Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149091
Websites
130
Industries
113
Countries
52
Avg Score
Page 9 of 38|Showing 401-450 of 1863
visabg.com favicon

Visa

visabg.com

69
FinanceBulgariaenterpriseMEDIUM

Visa Bulgaria's website serves as a regional portal for Visa's digital payment services and business solutions. The site is well-branded, professionally designed, and offers comprehensive information about Visa's offerings including premium benefits, contactless payments, mobile payment technologies, and business support hubs. The target audience includes consumers, businesses, and innovators in Bulgaria. The website reflects Visa's global market position as a leader in digital payments and financial technology services. Technically, the site uses modern web technologies such as Stencil.js, integrates analytics and marketing tools like Google Analytics, ContentSquare, and Tealium, and is hosted behind Cloudflare CDN ensuring good performance and security. The site is mobile-optimized and accessible, with proper SEO and metadata implemented. From a security perspective, the website enforces HTTPS, uses security headers, and provides cookie consent mechanisms aligned with GDPR. However, it lacks explicit security policies and incident response contacts, and no vulnerability disclosure or security.txt files were found. The WHOIS data is missing or unavailable, which is unusual but the site content and branding strongly indicate legitimacy. Overall, the website presents a low risk profile with strong business credibility and technical maturity. Strategic recommendations include publishing explicit security policies, adding incident response contacts, and maintaining transparent WHOIS data to enhance trust.

75
83
17
50
52
90
100
financepaymentsdigitalpaymentsvisabulgaria+4 more
Stencil.jsContentSquareTealiumCloudflare+2

Partner Domains:

visa.co.in
partner
usa.visa.com
partner

+1 more partners

2025-10-08T08:30:33.677Z
cookieyes.com favicon

CookieYes Limited

cookieyes.com

73
TechnologyUnited KingdommediumMEDIUM

CookieYes Limited operates a Google-certified Consent Management Platform (CMP) designed to help businesses comply with global privacy regulations such as GDPR and CCPA. The company targets businesses of all sizes, offering a SaaS model with free trials and paid plans. With over 1.5 million users worldwide and trusted by major brands, CookieYes holds a strong market position in the privacy compliance technology sector. The website provides comprehensive information about their services, including cookie consent banners, automated consent management, and integrations with industry standards like Google Tag Manager and IAB TCF v2.2. Technically, the website is built on WordPress with modern frameworks such as Bootstrap and integrates multiple analytics and marketing tools including Google Analytics, Microsoft Clarity, Hotjar, and Mixpanel. The site is well-optimized for performance, mobile responsiveness, SEO, and accessibility. Security practices include HTTPS enforcement, use of Google reCAPTCHA, and cookie consent mechanisms, although explicit security headers and policies are not evident. The security posture is solid with no visible vulnerabilities or exposed sensitive data, but the absence of a published security policy and incident response contacts is a gap. The WHOIS data for the domain is missing, which raises concerns about domain registration transparency, although the website content and business information are credible. Overall, CookieYes presents a professional, trustworthy, and technically mature platform with minor areas for improvement in security transparency. Strategic recommendations include implementing security headers, publishing a security policy and incident response information, and adding a security.txt file to facilitate vulnerability disclosures. These steps will enhance trust and compliance posture, supporting CookieYes's leadership in the privacy compliance market.

75
95
2
85
75
70
100
cookieconsentgdprccpaprivacycompliancecookiemanagement+3 more
WordPressYoast SEO pluginGoogle Tag ManagerGoogle Analytics+7

Partner Domains:

app.cookieyes.com
service
tapfiliate.com
partner
2025-10-07T23:18:56.609Z
D

Attention Required! | Cloudflare

dnib.com

59
OtherN/asmallMEDIUM

The website dnib.com is currently inaccessible due to a Cloudflare Web Application Firewall (WAF) block page, preventing access to any substantive content. The domain is well established, registered since 1997 through a reputable registrar, CSC Corporate Domains, Inc., and uses Cloudflare for DNS and security services. However, no business, contact, or policy information is available on the accessible page, limiting the ability to assess the company's operations or services. The technical infrastructure relies on Cloudflare's security platform, but DNSSEC is not enabled, and no security headers or privacy compliance indicators are visible due to the block. From a security perspective, the site benefits from Cloudflare's protection but lacks visible security best practices such as security headers or documented incident response contacts. The absence of privacy and cookie policies and contact information further reduces trust and compliance posture. The domain's legitimacy is supported by its age and registrar, but the lack of accessible content and policies is a significant gap. Overall, the site presents a high risk for users due to inaccessibility and lack of transparency. Strategic recommendations include resolving the WAF blocking issues to allow legitimate user access, publishing comprehensive privacy and security policies, enabling DNSSEC, and providing clear contact and incident response information to improve trust and compliance.

