Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149319
Websites
130
Industries
113
Countries
52
Avg Score
Page 79 of 136|Showing 3901-3950 of 6767
cnil.fr favicon

Commission Nationale de l’Informatique et des Libertés

cnil.fr

66
GovernmentFrancelargeMEDIUM

The CNIL website represents the official French national data protection authority, providing comprehensive information, guidance, and regulatory enforcement related to data privacy. It serves a broad audience including individuals, professionals, and the press, positioning itself as a key government regulator in the data protection sector. The website is well-maintained with a consistent brand identity and high-quality content that supports its mission effectively. Technically, the site is built on a modern Drupal CMS platform with Bootstrap for responsive design, enhanced by privacy-respecting analytics (Matomo) and a robust cookie consent mechanism (tarteaucitron.js). Hosting and DNS are managed via Cloudflare, ensuring good performance and security. The site is mobile-optimized and accessible, though accessibility could be improved further. From a security perspective, the site enforces HTTPS with strong SSL configuration and includes standard security headers. It avoids exposing sensitive data and uses privacy-conscious analytics. However, explicit security policies, incident response information, and vulnerability disclosure mechanisms are not publicly available, representing areas for improvement. Overall, the CNIL website demonstrates a strong security posture, excellent privacy compliance, and high business credibility as a government entity. It is a trustworthy source of information on data protection in France, with minimal risk factors identified.

70
25
17
65
90
70
100
dataprotectionprivacygdprgovernmentfrance+3 more
Drupal CMSBootstrap CSS frameworkjQueryMatomo analytics+1
2025-10-10T01:45:59.577Z
autohaus-ostmann.de favicon

Autohaus Ostmann

autohaus-ostmann.de

55
TransportationGermanymediumMEDIUM

Autohaus Ostmann is a regional automotive dealership in Germany offering new and used vehicles from multiple brands including Audi, Volkswagen, Skoda, Seat, Cupra, MG, and Maxus. The company provides a comprehensive range of services such as vehicle sales, leasing offers, service appointments, and parts sales. The website is professionally designed with good navigation and mobile optimization, targeting car buyers primarily in the German regions of Wolfhagen, Bad Arolsen, and surrounding areas. The business model focuses on multi-brand vehicle retail and after-sales services, positioning itself as a trusted regional player in the transportation sector. Technically, the website uses modern web technologies including Bootstrap, FontAwesome, and JavaScript libraries. It employs Usercentrics for consent management and Matomo along with Facebook Pixel for analytics and tracking, indicating a moderate level of digital maturity and privacy awareness. Hosting is supported by Microsoft Azure DNS infrastructure, suggesting reliable backend support. The site is accessible without WAF or security challenges, and SEO practices are well implemented. From a security perspective, the site uses HTTPS and consent management but lacks visible security headers and explicit security policies. No vulnerabilities or exposed sensitive data were detected in the provided content. The absence of a privacy policy and terms of service pages reduces privacy compliance confidence. WHOIS data is consistent with a legitimate business domain without privacy protection, supporting the site's trustworthiness. Overall, Autohaus Ostmann presents a professional and trustworthy online presence with good business credibility and technical implementation. Improvements in explicit privacy documentation, security headers, and contact information visibility would enhance compliance and security posture. The site is safe for general audiences with no adult or questionable content detected.

70
68
2
60
90
70
-
automotivecardealershiptransportationvehiclesalesservice+1 more
HTML5CSS3JavaScriptFontAwesome+2

Partner Domains:

ostmann-stiftung.de
partner
ostmann-wolfhagen.audi
partner

+3 more partners

2025-10-10T00:44:01.178Z
gartencenter-meckelburg.de favicon

Meckelburg Brilon GmbH

gartencenter-meckelburg.de

64
RetailGermanymediumMEDIUM

Gartencenter Meckelburg, operated by Meckelburg Brilon GmbH, is a regional garden center based in Brilon, Germany, specializing in retail sales of plants, gardening supplies, and related services. The company maintains a professional online presence with a focus on customer service, quality products, and community engagement through newsletters and social media. Their website is well-structured, providing clear navigation and relevant content tailored to gardening enthusiasts and local customers. Technically, the site employs modern JavaScript libraries such as jQuery, Bootstrap, Splide.js, and Owl Carousel, alongside Matomo Analytics for user tracking, indicating a mature digital infrastructure. Hosting is managed via rzone.de, and the site enforces HTTPS with a good SSL configuration, contributing to a secure browsing experience. Privacy compliance is robust, featuring a detailed cookie consent mechanism and a comprehensive privacy policy in German, aligned with GDPR requirements. However, the site lacks a publicly visible security policy or incident response information, which could enhance trust and preparedness. Overall, Gartencenter Meckelburg demonstrates a solid business and technical foundation with room for improvement in explicit security communications and advanced security headers.

