Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 773 of 800|Showing 38601-38650 of 39984
guarantee.money favicon

ООО «Айкюсофт»

guarantee.money

65
FinanceRussiamediumMEDIUM

The website guarantee.money operates as an escrow service platform primarily targeting Russian-speaking users. It facilitates secure transactions between buyers and sellers by acting as a trusted third party holding funds in escrow until transaction conditions are met. The business is positioned as a medium-sized technology and finance service founded in 2017, with a focus on online marketplaces, arbitration, and payment link generation. The company behind the service is ООО «Айкюсофт», based in Russia. Technically, the site is built on a modern React and Next.js stack with Material-UI for UI components, indicating a contemporary digital infrastructure. However, the site suffers from a critical security shortcoming: the absence of a valid SSL certificate and proper HTTPS support, which undermines user trust and data security. While HSTS headers are configured, they are ineffective without valid SSL. Privacy and terms of service pages exist but cookie consent mechanisms are missing, indicating partial privacy compliance. Contact information is limited to an email address at iqsoft.company, with no phone or physical address provided. Overall, the site is functional and content-rich but requires urgent security improvements to meet industry standards and user expectations.

70
40
25
70
100
70
100
escrowsafetransactionssecurepaymentsarbitrationpaymentlinks+1 more
ReactNext.jsMaterial-UIJavaScript+1

Partner Domains:

iqsoft.company
partnerpending
2025-06-15T10:26:32.553Z
C

Consorci Administració Oberta De Catalunya

seu-e.cat

50
GovernmentSpainmediumMEDIUM

EACAT is a mature government-operated digital platform serving the Catalan public administrations by providing electronic administration services and facilitating inter-administrative communication. The platform targets public sector entities within Catalonia and has been operational for over 15 years, reflecting a stable market position within the regional government sector. The website content and branding are consistent with official government services, supported by domain registration details matching the registrant organization and country. Technically, the website employs legacy JavaScript libraries such as jQuery 1.8.2 and Modernizr 2.6.2, with backend technologies based on Microsoft Visual Studio .NET and C#. Hosting is via Amazon AWS DNS infrastructure. Performance is suboptimal with a slow load time and large page size. Mobile optimization and accessibility are basic, and SEO practices are minimal. The site lacks a CMS and uses custom-built code. From a security perspective, the site has critical deficiencies including the absence of a valid SSL/TLS certificate, no HTTPS support, and no security headers. DNS records show valid SPF and DMARC configurations, but CAA records are malformed. No incident response or security policy information is provided. Sensitive login forms transmit credentials without encryption, posing significant risk. Privacy compliance is weak, with no cookie consent mechanism despite use of tracking scripts like Google Tag Manager and Lucky Orange. Overall, the website presents moderate business credibility as a government service but suffers from critical security and privacy shortcomings. Immediate remediation of SSL/TLS configuration and implementation of security best practices is essential to protect user data and maintain trust. Enhancing privacy compliance and modernizing technical infrastructure would further improve the platform's digital maturity and user experience.

15
25
17
60
75
70
100
governmente-administrationcataloniapublicservicesauthentication
JavaScriptjQuery 1.8.2Modernizr 2.6.2Google Tag Manager+2
2025-06-15T10:01:56.556Z
A

Atom

threesixty.com

53
TechnologyUnited StateslargeMEDIUM

Atom.com operates a comprehensive online marketplace specializing in premium domain name sales, branding contests, and related services such as trademark filing and audience research. The website for ThreeSixty.com serves as a landing page for a high-value domain sale, offering multiple purchase options including buy now, installments, and escrow services. The platform targets businesses and entrepreneurs seeking brandable domain names and branding solutions, positioning itself as a trusted and established player in the domain marketplace industry since 2011. Technically, the website employs modern JavaScript frameworks and monitoring tools such as New Relic and Intercom, hosted on Amazon AWS infrastructure. While the site is mobile-optimized and features good navigation and content quality, it suffers from critical security shortcomings including the absence of a valid SSL certificate and missing security headers, which significantly impact its security posture. From a security perspective, the lack of HTTPS and security headers exposes users to potential risks and undermines trust. However, the presence of a purchase protection program, verified domain badges, and clear contact information contribute positively to business credibility. The domain registration data aligns well with the website's claims, indicating legitimacy. Overall, while the business model and content quality are strong, immediate remediation of security issues is essential to enhance user trust and compliance. Strategic improvements in SSL deployment, security headers, and privacy mechanisms will elevate the platform's security and privacy compliance, supporting its market position and customer confidence.

