Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 8 of 17|Showing 351-400 of 827
wirtschaft.nrw favicon

MWEIMH Nordrhein-Westfalen

wirtschaft.nrw

65
GovernmentGermanylargeMEDIUM

The website wirtschaft.nrw is the official portal of the Ministry for Economic Affairs, Industry, Climate Protection and Energy of North Rhine-Westphalia, Germany. It serves as a comprehensive information hub for economic policy, industry, energy, climate protection, innovation, and digitalization initiatives within the state. The site targets businesses, entrepreneurs, policymakers, and the general public interested in these sectors. It is positioned as a trusted government source with extensive content and clear navigation. Technically, the site is built on Drupal CMS with modern web technologies including Bootstrap and Modernizr. It employs Matomo analytics with strong privacy controls respecting user consent and Do Not Track settings. The site is mobile-optimized, accessible, and performs moderately well. Hosting and domain registration are consistent with a German government entity. From a security perspective, the site uses HTTPS with good SSL configuration and cookie consent mechanisms. However, some security headers are not explicitly detected and DNSSEC is not enabled, which could be improved. There is no public security policy or incident response contact information visible. No vulnerabilities or suspicious content were found. Overall, wirtschaft.nrw demonstrates a high level of professionalism, trustworthiness, and compliance with privacy regulations. It is a safe and reliable resource for its audience. Strategic recommendations include enabling DNSSEC, enhancing security headers, publishing a security.txt file, and improving incident response visibility to further strengthen its security posture.

80
53
17
60
62
60
100
governmentenergyeconomyclimateprotectioninnovation+3 more
Drupal CMSMatomo AnalyticsBootstrapModernizr+1
2025-10-13T00:43:12.408Z
pomerleau.ca favicon

Pomerleau Inc.

pomerleau.ca

53
Real EstateCanadaenterpriseMEDIUM

Pomerleau Inc. is a leading Canadian construction company specializing in building, infrastructure, and civil engineering projects. Established in 2000, it has grown to become one of Canada's largest construction firms with revenues exceeding $4.8 billion in 2023. The company targets clients in various sectors including energy, transport, and real estate, offering comprehensive construction services with a focus on innovation and sustainability. The website reflects a professional and well-branded digital presence, supporting its market position and business model effectively. Technically, the website is built on Drupal CMS and integrates modern technologies such as Google Tag Manager and Cookiebot for analytics and privacy compliance. The site is mobile-optimized, accessible, and SEO-friendly, with structured data enhancing content discoverability. Performance is moderate, with room for optimization. From a security perspective, the site enforces HTTPS and employs a robust cookie consent mechanism, demonstrating good privacy compliance aligned with GDPR. However, there is an opportunity to enhance security posture by enabling DNSSEC, adding security headers, and publishing explicit security policies or incident response contacts. No critical vulnerabilities or suspicious indicators were detected. Overall, Pomerleau's website presents a trustworthy and professional front that aligns well with its business stature. Strategic recommendations include strengthening DNS security, enhancing HTTP security headers, and publishing formal security and incident response documentation to further build trust and compliance.

40
83
2
85
-
85
40
constructioninfrastructurecivilengineeringinnovationsustainable
Google Tag ManagerCookiebotVimeo embedDrupal CMS
2025-10-12T20:09:00.066Z
tigta.gov favicon

U.S. Treasury Inspector General for Tax Administration

tigta.gov

67
GovernmentUnited StatesenterpriseMEDIUM

The U.S. Treasury Inspector General for Tax Administration (TIGTA) operates as an independent oversight body for the Internal Revenue Service (IRS), focusing on promoting integrity, efficiency, and detecting fraud, waste, and abuse within IRS programs. The website serves as an official communication channel to provide reports, investigations, and avenues for submitting complaints related to IRS operations. The site is positioned as a trusted government resource with a clear mission and audience comprising taxpayers, government officials, and stakeholders interested in tax administration oversight. Technically, the website is built on the Drupal CMS platform and leverages the U.S. Web Design System (USWDS) for consistent government styling and accessibility. It uses modern JavaScript libraries such as Slick Carousel and is supported by Akamai CDN services for performance and security. The site demonstrates good mobile optimization, accessibility, and SEO practices, although some improvements in cookie consent and security headers could enhance compliance and security posture. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks explicit security headers and a published vulnerability disclosure or incident response policy, which are recommended best practices for government websites. The WHOIS data is unavailable due to .gov domain restrictions, but the domain's official status and consistent branding strongly support its legitimacy. Overall, the site maintains a high trust level with minor areas for improvement in privacy compliance and security transparency. The overall risk assessment is low, with recommendations focusing on enhancing security headers, implementing cookie consent mechanisms, and publishing security policies to strengthen user trust and regulatory compliance.

30
58
17
70
95
85
100
governmentirsoversighttaxadministrationfrauddetectionustreasury
JavaScriptUSWDS (U.S. Web Design System)Slick CarouselAkamai (cdn/akam)+1

