Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 8 of 29|Showing 351-400 of 1422
lumalabs.ai favicon

Luma AI

lumalabs.ai

0
TechnologyIcelandsmallMEDIUM

Luma AI is a technology startup founded in 2021 specializing in AI-driven video generation and animation tools. Their flagship products include Ray2, a large-scale video generative model, and Dream Machine, a platform enabling creators to generate and modify videos using AI. The company targets creators, developers, and enterprises seeking next-generation storytelling tools leveraging AI. Their market position is that of an innovative provider with proprietary AI models and a growing presence in the AI creative tools space. Technically, the website is built on a modern stack including Next.js and React, hosted on Vercel, and integrates multiple analytics and marketing tools such as HubSpot, Google Tag Manager, Apollo.io, and social media pixels. The site is fast, mobile-optimized, and SEO-friendly, reflecting a mature digital infrastructure for a startup. From a security perspective, the site enforces HTTPS, employs standard security headers, and uses domain privacy protection. However, it lacks publicly available security policies, incident response contacts, and vulnerability disclosure mechanisms. No critical vulnerabilities or exposures were detected. Privacy compliance is strong with clear privacy and cookie policies and consent mechanisms. Overall, Luma AI presents a professional and trustworthy online presence with strong technical and privacy practices. The absence of direct contact information and security policy details are minor gaps. Strategic recommendations include enabling DNSSEC, publishing security and incident response policies, and adding vulnerability disclosure information to enhance trust and security posture.

50
68
17
75
72
75
100
aivideogenerationtechnologymachinelearningcreativetools
Next.jsReactVercel AnalyticsHubSpot Analytics+4
2025-07-26T11:10:36.852Z
toyota.is favicon

Toyota Ísland

toyota.is

0
TransportationIcelandmediumMEDIUM

Toyota Ísland operates as the official representative and dealership for Toyota vehicles in Iceland, offering new and used cars, spare parts, and accessories. The website serves as a comprehensive portal for Icelandic customers to explore Toyota's vehicle lineup and locate dealers across multiple Icelandic cities. The company maintains a strong brand presence consistent with Toyota's global identity, supported by localized content and social media engagement. Technically, the website leverages modern analytics, tag management, and customer engagement tools such as Google Tag Manager, Datadog RUM, Adobe Launch, and Crisp Chat, indicating a mature digital infrastructure. The site is built on Adobe Experience Manager, a robust enterprise CMS platform, ensuring scalability and content management efficiency. Security posture is solid with HTTPS enforcement, use of CAPTCHA services, and cookie consent mechanisms, although explicit security policies and incident response contacts are not publicly disclosed. Overall, the site reflects a professional and trustworthy digital presence aligned with corporate standards. The absence of WHOIS data is noted but likely due to Icelandic registry policies rather than malicious intent. Strategic recommendations include enhancing security headers, publishing security policies, and improving transparency around incident response.

80
65
17
85
52
85
100
automotivetoyotaicelandcarsaleshybrid+2 more
Google Tag ManagerDatadog RUMAdobe LaunchCrisp Chat+3

Partner Domains:

toyota-europe.com
partner
toyota-fs.com
partner

+1 more partners

2025-07-25T22:09:49.991Z
A

Automatio

automatio.ai

0
TechnologyIcelandsmallMEDIUM

Automatio is a technology startup founded in 2023, offering a no-code web scraping and browser automation platform targeted at non-technical users and businesses seeking efficient data extraction solutions. The company positions itself as a leading no-code automation tool with cloud-based bot management and a Chrome extension to simplify bot creation. The website is professionally designed, mobile-optimized, and provides clear navigation and relevant content to its target audience. Technically, the site leverages modern web technologies including Webflow CMS, Google Fonts, jQuery, and integrates marketing and analytics tools such as Mailchimp and Google Tag Manager. Hosting and DNS services are managed via Cloudflare, ensuring good performance and security. The website implements HTTPS and cookie consent mechanisms, though it lacks some advanced security headers and published security policies. From a security perspective, the site demonstrates a moderate security posture with HTTPS enforced and clientTransferProhibited domain status. However, it lacks explicit security policies, incident response contacts, and vulnerability disclosure mechanisms. The WHOIS data is privacy protected but consistent with a legitimate startup profile. No critical vulnerabilities or suspicious indicators were found. Overall, Automatio presents a trustworthy and professional online presence with good technical maturity and privacy compliance. Strategic improvements in security headers, incident response transparency, and DNSSEC implementation would enhance its security posture and trustworthiness further.

