Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

149091
Websites
130
Industries
113
Countries
52
Avg Score
Page 1 of 39|Showing 1-50 of 1916
U

U.S. Government Publishing Office

govinfo.gov

54
GovernmentUnited StatesenterpriseMEDIUM

GovInfo is the official public access portal operated by the U.S. Government Publishing Office, providing free and authoritative access to government publications from all three branches of the federal government. The website serves a broad audience including the general public, researchers, and government officials, positioning itself as a trusted source for official government documents. The business model is a government service focused on transparency and public dissemination of information. Technically, the site is built on Drupal 10 CMS with Bootstrap 5 for responsive design, leveraging modern web technologies such as jQuery and FontAwesome. The site demonstrates good mobile optimization, accessibility, and SEO practices, although performance is moderate. The infrastructure appears stable and professionally maintained, consistent with a large government enterprise. From a security perspective, the site uses HTTPS and shows no signs of exposed sensitive data or vulnerable libraries. However, the absence of visible security headers and lack of published privacy, cookie, or incident response policies indicate areas for improvement. The WHOIS data is unavailable, likely due to government privacy policies, but the .gov domain and official branding strongly support legitimacy. Overall, GovInfo presents a secure, professional, and trustworthy government information portal with excellent content quality and user experience. Strategic enhancements in privacy compliance documentation, security header implementation, and incident response transparency would further strengthen its security posture and user trust.

30
35
17
40
57
70
100
governmentofficialpublishingdocumentspublicaccess+1 more
Drupal 10jQueryBootstrap 5FontAwesome+1
2026-04-17T13:16:08.224Z
vasarnap.com favicon

Duel-Press s.r.o.

vasarnap.com

47
MediaSlovakiamediumHIGH

Vasarnap.com is the online presence of Vasárnap, a Hungarian language family magazine published by Duel-Press s.r.o., based in Slovakia. The website offers a variety of family-oriented content including news, lifestyle articles, multimedia, and advertising services. It targets Hungarian-speaking families and general audiences interested in family magazine content. The business is well-established with a domain age dating back to 2003, indicating a mature market presence. Technically, the site is built on Drupal 10, uses Cloudflare DNS, and integrates reputable analytics and advertising platforms such as Gemius, Google Tag Manager, and AdsInteractive. The site is mobile optimized, accessible, and SEO friendly, providing a good user experience. Security posture is solid with HTTPS enforced and clientTransferProhibited domain status, though DNSSEC is not enabled and some security headers could be improved. Privacy compliance is strong with a comprehensive GDPR policy and cookie consent mechanism. No critical vulnerabilities or blocking mechanisms were detected, and the domain registration is consistent and trustworthy. Overall, Vasarnap.com presents a professional, secure, and compliant media website with a clear business focus and good technical implementation.

30
35
2
70
42
75
40
familymagazinehungarianlanguagemedianewsgdpr+2 more
Drupal 10Cloudflare DNSGoogle Tag ManagerGemius analytics+2

Partner Domains:

ujszo.com
partner
2025-11-01T16:44:28.899Z
heks.ch favicon

HEKS - Hilfswerk der Evangelisch-reformierten Kirche Schweiz

heks.ch

64
Non-profitSwitzerlandlargeMEDIUM

HEKS is a well-established Swiss non-profit organization affiliated with the Evangelical Reformed Church of Switzerland. It focuses on humanitarian aid, development projects, and social integration, with key thematic areas including climate justice, land and food rights, migration, and inclusion. The organization targets a broad audience including donors, partners, and beneficiaries, operating both nationally and internationally. The website reflects a mature digital presence with multilingual support and clear calls to action for donations and engagement. Technically, the website is built on Drupal 10 with Commerce 2, integrating modern analytics and marketing tools such as Google Tag Manager, Facebook Pixel, and Crazy Egg. The site is mobile-optimized, accessible, and SEO-friendly, demonstrating good digital maturity. Security measures include HTTPS enforcement and standard security headers, though there is room for improvement in publishing explicit security policies and incident response information. The security posture is solid with no detected vulnerabilities or exposed sensitive data. Privacy compliance is strong, with a comprehensive privacy and cookie policy and consent mechanisms in place. Business credibility is high, supported by transparent contact information, certifications like ZEWO, and trust signals such as a whistleblowing platform and ACT Alliance membership. Overall, HEKS presents a trustworthy, professional, and secure online presence suitable for its non-profit mission. Strategic recommendations include enhancing security transparency and incident response readiness to further strengthen stakeholder confidence.