55
35
2
70
100
85
100
blockedcloudflaresecuritywafinaccessible
Cloudflare
2025-10-07T19:52:11.812Z
posthog.com favicon

PostHog

posthog.com

64
TechnologyUnited StatesmediumMEDIUM

PostHog is a technology company specializing in product analytics tools designed for product engineers and software developers. Founded in 2020, it offers a modern SaaS and open-source platform that includes session recording, feature flags, heatmaps, and remote configuration. The company positions itself as an innovative alternative in the product analytics market, targeting engineering teams seeking comprehensive product insights. The website reflects a professional and consistent brand image with excellent content quality and user experience. Technically, the website is built using modern frameworks such as Gatsby and React, hosted behind Cloudflare CDN services, and employs PostHog's own analytics platform for tracking. The site is fast, mobile-optimized, and SEO-friendly, demonstrating a mature digital infrastructure. Security best practices are observed with HTTPS enforcement, strong security headers, and input masking in session recordings, although DNSSEC is not enabled. From a security perspective, PostHog maintains a strong posture with no evident vulnerabilities or exposed sensitive data. Privacy and cookie policies are comprehensive and GDPR compliant, though explicit incident response contacts and vulnerability disclosure mechanisms are not clearly presented. Overall, the risk profile is low, with recommendations to enhance transparency around security incident handling and to enable DNSSEC for domain security. Strategically, PostHog is well-positioned in the technology sector with a clear business model and target audience. The website's quality and trust indicators support its credibility, making it a reliable platform for product analytics solutions.

30
35
17
98
72
75
100
productanalyticssoftwaredevelopmentopensourcesessionrecordingfeatureflags+1 more
JavaScriptReactGatsbyCloudflare+1
2025-10-07T19:49:56.320Z
doozyonline.com favicon

SCGP

doozyonline.com

67
RetailThailandlargeMEDIUM

DoozyOnline by SCGP is an e-commerce platform specializing in a comprehensive range of packaging products including food containers, paper bags, boxes, postal equipment, and healthcare-related packaging. The website targets businesses and consumers in Thailand seeking quality packaging solutions under the SCGP brand, a recognized leader in the packaging industry. The platform positions itself as a one-stop shop for packaging needs, leveraging SCGP's standards and reputation. Technically, the website employs modern web technologies such as React, Google Tag Manager, Google Analytics, Facebook Pixel, and Taboola for marketing and analytics. It is hosted behind Cloudflare, ensuring good security and performance. The site is mobile-optimized and demonstrates good SEO practices, although accessibility features are basic. The cookie consent mechanism is implemented, reflecting some privacy compliance efforts. From a security perspective, the site uses HTTPS with strong SSL configuration and security headers. It integrates Google reCAPTCHA v3 to mitigate bot activity. However, there is no publicly available privacy policy, terms of service, or incident response information, which are important for compliance and trust. No vulnerabilities or exposed sensitive data were detected in the provided content. Overall, the website is professional, trustworthy, and well-branded but would benefit from enhanced transparency regarding privacy, terms, and security policies. Strategic improvements in these areas would strengthen compliance and user trust.

80
50
2
65
75
85
100
e-commercepackagingretailscgpthailand+3 more
React (implied by Venia CSS and JS chunks)Google Tag ManagerGoogle AnalyticsFacebook Pixel+3
2025-10-03T17:01:27.636Z
D

Danfoss

danfoss.com

82
EnergyDenmarkenterpriseLOW

Danfoss is a global enterprise specializing in engineering solutions that enhance machine productivity, reduce emissions, lower energy consumption, and enable electrification. The company positions itself as a family-owned business focused on long-term stakeholder value, targeting industrial and commercial sectors primarily in energy and transportation. The website reflects a mature digital presence with comprehensive content, strong branding, and professional design. Technically, the site leverages modern technologies including Google Tag Manager, Salesforce Commerce Cloud, Microsoft ASP.NET, and Auth0 for authentication, indicating a robust and scalable infrastructure. Security posture is strong with HTTPS enforced and use of secure third-party services, though explicit security headers could be verified further. Privacy compliance is well addressed with detailed cookie consent mechanisms and comprehensive privacy policies. However, the absence of WHOIS registration data is a notable anomaly that slightly impacts trust but does not detract from the overall legitimacy given the professional web presence and trusted integrations. Strategic recommendations include enhancing security header transparency, publishing incident response and vulnerability disclosure policies, and improving direct contact information visibility.

