Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149319
Websites
130
Industries
113
Countries
52
Avg Score
Page 92 of 99|Showing 4551-4600 of 4914
smarteyes.se favicon

Smarteyes

smarteyes.se

54
RetailSwedenlargeMEDIUM

Smarteyes is a well-established Swedish retail optician chain founded in 2007, offering a wide range of eyewear products including glasses, sunglasses, and contact lenses, alongside professional eye care services such as eye examinations. The company emphasizes affordable, high-quality Scandinavian design and operates over 70 physical stores across Sweden. As part of the global EssilorLuxottica group, Smarteyes benefits from strong market positioning and brand recognition. The website supports online booking and subscription services, reflecting a modern e-commerce approach. Technically, the website is built on a modern stack including React and Next.js, integrated with advanced search via Algolia, and uses robust analytics and consent management tools such as Google Tag Manager and OneTrust. The site is hosted with Cloudflare, ensuring good performance and security. Accessibility and SEO best practices are well implemented, providing a good user experience across devices. From a security perspective, the site enforces HTTPS, employs multiple security headers, and avoids exposing sensitive data. While no explicit security policy or incident response information is published, the overall security posture is strong. Privacy compliance is evident with comprehensive privacy and cookie policies and active consent mechanisms, aligning with GDPR requirements. Overall, Smarteyes presents a professional, trustworthy, and user-friendly online presence with strong business credibility and technical maturity. Strategic recommendations include publishing a dedicated security policy, incident response contacts, and vulnerability disclosure information to further enhance trust and compliance.

70
15
5
85
-
70
100
opticianglassescontactlensessunglassesretail+5 more
ReactNext.jsGoogle Tag ManagerAlgolia Search+4

Partner Domains:

essilorluxottica.com
parent
press.smarteyes.se
service

+1 more partners

2025-06-18T08:55:47.188Z
I

Indpro AB

indpro.se

44
TechnologySwedenmediumHIGH

Indpro AB is a Swedish IT consulting and staffing company specializing in providing top IT experts and development teams to businesses. With over 15 years of experience and a client base exceeding 250 satisfied customers, Indpro positions itself as a flexible and reliable partner for companies needing to augment their teams or develop products. Their services emphasize agile methodologies and SCRUM practices, ensuring efficient collaboration and delivery. Technically, the website is built on modern frameworks such as Next.js and React, with integration of Google Analytics and Tag Manager for performance and user behavior tracking. The site is mobile-optimized and presents a professional design with clear navigation, although some accessibility features could be enhanced. Security-wise, HTTPS is enabled, and cookie consent mechanisms are implemented, but there is room for improvement in security headers and explicit security policies. Overall, the security posture is moderate with no critical vulnerabilities detected, but the absence of incident response information and vulnerability disclosure pages suggests an opportunity to strengthen trust and compliance. The domain registration data aligns well with the business claims, supporting legitimacy and trustworthiness. Strategically, Indpro should focus on enhancing security transparency, improving accessibility, and possibly publishing terms of service and incident response details to elevate their compliance and trust levels further.

15
15
-
75
-
65
100
itconsultingsoftwaredevelopmentteamaugmentationagilescrum+2 more
ReactNext.jsJavaScriptGoogle Analytics+1
2025-06-18T08:55:47.152Z
diy.org favicon

DIY.ORG - Where every kid is a maker & creator!

