Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149319
Websites
130
Industries
113
Countries
52
Avg Score
Page 74 of 99|Showing 3651-3700 of 4914
visitfinland.com favicon

Visit Finland

visitfinland.com

77
HospitalityFinlandmediumLOW

Visit Finland operates as the official travel guide and tourism promotion platform for Finland, providing comprehensive information about the country's nature, culture, and travel opportunities. The website serves as a key resource for tourists planning trips to Finland, offering detailed guides, event information, and cultural highlights. It is positioned as an authoritative source backed by Business Finland, the parent organization responsible for promoting Finnish business and tourism internationally. The site targets a broad audience of international travelers and tourism stakeholders. Technically, the website is built on modern web technologies including React and Next.js, ensuring fast performance, mobile responsiveness, and good accessibility. Integration with Google Tag Manager and Cookiebot indicates a mature approach to analytics and privacy compliance. The site employs HTTPS with strong security headers, reflecting a solid security posture. However, there is a lack of publicly available security policies or incident response information, which could be improved to enhance transparency. The security posture is strong with no detected vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. The absence of WHOIS data for the domain is a notable anomaly but does not detract significantly from the overall trustworthiness given the official branding and content quality. Strategic recommendations include publishing explicit security policies, adding vulnerability disclosure mechanisms, and verifying domain registration details for completeness. Overall, Visit Finland presents a professional, secure, and user-friendly platform that effectively supports Finland's tourism promotion objectives while maintaining good privacy and security standards.

70
88
25
85
95
70
100
traveltourismfinlandofficialguide+2 more
ReactNext.jsGoogle Tag ManagerCookiebot
2025-07-10T08:01:28.266Z
vr.fi favicon

VR-Yhtymä Oyj

vr.fi

67
TransportationFinlandlargeMEDIUM

VR.fi is the official digital platform for VR-Yhtymä Oyj, Finland's primary railway operator. The website offers comprehensive services for domestic train travel including ticket sales, travel information, and customer support. It targets Finnish residents and visitors seeking sustainable and comfortable rail travel options. The company holds a strong market position as the national rail service provider with a large operational scale and a focus on environmental responsibility. Technically, the website is built on modern web technologies including React and Next.js, integrated with Contentful CMS for content management. It demonstrates excellent performance, mobile optimization, and accessibility. The site employs Google Tag Manager and Convertexperiments for analytics and A/B testing, with appropriate cookie consent mechanisms in place. From a security perspective, the site enforces HTTPS and includes standard security headers, ensuring a secure browsing experience. However, it lacks a dedicated security policy or incident response page and does not publish a vulnerability disclosure or security.txt file, which could enhance transparency and trust. Overall, VR.fi presents a professional, trustworthy, and user-friendly platform aligned with its business goals. Strategic improvements in security transparency and incident response communication are recommended to further strengthen its security posture and compliance.

70
25
17
75
82
80
100
transportationrailwaytravelfinlandtickets+4 more
ReactNext.jsContentful CMSGoogle Tag Manager+2

Partner Domains:

www.vrgroup.fi
parent
2025-07-10T04:40:05.515Z
hromadske.radio favicon

Hromadske Radio

hromadske.radio

58
MediaUkrainemediumMEDIUM

Hromadske Radio is an independent Ukrainian radio station providing unbiased news, podcasts, and multimedia content focused on Ukraine and global events. The website serves as a digital platform for live broadcasts, podcasts, news articles, and videos, targeting a general audience interested in current affairs and cultural topics. The business operates in the media sector with a medium-sized footprint and was founded in 2017. The domain registration aligns well with the organization's identity and location in Ukraine. Technically, the website uses modern web technologies including Next.js and React, hosted with Cloudflare DNS services. It integrates multiple analytics and tracking tools such as Gemius, Microsoft Clarity, and Google Tag Manager, indicating a mature digital infrastructure. The site is mobile-optimized and offers good user experience and navigation clarity. From a security perspective, the site uses HTTPS with a good SSL configuration but lacks DNSSEC and explicit security headers. There are no visible security or incident response policies published, and privacy compliance is weak due to the absence of privacy and cookie policies or consent mechanisms. Contact information is limited to phone numbers, with no email or contact forms detected. Overall, the website is professional and trustworthy with high business credibility but has room for improvement in privacy compliance and security policy transparency. Strategic recommendations include implementing privacy and cookie policies with consent, enhancing security headers, and publishing incident response contacts to strengthen user trust and regulatory compliance.

