Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157209
Websites
130
Industries
113
Countries
52
Avg Score
Page 757 of 3145|Showing 37801-37850 of 157209
clubcompetitions-shop.com favicon

UEFA Club Competitions Online Store

clubcompetitions-shop.com

69
E-commerceN/asmallMEDIUM

The website 'UEFA Club Competitions Online Store' is an e-commerce platform dedicated to selling official merchandise related to UEFA Champions League, UEFA Europa League, and UEFA Europa Conference League. It targets football fans and consumers interested in official UEFA club competition products. The business model is retail e-commerce, leveraging the Shopify platform for its online store. The domain is newly registered in July 2024, consistent with a recent business launch. The site uses official UEFA branding and integrates Google Tag Manager and Google Ads for marketing and analytics purposes. Technically, the website is built on Shopify using the Flex theme and includes modern JavaScript libraries such as jQuery 3.6.0 and Reqwest for XHR requests. Hosting is supported by Google Cloud DNS infrastructure. The site demonstrates moderate performance and good mobile optimization, with basic accessibility features and good SEO practices. However, advanced security headers like Content Security Policy are not detected. From a security perspective, the site enforces HTTPS and has domain transfer and update locks, enhancing domain security. DNSSEC is not enabled, which is a recommended improvement. No privacy or cookie policies are found, and no incident response or vulnerability disclosure information is provided, indicating gaps in compliance and security transparency. The site does not appear to be blocked by any WAF or security challenge, and content is fully accessible. Overall, the website presents a moderate risk profile with good business credibility but lacks important privacy and security compliance elements. Strategic recommendations include publishing comprehensive privacy and cookie policies with consent mechanisms, enabling DNSSEC, implementing advanced security headers, and providing clear incident response contacts to improve trust and compliance.

75
100
17
35
75
80
100
uefae-commercesportsmerchandiseshopifyfootball+1 more
ShopifyjQuery 3.6.0Google Tag ManagerLocksmith (access control)+1
2025-10-21T17:14:24.794Z
U

UEFA

uefa.ch

63
OtherSwitzerlandlargeMEDIUM

UEFA.com is the official digital presence of the Union of European Football Associations, the governing body for football in Europe. The website serves as a comprehensive platform for football fans, media, and stakeholders, offering news, live scores, video content, and detailed information about UEFA's competitions and initiatives. UEFA holds a leading position in European and global football, organizing prestigious tournaments such as the UEFA Champions League and UEFA EURO. The site targets a broad audience including football enthusiasts, clubs, and national associations. Technically, the website employs modern web technologies including React, integrates multiple analytics and marketing tools such as Google Analytics and OneTrust for cookie consent, and uses secure HTTPS protocols with strong security headers. The site is well-optimized for mobile devices and accessibility, providing a fast and user-friendly experience. From a security perspective, UEFA.com demonstrates good practices with HTTPS enforcement, security headers, and privacy compliance mechanisms. However, explicit security policies, incident response contacts, and vulnerability disclosure information are not publicly available, representing areas for improvement. The absence of WHOIS data for the domain is noted but does not detract from the site's legitimacy given the strong branding and official nature. Overall, UEFA.com presents a professional, secure, and trustworthy platform with excellent content quality and technical implementation. Strategic recommendations include enhancing transparency around security policies and incident response, publishing vulnerability disclosure details, and providing data protection officer contact information to further strengthen trust and compliance.

-
73
17
70
80
75
100
sportsfootballuefaeuropeanfootballsoccer+2 more
JavaScriptReactJWPlayerGoogle Analytics+2

