Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 987 of 1003|Showing 49301-49350 of 50115
postbillpay.com.au favicon

Australia Post

postbillpay.com.au

68
payment servicesAustralialargeMEDIUM

The website demonstrates a solid foundation in network, email, and SSL/TLS security, indicating good baseline protections. However, significant gaps exist in security headers, GDPR compliance, and adherence to NIS2 cybersecurity frameworks, which together expose the business to legal, reputational, and operational risks. Missing critical headers like Content-Security-Policy and X-Frame-Options leave the site vulnerable to cross-site scripting and clickjacking attacks. The absence of privacy and cookie policies, along with no cookie consent mechanism, poses compliance risks under data protection laws such as GDPR, potentially leading to fines and loss of customer trust. Lack of documented security policies, incident response procedures, and business continuity planning increases the risk of inadequate response to cyber incidents, threatening business operations. DNSSEC is not enabled, which could allow DNS spoofing attacks. Addressing these issues will significantly strengthen security posture, reduce compliance risks, and protect the organization from both cyber threats and regulatory penalties. Immediate focus on privacy policies, security headers, and incident response frameworks is recommended. Overall, the current posture requires urgent remediation to align with industry standards and legal requirements.

25
25
25
100
95
90
100
AngularJS (ng-app, ng-bind, ng-strict-di, ng-cloak)Adobe DTM (adobedtm script)jQueryMoment.js+5

Partner Domains:

auspost.com.au
partner70
bpay.com.au
paymentanalyzing...
2025-06-13T20:21:40.291Z
realpagecares.com favicon

RealPage

realpagecares.com

64
housing and community servicesUSAlargeMEDIUM

The website's overall security posture reveals significant gaps, particularly in governance and compliance areas such as GDPR and NIS2 frameworks, exposing the business to regulatory and reputational risks. Critical email security misconfigurations pose a high risk of phishing and spoofing attacks, potentially undermining customer trust. Missing key security headers like Content-Security-Policy and X-Frame-Options increase vulnerability to cross-site scripting and clickjacking attacks, threatening data integrity. Although network security and DNS health are relatively strong, foundational SSL/TLS and header configurations require improvement to safeguard data in transit. The absence of documented incident response and business continuity plans limits the organization's ability to effectively respond to cyber incidents, increasing potential downtime and financial loss. Lack of a cookie policy and consent mechanisms places the company at risk of non-compliance with privacy laws, which could result in fines and legal challenges. Immediate attention to these areas will reduce attack surfaces, ensure compliance, and strengthen overall resilience. Prioritizing governance frameworks and critical technical controls will deliver the greatest business impact.

35
43
25
75
77
85
100
housingcommunityaffordable housingnonprofitrealpage
SquarespaceGoogle AnalyticsjQueryShareThis+1

Partner Domains:

realpage.com
subsidiary74
2025-06-13T20:20:56.088Z
profisee.com favicon

Profisee

profisee.com

67
Enterprise Software / Data ManagementmediumMEDIUM

The website demonstrates a moderate overall security posture with no critical issues but multiple high and medium risk findings that could expose the business to significant operational, reputational, and regulatory risks. Key weaknesses exist in security headers, GDPR compliance, and adherence to NIS2 cybersecurity framework requirements, reflecting gaps in privacy protection, incident preparedness, and information security governance. SSL/TLS configurations show vulnerabilities including weak key lengths and impending certificate expiration, which threaten secure communications. While email security and network security measures score well, foundational security controls such as Content Security Policy and proper cookie management are missing. Failure to implement GDPR-required cookie consent and policies exposes the business to potential regulatory penalties and loss of customer trust. The absence of incident response and business continuity plans significantly heightens risk from cyber incidents. Immediate remediation will reduce attack surface, improve compliance, and strengthen customer confidence. Overall, addressing these gaps is essential to align with industry standards and regulatory obligations, protecting both the business and its customers.

