Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 70 of 90|Showing 3451-3500 of 4454
estia.fr favicon

ESTIA

estia.fr

0
EducationFrancemediumMEDIUM

ESTIA is a reputable French engineering school specializing in generalist and international trilingual engineering education. It is a member of the Groupe ISAE and affiliated with the CCI Bayonne Pays Basque. The institution offers a broad range of engineering programs, including preparatory cycles, bachelor, master, and specialized master's degrees, with a strong emphasis on international partnerships and research innovation. The website reflects a professional and well-established educational entity with comprehensive content and clear navigation. Technically, the website is built on TYPO3 CMS, uses modern analytics tools like Matomo and Google Analytics, and implements cookie consent mechanisms compliant with GDPR. The site is mobile-optimized and accessible, with good SEO practices. Security posture is solid with HTTPS enforced and no visible vulnerabilities, though security headers could be improved. The WHOIS data is unavailable, likely due to privacy protection, but the domain and website content align with a legitimate educational institution. Overall, ESTIA demonstrates a strong security and compliance posture with clear privacy policies, certifications, and contact information. The site is trustworthy and professionally maintained, serving its educational mission effectively.

40
68
17
85
67
80
100
educationengineeringinternationaltechnologyresearch+4 more
TYPO3 CMSMatomo AnalyticsBootstrapJavaScript+1

Partner Domains:

entreprendre.estia.fr
partner
www.compositadour.com
partner

+3 more partners

2025-07-29T05:46:23.308Z
citizenplane.com favicon

CitizenPlane

citizenplane.com

0
TransportationFrancemediumMEDIUM

CitizenPlane is a technology company providing an operating system and flight distribution platform tailored for airlines and tour operators. Their flagship products, Zenith and Air, enable airlines to optimize revenue, manage offers, and distribute flights through major online travel agencies and metasearch engines. The company positions itself as a global player with offices in France, Singapore, Brazil, and Panama, serving hundreds of airline customers worldwide. The website reflects a professional and modern digital presence built on Webflow, with strong branding and clear messaging focused on the airline industry. Technically, the website employs modern web technologies including Webflow CMS, Google reCAPTCHA for form security, and Amazon S3 for asset hosting. The site is mobile-optimized, fast-loading, and well-structured for SEO. However, some security best practices such as explicit security headers and cookie consent mechanisms are missing, which could be improved to enhance compliance and security posture. From a security perspective, the site uses HTTPS and includes CAPTCHA protections on forms, indicating a baseline security posture. The absence of WHOIS data for the domain is a concern, suggesting either recent registration or privacy protection, which slightly reduces trustworthiness. No critical vulnerabilities or exposed sensitive data were detected. Privacy and terms of service documents are provided, indicating attention to compliance, though cookie consent is lacking. Overall, CitizenPlane's website presents a credible and professional business with a solid technical foundation. Strategic improvements in security headers, cookie consent, and transparency around domain registration would further strengthen trust and compliance.

30
53
2
75
57
60
100
airlineoperatingsystemflightdistributionaviationtechnologysaas+1 more
Webflow CMSGoogle reCAPTCHAjQuery 3.5.1SVG graphics
2025-07-29T04:36:49.866Z
lexip.co favicon

Lexip

lexip.co

0
E-commerceFrancesmallMEDIUM

Lexip is a French-based e-commerce company specializing in premium gaming accessories and peripherals, including controllers, headsets, keyboards, mice, and limited edition collector items. Positioned as one of the main French manufacturers in this niche, Lexip targets professional and enthusiast gamers seeking high-quality gaming hardware. The website is built on a modern WordPress infrastructure utilizing WooCommerce for e-commerce capabilities, Elementor for design, and integrates marketing automation tools such as Sendinblue and Klaviyo. The site demonstrates good content quality, branding consistency, and a professional user experience, although explicit privacy and cookie policies are not readily found. From a security perspective, the website enforces HTTPS and uses security plugins like Wordfence, but lacks visible security headers and explicit incident response or security policy information. No WHOIS data is available due to privacy protection, which is common for commercial sites but limits domain trust verification. The site does not exhibit any adult or questionable content and is accessible without WAF or blocking mechanisms. Overall, Lexip presents a credible and professional e-commerce platform with moderate technical maturity and security posture. Improvements in privacy compliance documentation, security header implementation, and clearer contact information would enhance trust and compliance.