Partner Domains:

www.treasury.gov
partner
www.pandemicoversight.gov
partner

+1 more partners

2025-10-12T13:08:53.562Z
connectingup.org favicon

Connecting Up | Powered by Infoxchange

connectingup.org

69
Non-profitN/amediumMEDIUM

Connecting Up, powered by Infoxchange, is a platform dedicated to providing donated and discounted technology to not-for-profit organizations. The website positions itself as an exclusive access point for non-profits to obtain software and technology from major providers such as Adobe, Microsoft, and Bitdefender. The business model focuses on supporting the non-profit sector by facilitating access to technology resources, enhancing their operational capabilities. The platform appears to be medium-sized and professionally branded, with consistent messaging and clear target audience focus. From a technical perspective, the website is built on Drupal CMS and utilizes modern front-end frameworks like Bootstrap. It integrates several analytics and marketing tools including Google Analytics, Facebook Pixel, Hotjar, and LinkedIn Insight Tag, indicating a moderate level of digital maturity and user tracking. The site is mobile optimized and demonstrates good SEO practices, though accessibility features are basic. Security-wise, the site enforces HTTPS and uses secure connections, but lacks visible security headers and explicit security policies such as incident response or vulnerability disclosure. No critical vulnerabilities or exposed sensitive data were detected in the provided content. Privacy compliance is limited, with no clear privacy or cookie policies found in the analyzed HTML content, which is a gap for GDPR and other regulations. Overall, the website is trustworthy and professional, serving a clear non-profit technology access purpose. Strategic improvements in privacy compliance, security headers, and incident response transparency would enhance its security posture and regulatory alignment.

80
53
17
65
72
90
100
non-profittechnologydiscountdonationsoftware+3 more
Drupal CMSBootstrap CSSjQueryFontAwesome+5
2025-10-12T10:57:59.117Z
greenclimate.fund favicon

Green Climate Fund

greenclimate.fund

73
GovernmentN/alargeMEDIUM

The Green Climate Fund (GCF) is an international climate finance organization dedicated to mobilizing and delivering capital to developing countries to support climate change mitigation and adaptation projects. The website reflects a well-established global entity with a strong market position as a leading climate fund. It offers comprehensive information on projects, governance, funding modalities, and partnerships, targeting governments, accredited entities, and climate finance stakeholders. Technically, the website is built on Drupal CMS with modern web technologies including Bootstrap, Modernizr, and advanced analytics tools such as Microsoft Clarity and Google Tag Manager. The site is mobile-optimized, accessible, and demonstrates good SEO practices. Performance is moderate with room for optimization. From a security perspective, the site enforces HTTPS and does not expose sensitive data. However, explicit security headers and vulnerability disclosure mechanisms are not evident. Privacy and cookie policies are present with consent mechanisms, indicating good compliance with GDPR and related regulations. Overall, the website presents a professional, trustworthy, and content-rich platform aligned with the organization's mission. The lack of WHOIS data is mitigated by the organization's global reputation and transparent content. Strategic recommendations include enhancing security headers, publishing a security.txt file, and providing clearer incident response contacts to strengthen security posture and trust.

55
58
25
80
95
90
100
climatefinancenon-profitgovernmentsustainability+2 more
Drupal CMSNew Relic monitoringGoogle Tag ManagerClarity Microsoft analytics+1

Partner Domains:

knowledge.greenclimate.fund
partner
ilearn.greenclimate.fund
partner

+2 more partners

2025-10-12T09:48:27.097Z
mostateparks.com favicon

Missouri Department of Natural Resources

mostateparks.com

66
GovernmentUnited StateslargeMEDIUM

The Missouri State Parks website is an official government platform managed by the Missouri Department of Natural Resources, providing comprehensive information about state parks, historic sites, activities, reservations, and visitor resources. The site targets a broad audience including residents, tourists, and outdoor enthusiasts, positioning itself as the primary authoritative source for Missouri State Parks. The business model is a government-operated public service with a large scope and long-established presence since 1999. Technically, the website is built on Drupal CMS with a modern tech stack including jQuery, Google Maps API, and various JavaScript libraries for enhanced user experience. Performance is moderate with good mobile optimization and basic accessibility features. The site uses third-party analytics and monitoring tools such as Google Analytics and New Relic, indicating a mature digital infrastructure. From a security perspective, the site enforces HTTPS and has domain transfer protections but lacks DNSSEC and visible security headers like CSP or HSTS. There is no visible privacy or cookie policy, which is a compliance gap. No incident response or security contact information is provided. No WAF or blocking mechanisms are detected, and no suspicious content or vulnerabilities are apparent. Overall, the website is professional, trustworthy, and content-rich but would benefit from enhanced privacy compliance and security hardening. The risk level is low, but improvements in security headers, DNSSEC, and privacy disclosures are recommended.

60
35
17
70
90
80
100
governmentstateparksoutdoorrecreationhistoricsitesmissouri+1 more
Drupal CMSjQueryGoogle Maps APIGoogle Tag Manager+3
2025-10-12T09:46:26.531Z
d-trust.net favicon

D-Trust GmbH

d-trust.net

63
TechnologyGermanymediumMEDIUM

D-Trust GmbH is a qualified trust service provider and a subsidiary of the Bundesdruckerei Group, specializing in secure digital identities and eIDAS-compliant trust services such as electronic signatures, certificates, and secure data management solutions. The company targets businesses, government entities, and private users requiring secure digital processes, particularly in healthcare and government sectors. The website is professionally designed, well-structured, and provides comprehensive information about products and services, including recent news and press releases indicating active business operations. Technically, the site is built on Drupal CMS with Bootstrap 5, optimized for mobile, and employs eTracker analytics with GDPR-compliant cookie consent mechanisms. Security posture is strong with HTTPS and good practices, though explicit security headers could be improved. WHOIS data is missing or inaccessible, which is inconsistent with the active and professional website presence, suggesting a possible WHOIS query or registry issue rather than illegitimacy. Overall, the site is trustworthy and credible, but domain registration status should be verified through alternate WHOIS sources.