60
25
25
50
50
85
100
domainsalesbrandingnamingcontestspremiumdomainsaitools+1 more
JavaScriptNew Relic Browser AgentIntercomCloudflare Insights+3

Partner Domains:

atom.com
partner65
2025-06-15T09:18:27.404Z
guggenheim-bilbao.eus favicon

FUNDACION DEL MUSEO GUGGENHEIM BILBAO

guggenheim-bilbao.eus

31
Non-profitSpainlargeHIGH

The Museo Guggenheim Bilbao is a prominent non-profit cultural institution based in Bilbao, Spain, managed by the FUNDACION DEL MUSEO GUGGENHEIM BILBAO. The website serves as a comprehensive portal for visitors to plan their visits, explore exhibitions, and access educational resources. It targets a broad audience interested in art, culture, and museum experiences. The museum holds a strong market position as an internationally recognized art venue with strategic partnerships and sponsorships from government and corporate entities. Technically, the website leverages modern web technologies including Next.js and React, with a headless WordPress CMS backend. It integrates accessibility tools and multimedia content hosted on Vimeo. The site is mobile-optimized and SEO-friendly, providing a good user experience and navigation clarity. From a security perspective, the site currently lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability impacting user trust and data security. Other security headers and best practices are partially implemented, but the absence of HTTPS significantly lowers the security posture. Overall, the website is professionally designed and content-rich, but the lack of HTTPS is a major risk. Strategic recommendations include immediate SSL/TLS deployment, enabling HSTS, and improving certificate management to enhance security and user trust.

15
25
25
50
50
70
-
museumartcultureeducationnon-profit+2 more
Next.jsReactJavaScriptVimeo (video hosting)+2

Partner Domains:

guggenheim.org
parentpending
guggenheim-venice.it
sisterpending
2025-06-15T09:03:17.984Z
visitsanmarino.com favicon

Ufficio del Turismo

visitsanmarino.com

46
GovernmentSan MarinosmallHIGH

The website visitsanmarino.com serves as the official tourism portal for the Republic of San Marino, providing comprehensive information on events, travel planning, cultural experiences, shopping, and outdoor activities. It targets tourists and visitors interested in exploring San Marino, positioning itself as the authoritative source for tourism-related content in the country. The business model is government-driven, focusing on promoting tourism and cultural heritage. Technically, the site is built on Magnolia CMS and served via Apache, utilizing JavaScript libraries including jQuery and Google Tag Manager for analytics and marketing. The site is multilingual and mobile-optimized, though performance data suggests potential slowness. Accessibility and SEO are basic but functional. From a security perspective, the site lacks a valid SSL certificate and HTTPS support, which is a critical vulnerability. Security headers are minimal, and no advanced security policies or incident response information are published. Cookie consent mechanisms are absent despite the use of tracking tools, indicating privacy compliance gaps. Overall, the site is legitimate and trustworthy as an official government tourism resource but requires urgent improvements in security and privacy compliance to protect users and enhance trust.

20
25
25
50
50
70
100
tourismsanmarinoeventstravelculture+1 more
ApacheJavaScriptjQueryGoogle Tag Manager+1

Partner Domains:

terradisanmarino.com
partneranalyzing...
sanmarinopertutti.com
partnerpending

+3 more partners

2025-06-15T08:58:34.034Z
goodmorningamerica.com favicon

ABC News

goodmorningamerica.com

51
MediaUnited StatesenterpriseMEDIUM

GoodMorningAmerica.com is the official website for Good Morning America, a flagship morning news and lifestyle program under ABC News, owned by The Walt Disney Company. The site offers a rich mix of news, entertainment, lifestyle content, and affiliate e-commerce deals, targeting a broad audience interested in current events, culture, wellness, and shopping. The website is professionally designed with consistent branding and a strong social media presence, reflecting its position as a major media enterprise in the United States. Technically, the site leverages modern web technologies including React, AWS CloudFront CDN, and tag management tools like Google Tag Manager and Ensighten. The site is mobile-optimized and SEO-friendly, with comprehensive metadata and structured content. However, the SSL/TLS configuration is currently invalid, with no valid certificate and no modern TLS protocols enabled, which poses a significant security risk and impacts user trust. From a security perspective, while the site does not exhibit common vulnerabilities such as Heartbleed or POODLE, the lack of a valid SSL certificate and absence of security headers like HSTS reduce its security posture. Privacy policies and terms of service are comprehensive and hosted on Disney domains, indicating good privacy compliance. Contact information is limited to a web form, with no direct emails or phone numbers publicly listed. Overall, the website is a high-quality, authoritative media platform with excellent content and business credibility. The primary risk lies in its SSL/TLS misconfiguration, which should be addressed promptly to ensure secure user connections and maintain trust. Strategic improvements in security configuration and enhanced accessibility features would further strengthen the site’s digital maturity and user confidence.

