Skip to main content

High-risk security reports

Browse 46,997 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157364
Websites
130
Industries
113
Countries
52
Avg Score
Page 906 of 940|Showing 45251-45300 of 46997
O

OPEC Fund for International Development (OFID)

ofid.org

30
GovernmentAustriamediumHIGH

The OPEC Fund for International Development (OFID) is a mature, established international development finance institution founded in 1976 and headquartered in Austria. It serves member and partner countries by providing public sector lending, private sector and trade finance, grants, and special initiatives aimed at sustainable development. The website reflects a professional and comprehensive digital presence, targeting governments, investors, and development stakeholders globally. The content is rich, well-structured, and accessible, supporting the organization's mission to drive development and empower communities. Technically, the website employs modern technologies including a CMS platform (Ibexa), CDN (Fastly), and analytics (Google Analytics). The site is mobile-optimized with good accessibility and SEO practices. However, the absence of a valid SSL certificate and lack of modern TLS protocol support significantly impact the security posture, exposing the site to potential risks. Security-wise, the site implements several security headers such as Content Security Policy, X-Frame-Options, and Referrer Policy, but critical gaps exist in SSL/TLS configuration. No incident response or vulnerability disclosure information is found, indicating areas for improvement in security transparency and readiness. Overall, the website is credible and trustworthy, supported by consistent WHOIS data and a long domain history. Strategic recommendations include immediate SSL/TLS remediation, enabling HSTS, and enhancing incident response capabilities to strengthen security and compliance posture.

75
-
5
50
-
85
20
developmentfinanceopecinternationaldevelopmentpublicsectorlendingtradefinance+2 more
Google AnalyticsFastly CDNVarnish CacheBootstrap (implied by navbar classes)+2

Partner Domains:

opecfund.org
partnerpending
2025-06-15T21:48:25.949Z
B

BMO Global Asset Management

bmogam.nl

35
FinanceCanadalargeHIGH

BMO Global Asset Management (BMO GAM) is a leading Canadian asset manager offering a broad range of investment products including mutual funds, ETFs, and alternative products. The website clearly targets investors, advisors, and institutional clients, reflecting a mature and well-established financial services business. The company operates under the larger Bank of Montreal (BMO) umbrella, reinforcing its market position and credibility. Technically, the website leverages modern web technologies such as Next.js and integrates with Adobe Launch and OneTrust for marketing and compliance. Hosting is provided via Akamai CDN, ensuring global content delivery. However, the absence of a valid SSL certificate and disabled TLS protocols represent significant technical and security shortcomings that undermine user trust and data protection. From a security perspective, while some security headers like HSTS and X-Frame-Options are present, the lack of HTTPS and modern TLS support is a critical vulnerability. No published security policies, incident response contacts, or vulnerability disclosure mechanisms were found, indicating gaps in security transparency and readiness. Overall, the website is professionally designed and content-rich, but the lack of proper SSL/TLS configuration and security disclosures lowers its security posture and trustworthiness. Strategic improvements in SSL deployment, security policy publication, and DNS security would significantly enhance the site's security and compliance standing.

40
-
5
50
-
40
100
financeassetmanagementinvestmentcanadianbusinessbmo
React (Next.js)jQueryjQuery UIOneTrust Cookie Consent+5
2025-06-15T21:48:25.719Z
stantonchase.com favicon

