Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157031
Websites
130
Industries
113
Countries
52
Avg Score
Page 857 of 3141|Showing 42801-42850 of 157031
mastodon.energy favicon

mastodon.energy

mastodon.energy

60
EnergyN/asmallMEDIUM

mastodon.energy operates as a specialized Mastodon instance dedicated to professionals and academics involved in energy transition policy, infrastructure, technology, journalism, and science. It serves a niche community within the broader fediverse, providing a platform for discussion and networking in the energy sector. The website presents itself with a clear focus on this audience and offers federated social networking services without commercial advertising or tracking. Technically, the site runs Mastodon version 4.3.9, leveraging modern web technologies including React and WebSocket streaming APIs, hosted likely on DigitalOcean infrastructure. The site is mobile optimized and provides a good user experience with clear navigation and relevant content. Security-wise, the site enforces HTTPS and avoids exposing sensitive data, but lacks some security headers and formal security policies. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism or terms of service page. WHOIS data is privacy protected, which is common for community servers but limits transparency. Overall, mastodon.energy is a legitimate, well-maintained community platform with moderate security and privacy posture, suitable for its professional audience.

75
53
17
70
72
75
40
mastodonfediverseenergysocialnetworkprofessional+1 more
Mastodon 4.3.9JavaScriptReact (implied by chunked JS and SPA behavior)DigitalOcean Spaces (CDN for media)+1
2025-10-18T21:52:00.580Z
brid.gy favicon

Bridgy

brid.gy

63
TechnologyN/asmallMEDIUM

Bridgy is a specialized technology service that connects websites to social media platforms, enabling functionalities such as likes, reposts, mentions, and cross-posting. The service targets website owners and social media users seeking to integrate their web presence with social media interactions. The business operates as a small, niche player with an open-source approach, evidenced by its GitHub presence and transparent service offerings. The website is well-branded and consistent, with a clear focus on social media integration technology. Technically, the website employs standard web technologies including HTML5, CSS with Bootstrap for responsive design, and JavaScript. Hosting appears to be managed via Google Cloud DNS infrastructure. The site is mobile-optimized and structured for good SEO, though accessibility features are basic. Performance is moderate, with no major technical issues detected in the provided content. From a security perspective, the site uses HTTPS and has domain transfer protections in place. However, DNSSEC is not enabled, and no security headers were detected in the provided data, indicating room for improvement. The absence of privacy, cookie, and terms of service policies reduces privacy compliance scores. No contact information or incident response details are provided, limiting transparency. No vulnerabilities or suspicious content were found. Overall, Bridgy presents a trustworthy and professional web service with a solid technical foundation but could enhance its security posture and privacy compliance by adding relevant policies, security headers, and contact information. The risk level is low, but improvements in these areas would strengthen user trust and regulatory compliance.

75
50
2
40
95
70
100
socialmediaintegrationwebmentionopensourcetechnology
HTML5CSS (Bootstrap)JavaScript
2025-10-18T21:51:50.562Z
cyberplace.social favicon

Cyberplace

cyberplace.social

67
TechnologyN/asmallMEDIUM

Cyberplace.social is an independent Mastodon social media server focused on cybersecurity, fandom, video games, and technology communities. It operates within the fediverse, providing a decentralized platform for users interested in these topics. The site is administered by a known individual, Kevin Beaumont (@GossiTheDog), and maintains an active user base of approximately 937 monthly active users. The platform leverages Mastodon version 4.4.7 and modern web technologies such as React and ES modules, ensuring a contemporary user experience with mobile optimization and good navigation clarity. From a technical perspective, the site demonstrates moderate performance and basic SEO and accessibility features. It uses HTTPS, but no explicit security headers were detected in the provided data, suggesting room for improvement in security hardening. Privacy compliance is partial, with a privacy policy present but lacking cookie consent mechanisms and terms of service pages. No contact emails or phone numbers are publicly listed, which is common for federated social platforms prioritizing user privacy. The security posture is adequate but could be enhanced by implementing recommended security headers, publishing security policies, and improving privacy compliance. The WHOIS data is privacy protected, which is typical for social media platforms, and does not raise immediate legitimacy concerns given the known administrator and active community. Overall, Cyberplace.social presents as a legitimate, niche social media platform with a focus on cybersecurity and related interests, but with opportunities to strengthen its security and privacy posture.