30
43
25
95
72
85
100
EnterpriseMaster Data ManagementMDMData GovernanceMicrosoft Fabric+2 more
WordPressYoast SEOWP RocketElementor+9

Partner Domains:

microsoft.com
partner69
2025-06-13T20:20:03.297Z
freddiemac.com favicon

Freddie Mac

freddiemac.com

74
housing financeUnited StatesenterpriseMEDIUM

The website demonstrates a generally solid technical security foundation with no critical vulnerabilities detected and strong scores in email security, network security, SSL/TLS, and DNS health. However, significant gaps exist in regulatory compliance and governance, particularly regarding GDPR and NIS2 mandates, which present substantial legal and operational risks. The absence of essential policies such as cookie consent, incident response, and security frameworks exposes the organization to potential regulatory penalties and undermines customer trust. Missing key security headers and mixed content issues indicate areas where the website’s resilience against common web attacks can be improved. While foundational network and protocol configurations are strong, the low scores in compliance reflect a need for urgent attention to documentation, privacy, and incident management. Overall, the security posture is functional but incomplete, with business-critical exposure due to compliance shortcomings. Addressing these gaps will enhance legal compliance, customer confidence, and incident readiness, thereby reducing potential financial and reputational damage.

70
43
25
100
87
85
100
housing financemortgagehomeownershipfinancial servicesgovernment-sponsored enterprise+3 more
DrupalGoogle Tag ManagerVisual Website Optimizer (VWO)Cloudflare Email Protection+3

Partner Domains:

gcs-web.com
serviceanalyzing...
onetrust.com
service72
2025-06-13T20:19:09.744Z
briscoes.co.nz favicon

Briscoes

briscoes.co.nz

54
RetailNew ZealandlargeMEDIUM

The website's security posture is currently weak, exposing the business to significant cyber risks and potential regulatory non-compliance. Numerous critical and high-severity issues exist, especially in network security where multiple critical services such as Telnet, SMB, MSSQL, and databases are openly exposed, significantly increasing the risk of unauthorized access and data breaches. Key security controls including essential HTTP security headers and GDPR compliance measures like cookie policies and consent banners are missing, elevating legal and reputational risks. The absence of formal information security frameworks, incident response plans, and security policies further undermines the organization's resilience to cyber incidents. While email security and DNS health show relatively better scores, weaknesses remain in SSL/TLS configurations that could allow interception or downgrade attacks. Immediate remediation is required to protect sensitive data, maintain customer trust, and comply with regulations such as GDPR and NIS2. Failure to address these gaps could result in financial loss, legal penalties, and damage to brand reputation. Strengthening foundational security controls and network defenses should be prioritized to reduce the attack surface and improve overall risk posture.

30
43
25
85
65
85
-
homewareretailecommerceNew ZealandBriscoes+3 more
jQueryGoogle AnalyticsCloudflare

Partner Domains:

briscoes.com.au
subsidiaryanalyzing...
briscoegroup.co.nz
parent companypending

+3 more partners

2025-06-13T20:18:46.187Z
djreprints.com favicon

Dow Jones

djreprints.com

68
media and publishingUnited StatesmediumMEDIUM

The website exhibits a concerning security posture with no critical issues but multiple high and medium severity vulnerabilities, primarily related to missing security headers, GDPR compliance gaps, and lack of foundational NIS2 security documentation. The absence of key HTTP security headers such as Strict-Transport-Security, X-Frame-Options, and Content-Security-Policy exposes the site to common web-based attacks like clickjacking, content injection, and downgrade attacks. GDPR compliance deficiencies, including missing cookie consent and incomplete privacy policies, present legal and reputational risks. Furthermore, the lack of an information security framework, incident response procedures, and security policy documentation indicates immature security governance. While email security, SSL/TLS, DNS health, and network security show relatively strong scores, the overall low NIS2 compliance score signals significant gaps in regulatory adherence and operational readiness. Immediate focus on governance, policy implementation, and security header configuration will mitigate business risks and enhance trust. Addressing these issues is critical to safeguarding customer data, ensuring regulatory compliance, and maintaining brand reputation.

15
58
25
85
85
85
100
reprintslicensingmediapublishingDow Jones
WordPressGenesis Blocks PluginAstra ThemejQuery+2

Partner Domains:

dowjones.com
subsidiary93
wsj.com
sister companyanalyzing...

+1 more partners

2025-06-13T20:15:22.289Z