Skip to main content

High-risk security reports

Browse 43,501 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

148819
Websites
130
Industries
113
Countries
52
Avg Score
Page 814 of 871|Showing 40651-40700 of 43501
A

Attention Required! | Cloudflare

routeco.com

30
EnergyN/amediumHIGH

The website routeco.com is currently inaccessible due to a Cloudflare Web Application Firewall (WAF) block, presenting a security challenge page instead of business content. This prevents direct analysis of the website's content, policies, or contact information. The domain is mature, registered since 1997, and protected with strong domain status flags, indicating a legitimate business presence. However, the lack of a valid SSL/TLS certificate and the presence of a WAF block significantly limit the ability to assess the website's security posture and user experience. Technically, the site is hosted behind Cloudflare, which provides DNS and security services, but the absence of HTTPS and modern TLS protocols is a critical security gap. The security headers are partially implemented but insufficient without proper SSL. Performance and SEO cannot be evaluated due to the blocked content. No privacy, cookie, or terms of service policies are visible, nor is any contact information or business metadata. From a security perspective, the site suffers from critical issues including no SSL, no HSTS, and no OCSP stapling. The Cloudflare WAF block suggests active protection against potential threats but also impacts legitimate user access. The domain WHOIS data is consistent and trustworthy, with no suspicious patterns detected. Overall, the website's current state poses a high risk for user trust and accessibility. Strategic recommendations include immediate SSL certificate deployment, reviewing WAF rules to avoid blocking legitimate users, publishing clear privacy and cookie policies, and providing accessible contact information to improve business credibility and compliance.

35
-
5
50
-
85
100
blockedcloudflaresecuritywafinaccessible
Cloudflare
2025-06-15T21:54:39.662Z
V

Vebego Deutschland

hectas.com

28
Real EstateGermanylargeHIGH

Vebego Deutschland is a well-established facility services provider in Germany, offering a broad range of services including building cleaning, industrial cleaning, green care, facility management, and security services. The company positions itself as a reliable and innovative partner focused on enhancing client environments for better performance and quality of life. The website content is professional and well-structured, targeting business clients in need of comprehensive facility services. Technically, the website uses modern marketing and optimization tools such as Google Tag Manager and Visual Website Optimizer, but lacks a valid SSL certificate, which is a critical security shortfall. Security headers are partially implemented, but the absence of HTTPS and modern TLS protocols significantly weakens the security posture. Privacy compliance is partially addressed with a privacy policy present, but no cookie consent mechanism is detected, which may pose GDPR compliance risks. Business credibility is supported by multiple certifications and industry memberships, enhancing trust. Overall, the site is functional and professional but requires urgent security improvements to protect user data and comply with best practices.

55
18
5
50
-
80
20
facilityservicescleaningsecurityservicesfacilitymanagementgermany+2 more
Kestrel web serverVisual Website Optimizer (VWO)Google Tag Manager

Partner Domains:

vebego.de
partnerpending
2025-06-15T21:54:38.360Z
knapp.de favicon

Andreas Knapp

knapp.de

33
Real EstateGermanysmallHIGH

The website knapp.de represents Andreas Knapp, a publicly appointed and sworn expert specializing in real estate valuation and related expert services in Germany. The business operates in a niche market providing property valuation, expert reports, and legal valuation services primarily targeting clients requiring official property assessments. The website content is minimal and primarily informational, focusing on the expert's credentials and service offerings without extensive interactive features or modern web design elements. Technically, the website is outdated, employing legacy technologies such as jQuery 1.7.1 and a frameset layout, which negatively impacts user experience, SEO, and accessibility. Performance is poor with a high load time and large page size. Critically, the site lacks a valid SSL certificate and does not support HTTPS, exposing visitors to security risks. No modern security headers or compliance mechanisms such as privacy or cookie policies are present, indicating a low level of digital maturity and GDPR compliance. From a security perspective, the absence of HTTPS and security headers, combined with no evidence of incident response or vulnerability disclosure policies, presents significant risks. The domain registration data aligns with the business claims, showing consistent and legitimate ownership without privacy protection. However, the lack of security best practices and compliance documentation suggests the need for urgent improvements to protect user data and enhance trust. Overall, the website scores low on security and privacy compliance, with basic content quality and business credibility. Strategic recommendations include immediate SSL implementation, updating the technology stack, adding privacy and cookie policies, and improving security headers and compliance frameworks to align with modern standards.

15
15
17
50
75
65
20
realestatepropertyvaluationexpertwitnessgermanysachverstndiger
jQuery 1.7.1SuperfishTMS SliderGoogle Maps API
2025-06-15T21:54:29.013Z
etoninstitute.com favicon

Eton Institute

etoninstitute.com

30
EducationUnited Arab EmiratesmediumHIGH

Eton Institute is a well-established language school based in the UAE, recognized as the only EAQUALS-accredited language school in the region. It offers a wide range of language courses, special programs, exam preparation, teacher training, and corporate training services. The website targets individuals and corporate clients seeking language education with flexible learning options including in-person and online classes. The business has a strong market position supported by 19+ years of experience and multiple trust indicators such as certifications and testimonials. Technically, the website is built on WordPress using Elementor and Gravity Forms, with SEO optimizations via Yoast and analytics through Google Analytics and Tag Manager. While the design and content quality are excellent, the site suffers from slow performance and basic accessibility features. Mobile optimization is good, and navigation is clear. From a security perspective, the site has implemented several security headers but critically lacks a valid SSL certificate, resulting in no HTTPS availability. This is a major vulnerability that impacts user trust and security. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism or detailed security/incident response policies. Overall, the site is professional and credible but requires urgent improvements in SSL/TLS configuration and privacy compliance to enhance security posture and user trust. Strategic recommendations include obtaining a valid SSL certificate, enabling HSTS, implementing cookie consent, and publishing comprehensive security policies.

