Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 75 of 248|Showing 3701-3750 of 12372
M

Meta

messenger.com

70
TechnologyN/aenterpriseMEDIUM

Messenger.com is the official web platform for Meta's Messenger service, a leading global instant messaging and communication tool integrated with Facebook. The website offers users the ability to connect with friends and family through text, voice, and video, supporting community building and social interaction. The platform targets a broad general audience and operates under the Meta corporate umbrella, reflecting a mature and enterprise-level business model. Technically, the website employs modern web technologies including React and Facebook's proprietary BigPipe framework, ensuring fast performance and excellent mobile optimization. The infrastructure is hosted on Meta's own robust infrastructure, providing high availability and scalability. The site demonstrates good SEO and accessibility practices, with comprehensive metadata and multi-language support. From a security perspective, the site enforces HTTPS, uses secure login forms with encrypted password submission, and includes standard security headers. However, explicit cookie consent mechanisms and dedicated security policy pages are not evident, suggesting room for improvement in privacy compliance and incident response transparency. No vulnerabilities or exposed sensitive data were detected in the analyzed content. Overall, messenger.com presents a highly professional, trustworthy, and secure platform consistent with Meta's brand. The absence of WHOIS data is likely due to privacy protection and does not detract significantly from the site's legitimacy. Strategic recommendations include enhancing privacy compliance with explicit consent mechanisms, publishing security and incident response information, and providing clearer contact channels for security matters.

70
88
2
85
42
90
100
messagingsocialcommunicationmetafacebook+2 more
ReactJavaScriptCSSBigPipe+2

Partner Domains:

facebook.com
parent
2025-10-10T11:11:06.257Z
ccm.ch favicon

Connect Com AG

ccm.ch

62
EnergySwitzerlandmediumMEDIUM

Connect Com AG is a Swiss-based company specializing in fiber optic communication infrastructure solutions, serving sectors such as energy, transport, industry, and data centers. Established in 1993, the company offers a comprehensive range of products and services including fiber optic cables, building cabling, data center solutions, and installation services. Their market position is strong within Switzerland and Germany, supported by local manufacturing and logistics capabilities. The website reflects a professional B2B focus with clear product and service descriptions, customer testimonials, and a consistent brand image. Technically, the website employs modern web technologies including JavaScript frameworks, Google Tag Manager, Microsoft Clarity for analytics, and a cookie consent mechanism via Cookiefirst. The site is mobile-optimized and SEO-friendly, though it appears to use a custom or proprietary CMS. Performance is moderate with good mobile responsiveness and basic accessibility features. From a security perspective, the site uses HTTPS with a CSRF token present, indicating attention to secure form handling. However, explicit security headers like CSP or HSTS are not confirmed in the HTML content. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is partial, with a cookie consent banner but no visible privacy policy or terms of service on the main page. WHOIS data confirms the domain's legitimacy and consistency with the business claims. Overall, the website presents a low risk profile with good business credibility and technical implementation. Strategic improvements include publishing comprehensive privacy and security policies, implementing recommended security headers, and adding a vulnerability disclosure or security.txt file to enhance trust and compliance.

40
53
2
70
67
80
100
fiberopticstelecommunicationsenergytransportindustry+2 more
JavaScriptGoogle Tag ManagerMicrosoft ClarityCookiefirst Consent Banner+3
2025-10-10T10:00:56.970Z
Y