15
43
17
50
50
85
100
newsmediaentertainmentlifestylee-commerce+6 more
nginxReactJavaScriptAWS CloudFront CDN+4
2025-06-15T08:38:50.770Z
S

Social Più Srl

socialpiu.com

52
HospitalitySan MarinosmallMEDIUM

Social Più Srl is a specialized social media marketing agency primarily serving the hospitality, tourism, e-commerce, and corporate sectors. The company offers tailored marketing and advertising solutions designed to drive measurable business results. The website content is professionally presented in Italian, targeting businesses in San Marino and Italy, with a clear focus on hotels, camping villages, companies, and e-commerce platforms. The company is part of the TITANKA! Spa group, indicating a structured business backing. Technically, the website is built on the TITANKA! CMS platform, using Apache server technology and incorporates modern marketing tools such as Google Analytics, Google Tag Manager, and Facebook Pixel for tracking and advertising. The site uses Bootstrap for responsive design and shows good mobile optimization and SEO practices. However, performance metrics are not available, and the site reports zero load time and page size, indicating incomplete performance data. From a security perspective, the website lacks a valid SSL/TLS certificate and does not support any TLS protocols, which is a critical vulnerability exposing users to potential data interception. Security headers like X-Frame-Options and X-Content-Type-Options are present, but the absence of HTTPS severely impacts the security posture. Privacy and cookie policies are present with consent mechanisms, showing GDPR compliance awareness, but no explicit security policy or incident response information is found. Overall, while the business and content quality are good and the company appears legitimate and professional, the lack of HTTPS is a major security risk that must be addressed immediately. Strategic recommendations include installing a valid SSL certificate, enabling modern TLS protocols, and enhancing security headers and practices to protect user data and improve trustworthiness.

40
58
25
50
50
75
100
socialmediamarketingdigitalmarketinghospitalitymarketinge-commercetourismmarketing+1 more
ApacheGoogle Analytics (gtag)Facebook PixelJavaScript+2

Partner Domains:

titanka.com
parent40
semplify.net
partner54
2025-06-15T08:38:41.255Z
Q

quartarone.it

quartarone.it

34
OtherItalysmallHIGH

The website quartarone.it is currently a parked domain page primarily serving as a placeholder indicating the domain is for sale. The site lacks substantive business content, contact information, or any form of user engagement mechanisms. The target audience appears to be domain investors or buyers interested in acquiring the domain. The business model is domain parking and resale, with no active commercial operations visible on the site. From a technical perspective, the site is minimalistic, built with basic HTML and JavaScript, hosted via ParkingCrew services. Performance is slow with a load time of over 5 seconds and minimal resources. The site lacks modern web technologies, accessibility features, and SEO optimization. Mobile optimization is basic but functional. Security posture is weak, with no HTTPS/SSL certificate configured, no security headers, no DNSSEC, and no domain protection locks enabled. This exposes the domain to potential risks such as interception and domain hijacking. No privacy or cookie policies are present, indicating poor compliance with GDPR and related regulations. Overall, the site presents a low trust profile with critical security and compliance gaps. Strategic recommendations include implementing HTTPS, enabling domain protection mechanisms, adding privacy and cookie policies, and improving website content and professionalism to enhance credibility and security.

15
-
5
50
-
75
100
domainparkingdomainforsaleplaceholderparkingcrewtypeform
HTMLJavaScript
2025-06-15T08:35:27.292Z
S

S.M.Service

sm-service.net

24
OtherSan MarinosmallCRITICAL

S.M.Service is a small, local business based in Serravalle, San Marino, providing intelligent services as suggested by its name and website title. The website content is minimal, primarily offering contact details without detailed descriptions of services or business operations. The domain is mature, registered since 2003, indicating a longstanding presence, but the online footprint is limited. Technically, the website runs on an Apache server with basic JavaScript usage but lacks modern web technologies, mobile optimization, and SEO best practices. Critically, the site does not use HTTPS, exposing visitors to security risks. There are no security headers or advanced TLS protocols enabled, and no evidence of security or privacy policies, which indicates a low level of digital maturity. From a security perspective, the absence of SSL/TLS, security headers, and privacy compliance mechanisms are significant vulnerabilities. The domain registration data is consistent and legitimate, but the website itself does not reflect strong security or privacy practices. There is no evidence of incident response or vulnerability disclosure policies. Overall, the website poses moderate risk due to lack of encryption and privacy controls. Strategic recommendations include immediate implementation of HTTPS, addition of privacy and cookie policies, and enhancement of security headers and protocols to improve trust and compliance.