Partner Domains:

shopuefa.com
partner
clubcompetitions-shop.com
partner

+3 more partners

2025-10-21T17:14:14.620Z
webtrends-optimize.com favicon

Accelerate Group Ltd t/a Webtrends Optimize

webtrends-optimize.com

65
TechnologyUnited KingdommediumMEDIUM

Webtrends Optimize, operated by Accelerate Group Ltd, is a UK-based enterprise-grade SaaS platform specializing in website experimentation, AB testing, multivariate testing, and personalization to increase online conversions. The company positions itself as a market leader with a strong portfolio of services and a client base including major brands such as Microsoft, RS Components, Bupa, and Qantas. Their business model combines a powerful self-service platform with optional managed services and consulting, targeting businesses aiming to optimize digital experiences and conversion rates. The website content is professional, well-structured, and supported by strong trust signals including awards, case studies, and testimonials. Technically, the website uses modern JavaScript libraries including jQuery, integrates Google Analytics and Tag Manager, and employs secure HTTPS with enforced redirects. The site is mobile-optimized and SEO-friendly, hosted likely on a WordPress CMS platform. Security posture is good with HTTPS and no visible vulnerabilities, though HTTP security headers could be improved. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR adherence. The WHOIS data for the domain is missing, indicating either a non-registered domain or privacy protection, which slightly reduces trustworthiness. However, the professional presentation, external trust indicators, and consistent business information support the legitimacy of the site. Overall, the website demonstrates a mature digital presence with strong business credibility and technical implementation, though domain registration verification is recommended.

15
80
17
75
72
80
100
abtestingpersonalisationconversionoptimizationmultivariatetestingsaas+2 more
JavaScriptjQuery 3.6.2Google AnalyticsGoogle Tag Manager+3
2025-10-21T17:14:09.290Z
truckecopower.cz favicon

Truckecopower LTD.

truckecopower.cz

53
TransportationCzech RepublicsmallMEDIUM

Truckecopower LTD. operates a specialized business focused on software tuning and optimization services for heavy vehicles such as trucks and buses, aiming to reduce operational costs and improve engine performance. The company offers a comprehensive suite of services including engine software modifications, GPS-based vehicle monitoring, driver training for economical driving, and particulate filter cleaning. Their market position is that of a niche provider within the transportation sector in the Czech Republic, targeting fleet operators and commercial vehicle owners. Technically, the website is built on a modern stack utilizing HTML5, CSS3, Bootstrap, and jQuery, with integrations for Google Tag Manager, Facebook Pixel, and Pipedrive forms for lead capture. The site is mobile-optimized and demonstrates good SEO practices, although some improvements in accessibility and security headers could be made. Privacy compliance is well addressed with a clear privacy policy, cookie consent banner, and GDPR adherence. From a security perspective, the site enforces HTTPS and employs consent management for cookies, but lacks explicit security policies or incident response information. No critical vulnerabilities or exposed sensitive data were detected. The absence of WHOIS data limits domain trust assessment, but the website content and external partner references support legitimacy. Overall, the website presents a professional and trustworthy front for a small specialized business with moderate technical maturity and good privacy compliance. Strategic improvements in security headers and domain registration transparency would enhance trust and security posture.

20
40
17
85
85
75
20
transportationvehicleperformancesoftwaretuningfuelsavingsczechrepublic+2 more
HTML5CSS3BootstrapjQuery+3

Partner Domains:

xtuning.cz
partner
dpf-xtuning.cz
partner

+2 more partners

2025-10-21T17:13:58.973Z
beziers-mediterranee.com favicon

Office de Tourisme Béziers Méditerranée

beziers-mediterranee.com

64
HospitalityFrancemediumMEDIUM

Office de Tourisme Béziers Méditerranée operates as the official regional tourism office for the Béziers Méditerranée area in France, providing comprehensive tourism information, event listings, and booking services. The website is well-branded and professionally maintained, targeting tourists and visitors seeking cultural, leisure, and outdoor activities in the region. The business model focuses on promoting local tourism and facilitating visitor engagement through digital channels. Technically, the website is built on WordPress with a modern tech stack including jQuery, Google Analytics, Google Tag Manager, and a cookie consent platform (Axeptio). It features responsive design, good SEO practices, and accessibility considerations. The site integrates interactive maps and booking widgets enhancing user experience. Security posture is solid with HTTPS enforced and cookie consent implemented, though the absence of explicit security headers is noted. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is addressed with visible privacy and cookie policies, and GDPR consent mechanisms. Overall, the site presents a low-risk profile with strong business credibility and digital maturity. The main concern is the lack of WHOIS data, which should be investigated to confirm domain registration legitimacy. Strategic recommendations include enhancing security headers, publishing a vulnerability disclosure policy, and verifying domain registration details.