konsoleH :: Login

your-server.de

51
TechnologyGermanysmallMEDIUM

The website your-server.de serves primarily as a login portal for konsoleH, a server and account management interface likely associated with a hosting service provider. The site targets existing customers who manage their hosting accounts and webmail services. The business model revolves around providing server hosting and account administration services, with a technical infrastructure apparently hosted or supported by Hetzner, a known German hosting provider. The site content is minimal, focusing on login functionality without broader marketing or informational content. From a technical perspective, the website uses basic HTML and CSS without modern frameworks or CMS detected. The site lacks HTTPS on the main domain, which is a significant security shortfall. Mobile optimization and accessibility are minimal, and SEO practices are poor. External links point to related subdomains and Hetzner documentation, indicating some integration with the hosting provider's ecosystem. Security posture is weak due to the absence of HTTPS and security headers, exposing users to potential risks during login. No privacy, cookie, or terms of service policies are present, indicating non-compliance with GDPR and other privacy regulations. No contact or incident response information is provided, limiting transparency and trust. WHOIS data shows partial consistency but lacks detailed registrant information, slightly reducing trustworthiness. Overall, the website presents a basic, functional login portal with critical security and compliance gaps. Strategic improvements in SSL implementation, privacy compliance, and security best practices are essential to enhance trust and protect user data.

15
25
17
55
85
70
100
loginservermanagementhostingkonsolehaccountadministration
HTMLCSS
2025-10-10T09:56:25.749Z
leafletjs.com favicon

Internet Invest, Ltd. dba Imena.ua

leafletjs.com

53
TechnologyN/asmallMEDIUM

Leaflet is a well-established open-source JavaScript library specializing in mobile-friendly interactive maps. It holds a leading position in the mapping technology sector, serving developers and organizations requiring lightweight, extensible mapping solutions. The project is community-driven with a strong presence on GitHub and trusted by major technology companies. The website reflects a professional, well-maintained digital presence with excellent content quality and user experience. Technically, the site leverages modern web technologies including JavaScript, CSS, and HTML5, integrating third-party services such as OpenStreetMap and Mapbox for map tiles. The infrastructure is performant and optimized for both desktop and mobile platforms. However, there is room for improvement in security practices, particularly in enabling DNSSEC, adding security headers, and publishing privacy and cookie policies. From a security perspective, the website uses HTTPS and has domain transfer protections but lacks DNSSEC and explicit security headers. No contact information or incident response channels are provided, which limits transparency in security governance. The absence of privacy and cookie policies also indicates gaps in compliance with data protection regulations. Overall, the website is trustworthy and professionally managed but would benefit from enhanced security and privacy compliance measures to reduce risk and improve user trust.

15
35
2
60
62
70
100
javascriptopensourcemappingleafletinteractivemaps+2 more
JavaScriptCSSHTML5Google Analytics+3
2025-10-10T09:56:15.731Z
bremer-bonbon-manufaktur.de favicon

Bremer Bonbon Manufaktur

bremer-bonbon-manufaktur.de

60
RetailGermanysmallMEDIUM

Bremer Bonbon Manufaktur is a small artisanal confectionery business based in Bremen, Germany, specializing in handmade sweets such as bonbons, lollipops, fudge, and nougat. The company operates both a physical retail presence with two locations and an online shop, complemented by workshops and events targeting a broad audience including families and corporate clients. Their market position is that of a local specialty retailer with a focus on quality and craftsmanship. Technically, the website is built on the Shopware 6 e-commerce platform, leveraging modern web technologies including Google reCAPTCHA v3 for bot protection and PayPal for payment processing. The site is mobile-optimized, accessible, and SEO-friendly, with a moderate performance profile. The presence of cookie consent and privacy policies indicates a good level of digital maturity and GDPR compliance. From a security perspective, the site enforces HTTPS and integrates reCAPTCHA to protect forms, but lacks explicit mention of security headers such as X-Frame-Options or Content-Security-Policy in the HTML source. No vulnerabilities or exposed sensitive data were detected. The absence of a public security policy or incident response page suggests room for improvement in transparency and preparedness. Overall, the website presents a trustworthy and professional front for the business, with strong privacy compliance and a secure shopping experience. Strategic enhancements in security headers and incident response documentation would further strengthen their security posture and customer trust.