25
68
2
70
75
70
100
webscrapingautomationno-codebotbuilderdataextraction+2 more
Webflow CMSGoogle FontsjQuery 3.5.1CookieConsent.js+3
2025-07-23T11:01:40.546Z
lockdown.systems favicon

Lockdown Systems

lockdown.systems

0
TechnologyIcelandsmallMEDIUM

Lockdown Systems is a worker-owned collective focused on developing privacy and freedom-enhancing technologies. Their key offerings include open-source tools such as Cyd, OnionShare, and ICE Detention Map, alongside privacy and security consulting services. The organization targets individuals and organizations committed to protecting data privacy, including activists, journalists, and non-profits. Their business model balances commercial sustainability with mission-driven impact, emphasizing transparency and community empowerment. Technically, the website is built with modern web standards, hosted on DigitalOcean, and employs minimal tracking scripts focused on privacy. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a good level of digital maturity. However, some security best practices such as DNSSEC and security headers are not implemented, and no cookie consent mechanism is present despite privacy claims. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. The lack of published security policies, incident response contacts, and vulnerability disclosure mechanisms suggests room for improvement in security transparency and readiness. The domain registration uses privacy protection services, which aligns with the organization's privacy focus and does not raise legitimacy concerns. Overall, Lockdown Systems presents a trustworthy and professional online presence with a strong mission and solid technical foundation. Strategic enhancements in security policies, compliance mechanisms, and DNS security would further strengthen their posture and trustworthiness.

15
53
47
70
72
55
100
privacysecurityopen-sourceconsultingtechnology+2 more
HTML5CSSJavaScript
2025-07-22T23:37:10.278Z
V

VANTA COOL CLOTHING

vanta.cool

0
RetailIcelandsmallMEDIUM

VANTA COOL CLOTHING is a small retail clothing brand with an online presence primarily serving a general audience interested in unique clothing and art commissions. The business operates via an external e-commerce platform (artisans.coop) and offers direct commissions through email contact. The website is simple and visually styled with rainbow-themed animations and responsive design for mobile and desktop users. Technical infrastructure is basic, relying on standard HTML, CSS, and JavaScript without advanced frameworks or CMS detected. Hosting and domain registration are managed through NameCheap with privacy protection enabled, consistent with a new small business setup. From a security perspective, the website uses HTTPS but lacks DNSSEC and security headers, which are recommended to enhance protection. No privacy or cookie policies are present, indicating a gap in compliance with data protection regulations such as GDPR. The site does not collect user data via forms on the main page, limiting exposure but also limiting engagement features. No analytics or tracking scripts were detected, suggesting minimal user tracking. Overall, the website presents a low-risk profile with no adult or explicit content, but it would benefit from improved security practices and privacy compliance to build trust and meet regulatory standards. The domain is very new but appears legitimate with no suspicious WHOIS patterns. Strategic improvements in security headers, policy disclosures, and possibly adding analytics with privacy transparency would enhance the site's professionalism and compliance.

40
50
2
70
95
55
100
retailclothinge-commerceartcommissionssmallbusiness
HTML5CSS3JavaScript

Partner Domains:

artisans.coop
partner
vantaa.black
related
2025-07-22T15:35:07.805Z
kde.social favicon

Privacy service provided by Withheld for Privacy ehf

kde.social

0
TechnologyIcelandsmallMEDIUM

kde.social is an independent Mastodon server instance launched in 2023, providing a decentralized social networking platform focused on privacy, ethical design, and user data ownership. It operates within the Mastodon fediverse, targeting users who seek an ad-free and surveillance-free social media experience. The platform currently has a small user base and offers standard Mastodon features such as timelines and trending posts, although the explore page currently shows no trending content. Technically, the website is built on Mastodon version 4.4.1 using modern web technologies including React and ES modules. The site is moderately optimized for mobile devices and provides basic accessibility features. Hosting details are not explicit, but the domain uses HTTPS with a good SSL configuration. However, DNSSEC is not enabled, and no security headers are present in the HTML, indicating room for improvement in security hardening. From a security perspective, the site enforces HTTPS and has domain transfer protections but lacks advanced DNS security and HTTP security headers. There is no visible security policy, incident response contact, or vulnerability disclosure information. Privacy compliance is limited; a basic privacy policy exists but no cookie consent mechanism or terms of service are found. No contact information such as emails or phone numbers is provided, which may impact user trust and support. Overall, kde.social presents as a legitimate, privacy-focused Mastodon instance with a small but niche user base. The site is functional and uses modern technologies but would benefit from enhanced security practices, improved privacy compliance, and clearer business contact information to increase trust and compliance with regulations.