55
50
2
75
75
75
100
tourismtravelcultureeventsbooking+3 more
WordPressjQueryGoogle AnalyticsGoogle Tag Manager+4
2025-10-21T17:13:33.391Z
mysportsession.com favicon

My Sport Session

mysportsession.com

56
OtherFrancemediumMEDIUM

My Sport Session is an online platform based in France that enables users to discover and book a wide variety of sports and leisure activities without subscription or commitment. The service emphasizes flexibility, local availability, and ease of booking, targeting a broad audience interested in physical activities and leisure. The website is professionally designed with a consistent brand presence and includes user testimonials and social media integration to build trust. Technically, the website leverages modern web technologies including React and Google Tag Manager, with asynchronous and deferred script loading to optimize performance. The site is mobile-optimized and includes SEO best practices such as meta tags and Open Graph data. However, accessibility features are basic and could be improved. From a security perspective, the site enforces HTTPS and uses Google Tag Manager for analytics and marketing. There is a lack of visible security headers and no published privacy or cookie policies, which are important for GDPR compliance. The absence of WHOIS registration data for the domain is a notable concern, potentially indicating recent registration or privacy protection, which impacts trustworthiness. Overall, the platform presents a good user experience and a solid technical foundation but should enhance transparency around privacy, security policies, and contact information to improve compliance and user trust. Further verification of domain registration is recommended to confirm legitimacy.

15
35
2
75
65
80
100
sportsleisurebookingno-subscriptionfrench+1 more
JavaScriptReact (implied by data-react-helmet attributes)Google Tag ManagerGoogle Fonts
2025-10-21T17:13:28.382Z
portdelagrandemotte.fr favicon

Port de La Grande Motte (34)

portdelagrandemotte.fr

54
TransportationFrancesmallMEDIUM

Port de La Grande Motte is the official maritime port authority website serving the La Grande Motte region in France. It provides comprehensive information and services related to port operations, maritime regulations, events, and local tourism. The website targets boaters, tourists, and local residents, positioning itself as a trusted source for port-related information. The business model is focused on public service and maritime transportation facilitation. Technically, the website is built on WordPress CMS with modern plugins such as Advanced Custom Fields Pro and Rank Math SEO. It employs jQuery and integrates Google Translate for multilingual support. The site demonstrates good digital maturity with accessibility features, SEO optimization, and moderate performance. Analytics are handled via Matomo with privacy-conscious settings. From a security perspective, the site enforces HTTPS, includes essential security headers, and avoids exposing sensitive data. However, it lacks a dedicated security policy or vulnerability disclosure page, which could enhance its security posture. The WHOIS data is not publicly available, likely due to privacy protection, but the website's official nature and content consistency support its legitimacy. Overall, the website presents a low-risk profile with strong business credibility and good technical implementation. Strategic recommendations include publishing a security policy, adding vulnerability disclosure mechanisms, and enhancing incident response visibility to further strengthen trust and compliance.

60
28
2
40
62
60
100
portmaritimelagrandemottefranceofficial+2 more
WordPressPHPjQueryGoogle Translate+1
2025-10-21T17:13:12.894Z
grands-sites-occitanie.fr favicon

Tourisme en Occitanie

grands-sites-occitanie.fr

61
HospitalityFrancemediumMEDIUM

Tourisme en Occitanie is a regional tourism promotion website dedicated to showcasing the key destinations and attractions within the Occitanie region of France. It serves as an official portal providing comprehensive travel information, destination guides, and event promotion to attract tourists. The website targets travelers interested in cultural, outdoor, and leisure activities in the region. Technically, the site is built on WordPress using Elementor, with integrations for Google Tag Manager and Matomo Analytics, indicating a mature digital infrastructure. The site is well-optimized for SEO, mobile-friendly, and accessible, providing a professional user experience. Security-wise, the website enforces HTTPS and includes several security headers, although the Content-Security-Policy could be more comprehensive. Privacy compliance is strong, with clear cookie consent mechanisms and a detailed privacy policy aligned with GDPR requirements. However, the absence of WHOIS data for the domain reduces trust slightly, as domain registration details are not publicly available. Overall, the site presents a low-risk profile with good security and privacy practices but would benefit from enhanced transparency in domain registration and contact information.