70
53
17
60
77
50
100
digitaltrusteidasdigitalidentityelectronicsignaturehealthcare+2 more
Drupal CMSBootstrap 5jQuery (disabled in some scripts)eTracker analytics+2

Partner Domains:

bundesdruckerei.de
parent
support.bundesdruckerei.de
service
2025-10-12T08:36:21.367Z
amf-france.org favicon

Autorité des marchés financiers

amf-france.org

72
FinanceFrancelargeMEDIUM

The Autorité des marchés financiers (AMF) is the French financial markets regulatory authority responsible for protecting savings, informing investors, and ensuring the proper functioning of financial markets. The website serves as a comprehensive portal offering regulatory information, news, sanctions, and resources for both professionals and the general public. It holds a strong market position as a key government entity in the finance sector in France. Technically, the website is built on Drupal CMS with modern JavaScript libraries and includes cookie consent management tools. It is mobile-optimized, accessible, and performs moderately well. The site uses HTTPS with good SSL configuration and employs some security best practices, although explicit security headers are not fully confirmed. From a security perspective, the site shows a mature posture with no visible vulnerabilities or exposed sensitive data. Privacy compliance is strong with clear GDPR-aligned policies and cookie consent mechanisms. However, WHOIS data is unavailable or malformed, which limits domain registration verification and slightly impacts trustworthiness. Overall, the website is professional, trustworthy, and well-maintained, serving its regulatory and informational role effectively. Strategic recommendations include enhancing security header implementation, improving incident response visibility, and publishing vulnerability disclosure information to further strengthen security and trust.

55
68
17
75
100
80
100
financeregulationinvestorprotectiongovernmentamf+1 more
Drupal CMSJavaScriptjQueryTarteaucitron.js (cookie consent)+1

Partner Domains:

bdif.amf-france.org
service
geco.amf-france.org
service

+3 more partners

2025-10-11T23:24:28.758Z
dbsa.org favicon

Development Bank of Southern Africa

dbsa.org

70
FinanceSouth AfricalargeMEDIUM

The Development Bank of Southern Africa (DBSA) is a government-owned development finance institution focused on financing infrastructure projects to promote economic prosperity in Southern Africa. The website reflects a mature digital presence with comprehensive information about their services, sectors, and projects. The organization positions itself as a key player in infrastructure finance, climate financing, and sustainable development, targeting governments, municipalities, and investors across Africa. The site is well-branded, professionally designed, and offers multiple contact channels including forms, phone numbers, and social media links. Technically, the website is built on Drupal CMS and leverages modern web technologies such as lazy loading, Google Analytics, Google Tag Manager, and reCAPTCHA v3 for security on forms. The site is mobile optimized and accessible, with good SEO practices evident from meta tags and structured data. However, security headers are not detected in the provided data, which is an area for improvement. From a security perspective, the site uses HTTPS and implements anti-bot measures on forms, but lacks a published vulnerability disclosure or incident response contact information. The WHOIS data is unavailable or malformed, likely due to privacy protection, which is common for government entities. Overall, the site demonstrates a strong security posture but could enhance transparency and security header implementation. The overall risk assessment is low, with recommendations to improve security headers, publish vulnerability disclosure policies, and provide incident response contacts to further enhance trust and compliance. The website is professional, trustworthy, and aligns well with the organization's mission and government ownership.

95
68
2
80
62
70
100
developmentfinanceinfrastructuregovernmentafricasustainability+1 more
Drupal CMSGoogle AnalyticsGoogle Tag ManagerreCAPTCHA v3+4
2025-10-11T21:07:12.922Z
concur.com favicon

SAP Concur

concur.com

74
TechnologyUnited StatesenterpriseMEDIUM

SAP Concur is a leading provider of spend management software, integrating travel, expense, and invoice management on a unified platform. The company targets businesses of all sizes, offering AI-enabled tools to simplify and automate spend processes. As a subsidiary of SAP, Concur holds a strong market position with a comprehensive suite of products and global reach. The website reflects a mature digital presence with extensive product information, customer case studies, and multiple regional versions. Technically, the site is built on Drupal CMS with modern JavaScript libraries and integrates advanced analytics and performance monitoring tools such as New Relic and Adobe Target. The presence of TrustArc for cookie consent and Google reCAPTCHA for form security indicates a focus on privacy and security compliance. The site is mobile-optimized and accessible, providing a professional user experience. Security posture is strong with HTTPS enforced, security headers present, and no visible vulnerabilities. However, the absence of explicit security policy or incident response information is noted. Privacy compliance is well addressed with GDPR-consistent policies and consent mechanisms. Overall, the site demonstrates high trustworthiness and professionalism. Recommendations include publishing a dedicated security policy and vulnerability disclosure page, enhancing transparency around incident response, and maintaining continuous monitoring of third-party scripts and integrations to mitigate risks.

55
70
17
80
100
80
100
spendmanagementtravelexpenseinvoicesapconcur+5 more
Drupal CMSGoogle reCAPTCHATrustArc cookie consentNew Relic monitoring+1

Partner Domains:

www.concursolutions.com
partner
www.sap.com
parent

+1 more partners

2025-10-11T21:03:46.647Z
A

African Development Bank Group

afdb.org

69
FinanceIvory CoastenterpriseMEDIUM

The African Development Bank Group is a prominent regional multilateral development finance institution dedicated to fostering economic development and social progress across African countries. The website reflects a mature digital presence with comprehensive content including news, reports, projects, and sectoral information, targeting governments, investors, academia, and civil society. The institution's market position is strong, supported by extensive documentation and active engagement on multiple social media platforms. Technically, the website is built on Drupal CMS with modern libraries such as Bootstrap and Font Awesome, and integrates analytics tools like Google Analytics and Hotjar for user behavior insights. The site demonstrates good performance, mobile optimization, and accessibility features, ensuring a positive user experience. From a security perspective, the site enforces HTTPS, employs standard security headers, and avoids exposing sensitive data. However, explicit security policies and incident response contacts are not publicly detailed, representing an area for improvement. Privacy and cookie policies are present and appear GDPR compliant, enhancing user trust. Overall, the website is professional, trustworthy, and well-maintained, though the absence of WHOIS data limits domain registration verification. Strategic recommendations include publishing detailed security policies, adding vulnerability disclosure mechanisms, and enhancing transparency around data retention and incident response.