55
53
2
65
72
80
100
non-profithumanitariancharityclimatejusticemigration+3 more
Drupal 10Commerce 2Google Tag ManagerFacebook Pixel+4
2025-11-01T14:58:19.010Z
vobacom.pl favicon

VOBACOM sp. z o.o.

vobacom.pl

51
TechnologyPolandmediumMEDIUM

VOBACOM sp. z o.o. is a well-established Polish technology company specializing in intelligent IT solutions for businesses and institutions. Their offerings include web and mobile solutions based on Drupal 10 CMS, augmented reality applications, teletechnical systems, and professional training through their NewTech Academy. The company has a strong regional presence with notable clients such as PKP, PGNiG, and several Polish cities, reflecting a solid market position. The website is professionally designed, accessible, and optimized for mobile devices, providing clear navigation and relevant content tailored to their B2B audience. Technically, the website leverages modern technologies including Drupal 10, Google Tag Manager, and Google Analytics, hosted by OVH SAS. The site demonstrates good performance and accessibility standards, with appropriate SEO and privacy compliance measures such as cookie consent banners and a comprehensive privacy policy. Security posture is good with HTTPS enforced and no visible vulnerabilities, though DNSSEC is not enabled and security headers could be improved. Overall, the security posture is robust for a medium-sized technology firm, with no critical vulnerabilities detected. The domain registration data is consistent with the business claims, showing a long operational history since 2005. Privacy compliance is strong, with GDPR-aligned policies and user consent mechanisms in place. The website content is safe for general audiences, with no adult or questionable material. Strategically, VOBACOM should consider enhancing DNS security by enabling DNSSEC and implementing additional HTTP security headers. Publishing a security.txt file could improve vulnerability disclosure transparency. These steps would further strengthen their security posture and trustworthiness in the market.

55
25
2
85
52
90
20
technologydrupalaugmentedrealitywebsolutionstraining+1 more
Drupal 10Google Tag ManagerGoogle AnalyticsGTranslate
2025-11-01T13:40:20.582Z
frick.org favicon

The Frick Collection

frick.org

67
Non-profitUnited StatesmediumMEDIUM

The Frick Collection is a well-established non-profit art museum located in New York City, specializing in Renaissance to 19th-century art. The website serves as a comprehensive digital portal offering information on exhibitions, collections, educational programs, and membership opportunities. It targets art enthusiasts, researchers, students, and donors, positioning itself as a reputable cultural institution with a strong online presence. Technically, the website is built on Drupal 10, leveraging modern front-end technologies such as Tailwind CSS and Swiper.js for responsive design and user experience. It integrates Google Analytics and Tag Manager for visitor tracking and marketing insights. The site demonstrates good mobile optimization, accessibility, and SEO practices, contributing to a positive user experience. From a security perspective, the site enforces HTTPS and includes standard security headers, indicating a solid baseline security posture. However, the absence of a publicly available security policy, incident response contacts, and vulnerability disclosure mechanisms suggests room for improvement in transparency and readiness. The WHOIS data is unavailable or malformed, which slightly impacts domain trust assessment but does not detract significantly from the overall credibility given the professional website content. Overall, the Frick Collection website is a professional, secure, and user-friendly platform that effectively supports the institution's mission and audience engagement. Strategic enhancements in security transparency and domain registration clarity would further strengthen trust and compliance.