65
18
-
50
-
50
40
educationlanguageschooleaqualsaccreditedcorporatetraininglanguagecourses+1 more
WordPressElementorGravity FormsYoast SEO+1
2025-06-15T21:54:27.556Z
dataphone.at favicon

Dataphone GmbH

dataphone.at

25
TechnologyAustriamediumHIGH

Dataphone GmbH is an Austrian company specializing in digitalizing supply chain processes, offering innovative software and hardware solutions primarily for warehouse logistics, transport, and retail sectors. Their market position is strong within Austria, providing comprehensive services including warehouse management systems (LOGIS 4 and LOGIS Light), hardware products like barcode scanners and label printers, and professional maintenance and support services. The company targets businesses seeking to modernize and optimize their logistics and supply chain operations through digital transformation. Technically, the website is built on WordPress with a modern theme and uses a variety of plugins for SEO, performance optimization, cookie consent, and analytics. However, a critical security shortfall is the absence of a valid SSL certificate and HTTPS support, which significantly impacts the security posture. The site employs Google Analytics, Google Tag Manager, and other marketing tools with proper consent mechanisms, indicating good privacy compliance. Contact information and business details are clearly presented, enhancing business credibility. Overall, while the business and technical maturity are good, urgent improvements in security infrastructure are necessary to protect user data and build trust.

15
-
-
50
-
90
20
logisticswarehousemanagementsoftwarehardwaresupplychain+5 more
PHP 7.4.33nginxWordPress 6.8.1Yoast SEO plugin+10
2025-06-15T21:54:26.616Z
psolutions.at favicon

101domain GRS Limited

psolutions.at

37
TechnologyN/asmallHIGH

The website psolutions.at is currently a parked domain page managed by 101domain GRS Limited, a domain registration and related services provider. The site offers no original business content but promotes domain registration, Google Workspace, web hosting, and corporate brand services through 101domain. The target audience is individuals or businesses interested in acquiring this domain or other domains. The site is minimalistic with basic design and navigation, primarily serving as a placeholder and sales funnel for domain services. Technically, the site is hosted on an AWS IP with nginx server and uses modern frontend technologies such as jQuery and Modernizr. However, it lacks SSL/TLS encryption, serving content over HTTP only, which is a significant security shortfall. Performance metrics are not available, but the site appears lightweight. Mobile optimization is good due to responsive CSS, but accessibility and SEO are basic. Security posture is weak due to the absence of HTTPS, no HSTS, no DMARC, no DNSSEC, and no valid SSL certificate. Some security headers like Content-Security-Policy and X-Frame-Options are present, but overall security best practices are not fully implemented. There are no signs of vulnerabilities like Heartbleed or POODLE, but the lack of encryption is critical. Overall, the site poses low risk as it is a parked domain with no user data collection or business operations. However, the lack of HTTPS and privacy policies reduces trustworthiness and compliance. Strategic recommendations include implementing SSL/TLS, adding privacy and cookie policies, and improving security headers to enhance trust and security posture.

45
-
5
50
-
75
100
domainparkingdomainregistration101domainparkedpage
nginxjQuery 3.6.0Modernizrwoff2 fonts+1
2025-06-15T21:54:26.570Z
C

Chava Beijk

chavabeijk.nl

26
OtherNetherlandssmallHIGH

The website chavabeijk.nl represents a personal artist site for soprano Chava Beijk, providing information about her musical repertoire, collaborations, and contact details for concerts and singing lessons. The site targets classical music enthusiasts, concert organizers, and students interested in vocal training. The business model is focused on personal promotion and service offerings in the niche classical music sector, with a small scale and localized presence in the Netherlands. Technically, the site is hosted on an Apache server with basic JavaScript for UI interactions and is hosted by Mijndomein. The site lacks modern frameworks, CMS, or advanced performance optimizations, resulting in slow loading and poor mobile optimization. No analytics or tracking technologies are detected, indicating minimal digital maturity. From a security perspective, the site lacks HTTPS and a valid SSL certificate, exposing users to potential risks. No advanced security headers or policies are implemented, and no privacy or cookie policies are present, indicating poor compliance with GDPR and modern privacy standards. The DNS configuration is basic with SPF but lacks DNSSEC and CAA records. Overall, the security posture is weak, with critical recommendations needed to improve encryption and security headers. Overall, the site is functional for its purpose but requires urgent improvements in security and privacy compliance to enhance trustworthiness and protect visitors. The lack of HTTPS is a critical issue that significantly lowers the security score and overall AI rating.

15
-
-
50
-
85
40
sopraanoperamusicalzangconcert+3 more
ApacheJavaScript
2025-06-15T21:54:26.077Z