Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 102 of 579|Showing 5051-5100 of 28928
worldinvestorweek.org favicon

International Organization of Securities Commissions (IOSCO)

worldinvestorweek.org

0
FinanceN/amediumMEDIUM

World Investor Week (WIW) is a globally recognized campaign promoted by the International Organization of Securities Commissions (IOSCO) to enhance investor education and protection worldwide. The website serves as a central hub for information on events, initiatives, and resources related to investor awareness, targeting regulators, investors, and financial education stakeholders. The platform is well-branded, consistent, and supported by numerous reputable global organizations, reflecting a strong market position in the finance and non-profit sectors. Technically, the website employs modern web technologies including Bootstrap, jQuery, Chart.js, and amCharts for interactive and responsive design. It integrates Google Analytics for user tracking and uses secure HTTPS connections. The site is mobile-optimized and accessible, with good SEO practices evident in meta tags and structured content. However, some improvements could be made in security headers and privacy compliance disclosures. From a security perspective, the site shows a solid baseline with HTTPS and no visible vulnerabilities or exposed sensitive data. The absence of explicit privacy and cookie policies, as well as contact information for security incidents, represents compliance gaps. The lack of WHOIS data limits full trust assessment but the professional presentation and affiliations mitigate concerns. Overall, the security posture is good but could be enhanced with additional transparency and policies. The overall risk is moderate to low given the site's reputable backing and content quality. Strategic recommendations include publishing comprehensive privacy and cookie policies, implementing security headers, providing clear contact channels for incident response, and adding a vulnerability disclosure policy. These steps will strengthen compliance, user trust, and security maturity.

60
35
2
60
82
70
100
worldinvestorweekioscoinvestoreducationfinancialliteracysecuritiesregulators+1 more
Bootstrap 5.3.3jQuery 3.7.1Chart.js 4.4.3amCharts 5+2
2025-10-15T16:58:07.630Z
wowza.com favicon

Wowza

wowza.com

0
TechnologyN/amediumMEDIUM

Wowza is a well-established technology company specializing in video streaming platforms, offering cloud, private cloud, and hybrid streaming solutions. Their platform supports live and on-demand video streaming with integrated content management, analytics, and CDN services. The company targets developers, broadcasters, publishers, and enterprises requiring scalable and reliable streaming infrastructure. The website reflects a mature digital presence with comprehensive resources, developer documentation, and community engagement. Technically, the website is built on WordPress with a modern tech stack including multiple analytics and tracking tools such as PostHog, HubSpot, Google Tag Manager, and LinkedIn Insight. The site is mobile-optimized and demonstrates good SEO and accessibility practices, though accessibility could be further improved. Performance is moderate, with room for optimization. Security posture is strong with HTTPS enforced, appropriate security headers, and no visible vulnerabilities or exposed sensitive data. However, the absence of a public security policy, incident response contacts, and vulnerability disclosure mechanisms suggests areas for enhancement in transparency and readiness. Overall, the website and business appear legitimate and professional, though the lack of publicly available WHOIS data introduces some uncertainty. Strategic recommendations include publishing security policies, enhancing accessibility, and formalizing vulnerability disclosure to strengthen trust and compliance.

15
65
17
65
-
85
100
videostreaminglivestreamingvodcloudstreamingmediaserver+3 more
JavaScriptPostHog analyticsGoogle Tag ManagerLinkedIn Insight Tag+3

Partner Domains:

developer.wowza.com
service
community.wowza.com
service

+3 more partners

2025-10-15T16:57:37.561Z
getgrav.org favicon

Trilby Media

getgrav.org

0
TechnologyN/asmallMEDIUM

Grav is an open source flat-file CMS developed and maintained by Trilby Media, a small technology company founded in 2014. The platform targets developers and businesses seeking a fast, flexible, and easy-to-use CMS without the complexity of databases. Grav has a strong market position in the niche flat-file CMS segment, supported by multiple industry awards and a vibrant community on GitHub, forums, and Discord. The business model combines free open source software with professional consulting services and premium add-ons. Technically, the website is well-built using modern JavaScript libraries such as jQuery, Owl Carousel, and Google reCAPTCHA v3 for form security. The site is hosted behind Cloudflare DNS and uses HTTPS with good SSL configuration. The CMS itself uses Twig templating and a flat-file architecture, contributing to fast performance and excellent mobile optimization. SEO and accessibility features are well implemented. From a security perspective, the site enforces HTTPS and uses reCAPTCHA to protect forms. However, it lacks important security headers and does not publish a security policy or incident response contacts. DNSSEC is not enabled, which is a recommended improvement. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is limited due to the absence of privacy and cookie policies, which may pose regulatory risks. Overall, Grav.org is a professional, trustworthy, and technically mature website with strong business credibility. The main risks relate to privacy compliance and some security best practices. Strategic improvements in these areas would enhance trust and regulatory adherence.