75
83
47
98
90
80
100
industrialenergyelectrificationmanufacturingb2b+4 more
Google Tag ManagerSalesforceMicrosoft ASP.NETAuth0+3

Partner Domains:

danfoss.secure.force.com
service
accounts.danfoss.com
service

+1 more partners

2025-10-03T16:20:18.591Z
geojs.io favicon

GeoJS

geojs.io

71
TechnologyN/asmallMEDIUM

GeoJS is a small technology company providing a highly available REST/JSON/JSONP IP Geolocation lookup API service. The website is professionally designed and targets developers and businesses requiring geolocation data for IP addresses. The business model is based on offering free API access supported by sponsorships from reputable technology companies such as DigitalOcean, Cloudflare, and DNS Spy. The site includes useful features like ChatOps integration and multiple data formats with no current rate limits. Technically, the website is built using modern static site generation technology (Hugo), styled with Bulma CSS, and hosted on Netlify with backend API services powered by DigitalOcean and Cloudflare CDN. The site is fast, mobile optimized, and accessible with good SEO practices. The use of HTTPS is enforced, but some security headers are not explicitly detected in the HTML content. From a security perspective, the site demonstrates good baseline practices including HTTPS and CORS support. However, it lacks visible security policies, incident response information, and vulnerability disclosure mechanisms. The WHOIS data is unavailable due to privacy protection or query failure, which is common for small tech services but reduces transparency. No critical vulnerabilities or exposed sensitive data were found in the content. Overall, GeoJS presents a trustworthy and professional service with a solid technical foundation. Strategic improvements include adding security headers, publishing security and incident response policies, and implementing a vulnerability disclosure program to enhance trust and compliance.

85
58
2
100
65
80
100
geoipapigeolocationrestjson+2 more
JavaScriptHugoBulma CSSNetlify+1
2025-10-03T15:43:54.950Z
E

emcpi.com | 526: Invalid SSL certificate

emcpi.com

47
OtherN/asmallHIGH

The website emcpi.com is currently inaccessible due to an invalid SSL certificate on the origin server, resulting in a Cloudflare error 526 page being served. This prevents any meaningful content or business information from being accessed or analyzed. The domain is registered with NameCheap since 2019 and uses Cloudflare DNS services, but lacks DNSSEC and proper SSL configuration. No privacy, cookie, or terms of service policies are present, nor are there any contact details or business descriptions visible. The technical infrastructure relies on Cloudflare as a CDN and WAF, but the misconfiguration severely impacts availability and trust. From a security perspective, the invalid SSL certificate is a critical vulnerability that must be addressed immediately to restore secure access. The absence of security headers and policies further weakens the security posture. No analytics or tracking technologies are detected, indicating minimal digital maturity or possibly a placeholder site. The lack of business information and trust indicators limits the ability to assess market position or business credibility. Overall, the site scores very low on content quality, technical implementation, security posture, privacy compliance, and business credibility due to the blocking error and lack of accessible content. Strategic remediation should prioritize fixing the SSL certificate issue, implementing standard security headers, and publishing essential policies and contact information to improve trust and compliance.

-
35
2
70
75
70
100
errorsslcloudflaresecurityblocked
Cloudflare
2025-09-07T12:57:18.901Z
memeinsider.com favicon