95
80
2
80
-
70
100
gardencenterretailgardeningplantsgiftvouchers+2 more
jQueryBootstrapSplide.jsOwl Carousel+2
2025-10-10T00:43:40.567Z
dgjw-egin.org favicon

Deutsch-Griechisches Jugendwerk (DGJW)

dgjw-egin.org

55
Non-profitGermanysmallMEDIUM

The Deutsch-Griechisches Jugendwerk (DGJW) is a non-profit organization dedicated to fostering youth exchange and cooperation between Germany and Greece. Their website clearly communicates their mission to promote understanding and collaboration among young people and youth workers in both countries. The organization offers various programs including youth encounters, professional development for youth workers, internships, and project funding. Their market position is niche but well-defined within the international youth work sector. Technically, the website is built on WordPress with modern plugins such as WPBakery Page Builder and W3 Total Cache, ensuring a responsive and performant user experience. Privacy and compliance are well addressed with GDPR-compliant privacy and cookie policies, and the use of Matomo analytics with explicit consent mechanisms. The site is hosted with a reputable registrar and uses HTTPS with good SSL configuration. From a security perspective, the site follows best practices including HTTPS, reCAPTCHA on forms, and cookie consent management. However, there is room for improvement by enabling DNSSEC and adding additional HTTP security headers. No vulnerabilities or exposed sensitive data were detected. Overall, the site demonstrates a strong security posture suitable for a non-profit organization. The overall risk assessment is low with no critical issues found. Strategic recommendations include enhancing DNS security, implementing additional security headers, and publishing a vulnerability disclosure policy to further strengthen trust and security culture.

65
80
2
70
57
80
-
non-profityouthexchangegermanygreeceinternationalcooperation+3 more
WordPressWPBakery Page BuilderW3 Total CacheMatomo Analytics+3
2025-10-10T00:38:38.070Z
bubok.es favicon

Bubok Publishing, S.L.

bubok.es

61
MediaSpainmediumMEDIUM

Bubok Publishing, S.L. operates www.bubok.es, a leading Spanish self-publishing platform specializing in independent authors seeking control over their book publishing process. The company offers a comprehensive suite of services including editorial assistance, international book distribution in both digital and physical formats, and a robust online bookstore. With over 140,000 authors worldwide, Bubok holds a strong market position in the Spanish-speaking publishing industry. The website is professionally designed, mobile-optimized, and rich in content, providing a seamless user experience for authors and readers alike. Technically, the site employs modern web technologies such as Bootstrap, jQuery, Matomo analytics, Google Tag Manager, and Facebook Pixel, ensuring effective tracking and marketing capabilities. Security measures include HTTPS enforcement, reCAPTCHA Enterprise integration, and basic security headers, though there is room for enhancement in header coverage and library updates. Privacy and cookie policies are comprehensive and GDPR compliant, with clear consent mechanisms. Contact information is prominently displayed, including phone numbers, email, and social media channels, reinforcing business credibility. WHOIS data is unavailable due to query restrictions, but no inconsistencies or suspicious patterns were detected. Overall, Bubok demonstrates a mature digital presence with strong trust signals and a secure, user-friendly platform.