55
68
25
75
65
80
100
africadevelopmentbankfinancemultilateral+3 more
Drupal CMSjQueryBootstrap 3.4.1Font Awesome 6+3

Partner Domains:

adf.afdb.org
subsidiary
am.afdb.org
subsidiary

+3 more partners

2025-10-11T18:48:52.105Z
U

United Nations Development Programme

undp.org

55
GovernmentN/aenterpriseMEDIUM

The United Nations Development Programme (UNDP) website serves as the official digital presence of the UN's lead agency on international development. It provides extensive information about UNDP's mission to eradicate poverty, reduce inequalities, and promote sustainable development across more than 170 countries and territories. The site is well-structured, professionally designed, and targets a broad audience including governments, development partners, and the general public. It offers key services such as policy advice, capacity building, and partnership facilitation, positioning itself as a global leader in development efforts. Technically, the website is built on the Drupal CMS platform and leverages modern web technologies including Google Tag Manager, Google Analytics, Facebook Pixel, and Akamai CDN for performance and analytics. The site demonstrates good mobile optimization, accessibility, and SEO practices, ensuring a positive user experience across devices. Performance is moderate, with asynchronous loading of scripts and use of content delivery networks. From a security perspective, the site enforces HTTPS with strong SSL configuration and includes essential security headers such as Content-Security-Policy and Strict-Transport-Security. No exposed sensitive data or vulnerable libraries were detected. Privacy compliance is robust, with clear privacy and cookie policies and GDPR adherence. However, the absence of a public vulnerability disclosure policy and incident response contact details suggests room for improvement. Overall, the website reflects a mature and trustworthy digital asset consistent with the UNDP's global stature. The lack of WHOIS data is likely due to privacy protection and does not detract from the site's legitimacy. Strategic recommendations include enhancing transparency around security incident response, tightening CSP policies, and continuous monitoring of third-party scripts to maintain security posture.

25
35
25
85
-
85
100
undpunitednationsdevelopmentsustainabledevelopmentgoalspovertyeradication+3 more
Drupal CMSGoogle Tag ManagerGoogle AnalyticsLinkedIn Insight Tag+3

Partner Domains:

shop.undp.org
partner
hdr.undp.org
partner

+1 more partners

2025-10-11T18:48:42.089Z
eurazeo.com favicon

Eurazeo

eurazeo.com

72
FinanceFrancelargeMEDIUM

Eurazeo is a prominent investment group specializing in private markets asset management, including private equity, private debt, and real assets. Positioned as a leading private asset manager in Europe, Eurazeo offers a range of investment services aimed at supporting business growth and development. The website reflects a professional and comprehensive digital presence targeting investors, shareholders, and businesses seeking investment opportunities. Technically, the website leverages modern technologies such as Drupal CMS, Google Analytics, Google Tag Manager, and Cookiebot for consent management. The site demonstrates good mobile optimization, accessibility, and SEO practices, contributing to a positive user experience. Performance is moderate, with lazy loading implemented for images. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms aligned with GDPR requirements. However, explicit security headers are not clearly visible in the provided content, and no dedicated security policy or incident response contact information is found. The absence of WHOIS data for the domain raises concerns about domain registration transparency, which slightly impacts trustworthiness. Overall, Eurazeo's website is professional, secure, and privacy compliant, but it would benefit from enhanced transparency regarding domain registration and explicit security policies to strengthen trust and compliance.

65
95
2
80
75
80
100
financeinvestmentprivateequityassetmanagementgdpr+2 more
Google AnalyticsGoogle Tag ManagerCookiebotLazySizes (lazy loading images)+1
2025-10-11T16:36:38.099Z
pap.pl favicon

Polska Agencja Prasowa SA

pap.pl

62
MediaPolandlargeMEDIUM

Polska Agencja Prasowa SA operates the website pap.pl, the largest news agency portal in Poland, providing comprehensive and objective news coverage domestically and internationally. The site offers a variety of news categories including business, health, science, culture, and sports, enriched with multimedia content such as photos and videos. The company holds a strong market position as a key media entity in Poland, targeting a general audience with timely and relevant news content. Technically, the website is built on Drupal CMS and employs modern web technologies including Google Tag Manager and Hotjar for analytics and user behavior tracking. The site is mobile-optimized and features a clear navigation structure, although some accessibility features could be improved. Security posture is moderate with HTTPS usage and cookie consent mechanisms in place, but lacks visible security headers and explicit security policies. WHOIS data is unavailable, likely due to privacy protection, but the website's professional presentation and official social media presence support its legitimacy. Overall, the site is a reliable and professional media platform with room for enhancement in privacy transparency and security best practices.