Stanton Chase

stantonchase.com

40
OtherN/alargeHIGH

Stanton Chase is a globally recognized executive search and leadership consultancy firm founded in 1990. It operates with a large international footprint, boasting 70 offices and 350 consultants across 45 countries. The company specializes in retained executive search, leadership assessment, succession planning, and onboarding services, targeting corporate clients seeking top leadership talent. The website is professionally designed, content-rich, and well-branded, reflecting a high level of business maturity and market positioning. Technically, the website uses modern frameworks such as Nuxt.js and is hosted behind Cloudflare, leveraging CDN and security features. However, a critical security gap exists due to the absence of a valid SSL certificate, resulting in no HTTPS support. This significantly undermines the security posture despite the presence of some security headers. The site lacks a cookie consent mechanism despite using tracking and marketing automation scripts, indicating partial privacy compliance. Security-wise, the site has implemented some best practices like HSTS and X-Frame-Options headers but fails to provide a secure encrypted connection, which is a major vulnerability. No incident response or security policy information is publicly available. The WHOIS data confirms the domain's legitimacy and maturity, consistent with the company's claimed history. Overall, Stanton Chase's website demonstrates strong business credibility and content quality but requires urgent security improvements to protect user data and enhance trust. Privacy compliance should also be improved by implementing explicit cookie consent mechanisms.

55
18
-
50
-
80
100
executivesearchleadershipconsultancyglobalretainedsearchboardservices+1 more
Nuxt.jsCloudflareJavaScriptNuxt
2025-06-15T21:48:25.454Z
leica-microsystems.com favicon

Leica Microsystems

leica-microsystems.com

40
ManufacturingGermanylargeHIGH

Leica Microsystems is a well-established global leader in microscopy and imaging solutions, serving diverse sectors including life sciences, industrial manufacturing, medical specialties, and education. The company offers a broad portfolio of products ranging from light and confocal microscopes to software and consumables, supported by comprehensive service and application support. The website reflects a mature digital presence with rich, professional content and consistent branding, targeting scientific and industrial professionals worldwide. Technically, the site is built on TYPO3 CMS with modern frontend technologies and integrates marketing and analytics tools such as Google Tag Manager and OneTrust for cookie consent. However, the current lack of a valid SSL certificate and absence of HTTPS significantly undermines the security posture, despite the presence of several security headers and policies. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR adherence. WHOIS data confirms the domain's maturity and legitimacy, registered under Network Solutions without privacy protection, consistent with the company's profile. Strategic improvements in SSL/TLS configuration and enhanced security practices are recommended to elevate trust and protect user data.

85
33
5
50
-
70
100
microscopyimaginglifesciencemedicalindustrial+2 more
TYPO3 CMSJavaScriptSwiper.jsGoogle Tag Manager+2

Partner Domains:

danaher.com
parentpending
atto-tec.com
subsidiarypending
2025-06-15T21:48:24.823Z
szco.com favicon

SZCO Supplies, Inc.

szco.com

35
RetailUnited StatesmediumHIGH

SZCO Supplies, Inc. operates a wholesale e-commerce platform specializing in knives, swords, self-defense products, and historical replicas. The company targets wholesale buyers, collectors, and enthusiasts in the United States, offering a broad catalog of niche products. The website is built on a classic ASP.NET Web Forms platform hosted on Microsoft IIS, with Ephost as the hosting provider. The technical infrastructure includes jQuery and Bootstrap for frontend interactivity and layout. However, the site lacks modern performance optimizations and accessibility features. From a security perspective, the website does not have a valid SSL certificate, resulting in no HTTPS support, which is a critical vulnerability. Security headers are minimal, and no advanced security practices like HSTS or OCSP stapling are implemented. Privacy compliance is poor, with no visible privacy or cookie policies, and user tracking is done via Google Analytics without clear consent mechanisms. Contact information is clearly presented, enhancing business credibility, but the lack of security and privacy controls poses risks. Overall, the site is functional and professionally designed but requires urgent improvements in security and privacy compliance to protect user data and build trust. Strategic recommendations include obtaining a valid SSL certificate, enabling HTTPS, implementing comprehensive privacy policies, and enhancing security headers and protocols.