50
25
17
55
75
80
100
publishingbooksself-publishingeditorialservicesindependentauthors+3 more
jQuery 1.9.1Bootstrap (glyphicons)Matomo analyticsGoogle Tag Manager+4

Partner Domains:

blavox.com
subsidiary
mylibreto.com
subsidiary

+3 more partners

2025-10-10T00:38:11.116Z
M

Municipalité d’Yverdon-les-Bains

yverdon-les-bains.ch

46
GovernmentSwitzerlandmediumHIGH

The website www.yverdon-les-bains.ch is the official digital portal for the municipal government of Yverdon-les-Bains, Switzerland. It provides comprehensive information and services related to administrative procedures, urban development, social cohesion, cultural events, sports, sustainability, and economic promotion. The site targets residents, visitors, entrepreneurs, and community members, positioning itself as a central hub for local governance and community engagement. The business model is public sector focused, delivering essential municipal services and information. Technically, the website is built on TYPO3 CMS, leveraging modern JavaScript libraries such as jQuery, Bootstrap, Slick Slider, and AOS for animations. It integrates Matomo for analytics and uses tarteaucitron.js for cookie consent management, indicating a mature digital infrastructure. The site is mobile-optimized and exhibits good SEO and accessibility practices, although some accessibility features could be enhanced. From a security perspective, the site enforces HTTPS and uses Google reCAPTCHA on forms to mitigate spam. However, it lacks visible security headers like CSP or HSTS, and no explicit security or incident response policies are published. No vulnerabilities or exposed sensitive data were detected in the HTML content. The WHOIS data confirms the domain's legitimacy, registered to a Swiss municipal entity consistent with the website's claims. Overall, the website demonstrates a high level of professionalism, trustworthiness, and content quality suitable for a government portal. Strategic improvements include publishing comprehensive privacy and security policies, implementing security headers, and enhancing accessibility compliance to further strengthen the site's security posture and user trust.

25
35
17
70
42
75
20
municipalitygovernmentyverdon-les-bainsswitzerlandtypo3+6 more
TYPO3 CMSjQueryBootstrapSlick Slider+5
2025-10-10T00:37:25.746Z
I

IATI (International Aid Transparency Initiative)

d-portal.org

57
Non-profitN/amediumMEDIUM

The d-portal website serves as a key tool within the International Aid Transparency Initiative (IATI) ecosystem, providing users with the ability to explore, search, and analyze international development and humanitarian aid data. The platform targets development professionals, NGOs, researchers, and policymakers, offering open access to detailed activity data from various reporting organizations. The site is well-branded and consistent with IATI standards, supporting multiple languages and providing helpful documentation links. Technically, the site employs a modern JavaScript stack including jQuery, Chartist.js for data visualization, and multiple analytics platforms such as Google Analytics, Matomo, and Plausible. The site is mobile-optimized with good navigation and user experience, though accessibility features are basic. Performance is moderate, with room for improvement in SEO and accessibility compliance. From a security perspective, the site uses HTTPS and avoids exposing sensitive data in the HTML. However, no explicit security headers were detected, and privacy and cookie policies are not present in the analyzed content, indicating gaps in privacy compliance. WHOIS data is unavailable or malformed, likely due to privacy protection, but the domain is consistent with the official IATI network, supporting legitimacy. Overall, the site is a credible and professional resource for aid transparency, but it would benefit from enhanced privacy disclosures, security header implementation, and accessibility improvements to strengthen its security posture and compliance.

15
58
67
80
65
55
40
iatiaidtransparencydevelopmentdatahumanitarianopendata+1 more
JavaScriptjQueryGoogle AnalyticsMatomo Analytics+3
2025-10-09T22:18:22.503Z
iatistandard.org favicon

International Aid Transparency Initiative

iatistandard.org

54
GovernmentN/amediumMEDIUM

The International Aid Transparency Initiative (IATI) operates as a global non-profit initiative focused on improving transparency in development and humanitarian aid. It provides a standardized framework and tools for publishing and accessing data on aid activities worldwide. The website reflects a mature and well-established organization with a clear mission to enhance accountability and decision-making through open data. The target audience includes development agencies, governments, civil society, and researchers. Technically, the website employs modern web technologies including HTML5, CSS3, JavaScript, and uses analytics platforms such as Matomo and Plausible for minimal user tracking. It is hosted with Cloudflare DNS services, ensuring good performance and security. The site is mobile-optimized, accessible, and well-structured, providing a professional user experience. From a security perspective, the site uses HTTPS with a good SSL configuration but lacks DNSSEC and explicit security headers in the HTML. There is no publicly available security policy or incident response information, and no vulnerability disclosure mechanism is evident. The WHOIS data indicates a consistent and legitimate domain registration dating back to 2010, supporting the organization's credibility. Overall, the website is trustworthy, professional, and technically sound but would benefit from enhanced privacy compliance measures and explicit security documentation to improve user trust and regulatory adherence.