75
58
17
70
52
70
100
mastodonsocialnetworkdecentralizedfediverseprivacy
Mastodon 4.4.1ReactJavaScript ES ModulesCSS+1
2025-07-22T12:09:51.933Z
plasma-mobile.org favicon

KDE e.V.

plasma-mobile.org

0
TechnologyIcelandmediumMEDIUM

Plasma Mobile is an open-source mobile user interface project developed by the KDE community, aiming to provide a privacy-respecting, secure, and flexible phone ecosystem based on Linux technologies. The project is community-driven, supported by donations and patrons including major technology companies, positioning itself as a niche alternative to mainstream mobile operating systems. The website reflects a mature and professional presence with excellent content quality and user experience, targeting open source enthusiasts and privacy-conscious users. Technically, the site is built using the Hugo static site generator, leveraging modern web technologies such as Bootstrap for responsive design. The project integrates established Linux components like KWin, Wayland, ModemManager, and PulseAudio/PipeWire, demonstrating a solid technical foundation. Hosting and DNS services are stable, though DNSSEC is not enabled, which is a minor security gap. From a security perspective, the website enforces HTTPS and uses domain transfer protection, but lacks DNSSEC and explicit security headers. No security policy or incident response information is published, which could be improved to enhance trust and compliance. Privacy compliance is strong with a comprehensive privacy policy linked to the KDE main site, but no cookie consent mechanism is present. Overall, the website and project exhibit high professionalism and trustworthiness with minimal security concerns. Strategic recommendations include enabling DNSSEC, adding security headers, publishing a security policy, and implementing cookie consent to improve compliance and security posture.

75
53
2
60
72
70
40
opensourcemobilelinuxprivacycommunity+2 more
Hugo static site generatorBootstrap CSSWaylandKWin+3

Partner Domains:

kde.org
partner
invent.kde.org
partner
2025-07-22T12:09:36.884Z
kde.org favicon

KDE e.V.

kde.org

0
TechnologyIcelandmediumMEDIUM

KDE e.V. operates the kde.org website as the central hub for the KDE community, a globally recognized open source software organization focused on developing the KDE Plasma desktop environment and a wide range of applications. The organization is a non-profit entity with a long history dating back to 1996, serving a diverse audience of Linux users, developers, and digital privacy advocates. The website effectively communicates the community's mission, products, and opportunities for involvement and donations. Technically, the site is built using the Hugo static site generator, leveraging modern web technologies such as Bootstrap for responsive design and Matomo for privacy-conscious analytics. The site is well-optimized for performance, mobile devices, and accessibility, with comprehensive multilingual support. Security is robust with HTTPS enforced, secure donation forms, and no visible vulnerabilities, although some HTTP security headers could be enhanced. From a security and compliance perspective, the site includes clear privacy and cookie policies aligned with GDPR, but lacks a dedicated security policy or incident response information. The domain registration is privacy-protected but consistent with the organization's non-profit nature and long-standing presence. No suspicious or malicious indicators were found. Overall, kde.org is a professional, trustworthy, and well-maintained website that effectively supports the KDE community's goals. Strategic improvements could include publishing explicit security policies, incident response contacts, and implementing a cookie consent mechanism to further enhance compliance and user trust.

90
53
17
85
100
55
40
opensourcelinuxcommunitysoftwaretechnology+1 more
Hugo static site generatorBootstrap CSS frameworkMatomo analyticsJavaScript+2
2025-07-22T11:03:16.448Z
xoxo.zone favicon