35
25
17
85
69
85
100
newsmediapolandpressagencyjournalism+2 more
Google Tag ManagerHotjarGoogle FontsDoubleClick for Publishers (DFP)+1

Partner Domains:

biznes.pap.pl
service
samorzad.pap.pl
service

+3 more partners

2025-10-11T04:24:51.325Z
cnil.fr favicon

Commission Nationale de l’Informatique et des Libertés

cnil.fr

66
GovernmentFrancelargeMEDIUM

The CNIL website represents the official French national data protection authority, providing comprehensive information, guidance, and regulatory enforcement related to data privacy. It serves a broad audience including individuals, professionals, and the press, positioning itself as a key government regulator in the data protection sector. The website is well-maintained with a consistent brand identity and high-quality content that supports its mission effectively. Technically, the site is built on a modern Drupal CMS platform with Bootstrap for responsive design, enhanced by privacy-respecting analytics (Matomo) and a robust cookie consent mechanism (tarteaucitron.js). Hosting and DNS are managed via Cloudflare, ensuring good performance and security. The site is mobile-optimized and accessible, though accessibility could be improved further. From a security perspective, the site enforces HTTPS with strong SSL configuration and includes standard security headers. It avoids exposing sensitive data and uses privacy-conscious analytics. However, explicit security policies, incident response information, and vulnerability disclosure mechanisms are not publicly available, representing areas for improvement. Overall, the CNIL website demonstrates a strong security posture, excellent privacy compliance, and high business credibility as a government entity. It is a trustworthy source of information on data protection in France, with minimal risk factors identified.

70
25
17
65
90
70
100
dataprotectionprivacygdprgovernmentfrance+3 more
Drupal CMSBootstrap CSS frameworkjQueryMatomo analytics+1
2025-10-10T01:45:59.577Z
wfp.org favicon

UN World Food Programme (WFP)

wfp.org

74
Non-profitN/aenterpriseMEDIUM

The UN World Food Programme (WFP) is the world's largest humanitarian organization dedicated to saving lives in emergencies and providing food assistance to build peace, stability, and prosperity for populations affected by conflict, disasters, and climate change. The organization operates globally with a presence in over 120 countries and territories, offering a broad range of services including emergency relief, food assistance, supply chain management, and resilience building. Their business model is non-profit, relying heavily on donations and partnerships with governments, NGOs, and private sectors. The website reflects a strong market position as a leading humanitarian entity with extensive outreach and engagement capabilities. Technically, the website is built on Drupal CMS and employs a modern technology stack including Google Tag Manager, Google Analytics, TikTok Analytics, Facebook Pixel, Hotjar, and Bing Ads for analytics and marketing. The site is mobile-optimized, accessible, and SEO-friendly, with fast to moderate performance. The use of multiple languages and comprehensive content demonstrates digital maturity and global accessibility. From a security perspective, the website enforces HTTPS, implements multiple security headers, and follows best practices for secure forms and data handling. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with clear privacy and cookie policies and GDPR adherence. However, the WHOIS data is not publicly available, likely due to privacy protection, which is justified given the organization's international and humanitarian nature. Overall, the WFP website is a highly professional, trustworthy, and secure platform that effectively supports the organization's mission. Strategic recommendations include maintaining regular security audits, monitoring third-party scripts, and establishing a public vulnerability disclosure policy to further enhance security posture and transparency.

75
65
25
85
69
85
100
humanitariannon-profitfoodassistanceemergencyreliefun+3 more
Google Tag ManagerGoogle AnalyticsTikTok AnalyticsFacebook Pixel+5

Partner Domains:

donate.wfp.org
service
multimedia.wfp.org
service

+1 more partners

2025-10-09T18:55:08.878Z
mit.edu favicon

Massachusetts Institute of Technology

mit.edu

71
EducationUnited StateslargeMEDIUM

The Massachusetts Institute of Technology (MIT) is a globally recognized educational and research institution focused on advancing knowledge in science, technology, and related fields. The website serves a diverse audience including prospective and current students, faculty, researchers, alumni, and the general public. It offers comprehensive information on education, research, innovation, admissions, campus life, and alumni engagement. The site is well-branded, professionally designed, and provides rich content aligned with MIT's mission. Technically, the website is built on Drupal CMS and leverages modern web technologies including SVG graphics, asynchronous JavaScript loading, and integration with Google Analytics and Facebook Pixel for analytics and marketing. The site is mobile-optimized, accessible, and performs well with fast loading times. Security best practices are observed with HTTPS enforcement, security headers, and anonymized IP tracking. From a security perspective, the site demonstrates a strong posture with no visible vulnerabilities or exposed sensitive data. However, there is room for improvement in privacy compliance, particularly in implementing explicit cookie consent mechanisms and publishing a public security policy or incident response contact. The absence of WHOIS data is noted but likely due to registrar privacy policies rather than malicious intent. Overall, MIT's website is a high-quality, trustworthy digital presence that effectively supports its educational and research mission. Strategic recommendations include enhancing privacy compliance, publishing security policies, and maintaining vigilance on third-party scripts to sustain security and trust.

45
53
47
65
90
80
100
educationresearchtechnologyuniversityscience+1 more
Drupal CMSGoogle Tag ManagerGoogle AnalyticsFacebook Pixel+3

Partner Domains:

news.mit.edu
partner
socialmediahub.mit.edu
partner

+1 more partners

2025-10-09T10:42:18.270Z
L

LBJ Presidential Library

discoverlbj.org

62
GovernmentUnited StatesmediumMEDIUM

The Discover LBJ website serves as the official digital archive for the Lyndon B. Johnson Presidential Library, providing access to a wide range of archival collections, digitized materials, and research resources. It targets researchers, historians, students, and the general public interested in presidential history and LBJ's legacy. The site is government-operated under the National Archives and Records Administration, positioning it as a trusted and authoritative source in its niche. Technically, the website is built on Drupal CMS with modern integrations such as React and Gutenberg editor components. It leverages Cloudflare for DNS and likely CDN services, ensuring moderate performance and good mobile responsiveness. Accessibility and SEO optimizations are well implemented, contributing to a positive user experience. From a security standpoint, the site enforces HTTPS and has domain transfer protections in place. However, it lacks DNSSEC, security headers, and a formal security policy or incident response contact, which are areas for improvement. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism detected. Analytics usage includes Google Analytics and Tag Manager, indicating moderate user tracking. Overall, the website is professional, trustworthy, and well-maintained, with minor gaps in security and privacy compliance that, if addressed, would enhance its posture and user trust.

