Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 97 of 166|Showing 4801-4850 of 8293
hackney.gov.uk favicon

London Borough of Hackney

hackney.gov.uk

59
GovernmentUnited KingdomlargeMEDIUM

Hackney Council operates as the official local government authority for the London Borough of Hackney, providing a wide range of public services including council tax management, parking, waste collection, housing, and community engagement. The website serves residents, businesses, and visitors with comprehensive information and online services, positioning itself as a trusted and authoritative source for local governance. The domain's long history since 1996 and its use of a .gov.uk domain underscore its legitimacy and established presence. Technically, the website leverages modern web technologies such as React and Gatsby, ensuring fast performance, mobile responsiveness, and good accessibility. The integration of multiple analytics and user engagement tools like Google Analytics, Hotjar, Microsoft Clarity, and Tawk.to live chat demonstrates a mature digital infrastructure focused on user experience and data-driven improvements. From a security perspective, the site enforces HTTPS and uses reputable third-party services, with no visible vulnerabilities or exposed sensitive data. However, explicit security policies and incident response contacts are not published, representing an area for improvement. Privacy compliance is well addressed with clear privacy and cookie policies, including consent mechanisms aligned with GDPR requirements. Overall, Hackney Council's website presents a professional, secure, and user-friendly platform that effectively supports its public service mission. Strategic enhancements in security transparency and incident response readiness would further strengthen its trustworthiness and resilience.

30
53
2
75
52
70
100
governmentlocalcouncilpublicservicesukhackney+5 more
ReactGatsbyGoogle Tag ManagerHotjar+3
2025-07-27T04:32:31.384Z
P

Private by Design, LLC

lily.pet

46
TechnologyUnited StatessmallHIGH

The website lily.pet is a personal portfolio and blog site for Lily, a UK-based student and programmer. The site showcases Lily's interests in programming, particularly in web development using React and Astro, as well as Kotlin for Minecraft plugins. The business model is personal branding and sharing projects, targeting a general audience interested in technology and programming. The site is hosted via Cloudflare DNS and uses modern web technologies but lacks advanced security and privacy features. Technically, the site employs modern JavaScript frameworks and is moderately optimized for performance and mobile devices. However, accessibility and SEO optimizations are basic. The site does not use a CMS and appears to be a custom-built static or semi-static site. No analytics or advertising scripts were detected, indicating minimal user tracking. From a security perspective, the site uses HTTPS and has domain status protections but lacks DNSSEC and security headers. No privacy or cookie policies are present, and no contact or incident response information is provided. The domain registration is consistent and legitimate, with privacy protection justified for a personal site. Overall, the security posture is moderate but could be improved with standard best practices. The overall risk is low given the personal nature and lack of sensitive data collection, but improvements in privacy compliance, security headers, and contact transparency are recommended to enhance trust and compliance.

15
50
2
60
52
75
40
personalportfolioprogrammingstudenttechnology+1 more
JavaScriptReactAstroKotlin
2025-07-27T04:30:50.520Z
S

slice.zone

slice.zone

53
TechnologyUnited StatessmallMEDIUM

The website skip.house is a personal site belonging to an individual named Skip, a computer programmer from California. The site appears to serve as a personal portfolio or blog, focusing on interests such as electronic music, UI design, rhythm games, and languages. The domain is newly registered in March 2024 and hosted via Cloudflare, using a modern React and Next.js technology stack. However, the site currently displays an application error page, limiting content accessibility and analysis. From a technical perspective, the site uses contemporary web frameworks but lacks advanced SEO, accessibility, and performance optimizations. There are no detected privacy, cookie, or terms of service policies, nor any contact information or security policies published. Security posture is basic, with no DNSSEC enabled and no security headers detected, which could expose the site to certain risks. Overall, the security posture is weak, with no incident response or vulnerability disclosure mechanisms evident. The domain registration is consistent with the personal nature of the site, and no suspicious patterns were found. The site does not contain any adult or questionable content and targets a general audience. The lack of policies and contact information, combined with the application error, reduces trustworthiness and business credibility. Strategic recommendations include fixing the application error to restore site functionality, implementing privacy and cookie policies, enabling DNSSEC and security headers, and publishing security and incident response information to improve trust and compliance.

