Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157325
Websites
130
Industries
113
Countries
52
Avg Score
Page 99 of 101|Showing 4901-4950 of 5032
bonify.de favicon

Forteil GmbH

bonify.de

65
FinanceGermanymediumMEDIUM

bonify.de is a German financial technology platform operated by Forteil GmbH, specializing in credit management and financial fitness services. The company provides users with free and transparent access to their SCHUFA credit data, credit scores, and personalized financial insights. With over 2.5 million users and certifications from TÜV Saarland and BaFin, bonify holds a strong market position in Germany's finance sector. The platform offers a comprehensive suite of services including credit monitoring, tenant credit reports, contract management, and credit offers, targeting consumers seeking to improve their financial health. Technically, bonify employs modern web technologies such as React with Next.js, Prismic CMS, and Cloudflare for hosting and DNS. The site integrates various third-party services including Google Tag Manager, Usercentrics for cookie consent, and Adjust for app marketing. Performance is moderate with good mobile optimization and SEO practices. Privacy compliance is well addressed with GDPR-aligned policies and cookie consent mechanisms. From a security perspective, bonify uses SSL encryption and domain verification but lacks advanced DNS security features like DNSSEC and HSTS. The DMARC policy is set to none, which could be strengthened to reduce email spoofing risks. The presence of a responsible disclosure page indicates security awareness, though no explicit incident response contacts were found. Overall, bonify.de demonstrates a mature digital presence with strong business and security fundamentals. Opportunities exist to enhance DNS and email security configurations and to publish more explicit security policies and incident response information to further build user trust and compliance posture.

85
18
35
85
67
80
100
financecreditschufabonittfinanzen+5 more
React (Next.js)Cloudflare DNS and CDNGoogle Tag ManagerUsercentrics (cookie consent)+8

Partner Domains:

schufa.de
partnerpending
tuev-saar.de
partnerpending
2025-06-14T18:22:14.276Z
next-video.dev favicon

Next.js video embedding with next-video

next-video.dev

58
TechnologyN/asmallMEDIUM

Next-video.dev is a specialized technology website offering a Next.js video embedding solution called next-video. The platform targets developers building Next.js applications who require high-performance video embedding, streaming, and customization capabilities. The business leverages partnerships with Mux, a leading video API provider, and Vercel, a popular hosting and deployment platform, to deliver scalable and optimized video streaming services. The website presents a modern, developer-focused interface with comprehensive technical documentation and code examples, positioning itself as a niche player in the video streaming technology market. Technically, the website is built on Next.js and React frameworks, hosted likely on Vercel infrastructure, and integrates with Mux for video streaming. The tech stack includes modern web technologies and optimized media delivery, although the page load time is relatively slow, indicating potential performance optimization opportunities. The site demonstrates good mobile optimization, accessibility, and SEO practices, contributing to an excellent user experience. From a security perspective, the site employs strong TLS configurations with no known vulnerabilities such as Heartbleed or FREAK. However, it lacks several security best practices including HTTP Strict Transport Security (HSTS), OCSP stapling, and security headers like Content-Security-Policy. There is no visible privacy, cookie, or terms of service policy, nor contact information for security incident response or data protection officers, which may pose compliance and trust challenges. Overall, next-video.dev is a technically mature platform with strong business partnerships and a clear developer focus. To enhance its security posture and compliance, it should implement missing security headers, publish privacy and cookie policies, and provide clear contact channels for security and privacy concerns. These improvements will strengthen trust and align the platform with industry best practices.

30
40
25
50
87
75
100
nextjsvideoembeddingstreamingmuxvercel+2 more
Next.jsReactMux PlayerVercel Blob+3

Partner Domains:

mux.com
partner68
vercel.com
partner75
2025-06-14T18:15:49.875Z
42matters.com favicon