15
50
2
90
72
80
100
gaminge-commerceaccessoriesgamingperipheralsfrenchmanufacturer
WordPressWooCommerceElementorYoast SEO+5
2025-07-28T20:32:05.179Z
full.life favicon

Fulllife

full.life

0
E-commerceFrancesmallMEDIUM

Fulllife is a French e-commerce company specializing in eco-responsible streetwear apparel targeted at the gaming community. The website presents a professional and consistent brand image with a focus on sustainability and gaming culture. The business operates primarily online using a Magento-based platform, integrating various marketing and analytics tools such as Google Tag Manager, Klaviyo, and Adobe Commerce SDK. The domain is registered with Scaleway SAS in France since 2018, aligning well with the company's profile and market presence. Technically, the website employs a modern e-commerce stack with responsive design and moderate performance. However, there is room for improvement in security practices, including enabling DNSSEC, implementing security headers, and publishing comprehensive privacy and cookie policies. No WAF or blocking mechanisms were detected, indicating full accessibility. Security posture is adequate with HTTPS enforced and domain transfer protection, but lacks advanced security headers and formal incident response or vulnerability disclosure information. Privacy compliance is weak due to missing policies and consent mechanisms, which could expose the company to regulatory risks. Overall, the website is functional and credible but would benefit from enhanced security and privacy compliance measures to strengthen trust and regulatory adherence.

85
65
2
70
72
50
100
e-commercefashionstreetweargamingeco-responsible+2 more
MagentoGoogle Tag ManagerKlaviyoHiPay+2
2025-07-28T20:31:29.894Z
iw3c2.org favicon

International World Wide Web Conference Committee

iw3c2.org

0
TechnologyFrancesmallHIGH

The International World Wide Web Conference Committee (IW3C2) is a small, non-profit organization founded in 1994 and incorporated in 1996 under Swiss law, historically responsible for managing the WWW Conference series. Since 2022, the organization transitioned its mission to managing funds for awards related to conference publications, ceasing its association activities in 2025 with ACM/SIGWEB assuming responsibility. The website serves primarily as an archival and informational resource for the Web research community, hosting conference archives and award information. Technically, the website is built on basic HTML, CSS, and JavaScript without modern frameworks or CMS, hosted by OVH sas. The site is accessible and moderately optimized for mobile and SEO, though it lacks advanced accessibility features and modern performance optimizations. Security posture is basic, with HTTPS enabled but missing DNSSEC and security headers. No privacy or cookie policies are published, and no contact or incident response information is provided. Overall, the security posture is adequate for an informational archival site but would benefit from improvements in security headers, DNSSEC, and privacy compliance. The domain registration is consistent and trustworthy, reflecting the organization's long history and legitimacy. No adult or questionable content is present, making the site safe for general audiences. Strategic recommendations include enhancing security configurations, publishing privacy and cookie policies, and improving mobile and accessibility features to align with modern standards and user expectations.