15
-
-
50
-
85
100
e-commercewholesaleknivesswordsself-defense+1 more
ASP.NETMicrosoft IIS 8.5jQueryBootstrap+3
2025-06-15T21:48:24.078Z
konicaminolta.at favicon

Konica Minolta Business Solutions Austria GmbH

konicaminolta.at

40
TechnologyAustrialargeHIGH

Konica Minolta Business Solutions Austria GmbH operates as a leading technology and managed service provider specializing in intelligent workplace solutions, printing systems, cloud services, and IT infrastructure management. The company holds a strong market position in Austria and the DACH region, supported by a broad portfolio including multifunctional printers, professional printing, enterprise software, cybersecurity, and healthcare solutions. Their business model leverages direct sales and a partner network to serve a diverse business clientele. Technically, the website is built on modern frameworks such as Next.js and hosted on Vercel, with a CMS likely powered by Contentstack. The site demonstrates good mobile optimization, accessibility, and SEO practices, although performance is currently slow. Analytics and consent management tools like Google Tag Manager and Usercentrics are integrated, indicating a mature digital infrastructure. From a security perspective, the absence of a valid SSL certificate and HTTPS support is a critical vulnerability, severely impacting the site's security posture. While some security headers are present, the lack of TLS protocols and session management features exposes the site to risks. Privacy compliance is strong, with comprehensive policies and consent mechanisms in place. Overall, the site is professionally designed and content-rich, reflecting a reputable business. However, the critical lack of HTTPS undermines trust and security, necessitating urgent remediation to protect users and maintain compliance.

55
-
5
50
-
85
100
technologyprintingitserviceshealthcaremanagedservices+2 more
Next.jsReactVercel hostingGoogle Tag Manager+2
2025-06-15T21:48:21.687Z
seso.at favicon

seso media group gmbh

seso.at

28
MediaAustriamediumHIGH

SESO media group gmbh is a well-established Austrian digital agency specializing in consulting, creative services, and digital development. The company targets businesses seeking to enhance their digital presence and user experience, positioning itself as a partner for digital transformation in the Economy of Experiences. Their client portfolio includes notable brands such as A1 Telekom Austria, Jägermeister, Red Bull, and AbbVie, indicating a strong market presence in Austria and Switzerland. The website content is professionally crafted, with clear messaging and consistent branding that supports their market positioning. Technically, the website is built on WordPress with a modern frontend stack including Bootstrap, jQuery, GSAP, and AOS for animations. The site is mobile-optimized and SEO-friendly, leveraging Yoast SEO plugin and structured data for enhanced search visibility. Hosting appears to be managed via GlobeDom DNS services, and email protection is handled through Microsoft Outlook's mail protection services. However, performance metrics are unavailable, and accessibility is basic but functional. From a security perspective, the site lacks a valid SSL/TLS certificate, resulting in no HTTPS support, which is a critical vulnerability. Although several security headers are implemented, the absence of HTTPS severely undermines the overall security posture. No vulnerability disclosure or incident response policies are publicly available. Privacy and cookie policies are present and appear GDPR compliant, with a consent mechanism implemented. Contact information is comprehensive, including email, phone, physical address, and a detailed contact form. Overall, while SESO demonstrates strong business credibility and digital maturity, the lack of HTTPS is a significant risk that must be addressed immediately to protect user data and maintain trust. Strategic recommendations include installing a valid SSL certificate, enabling modern TLS protocols, and enhancing security configurations. The website otherwise reflects a professional and trustworthy digital agency with a solid market position.

80
-
5
50
-
85
20
digitalagencyconsultingcreativedevelopmentmediatechnology+4 more
nginxjQueryBootstrapGSAP+5
2025-06-15T21:48:21.509Z
V