55
70
17
75
62
75
100
museumartcultureeducationnon-profit+2 more
Drupal 10Tailwind CSSGoogle Tag ManagerGoogle Analytics+3

Partner Domains:

collections.frick.org
partner
shop.frick.org
partner
2025-11-01T13:35:54.827Z
syfy.com favicon

SYFY

syfy.com

68
MediaN/alargeMEDIUM

SYFY is a well-established media brand specializing in science fiction, fantasy, and horror entertainment. The website serves as an official platform for streaming full episodes, exclusive videos, and providing news and schedules related to SYFY shows. It operates under the NBCUniversal umbrella, which positions it strongly in the cable and digital entertainment market. The site targets a general audience interested in genre entertainment and leverages a business model focused on content distribution and advertising revenue. Technically, the website is built on Drupal 10 and integrates multiple modern technologies including Adobe Launch, Google Tag Manager, mParticle, and Amazon Ads. The infrastructure supports extensive advertising and tracking mechanisms while maintaining good performance and mobile optimization. SEO and accessibility features are adequately implemented, contributing to a positive user experience. From a security perspective, the site enforces HTTPS and employs a comprehensive set of security headers, indicating a mature security posture. Privacy compliance is robust with clear privacy and cookie policies and consent mechanisms. However, the absence of explicit security policies, incident response contacts, and vulnerability disclosure programs suggests areas for improvement. The WHOIS data is notably missing or unavailable, which is unusual for a major brand and slightly detracts from trustworthiness, though the site content and technical indicators strongly support legitimacy. Overall, SYFY's website demonstrates a strong digital presence with good security and privacy practices, serving its audience effectively. Strategic enhancements in transparency around security policies and registrant information would further strengthen trust and compliance.

65
88
17
60
52
80
100
entertainmenttvshowsmediastreamingsciencefiction+2 more
Drupal 10Google Tag ManagermParticleAmazon Ads+2

Partner Domains:

nbc.com
parent
usanetwork.com
sister

+3 more partners

2025-11-01T13:13:48.542Z
giswatch.org favicon

Association for Progressive Communications (APC)

giswatch.org

57
Non-profitN/amediumMEDIUM

Global Information Society Watch (GISWatch) is a reputable non-profit initiative supported by the Association for Progressive Communications (APC) and Sida. It focuses on publishing comprehensive reports and fostering civil society advocacy around digital rights, internet governance, and information society issues globally. The website is multilingual and provides extensive resources and author profiles, targeting civil society, researchers, and policy makers. Technically, the website is built on Drupal 10, uses modern JavaScript libraries such as Leaflet.js for mapping, and employs Matomo analytics with privacy-conscious settings (no cookies, Do Not Track respected). The site is mobile-optimized and accessible, with good SEO practices. Security posture is solid with HTTPS enforced and domain registration locked against unauthorized changes. However, DNSSEC is not enabled, and there is no published security or incident response policy. Privacy compliance is basic, lacking a cookie consent mechanism. Contact information is limited to a contact form, with no explicit emails or phone numbers. Overall, the website presents a trustworthy and professional platform for its non-profit mission, with recommendations to enhance privacy compliance, security transparency, and contact accessibility.

50
53
2
60
52
60
100
digitalrightsinternetgovernancecivilsocietynon-profitinformationsociety+2 more
Drupal 10Leaflet.jsMatomo AnalyticsModernizr
2025-11-01T12:50:06.174Z
ciob.org favicon

The Chartered Institute of Building

ciob.org

67
Real EstateUnited KingdomlargeMEDIUM

The Chartered Institute of Building (CIOB) is a well-established professional body founded in 1834, dedicated to advancing the science, ethics, and practice of construction management and leadership globally. The organization offers membership services, professional development courses, events, and industry support, positioning itself as a leading authority in the built environment sector. The website reflects a mature digital presence with a clear focus on education, member support, and industry engagement. Technically, the site is built on Drupal 10, leveraging modern web technologies and Google Tag Manager for analytics and marketing. It demonstrates good mobile optimization, accessibility compliance (AA certified), and a professional design that supports user engagement and navigation. The presence of multiple certifications such as Cyber Essentials and Disability Confident further underscores its commitment to security and inclusivity. From a security perspective, the site enforces HTTPS and employs recognized certifications, though explicit security headers could be more visible. Privacy compliance is robust, with clear cookie and privacy policies and consent mechanisms in place. However, no explicit incident response or vulnerability disclosure information is provided, which could be improved. Overall, CIOB's website presents a low-risk profile with strong business credibility and technical maturity. Strategic recommendations include enhancing security header implementation, publishing vulnerability disclosure policies, and providing clearer incident response contacts to further strengthen trust and security posture.