diy.org

50
EducationN/amediumMEDIUM

DIY.org is a well-established online educational platform focused on providing a safe and engaging community for kids to learn creative skills through hands-on projects, video challenges, and courses. The platform targets children and families, offering a subscription-based model with a free trial to encourage skill development in areas such as art, coding, and gaming. The website demonstrates a strong market position with over 500,000 families trusting the service and more than 2 million projects completed. Technically, the site is built on modern web technologies including React and Next.js, with integrations for Stripe payments and analytics tools like PostHog and Google Tag Manager. The site is optimized for performance and mobile responsiveness, providing an excellent user experience with clear navigation and professional design. From a security perspective, the website enforces HTTPS, employs security headers, and avoids exposing sensitive data. However, it lacks publicly available security policies, incident response plans, and vulnerability disclosure mechanisms, which are recommended for enhanced transparency and trust. Privacy compliance is generally good, with a comprehensive privacy policy present, though a visible cookie consent mechanism is missing. Overall, DIY.org presents a trustworthy and professional online learning environment for kids, with strong content quality and technical implementation. Strategic improvements in privacy consent and security transparency would further strengthen its security posture and compliance.

35
28
5
85
-
60
100
educationkidslearningcreativecommunity+4 more
ReactNext.jsStripePostHog analytics+2
2025-06-18T08:07:09.444Z
L

Lightspeed Financial Services Group LLC

lightspeed.com

65
FinanceUnited StatesmediumHIGH

Lightspeed Financial Services Group LLC operates a professional brokerage platform specializing in low-cost stock, options, and futures trading tailored for active and professional traders. The company offers a suite of customizable trading platforms, including Lightspeed Trader, web and mobile solutions, and specialty platforms, supported by advanced technology and risk management tools. Positioned as a reliable and technologically advanced brokerage, Lightspeed emphasizes fast execution, platform stability, and extensive order management capabilities. The website reflects a mature digital presence with comprehensive content, clear pricing, and regulatory compliance signals such as FINRA, NFA, and SIPC memberships. Technically, the site leverages modern frameworks like React and Next.js, integrates multiple marketing and analytics tools, and employs security best practices including HTTPS and security headers. While no dedicated security policy or incident response contacts are published, the overall security posture is strong with no visible vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. The site is professionally designed, mobile-optimized, and provides multiple contact channels, enhancing user trust and engagement.

70
73
18
85
-
85
100
financetradingbrokeragestocksoptions+3 more
ReactNext.jsHubSpot (forms, analytics, ads pixel)Google Tag Manager+5
2025-06-17T22:10:39.583Z
H

Hasura, Inc.

promptql.io

65
TechnologyUnited StatesmediumHIGH

PromptQL is an AI platform developed by Hasura, Inc. that provides enterprise-grade natural language analysis and automation solutions with human-level reliability. The platform is designed to codify unique business language into deterministic commands for large language models, enabling complex data-driven processes to be automated and analyzed efficiently. Positioned as a reliable AI staff-level analyst or engineer, PromptQL targets enterprise data and AI teams seeking to enhance decision-making and operational efficiency. Technically, the website leverages modern web technologies including React and Next.js, with integrations to marketing and analytics tools such as Marketo, Segment, Google Analytics, Microsoft Clarity, and PostHog. The site demonstrates good mobile optimization, SEO practices, and moderate performance. Hosting appears to be managed by Hasura or associated cloud providers. From a security perspective, the site employs HTTPS with strong security headers like Content Security Policy and Referrer Policy. It uses a comprehensive cookie consent mechanism compliant with GDPR, offering users granular control over cookie categories. No critical vulnerabilities or exposed sensitive data were detected. However, explicit security policies and incident response information are not published, representing an area for improvement. Overall, the website presents a professional, trustworthy, and well-structured digital presence for PromptQL, with strong privacy compliance and marketing transparency. Strategic recommendations include publishing detailed security and incident response policies, enhancing accessibility features, and maintaining vigilance over third-party script security to sustain trust and compliance.