Meme Insider

memeinsider.com

61
MediaN/asmallMEDIUM

Meme Insider is a niche media publication specializing in internet culture and memes, operating primarily through subscription-based magazine releases both in print and digital formats. The website positions itself as a leading internet trends magazine and is a Know Your Meme publication, targeting enthusiasts of meme culture and digital media consumers. The business model revolves around premium subscriptions and content delivery, with a small-sized operation founded in 2018. Technically, the website is built using modern web technologies including React and Gatsby, leveraging Cloudflare for DNS and GoDaddy for domain registration. The site demonstrates good performance, mobile optimization, and accessibility, with integration of analytics and marketing tools such as Google Tag Manager, Facebook Pixel, and Hotjar. Security practices include HTTPS enforcement and use of reCAPTCHA on forms, though there is room for improvement in DNS security and HTTP security headers. From a security perspective, the site maintains a good posture with no critical vulnerabilities detected. However, the absence of DNSSEC, lack of explicit security headers, and missing cookie consent mechanisms indicate areas for enhancement, especially to align with privacy regulations like GDPR. The WHOIS data aligns well with the website's business claims, showing consistent registration details and domain age appropriate to the business history. Overall, Meme Insider presents a professional and trustworthy online presence with solid technical infrastructure and a clear business focus. Strategic improvements in privacy compliance and security hardening would further strengthen its risk profile and user trust.

65
53
2
45
75
70
100
internettrendsmemesmediamagazinesubscription
ReactGatsbyCloudflareGoogle Tag Manager+3

Partner Domains:

memeinsider.memberful.com
partner
2025-09-07T05:39:48.859Z
ravenspacepublishing.org favicon

RavenSpace

ravenspacepublishing.org

66
EducationN/asmallMEDIUM

RavenSpace is a specialized digital publishing platform focused on media-rich, interactive books that facilitate respectful collaboration between Indigenous communities and scholars. The platform emphasizes cultural knowledge circulation across generations and offers educational multimedia content such as stories, language teachings, and animations. Supported by the Mellon Foundation, RavenSpace positions itself as a niche academic and cultural resource with peer-reviewed and community-approved content. Technically, the website is built on modern frameworks including Next.js and React, hosted on Cloudflare Pages, and uses TinaCMS for content management. The site demonstrates excellent design quality, mobile optimization, and accessibility, with fast performance and a clean user experience. Security posture is strong with HTTPS enforced and appropriate security headers, though some compliance aspects like cookie consent and terms of service are missing. Overall, the site is trustworthy and professional, with no detected vulnerabilities or suspicious elements. The WHOIS data is unavailable due to privacy protection, which is justified given the platform's focus and community sensitivity. Strategic recommendations include adding cookie consent, terms of service, and vulnerability disclosure policies to enhance compliance and trust.

55
53
2
85
75
75
100
digitalpublishinginteractivebooksindigenousknowledgeeducationmultimedia+2 more
ReactNext.jsCloudflareTinaCMS
2025-09-07T05:38:43.685Z
D

Dune

smlxl.io

54
TechnologyN/amediumMEDIUM

The website dune.com is currently inaccessible due to a Cloudflare Web Application Firewall (WAF) block, which prevents access to any substantive content. As a result, no direct business descriptions, policies, or contact information are available for analysis. The domain is well-established, registered since 1997, and shows no signs of privacy protection or suspicious registration patterns, indicating legitimacy. The technical infrastructure includes Cloudflare security services and hosting via Amazon Registrar, Inc. However, the inability to access the actual website content severely limits the assessment of the company's digital maturity and security posture beyond the presence of a robust WAF. Given the block, the security posture is partially observable only through the presence of Cloudflare protection, but no detailed security policies or incident response information are available. Privacy compliance indicators such as GDPR adherence, cookie consent mechanisms, and data protection officer contacts are not found. The lack of accessible content also precludes evaluation of business credibility, user experience, or marketing practices. Overall, the site appears legitimate based on WHOIS data but is currently inaccessible for a full security and compliance audit. Strategic recommendations focus on resolving access issues to enable comprehensive analysis and ensuring that privacy and security policies are publicly accessible once the site is reachable.

35
35
2
80
75
85
100
securitycloudflareblockedwafprotection
Cloudflare
2025-09-06T22:41:29.101Z
plentydefi.com favicon