25
50
2
60
75
80
-
non-profitwebconferenceacademicarchivaltechnology
HTML5CSSJavaScript

Partner Domains:

sigweb.org
partner
2025-07-28T09:31:57.027Z
nicotine-plus.org favicon

Nicotine+

nicotine-plus.org

0
TechnologyFrancesmallMEDIUM

Nicotine+ is an open source software project providing a graphical client for the Soulseek peer-to-peer network. The project targets users of Soulseek and open source contributors, offering a lightweight and feature-rich alternative client. The website is well structured with good SEO metadata and clear information about the software, its development, and community involvement. The domain is long-standing and registered with OVH in France, consistent with the project's history. Technically, the site uses Jekyll for static site generation, Python and GTK for the client software, and is hosted by OVH. The website performance is moderate with basic mobile optimization and accessibility. No CMS beyond Jekyll is detected. The site lacks advanced security headers and DNSSEC is not enabled, which are areas for improvement. No analytics or tracking scripts are present, indicating minimal user tracking. Security posture is moderate; the site uses HTTPS but lacks security headers and DNSSEC. The Soulseek protocol itself is unencrypted, which is disclosed on the site. No privacy or cookie policies are provided, representing a compliance gap. No contact information or incident response contacts are listed, limiting transparency. Overall, the website is trustworthy and professional for an open source project but should improve privacy and security practices to enhance compliance and user trust.

15
53
2
60
95
75
100
opensourcepeer-to-peersoftwaretechnologynicotine+1 more
PythonGTK
2025-07-27T17:26:58.591Z
arsys.fr favicon

Arsys Internet S.L.U.

arsys.fr

0
TechnologyFrancelargeMEDIUM

Arsys Internet S.L.U. is a well-established European technology company specializing in domain registration, web hosting, cloud services, and managed IT solutions. With over 25 years of experience, Arsys targets businesses and individuals primarily in France, Spain, Portugal, and English-speaking markets. Their offerings include domain sales, professional email, WordPress and ecommerce hosting, VPS and dedicated servers, and comprehensive cloud solutions with a focus on European data sovereignty. Technically, the website demonstrates a mature digital infrastructure with modern web technologies, responsive design, and integration of advanced analytics and error monitoring tools such as Sentry and Tune. The presence of structured data enhances SEO and business transparency. The hosting environment appears robust, likely leveraging their own or Ionos infrastructure, ensuring fast performance and good accessibility. From a security perspective, the site enforces HTTPS and uses secure cookie settings, with no visible vulnerabilities or exposed sensitive data. However, explicit security headers and a published security policy or incident response contacts are absent, representing areas for improvement. Privacy compliance is well addressed with clear privacy and cookie policies, including consent mechanisms aligned with GDPR. Overall, Arsys presents a trustworthy and professional online presence with strong business credibility and technical maturity. The lack of WHOIS data due to privacy protection slightly reduces domain trust but is justified for this business type. Strategic recommendations include enhancing security header implementation, publishing a security policy, and adding vulnerability disclosure mechanisms to further strengthen security posture and customer trust.

75
25
25
70
77
70
100
arsyshbergementdomaineemailcloud+5 more
HTML5CSS3JavaScriptSentry (error tracking)+2

Partner Domains:

www.arsys.es
partner
www.arsys.pt
partner

+1 more partners

2025-07-27T15:14:27.128Z
in-part.com favicon

Inpart

in-part.com

0
HealthcareFrancemediumMEDIUM

Inpart operates as a specialized SaaS platform facilitating scientific partnering, primarily targeting the biopharma, scientific, and academic sectors. The company positions itself as a trusted partner offering solutions to connect, network, and execute collaborations efficiently. Their market presence is supported by a global vetted network including top R&D firms and academic institutions, emphasizing their role in accelerating innovation and commercialization in healthcare and biotechnology. Technically, the website leverages modern web technologies such as SvelteKit and integrates Google Tag Manager for analytics, indicating a contemporary and maintainable digital infrastructure. The site demonstrates good mobile optimization, accessibility, and SEO practices, contributing to a positive user experience and discoverability. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data in its HTML content. However, it lacks explicit security headers and published privacy or cookie policies, which are important for compliance and trust. No incident response or vulnerability disclosure information is provided, which could be improved to enhance security posture and transparency. Overall, the website is professional, trustworthy, and well-designed, with a moderate to high security posture. The absence of WHOIS registrant data is mitigated by consistent business information and structured data on the site. Strategic improvements in privacy compliance and security best practices are recommended to further strengthen trust and regulatory adherence.