15
83
25
75
60
75
100
aiautomationenterprisedataanalysisnaturallanguageprocessing+4 more
ReactNext.jsGoogle FontsMarketo+4

Partner Domains:

hasura.io
parent
2025-06-17T22:08:48.368Z
swetrix.com favicon

Swetrix

swetrix.com

52
TechnologyUnited KingdomsmallMEDIUM

Swetrix is a privacy-first web analytics platform positioned as a cookieless and GDPR-compliant alternative to Google Analytics. The company targets website owners and businesses seeking detailed user insights without compromising visitor privacy. Their business model is subscription-based with a free trial and tiered pricing based on monthly event volumes. The platform is open source, enhancing transparency and trust. Technically, Swetrix employs a modern technology stack including React, Vue, Svelte, Node.js, and Next.js frameworks. The website is well-optimized for performance, mobile responsiveness, and accessibility, reflecting a mature digital infrastructure. The absence of cookies for tracking and the use of anonymous data collection methods demonstrate a strong commitment to privacy compliance. From a security perspective, the site enforces HTTPS and avoids collecting personal identifiers, reducing risk exposure. However, explicit security headers and a formal security policy or incident response contacts are not present, representing areas for improvement. No vulnerabilities or exposed sensitive data were detected in the analyzed content. Overall, Swetrix presents a trustworthy and professional online presence with a strong privacy and compliance posture. Strategic recommendations include enhancing security headers, publishing a security policy, and establishing a vulnerability disclosure program to further strengthen security and trust.

30
80
25
60
60
75
-
analyticsprivacygdprcookielessopensource+2 more
ReactVueSvelteNode.js+1
2025-06-17T22:06:54.702Z
swetrix.org favicon

Swetrix

swetrix.org

68
TechnologyUnited KingdomsmallHIGH

Swetrix is a privacy-first web analytics platform offering a cookieless and GDPR-compliant alternative to Google Analytics. Positioned as an ethical and open source solution, it targets website owners and marketers who prioritize user privacy and data ownership. The company provides a subscription-based SaaS model with transparent pricing and a free trial, emphasizing ease of use and comprehensive analytics features including traffic insights, session analysis, marketing funnels, and custom event tracking. Technically, Swetrix employs a modern technology stack including React, Next.js, Node.js, and supports multiple frontend frameworks. The website is well-optimized for performance, mobile responsiveness, and accessibility, reflecting a mature digital infrastructure. The open source nature of the platform enhances transparency and community trust. From a security perspective, the site enforces HTTPS and avoids tracking cookies, aligning with privacy best practices. However, it lacks explicit security policy documentation and incident response contacts, which are recommended for enhanced trust and compliance. No vulnerabilities or exposed sensitive data were detected. Overall, Swetrix presents a strong privacy and security posture with excellent content quality and technical implementation. Strategic improvements include publishing security policies, incident response details, and implementing a cookie consent mechanism despite the cookieless approach to further strengthen compliance and user trust.

30
80
25
80
60
80
100
analyticsprivacycookielessgdpropensource+2 more
ReactVueSvelteNode.js+1
2025-06-17T22:06:48.757Z
tidio.com favicon

Tidio

tidio.com

71
TechnologyN/amediumHIGH

Tidio is a technology company specializing in AI-driven customer service solutions, including live chat, help desk software, and automation tools. Positioned as a trusted provider with over 300,000 business users, Tidio offers a comprehensive platform that integrates AI agents like Lyro to automate up to 67% of customer interactions across multiple channels. Their market presence spans ecommerce, fintech, education, and travel sectors, emphasizing scalability and multilingual support. Technically, Tidio employs a modern web infrastructure based on Next.js and React, with integrations of various analytics and marketing tools such as Google Tag Manager, Amplitude, and Cookiebot. The platform supports multiple operating systems and devices, ensuring excellent mobile optimization and accessibility. Hosting appears to leverage Cloudflare and AWS services, contributing to fast performance and robust security. From a security perspective, Tidio demonstrates strong practices including HTTPS enforcement, SOC 2 certification, and comprehensive cookie consent mechanisms aligned with GDPR and CCPA. No critical vulnerabilities or exposed sensitive data were detected. However, the site could enhance its security posture by publishing an incident response policy and a security.txt file. Overall, Tidio presents a low-risk profile with a high level of professionalism, technical maturity, and compliance. Strategic recommendations include improving transparency around incident response and data protection officer contacts to further build trust and compliance assurance.