30
35
2
70
72
70
100
personalprogrammertechnologyreactnextjs+1 more
ReactNext.jsCloudflare
2025-07-27T04:30:25.343Z
breq.dev favicon

Application error: a client-side exception has occurred

breq.dev

59
TechnologyN/asmallMEDIUM

The website breq.dev serves as a personal portfolio and project showcase primarily focused on software development, hardware projects, and open source contributions. It targets developers and technology enthusiasts interested in programming, hardware tinkering, and web applications. The site hosts numerous projects with demos and repositories, reflecting a strong technical background and active development. However, the main page currently suffers from a client-side application error, which significantly impacts user experience and accessibility. Technically, the site is built using modern web technologies including Next.js, React, Python, Flask, and Node.js, and is hosted on Vercel. The technology stack is diverse and up-to-date, supporting a variety of programming languages and frameworks. Despite this, the site lacks important security headers and privacy compliance elements, and the frontend error suggests some technical debt or deployment issues. From a security perspective, the site does not present explicit vulnerabilities but lacks essential security best practices such as HTTPS verification, security headers, and privacy policies. No incident response or vulnerability disclosure information is provided, which limits trust and compliance with data protection regulations. Analytics usage is minimal and limited to Cloudflare Insights, with no aggressive tracking or advertising. Overall, the site is a technically competent personal portfolio with good content relevance but suffers from poor user experience due to errors and missing compliance/security features. Strategic improvements in frontend stability, privacy compliance, and security hardening are recommended to enhance trustworthiness and professionalism.

30
50
2
85
72
80
100
technologyportfolioopensourceprojectshardware+5 more
Next.jsReactJavaScriptPython+8
2025-07-27T04:29:55.203Z
coolmathgam.es favicon

coolmathgam.es

coolmathgam.es

68
TechnologyN/asmallMEDIUM

coolmathgam.es operates as a parody Mastodon instance within the fediverse, providing a niche social networking platform that mimics Mastodon but is explicitly unaffiliated with the well-known Cool Math Games site. The platform offers basic Mastodon features such as user profiles, public timelines, and trending feeds, targeting general users interested in decentralized social media. The site is small in scale with minimal active users and clear disclaimers about its parody nature. Technically, the website is built on a modern tech stack including Mastodon version 4.4.0-nightly and React, leveraging Cloudflare for hosting and analytics. The site uses HTTPS with script integrity checks, indicating a reasonable level of technical maturity. However, some standard security headers are missing, and privacy compliance mechanisms such as cookie consent banners are absent. From a security perspective, the site benefits from HTTPS and no visible vulnerabilities or exposed sensitive data. The use of privacy protection in domain registration is typical for small or parody sites, though it limits transparency. The absence of contact information, terms of service, and security policies reduces trust and compliance posture. Overall, the security posture is moderate but could be improved with additional headers and policies. The overall risk is low given the site's parody and small scale nature, but strategic improvements in privacy compliance, security headers, and transparency would enhance trustworthiness and user confidence.

75
28
17
95
75
85
100
socialnetworkmastodonparodyfediversetechnology
Mastodon 4.4.0-nightlyReactJavaScript ES ModulesCloudflare Insights (beacon)+1
2025-07-27T04:28:13.286Z
eldritch.cafe favicon