80
58
47
85
72
75
40
socialmediamastodoncybersecuritytechnologyfandom+1 more
Mastodon 4.4.7ReactJavaScript ES ModulesCSS+1
2025-10-18T21:51:25.505Z
bootstrapmade.com favicon

BootstrapMade

bootstrapmade.com

68
TechnologyN/asmallMEDIUM

BootstrapMade is a specialized provider of free and premium Bootstrap templates and themes, catering primarily to web developers, startups, and businesses seeking professional and responsive website designs. Established in 2013, the company has built a strong market presence with over 9 million downloads and a broad portfolio of templates across multiple industries. Their business model revolves around offering both free templates with footer credits and premium templates with advanced features and dedicated support, supplemented by a visual Bootstrap Template Builder for premium users. Technically, the website is built on modern web standards using Bootstrap 5, HTML5, CSS3, and JavaScript, hosted and protected by Cloudflare infrastructure. The site demonstrates excellent mobile optimization, fast performance, and good SEO practices. Analytics and tracking are implemented via Google Tag Manager and Cloudflare Insights, reflecting a moderate level of user tracking balanced with privacy considerations. From a security perspective, the site enforces HTTPS and uses Cloudflare DNS and hosting, providing a solid SSL configuration. However, explicit security headers such as Content-Security-Policy and X-Frame-Options are not visibly implemented, and no public security policy or incident response contacts are provided. Forms use secure POST methods, and no sensitive data exposure or vulnerabilities were detected in the HTML content. Overall, BootstrapMade presents a trustworthy and professional online presence with high-quality content and technical maturity. The absence of direct contact emails or phone numbers is mitigated by a contact form. Privacy and cookie policies are present with consent mechanisms, supporting GDPR compliance. Recommendations include enhancing security headers, publishing a security policy, and adding vulnerability disclosure information to further strengthen trust and security posture.

50
68
17
65
75
80
100
bootstraptemplatesthemesfreepremium+4 more
Bootstrap 5HTML5CSS3JavaScript+4
2025-10-18T21:51:10.473Z
eupolicy.social favicon

eupolicy.social

eupolicy.social

61
GovernmentN/asmallMEDIUM

eupolicy.social is a niche Mastodon server dedicated to professionals and enthusiasts involved in EU policy. It operates as a community-driven platform providing a respectful and friendly environment for discussion related to EU policy matters. The server is administered by a small team of volunteers and funded through voluntary contributions, emphasizing its non-commercial and community-oriented nature. The website clearly communicates its purpose, rules, and administrative contacts, fostering trust and transparency within its user base. Technically, the site leverages the Mastodon open-source social networking platform (version 4.4.5) and modern web technologies including React and JavaScript ES modules. The platform supports federated social media participation via the ActivityPub protocol. The website demonstrates good mobile optimization and basic accessibility features, with a moderate performance profile. SEO practices are adequate with proper meta tags and Open Graph data. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data in its HTML content. However, it lacks explicit security headers such as Content Security Policy and HSTS, and does not provide a cookie consent mechanism, which are areas for improvement. The absence of WHOIS data due to privacy protection is justified given the community nature of the service, though it slightly reduces trustworthiness from a domain registration perspective. Overall, eupolicy.social presents a trustworthy, well-maintained community platform with a clear focus and good technical foundation. Strategic recommendations include enhancing security headers, implementing cookie consent for GDPR compliance, publishing a security policy, and improving accessibility to further strengthen its security posture and user trust.