30
53
17
70
72
75
100
sciencepartneringbiopharmaacademiccollaborationsaasplatformnetworking+3 more
SvelteKitJavaScriptGoogle Tag ManagerGoogle Analytics
2025-07-27T14:06:27.899Z
cure51.com favicon

Cure51

cure51.com

0
HealthcareFrancesmallMEDIUM

Cure51 is a specialized TechBio company focused on cancer research and drug discovery by leveraging a unique database of cancer survivors known as Outliers. The company collaborates with leading international oncology centers and renowned scientific leaders to develop precision medicine tools and novel therapeutic targets. Their market position is that of an innovative and credible player in the healthcare and biotechnology sectors, with a strong emphasis on scientific rigor and partnerships. Technically, the website is built on a modern React and Next.js stack, hosted and registered via Cloudflare, and uses Matomo for privacy-conscious analytics. The site is well-optimized for performance, mobile responsiveness, and SEO, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS and has domain transfer protections but lacks DNSSEC and published security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is well addressed with clear privacy and cookie policies and GDPR indicators. Overall, Cure51 presents a trustworthy and professional online presence with minor security and compliance improvements recommended to enhance trust and resilience.

15
68
17
70
52
75
40
canceroncologyprecisionmedicinebiotechresearch+3 more
ReactNext.jsMatomo AnalyticsCloudflare DNS and registrar

Partner Domains:

gustaveroussy.fr
partner
vhio.net
partner

+3 more partners

2025-07-27T11:47:48.771Z
pronoms.fr favicon

Le collectif du « Conseil du Langage Neutre »

pronoms.fr

0
OtherFrancesmallHIGH

Pronoms.fr is a French-based, volunteer-driven, open-source project focused on promoting inclusive and non-binary language through examples of personal pronouns and neutral language usage. It offers users the ability to create and share personalized pronoun cards, supports multiple languages, and fosters community engagement through social media and a dedicated queer calendar. The project is positioned as a niche educational and social inclusion resource within the LGBTQ+ community and language activism space. Technically, the website is built using modern frameworks such as Nuxt.js and Vue.js, with integration of Shopify for e-commerce functionalities. It leverages Cloudflare for DNS and possibly CDN services, uses Google Fonts and Font Awesome for UI, and employs Plausible Analytics for privacy-respecting visitor tracking. The site is well-optimized for mobile devices, accessible, and SEO-friendly, reflecting a mature digital infrastructure for a small community project. From a security perspective, Pronoms.fr enforces HTTPS, implements key security headers, and avoids exposing sensitive data. However, it lacks a visible cookie consent mechanism and formal security or incident response policies, which are recommended for compliance and transparency. No vulnerabilities or suspicious activities were detected, indicating a strong security posture for its scale. Overall, Pronoms.fr presents a trustworthy, professional, and community-oriented platform with excellent content quality and technical implementation. Strategic improvements in privacy compliance and formal security documentation would further enhance its credibility and user trust.

50
50
50
50
-
50
100
pronounsinclusivelanguagelgbtqnon-binarygenderneutrality+3 more
Nuxt.jsVue.jsShopify Buy SDKCloudflare DNS+4