15
35
17
85
75
60
100
mediaradionewspodcastsukraine+2 more
ReactNext.jsCloudflare DNSGoogle Tag Manager+2
2025-07-10T04:36:59.272Z
wellcome.org favicon

Wellcome

wellcome.org

64
HealthcareUnited KingdomlargeMEDIUM

Wellcome is a globally recognized charitable foundation dedicated to advancing discovery research in life sciences, health, and wellbeing. The organization focuses on critical global health challenges including mental health, infectious diseases, and climate-related health issues. Their website reflects a mature digital presence with comprehensive content aimed at researchers, policymakers, and the public, supported by a professional design and clear navigation. The foundation operates with a transparent and user-friendly approach to privacy and cookie management, demonstrating compliance with GDPR and related regulations. Technically, the website leverages modern frameworks such as Next.js and React, hosted on AWS infrastructure, and integrates Google Tag Manager for analytics and marketing. The site is optimized for performance and mobile responsiveness, with good accessibility features. Security posture is strong with HTTPS enforcement and domain protections, though DNSSEC is not enabled and explicit security policies are not published. Overall, the security posture is solid with no evident vulnerabilities or exposed sensitive data. The WHOIS data confirms a long-standing domain registration consistent with the organization's history, using privacy protection appropriately. The site maintains a high level of trustworthiness and professionalism, supported by active social media channels and clear business information.

15
68
2
85
67
85
100
healthresearchcharityglobalhealthscience+4 more
ReactNext.jsGoogle Tag ManagerWeb Vitals

Partner Domains:

funding.wellcome.org
service
wellcomecollection.org
partner
2025-07-10T03:34:24.596Z
wellcome.ac.uk favicon

Wellcome

wellcome.ac.uk

64
HealthcareUnited KingdomlargeMEDIUM

Wellcome is a globally recognized charitable foundation dedicated to advancing discovery research in life sciences, health, and wellbeing. The organization focuses on critical global health challenges including mental health, infectious diseases, and climate-related health issues. Their market position is strong, supported by a large portfolio of active grants and a significant charitable expenditure. The website reflects a professional and authoritative presence, targeting researchers, policymakers, and the general public interested in health and science. Technically, the website is built on modern frameworks such as Next.js and React, hosted on AWS infrastructure, and incorporates performance and accessibility best practices. The use of Google Tag Manager and Web Vitals indicates a mature approach to analytics and performance monitoring. The site is mobile-optimized and SEO-friendly, with structured data and meta tags properly implemented. From a security perspective, the site enforces HTTPS, employs domain status protections, and has a cookie consent mechanism aligned with GDPR requirements. However, DNSSEC is not enabled, and there is no explicit security policy or incident response contact information published. No vulnerabilities or exposed sensitive data were detected in the analysis. Overall, the website demonstrates a high level of professionalism, security, and compliance suitable for a large charitable organization. Strategic recommendations include enabling DNSSEC, publishing a formal security policy, and establishing a vulnerability disclosure program to further enhance trust and security posture.

15
68
2
85
67
85
100
healthresearchcharityscienceglobalhealth+3 more
ReactNext.jsGoogle Tag ManagerWeb Vitals+1

Partner Domains:

funding.wellcome.org
service
wellcomecollection.org
partner
2025-07-10T02:22:05.645Z
fimspeedway.com favicon

SGP - FIM Speedway

fimspeedway.com

63
TransportationN/amediumMEDIUM

The website www.fimspeedway.com serves as the official digital platform for the FIM Speedway Grand Prix and related speedway events. It offers comprehensive information including event calendars, standings, results, rider profiles, news, media access, ticket purchasing, and an e-commerce shop. The site targets speedway fans and sports enthusiasts globally, positioning itself as a central hub for speedway racing content and engagement. Technically, the site is built using modern web technologies such as React and Next.js, ensuring good mobile optimization and SEO performance. It integrates Google Tag Manager and Google Analytics for tracking and uses OneTrust for cookie consent management, reflecting a moderate level of digital maturity. The site loads with moderate speed and provides a good user experience with clear navigation and consistent branding. From a security perspective, the website enforces HTTPS and implements cookie consent mechanisms, but lacks explicit security headers and published security policies. No contact information or privacy policy was detected in the provided content, which may impact user trust and compliance with data protection regulations. The absence of WHOIS data for the domain raises concerns about domain registration legitimacy, although the website content and official social media presence suggest a legitimate operation. Overall, the site is professionally designed and functional but would benefit from enhanced transparency regarding privacy, security policies, and contact information. Verification of domain registration and addition of security best practices would strengthen its trustworthiness and compliance posture.