65
68
2
75
72
80
40
tourismoccitanietravelregionalfrance+4 more
jQueryElementorGoogle Tag ManagerMatomo Analytics+1

Partner Domains:

www.visit-occitanie.com
partner
panier.laetis.fr
service
2025-10-21T17:13:07.876Z
L

La Grande Motte Destination Affaires

lagrandemotte-congres.com

42
HospitalityFrancesmallHIGH

La Grande Motte Destination Affaires operates the Palais des Congrès La Grande Motte, a venue specializing in hosting conferences, business events, and corporate meetings in the La Grande Motte region of France. The website presents a professional and consistent brand image, targeting event organizers and business professionals seeking event spaces and related services. The business model centers on venue rental and event support services, positioning itself as a regional leader in hospitality and business destination services. The company has been established since 2010, supported by a domain age consistent with its operational history. Technically, the website is built on WordPress using the Avada theme and several plugins such as LayerSlider and Contact Form 7. It is hosted by OVH sas, a reputable provider. The site demonstrates moderate performance and good mobile optimization, with SEO and accessibility features at a basic to good level. Google Analytics and Tag Manager are used for visitor tracking, with a cookie consent mechanism implemented to comply with GDPR requirements. From a security perspective, the site uses HTTPS and has implemented cookie consent, but lacks advanced security headers and explicit security policies or incident response information. No vulnerabilities or exposed sensitive data were detected. The WHOIS data confirms the domain's legitimacy and consistency with the business claims, enhancing trustworthiness. Overall, the website is professional, trustworthy, and suitable for its target audience, with room for improvement in security best practices and explicit policy disclosures to enhance compliance and resilience.

15
50
2
70
42
75
-
conferenceeventbusinesshospitalitylagrandemotte+1 more
WordPressAvada themeLayerSlider pluginPhoto Gallery plugin+3
2025-10-21T17:12:52.749Z
monmatomo.com favicon

Sign in - Matomo

monmatomo.com

53
TechnologyFrancesmallMEDIUM

The website monmatomo.com serves as a login portal for the Matomo analytics platform, an open-source, privacy-focused web analytics solution. The platform is hosted by Scaleway SAS, a French hosting provider, and the domain registration aligns with this hosting arrangement. The site primarily offers analytics services targeting website owners and administrators who require detailed visitor tracking and data analysis capabilities. The business model appears to be centered around providing analytics software either as a service or self-hosted solution, with a focus on privacy and data control. The platform is relatively new, with the domain registered in late 2022, indicating a growing or recently launched service. Technically, the site uses standard web technologies including JavaScript, PHP, and HTML5, with the Matomo platform as the core framework. The site enforces HTTPS, ensuring secure data transmission. However, the site lacks visible security headers and explicit privacy or cookie policies on the login page, which are important for compliance and user trust. The site’s performance and mobile optimization are basic but functional, suitable for its purpose as a login portal. From a security perspective, the site demonstrates good practices such as HTTPS enforcement, support for two-factor authentication, and client-side DoNotTrack detection. However, the absence of security headers and public security policies reduces the overall security posture. No vulnerabilities or exposed sensitive data were detected in the provided content. The WHOIS data is consistent and transparent, with no privacy protection, which supports legitimacy. Overall, the site is functional and trustworthy as a login portal for an analytics platform but would benefit from enhanced privacy disclosures, security headers, and contact information to improve compliance and user confidence. Strategic recommendations include enabling DNSSEC, publishing comprehensive privacy and security policies, and implementing security headers to strengthen the security posture.