Partner Domains:

pronouns.page
partner
shop.pronouns.page
partner

+2 more partners

2025-07-27T09:07:34.797Z
A

Associazione AI ODV

onenetbeyond.org

0
OtherFrancesmallHIGH

The website onenetbeyond.org is currently inaccessible or blocked, presenting only a minimal placeholder page with the message: 'You have reached this page because your request could not be properly identified.' This prevents any meaningful extraction of business or service information from the site itself. The domain is registered to Associazione AI ODV, a French organization, with a long registration history dating back to 2005, indicating an established entity. However, the lack of accessible content and absence of privacy, cookie, or contact information significantly limit the ability to assess the business model or market position. From a technical perspective, no information about the technology stack, CMS, or hosting beyond the nameservers is available. The site appears to be hosted on servers related to investici.org. No security headers or SSL configuration details were provided, and no analytics or tracking technologies were detected. The minimal content and lack of metadata suggest poor SEO and user experience. Security posture evaluation is constrained by the lack of accessible content and technical data. No privacy policies, incident response contacts, or security frameworks are evident. The domain registration data is consistent and legitimate, but the absence of website content and security best practices lowers the overall trust and security score. The site is likely behind a generic blocking mechanism or misconfigured server, resulting in a low AI score and high risk for users seeking information. Overall, the website requires significant improvements in accessibility, content provision, security policies, and compliance documentation to be considered trustworthy and professional.

15
40
17
83
95
85
40
2025-07-27T07:58:19.454Z
elenarossini.com favicon

Elena Rossini

elenarossini.com

0
MediaFrancesmallMEDIUM

Elena Rossini's website serves as a professional portfolio and advocacy platform for her work as an Italian filmmaker, photographer, and diversity advocate based in Paris, France. The site highlights her notable documentary 'The Illusionists' and her activism focused on social justice and media representation. The business model centers on freelance filmmaking, content creation, and educational outreach through blogs and newsletters. The website is well-positioned within a niche market of socially conscious media production and advocacy, targeting film enthusiasts and diversity supporters. Technically, the site is built on WordPress using the Salient theme and WPBakery Page Builder, with SEO optimization via Yoast SEO and analytics through Plausible Analytics. Hosting is supported by a CDN, and the site is mobile-optimized with good performance. However, there is room for improvement in accessibility and security headers. From a security perspective, the site uses HTTPS with a secure domain registration status but lacks DNSSEC and security headers. There are no visible vulnerabilities or exposed sensitive data. Privacy compliance is weak due to the absence of privacy and cookie policies and consent mechanisms. Contact information is available, but no formal security or incident response policies are published. Overall, the website is professional, trustworthy, and content-rich, with minor gaps in privacy compliance and security best practices. Strategic improvements in these areas would enhance user trust and regulatory adherence.

30
35
17
55
85
80
100
filmphotographydiversityactivismportfolio+3 more
WordPressYoast SEOWPBakery Page BuilderjQuery+2
2025-07-27T07:52:36.511Z
mopigames.gay favicon

Mopigames

mopigames.gay

0
TechnologyFrancesmallHIGH

This website represents a personal portfolio and blog for an individual developer known as Mopigames, a lesbian MtF transgender girl living in France. The site serves as a personal branding platform with links to social media and community sites, targeting a general audience interested in technology and personal content. The domain is newly registered in 2024 with privacy protection, consistent with the personal nature of the site. Technically, the site uses standard HTML, CSS, and JavaScript with Cloudflare DNS services. The site is moderately optimized for performance and mobile use but lacks advanced SEO and accessibility features. Security posture is basic with HTTPS enabled but no additional security headers or policies present. No privacy, cookie, or terms of service policies are found, indicating low privacy compliance. Contact information is clearly provided via email and social media links. No forms or data collection mechanisms are present, reducing risk exposure. The content is safe for general audiences with no adult or explicit material detected. Overall, the site is a small personal project with moderate professionalism and trustworthiness. Security and privacy improvements are recommended to enhance compliance and user trust.