eldritch.cafe

eldritch.cafe

59
TechnologyFrancesmallMEDIUM

Eldritch.cafe operates as an independent Mastodon instance providing decentralized social media services primarily targeting queer, feminist, and anarchist communities, with a focus on French-speaking users. The platform emphasizes community moderation, inclusivity, and amplifying marginalized voices. It maintains a small but active user base and is hosted by Fedi Monster in France. The website content is bilingual and includes detailed moderation guidelines, credits, and legal notices consistent with French law. Technically, the site runs on a Glitch-soc fork of Mastodon, leveraging modern web technologies such as React and JavaScript. The infrastructure is moderately performant and mobile-optimized, though accessibility and SEO features are basic. Hosting and domain registration are consistent and legitimate, with HTTPS enabled and domain transfer protections in place. However, DNSSEC is not enabled, and security headers are absent, indicating room for improvement in security hardening. From a security perspective, the instance enforces clear community rules prohibiting hateful conduct, harassment, misinformation, and illegal content. While no explicit security policy or incident response contacts are published, the moderation team is transparent and active. Privacy compliance is adequate with a privacy policy present, but the absence of a cookie consent mechanism is a minor gap. No vulnerabilities or suspicious patterns were detected in the analysis. Overall, eldritch.cafe presents a trustworthy, community-driven social media platform with a solid technical foundation and clear governance. Strategic enhancements in security headers, cookie consent, and incident response transparency would further strengthen its security posture and compliance standing.

75
53
17
65
65
80
40
socialmediamastodonfederatedcommunityqueer+3 more
MastodonReactJavaScriptCSS
2025-07-27T02:16:42.268Z
ussein.sn favicon

USSEIN - Université du Sine Saloum El-Hâdj Ibrahima NIASS

ussein.sn

31
GovernmentSenegalsmallHIGH

The website www.ussein.sn represents the Union des Syndicats des Enseignants du Sénégal (USSEIN), a teachers' union in Senegal focused on labor rights and education advocacy. The site targets education professionals within Senegal and serves as a platform for union-related information and activities. The market position is that of an important national union, though the website content and design are basic and primarily in French. Technically, the website is built on WordPress with common plugins such as LayerSlider and uses Google Fonts and Google Maps API. It employs Google Analytics for user tracking. The site is moderately optimized for performance and mobile use but lacks advanced accessibility and SEO features. From a security perspective, the site uses HTTPS but does not implement advanced security headers or provide security policies or incident response information. No vulnerability disclosure or data protection officer details are found. The security posture is moderate but could be improved with better headers and formal policies. Overall, the website is safe for general audiences, with no adult or explicit content detected. However, the absence of privacy and cookie policies and limited contact information reduce privacy compliance and business credibility scores. Strategic improvements in security and compliance documentation are recommended.

20
35
17
60
-
75
-
educationunionteacherssenegallaborrights
JavaScriptGoogle FontsGoogle Maps APIReact
2025-07-26T23:55:58.890Z
rattle.com favicon

Rattle Foundation

rattle.com

62
MediaUnited StatessmallMEDIUM

Rattle.com is the official website of Rattle Poetry, an independent poetry magazine published by the Rattle Foundation, a 501(c)3 non-profit organization. Established in 1995, it serves the poetry community by offering literary content, poetry contests, chapbook publications, workshops, and community engagement. The website targets poets, poetry readers, educators, and literary enthusiasts, positioning itself as a respected and long-standing publication in the poetry media sector. Technically, the website employs a modern tech stack including React and Next.js for the frontend, with WordPress as the backend CMS and WooCommerce for e-commerce functionalities. Hosting and DNS are managed via Vercel and Network Solutions respectively. The site is well-optimized for mobile devices, has good SEO practices, and delivers fast performance with a professional design and clear navigation. From a security perspective, the site uses HTTPS with a domain status that prevents unauthorized transfers, but lacks DNSSEC and explicit security headers. There is no visible security policy or incident response information, and no cookie consent mechanism is present, which are areas for improvement. The WHOIS data confirms the domain's legitimacy and long-term operation, consistent with the organization's claims. Overall, Rattle.com is a credible, professional, and content-rich website serving a niche literary audience. Strategic improvements in security headers, privacy compliance, and incident response transparency would enhance its security posture and user trust.