Plenty

plentydefi.com

57
FinanceN/asmallMEDIUM

Plenty DeFi is a decentralized finance platform focused on sustainable yield farming on the Tezos blockchain. The website positions itself as a beta product aimed at bringing more liquidity and users to the Tezos DeFi ecosystem. The platform targets DeFi users and liquidity providers interested in yield farming opportunities within the Tezos blockchain environment. The business model revolves around decentralized finance services, specifically yield farming and liquidity provision, positioning itself as a niche player in the blockchain finance sector. Technically, the website is built using modern JavaScript frameworks such as React and Webpack, hosted and protected by Cloudflare services. The site demonstrates moderate performance and basic mobile optimization. However, accessibility and SEO optimizations are minimal, and no CMS is detected. The technical infrastructure is adequate for a small-scale DeFi project but could benefit from enhancements in accessibility and SEO. From a security perspective, the website uses HTTPS and has domain status locks that prevent unauthorized domain transfers or deletions. However, DNSSEC is not enabled, and no advanced security headers are detected in the provided data. The absence of privacy, cookie, and terms of service policies indicates gaps in compliance and user transparency. No contact or incident response information is provided, limiting trust and security communication. Overall, the website presents a functional but basic online presence for a DeFi project in beta. The lack of privacy and cookie policies, absence of contact information, and minimal security headers reduce the overall trust and compliance posture. Strategic improvements in security practices, compliance documentation, and user communication are recommended to enhance credibility and user trust.

55
35
2
60
60
80
100
plentydefiplentytokenyieldfarmingtezostezosdefiplentydao
ReactWebpackCloudflare
2025-09-06T18:05:32.254Z
aave.com favicon

Aave

aave.com

68
FinanceN/alargeMEDIUM

Aave is a leading decentralized finance (DeFi) protocol that enables users to supply, borrow, swap, and stake digital assets across multiple blockchain networks. It operates as a non-custodial liquidity market with a strong emphasis on open-source development and community governance. The platform holds a prominent market position as one of the largest liquidity protocols in the DeFi space, offering innovative services such as the Aave-native stablecoin GHO and multi-network deployment capabilities. The website reflects a mature and professional digital presence with excellent design, clear navigation, and comprehensive content tailored to DeFi users, developers, and financial institutions. Technically, the site leverages modern web technologies including React and Next.js, hosted on Cloudflare for performance and security. It is optimized for mobile devices and accessibility, with fast loading times and proper SEO practices. Security is robust, featuring HTTPS, security headers, public audit reports, and a bug bounty program hosted on Immunefi. However, DNSSEC is not enabled, and a security.txt file is absent, which are areas for improvement. The security posture is strong with no detected vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies, including consent mechanisms and GDPR adherence. Business credibility is high, supported by transparent domain registration, consistent branding, and trust signals such as community governance and partnerships. No direct contact emails or phone numbers are publicly listed, which is common for decentralized protocols but could be enhanced for user support. Overall, Aave presents a secure, trustworthy, and technically advanced platform with a clear focus on DeFi innovation and community engagement. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, and enhancing incident response contact transparency to further strengthen trust and security culture.

40
53
20
85
75
80
100
defifinanceblockchaincryptocurrencylending+5 more
ReactNext.jsCloudflareWeb3 integrations+2

Partner Domains:

app.aave.com
service
governance.aave.com
service

+1 more partners

2025-09-06T11:10:27.346Z
mintology.app favicon

Mintology, Inc.

mintology.app

67
TechnologyN/aenterpriseMEDIUM

Mintology, Inc. is an enterprise-focused technology company specializing in NFT API solutions that enable businesses to integrate blockchain technology for customer engagement, loyalty, and memberships. The company is positioned as a trusted provider for Fortune 500 clients and offers a comprehensive suite of NFT-related products including wallets, token gating, tokenization, and gasless minting. Their market position is strong within the NFT and blockchain technology sector, targeting large enterprises and global businesses. Technically, Mintology's website is built on a modern React and Next.js stack, hosted behind Cloudflare, ensuring fast performance and good mobile optimization. The site employs security best practices such as HTTPS, security headers, and does not expose sensitive data. However, it lacks a visible cookie consent mechanism and detailed security or incident response policies. From a security perspective, the site demonstrates a mature posture with strong SSL configuration and security headers. No vulnerabilities or exposed sensitive data were detected. The absence of explicit security contact information and vulnerability disclosure policies is a minor gap. Overall, the site is secure and trustworthy. The overall risk assessment is low, with recommendations to improve privacy compliance by adding cookie consent and publishing security policies. Enhancing transparency with direct contact emails for security and abuse reporting would further strengthen trust. The website is professional, well-branded, and provides clear business information, supporting its credibility in the enterprise NFT market.

55
53
2
75
75
90
100
nftenterpriseblockchainapitechnology+2 more
ReactNext.jsCloudflareGoogle Tag Manager

Partner Domains:

mintable.com
partner
immutable.com
partner

+2 more partners

2025-09-06T10:02:46.180Z