Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157325
Websites
130
Industries
113
Countries
52
Avg Score
Page 96 of 101|Showing 4751-4800 of 5032
cpbcon.com.au favicon

CPB Contractors

cpbcon.com.au

40
TransportationAustraliaenterpriseHIGH

CPB Contractors is a well-established major contractor specializing in critical and complex infrastructure projects across Australia and New Zealand. The company operates as a subsidiary of the CIMIC Group and holds a leading market position in sectors such as transport, energy, and construction. Their website reflects a professional business model focused on large-scale infrastructure delivery, with key services including rail, tunneling, roads, water, and new energy projects. The target audience includes government agencies, industry partners, and prospective employees. Technically, the website is built on modern frameworks including Next.js and Material-UI, integrated with Sitecore CMS, and employs Google Analytics and Tag Manager for tracking. However, the site suffers from slow load times and lacks a valid SSL certificate, which critically impacts security and user trust. Mobile optimization and SEO are adequately addressed, but accessibility features are basic. From a security perspective, the absence of HTTPS and security headers represents a significant vulnerability. No explicit security policies or incident response contacts are published, and privacy compliance is limited despite the presence of a privacy policy. The site uses tracking technologies but lacks cookie consent mechanisms, indicating partial privacy compliance. Overall, the website is functional and professional but requires urgent security improvements, especially SSL implementation and enhanced privacy compliance, to reduce risk and improve trustworthiness.

50
18
5
50
-
85
100
constructioninfrastructurecontractoraustraliatransport+3 more
ReactNext.jsMaterial-UIGoogle Analytics+2

Partner Domains:

cimic.com.au
parentpending
leightonasia.com
partnerpending

+3 more partners

2025-06-15T21:49:55.741Z
iwgplc.com favicon

International Workplace Group plc

iwgplc.com

40
Real EstateUnited KingdomenterpriseHIGH

International Workplace Group plc (IWG) is a global leader in providing hybrid working solutions through an extensive network of office spaces, coworking locations, virtual offices, and meeting rooms. The company targets businesses and professionals seeking flexible workspace options worldwide, positioning itself as the premier provider in the real estate sector for hybrid work environments. Their business model revolves around workspace-as-a-service, offering scalable and customizable solutions to meet diverse client needs. Technically, the website leverages modern frameworks such as Next.js and Sitecore CMS, hosted on Azure, with integrations including OneTrust for privacy management and Google Tag Manager for analytics. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, although performance metrics are moderate due to lack of explicit data. From a security perspective, the site exhibits several best practices including comprehensive security headers and secure cookie attributes. However, a critical issue is the absence of a valid SSL certificate and lack of HTTPS enforcement, which significantly impacts the security posture. Other vulnerabilities include disabled TLS protocols and missing HSTS enforcement. Privacy compliance is strong with clear policies and consent mechanisms in place. Overall, while the business and technical aspects of the website are robust and professional, the critical security gaps related to SSL/TLS must be addressed promptly to ensure user trust and data protection. Strategic recommendations include immediate SSL certificate installation, enabling modern TLS protocols, and enhancing security headers to elevate the security posture.

-
-
5
50
-
80
100
hybridworkingofficespacecoworkingvirtualofficemeetingrooms+3 more
ReactNext.jsSitecoreAzure+3
2025-06-15T21:49:47.454Z
F

fiskaly GmbH

fiskaly.com

40
TechnologyGermanymediumHIGH

fiskaly GmbH is a technology company specializing in cloud-based fiscalization solutions tailored for European markets including Germany, Austria, Spain, Italy, and France. Their services focus on enabling retailers and POS providers to comply with complex fiscal regulations through APIs and cloud services. fiskaly holds a strong market position as a leading provider of cloud TSS solutions in Germany and is expanding its footprint across Europe. The website demonstrates a professional, well-branded presence with comprehensive content, customer testimonials, and partner endorsements. Technically, the website is built on a modern Next.js framework hosted on Netlify, leveraging React and various marketing and analytics tools such as Google Tag Manager and Visual Website Optimizer. The site is mobile-optimized and accessible, with good SEO practices. However, a critical security issue is present due to an invalid or missing SSL certificate and disabled TLS protocols, which significantly impacts the security posture. Security-wise, fiskaly implements several best practices including HSTS and security headers, and holds ISO 27001 certification, indicating a mature security framework. Despite this, the lack of a valid SSL certificate and TLS support is a major vulnerability that must be addressed urgently to protect user data and maintain trust. Overall, fiskaly presents a credible and professional business with strong compliance and technical capabilities but must remediate critical SSL/TLS issues to ensure secure and trustworthy operations online.