30
58
17
55
72
85
100
poetryliterarymagazinenon-profitindependentpublicationpoetrycontests+2 more
ReactNext.jsVercel DNSWordPress (backend)+2
2025-07-26T23:54:11.198Z
B

Bankrupt Trump - Find Better Alternatives

bankrupttrump.org

59
OtherN/asmallMEDIUM

The website 'Bankrupt Trump' serves as an informational platform offering users alternatives to mainstream products and services primarily found in the United States and Russia. It targets a general audience interested in ethical, independent, and innovative options sourced globally. The site positions itself as a niche directory, focusing on providing curated alternatives across multiple categories such as technology, finance, health, and more. The business model appears to be content-driven, relying on user searches and informational listings without direct e-commerce or transactional services. Technically, the website is built on modern web technologies including Next.js and React, ensuring a responsive and user-friendly experience across devices. The site demonstrates good SEO practices and basic accessibility features, with moderate performance. However, there is room for improvement in accessibility and performance optimization. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. Nonetheless, it lacks important security headers and a cookie consent mechanism, which are critical for enhancing security posture and privacy compliance. The absence of WHOIS data and registrant information introduces some trust concerns, although the website content and structure appear professional and legitimate. Overall, the website presents a moderate risk profile with good content quality and technical implementation but requires enhancements in security practices and privacy compliance to improve trustworthiness and user protection.

30
53
2
70
72
70
100
alternativesethicalindependentnon-usdirectory+2 more
Next.jsReactJavaScriptCSS
2025-07-26T22:48:48.401Z
mynbc15.com favicon

WPMI

mynbc15.com

68
MediaUnited StatesmediumMEDIUM

WPMI NBC 15 is a local NBC affiliate providing comprehensive news, weather, sports, and entertainment content primarily serving the Mobile Bay area and surrounding communities. The website is positioned as a trusted local media source with a focus on community engagement and live broadcasting. It operates under the Sinclair Broadcast Group umbrella, a major media conglomerate, which enhances its market credibility and resource access. The business model revolves around local news delivery supported by advertising revenue and digital content distribution. Technically, the website employs modern web technologies including React and Next.js frameworks, integrated with JWPlayer for video streaming and advanced advertising technologies such as Google Ad Manager and Prebid.js for header bidding. The site demonstrates good mobile optimization, accessibility compliance via UserWay, and SEO best practices. Hosting and DNS infrastructure leverage AWS services, ensuring reliable performance and scalability. From a security perspective, the site enforces HTTPS with a valid SSL certificate and implements several security headers to protect users. However, DNSSEC is not enabled, and there is no publicly available dedicated security policy or incident response contact, which are areas for improvement. Privacy compliance is well addressed with clear privacy and cookie policies, consent mechanisms, and GDPR considerations managed through Ketch consent management. Overall, WPMI NBC 15 presents a professional, secure, and user-friendly digital presence with strong business credibility. Strategic enhancements in DNS security and explicit security governance documentation would further strengthen its security posture and trustworthiness.

50
80
17
60
77
75
100
newslocalweathersportsentertainment+2 more
ReactNext.jsJWPlayerGoogle Analytics+5

Partner Domains:

sbgi.net
partner
sinclairbroadcastgroup.com
parent
2025-07-26T22:47:17.908Z
S

sc07 LLC

sc07.company

49
TechnologyN/asmallHIGH

sc07 LLC is a small creative and technology group operating a portfolio of projects and services primarily focused on federated social platforms and community tools. Their website serves as a hub linking to various projects such as Fediverse Events, toast.ooo (Lemmy), grants.cafe (Mastodon), aftermath.gg (Matrix), and others, indicating a niche market position within the open-source and federated social ecosystem. The company appears to be established since 2018, though the domain sc07.com was registered recently in 2023, suggesting a possible rebranding or expansion. Technically, the website is built using modern web technologies including Next.js and React, with good mobile optimization and a clean, consistent design. Hosting is provided by highway.host, which also manages their DNS. The site lacks advanced SEO and accessibility features but maintains a moderate performance profile. No analytics or tracking scripts were detected, indicating a privacy-conscious approach. From a security perspective, the site uses HTTPS with a valid SSL configuration and domain registration protections such as clientDeleteProhibited and clientTransferProhibited status flags. However, it lacks security headers and DNSSEC, and there are no published privacy, cookie, or security policies, which are compliance gaps. No incident response or vulnerability disclosure information is available, limiting transparency in security management. Overall, sc07.com presents as a legitimate, small-scale technology and creative group with a focus on federated social projects. The absence of privacy and security policies and contact details reduces trust and compliance posture. Strategic improvements in these areas would enhance their security maturity and business credibility.