55
53
2
55
75
75
100
governmentarchivelibraryhistoryeducation+1 more
Drupal CMSReactGutenberg editorFont Awesome+1
2025-10-08T21:46:52.008Z
M

Mine Safety and Health Administration

msha.gov

65
GovernmentUnited StateslargeMEDIUM

The Mine Safety and Health Administration (MSHA) is a U.S. federal government agency under the Department of Labor dedicated to ensuring safe and healthful working conditions for miners. The website serves as a comprehensive portal for mine safety regulations, training programs, compliance assistance, enforcement data, and fatality reports. It targets miners, mine operators, government officials, and the public, providing authoritative information and resources. The site is well-branded with official government trust signals and uses a Drupal CMS infrastructure integrated with Google Tag Manager for analytics. Technically, the website is modern, mobile-optimized, and accessible, with a clear navigation structure and good SEO practices. Security posture is solid with HTTPS enforced and secure form handling, though explicit security headers and privacy policies are lacking. The WHOIS data is minimal due to the .gov domain nature, but the domain is legitimate and consistent with a government entity. Analytics usage is moderate, with some tracking via Google Tag Manager but no visible cookie consent mechanisms. Overall, the site is trustworthy and professional, though improvements in privacy compliance and explicit security headers would enhance its security and user trust. The current lapse in appropriations notice indicates a temporary pause in updates but does not affect the site's core functionality or legitimacy.

20
53
25
85
75
80
100
governmentminesafetyhealthtrainingcompliance+3 more
Drupal CMSGoogle Tag ManagerFontAwesomeUSA.gov search integration
2025-10-08T21:46:36.979Z
trisquel.info favicon

The Trisquel Project

trisquel.info

52
TechnologyN/asmallMEDIUM

The Trisquel Project operates a website dedicated to distributing Trisquel GNU/Linux, a fully free operating system aimed at home users, small enterprises, and educational centers. The project is community-driven, emphasizing software freedom and privacy. The website provides downloads, documentation, forums, and donation options, reflecting an engaged user base and active development. The market position is niche but well-established within the free software ecosystem, with a history dating back to at least 2004. Technically, the site is built on Drupal CMS with GPL-licensed JavaScript and uses jQuery. The site is moderately optimized for performance and mobile use, with good SEO practices and clear navigation. However, accessibility and mobile responsiveness could be improved. No advanced analytics or tracking services are detected, aligning with the project's privacy focus. From a security perspective, the site uses HTTPS (implied by the URL), but no explicit security headers were detected in the provided data. There is no visible security policy or incident response contact information, and no cookie consent mechanism is present, which may impact GDPR compliance. No vulnerabilities or exposed sensitive data were found in the HTML content. The WHOIS data is privacy protected, which is reasonable for this type of project, though it limits registrant transparency. Overall, the website is trustworthy and professional, with strong community and open source trust signals. Recommendations include implementing security headers, publishing a security policy, adding cookie consent for privacy compliance, and improving mobile and accessibility features to enhance user experience and compliance.

15
53
17
85
52
75
40
freesoftwarelinuxgnuopensourcecommunity+1 more
Drupal CMSjQueryGNU GPL licensed JavaScript
2025-10-08T21:42:11.066Z
archives.gov favicon

National Archives and Records Administration

archives.gov

65
GovernmentUnited StateslargeMEDIUM

The National Archives and Records Administration (NARA) is the official U.S. government agency responsible for preserving and providing access to federal records and historical documents. The website serves a broad audience including researchers, veterans, educators, and the general public, offering services such as military records requests, educational resources, and access to presidential libraries. The site is positioned as the authoritative archival institution for the United States government. Technically, the website is built on Drupal CMS with Bootstrap for responsive design, integrating modern analytics tools like Google Analytics, Google Tag Manager, and Crazy Egg for user behavior insights. The site demonstrates good mobile optimization, accessibility, and SEO practices, with structured data enhancing search engine understanding. Performance is moderate, with room for optimization. From a security perspective, the site enforces HTTPS and uses secure forms, but lacks visible security headers and published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with a comprehensive privacy policy, though cookie consent mechanisms are absent. The WHOIS data is unavailable, typical for .gov domains, but the domain's .gov status strongly supports legitimacy. Overall, the website is professional, trustworthy, and well-maintained, with minor recommendations to enhance security headers, cookie consent, and transparency around security policies to further strengthen its posture.