40
18
5
50
-
85
100
companyculturecustomersuccessstorye-invoicefaq+6 more
Next.jsReactNetlifyJavaScript
2025-06-15T21:49:27.021Z
cloudbees.com favicon

CloudBees, Inc.

cloudbees.com

40
TechnologyUnited StatesenterpriseHIGH

CloudBees, Inc. is a leading enterprise software company specializing in continuous integration and continuous delivery (CI/CD) solutions, primarily based on Jenkins. The company offers a comprehensive suite of DevOps tools and platforms designed to accelerate software delivery, improve developer productivity, and ensure security and compliance at scale. CloudBees holds a strong market position as the #1 Jenkins enterprise CI/CD platform provider, serving large enterprises globally with a focus on technology sectors. Their business model includes SaaS and on-premises offerings, targeting enterprise development teams and IT executives. Technically, CloudBees employs modern web technologies such as React and Next.js, hosted on AWS infrastructure with integrations to major cloud providers. The website demonstrates good digital maturity with responsive design, SEO optimization, and accessibility considerations. Marketing and analytics tools are implemented with user consent mechanisms, reflecting privacy compliance. From a security perspective, while the website implements multiple security headers and policies, a critical issue is the invalid or missing SSL certificate and disabled TLS protocols, which significantly impact the security posture. The company maintains security policies, incident response contacts, and certifications such as SOC 2 and ISO 27001, indicating a mature security framework. However, immediate remediation of SSL and TLS configurations is necessary to protect user data and maintain trust. Overall, CloudBees presents a professional and trustworthy online presence with strong business credibility and technical infrastructure. Addressing the SSL and TLS issues will elevate their security posture and align with their enterprise-grade offerings.

75
-
5
50
-
90
100
devopscicdjenkinsenterprisesoftwarecloudcomputing+3 more
ReactNext.jsGoogle Tag ManagerOneTrust Cookie Consent+4
2025-06-15T21:49:12.923Z
wikifolio.com favicon

wikifolio Financial Technologies AG

wikifolio.com

37
FinanceAustriamediumHIGH

wikifolio Financial Technologies AG operates a sophisticated online investment platform focused on European stocks and social trading. The platform enables investors worldwide to access trading ideas, create virtual portfolios, and invest in wikifolio certificates listed on stock exchanges in Germany, Austria, and Switzerland. The company is well-positioned in the European finance sector with a medium-sized operation and a strong brand presence supported by partnerships and positive testimonials. Technically, the website leverages modern web technologies including React, Next.js, and Chakra UI, hosted on Azure infrastructure with CDN support for performance. The site is well-optimized for SEO, accessibility, and mobile responsiveness, providing a professional user experience. From a security perspective, the site currently lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability. Security headers are partially implemented but key features like HSTS and OCSP stapling are missing. Privacy compliance is strong with comprehensive policies and clear contact information, but incident response and security policy disclosures are absent. Overall, the website presents a trustworthy and professional business front but requires urgent improvements in SSL/TLS security to protect user data and maintain trust. Strategic recommendations include immediate SSL certificate installation, enabling TLS 1.2+, and enhancing security headers and incident response readiness.

30
-
5
50
-
75
100
financeinvestmentsocialtradingwikifoliocertificates+1 more
ReactNext.jsAzure CDNMicrosoft ASP.NET+2

Partner Domains:

1822direkt.de
partnerpending
anlegerplus.de
partnerpending

+3 more partners

2025-06-15T21:48:50.751Z
B

BMO Global Asset Management

bmogam.nl

35
FinanceCanadalargeHIGH

BMO Global Asset Management (BMO GAM) is a leading Canadian asset manager offering a broad range of investment products including mutual funds, ETFs, and alternative products. The website clearly targets investors, advisors, and institutional clients, reflecting a mature and well-established financial services business. The company operates under the larger Bank of Montreal (BMO) umbrella, reinforcing its market position and credibility. Technically, the website leverages modern web technologies such as Next.js and integrates with Adobe Launch and OneTrust for marketing and compliance. Hosting is provided via Akamai CDN, ensuring global content delivery. However, the absence of a valid SSL certificate and disabled TLS protocols represent significant technical and security shortcomings that undermine user trust and data protection. From a security perspective, while some security headers like HSTS and X-Frame-Options are present, the lack of HTTPS and modern TLS support is a critical vulnerability. No published security policies, incident response contacts, or vulnerability disclosure mechanisms were found, indicating gaps in security transparency and readiness. Overall, the website is professionally designed and content-rich, but the lack of proper SSL/TLS configuration and security disclosures lowers its security posture and trustworthiness. Strategic improvements in SSL deployment, security policy publication, and DNS security would significantly enhance the site's security and compliance standing.