15
35
2
40
62
70
100
personaldeveloperlgbtqblogtechnology
HTML5CSSJavaScriptCloudflare DNS

Partner Domains:

estrogen.monster
partner
uncertainalex.estrogen.monster
partner

+1 more partners

2025-07-27T06:46:42.256Z
raru.re favicon

RaRu.Re

raru.re

0
TechnologyFrancesmallMEDIUM

RaRu.Re is a small, community-driven Mastodon instance hosted in France, providing decentralized social media services within the Fediverse. The platform is operated by a small team of administrators and funded primarily through personal contributions and voluntary tips. The website offers clear information about its community, federation policies, and operational transparency, targeting Mastodon users seeking a cozy, friendly social media environment. Technically, the site runs Mastodon version 4.4.2 on a Ruby on Rails backend, hosted on Scaleway servers in Paris. The frontend uses modern JavaScript modules with integrity checks, and the site is mobile-optimized with good navigation and design quality. However, some accessibility and SEO features are basic, and no cookie consent mechanism is implemented despite having a privacy policy. From a security perspective, HTTPS is enforced with good SSL configuration, and daily backups are performed. Federation moderation policies help manage nuisance communities. However, the absence of explicit security headers and published incident response policies indicates room for improvement. Direct messages are explicitly noted as insecure for sensitive communication. Overall, RaRu.Re presents a trustworthy and well-maintained community Mastodon instance with moderate technical maturity and a good security posture. Strategic improvements in privacy compliance, security headers, and incident response transparency would enhance its risk profile and user trust.

85
58
25
60
65
70
40
mastodonfediversesocialmediacommunitydecentralized
Mastodon 4.4.2Ruby on RailsJavaScript ES ModulesScaleway hosting
2025-07-27T05:40:58.904Z
B

brodokk.space

brodokk.space

0
TechnologyFrancesmallHIGH

The website brodokk.space serves as a personal homepage for an individual known as Brodokk, who identifies as a Fennec fox persona. The site highlights personal and professional programming activities, server management, and participation in various online communities and projects. The content is straightforward, primarily textual with some images, and links to multiple social media and community platforms. The website is small-scale and targeted at a general audience interested in technology and creative online communities. From a technical perspective, the site is built with basic HTML and CSS, hosted by Gandi SAS, and does not use any advanced frameworks or CMS. The site is moderately optimized for mobile devices and accessibility but lacks advanced SEO and performance optimizations. No analytics or advertising technologies are detected, indicating a privacy-conscious or minimalistic approach. Security posture is basic; the domain uses HTTPS (implied by the URL), but no DNSSEC is enabled, and no security headers are present. There are no forms or data collection points, reducing attack surface but also limiting user interaction. The WHOIS data is transparent and consistent with the website's personal nature, with no privacy protection used. No privacy or cookie policies are present, which is a compliance gap. Overall, the website is low risk, safe for general audiences, and serves as a personal portfolio and community hub. Strategic recommendations include improving security headers, adding privacy and cookie policies, enabling DNSSEC, and enhancing mobile and accessibility features to improve user experience and compliance.

15
35
2
85
72
80
40
personaltechnologyprogrammingcommunityportfolio
HTML5CSS
2025-07-27T02:17:22.406Z
eldritch.cafe favicon

eldritch.cafe

eldritch.cafe

0
TechnologyFrancesmallMEDIUM

Eldritch.cafe operates as an independent Mastodon instance providing decentralized social media services primarily targeting queer, feminist, and anarchist communities, with a focus on French-speaking users. The platform emphasizes community moderation, inclusivity, and amplifying marginalized voices. It maintains a small but active user base and is hosted by Fedi Monster in France. The website content is bilingual and includes detailed moderation guidelines, credits, and legal notices consistent with French law. Technically, the site runs on a Glitch-soc fork of Mastodon, leveraging modern web technologies such as React and JavaScript. The infrastructure is moderately performant and mobile-optimized, though accessibility and SEO features are basic. Hosting and domain registration are consistent and legitimate, with HTTPS enabled and domain transfer protections in place. However, DNSSEC is not enabled, and security headers are absent, indicating room for improvement in security hardening. From a security perspective, the instance enforces clear community rules prohibiting hateful conduct, harassment, misinformation, and illegal content. While no explicit security policy or incident response contacts are published, the moderation team is transparent and active. Privacy compliance is adequate with a privacy policy present, but the absence of a cookie consent mechanism is a minor gap. No vulnerabilities or suspicious patterns were detected in the analysis. Overall, eldritch.cafe presents a trustworthy, community-driven social media platform with a solid technical foundation and clear governance. Strategic enhancements in security headers, cookie consent, and incident response transparency would further strengthen its security posture and compliance standing.