42matters AG

42matters.com

77
TechnologySwitzerlandmediumLOW

42matters AG is a technology company specializing in mobile and connected TV (CTV) app intelligence solutions. Their offerings include a comprehensive app market explorer, APIs for real-time app data access, and bulk file dumps for large-scale data ingestion. Positioned as a leading provider in the app intelligence market, 42matters serves a diverse clientele including ad tech firms, cybersecurity companies, SDK developers, and marketing agencies. The company is part of the Similarweb family, enhancing its market reach and capabilities. Technically, the website is built on a modern Next.js and React framework, hosted on Amazon AWS infrastructure. It employs multiple analytics and marketing tools such as Google Tag Manager, HubSpot, Microsoft Clarity, and Visual Website Optimizer, indicating a mature digital marketing and analytics strategy. Performance is moderate with room for optimization, and mobile responsiveness is good. SEO practices are well implemented with comprehensive metadata and Open Graph tags. From a security perspective, the site uses a valid Amazon-issued SSL certificate but lacks advanced TLS protocol support and security headers like HSTS, DNSSEC, and CAA records. No explicit security or incident response policies are publicly available, which may represent an area for improvement. The cookie consent mechanism is robust and GDPR compliant, reflecting good privacy practices. Overall, 42matters demonstrates a strong market position with excellent content quality and trust indicators. Security posture is adequate but could be enhanced by adopting additional best practices. Strategic recommendations include improving TLS support, enabling DNSSEC, and publishing detailed security policies to bolster trust and compliance.

85
58
25
95
85
85
100
appintelligencemobileappsconnectedtvappmarketdatasdkanalytics+4 more
Next.jsReactGoogle Tag ManagerVisual Website Optimizer+4

Partner Domains:

similarweb.com
parentpending
2025-06-14T13:53:34.764Z
vnda.com.br favicon

Olist Vnda

vnda.com.br

61
E-commerceBrazilenterpriseMEDIUM

Olist Vnda is a leading Brazilian omnichannel e-commerce platform designed to empower online retailers with integrated technology and marketing tools to accelerate business growth. The platform offers advanced features such as marketing automation, order management, and direct sales force digitalization, positioning itself strongly in the competitive e-commerce market. Technically, the website is built on modern frameworks like Next.js and React, leveraging Cloudflare for hosting and security. It integrates multiple analytics and marketing tools including Google Analytics, Mixpanel, LinkedIn Insight Tag, and Bing UET, indicating a mature digital marketing strategy. However, the security posture reveals critical gaps, notably the absence of a valid SSL/TLS certificate and disabled TLS protocols, which significantly undermine secure communications and user trust. While security headers are well configured, the lack of HTTPS is a major vulnerability. The website demonstrates excellent design, user experience, and content quality, with strong branding and trust signals such as customer case studies and comprehensive privacy policies. Strategic recommendations include immediate SSL/TLS deployment, enabling modern TLS protocols, and implementing cookie consent mechanisms to enhance compliance and security.

75
25
25
80
50
85
100
e-commerceomnichannelmarketingautomationintegrationplatform+2 more
Next.jsReactCloudflareGoogle Tag Manager+7

Partner Domains:

olist.com
parent57
tiny.com.br
partner61

+1 more partners

2025-06-14T13:04:06.179Z
alipayplus.com favicon

Alipay+

alipayplus.com

69
FinanceN/aenterpriseMEDIUM

Alipay+ is a global digital payment platform operated by Ant International, providing cross-border mobile payment solutions and digitalization technologies to millions of consumers and businesses worldwide. The platform enables seamless payments via multiple e-wallets and banking apps, targeting global brands, mobile payment providers, and merchants. Their extensive partner ecosystem and large consumer base position them as a significant player in the financial technology sector. Technically, the website leverages modern web technologies including React and Next.js, hosted on Alibaba Cloud infrastructure with CDN acceleration, ensuring fast and mobile-optimized user experiences. Security posture is generally strong with valid SSL certificates, HSTS enabled, and no detected major vulnerabilities. However, the absence of TLS 1.2+ protocols and DNSSEC implementation are notable gaps. Privacy and cookie policies are present and appear GDPR compliant, but explicit security and incident response policies are not publicly disclosed. Overall, Alipay+ demonstrates a mature digital presence with strong branding, comprehensive service offerings, and a good security baseline, though some improvements in security protocols and transparency could enhance trust and compliance.

25
40
17
100
92
85
100
mobilepaymentcross-borderpaymentsdigitalwallete-walletfinancialtechnology+3 more
ReactNext.jsTengine web serverCDN (marmot-cloud.com)+4

Partner Domains:

antglobal.com
partneranalyzing...
antom.com
partneranalyzing...