40
83
10
80
57
80
100
constructionprofessionalbodyeducationmembershipbuiltenvironment+1 more
Drupal 10Google Tag ManagerJavaScriptCSS+1

Partner Domains:

ciobacademy.org
subsidiary
ciobjobs.com
subsidiary

+2 more partners

2025-11-01T12:31:55.808Z
nationalestaalprijs.nl favicon

Nationale staalprijs

nationalestaalprijs.nl

46
ManufacturingNetherlandssmallHIGH

Nationale staalprijs is a Dutch organization dedicated to promoting and awarding excellence in steel construction projects. The website serves as a platform to showcase nominations, winners, and project submissions related to steel construction within the Netherlands. It targets professionals and companies in the steel construction industry, providing information and recognition to encourage innovation and quality in this sector. The business model appears to be non-profit or industry promotional in nature, focusing on national recognition rather than commercial sales. Technically, the website is built on Drupal 10 CMS and integrates modern web technologies including Google Tag Manager, Google Analytics, YouTube and Vimeo APIs, and Google reCAPTCHA for form security. The site is mobile optimized with good navigation and SEO practices, although some accessibility features could be improved. Performance is moderate with asynchronous loading of scripts. From a security perspective, the site enforces HTTPS and uses Google reCAPTCHA on user registration and login forms to mitigate automated abuse. However, no explicit security headers were detected in the provided content, and there is no published security policy or incident response information. No vulnerabilities or exposed sensitive data were found in the analysis. Privacy compliance is limited as no privacy or cookie policies were found on the homepage content, which could be improved to meet GDPR standards. Overall, the website is professional, trustworthy, and well-targeted to its audience. The main risks relate to privacy compliance and security policy transparency. Strategic recommendations include publishing privacy and cookie policies, implementing security headers, and providing vulnerability disclosure information to enhance trust and compliance.

60
10
2
85
72
60
-
steelconstructionawardnetherlandsdrupal+1 more
Drupal 10Google Tag ManagerGoogle AnalyticsYouTube iframe API+2
2025-11-01T12:30:43.442Z
aeschbachquartier.ch favicon

Mobimo Management AG

aeschbachquartier.ch

61
Real EstateSwitzerlandmediumMEDIUM

The website www.aeschbachquartier.ch represents the Aeschbachquartier Aarau, a mixed-use urban development project managed by Mobimo Management AG, a reputable Swiss real estate company. The site offers detailed information about residential, commercial, and community spaces, targeting residents, businesses, and visitors in Aarau. The business model centers on real estate development and management, with a medium-sized market presence in Switzerland. Technically, the website is built on Drupal 10 with Bootstrap 5, featuring embedded Vimeo videos and Matomo analytics configured to respect DoNotTrack settings. The site is mobile-optimized, accessible, and SEO-friendly, with moderate performance. Security posture is good with HTTPS enforced and some security headers present, though improvements are recommended in cookie consent and explicit security policies. No critical vulnerabilities or suspicious content were detected. Privacy compliance is adequate with a comprehensive privacy policy, but lacks a visible cookie consent mechanism. Contact information is clear, though no direct email addresses are published. Overall, the site is professional, trustworthy, and aligned with the parent company Mobimo Management AG.