50
50
25
55
72
80
20
analyticsmatomologinprivacytracking
Matomo AnalyticsJavaScriptPHPHTML5+1
2025-10-21T17:12:27.034Z
D

以优惠的价格购买过期域名用于SEO

domstocks.asia

34
TechnologySpainsmallHIGH

The website domstocks.asia operates as a specialized platform offering expired domain names primarily for SEO purposes. It targets SEO professionals, website builders, and link sellers, providing a curated selection of domains with good SEO metrics and no spam history. The business model focuses on fixed low pricing without auctions, aiming to serve a broad international clientele, especially in France and Spain. The site content is presented mainly in Chinese with some French, reflecting a multilingual approach to reach diverse markets. Technically, the site uses modern front-end frameworks such as Bootstrap and Material Design Bootstrap, ensuring a responsive and visually appealing user experience. However, the site lacks a CMS indication and detailed hosting information. Security-wise, HTTPS is enabled but lacks advanced security headers and policies, and no incident response or vulnerability disclosure information is provided. The absence of privacy and cookie policies indicates compliance gaps, particularly regarding GDPR. WHOIS data is unavailable due to malformed queries, limiting trust and transparency regarding domain registration details. Overall, the site is functional and professional but requires improvements in security, privacy compliance, and transparency to enhance trust and reduce risk.

15
35
2
60
-
75
20
seoexpireddomainsdomainsaleschinesefrench+2 more
BootstrapMaterial Design BootstrapFont AwesomeStatcounter

Partner Domains:

www.domainepremium.fr
partner
www.refdomaine.com
partner

+2 more partners

2025-10-21T16:57:38.312Z
domstocks.com favicon

Domain Name News, Publications and Services

domstocks.com

51
TechnologyN/asmallMEDIUM

OnlineStrat.com is a niche website dedicated to providing comprehensive resources, news, and tools related to the domain name industry. It targets domain name professionals, enthusiasts, and organizations by offering directories of key players, industry news, publications, and event information. The site positions itself as an information hub within the domain name ecosystem, focusing on education and resource sharing rather than commercial sales or services. Technically, the website employs a modern tech stack including Bootstrap, jQuery, Font Awesome, and integrates third-party services such as Google Maps API, Statcounter analytics, and Brevo (Sendinblue) forms. The site is mobile-optimized and uses HTTPS, but lacks some advanced security headers and formal privacy or cookie policies, indicating room for improvement in compliance and security hardening. From a security perspective, the site shows a moderate posture with HTTPS enabled and no visible vulnerabilities or exposed sensitive data. However, the absence of privacy policies, cookie consent mechanisms, and WHOIS registrant data reduces trust and compliance levels. The missing WHOIS data is a notable concern, as it may indicate recent registration or privacy restrictions, which impacts domain legitimacy assessment. Overall, the website is functional, informative, and safe for general audiences, but it would benefit from enhanced transparency, improved security headers, and formalized privacy and contact information to strengthen trust and compliance.

15
35
47
85
62
75
20
domainnamesdomainindustryinternetgovernancedomainnewsdomaintools+1 more
Bootstrap CSSFont AwesomejQueryOwl Carousel+3
2025-10-21T16:57:33.303Z
noviny.sk favicon

Slovenská produkčná, a.s.

noviny.sk

64
MediaSlovakialargeMEDIUM

Noviny.sk is a prominent Slovak online news portal operated by Slovenská produkčná, a.s., a media company based in Bratislava, Slovakia. The website offers a wide range of news content including politics, economy, sports, crime, weather, and multimedia such as videos and podcasts. It targets a general audience seeking up-to-date news and information. The business model relies primarily on advertising revenue, supported by multiple ad networks and programmatic bidding technologies integrated into the site. The portal is part of a larger media group including joj.sk and jojgroup.sk, enhancing its market position in the Slovak media landscape. Technically, the website employs modern JavaScript modules, header bidding with Prebid.js, and multiple analytics and advertising platforms such as Google Analytics, Facebook Pixel, Gemius, Smart AdServer, and Teads. Consent management is handled via the Didomi CMP, ensuring GDPR compliance mechanisms are in place. The site is mobile-optimized with good SEO practices and structured data markup to enhance search engine visibility. From a security perspective, the site enforces HTTPS and uses consent management for privacy compliance. However, explicit security headers like Content-Security-Policy and X-Frame-Options are not visibly implemented, and there is no public security policy or incident response contact information. No vulnerabilities or exposed sensitive data were detected in the provided HTML content. Overall, the security posture is moderate but could be improved with additional headers and transparency. The overall risk assessment is low, with the site appearing legitimate, professionally managed, and compliant with basic privacy regulations. Strategic recommendations include publishing clear privacy and terms of service pages, enhancing security headers, and providing incident response contacts to improve trust and compliance.

