Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149319
Websites
130
Industries
113
Countries
52
Avg Score
Page 93 of 99|Showing 4601-4650 of 4914
playosmo.com favicon

Osmo

playosmo.com

58
EducationUnited StatesmediumMEDIUM

Osmo is an educational technology company specializing in interactive learning systems that combine physical game pieces with digital apps primarily for iPad and iPhone users. The website positions Osmo as an award-winning brand with a focus on fostering social intelligence and creative thinking through hands-on play. The business model centers on e-commerce sales of educational products and digital content, targeting parents and educators seeking engaging learning tools for children. The site is professionally designed with consistent branding and positive media testimonials, indicating a strong market presence in the education sector. Technically, the website is built on modern frameworks such as Next.js and React, hosted behind Cloudflare, and uses Google Tag Manager for analytics. While the site is mobile-optimized and SEO-friendly, performance metrics are unavailable. Security-wise, the site uses HTTPS with a valid SSL certificate but lacks modern TLS protocol support and OCSP stapling, which are important for robust security. Security headers are partially implemented, but critical headers like HSTS are not fully enabled. No privacy or cookie policies were found, indicating gaps in compliance with data protection regulations. Overall, the security posture is moderate with room for improvement in encryption protocols and privacy compliance. The absence of contact information and policy pages reduces transparency and user trust. The domain registration is consistent with the business claims, and no suspicious patterns were detected, supporting the legitimacy of the site. Strategic recommendations include enabling modern TLS protocols, fully implementing HSTS, publishing comprehensive privacy and cookie policies, adding contact information, and establishing a vulnerability disclosure program to enhance security and compliance posture.

40
25
17
50
75
50
100
educationgameslearningipadosmo+1 more
Next.jsReactCloudflareGoogle Tag Manager+3
2025-06-15T21:58:32.300Z
cmcmarkets.com favicon

CMC Markets

cmcmarkets.com

40
FinanceUnited KingdomlargeHIGH

CMC Markets is a well-established global online trading platform founded in 1989, offering leveraged trading on a wide range of financial instruments including forex, indices, commodities, cryptocurrencies, shares, ETFs, and bonds. The company operates multiple trading platforms such as MetaTrader 4, MetaTrader 5, TradingView integration, and its proprietary web and mobile platforms, serving over 1.5 million global clients. It is a FTSE 250 listed company with a strong market position and multiple regulatory licenses, including in Bermuda and the UK. The website is professionally designed, content-rich, and targets retail and institutional traders worldwide. Technically, the website is built on modern frameworks like Next.js and hosted on Vercel, with good mobile optimization and SEO practices. The platform supports multiple device types and integrates third-party services for enhanced user experience and marketing. However, the SSL certificate is currently invalid or missing, which is a critical security concern. Security headers are partially implemented, and there is no evidence of advanced security policies or incident response information on the site. The security posture is moderate with room for improvement, especially in SSL configuration and additional security headers. Privacy and cookie policies are present and indicate GDPR compliance, with clear consent mechanisms. Contact information is comprehensive, including phone, email, and physical addresses in multiple countries. The company demonstrates strong business credibility through trust indicators such as awards, Trustpilot reviews, and regulatory compliance. Overall, CMC Markets presents a professional and trustworthy online trading service with a mature digital presence. Addressing the SSL certificate issue and enhancing security headers would significantly improve the security posture and user trust.

30
33
5
50
-
90
100
financetradingforexcfdcryptocurrency+5 more
React (Next.js)Vercel hostingMetaTrader 4 and 5 platformsTradingView integration+5

Partner Domains:

partner-portal.cmcmarkets.com
partner
signup.cmcmarkets.com
service

+2 more partners

2025-06-15T21:53:36.496Z
larepublica.pe favicon

Grupo La República Publicaciones

larepublica.pe

34
MediaPerulargeHIGH

La República.pe is a prominent Peruvian news media company providing comprehensive news coverage across multiple domains including politics, economy, sports, entertainment, and international affairs. The website offers rich multimedia content such as videos, podcasts, and live updates, targeting Spanish-speaking audiences primarily in Peru. The company is well-established since 1981 and operates several subsidiary and partner sites, reinforcing its market presence. Technically, the site is built on modern web technologies including React and Next.js, hosted on Amazon CloudFront, and integrates advertising and analytics tools like Google Tag Manager, Teads, and Taboola. The site is mobile-optimized and SEO-friendly, providing a good user experience with clear navigation and professional design. From a security perspective, the site currently suffers from an invalid SSL certificate, which is a critical issue that undermines user trust and secure communications. Other security best practices such as HSTS, OCSP stapling, and DNSSEC are not implemented, indicating room for improvement. Privacy compliance is partial, with a comprehensive privacy policy but no detected cookie consent mechanism. Overall, the site is a high-quality, trusted news source with strong business credibility but needs urgent attention to its SSL configuration and privacy compliance to enhance security and user trust.