65
53
2
70
72
45
100
realestateurbandevelopmentresidentialcommercialmobimo+2 more
Drupal 10Bootstrap 5Matomo AnalyticsVimeo embed

Partner Domains:

hallenundhofhaus.aeschbachquartier.ch
partner
mobimo.ch
parent
2025-11-01T09:57:36.330Z
triflex.com favicon

Triflex GmbH & Co. KG

triflex.com

66
ManufacturingGermanymediumMEDIUM

Triflex GmbH & Co. KG is a specialized manufacturer and provider of waterproofing and marking solutions primarily targeting construction professionals and infrastructure managers. The company offers durable systems for waterproofing roofs, balconies, and parking decks, as well as road and cycle path markings. Their market position is that of a reputable specialist in their niche, with a medium-sized business footprint in Germany. The website reflects a professional and consistent brand image with good content quality and clear business focus. Technically, the website is built on Drupal 10 and integrates multiple modern analytics and marketing technologies including Google Tag Manager, Google Analytics, Facebook Pixel, Hotjar, and Mouseflow. The site is mobile optimized and demonstrates good SEO and accessibility practices. Cookie consent is managed via Cookiebot, ensuring compliance with GDPR and related privacy regulations. From a security perspective, the site enforces HTTPS and uses anti-bot cookies to enhance security. However, explicit security headers like Content-Security-Policy and X-Frame-Options were not clearly identified in the provided data. There is no visible security policy or incident response contact information, which could be improved. The absence of WHOIS data for the domain is a concern, reducing the overall trust score, though the website content and business presence appear legitimate. Overall, the website scores well in content quality, technical implementation, and security posture, but could benefit from improved transparency in domain registration and security policies. Strategic recommendations include publishing a security.txt file, enhancing security headers, and providing clear contact information for security incidents.

50
83
2
70
72
70
100
waterproofingmarkingconstructionb2bdrupal+3 more
Drupal 10Google Tag ManagerGoogle AnalyticsFacebook Pixel+5
2025-11-01T06:15:24.143Z
e-ifu.com favicon

Johnson & Johnson Medical Devices Companies

e-ifu.com

55
HealthcareN/aenterpriseMEDIUM

The website www.e-ifu.com serves as a digital portal for accessing Instructions for Use (IFU) documents related to Johnson & Johnson Medical Devices. It targets medical professionals and patients, providing multilingual support and a structured interface for document retrieval. The site is branded consistently with Johnson & Johnson Medical Devices Companies and uses modern web technologies including Drupal 10, Bootstrap 5, and various JavaScript libraries for enhanced user experience and functionality. Despite the professional presentation and clear business focus, the absence of WHOIS registration data raises questions about domain legitimacy, although the content and branding strongly suggest a legitimate enterprise presence. From a technical perspective, the site employs a robust technology stack with good mobile optimization and accessibility features. The use of Google Analytics, Google Tag Manager, and Qualtrics indicates moderate user tracking and marketing analytics integration. However, the site lacks visible privacy and cookie policies, which impacts its privacy compliance rating. Security best practices such as HTTPS usage and secure form handling are observed, but security headers and incident response contact information are not evident. Overall, the security posture is moderate with no critical vulnerabilities detected in the provided content. The missing WHOIS data and lack of explicit privacy documentation are notable gaps. The website is safe for general audiences, with no adult or questionable content detected. Strategic recommendations include publishing comprehensive privacy and cookie policies, enhancing security headers, and providing clear contact information for security incidents to improve trust and compliance.

75
35
2
30
57
65
100
healthcaremedicaldevicesinstructionsforusejohnsonjohnsondrupal+1 more
Drupal 10jQueryjQuery UIBootstrap 5+5
2025-11-01T03:13:55.426Z
getsmartaboutafib.com favicon

Johnson & Johnson (implied by DNS and name servers)

getsmartaboutafib.com

67
HealthcareN/alargeMEDIUM

The website getsmartaboutafib.net is a professionally developed healthcare education platform focused on providing comprehensive information about Atrial Fibrillation (AFib), its symptoms, treatment options, and patient experiences. The site targets patients and the general public seeking to understand AFib better and make informed decisions about their care. The branding and DNS infrastructure strongly suggest ownership or sponsorship by Johnson & Johnson, a major healthcare corporation, lending credibility and trust to the platform. Technically, the website leverages modern technologies including Drupal 10 as the CMS and React for interactive components, supported by standard marketing and analytics tools such as Google Tag Manager, Facebook Pixel, and Hotjar. The site is mobile optimized, accessible, and SEO friendly, providing a good user experience. Cookie consent is implemented via OneTrust, indicating compliance with GDPR and privacy regulations. From a security perspective, the site uses HTTPS with a good SSL configuration and has domain transfer protections in place. However, DNSSEC is not enabled, and security headers are not explicitly detected in the provided data, suggesting room for improvement. No direct contact information or security policies are found, which could be enhanced to improve transparency and incident response readiness. Overall, the website presents a low-risk profile with strong business credibility and good technical maturity. Strategic recommendations include enabling DNSSEC, publishing privacy and security policies, and adding clear contact channels for security incidents to further strengthen trust and compliance.