55
53
17
70
85
50
100
governmentarchivesrecordshistoryeducation+1 more
Google Tag ManagerGoogle AnalyticsCrazy EggjQuery+3
2025-10-08T20:33:43.952Z
mandiant.com favicon

Mandiant

mandiant.com

85
TechnologyUnited StatesenterpriseLOW

Mandiant is a leading cybersecurity company specializing in threat intelligence, incident response, and managed security services. As part of Google Cloud, it leverages extensive frontline expertise and advanced technology to help organizations defend against evolving cyber threats. The company offers a broad portfolio of services including consulting, AI security, cyber risk management, and digital risk protection, targeting enterprises and government sectors. The website reflects a mature, professional digital presence with comprehensive content and clear navigation, supporting its market leadership position. Technically, the website is built on Drupal CMS and integrates multiple modern marketing and analytics tools such as Google Analytics, Marketo, Hotjar, and various social media pixels. It is hosted on Google Cloud infrastructure, ensuring reliable performance and scalability. The site is mobile-optimized and accessible, with good SEO practices and structured data for enhanced search visibility. From a security perspective, the site enforces HTTPS and employs reCAPTCHA for form protection. While explicit security headers are not fully confirmed, the overall security posture is strong with no visible vulnerabilities or exposed sensitive data. Privacy compliance is robust, featuring clear privacy and cookie policies with consent mechanisms aligned with GDPR requirements. Overall, Mandiant's website demonstrates high professionalism, trustworthiness, and technical maturity. The only notable gap is the absence of detailed WHOIS registration data, likely due to privacy protections or registry limitations, which does not detract from the site's legitimacy given its corporate affiliation and content quality.

85
88
77
80
75
90
100
cybersecuritythreatintelligenceincidentresponsemanagedservicesconsulting+2 more
Drupal CMSGoogle Tag ManagerGoogle AnalyticsMarketo+8

Partner Domains:

cloud.google.com
partner
2025-10-08T19:22:00.586Z
redhat.com favicon

Red Hat, Inc.

redhat.com

83
TechnologyUnited StatesenterpriseLOW

Red Hat, Inc. is a leading enterprise open source software company, providing a broad portfolio of products including Red Hat Enterprise Linux, OpenShift, and Ansible Automation. As a subsidiary of IBM, Red Hat holds a strong market position in the technology sector, targeting enterprise IT professionals and developers with subscription-based software and services. The website reflects a mature digital presence with excellent content quality, clear navigation, and consistent branding. Technically, the site is built on Drupal CMS with modern JavaScript frameworks and integrates secure authentication via OpenID Connect. Privacy and security compliance are well addressed, with comprehensive policies and incident response contacts clearly provided. The security posture is strong, with HTTPS enforced and multiple security headers implemented. No vulnerabilities or suspicious content were detected. WHOIS data is unavailable, likely due to privacy or registrar policies, but this does not detract from the site's legitimacy given the strong brand and trust indicators. Overall, the website demonstrates a high level of professionalism, security, and compliance suitable for an enterprise technology leader.

80
70
55
85
100
90
100
opensourceenterpriselinuxcloudcontainer+3 more
Drupal CMSJavaScriptRed Hat CMS 1.0OpenID Connect (OIDC) for authentication+2

Partner Domains:

developers.redhat.com
subsidiary
access.redhat.com
subsidiary

+2 more partners

2025-10-08T18:17:53.642Z
gsa.gov favicon

U.S. General Services Administration

gsa.gov

65
GovernmentUnited StatesenterpriseMEDIUM

The U.S. General Services Administration (GSA) operates as a federal government agency providing comprehensive services in real estate management, acquisition, technology solutions, and travel services to government entities and the American public. The agency holds a strong market position as the primary federal provider of these services, targeting government agencies, contractors, and businesses. The website reflects a professional and authoritative presence consistent with its government mandate. Technically, the website is built on the Drupal CMS platform, leveraging the U.S. Web Design System (USWDS) for accessibility and responsive design. It integrates modern analytics and marketing tools such as Google Tag Manager and Oracle Eloqua, ensuring effective user engagement tracking while maintaining privacy compliance. The site demonstrates good performance and excellent mobile optimization. From a security perspective, the site enforces HTTPS, implements robust security headers, and follows best practices for secure forms and data handling. The presence of cybersecurity policies aligned with NIST frameworks and certifications like FedRAMP further strengthen its security posture. No significant vulnerabilities were detected, and incident response contacts are clearly provided. Overall, the GSA website presents a low-risk profile with high trustworthiness, excellent content quality, and strong compliance with privacy and security standards. Strategic recommendations include maintaining up-to-date third-party libraries, enhancing GDPR-specific disclosures, and continuing proactive security monitoring.

50
53
59
83
-
85
100
governmentprocurementrealestatetechnologytravel+3 more
Google Tag ManagerGoogle AnalyticsDrupal CMSJavaScript+2
2025-10-08T04:00:26.489Z
usa.gov favicon

USA.gov

usa.gov

70
GovernmentUnited StatesenterpriseMEDIUM

USA.gov is the official U.S. government web portal designed to make government services and information easier to find for U.S. residents and citizens. It provides comprehensive access to government benefits, programs, agencies, and critical information such as passports, Social Security, taxes, voting, and immigration. The site is operated under the U.S. General Services Administration, reinforcing its authoritative position as a trusted government resource. The business model focuses on centralized information dissemination rather than commercial activities, serving a broad audience seeking government-related assistance and resources. Technically, the website is built on the Drupal CMS and leverages modern web technologies including the US Web Design System for consistent government branding and accessibility. It integrates analytics and tracking tools such as Google Tag Manager, CrazyEgg, and Siteimprove Analytics to monitor performance and user engagement. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, ensuring a high-quality user experience across devices. From a security perspective, USA.gov enforces HTTPS with strong SSL configurations and includes essential security headers. While no critical vulnerabilities or exposed sensitive data were detected, the site could improve by adding explicit Content-Security-Policy headers and publishing a vulnerability disclosure or security.txt file. Privacy compliance is strong with a comprehensive privacy policy and security policies publicly available, though a cookie consent mechanism is not evident, possibly due to government exemptions. Overall, USA.gov exhibits a high level of trustworthiness and professionalism consistent with its role as a federal government portal. The lack of public WHOIS data is typical for .gov domains and does not detract from its legitimacy. Strategic recommendations include enhancing transparency around cookie usage, publishing incident response contacts, and further strengthening security headers to maintain and improve its security posture.