15
15
5
60
-
80
20
servicecontactitaliansmallbusinesslocal
ApacheJavaScript
2025-06-15T08:35:27.194Z
unife.it favicon

Università degli Studi di Ferrara

unife.it

40
EducationItalylargeHIGH

The Università degli Studi di Ferrara is a well-established public university in Italy, providing a broad range of academic courses, research opportunities, and community engagement initiatives. The website targets students, researchers, and the general public, offering clear navigation and comprehensive institutional information. The university maintains an active presence on major social media platforms and provides transparent contact details and legal notices, enhancing trust and credibility. Technically, the website is built on the Plone CMS platform using Python and Zope technologies. While the site demonstrates good design, accessibility, and SEO practices, performance data is lacking, and the SSL/TLS configuration is critically deficient, with no valid certificate or HTTPS support detected. This significantly impacts the security posture and user trust. Security-wise, the site includes some security headers but lacks a valid SSL certificate, modern TLS protocols, and incident response contact information. Privacy and cookie policies are present and appear GDPR compliant, reflecting good privacy practices. Overall, the site is functional and professional but requires urgent improvements in SSL/TLS security to protect users and data. The domain registration data aligns well with the university's identity, showing consistency and legitimacy. No suspicious patterns or privacy protection on WHOIS are present, supporting the trustworthiness of the domain.

45
-
5
50
-
85
100
educationuniversityacademicresearchitaly+1 more
PythonZopePloneJavaScript
2025-06-15T08:35:24.251Z
bristol.ac.uk favicon

University of Bristol

bristol.ac.uk

39
EducationUnited KingdomlargeHIGH

The University of Bristol operates a comprehensive and professional website serving prospective and current students, staff, alumni, and the wider community. The site provides detailed information on undergraduate and postgraduate courses, research activities, and community engagement, positioning the university as a leading educational institution in the UK and globally. The website content is well-structured, accessible, and rich in relevant information, reflecting a strong digital presence. Technically, the website employs modern JavaScript frameworks such as StencilJS and integrates tracking and analytics tools like Google Tag Manager and TrackedWeb. However, the site suffers from significant performance issues, including a slow load time and a large page size, which could impact user experience. Mobile optimization and accessibility are well addressed, contributing positively to overall usability. From a security perspective, the website exhibits critical weaknesses, notably the absence of a valid SSL certificate and HTTPS support, exposing users to potential data interception risks. Additionally, no security headers or advanced TLS protocols are enabled, and no incident response or vulnerability disclosure policies are publicly available. Privacy compliance is strong, with comprehensive privacy and cookie policies aligned with GDPR requirements. Overall, while the University of Bristol's website excels in content quality and business credibility, urgent improvements in security infrastructure and performance optimization are necessary to enhance trust and protect users. Strategic recommendations include implementing HTTPS, enabling security headers, optimizing performance, and publishing clear security policies.

15
15
5
50
-
85
100
educationuniversityresearchcoursesstudents+1 more
JavaScriptGoogle Tag ManagerTrackedWebTermly+1
2025-06-15T08:35:24.132Z
bayequityhomeloans.com favicon

Bay Equity LLC

bayequityhomeloans.com

40
FinanceUnited StatesmediumHIGH

Bay Equity LLC operates as a full-service home mortgage lender in the United States, licensed in 48 states and DC. The company offers a range of home loan products including first-time homebuyer loans, refinancing options, and specialty loans such as FHA, Jumbo, VA, and USDA loans. Their market position is supported by a broad network of local teams and a focus on personalized service through dedicated loan officers. The website is professionally designed with clear navigation and comprehensive content aimed at homebuyers and current homeowners. Technically, the website is built on a modern React and Gatsby framework, hosted on Netlify, indicating a contemporary and scalable infrastructure. While the site is mobile-optimized and includes accessibility features, performance metrics are not available for a complete assessment. The site employs cookie consent mechanisms and integrates third-party marketing and tracking tools responsibly. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability that undermines user trust and data protection. Security headers are partially implemented, but important features like HSTS are not fully enabled. No explicit security or incident response policies are found, and there is no vulnerability disclosure or security.txt file. Overall, the business appears legitimate and well-established, but the critical security issues related to SSL/TLS must be addressed immediately to ensure secure user interactions and compliance with best practices. Strategic recommendations include fixing the SSL configuration, enabling strong security headers, and enhancing transparency around security policies.