viennaconservatory.at

viennaconservatory.at

37
EducationAustriasmallHIGH

The website for viennaconservatory.at currently serves only a minimal maintenance placeholder page with no substantive content or metadata. The domain is registered and hosted behind Cloudflare, using PHP 8.3.22, but lacks a valid SSL certificate, resulting in HTTP-only access. No privacy, cookie, or terms of service policies are present, and no contact information or business details are provided on the site. This severely limits the site's usability and trustworthiness for visitors. From a technical perspective, the site uses a basic PHP backend and Cloudflare for hosting and DNS, but performance data is unavailable and the site shows poor SEO, accessibility, and mobile optimization. Security headers are minimal and no advanced security practices are implemented. The absence of HTTPS is a critical security issue. The security posture is weak due to the lack of SSL/TLS encryption and missing security headers. No vulnerabilities such as Heartbleed or POODLE were detected, but the site is exposed to risks from unencrypted traffic. The lack of privacy and cookie policies also indicates non-compliance with GDPR and related regulations. Overall, the site is not currently functional for end users and presents significant security and compliance gaps. Strategic recommendations include implementing HTTPS with a valid certificate, publishing privacy and cookie policies with consent mechanisms, adding contact and business information, and improving content quality and SEO to enhance trust and usability.

15
-
-
50
-
85
100
maintenanceeducationconservatoryvienna
PHP 8.3.22Cloudflare
2025-06-15T21:48:16.563Z
isg.com favicon

ISG - International Service Group

isg.com

38
OtherAustrialargeHIGH

ISG - International Service Group is a well-established HR consulting company founded in 1999, specializing in recruiting, executive search, training, and personnel management services. With over 800 employees and more than 60 offices worldwide, ISG holds a strong market position as a leading personnel consulting provider in Europe and beyond. Their business model focuses on delivering tailored HR solutions across multiple industries including automotive, finance, technology, and healthcare. The website content is professionally presented, targeting businesses seeking comprehensive HR services internationally. Technically, the website is built on WordPress with modern plugins such as Gravity Forms and uses LiteSpeed Cache for performance optimization. However, the site currently lacks a valid SSL certificate and does not support modern TLS protocols, which significantly impacts its security posture. The site includes a cookie consent mechanism and privacy policy, indicating awareness of privacy compliance, but lacks explicit security or incident response policies. From a security perspective, the absence of HTTPS and modern encryption protocols is a critical vulnerability that exposes users to risks. While some security headers like HSTS are present, the overall SSL/TLS configuration is poor. There are no detected vulnerabilities related to common exploits, but the lack of encryption is a major concern. WHOIS data confirms the legitimacy and consistency of the domain registration with the business claims. Overall, ISG's website demonstrates strong business credibility and content quality but requires urgent security improvements to protect user data and enhance trust. Strategic recommendations include immediate installation of a valid SSL certificate, enabling modern TLS protocols, and implementing additional security headers and policies to improve the security posture and compliance.

30
18
-
50
-
85
100
hrrecruitingexecutivesearchtrainingpersonnelmanagement+2 more
nginxLiteSpeed CacheWordPress 6.8.1Gravity Forms+3
2025-06-15T21:48:14.423Z
hill-rom.com favicon

Hillrom

hill-rom.com

40
HealthcareUnited StatesenterpriseHIGH

Hillrom is a leading medical technology provider specializing in healthcare equipment and connected care solutions for hospitals and healthcare providers globally. The company offers a wide range of products including smart beds, patient monitoring devices, care communication systems, and surgical equipment. With a strong enterprise presence and integration with Baxter International, Hillrom positions itself as a key player in advancing connected care. The website reflects a professional and comprehensive digital presence with multiple localized versions and extensive product and service information. Technically, the site is built on Adobe Experience Manager and leverages modern technologies such as Adobe Launch and Google Tag Manager, hosted behind Cloudflare for performance and security. However, the SSL/TLS configuration is currently deficient with an invalid certificate and no enabled TLS protocols, which poses a significant security risk. Privacy and compliance policies are well documented, indicating a mature approach to data protection and regulatory adherence. Overall, the site is trustworthy and professional but requires urgent remediation of SSL issues to improve security posture and user trust.

90
18
15
50
-
85
100
healthcaremedicaltechnologyhospitalequipmentpatientmonitoringconnectedcare+1 more
Adobe Launch (Adobe DTM)Google Tag ManagerLucidworks Search UICloudflare CDN and security+6

Partner Domains:

baxter.com
partner40
bardydx.com
subsidiarypending

+1 more partners

2025-06-15T21:48:14.064Z