45
95
47
65
42
85
100
aicustomerservicechatbotlivechathelpdesk+3 more
ReactNext.jsJavaScriptGoogle Tag Manager+3
2025-06-17T22:01:00.353Z
burgenlandenergie.at favicon

Burgenland Energie

burgenlandenergie.at

40
EnergyAustrialargeHIGH

Burgenland Energie is a regional energy provider based in Austria, specializing in renewable energy solutions such as photovoltaic systems, battery storage, heat pumps, and e-mobility services. The company targets private customers and municipalities within the Burgenland region, emphasizing energy independence and sustainability. Their market position is that of a trusted regional leader in renewable energy, supported by a comprehensive portfolio of products and services tailored to modern energy needs. Technically, the website is built on modern frameworks including React and Next.js, hosted on AWS infrastructure with Amazon S3 and CloudFront for content delivery. The site demonstrates strong digital maturity with fast performance, mobile optimization, and good SEO practices. Integration with marketing and analytics tools like Google Tag Manager and Zoho CRM is implemented with user privacy in mind, including cookie consent mechanisms. From a security perspective, the site enforces HTTPS with a valid SSL certificate and uses AWS KMS for server-side encryption. OCSP stapling is enabled, but HTTP security headers like HSTS are not fully implemented, representing an area for improvement. No critical vulnerabilities or exposed sensitive data were detected. Privacy policies and terms of service are present and comprehensive, supporting GDPR compliance. Overall, the website presents a professional, trustworthy, and secure digital presence aligned with the company's business objectives. Strategic recommendations include enhancing HTTP security headers, continuous monitoring of third-party scripts, and maintaining strong privacy compliance to further strengthen user trust and security posture.

15
18
25
50
82
85
100
energyrenewablephotovoltaicbatteriesheatpumps+3 more
ReactNext.jsAmazon S3CloudFront+3

Partner Domains:

befunkt.at
partner37
fcbe.at
partner38

+2 more partners

2025-06-16T16:23:11.551Z
J

Johnson & Johnson Vision

amo-inc.com

59
HealthcareUnited StatesenterpriseMEDIUM

Johnson & Johnson Vision operates a professional website focused on refractive surgery and related eye health products. The company is a recognized leader in the ophthalmology healthcare sector, offering advanced surgical technologies such as iLASIK and femtosecond lasers. The website targets eye health professionals, providing detailed product information, educational resources, and access to ordering and support services. The business is positioned as a market leader with a strong brand presence and extensive industry experience under the Johnson & Johnson umbrella. Technically, the website leverages modern web frameworks including Next.js and React, integrates advanced analytics and marketing tools such as Google Tag Manager, Optimizely, and WalkMe, and employs robust cookie consent management via OneTrust. The site is well-optimized for mobile devices and accessibility, with good SEO practices and performance metrics. From a security perspective, the site enforces HTTPS, uses security headers, and integrates Google reCAPTCHA Enterprise to protect forms. Privacy compliance is strong, with clear privacy and cookie policies and user consent mechanisms. However, there is no explicit security policy or incident response contact information published, which could be improved. Overall, the website demonstrates a mature digital presence with strong business credibility and security posture. Strategic recommendations include publishing a dedicated security policy, providing incident response contacts, and considering a vulnerability disclosure program to enhance transparency and trust.