55
43
2
60
72
65
100
e-commerceconfectioneryhandmadesweetsshopwaregdpr+3 more
Shopware 6Google reCAPTCHA v3PayPal integrationJavaScript+1
2025-10-10T08:50:15.657Z
aha.io favicon

Aha!

aha.io

77
TechnologyN/alargeLOW

Aha! is a leading SaaS provider specializing in product development software, trusted by over one million product builders worldwide. Their comprehensive suite includes tools for roadmapping, customer interview management, idea capture, project management, and agile delivery, enhanced by a purpose-built AI assistant to accelerate workflows. The company positions itself as the world's #1 product development software, serving product teams across various industries with a focus on delivering lovable products efficiently. Technically, the website leverages modern web technologies including React, Lottie animations, and integrates with Contentful for asset management. The site is well-optimized for performance, mobile responsiveness, and accessibility, reflecting a mature digital infrastructure. SEO best practices are evident through comprehensive metadata and structured data. From a security perspective, the site enforces HTTPS and employs secure form handling and event tracking. However, explicit security headers and a public security policy are absent, indicating room for improvement in transparency and defense-in-depth. Privacy compliance is strong with clear privacy and cookie policies and consent mechanisms, aligning with GDPR requirements. Overall, the website demonstrates a high level of professionalism, trustworthiness, and business credibility. The lack of public WHOIS data is consistent with privacy protection practices common among large SaaS providers. No critical security issues or content safety concerns were identified, positioning Aha! as a reliable and secure platform for product development teams.

85
58
17
80
100
85
100
productdevelopmentproductmanagementsaasaiassistantroadmapping+4 more
ReactJavaScriptCSSLottie animations+3
2025-10-10T07:38:57.462Z
dynamed.com favicon

EBSCO Industries, Inc.

dynamed.com

68
HealthcareUnited StatesenterpriseMEDIUM

DynaMed is a leading clinical decision support platform operated by EBSCO Industries, Inc., providing evidence-based medical content, alerts, drug resources, and continuing education primarily targeting healthcare professionals and institutions. The platform is subscription-based and recognized for its authoritative medical guidance, holding prestigious awards such as the Best in KLAS Clinical Decision Support recognition. Technically, the website employs modern web technologies including React, JavaScript, and integrates advanced analytics and consent management tools such as Gainsight PX, Amplitude, Datadog RUM, and Osano CMP, reflecting a mature digital infrastructure with good performance and accessibility. Security posture is strong with HTTPS enforcement, security headers, and cookie consent mechanisms, though explicit security policies and incident response contacts are not publicly disclosed. The absence of WHOIS registration data is a notable anomaly, potentially indicating privacy protection or registration issues, but the website's branding and external references confirm its association with a reputable enterprise. Overall, the site demonstrates high professionalism, trustworthiness, and compliance with privacy regulations, making it a reliable resource for its target audience.

70
68
17
55
67
80
100
healthcaremedicalclinicaldecisionsupportsubscriptioneducation+4 more
ReactJavaScriptCSSGainsight PX+3

Partner Domains:

more.ebsco.com
partner
www.ebsco.com
parent
2025-10-10T07:36:15.221Z
nutzfahrzeuge-autohaus-ostmann.de favicon

Autohaus Ostmann GmbH & Co. KG

nutzfahrzeuge-autohaus-ostmann.de

70
TransportationGermanymediumMEDIUM

Autohaus Ostmann GmbH & Co. KG is a well-established automotive dealership group operating in the Nordhessen region of Germany, with over 60 years of experience. The company offers a broad portfolio of vehicles from Volkswagen, Volkswagen Nutzfahrzeuge, Audi, SEAT, CUPRA, ŠKODA, and MAXUS, serving both retail and commercial customers. Their services include new and used vehicle sales, servicing, repairs, parts, and fleet management, positioning them as a comprehensive automotive service provider in their regional market. The website reflects a professional and consistent brand presence aligned with Volkswagen's corporate identity. Technically, the website is built on a modern React framework integrated with Volkswagen's proprietary CMS platform, leveraging Adobe Helix RUM for performance monitoring. The site is mobile-optimized and SEO-friendly, with structured data enhancing search engine visibility. Hosting and asset delivery are managed within Volkswagen's corporate infrastructure, ensuring reliability and security. From a security perspective, the site enforces HTTPS with strong SSL configurations and implements key security headers. No critical vulnerabilities or exposed sensitive data were detected. Privacy and cookie policies are comprehensive and GDPR compliant, though explicit security policy and incident response information are not publicly detailed. The absence of a vulnerability disclosure policy suggests an area for improvement. Overall, the website demonstrates a strong digital maturity and security posture appropriate for a medium-sized automotive dealership. Strategic recommendations include publishing a dedicated security policy, enhancing incident response transparency, and adopting a vulnerability disclosure framework to further strengthen trust and compliance.