40
-
5
50
-
40
100
financeassetmanagementinvestmentcanadianbusinessbmo
React (Next.js)jQueryjQuery UIOneTrust Cookie Consent+5
2025-06-15T21:48:25.719Z
konicaminolta.at favicon

Konica Minolta Business Solutions Austria GmbH

konicaminolta.at

40
TechnologyAustrialargeHIGH

Konica Minolta Business Solutions Austria GmbH operates as a leading technology and managed service provider specializing in intelligent workplace solutions, printing systems, cloud services, and IT infrastructure management. The company holds a strong market position in Austria and the DACH region, supported by a broad portfolio including multifunctional printers, professional printing, enterprise software, cybersecurity, and healthcare solutions. Their business model leverages direct sales and a partner network to serve a diverse business clientele. Technically, the website is built on modern frameworks such as Next.js and hosted on Vercel, with a CMS likely powered by Contentstack. The site demonstrates good mobile optimization, accessibility, and SEO practices, although performance is currently slow. Analytics and consent management tools like Google Tag Manager and Usercentrics are integrated, indicating a mature digital infrastructure. From a security perspective, the absence of a valid SSL certificate and HTTPS support is a critical vulnerability, severely impacting the site's security posture. While some security headers are present, the lack of TLS protocols and session management features exposes the site to risks. Privacy compliance is strong, with comprehensive policies and consent mechanisms in place. Overall, the site is professionally designed and content-rich, reflecting a reputable business. However, the critical lack of HTTPS undermines trust and security, necessitating urgent remediation to protect users and maintain compliance.

55
-
5
50
-
85
100
technologyprintingitserviceshealthcaremanagedservices+2 more
Next.jsReactVercel hostingGoogle Tag Manager+2
2025-06-15T21:48:21.687Z
duffeypetrosky.com favicon

DP+ (now part of Fusion92)

duffeypetrosky.com

26
MediaN/amediumHIGH

DP+ is a marketing and innovation company recently acquired by Fusion92, positioning itself as a Midwest marketing innovation powerhouse. The website serves primarily as a landing page to announce this acquisition and redirect visitors to Fusion92's main site for further information. The business targets organizations seeking marketing and brand innovation services, operating within the media sector. The site branding is consistent and professional, reflecting the parent company's identity. Technically, the website is built using modern frameworks such as Next.js and React, hosted on Vercel, indicating a contemporary digital infrastructure. However, performance data is missing, and the site lacks a valid SSL certificate, resulting in no HTTPS support, which is a critical security shortfall. Mobile optimization is good, but accessibility and SEO optimizations are basic. From a security perspective, the absence of a valid SSL certificate and TLS protocols severely impacts the security posture. While some security headers are present, critical best practices like OCSP stapling, session resumption, and comprehensive HSTS policies are missing. No privacy or cookie policies are actively presented on the landing page, and no contact or incident response information is available, limiting compliance and user trust. Overall, the website presents moderate business credibility but suffers from critical security issues that must be addressed urgently. Strategic improvements in SSL deployment, privacy compliance, and contact transparency are recommended to enhance trust and security.

30
18
5
50
-
85
20
marketingacquisitionfusion92dpplusmedia+1 more
Next.jsReactVercel
2025-06-15T21:47:18.457Z
avanade.com favicon

Avanade Inc.

avanade.com

40
TechnologyUnited StatesenterpriseHIGH

Avanade Inc. is a leading global provider of cloud, AI, and advisory services focused on the Microsoft ecosystem. With over 25 years of experience and a strong market position as the world’s leading Microsoft expert, Avanade serves enterprise clients across multiple industries including technology, energy, banking, healthcare, government, and retail. The company operates globally with headquarters in the United States, Europe, and Asia, and is a subsidiary of Accenture. Their business model centers on delivering advisory, managed services, and integrated Microsoft technology solutions to help organizations unlock digital transformation and sustainability goals. Technically, Avanade’s website leverages modern frameworks such as Next.js and Sitecore CMS, hosted on Vercel and integrated with marketing and analytics tools like Adobe Launch, Google Tag Manager, and OneTrust for consent management. The site is well-designed, mobile-optimized, and rich in content, providing a professional user experience with clear navigation and comprehensive business information. From a security perspective, the website currently suffers from critical issues including the absence of a valid SSL certificate and lack of TLS protocol support, severely impacting its security posture. While security headers such as Content-Security-Policy and HSTS are present, they are not fully hardened. The presence of a vulnerability disclosure page and detailed privacy and cookie policies indicate a mature approach to compliance and security awareness, but the lack of HTTPS is a major risk. Overall, the website is highly credible and professional but requires urgent remediation of its SSL/TLS configuration to ensure secure communications and maintain trust. Strategic improvements in security practices and continued adherence to privacy compliance will strengthen Avanade’s digital presence and risk posture.