75
58
17
80
52
85
40
mastodonsocialmediaeupolicyfederatedcommunity
Mastodon 4.4.5ReactJavaScript ES ModulesActivityPub protocol
2025-10-18T21:51:05.460Z
napec-portal.com favicon

WebPortal

napec-portal.com

47
OtherN/asmallHIGH

The website napec-portal.com serves as a login portal for NAPEC, presumably the Nigerian Association of Petroleum Explorationists or a related entity. The portal is designed for members or authorized users to access their profiles and services. The site is built using Angular 14 framework and incorporates Usercentrics for cookie consent management, indicating some attention to privacy compliance. However, the public-facing content is minimal, focusing solely on login functionality without detailed business or contact information. The domain is recently registered in April 2023, consistent with a new portal launch. From a technical perspective, the site uses modern web technologies including Angular and Bootstrap for styling. DNS is managed via Google Domains, and the domain registrar is Squarespace Domains II LLC. The site shows moderate performance and basic mobile optimization but lacks advanced SEO and accessibility features. No CMS or hosting provider details are explicitly found. Cookie consent is implemented via Usercentrics, but Google Analytics is present only in commented form, indicating limited active tracking. Security posture is moderate but could be improved. HTTPS is implied but no explicit security headers such as CSP, HSTS, or X-Frame-Options are detected in the HTML content. The login form lacks visible anti-CSRF tokens or advanced input security measures. No privacy policy, terms of service, or incident response contacts are published, which limits compliance and user trust. The domain registration is consistent and shows no suspicious patterns, but the lack of detailed business information and security policies reduces overall trustworthiness. Overall, the website is functional as a login portal but lacks comprehensive privacy, security, and business transparency features. Strategic improvements in security headers, privacy documentation, and contact information publication are recommended to enhance trust and compliance.

30
35
2
60
72
80
40
loginportalnapecusercentricsangular+1 more
Angular 14Usercentrics Consent ManagementBootstrap CSSSweetAlert2+1
2025-10-18T21:50:55.440Z
aquahoteldecin.cz favicon

Děčínská sportovní, příspěvková organizace

aquahoteldecin.cz

59
HospitalityCzech RepublicsmallMEDIUM

The website booking.previo.app hosts a direct online booking platform for Aqua Hotel, operated by Děčínská sportovní, a Czech hospitality organization. The platform facilitates hotel reservations with clear business and contact information, supporting multiple languages and currencies. The site includes comprehensive privacy and cookie policies with consent mechanisms, and detailed terms of service including cancellation policies. The business targets general audiences seeking accommodation in Děčín, Czech Republic, positioning itself as a small local hospitality provider with direct booking capabilities. Technically, the website employs modern JavaScript libraries, Google Tag Manager, and analytics tools such as Smartlook and Contentsquare. The design is responsive and user-friendly, with good navigation and content relevance. However, some security best practices like security headers are missing, representing an area for improvement. The SSL configuration is good, and no critical vulnerabilities or exposed sensitive data were detected. From a security and compliance perspective, the site demonstrates good GDPR compliance with clear privacy disclosures and cookie consent. Incident response and security policy details are not explicitly provided, which could be enhanced. No suspicious or adult content is present, making the site safe for general users. The domain registration aligns well with the business entity, supporting legitimacy. Overall, the website is a professionally maintained hospitality booking platform with solid privacy and compliance posture, moderate technical sophistication, and room for security enhancements. Strategic recommendations include implementing security headers, enhancing incident response transparency, and continuous monitoring of third-party scripts to maintain security and trust.

20
35
17
65
72
85
100
hotelbookingreservationhospitalityprivacy+3 more
JavaScriptjQueryGoogle Tag ManagerSmartlook+1
2025-10-18T21:50:40.048Z
peatix.com favicon

Peatix Inc.