20
88
17
70
65
70
100
speedwaysportsmotorsportfimsgp+3 more
ReactNext.jsGoogle Tag ManagerGoogle Analytics+1
2025-07-10T01:14:51.757Z
studentagency.cz favicon

STUDENT AGENCY TRAVEL k.s.

studentagency.cz

65
TransportationCzech RepubliclargeMEDIUM

STUDENT AGENCY is a well-established Czech travel company offering a broad range of travel services including flight tickets, bus tickets, vacations, and language stays. With a market presence spanning over 30 years, it holds a strong position in the transportation sector in the Czech Republic. The website reflects a professional and comprehensive online travel agency platform targeting travelers seeking affordable and convenient travel options. The company operates multiple related domains serving different travel needs, indicating a diversified service portfolio. Technically, the website is built on modern frameworks such as Next.js and React, incorporating Google Tag Manager and reCAPTCHA for analytics and security. The site is mobile-optimized, accessible, and SEO-friendly, providing a smooth user experience. Security measures include HTTPS enforcement and standard security headers, contributing to a robust security posture. However, the absence of visible privacy and cookie policies, as well as lack of WHOIS transparency, slightly reduce the overall trust and privacy compliance score. No explicit incident response or vulnerability disclosure information is found, which could be improved to enhance security transparency. Overall, the site is secure, professional, and trustworthy with room for improvement in privacy and compliance documentation. Strategic recommendations include publishing comprehensive privacy and cookie policies with consent mechanisms, enhancing WHOIS data transparency, and establishing clear security incident response and vulnerability disclosure channels to strengthen compliance and trust.

20
73
17
85
77
70
100
travelflightsticketsvacationslanguagestays+2 more
ReactNext.jsGoogle Tag ManagerGoogle reCAPTCHA v3+1

Partner Domains:

regiojet.cz
subsidiary
regiojethotels.cz
subsidiary

+1 more partners

2025-07-09T18:28:24.651Z
sa.cz favicon

STUDENT AGENCY TRAVEL k.s.

sa.cz

66
TransportationCzech RepubliclargeMEDIUM

STUDENT AGENCY TRAVEL k.s. operates a comprehensive online travel platform primarily serving the Czech Republic. The company offers a wide range of travel-related services including flight tickets, bus tickets, holiday packages, language stays, hotel bookings, and travel insurance. With a market presence of over 30 years, it holds a strong position in the regional travel market, targeting travelers, students, and general consumers seeking affordable and convenient travel options. The website reflects a mature business model with multiple related domains and a consistent brand identity. Technically, the website is built on modern frameworks such as Next.js and React, leveraging Google Tag Manager and reCAPTCHA v3 for analytics and security. The site is well-optimized for performance, mobile responsiveness, and accessibility, providing a seamless user experience. Security best practices are observed, including HTTPS enforcement and security headers, although explicit security policies and incident response details are not publicly disclosed. The security posture is solid with no evident vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies, including GDPR adherence. Contact information is transparent, enhancing business credibility. However, the absence of WHOIS data and vulnerability disclosure mechanisms slightly reduce trust scores. Overall, the site is professional, secure, and trustworthy, suitable for general audiences without any adult or questionable content.

20
73
17
85
77
70
100
travelflightsticketsholidaylanguagestays+3 more
ReactNext.jsGoogle Tag ManagerGoogle reCAPTCHA v3

Partner Domains:

regiojet.cz
partner
regiojethotels.cz
partner

+1 more partners

2025-07-09T18:28:19.609Z
regiojet.cz favicon

RegioJet a.s.

regiojet.cz

69
TransportationCzech RepubliclargeMEDIUM

RegioJet a.s. is a well-established transportation company founded in 2009, operating primarily in the Czech Republic and across Europe. The company offers train and bus ticketing services with a strong focus on customer service and convenience. Their website reflects a mature digital presence with multilingual support, comprehensive travel options, and integration with partner services such as hotel bookings and language stays. The company holds a strong market position as a leading private transport operator in Central Europe. Technically, the website is built on modern frameworks such as Next.js and React, leveraging Google Tag Manager and reCAPTCHA for analytics and security. The site is mobile-optimized, fast, and accessible, with good SEO practices. Security posture is strong with HTTPS, security headers, and no visible vulnerabilities. Privacy compliance is well addressed with clear policies and consent mechanisms. Overall, the security posture is robust, though the site lacks a dedicated security policy and incident response contact information. No critical vulnerabilities or suspicious activities were detected. The domain registration data aligns well with the business history, supporting legitimacy and trustworthiness. The risk assessment is low, with recommendations focusing on enhancing transparency around security policies and incident response. The company demonstrates a professional and trustworthy online presence suitable for its business sector.