30
43
25
40
50
85
100
mortgagehomeloansrefinanceloanofficersfirst-timehomebuyer+2 more
ReactGatsbyNetlifyJavaScript+1

Partner Domains:

bkiconnect.com
partneranalyzing...
2025-06-15T07:55:07.212Z
airfocus.com favicon

airfocus

airfocus.com

53
TechnologyN/amediumMEDIUM

airfocus is a modular product management SaaS platform designed to help product teams manage strategy, prioritize roadmaps, and align stakeholders effectively. The company positions itself as an enterprise-ready solution with strong integrations such as Jira, targeting product managers and teams seeking flexible and scalable product management tools. The website content is rich, professionally designed, and includes multiple trust indicators such as certifications and customer testimonials, reflecting a mature business presence. Technically, the website is built using modern technologies including React and Gatsby, hosted on Google Cloud infrastructure. While the site demonstrates good SEO and mobile optimization, performance metrics are not explicitly available. Security headers are implemented, but the SSL/TLS configuration is critically flawed with an invalid certificate and no TLS protocols enabled, significantly impacting the security posture. The security posture shows strengths in header implementation and compliance certifications (ISO 27001, SOC2, GDPR), but the lack of a valid SSL certificate and missing cookie consent mechanisms are notable weaknesses. No incident response or vulnerability disclosure information is publicly available, which could be improved to enhance trust. Overall, the website is professional and trustworthy from a business perspective but requires urgent remediation of SSL/TLS issues to ensure secure user interactions and compliance with best practices. Strategic recommendations include fixing the SSL certificate, enabling modern TLS protocols, implementing cookie consent, and publishing incident response details to strengthen security and privacy compliance.

75
43
25
50
50
50
100
productmanagementroadmapsaasenterpriseiso27001+3 more
ReactGatsbyGoogle FrontendJavaScript+1
2025-06-15T07:54:34.070Z
achmeamortgages.nl favicon

Achmea

achmeamortgages.nl

40
FinanceNetherlandslargeHIGH

Achmea Mortgages operates as a specialized financial services provider focusing on mortgage investments within the Dutch market. The company offers investment funds, market insights, and ESG-related reporting, targeting investors and financial professionals interested in mortgage-backed assets. The website reflects a mature business presence with consistent branding and professional content, although direct contact information is not prominently displayed. Technically, the website is built on a modern stack including React and Sitecore CMS, with integrations for consent management and analytics. However, performance is suboptimal with a slow page load time exceeding 12 seconds, which could affect user engagement. Mobile optimization and SEO appear adequate, but accessibility is basic. From a security perspective, the absence of a valid SSL certificate and HTTPS support is a critical vulnerability, severely impacting the site's security posture. Additionally, the lack of security headers and modern TLS protocols further exposes the site to risks. Privacy compliance is strong, with clear cookie and privacy policies and a consent mechanism in place. Overall, while the business credibility and content quality are good, the security deficiencies significantly reduce the trustworthiness and safety of the website. Immediate remediation of SSL and HTTPS issues is recommended to protect users and improve the site's security rating.

75
-
25
50
50
75
100
mortgagesfinanceinvestmentesgdutchmortgages
ReactSitecoreJavaScriptHarvest Consent Monitor+1
2025-06-15T07:36:36.855Z
achmeainvestmentmanagement.nl favicon

Achmea Investment Management

achmeainvestmentmanagement.nl

40
FinanceNetherlandslargeHIGH

Achmea Investment Management is a prominent Dutch asset management firm specializing in fiduciary management and impact investing for institutional and private clients. The company operates under the Achmea brand, one of the largest financial services groups in the Netherlands, and offers portfolio construction, risk management, and asset management solutions. The website reflects a professional presence with clear business focus and relevant content targeted at institutional investors and private individuals. Technically, the website is hosted on Amazon AWS infrastructure and uses standard web technologies such as JavaScript, CSS, and HTML5. However, the site suffers from slow load times and lacks modern performance optimizations. Mobile optimization and accessibility are basic but functional. SEO practices are present but could be improved. From a security perspective, the website has critical shortcomings. It lacks a valid SSL/TLS certificate, resulting in no HTTPS support, which severely impacts user trust and security posture. No security headers or advanced TLS protocols are enabled, and DNS records show malformed CAA entries and missing domain protection locks. Cookie and privacy policies are present and GDPR compliant, but incident response and vulnerability disclosure mechanisms are absent. Overall, the website is functional and professional but requires urgent security improvements, especially enabling HTTPS and correcting DNS configurations, to enhance trustworthiness and compliance.

75
-
25
50
50
60
100
financeinvestmentassetmanagementfiduciarymanagementimpactinvesting
JavaScriptCSSHTML5
2025-06-15T07:36:33.453Z