XOXO Zone

xoxo.zone

0
TechnologyIcelandsmallMEDIUM

XOXO Zone operates as a community-run Mastodon instance primarily serving attendees and speakers of the XOXO Festival, a cultural event held in Portland, Oregon. The platform facilitates social networking within the fediverse, leveraging the open-source Mastodon software. The website presents a niche social media service with a focused target audience, maintaining a small but active user base. The business model centers on community engagement rather than commercial monetization. Technically, the website is built on Mastodon version 4.4.1, utilizing React and modern JavaScript modules, hosted on DigitalOcean infrastructure with CDN support for media assets. The site demonstrates moderate performance and good mobile optimization, though accessibility and SEO optimizations are basic. The technical stack is modern and appropriate for a social networking platform of this scale. From a security perspective, the site enforces HTTPS and uses domain transfer protection, but lacks DNSSEC and several recommended security headers. No exposed sensitive data or vulnerable libraries were detected. Privacy compliance is partial, with a privacy policy present but no cookie consent mechanism or terms of service published. Contact information is limited to Mastodon user profiles and sign-in forms, with no direct company emails or phone numbers. Overall, XOXO Zone is a trustworthy and professionally maintained community platform with a clear niche focus. Security posture is adequate but could be improved with enhanced policies and technical controls. Privacy compliance requires attention to meet GDPR standards fully. Strategic recommendations include enabling DNSSEC, publishing terms of service, implementing cookie consent, and enhancing security headers to strengthen trust and compliance.

80
58
17
60
72
70
100
mastodonsocialnetworkcommunityxoxofestivalfediverse
Mastodon 4.4.1ReactJavaScript ES ModulesDigitalOcean Spaces CDN+1
2025-07-22T06:26:53.662Z
W

Webmention Rocks!

webmention.rocks

0
TechnologyIcelandsmallHIGH

Webmention Rocks! is a niche technical website providing a validator and test suite for the Webmention protocol, primarily targeting developers and implementers within the IndieWeb and web standards communities. The site offers a variety of tests for endpoint discovery, updates, deletes, and receiver functionality, and encourages users to submit implementation reports to the W3C. It is open source and hosted on Linode, with a domain registered in 2016 and privacy protection enabled. From a technical perspective, the website uses a classic web stack including jQuery 1.11.3 and Semantic UI for styling and interactivity. The site is moderately performant, mobile optimized, and has a clear navigation structure. However, accessibility and SEO optimizations are basic. No CMS is detected, indicating a custom or static site. Security posture is moderate; the domain uses clientTransferProhibited status to prevent unauthorized transfers but lacks DNSSEC and visible security headers. No privacy or cookie policies are present, and no contact information is provided for security incidents or general inquiries. There are no signs of vulnerabilities or malicious content, and the site content is safe for general audiences. Overall, the website is a credible and useful tool within its niche but would benefit from improved security practices, privacy compliance, and contact transparency to enhance trust and compliance.

15
50
2
60
42
70
40
webmentionvalidatoropensourcewebstandardsdevelopertool
jQuery 1.11.3Semantic UIHTML5CSS3+1
2025-07-22T06:25:53.204Z
Z

Z K N T

zknt.org

0
OtherIcelandsmallMEDIUM

The website zknt.org presents minimal publicly accessible content, primarily a password input form accompanied by ASCII art and a cryptic phrase. There is no visible business description, contact information, or policy documentation, which limits the ability to assess the organization's market position or services. The domain is registered through NameCheap with privacy protection enabled, dating back to 2013, indicating a potentially long-standing but private or restricted-access entity. From a technical perspective, the website lacks modern web technologies, metadata, and optimization features. There are no detected analytics, tracking, or advertising technologies, and no security headers or DNSSEC are enabled. The site appears to be a simple static page with minimal styling and no CMS or frameworks detected. Mobile optimization and accessibility are poor due to the simplistic and minimal design. Security posture is weak due to the absence of security headers and DNSSEC, although the domain uses HTTPS (assumed but not confirmed) and is registered with a reputable registrar. No vulnerabilities or exposed sensitive data were detected, but the lack of policies and contact information reduces transparency and trust. The site does not provide GDPR or privacy compliance indicators. Overall, the website represents a low-content, low-transparency presence with limited business credibility and poor user experience. Strategic recommendations include enhancing transparency with privacy and cookie policies, improving security configurations, and providing clear contact and business information to build trust and compliance.

15
50
2
70
72
70
100
minimalpassword-protectedprivacy-protectedascii-artno-contact-info
2025-07-15T01:35:44.383Z
stjornarradid.is favicon

Stjórnarráð Íslands

stjornarradid.is

0
GovernmentIcelandlargeMEDIUM

Stjórnarráðið is the official website of the Icelandic government, providing comprehensive information about ministries, government projects, news, and public services. The site serves Icelandic citizens, government officials, and media by offering authoritative content and official communication channels. The website is well-branded with consistent government logos and symbols, reinforcing its official status. Technically, the site uses a custom CMS with ASP.NET backend, leveraging common web technologies such as jQuery, Bootstrap, and lazy loading for images. It integrates accessibility tools like ReadSpeaker and analytics via Siteimprove. The site is mobile-optimized and features a clear navigation structure, ensuring a good user experience. From a security perspective, the site enforces HTTPS and includes CAPTCHA on its contact form to prevent spam. Cookie consent is managed via CookieHub, indicating compliance with privacy regulations. However, explicit security policies and incident response contacts are not found, suggesting room for improvement in transparency and security governance. Overall, the website is trustworthy, professionally maintained, and serves as a critical information hub for Iceland's government. Strategic enhancements in security policy publication and vulnerability disclosure would further strengthen its security posture.