75
88
25
40
57
70
100
healthcareatrialfibrillationpatienteducationmedicalinformationcardiology
Drupal 10ReactGoogle Tag ManagerHotjar+2
2025-11-01T03:13:30.362Z
D

DePuy Synthes

depuysynthes.com

10
HealthcareUnited StatesenterpriseCRITICAL

DePuy Synthes, a Johnson & Johnson company, operates as a leading global provider of orthopaedic medical devices and solutions. The website targets healthcare professionals and showcases a broad portfolio of orthopaedic implants and surgical instruments. The business model is primarily B2B, focusing on medical institutions and professionals. The site reflects a strong market position within the healthcare sector under the Johnson & Johnson MedTech umbrella. Technically, the website is built on a modern stack including Drupal 10 and React, with integration of Brightcove for video content and Google Tag Manager for analytics. The site demonstrates good mobile optimization, accessibility, and SEO practices, indicating a mature digital infrastructure. Cookie consent and privacy policies are implemented, reflecting compliance with GDPR and other privacy regulations. From a security perspective, the site enforces HTTPS with strong SSL configuration and includes standard security headers. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not publicly available, representing areas for improvement. No vulnerabilities or exposed sensitive data were detected during analysis. Overall, the website is professional, trustworthy, and well-maintained, with a strong business credibility score. The absence of WHOIS data limits domain registration trust analysis but does not detract from the evident legitimacy of the site as a corporate entity of Johnson & Johnson. Strategic recommendations include publishing detailed security policies and incident response information to enhance transparency and trust.

-
-
-
-
-
-
-
healthcaremedicaldevicesorthopaedicsjohnsonjohnsonmedtech
Drupal 10ReactBrightcove PlayerGoogle Tag Manager+1

Partner Domains:

jnj.com
parent
depuysynthes.com
subsidiary
2025-11-01T03:01:02.683Z
foireurop.com favicon

Accueil | Foire Européenne de Strasbourg

foireurop.com

59
OtherFrancesmallMEDIUM

The website www.foireurop.com represents the Foire Européenne de Strasbourg, a European fair event held in Strasbourg, France. The site provides information about the event, targeting visitors and exhibitors interested in attending. The business model revolves around event organization and promotion, catering primarily to the general public and regional visitors. The website is built on Drupal 10, leveraging modern web technologies such as FontAwesome, Leaflet.js for maps, and Slick Carousel for UI components. Analytics are handled via Matomo and Google Tag Manager, with cookie consent managed through tarteaucitron.io, indicating some level of GDPR compliance awareness. From a security perspective, the site uses HTTPS and implements cookie consent mechanisms, but lacks visible security headers and explicit privacy or terms of service pages in the provided content. No contact information or incident response channels are clearly presented, which may hinder user trust and compliance. The WHOIS data is unavailable, raising concerns about domain registration legitimacy and reducing overall trustworthiness. No WAF or blocking mechanisms were detected, and the site content is accessible and safe for general audiences. Overall, the website demonstrates moderate digital maturity with good technical implementation and content quality but requires improvements in transparency, security best practices, and business credibility to enhance trust and compliance. Strategic recommendations include publishing clear privacy and terms policies, adding contact and security incident information, and improving security headers and monitoring of third-party scripts.

55
53
17
60
52
75
100
eventfairstrasbourgeuropeanfairdrupal+1 more
Drupal 10FontAwesome 6 ProLeaflet.jsSlick Carousel+4
2025-11-01T00:57:55.124Z