80
73
22
70
70
60
100
automotivevolkswagendealershipservicegermany+1 more
ReactAdobe Helix RUMJavaScriptCSS+1
2025-10-10T06:29:07.567Z
F

Facebook

fb.com

77
TechnologyN/aenterpriseLOW

Facebook, operated by Meta Platforms, Inc., is a leading global social networking platform that enables users to connect, share content, and engage with communities worldwide. The platform offers a variety of services including messaging, video content, business pages, and advertising solutions, positioning itself as a dominant player in the technology and social media industry. The website's design and content reflect a mature, enterprise-level digital presence with a focus on user engagement and monetization through advertising. Technically, Facebook employs a modern and robust infrastructure leveraging advanced JavaScript frameworks, asynchronous loading techniques, and secure HTTPS protocols to ensure fast, reliable, and secure user experiences across devices. The platform demonstrates strong security practices including HSTS, secure cookies, and CSRF protections on login forms, although explicit incident response and vulnerability disclosure information is not publicly detailed on the main site. Privacy compliance is well addressed with comprehensive policies and cookie consent mechanisms, reflecting adherence to GDPR and other regulations. Overall, Facebook's website exhibits high professionalism, security, and compliance, supporting its reputation as a trusted and influential technology enterprise.

85
88
2
98
65
90
100
socialnetworkingtechnologyprivacysecurityadvertising+2 more
JavaScriptReact (implied by Facebook's known stack)BigPipeHasteSupportData+4

Partner Domains:

instagram.com
subsidiary
threads.com
subsidiary

+2 more partners

2025-10-10T06:25:08.958Z
boe.es favicon

Agencia Estatal Boletín Oficial del Estado

boe.es

62
GovernmentSpainlargeMEDIUM

The Agencia Estatal Boletín Oficial del Estado (BOE) operates as the official Spanish government agency responsible for publishing the Boletín Oficial del Estado and other official journals. It serves a broad audience including legal professionals, government officials, businesses, and the general public requiring access to official legal publications. The agency holds a primary market position as the authoritative source for Spanish legal and governmental publications, offering key services such as the BOE, BORME, legal information libraries, notifications, judicial edicts, and open data services. Technically, the website employs standard web technologies including HTML5, CSS, and JavaScript, with a well-structured, accessible, and mobile-optimized design. The site demonstrates good SEO practices and clear navigation, although no advanced frameworks or CMS were detected. Performance is moderate, suitable for the content and audience served. From a security perspective, the site uses HTTPS but lacks visible security headers and explicit security policies. No vulnerabilities or exposed sensitive data were detected in the HTML content. The WHOIS data is restricted by Red.es policies typical for .es domains, which is standard and justified for government domains. Privacy and cookie policies are present but lack an explicit consent mechanism. No incident response or vulnerability disclosure policies are publicly available. Overall, the website is trustworthy, professional, and serves its governmental function effectively. Strategic improvements in security headers, cookie consent, and public security policies would enhance its security posture and compliance.

60
25
17
70
67
75
100
governmentlegalofficialpublicationsspainboe+1 more
HTML5CSSJavaScript

Partner Domains:

mpr.gob.es
partner
contrataciondelestado.es
partner

+3 more partners

2025-10-10T05:18:37.371Z