+2 more partners

2025-06-14T12:59:58.749Z
mongodb.com favicon

MongoDB, Inc.

mongodb.com

91
TechnologyUnited StatesenterpriseLOW

MongoDB, Inc. is a leading provider of modern, flexible, and AI-ready database solutions designed to help developers and enterprises build scalable applications. Positioned as a market leader in cloud database management systems, MongoDB offers a comprehensive suite of services including MongoDB Atlas, self-managed enterprise solutions, and developer tools. The company targets a broad audience ranging from startups and AI innovators to large enterprises across various sectors such as technology, financial services, healthcare, retail, automotive, and telecommunications. Their business model combines SaaS offerings with self-managed deployments, emphasizing flexibility and performance. Technically, MongoDB's website leverages modern web technologies including Next.js and React, hosted on AWS CloudFront CDN, and managed via Contentstack CMS. The site demonstrates fast performance, good mobile optimization, and strong SEO practices. Security-wise, MongoDB employs a valid SSL certificate but currently lacks modern TLS protocol support and HSTS enforcement, which are recommended for enhanced security. The site includes comprehensive legal and security policies, including a vulnerability disclosure policy, but lacks a visible cookie consent mechanism. Overall, MongoDB maintains a strong security posture with no detected vulnerabilities in SSL/TLS configurations and provides clear trust signals through customer case studies and industry recognitions. The company’s digital maturity is high, with a well-structured, professional website that supports its market leadership. Strategic improvements in security protocols and privacy compliance mechanisms would further strengthen their risk management and user trust.

-
-
-
100
80
85
100
databaseclouddeveloperAIenterprise+4 more
Next.jsReactSource Code Pro fontEuclid Circular A font+2

Partner Domains:

cloud.mongodb.com
service
support.mongodb.com
service

+1 more partners

2025-06-14T12:17:27.850Z
nifty.com favicon

NIFTY Corporation

nifty.com

82
TelecommunicationsJapanlargeLOW

NIFTY Corporation operates as a major Japanese internet service provider offering a wide range of broadband, mobile SIM, security, and media services primarily targeting Japanese consumers. The company maintains a strong market position with a comprehensive portfolio including @nifty光 broadband, NifMo mobile SIM, and various security and lifestyle services. Their digital presence is built on modern web technologies such as Next.js and is hosted via Amazon CloudFront, ensuring fast content delivery and good mobile optimization. However, the website currently lacks a valid SSL certificate, which is a critical security concern that undermines user trust and data protection. Security headers are partially implemented, but the absence of DNSSEC, CAA records, and HSTS reduces domain and transport security. The site uses multiple advertising and tracking services, with moderate user tracking and basic privacy compliance. Contact information is limited to a phone number with no visible email addresses or contact forms on the main page. Overall, the website is professionally designed with good content relevance and navigation clarity but requires urgent security improvements to protect users and enhance trust.

55
-
-
70
100
85
100
ISPInternet Service ProviderJapanTelecommunicationsSecurity+3 more
Next.jsReactJavaScriptAmazon CloudFront+1

Partner Domains:

lifemedia.jp
partnerpending
nojima.co.jp
partnerpending

+3 more partners

2025-06-14T12:17:00.411Z
everyday.com.au favicon

Everyday Rewards

everyday.com.au

66
loyalty programAustralialargeMEDIUM

The website demonstrates a strong foundation in network security and SSL/TLS implementation, scoring 100 in these areas, which ensures encrypted communication and robust network defenses. However, significant gaps exist in security headers, GDPR compliance, and adherence to the NIS2 directive, with scores ranging from 25 to 35 out of 100, exposing the business to regulatory, reputational, and operational risks. The absence of critical security headers like Content-Security-Policy and X-Frame-Options increases vulnerability to cross-site scripting and clickjacking attacks. Lack of privacy policies, cookie consent mechanisms, and third-party privacy disclosures pose serious compliance issues under GDPR, potentially resulting in fines and legal consequences. Deficiencies in information security frameworks, incident response plans, and business continuity preparations further heighten the risk of prolonged service disruptions and inadequate breach management. While email security and DNS health are relatively strong, enabling DNSSEC and configuring CAA records would enhance domain integrity and prevent abuse. Addressing these weaknesses promptly will protect customer trust, ensure regulatory compliance, and reduce the likelihood of costly security incidents.

35
25
25
85
100
85
100
loyaltyrewardsretailAustraliaWoolworths
ReactNext.jsJavaScriptAEM (Adobe Experience Manager)+2

Partner Domains:

bigw.com.au
subsidiaryanalyzing...
originenergy.com.au
partneranalyzing...

+1 more partners

2025-06-13T21:58:14.151Z