated to providing podcast content focused on Android accessibility for blind and visually impaired users. The website hosts a podcast player with multiple recent episodes and links to popular podcast platforms such as Spotify, Amazon Music, and Apple Podcasts. The target audience is primarily blind Android users and accessibility advocates. The business model revolves around content creation and community engagement, supported by donations and social media presence. Technically, the website is built on WordPress using modern plugins including Podcast Player, Gutenberg blocks, and performance optimizations via WP Rocket. It employs HTTPS with good SSL configuration and integrates Google Tag Manager for analytics. The site is mobile-optimized and accessible, with good SEO practices evident from meta tags and structured data. However, no hosting provider or domain registration details are available, raising questions about domain legitimacy. From a security perspective, the site uses HTTPS but lacks important security headers and does not provide privacy, cookie, or terms of service policies, which are critical for compliance and user trust. No incident response or vulnerability disclosure information is present. The absence of WHOIS data for the domain is a significant concern, suggesting either a very new or unregistered domain, or use of privacy protection that is not reflected in the WHOIS query results. Overall, the website presents professional content and a good user experience but requires improvements in transparency, compliance, and security best practices. The domain legitimacy should be verified to ensure trustworthiness.

15
35
2
70
-
60
20
podcastaccessibilityblindandroidtechnology+1 more
WordPressPodcast Player pluginGutenberg blocksGoogle Tag Manager+3
2025-06-26T23:29:07.977Z
specialist.vc favicon

Specialist VC

specialist.vc

48
TechnologyEstoniamediumHIGH

Specialist VC is a venture capital fund focused on supporting early-stage technology startups primarily in Estonia, Latvia, Lithuania, Finland, Ukraine, and Belarus. The fund invests mainly in pre-seed to Series A rounds, with occasional secondary investments in later rounds. Their portfolio includes over 60 companies, many of which are recognized regional tech leaders. The website presents a professional and consistent brand image, with detailed team bios and clear contact information, positioning Specialist VC as a credible and established player in the regional VC ecosystem. Technically, the website is built on WordPress with modern plugins such as Rank Math for SEO and uses jQuery and Splide.js for interactive elements. The site is mobile-optimized and performs moderately well, with good SEO practices and accessibility features. HTTPS is enforced, ensuring secure communications. From a security perspective, the site has a solid SSL configuration but lacks some security headers and does not provide a vulnerability disclosure or incident response contact. Privacy compliance is partial, with an ESG policy page but no dedicated privacy or cookie policy pages, nor cookie consent mechanisms. Contact information is comprehensive, including multiple team emails and phone numbers. Overall, Specialist VC's website reflects a mature business with a strong market position and good technical implementation. However, improvements in privacy compliance and security best practices would enhance trust and regulatory adherence.

15
35
17
70
72
75
20
venturecapitalinvestmenttechnologystartupsb2b+3 more
WordPress 6.8.1jQuery 3.7.1Rank Math SEO pluginSplide.js slider

Partner Domains:

veriff.com
partner
bolt.eu
partner

+1 more partners

2025-06-26T23:26:57.465Z
kooliraamatukogud.ee favicon

Zone Media OÜ

kooliraamatukogud.ee

47
EducationEstoniasmallHIGH

The website kooliraamatukogud.ee serves as a digital catalog platform named RIKSWEB for Estonian school libraries, enabling users to search library collections, view item statuses, and access news literature and events. It targets educational institutions in Estonia, providing a niche service that supports library management and user engagement. The platform is operated by Zone Media OÜ, a known Estonian registrar and hosting provider, which aligns with the website's regional and sector focus. Technically, the website employs a modern yet simple technology stack including jQuery and Google Fonts, with multiple CSS stylesheets for styling and responsive design. The site is mobile-optimized and offers a clear navigation structure, although SEO optimization is minimal. No CMS or advanced frameworks are detected, indicating a custom or lightweight solution. Performance is moderate, with no evident blocking or WAF interference. From a security perspective, the site uses HTTPS and avoids exposing sensitive data or vulnerable libraries. However, it lacks important security headers and does not provide privacy or cookie policies, which are critical for GDPR compliance. No incident response or vulnerability disclosure information is available, and no contact details for security matters are provided. These gaps reduce the overall security posture and privacy compliance. Overall, the website is functional and professionally presented for its educational purpose but requires improvements in privacy compliance, security best practices, and contact transparency to enhance trust and regulatory adherence.