55
25
17
85
75
75
100
newsmediaslovakiaonlinenewsadvertising+2 more
JavaScript ES modulesPrebid.js for header biddingGoogle Tag ManagerGoogle Analytics+6

Partner Domains:

joj.sk
partner
jojgroup.sk
partner

+1 more partners

2025-10-21T16:57:07.227Z
chaty.app favicon

Chaty

chaty.app

64
TechnologyN/amediumMEDIUM

Chaty is a technology company offering a SaaS chat widget solution that integrates multiple popular messaging platforms such as WhatsApp, Facebook Messenger, Telegram, and more into a single widget for websites. The company targets website owners, e-commerce businesses, and customer support teams aiming to improve customer engagement and conversion rates. With over 300,000 websites using Chaty and a strong base of positive reviews, Chaty holds a solid market position in the customer communication tools sector. Technically, the website is built on WordPress with modern JavaScript libraries and supports multiple platforms including Shopify, Wix, and BigCommerce, reflecting a mature and versatile digital infrastructure. The site is mobile-optimized, accessible, and SEO-friendly, providing a good user experience. Security-wise, Chaty enforces HTTPS, implements key security headers, and avoids exposing sensitive data, though it lacks a publicly visible security policy or incident response plan. Privacy compliance is partially addressed with a comprehensive privacy policy and GDPR page, but the absence of a cookie consent mechanism is a notable gap. Overall, Chaty presents a trustworthy and professional online presence with room for improvement in privacy and security transparency.

30
65
2
75
75
80
100
chatwidgetcustomerengagementwhatsappbuttonfacebookmessengerlivechat+4 more
WordPressjQueryAOS (Animate On Scroll)Slick Carousel+2

Partner Domains:

chatway.app
partner
premio.io
partner
2025-10-21T16:56:47.183Z
goyer.cloud favicon

Site en construction

goyer.cloud

53
OtherFrancesmallMEDIUM

The website goyer.cloud is currently a placeholder page indicating that the site is under construction. It is hosted and registered through OVHcloud, a reputable French hosting provider. The site content is minimal, consisting primarily of a 'Site en construction' message in French, with links to OVHcloud support resources. There is no business-specific content, contact information, or policies published at this time. From a technical perspective, the site uses basic HTML and CSS with no advanced frameworks or CMS detected. The hosting infrastructure is OVHcloud, but no security headers or DNSSEC are enabled, representing minor security gaps. The site is mobile responsive at a basic level but lacks SEO optimization and accessibility features. Security posture is minimal with no HTTPS enforcement details available and no privacy or cookie policies present. No forms or data collection mechanisms are implemented, reducing immediate data protection concerns but also indicating a lack of business maturity. The domain registration is consistent and legitimate, created recently in April 2023, matching the site's under construction status. Overall, the site currently poses low risk but also offers limited business credibility or user engagement. Strategic recommendations include enabling DNSSEC, implementing security headers, publishing privacy and cookie policies, and adding contact information to improve trust and compliance.

15
50
2
70
75
75
100
placeholderunderconstructionovhcloudfrenchbasic
HTML5CSS3OVHcloud hosting
2025-10-21T16:56:32.155Z
C

Waiting for the redirectiron...