65
15
15
50
-
90
100
technologycloudaimicrosoftconsulting+2 more
React (Next.js)Brightcove video playerGoogle Tag ManagerAdobe Launch+7
2025-06-15T21:47:11.143Z
alliedpanels.com favicon

GoDaddy Operating Company, LLC

alliedpanels.com

38
E-commerceUnited StateslargeHIGH

The website alliedpanels.com is a domain aftermarket sales landing page hosted and operated under GoDaddy's platform. It offers the domain for sale with options to buy now, lease to own, or make an offer. The site targets domain investors and businesses seeking premium domain names, leveraging GoDaddy's trusted marketplace and brokerage services. The business model is focused on domain sales and brokerage within the e-commerce sector, supported by GoDaddy's large market presence and infrastructure. Technically, the site is built using modern JavaScript frameworks such as React and Next.js, hosted on AWS infrastructure. However, the site suffers from slow load times and lacks a valid SSL certificate, resulting in no HTTPS support. While the design and user experience are good and mobile optimized, the absence of HTTPS and security headers significantly weakens the security posture. Security evaluation reveals critical issues including no valid SSL certificate, no HSTS, and missing security headers, which expose users to potential risks. Privacy compliance is supported by comprehensive GoDaddy privacy and cookie policies, with GDPR compliance indicated. Contact information is limited but present via phone and contact form. Overall, the site is legitimate and consistent with domain aftermarket sales but requires urgent security improvements. Strategically, the site should prioritize obtaining and configuring a valid SSL certificate to enable HTTPS, implement security headers, and improve performance to enhance trust and user experience. These steps will strengthen the security posture and align with best practices for e-commerce platforms.

15
15
5
50
-
80
100
domain-for-saledomain-marketplacegodaddyafternicpremium-domain
ReactNext.jsJavaScriptCSS+3

Partner Domains:

afternic.com
partner75
godaddy.com
parent73

+1 more partners

2025-06-15T21:47:05.260Z
opalcamera.com favicon

Opal Camera Inc.

opalcamera.com

64
TechnologyUnited StatessmallMEDIUM

Opal Camera Inc. is a California-based technology company specializing in the design and engineering of high-end webcams and camera-related products. Their flagship products include the Opal C1 professional webcam and the Opal Tadpole, the first webcam designed specifically for laptops. The company targets consumers and professionals seeking premium webcam solutions, positioning itself as an innovative niche player in the webcam market. The business model focuses on direct sales of hardware and complementary software, supported by customer service and digital marketing efforts. Technically, the website is built using modern web technologies including React and Next.js, hosted with Cloudflare DNS services. The site integrates multiple analytics and advertising platforms such as Google Analytics, TikTok, Facebook, and Twitter pixels, indicating a mature digital marketing strategy. However, the website suffers from slow load times and lacks a valid SSL certificate, which impacts user trust and security. From a security perspective, the site has enabled HSTS but lacks a valid SSL certificate, OCSP stapling, and DNSSEC, which are critical for secure communications and DNS integrity. No explicit security or incident response policies are found, and cookie consent mechanisms are absent, raising privacy compliance concerns. The domain registration is mature and consistent with the business claims, enhancing legitimacy. Overall, while the company presents a professional and trustworthy front with quality content and branding, critical security gaps and performance issues pose risks. Strategic improvements in SSL deployment, privacy compliance, and website optimization are recommended to enhance security posture and user trust.

30
25
25
85
97
85
100
webcamtechnologyhardwarecameraconsumerelectronics
ReactNext.jsCloudflare DNSGoogle Analytics+4
2025-06-15T15:49:14.091Z
diku.no favicon

Direktoratet for høyere utdanning og kompetanse

diku.no

49
EducationNorwaymediumHIGH

Direktoratet for høyere utdanning og kompetanse (HK-dir) is a Norwegian government agency responsible for national administration and policy implementation in higher education, vocational education, and competence development. Established in 2021 through a merger of several agencies, it serves as a key authority in Norway's education sector, providing services such as career guidance, foreign education recognition, funding programs, and statistical reporting. The website targets professionals and stakeholders in education and workforce development within Norway. Technically, the website is built using modern web technologies including Next.js and Sanity CMS, with integration of Google Fonts and Siteimprove Analytics. The site is well-structured, mobile-optimized, and provides good accessibility and SEO features. However, performance is moderate with a load time of approximately 5.8 seconds. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical vulnerability. No security headers or advanced TLS configurations are present, exposing the site to potential risks. Privacy compliance is strong, with a comprehensive GDPR-compliant privacy policy and clear contact information. No cookie consent mechanism or terms of service were found. Overall, while the business and content aspects are solid and trustworthy, the lack of HTTPS and proper SSL configuration significantly lowers the security posture and overall risk rating. Immediate remediation of SSL/TLS issues is recommended to protect user data and enhance trust.

35
25
25
55
50
85
100
educationgovernmenthighereducationcompetencenorway+1 more
React (Next.js)Google FontsSiteimprove AnalyticsNext.js
2025-06-15T13:19:10.365Z