peatix.com

71
TechnologyJapanmediumMEDIUM

Peatix Inc. operates a well-established online platform specializing in event ticketing and community management, targeting event organizers and attendees globally. Founded in 2010, the company offers tools to promote, manage, and sell tickets for events, emphasizing simplicity, transparency, and customer support. The website reflects a professional and consistent brand image with a clear focus on its core business services. Technically, the website leverages modern JavaScript frameworks such as Vue.js, integrates Google Tag Manager and Facebook SDK for analytics and marketing, and is hosted on Amazon AWS infrastructure. The site is mobile-optimized and employs cookie consent mechanisms compliant with GDPR, enhancing user privacy and regulatory adherence. From a security perspective, Peatix enforces HTTPS, includes anti-clickjacking measures, and provides granular cookie consent options. However, there is room for improvement by enabling DNSSEC, adding explicit security headers, and publishing a formal security policy and incident response contacts. No critical vulnerabilities or exposed sensitive data were detected. Overall, Peatix presents a secure, compliant, and professionally maintained online presence with moderate to high trustworthiness. Strategic enhancements in security transparency and contact information disclosure would further strengthen its posture and user confidence.

75
65
2
100
72
70
100
eventmanagementticketingcommunityonlineregistrationpayment+1 more
JavaScriptjQueryGoogle Tag ManagerOneTrust Cookie Consent+1
2025-10-18T21:50:28.816Z
chachar.cz favicon

Chachar catering s.r.o.

chachar.cz

46
RetailCzech RepublicmediumHIGH

Chachar catering s.r.o. operates a regional pizza delivery and catering service in the Czech Republic, established since 2006. The company offers fast delivery of pizza, wings, and other fresh food items through an online ordering platform and telephone. With multiple branch locations across various Czech cities, the business targets general consumers seeking convenient food delivery. The website is professionally designed with consistent branding and good content quality, supporting a medium-sized enterprise model focused on retail and hospitality sectors. Technically, the website is built on WordPress 4.9.8 with a modern tech stack including jQuery, Bootstrap, Google Tag Manager, and reCAPTCHA for security. Hosting is consistent with Czech providers, and the site uses HTTPS with no detected blocking or WAF interference. Performance and mobile optimization are good, though accessibility is basic. SEO practices are adequate with proper meta tags and structured navigation. Security posture is solid with HTTPS, reCAPTCHA, and cookie consent mechanisms in place. However, explicit security headers and a formal security policy or incident response contacts are absent. No vulnerabilities or exposed sensitive data were found in the HTML content. Privacy compliance is evident with GDPR-related pages and cookie consent, though no dedicated data protection officer contact was identified. Overall, the website and business present a trustworthy and professional front with low risk. Strategic improvements include enhancing security headers, updating WordPress to the latest version, and publishing explicit security and incident response policies to further strengthen trust and compliance.

20
10
2
90
62
80
20
pizzafooddeliverycateringczechrepubliconlineordering+1 more
WordPress 4.9.8jQuery 3.3.1Bootstrap 4.3.1Google Tag Manager+5

Partner Domains:

bilovec-chachar.cz
subsidiary
bolatice-chachar.cz
subsidiary

+3 more partners

2025-10-18T20:48:42.228Z
kamenynaburni.cz favicon

AREON s.r.o.

kamenynaburni.cz

66
Real EstateCzech RepublicsmallMEDIUM

The website www.kamenynaburni.cz represents a professional real estate development project named 'Kameny Na Burni' located in Slezská Ostrava, Czech Republic. The business behind the project is AREON s.r.o., a small-sized real estate developer under the parent company ALUMONT HOLDING a.s. The site offers detailed information about new apartments for sale, including visualizations, construction updates, and contact options. The target audience is potential home buyers seeking premium residential properties in a quiet urban setting. Technically, the website employs modern web technologies such as Svelte, JavaScript ES modules, and integrates Google Analytics and CookieScript for tracking and consent management. The site is well-optimized for mobile devices and provides a good user experience with clear navigation and professional design. Security-wise, the site uses HTTPS and implements GDPR-compliant cookie consent mechanisms and contact forms with explicit consent checkboxes. However, explicit security headers and detailed security policies are absent, and WHOIS data for the domain is missing, which slightly reduces trustworthiness. Overall, the site is reliable and professional but would benefit from enhanced transparency in domain registration and security disclosures.