70
63
5
70
-
80
100
refractivesurgeryhealthcareophthalmologymedicaldevicesprivacy+2 more
ReactNext.jsGoogle Tag ManagerGoogle reCAPTCHA Enterprise+3

Partner Domains:

productcomplaintcenter.jnj.com
service
jjvisionmedicalaffairs.com
service

+1 more partners

2025-06-15T22:26:26.899Z
nhm.ac.uk favicon

The Natural History Museum

nhm.ac.uk

40
EducationUnited KingdomlargeHIGH

The Natural History Museum website serves as a comprehensive digital portal for one of the UK's leading educational and cultural institutions. It offers extensive information on exhibitions, scientific research, educational resources, and visitor services, targeting a broad audience including the general public, educators, and researchers. The site is well-branded, professionally designed, and provides clear navigation and rich content relevant to its mission. Technically, the website leverages modern web technologies such as React with Next.js and Adobe Experience Manager as its CMS, hosted on Microsoft Azure. While the site is mobile-optimized and accessible, performance is currently hindered by an invalid SSL certificate and lack of enabled TLS protocols, which also impacts the security posture. Security-wise, the site implements some security headers like HSTS and X-Frame-Options but lacks a valid SSL certificate and proper TLS support, which are critical for secure communications. Privacy and cookie policies are comprehensive and GDPR compliant, with a clear consent mechanism in place. Social media integration and tracking tools like Google Tag Manager and Adobe DTM are used responsibly with privacy considerations. Overall, the website is trustworthy and professional but requires urgent remediation of SSL and TLS issues to ensure secure user interactions and improve its security score. Strategic improvements in SSL management and security best practices will enhance user trust and compliance.

45
-
5
50
-
85
100
museumeducationsciencenaturalhistoryuk+1 more
React (Next.js)Adobe Experience Manager (AEM)Google Tag ManagerAdobe DTM (Dynamic Tag Management)+3
2025-06-15T22:12:49.186Z
B

Burgenland Energie

bewag.at

40
EnergyAustriamediumHIGH

Burgenland Energie is a regional energy provider based in Austria, specializing in renewable energy solutions such as photovoltaic systems, battery storage, heat pumps, and e-mobility services. The company targets private customers, municipalities, and businesses within the Burgenland region, emphasizing energy independence and sustainability. Their digital presence includes a professional website with comprehensive product information, customer portals, and active social media channels. Technically, the website is built using modern web technologies including React and Next.js, hosted on AWS infrastructure with CloudFront and S3. While the site is mobile-optimized and well-structured for SEO and accessibility, performance metrics indicate slow loading times, which could be improved. The use of Google Tag Manager and Zoho CRM scripts indicates integration with marketing and customer relationship management tools. From a security perspective, the website lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability that undermines user trust and data security. Other security best practices such as HSTS, OCSP stapling, and session resumption are also missing. Privacy compliance is well addressed with clear privacy and cookie policies and a consent mechanism in place. Overall, the website presents a trustworthy and professional business with strong content and user experience but requires urgent improvements in SSL/TLS configuration to enhance security posture and protect user data effectively.

-
-
-
50
-
50
100
energyrenewableenergyphotovoltaicbatteriesheatpumps+4 more
ReactNext.jsAmazon S3AWS KMS encryption+2

Partner Domains:

befunkt.at
partnerpending
fcbe.at
partnerpending

+3 more partners

2025-06-15T22:07:39.279Z
bytesource.net favicon

ByteSource Technology Consulting GmbH

bytesource.net

40
TechnologyAustriamediumHIGH

ByteSource Technology Consulting GmbH is a medium-sized Austrian technology consulting firm specializing in cloud migration, Atlassian ecosystem services, DevOps, agile software development, and AI-driven business transformation solutions. Positioned as a leading Atlassian Platinum Solution Partner and AWS Advanced Tier Services Partner in Austria, ByteSource serves enterprises and medium to large businesses with a comprehensive portfolio of technology consulting and software development services. The company emphasizes innovation, security, and operational excellence, supported by certifications such as ISO 27001 and TISAX AL3. Technically, the website is built on modern frameworks including Next.js and is hosted on Amazon AWS infrastructure leveraging S3 and CloudFront CDN. The site integrates various marketing and analytics tools such as Google Tag Manager, Facebook Pixel, Zoho SalesIQ, and Leadforensics, reflecting a mature digital marketing strategy. However, performance metrics indicate slow loading times, and while mobile optimization and accessibility are excellent, there is room for improvement in performance. From a security perspective, the site lacks a valid SSL certificate and does not support TLS protocols, which is a critical vulnerability impacting the overall security posture. Security headers are partially implemented, but the absence of HTTPS and modern TLS protocols significantly reduces the security score. Privacy compliance is strong, with comprehensive privacy and cookie policies and consent mechanisms in place, aligning with GDPR requirements. Overall, ByteSource presents a professional and trustworthy online presence with strong business credibility and technical maturity, but the lack of HTTPS and proper SSL/TLS configuration poses a significant risk. Strategic recommendations include immediate remediation of SSL/TLS issues, enhancement of security headers, and performance optimization to improve user experience and security posture.