15
-
5
50
-
50
100
newsperumediasportspolitics+6 more
ReactNext.jsGoogle Tag ManagerGoogle Publisher Tags (GPT)+4
2025-06-15T21:53:20.408Z
ahoikapptn.com favicon

Ahoi Kapptn FlexCo

ahoikapptn.com

40
TechnologyAustriasmallHIGH

Ahoi Kapptn FlexCo is a technology-focused company specializing in digital solutions for businesses, including consulting, UI/UX design, AI applications, and scalable software development. The company serves a diverse clientele including notable brands such as Red Bull, SAP, and the Austrian Football Association, positioning itself as a trusted provider of innovative digital products. Their business model revolves around delivering end-to-end digital product development and optimization services, targeting businesses seeking to evolve their digital presence and capabilities. Technically, the website is built on a modern stack using Next.js and React, hosted on Vercel, with native mobile app development capabilities demonstrated in their projects. The site is well-structured, mobile-optimized, and rich in content, reflecting a mature digital infrastructure. However, a critical security gap exists due to the absence of a valid SSL certificate and HTTPS enforcement, which undermines user trust and data security. Privacy compliance is generally good, with a clear privacy policy and GDPR adherence, though the lack of a cookie consent mechanism is a notable shortfall. Overall, the website presents a professional and credible business front but requires urgent security improvements to align with best practices and user expectations.

-
-
-
50
-
85
100
digitalsolutionssoftwaredevelopmentaiapplicationsmobileappsuiuxdesign+2 more
Next.jsReactVercel hostingSpring Boot (backend for projects)+6
2025-06-15T21:53:13.281Z
cpbcon.com.au favicon

CPB Contractors

cpbcon.com.au

40
TransportationAustraliaenterpriseHIGH

CPB Contractors is a well-established major contractor specializing in critical and complex infrastructure projects across Australia and New Zealand. The company operates as a subsidiary of the CIMIC Group and holds a leading market position in sectors such as transport, energy, and construction. Their website reflects a professional business model focused on large-scale infrastructure delivery, with key services including rail, tunneling, roads, water, and new energy projects. The target audience includes government agencies, industry partners, and prospective employees. Technically, the website is built on modern frameworks including Next.js and Material-UI, integrated with Sitecore CMS, and employs Google Analytics and Tag Manager for tracking. However, the site suffers from slow load times and lacks a valid SSL certificate, which critically impacts security and user trust. Mobile optimization and SEO are adequately addressed, but accessibility features are basic. From a security perspective, the absence of HTTPS and security headers represents a significant vulnerability. No explicit security policies or incident response contacts are published, and privacy compliance is limited despite the presence of a privacy policy. The site uses tracking technologies but lacks cookie consent mechanisms, indicating partial privacy compliance. Overall, the website is functional and professional but requires urgent security improvements, especially SSL implementation and enhanced privacy compliance, to reduce risk and improve trustworthiness.

50
18
5
50
-
85
100
constructioninfrastructurecontractoraustraliatransport+3 more
ReactNext.jsMaterial-UIGoogle Analytics+2

Partner Domains:

cimic.com.au
parentpending
leightonasia.com
partnerpending

+3 more partners

2025-06-15T21:49:55.741Z
iwgplc.com favicon

International Workplace Group plc

iwgplc.com

40
Real EstateUnited KingdomenterpriseHIGH

International Workplace Group plc (IWG) is a global leader in providing hybrid working solutions through an extensive network of office spaces, coworking locations, virtual offices, and meeting rooms. The company targets businesses and professionals seeking flexible workspace options worldwide, positioning itself as the premier provider in the real estate sector for hybrid work environments. Their business model revolves around workspace-as-a-service, offering scalable and customizable solutions to meet diverse client needs. Technically, the website leverages modern frameworks such as Next.js and Sitecore CMS, hosted on Azure, with integrations including OneTrust for privacy management and Google Tag Manager for analytics. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, although performance metrics are moderate due to lack of explicit data. From a security perspective, the site exhibits several best practices including comprehensive security headers and secure cookie attributes. However, a critical issue is the absence of a valid SSL certificate and lack of HTTPS enforcement, which significantly impacts the security posture. Other vulnerabilities include disabled TLS protocols and missing HSTS enforcement. Privacy compliance is strong with clear policies and consent mechanisms in place. Overall, while the business and technical aspects of the website are robust and professional, the critical security gaps related to SSL/TLS must be addressed promptly to ensure user trust and data protection. Strategic recommendations include immediate SSL certificate installation, enabling modern TLS protocols, and enhancing security headers to elevate the security posture.

-
-
5
50
-
80
100
hybridworkingofficespacecoworkingvirtualofficemeetingrooms+3 more
ReactNext.jsSitecoreAzure+3
2025-06-15T21:49:47.454Z
F

fiskaly GmbH

fiskaly.com

40
TechnologyGermanymediumHIGH

fiskaly GmbH is a technology company specializing in cloud-based fiscalization solutions tailored for European markets including Germany, Austria, Spain, Italy, and France. Their services focus on enabling retailers and POS providers to comply with complex fiscal regulations through APIs and cloud services. fiskaly holds a strong market position as a leading provider of cloud TSS solutions in Germany and is expanding its footprint across Europe. The website demonstrates a professional, well-branded presence with comprehensive content, customer testimonials, and partner endorsements. Technically, the website is built on a modern Next.js framework hosted on Netlify, leveraging React and various marketing and analytics tools such as Google Tag Manager and Visual Website Optimizer. The site is mobile-optimized and accessible, with good SEO practices. However, a critical security issue is present due to an invalid or missing SSL certificate and disabled TLS protocols, which significantly impacts the security posture. Security-wise, fiskaly implements several best practices including HSTS and security headers, and holds ISO 27001 certification, indicating a mature security framework. Despite this, the lack of a valid SSL certificate and TLS support is a major vulnerability that must be addressed urgently to protect user data and maintain trust. Overall, fiskaly presents a credible and professional business with strong compliance and technical capabilities but must remediate critical SSL/TLS issues to ensure secure and trustworthy operations online.

40
18
5
50
-
85
100
companyculturecustomersuccessstorye-invoicefaq+6 more
Next.jsReactNetlifyJavaScript
2025-06-15T21:49:27.021Z
cloudbees.com favicon

CloudBees, Inc.

cloudbees.com

40
TechnologyUnited StatesenterpriseHIGH

CloudBees, Inc. is a leading enterprise software company specializing in continuous integration and continuous delivery (CI/CD) solutions, primarily based on Jenkins. The company offers a comprehensive suite of DevOps tools and platforms designed to accelerate software delivery, improve developer productivity, and ensure security and compliance at scale. CloudBees holds a strong market position as the #1 Jenkins enterprise CI/CD platform provider, serving large enterprises globally with a focus on technology sectors. Their business model includes SaaS and on-premises offerings, targeting enterprise development teams and IT executives. Technically, CloudBees employs modern web technologies such as React and Next.js, hosted on AWS infrastructure with integrations to major cloud providers. The website demonstrates good digital maturity with responsive design, SEO optimization, and accessibility considerations. Marketing and analytics tools are implemented with user consent mechanisms, reflecting privacy compliance. From a security perspective, while the website implements multiple security headers and policies, a critical issue is the invalid or missing SSL certificate and disabled TLS protocols, which significantly impact the security posture. The company maintains security policies, incident response contacts, and certifications such as SOC 2 and ISO 27001, indicating a mature security framework. However, immediate remediation of SSL and TLS configurations is necessary to protect user data and maintain trust. Overall, CloudBees presents a professional and trustworthy online presence with strong business credibility and technical infrastructure. Addressing the SSL and TLS issues will elevate their security posture and align with their enterprise-grade offerings.

75
-
5
50
-
90
100
devopscicdjenkinsenterprisesoftwarecloudcomputing+3 more
ReactNext.jsGoogle Tag ManagerOneTrust Cookie Consent+4
2025-06-15T21:49:12.923Z