55
25
17
80
85
85
100
realestateresidentialdevelopmentapartmentsostravaczechrepublic+3 more
JavaScript ES ModulesSvelte (inferred from svelte-* classes)CookieScript (consent management)Google Analytics+4

Partner Domains:

areon-development.cz
partner
alumont.cz
partner

+2 more partners

2025-10-18T20:48:28.830Z
A

altMBA LLC

altmba.com

53
EducationN/asmallMEDIUM

altMBA LLC operates a niche online leadership workshop aimed at professionals and leaders seeking transformative development experiences. The website presents a clean, focused message emphasizing its 9 years of operation and global alumni network. The business model centers on delivering leadership education and fostering an alumni community, positioning itself as a specialized provider in the education sector. The site is simple and static, with minimal interactive features and no evident e-commerce or complex platform integrations. Technically, the website uses basic HTML5, CSS, and JavaScript with embedded video content. There is no evidence of a CMS or advanced frameworks, and hosting details are limited to DNS provider information. Performance and mobile optimization are basic but adequate for the site's scope. SEO and accessibility features are minimal, and no analytics or tracking technologies are detected, indicating a low digital maturity level. From a security perspective, the site lacks critical security headers and does not indicate HTTPS usage, which is a significant concern. The absence of privacy, cookie, and terms of service policies suggests compliance gaps with GDPR and other privacy regulations. Contact information is limited to a single email address, with no phone or physical address provided. The domain registration is stable and consistent with the business history, supporting legitimacy. Overall, the security posture is weak and requires improvements to protect user data and enhance trust. The overall risk assessment highlights the need for immediate implementation of HTTPS, security headers, and privacy policies to meet modern security and compliance standards. Strategic recommendations include enhancing security configurations, adding comprehensive privacy and cookie policies, and improving transparency with users. These steps will strengthen the website's trustworthiness and align it with best practices in security and privacy.

15
35
2
75
52
75
100
educationleadershipworkshopalumniprofessionaldevelopment
HTML5CSSJavaScriptHTML5 video
2025-10-18T20:47:27.558Z
wearecollins.com favicon

COLLINS

wearecollins.com

54
MediaN/amediumMEDIUM

COLLINS is a recognized transformation consultancy specializing in design and business transformation services for enterprises at critical inflection points. The company holds prestigious industry awards including Ad Age’s Transformation Firm of the Year and Design Firm of the Year for multiple years, positioning it as a leader in its sector. The website showcases extensive case studies, press coverage, and a strong brand presence targeting businesses seeking strategic transformation and design expertise. Technically, the website is built on Jekyll, uses modern JavaScript libraries like Flickity for UI components, and leverages Imgix for image delivery, indicating a modern and performant infrastructure. Analytics tools such as Microsoft Clarity and Google Analytics are employed for user behavior insights. Security posture is generally good with HTTPS enforced and secure form handling; however, the absence of security headers and published privacy or cookie policies indicates room for improvement in compliance and security transparency. The WHOIS data is unavailable, which raises concerns about domain registration legitimacy, though the website content and branding suggest a professional and trustworthy business. Overall, the site is well-designed, user-friendly, and content-rich, but would benefit from enhanced privacy disclosures and security policies to improve trust and compliance.

15
35
17
45
67
75
100
transformationconsultancydesignbrandingmedia+1 more
Jekyll v3.8.5Flickity carouselImgix image CDNMicrosoft Clarity analytics+1
2025-10-18T20:47:22.517Z
portaltransparencia.gov.br favicon