40
53
17
65
-
70
100
aidtransparencydevelopmenthumanitarianopendata+3 more
HTML5CSS3JavaScriptMatomo Analytics+2
2025-10-09T21:08:37.455Z
tsoshop.co.uk favicon

The Stationery Office Limited

tsoshop.co.uk

62
GovernmentUnited KingdommediumMEDIUM

TSO Shop is a specialist e-commerce platform operated by The Stationery Office Limited, providing official UK government publications and specialist books targeted at academics, professionals, and businesses. The website offers a broad catalog of authoritative publications including regulatory guides, official gazettes, and best practice manuals, positioning itself as a trusted source for official and specialist content in the UK market. The company has a well-established presence since 2004, reinforcing its credibility and market position. Technically, the website employs a moderately modern technology stack including jQuery, RequireJS, and polyfills to support legacy browsers. Analytics are implemented via Google Analytics and Matomo with user consent mechanisms in place, reflecting a reasonable level of digital maturity. The site is functional with good navigation and content relevance, though some technical improvements such as updated libraries and enhanced security headers could be beneficial. From a security perspective, the site uses HTTPS and implements cookie consent with opt-in for analytics, demonstrating compliance with privacy regulations like GDPR. However, the absence of explicit security headers and use of an older jQuery version present moderate risks. No incident response or vulnerability disclosure policies are publicly available, which could be improved to enhance security posture. Overall, the website is professional, trustworthy, and compliant with privacy standards, serving its niche market effectively. Strategic improvements in security practices and technical modernization would further strengthen its resilience and user trust.

70
68
2
40
67
70
100
publishinggovernmentbooksofficialpublicationse-commerce
jQuery 3.4.1RequireJSPromise polyfillFetch polyfill+4
2025-10-09T20:03:28.688Z
T

TSO (The Stationery Office)

thegazette.co.uk

65
GovernmentUnited KingdommediumMEDIUM

The Gazette is the UK's official public record publication, established in 1665 and published by TSO under the authority of His Majesty's Stationery Office, part of The National Archives. It serves as a trusted source for official notices including insolvency, wills and probate, company data, and historical archives. The website targets businesses, legal professionals, government entities, and the general public seeking authoritative public records. Its business model includes providing official notices, data services, and archival access with paid options for notice placement and data subscriptions. Technically, the website employs modern JavaScript libraries such as RequireJS and Modernizr, uses Matomo Analytics with consent management, and integrates a live chat widget for customer support. The site is moderately optimized for performance and mobile devices, with good accessibility and SEO practices. The presence of cookie consent banners and privacy policies indicates a mature approach to privacy compliance. From a security perspective, the site enforces HTTPS and uses cookie consent mechanisms to manage analytics tracking. However, it lacks explicit security policy pages and incident response information, and security headers are not visibly present in the HTML. No vulnerabilities or exposed sensitive data were detected. Overall, the security posture is solid but could be improved with additional transparency and technical controls. The domain WHOIS data is unavailable due to Nominet UK restrictions, consistent with the domain being government-controlled. This lack of public WHOIS data does not detract from the site's legitimacy given its official status. The site is trustworthy, professionally maintained, and safe for general audiences.

80
83
17
75
-
80
100
officialgovernmentpublicrecordukdataservice+4 more
JavaScriptMatomo AnalyticsRequireJSModernizr+1

Partner Domains:

www.nationalarchives.gov.uk
partner
www.tsoshop.co.uk
partner
2025-10-09T18:52:13.750Z
scor.com favicon

SCOR

scor.com

71
FinanceFranceenterpriseMEDIUM

SCOR is a leading global reinsurance company headquartered in France, offering a broad portfolio of innovative Property & Casualty, Life & Health, and Investment solutions. The company targets insurance firms and investors, positioning itself as a financially solid and innovative market leader. The website reflects a mature digital presence with comprehensive corporate, investor, and compliance information, supporting transparency and trust. Technically, the site is built on Drupal 10 with modern web technologies including Matomo analytics for privacy-respecting user tracking, lazy loading images, and embedded multimedia content. The site is mobile-optimized, accessible, and SEO-friendly, providing a fast and professional user experience. From a security perspective, the website enforces HTTPS, uses security cookies, and implements a robust cookie consent mechanism aligned with GDPR. No critical vulnerabilities or exposed sensitive data were detected. However, explicit security headers like Content-Security-Policy could be improved, and a security.txt file is absent. Overall, the domain WHOIS data is unavailable, likely due to privacy protection, but the website's professional content and compliance posture support legitimacy. The risk profile is low, with recommendations to enhance security transparency and incident response visibility.