-
10
2
60
72
60
100
libraryeducationcatalogestoniaschool+2 more
jQuery 3.6.4Google Fonts (Open Sans, Source Sans Pro)CSS stylesheetsJavaScript custom scripts
2025-06-26T23:26:37.302Z
terviseinfo.ee favicon

Tervise Arengu Instituut

terviseinfo.ee

38
HealthcareEstoniamediumHIGH

Terviseinfo.ee is a well-established Estonian health information portal managed by the Tervise Arengu Instituut, a government-affiliated health development institute. The website provides comprehensive health promotion content, news, and educational resources targeted primarily at health promotion specialists and the general public. It covers a broad range of health topics including alcohol, HIV/AIDS, nutrition, mental health, and more, positioning itself as a trusted national resource for health information. Technically, the site is built on Joomla CMS and utilizes common JavaScript libraries such as MooTools and jQuery, along with Google Fonts and Google Analytics for tracking. The site is served over HTTPS, ensuring secure communication, and includes CSRF tokens in forms to protect against cross-site request forgery. However, it lacks explicit security headers like Content-Security-Policy and HSTS, and does not have a visible cookie consent mechanism or privacy policy page, which are important for GDPR compliance. From a security perspective, the website demonstrates a moderate security posture with secure form handling and HTTPS usage but could improve by implementing additional HTTP security headers and publishing clear privacy and cookie policies. No WAF or blocking mechanisms were detected, and the site content is fully accessible. The WHOIS data aligns well with the website's governmental health mission, showing a consistent and legitimate registration since 2011. Overall, the website is professional, trustworthy, and serves its public health mission effectively, but should enhance privacy compliance and security headers to strengthen its security posture and regulatory adherence.

20
10
2
40
72
60
20
healthinformationestoniagovernmentnewsletter+1 more
Joomla CMSMooTools JavaScriptjQueryGoogle Fonts+2

Partner Domains:

www.tai.ee
partner
heaoluprofiil.tai.ee
partner
2025-06-26T23:26:22.243Z
playversity.co favicon

Playversity

playversity.co

46
EducationUnited StatessmallHIGH

Playversity is an educational platform focused on transforming teaching through game-based learning. The website offers games, resources, learning opportunities, and programs for trainers, targeting educators and learners interested in innovative educational methods. The business is relatively new, founded in 2021, and operates primarily online with a small organizational size. The platform maintains a professional and consistent brand presence with good content quality and clear navigation. Technically, the site is built on WordPress using Elementor and several addons, hosted on HostGator. The infrastructure is modern and supports mobile responsiveness and SEO best practices. Performance is moderate, with room for improvement in accessibility and security headers. The site uses HTTPS and domain registration includes protective EPP locks, but DNSSEC is not enabled. From a security perspective, the site has a good baseline with HTTPS and domain protections but lacks critical security headers and privacy compliance documents such as privacy and cookie policies. No forms or data collection mechanisms were detected on the homepage, reducing immediate data protection concerns. The WHOIS data shows privacy protection for the registrant, which is reasonable for this business type. Overall, the website is functional and professional but should improve privacy compliance and security posture to enhance trust and regulatory adherence.

30
35
2
85
72
75
-
educationgame-basedlearningwordpresselementoronlinelearning
WordPressElementorYoast SEOjQuery+4
2025-06-26T23:25:52.189Z
mega-service.org favicon

ООО «Мега Сервис»

mega-service.org

45
TechnologyRussiamediumHIGH

ООО «Мега Сервис» is a Russian service provider specializing in maintenance, repair, and recycling of digital satellite, cable, and terrestrial receivers. The company operates a large network of over 300 authorized service centers across Russia and owns facilities for electronic waste processing in Tula and Gusev. Their business model focuses on providing professional servicing and environmentally compliant recycling solutions, targeting both end-users and partner organizations. The website content is well-structured, professionally designed, and consistent with the company's market position as a medium-sized technology service provider founded in 2009. Technically, the website employs standard web technologies including HTML5, CSS3, and jQuery libraries. It is hosted under a reputable Russian registrar with HTTPS enabled, though it lacks advanced security headers and DNSSEC. The site performs moderately well with good mobile optimization but basic accessibility and SEO features. No major technical debt or outdated technologies were detected. From a security perspective, the site benefits from HTTPS and domain transfer protection but lacks DNSSEC and security headers that could mitigate common web threats. There is no visible privacy or cookie policy, nor incident response contacts, which indicates compliance gaps especially regarding GDPR or similar regulations. No forms or user data collection mechanisms were found on the main page, reducing immediate data exposure risks but also limiting user engagement features. Overall, the website presents a moderate risk profile with good business credibility but needs improvements in privacy compliance and security best practices. Strategic recommendations include implementing DNSSEC, adding security headers, publishing privacy and cookie policies, and providing clear contact information for security incidents to enhance trust and regulatory compliance.

15
50
2
55
67
60
40
serviceelectronicsrepairrecyclingrussia+1 more
HTML5CSS3jQueryjQuery UI+1
2025-06-26T22:19:06.047Z