Controladoria-Geral da União

portaltransparencia.gov.br

69
GovernmentBrazilenterpriseMEDIUM

The Portal da Transparência do Governo Federal is an official Brazilian federal government transparency portal managed by the Controladoria-Geral da União. It provides comprehensive public access to government spending data, contracts, social benefits, employee remuneration, bidding processes, sanctions, and other fiscal information. The portal targets Brazilian citizens and stakeholders interested in government transparency and social control. It operates as an enterprise-level government service, offering open data downloads and APIs to facilitate public analysis and oversight. Technically, the website employs a modern technology stack including jQuery, Bootstrap, Google Tag Manager, and AWS hosting infrastructure. It uses the govbr design system ensuring consistent branding and accessibility. The site is mobile optimized and includes accessibility features, with good SEO and performance characteristics. The use of AWS WAF scripts indicates a security-aware hosting environment. From a security perspective, the portal enforces HTTPS with excellent SSL configuration and manages cookie consent in compliance with LGPD (Brazilian data protection law). While explicit security headers are not fully visible in the HTML, best practices are implied. No vulnerabilities or exposed sensitive data were detected. However, the site lacks a published security policy, incident response contacts, and a security.txt file, which are recommended for enhanced transparency and vulnerability management. Overall, the portal demonstrates a high level of professionalism, trustworthiness, and compliance with privacy regulations. It serves as a critical tool for public accountability in Brazil. Strategic recommendations include formalizing security policies, publishing incident response contacts, enhancing security headers, and expanding transparency on data retention and privacy practices.

85
50
22
60
90
60
100
governmenttransparencypublicdatabrazilopendata+2 more
jQuery 2.2.4Bootstrap 4Google Tag ManagerGoogle Analytics (gtag.js)+3
2025-10-18T20:47:12.482Z
wexdrive.com favicon

WEX Inc.

wexdrive.com

11
FinanceUnited StatesenterpriseCRITICAL

WEX Inc. operates as a global fintech company specializing in fuel cards, fleet management, employee benefits administration, and business payment solutions. The company targets businesses of various sizes seeking to optimize fuel expenses, streamline employee benefits, and digitize payment processes. WEX holds a strong market position as a leader in these sectors, supported by a comprehensive product portfolio and global reach. Technically, the website is built on WordPress with modern JavaScript libraries such as jQuery and Swiper.js, integrated with Google Tag Manager and Sentry for analytics and error tracking. The site demonstrates excellent performance, mobile optimization, and SEO practices, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS, employs multiple security headers, and avoids exposing sensitive data. However, it lacks a publicly accessible security policy and incident response information, which are recommended for enterprise trust and compliance. The absence of WHOIS registration data is a notable anomaly, warranting further investigation to confirm domain legitimacy. Overall, WEX presents a professional and trustworthy online presence with strong business credibility and technical maturity. Strategic improvements in transparency around security policies and domain registration would enhance trust and compliance posture.

-
-
-
-
-
-
-
fuelcardsfleetmanagementemployeebenefitsbusinesspaymentsfintech+3 more
WordPressjQuerySwiper.jsGoogle Tag Manager+3

Partner Domains:

customer.wexinc.com
service
careers.wexinc.com
service

+2 more partners

2025-10-18T20:47:07.474Z
C

capline.org

capline.org

57
TransportationFrancesmallMEDIUM

The website capline.org is a French digital platform dedicated to the registration of nautical races. It centralizes race registrations and allows participants to upload and reuse necessary documents for their participation. The platform targets participants and organizers of nautical races, positioning itself as a niche service within the transportation sector. The domain was registered in April 2023, consistent with the business's recent establishment. Technically, the website uses modern web technologies including JavaScript and Bootstrap for responsive design. It is hosted by Gandi SAS and served over HTTPS, ensuring basic security. However, the site lacks advanced security headers and DNSSEC, which could be improved to enhance security posture. The website is moderately optimized for mobile devices and performance is average. From a security perspective, the site has a basic security posture with HTTPS enabled but missing important security headers and no DNSSEC. There are no privacy or cookie policies present, which is a compliance gap especially under GDPR. No contact information or incident response details are provided, limiting transparency and user trust. No analytics or tracking scripts were detected, indicating minimal user tracking. Overall, the website is functional and serves its business purpose but requires improvements in privacy compliance, security best practices, and contact transparency to increase trustworthiness and regulatory compliance. Strategic recommendations include adding privacy and cookie policies, implementing security headers, enabling DNSSEC, and providing clear contact and incident response information.

30
50
2
60
75
70
100
nauticalregistrationsportsdigitalplatformfrance
JavaScriptCSSHTML
2025-10-18T20:47:02.465Z