30
85
17
85
77
70
100
transportationtravelticketstrainbus+3 more
ReactNext.jsGoogle Tag ManagerGoogle reCAPTCHA v3

Partner Domains:

www.studentagency.cz
partner
dovolena.cz
partner

+2 more partners

2025-07-09T17:17:04.153Z
chodrockfest.cz favicon

Novinky | Chodrockfest | rockový open-air festival

chodrockfest.cz

54
HospitalityCzech RepublicsmallMEDIUM

Chodrockfest.cz is a Czech-language website dedicated to promoting and providing news about the Chodrockfest rock open-air festival. The site targets rock music fans and festival attendees primarily in the Czech Republic. The business model focuses on event promotion and information dissemination, with a local/regional market position. The website was founded in 2010, consistent with the domain registration date, and presents a professional design with good content relevance and navigation clarity. Technically, the website leverages modern web technologies including React, Next.js, and Material-UI, with Google Tag Manager integrated for analytics. The site shows moderate performance and good mobile optimization but lacks advanced accessibility features. Hosting appears to be linked to the Czech registrar WEDOS, aligning with the local focus. From a security perspective, the website lacks critical security headers and does not present privacy or cookie policies, indicating compliance gaps with GDPR and other privacy regulations. No incident response or vulnerability disclosure information is available. The absence of contact information and security policies reduces trustworthiness and business credibility. The domain WHOIS data is transparent and consistent with the website's business and location, supporting legitimacy. Overall, the website is functional and professionally designed but requires significant improvements in privacy compliance, security posture, and contact transparency to enhance trust and regulatory adherence.

15
10
17
60
85
75
100
rockfestivalopen-airmusiceventczechrepublic
ReactNext.jsGoogle FontsGoogle Tag Manager
2025-07-09T13:52:34.639Z
H

Helply

helply.com

62
TechnologyN/asmallMEDIUM

Helply is a technology company specializing in AI-powered customer support automation. Their platform offers next-generation AI agents that help service leaders scale high-quality support by learning from past tickets to improve speed and accuracy across multiple languages. Positioned as a SaaS solution, Helply targets customer support teams from startups to global industry leaders, providing services such as AI agents, knowledge management, workflow automation, and integrations with popular help desk tools. The company is part of OptimizeCX and has been operating since 2007, indicating a mature presence in the market. Technically, Helply's website is built using modern web technologies including React and Next.js, hosted on AWS infrastructure. The site demonstrates excellent performance, mobile optimization, and accessibility. Privacy and cookie consent mechanisms are implemented with a clear opt-out approach for ad and analytics storage, reflecting good privacy compliance. The domain registration is consistent with the business claims, with no privacy protection and a long domain age supporting legitimacy. From a security perspective, the website enforces HTTPS and employs cookie consent to restrict tracking by default. However, it lacks DNSSEC and some recommended security headers, and no public vulnerability disclosure or security.txt file was found. No critical vulnerabilities or exposed sensitive data were detected. Overall, the security posture is solid but could be improved by adding DNSSEC and security headers. The overall risk assessment is low, with a professional and trustworthy online presence. Strategic recommendations include enabling DNSSEC, publishing a vulnerability disclosure policy, and enhancing security headers to further strengthen the security posture and trustworthiness of the platform.

35
68
17
35
72
80
100
aicustomersupportsaasautomationtechnology+1 more
ReactNext.jsAWS DNSGoogle Tag Manager+1

Partner Domains:

optimizecx.com
partner
2025-07-09T11:24:25.365Z
fundrbird.com favicon

Fundrbird

fundrbird.com

68
FinanceN/amediumMEDIUM

Fundrbird is a specialized SaaS provider offering integrated fund operations software tailored for private equity and venture capital funds. The platform automates fund accounting, investor reporting, KYC & AML compliance, and investor onboarding, serving over 550 funds with EUR 50 billion assets under administration. The company positions itself as a mature and trusted solution with a strong client retention rate and ISO 27001:2022 certification, indicating a commitment to information security. Technically, the website is built on a modern Next.js framework with React, hosted with Cloudflare DNS and registered via Amazon Registrar. It employs Google reCAPTCHA v3 for form security and demonstrates excellent mobile optimization and performance. SEO and accessibility are well addressed, though some security headers are missing. Security posture is solid with HTTPS enforced and domain registration locks in place, but improvements are recommended such as enabling DNSSEC, adding security headers, and publishing incident response and security policies. Privacy compliance is partial; a privacy policy exists but lacks cookie consent mechanisms and GDPR compliance indicators. Overall, Fundrbird presents a professional, trustworthy, and technically sound online presence with minor gaps in privacy compliance and security best practices. Strategic enhancements in these areas would further strengthen their security posture and regulatory alignment.

40
53
17
85
77
85
100
privateequityventurecapitalfundaccountingkycaml+3 more
Next.jsReactCloudflare DNSGoogle reCAPTCHA v3
2025-07-09T04:25:55.520Z