40
50
17
70
75
85
100
governmenticelandministriespublicservicesofficial+2 more
jQuery 3.1.1Bootstrap v3.3.1LazySizes (lazy loading images)ReadSpeaker (text-to-speech)+4
2025-07-14T02:37:33.787Z
ajdg.net favicon

AJdG Solutions

ajdg.net

0
TechnologyIcelandsmallMEDIUM

AJdG Solutions is a small technology company specializing in the development and sale of WordPress and ClassicPress plugins, with a strong focus on advertising management and WooCommerce enhancements. Their flagship product, AdRotate Banner Manager, is trusted by over 50,000 users, positioning the company as a niche leader in the WordPress plugin market. The business model centers on software license sales and support services, targeting website owners and developers seeking to optimize advertising revenue and e-commerce functionality. Technically, the website is built on WordPress using the Storefront theme and WooCommerce platform, hosted by InMotion Hosting. The site employs modern web technologies including jQuery and JavaScript, and demonstrates good mobile optimization and SEO practices. Analytics are handled via Matomo, reflecting a privacy-conscious approach. Performance is moderate, with opportunities for improvement in accessibility and security headers. From a security perspective, the site enforces HTTPS and uses domain transfer protection, but lacks DNSSEC and security headers such as CSP or HSTS. No explicit security policy or incident response information is provided, and there is no cookie consent mechanism despite cookie usage. The domain registration is privacy protected but consistent with the business location and history, supporting legitimacy. Overall, the security posture is solid but could be enhanced with additional best practices. The overall risk assessment is low, with no critical vulnerabilities detected. Strategic recommendations include enabling DNSSEC, implementing security headers, adding a cookie consent banner, and publishing a security policy with incident response contacts. These improvements would strengthen compliance, user trust, and resilience against potential threats.

15
58
2
80
62
80
100
wordpressclassicpresswoocommercepluginsadvertising+1 more
WordPressWooCommercejQueryPHP+2

Partner Domains:

support.ajdg.net
service
stats.ajdg.net
service
2025-07-13T23:18:02.090Z
P

Privacy service provided by Withheld for Privacy ehf

collata.site

0
EducationIcelandsmallMEDIUM

Collata.site is a specialized website builder and content management system tailored specifically for public libraries. The platform offers a comprehensive suite of tools including event and space reservation systems, book lists, blogs, accessibility features, and digital signage. The business targets small to medium-sized public libraries, providing both a hosted SaaS edition and an open-source community edition, positioning itself as a niche player in the education technology sector. The website content is professionally designed, consistent in branding, and rich in relevant information, supported by client logos from various public libraries, which enhances trust and credibility. Technically, the website employs modern web technologies such as HTML5, CSS3, JavaScript, Google Fonts, and Font Awesome. It integrates Google Translate for multilingual support and uses legacy Google Analytics for tracking. The site appears mobile-optimized and accessible, with features supporting WCAG compliance. However, there is no evidence of advanced security headers or DNSSEC, and the domain uses privacy protection services, which is common for small tech companies. From a security perspective, the site uses HTTPS and has a clientTransferProhibited domain status, but lacks visible security headers like CSP or HSTS. The use of legacy analytics scripts and absence of privacy and cookie policies indicate gaps in privacy compliance. No incident response or vulnerability disclosure information is present. Overall, the security posture is moderate but could be improved with better headers, updated analytics, and explicit privacy documentation. The overall risk assessment suggests a legitimate, niche-focused business with good technical and content quality but with room for improvement in privacy compliance and security best practices. Strategic recommendations include implementing comprehensive privacy and cookie policies, enabling DNSSEC, adding security headers, updating analytics tools, and providing clear incident response contacts to enhance trust and compliance.

20
35
17
70
72
70
100
cmspubliclibrariesaccessibilityeventmanagementdigitalbranch+1 more
HTML5CSS3JavaScriptGoogle Fonts+4
2025-07-13T22:07:32.167Z