culture-com.fr

46
OtherFrancesmallHIGH

The website culture-com.fr is currently inaccessible beyond a security check page that performs an automated redirect after a brief countdown. The visible content is minimal and primarily consists of a loading animation and a message indicating a security check by BitNinja.IO. The site appears to be built on outdated CMS platforms, Joomla 1.5 and WordPress 2.5, which are no longer supported and pose significant security risks. No business-specific content, contact information, or privacy-related policies are present on the accessible page, limiting the ability to assess the company's operations or market positioning. Technically, the site is hosted by OVH, a reputable French hosting provider, and the domain registration details are consistent with the .fr TLD and French origin. However, the lack of modern security headers, absence of HTTPS enforcement visible in the content, and outdated CMS versions indicate a weak security posture. The presence of a security check page suggests some level of protection against automated threats, but the overall security implementation is minimal and outdated. From a security perspective, the site lacks essential compliance elements such as privacy and cookie policies, GDPR indicators, and contact channels for incident response. The use of legacy CMS versions exposes the site to known vulnerabilities. The security score is low, and the site is effectively blocked from full analysis due to the WAF/security challenge. No adult or explicit content is detected, and the site appears safe for general audiences. Overall, the website requires significant improvements in content availability, security modernization, privacy compliance, and business transparency to enhance trustworthiness and operational effectiveness.

20
25
2
60
52
80
100
joomlawordpressdrupal
Joomla 1.5WordPress 2.5
2025-10-21T16:56:27.146Z
eiffagerail.com favicon

Eiffage

eiffagerail.com

58
TransportationFrancelargeMEDIUM

Eiffage Rail is a large French company specializing in the design, construction, maintenance, and management of railway infrastructure both in France and internationally. It operates as a key partner to public and private railway transport operators, offering a comprehensive range of services including track construction, renewal, catenary systems, safety, and equipment maintenance. The company is part of the larger Eiffage group, a well-established construction and infrastructure conglomerate with multiple subsidiaries. The website reflects a professional and consistent corporate identity, emphasizing certifications and trustworthiness. Technically, the website uses a modern tech stack including jQuery, video APIs, Google reCAPTCHA, and consent management tools, built on the Jahia CMS platform. It is mobile-optimized with good SEO and basic accessibility features. Security posture is strong with HTTPS, reCAPTCHA, and cookie consent, though explicit security headers and incident response information are lacking. The WHOIS data is unavailable, which raises some concerns about domain registration transparency; however, the website content and branding strongly align with the legitimate Eiffage Rail business. No blocking or WAF challenges were detected, and the site is fully accessible. Privacy and cookie policies are present and GDPR compliant. Overall, the site is trustworthy and professionally maintained, with room for improvement in security policy transparency and accessibility. Strategic recommendations include enhancing security headers, publishing incident response and vulnerability disclosure policies, improving accessibility compliance, and providing explicit data protection officer contact details to strengthen trust and compliance.

45
50
2
40
75
70
100
railwayinfrastructureconstructionmaintenancetransport+4 more
jQuery 3.7.1YouTube iframe APIVimeo Player APIGoogle reCAPTCHA v2+3

Partner Domains:

www.eiffage.com
parent
www.eiffageconstruction.com
subsidiary

+3 more partners

2025-10-21T16:56:07.107Z
eiffagegeniecivil.com favicon

Eiffage

eiffagegeniecivil.com

58
TransportationFranceenterpriseMEDIUM

Eiffage Génie Civil is a division of the Eiffage Group specializing in the design, construction, and maintenance of civil engineering infrastructures both terrestrial and maritime across France, Europe, and internationally. The company offers a broad range of services including demolition, depollution, deep foundations, nuclear industrial civil engineering, water and environmental engineering, pipelines, and maritime works. It targets business and public sector clients requiring large-scale infrastructure projects. The website reflects a large enterprise with consistent branding and multiple subsidiaries, indicating a strong market position in the transportation and construction sectors. Technically, the website employs modern JavaScript libraries such as jQuery, YouTube and Vimeo APIs, Google reCAPTCHA, and analytics tools like Piano Analytics and TagCommander. It is built on the Jahia CMS platform, optimized for mobile, and includes accessibility features. SEO and metadata are well implemented, with Open Graph and JSON-LD structured data present. Cookie consent and privacy policies are implemented, indicating compliance with GDPR. From a security perspective, the site uses HTTPS with good SSL configuration and includes reCAPTCHA for form protection. However, explicit security headers like Content-Security-Policy and X-Content-Type-Options are not detected. No explicit security or incident response policies or vulnerability disclosure mechanisms are found. The WHOIS data is missing or unavailable, which raises concerns about domain registration legitimacy, though the website content and branding suggest a legitimate enterprise. Overall, the website is professional and trustworthy with good technical and privacy compliance. The lack of WHOIS data and explicit security policies are areas for improvement. Strategic recommendations include enhancing security headers, publishing incident response and vulnerability disclosure policies, and clarifying domain registration information.