15
50
2
85
72
75
20
technologycreativeprojectsservicesfediverse+1 more
ReactNext.jsFont Awesome 6JavaScript

Partner Domains:

highway.host
partner
2025-07-26T22:38:51.883Z
ruptly.agency favicon

Ruptly

ruptly.agency

55
MediaRussiamediumMEDIUM

Ruptly is a media agency specializing in video content distribution, targeting registered users who require access to their services. The website functions primarily as a login portal restricting access to authorized users, with contact provided via email for further inquiries. The business operates in the media sector and appears to be a medium-sized entity based in Russia, although the domain WHOIS data shows privacy protection and an anomalous future creation date, which raises some concerns about registration transparency. Technically, the website employs modern frontend technologies including React, service workers, and Cloudflare DNS hosting. It uses Yandex Metrika for analytics and tracking, indicating moderate user tracking practices. The site is mobile optimized and includes accessibility features, but SEO optimization and content richness are basic. The cookie consent mechanism is present and functional, though no privacy policy or terms of service are visible, which impacts compliance. From a security perspective, HTTPS is enforced and the domain status includes clientTransferProhibited, which are positive indicators. However, no DNSSEC is enabled, no security headers are detected, and there is no published security policy or incident response information. The domain's privacy protection and unusual creation date reduce trustworthiness somewhat. Overall, the security posture is moderate but could be improved with better transparency and security controls. The overall risk assessment suggests a functional but basic media content platform with moderate security and privacy compliance. Strategic recommendations include enabling DNSSEC, publishing privacy and security policies, adding security headers, and clarifying domain registration details to enhance trust and compliance.

15
50
2
60
75
70
100
medialoginvideocontentprivacy+2 more
ReactCloudflare DNSYandex MetrikaService Worker+1
2025-07-26T21:24:39.203Z
calacanis.com favicon

Zone Media OÜ

calacanis.com

63
TechnologyEstonialargeMEDIUM

This website represents the Linktree profile of Jason Calacanis, a prominent angel investor, podcaster, and entrepreneur. The profile aggregates multiple links to his podcasts, newsletters, investment clubs, and social media channels, serving as a centralized hub for his digital presence. The business model leverages affiliate marketing and sponsorships integrated within the Linktree platform, which is a leading link-in-bio service with a large user base. The website is professionally designed, mobile-optimized, and provides a seamless user experience with clear navigation and relevant content for its target audience of entrepreneurs and startup enthusiasts. Technically, the site is built using modern web technologies including React and Next.js, hosted on AWS infrastructure, and employs various third-party integrations such as OneTrust for cookie consent and Snapchat SDK for social sharing. The site demonstrates good SEO practices, accessibility features, and fast performance. Security posture is strong with HTTPS enforced, appropriate security headers, and no visible vulnerabilities. Privacy compliance is evident through the presence of a comprehensive privacy policy and cookie consent mechanisms. While the site lacks explicit published security policies or incident response contacts, it maintains a high level of trustworthiness supported by verified social media links and consistent WHOIS data. The domain is well-established since 2016, registered to Zone Media OÜ, aligning with the website's business claims. Overall, the site presents a low-risk profile with strong business credibility and technical maturity. Strategic recommendations include publishing detailed security and incident response policies, adding a vulnerability disclosure or security.txt file, and providing more direct security contact channels to enhance transparency and trust further.

55
33
10
85
62
70
100
link-in-biopersonalbrandingaffiliatemarketingpodcastingstartupinvesting+1 more
ReactNext.jsAWS DNSOneTrust (cookie consent)+4

Partner Domains:

thanks.is
partner
click.linksynergy.com
partner

+2 more partners

2025-07-26T19:12:17.372Z