75
53
17
65
65
80
40
socialmediamastodonfederatedcommunityqueer+3 more
MastodonReactJavaScriptCSS
2025-07-27T02:16:42.268Z
ipregistry.co favicon

Ipregistry

ipregistry.co

0
TechnologyFrancemediumMEDIUM

Ipregistry is a technology company specializing in IP address data services, including geolocation and threat intelligence. Established in 2019 and based in France, it serves over 23,000 organizations globally, offering scalable API solutions for IP data enrichment, fraud prevention, and cybersecurity. The company positions itself as a reliable and accurate provider in the IP data market, supported by a strong customer base and professional branding. Technically, Ipregistry leverages modern web technologies, Cloudflare CDN for hosting and security, and provides a fast, mobile-optimized user experience. The website integrates JSON-LD structured data, uses Crisp chat for customer engagement, and employs Cloudflare analytics for performance monitoring. The technical infrastructure reflects a mature and well-maintained digital presence. From a security perspective, the site enforces HTTPS, uses Cloudflare protections, and implements secure input validation. However, DNSSEC is not enabled, and explicit security policies or incident response contacts are not published. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with clear policies and cookie consent mechanisms. Overall, Ipregistry presents a low-risk profile with a professional, trustworthy online presence. Strategic recommendations include enabling DNSSEC, publishing a security policy and incident response contacts, and adding a security.txt file to enhance vulnerability disclosure transparency.

55
95
2
87
75
85
100
ipregistryipaddressgeolocationthreatintelligenceapi+4 more
JavaScriptJSON-LDCloudflare CDNAnycast routing+1
2025-07-27T00:58:13.054Z
J

John Selbie

stunprotocol.org

0
TechnologyFrancesmallHIGH

The website stunprotocol.org represents an open source project named STUNTMAN, which provides a STUN server implementation for NAT traversal and WebRTC applications. The project is authored by John Selbie and has been active since 2012. It offers downloadable binaries and source code for multiple platforms including Unix/Linux, MacOS, and Windows (via Cygwin). The site targets developers and organizations requiring STUN server software and related client libraries. The business model is based on open source distribution under the Apache 2.0 license, positioning itself as a niche technology provider in the networking software space. Technically, the website uses a combination of C++ for the server software and React 17 with JavaScript for the frontend interface. Hosting appears to be on Amazon AWS infrastructure, inferred from DNS nameservers. The site includes Google Analytics for traffic monitoring but lacks cookie consent mechanisms. Mobile optimization and accessibility are basic but functional. The site design is simple and consistent, focusing on content delivery rather than advanced UI/UX features. From a security perspective, the domain is registered since 2012 with consistent WHOIS data and no privacy protection, indicating transparency. However, the site lacks DNSSEC, security headers, and explicit HTTPS enforcement details, which are areas for improvement. No privacy or cookie policies are present, which impacts compliance with GDPR and other privacy regulations. The use of Google Analytics without consent mechanisms further reduces privacy compliance. No incident response or vulnerability disclosure policies are found. Overall, the website is a legitimate, small-scale open source project site with good business credibility and moderate technical implementation. Security posture and privacy compliance require enhancements to meet modern standards. Strategic recommendations include adding privacy and cookie policies, enabling DNSSEC, implementing security headers, and improving consent mechanisms to enhance trust and compliance.

15
35
2
60
62
70
-
stunopensourcewebrtcnattraversalnetworking+2 more
C++React 17JavaScriptGoogle Analytics+1
2025-07-26T23:49:43.720Z