45
65
2
40
65
70
100
civilengineeringconstructioninfrastructureeiffagefrance+1 more
jQuery 3.7.1YouTube iframe APIVimeo Player APIGoogle reCAPTCHA v2+2

Partner Domains:

www.eiffage.com
parent
www.eiffageroute.com
subsidiary

+3 more partners

2025-10-21T16:55:57.090Z
eiffageconstruction.com favicon

Eiffage

eiffageconstruction.com

54
Real EstateFranceenterpriseMEDIUM

Eiffage Construction is a major construction and real estate development company operating primarily in France and Europe. As a subsidiary of the Eiffage group, it offers expertise in construction, urban development, real estate promotion, and maintenance services. The website reflects a professional corporate presence with consistent branding and clear navigation aimed at business and public sector clients. Technically, the site uses modern JavaScript libraries and analytics tools, including jQuery, Google reCAPTCHA, and Piano Analytics, and appears to be built on the Jahia CMS platform. The site is mobile-optimized and includes accessibility features, although explicit security headers are not detected in the provided content. The WHOIS data for the domain is missing or unavailable, which is unusual for a corporate domain and warrants further investigation. Privacy compliance is supported by a cookie consent mechanism, but explicit privacy and terms of service pages were not found in the provided content. Overall, the website is professional and trustworthy, but the lack of WHOIS data and explicit contact/security policies are areas for improvement.

45
65
2
40
65
40
100
constructionrealestateurbandevelopmentcorporatefrance+2 more
jQuery 3.7.1YouTube iframe APIVimeo Player APIGoogle reCAPTCHA+2

Partner Domains:

www.eiffage-amenagement.fr
subsidiary
www.eiffage-immobilier-corporate.fr
subsidiary

+3 more partners

2025-10-21T16:55:37.049Z
demarches-simplifiees.fr favicon

Démarches Simplifiées / Direction interministérielle du numérique (DINUM)

demarches-simplifiees.fr

74
GovernmentFrancelargeMEDIUM

Démarches Simplifiées is a French government digital platform designed to facilitate online administrative procedures for citizens and public administration agents. It serves as a centralized service to submit and manage administrative files, significantly reducing processing times and improving user experience. The platform is backed by the Direction interministérielle du numérique (DINUM), ensuring strong governmental support and legitimacy. The website features professional design, clear navigation, and comprehensive content tailored to its target audience of general public users and government agents. Technically, the website employs modern web technologies including Ruby on Rails, StimulusJS, and Vite for asset management. It integrates privacy-respecting analytics via Matomo and error tracking through Sentry, reflecting a mature digital infrastructure. The site is mobile-optimized and accessible, with good SEO practices and performance characteristics. From a security perspective, the platform enforces HTTPS, uses CSRF tokens, and publishes a security policy and vulnerability disclosure guidelines. However, explicit security headers are not evident in the HTML content, and there is no visible cookie consent mechanism despite the presence of a cookie policy page. Incident response contact details are not explicitly provided. Overall, the security posture is strong but could be enhanced by adding recommended headers and improving privacy compliance mechanisms. The overall risk assessment is low, with high trust indicators stemming from government affiliation, open source transparency, and consistent branding. Strategic recommendations include implementing cookie consent banners, publishing incident response contacts, adding security headers, and considering a security.txt file to facilitate vulnerability reporting.

80
68
47
75
72
65
100
governmentadministrationdigitalservicesonlineproceduresfrenchgovernment+1 more
JavaScript ES6 ModulesStimulusJSMatomo AnalyticsSentry for error tracking+1
2025-10-21T16:55:27.027Z