70
18
-
50
-
50
100
cloudatlassiandevopsagiledevelopmentai+5 more
React (Next.js)Amazon S3 hostingCloudFront CDNGoogle Tag Manager+5
2025-06-15T22:05:44.670Z
aplaceformom.com favicon

A Place for Mom

aplaceformom.com

40
HealthcareUnited StateslargeHIGH

A Place for Mom is a leading senior living referral service that connects families with assisted living, memory care, independent living, home care, nursing homes, and other senior care options. The company operates a large network of communities and home care providers, offering personalized support through expert advisors at no cost to families. Their market position is strong, supported by extensive consumer reviews, award recognitions, and a broad geographic presence across major US cities. Technically, the website is built on modern frameworks such as Next.js and React, leveraging AWS CloudFront for content delivery and integrating advanced analytics and marketing tools like Segment, Optimizely, and Drift. The site demonstrates good mobile optimization, accessibility, and SEO practices, providing a professional and user-friendly experience. However, the security posture is currently weak due to the absence of a valid SSL certificate and lack of HTTPS support, which is a critical vulnerability. While security headers are properly configured, the lack of TLS protocols and OCSP stapling reduces overall security. Privacy compliance is well addressed with comprehensive policies and consent mechanisms. Overall, the website presents a trustworthy and professional front for its business but requires urgent improvements in SSL/TLS implementation to ensure secure user interactions and maintain trust. Strategic recommendations include immediate SSL certificate installation, enabling modern TLS protocols, and enhancing DNS security measures.

95
18
-
50
-
85
100
seniorlivingassistedlivingmemorycarenursinghomeshomecare+3 more
Next.jsReactSegment AnalyticsOptimizely+3
2025-06-15T22:04:04.687Z
f-secure.com favicon

F-Secure Corporation

f-secure.com

40
TechnologyFinlandlargeHIGH

F-Secure Corporation is a well-established Finnish cybersecurity company with over 35 years of experience and a global user base exceeding 30 million. The company offers a comprehensive suite of cybersecurity products including antivirus, VPN, identity protection, and scam protection, targeting both consumers and service providers. Their business model is subscription-based, emphasizing digital security and privacy. The website is professionally designed, multilingual, and rich in content, reflecting a mature digital presence. Technically, the site uses modern frameworks like Next.js and is hosted on Netlify, with good mobile optimization and SEO practices. However, the current SSL/TLS configuration is invalid or missing, which is a critical security concern that needs immediate remediation. Security headers are properly set, but the lack of valid HTTPS reduces the overall security posture. The site complies with GDPR and provides comprehensive privacy and cookie policies. Overall, the domain registration and WHOIS data align well with the company's identity, supporting high legitimacy and trust. Strategic recommendations include renewing SSL certificates, enabling modern TLS protocols, and enhancing security best practices to improve trust and compliance.

-
-
-
50
-
90
100
cybersecurityprivacyvpnantivirusidentityprotection+3 more
Next.jsReactNetlify hostingGoogle Tag Manager+1

Partner Domains:

vodafone.com
partner71
virginmedia.com
partner61

+2 more partners

2025-06-15T22:00:43.295Z