75
68
10
65
82
80
100
reinsurancefinancecorporateinvestorscompliance+3 more
Drupal 10Matomo AnalyticsBootstrapLazySizes (lazy loading images)+1

Partner Domains:

foundation.scor.com
subsidiary
scor-ip.com
subsidiary

+1 more partners

2025-10-09T14:15:38.323Z
rootbsd.net favicon

NetActuate

rootbsd.net

68
TechnologyUnited StatesmediumMEDIUM

NetActuate is a technology company specializing in global edge infrastructure, cloud, networking, and AI services, with a strong emphasis on BSD-based hosting solutions. The company has integrated RootBSD since 2015, expanding its footprint and service capacity. Their market position is that of a medium-sized, reputable provider with a focus on high-performance, scalable infrastructure for enterprises and developers. The website reflects a professional and consistent brand with comprehensive service offerings including AI inference, GPU as a service, colocation, and advanced networking solutions. Technically, the website is built on Webflow CMS and leverages modern analytics and tag management tools such as Google Tag Manager, Matomo, and Plausible. The site is fast, mobile-optimized, and well-structured with good SEO and accessibility practices. Hosting appears to be on NetActuate's own infrastructure or via Cloudflare CDN. The cookie consent mechanism is robust and GDPR compliant, indicating a mature privacy posture. Security-wise, the site enforces HTTPS and employs layered consent management, but lacks explicit security headers and a published security.txt file. Certifications such as SOC 1, SOC 2, SOC 3, and PCI DSS are prominently displayed, enhancing trust. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of WHOIS data for the domain introduces some uncertainty about domain registration legitimacy. Overall, the website presents a low-risk profile with strong business credibility and technical maturity. Strategic recommendations include adding explicit security headers, publishing vulnerability disclosure information, and clarifying incident response contacts to further enhance security posture and trust.

30
80
25
77
75
75
100
technologycloudedgeinfrastructurebsdhostingai+3 more
Google Tag ManagerMatomo AnalyticsPlausible AnalyticsWebflow CMS+2

Partner Domains:

anycast.com
partner
tranquil-hosting.com
subsidiary
2025-10-09T14:13:02.505Z
lpi.org favicon

Linux Professional Institute (LPI)

lpi.org

62
TechnologyN/amediumMEDIUM

Linux Professional Institute (LPI) is a well-established non-profit organization specializing in global Linux and open source certification and career support. It holds a strong market position as the world's first and largest vendor-neutral Linux certification body, serving over 350,000 certified professionals across more than 180 countries. The organization offers a comprehensive portfolio of certifications, training partnerships, and community engagement programs, targeting IT professionals, educators, and organizations worldwide. Technically, the website is built on a modern WordPress CMS with a robust tech stack including Bootstrap, Elementor, and various performance and analytics tools such as Matomo and Google Tag Manager. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, providing a fast and user-friendly experience. From a security perspective, the site enforces HTTPS, employs cookie consent mechanisms, and integrates CAPTCHA for form protection. While explicit security headers are not fully confirmed, no critical vulnerabilities or exposed sensitive data were detected. The absence of WHOIS data due to privacy protection is justified given the organization's non-profit status and global presence. Overall, the website reflects a high level of professionalism, trustworthiness, and compliance with privacy regulations, making it a reliable resource for Linux certification and open source community support.

40
95
25
70
67
70
40
linuxopensourcecertificationeducationnon-profit+3 more
WordPress 6.8.3BootstrapSlick CarouselFontAwesome 6.4.0+6

Partner Domains:

home.pearsonvue.com
partner
cs.lpi.org
partner

+3 more partners

2025-10-09T14:11:56.922Z