55
53
17
70
95
80
100
governmentinformationservicesusaofficial+5 more
JavaScriptGoogle Tag ManagerCrazyEggSiteimprove Analytics+1
2025-10-08T02:45:10.960Z
D

Department of Health & Human Services

hhs.gov

75
GovernmentUnited StatesenterpriseMEDIUM

The Department of Health & Human Services (HHS) is a U.S. federal government agency dedicated to enhancing the health and well-being of Americans. The website serves as a comprehensive portal for health programs, services, grants, regulations, and public health information. It targets the general public and stakeholders in the healthcare sector, positioning itself as the authoritative source for health-related government services and information. The site is well-branded, professionally designed, and consistent with government standards, reflecting its enterprise-level scale and importance. Technically, the website is built on Drupal CMS and leverages modern web technologies including Google Tag Manager, Siteimprove Analytics, and Crazy Egg for performance and user behavior tracking. The site is mobile-optimized, accessible, and SEO-friendly, with a moderate performance profile. Security is robust with HTTPS enforced and secure cookie configurations, although explicit security headers could be more visible. Privacy compliance is strong with a comprehensive privacy policy, though a cookie consent mechanism is not evident. The security posture is strong, with no visible vulnerabilities or exposed sensitive data. The domain uses a .gov TLD, which is tightly controlled and indicative of high legitimacy. WHOIS data is not publicly available, which is typical for .gov domains. The site is free from WAF blocking or security challenges, allowing full content access. Overall, the website demonstrates a high level of trustworthiness, professionalism, and compliance suitable for a critical government health agency.

30
58
65
83
90
85
100
governmenthealthpublicservicesofficialhhs+1 more
Google Tag ManagerSiteimprove AnalyticsCrazy EggDrupal CMS+3
2025-10-08T02:45:05.945Z
fda.gov favicon

U.S. Food and Drug Administration

fda.gov

70
GovernmentUnited StatesenterpriseMEDIUM

The U.S. Food and Drug Administration (FDA) is a federal government agency responsible for protecting public health through regulation and oversight of food, drugs, medical devices, and related products. The website serves as a comprehensive resource for consumers, industry professionals, and government officials, providing regulatory information, safety alerts, guidance documents, and news updates. The FDA holds a primary market position as the authoritative regulatory body in the United States for these sectors. Technically, the website is built on the Drupal CMS platform, utilizing modern web technologies including Bootstrap for responsive design, Google Tag Manager, Google Analytics, and CrazyEgg for analytics and user behavior tracking. The site demonstrates good mobile optimization, accessibility, and SEO practices, though some security headers are missing. The performance is moderate, with asynchronous loading of scripts enhancing user experience. From a security perspective, the site enforces HTTPS and links to a vulnerability disclosure policy, indicating a mature security posture. However, explicit security headers like Content-Security-Policy and X-Frame-Options are absent, and no incident response contact details are published. Privacy compliance is addressed with a comprehensive privacy policy and cookie information, though no explicit cookie consent mechanism is present. Overall, the FDA website is a highly trustworthy and professional government resource with excellent content quality and business credibility. The incomplete WHOIS data is mitigated by the .gov domain status and consistent branding. Strategic recommendations include enhancing security headers, implementing cookie consent, publishing incident response contacts, and adding a security.txt file to improve transparency and security posture.

55
53
35
70
80
80
100
governmenthealthcarefdapublichealthregulation+3 more
Google Tag ManagerGoogle Analytics (gtag.js)CrazyEggDrupal CMS+2
2025-10-08T00:29:48.133Z
airbus.com favicon

Airbus

airbus.com

78
TransportationFranceenterpriseLOW

Airbus is a global aerospace leader specializing in the design, manufacture, and delivery of commercial aircraft, helicopters, military transports, satellites, and launchers. The company positions itself as a pioneer in sustainable aerospace, emphasizing innovation and environmental responsibility. The website reflects a mature digital presence with comprehensive content targeting industry professionals, customers, investors, and the general public interested in aerospace and sustainability. Airbus maintains a strong market position with a broad portfolio of products and services across multiple aerospace sectors. Technically, the website is built on Drupal CMS and leverages modern web technologies including Video.js for multimedia, Piwik PRO for analytics, and OneTrust for cookie consent management. The site is mobile-optimized, accessible, and SEO-friendly, providing a smooth user experience. External integrations include social media platforms and analytics services, all implemented with privacy compliance in mind. From a security perspective, Airbus employs HTTPS with strong SSL configurations and implements key security headers to protect users. The presence of ISO 27001 certification indicates a commitment to information security management. However, the absence of publicly available incident response contacts and vulnerability disclosure policies suggests areas for improvement. No critical vulnerabilities or exposed sensitive data were detected in the website content. Overall, the website is professional, trustworthy, and aligns well with Airbus's corporate stature. The missing WHOIS data is a notable anomaly but likely due to privacy or registry policies rather than malicious intent. Strategic recommendations include enhancing transparency around security incident response and vulnerability reporting to further strengthen trust and security posture.

80
58
47
85
82
85
100
aerospaceaviationmanufacturingtechnologyinnovation+3 more
Drupal CMSVideo.jsPiwik PRO analyticsOneTrust cookie consent+2

Partner Domains:

aircraft.airbus.com
subsidiary
www.acj.airbus.com
subsidiary

+1 more partners

2025-10-04T04:19:07.412Z