95
35
25
75
65
80
100
flat-filecmsopensourcetechnologydeveloper+2 more
jQueryOwl CarouselGoogle reCAPTCHA v3Gumroad JS+2

Partner Domains:

trilby.media
partner
2025-10-15T16:57:32.553Z
S

slurpslimes.org

slurpslimes.org

0
OtherN/asmallMEDIUM

The website slurpslimes.org is currently a newly registered domain with no accessible content or metadata. The site contains an empty HTML body with no visible text, forms, scripts, or external links. The domain is registered with Dynadot Inc and hosted on Amazon AWS DNS infrastructure. There are no privacy, cookie, or terms of service policies present, nor any contact or security-related information. This indicates the website is either under development or abandoned. From a technical perspective, the site lacks any detectable technology stack, frameworks, or CMS. The absence of security headers and DNSSEC reduces the overall security posture. The SSL configuration is basic but HTTPS presence is assumed due to DNS and domain status. No analytics or tracking technologies are detected, and no advertising or marketing tools are present. Security posture is minimal with no evident vulnerabilities but also no advanced protections. The domain registration is consistent with a new entity but lacks trust signals such as business information or certifications. The overall risk is low due to lack of content but the site is not currently providing any business or user value. Strategic recommendations include adding comprehensive privacy and cookie policies, implementing security best practices such as DNSSEC and security headers, publishing contact and incident response information, and developing meaningful website content to improve trust and credibility.

20
40
17
60
72
70
100
2025-10-15T14:39:47.247Z
E

Elfsight

elf.site

0
TechnologyN/amediumMEDIUM

Elfsight is a well-established technology company founded in 2012 that specializes in providing a wide range of website widgets designed to help businesses grow online by increasing sales, engaging visitors, and collecting leads. The company serves a broad audience of website owners and businesses seeking to enhance their web presence through social media feeds, reviews, chats, video, audio, and other interactive tools. Their market position is strong, supported by a large user base and a comprehensive widget portfolio. Technically, the website is built on WordPress with modern performance optimizations including WP Rocket and Cloudflare DNS, and integrates multiple analytics and marketing tools such as Google Tag Manager, Facebook Pixel, Microsoft Clarity, and LinkedIn Insight Tag. The site demonstrates excellent design quality, mobile optimization, and SEO practices, contributing to a positive user experience and high trustworthiness. Security-wise, the site uses HTTPS with good SSL configuration and domain registration practices, though it lacks explicit security policies, vulnerability disclosures, and some security headers. Overall, the website is secure, professional, and compliant with privacy regulations, but could improve transparency around security and incident response. The domain WHOIS data is consistent with the business claims, showing a mature and legitimate online presence.

35
95
17
82
75
85
100
websitewidgetsbusinessgrowthsocialmediareviewsvideo+4 more
WordPressWP RocketCloudflare DNSGoogle Tag Manager+4

Partner Domains:

dash.elfsight.com
service
help.elfsight.com
service

+1 more partners

2025-10-15T13:30:28.375Z
levelpath.com favicon

Levelpath

levelpath.com

0
TechnologyN/amediumMEDIUM

Levelpath is a technology company offering an AI-native procurement platform designed to simplify and enhance procurement processes for enterprises. The company positions itself as a leader in AI-driven procurement solutions, recognized by Gartner as a Cool Vendor in sourcing and procurement technology. Their platform includes modules such as Front Door to Procure, Sourcing, Pipeline, Contracts, and Risk Management, targeting enterprise customers seeking efficiency and innovation in procurement. Technically, the website is built using modern frameworks like Next.js and React, hosted likely behind Cloudflare, and integrates multiple marketing and analytics tools including HubSpot, Google Tag Manager, and Microsoft Clarity. The site is well optimized for performance, mobile responsiveness, and SEO, providing an excellent user experience. From a security perspective, the site enforces HTTPS and implements a comprehensive cookie consent mechanism with detailed categories. However, it lacks visible security headers and published security policies or incident response information. The absence of WHOIS registration data raises some concerns about domain legitimacy, though the professional web presence and business signals mitigate this risk. Overall, Levelpath presents a strong digital and business profile with room for improvement in transparency around privacy policies, security disclosures, and domain registration information. Strategic recommendations include publishing explicit privacy and security policies, enhancing security headers, and verifying domain registration details to strengthen trust and compliance.

20
83
17
75
52
65
100
aiprocurementtechnologysaasenterprise+4 more
Next.jsReactVimeo PlayerHubSpot+4
2025-10-15T12:26:19.119Z
onwebchat.com favicon

onWebChat

onwebchat.com

0
TechnologyN/asmallMEDIUM

onWebChat is a technology company specializing in AI-powered live chat and chatbot software designed to enhance customer support and boost sales for businesses. The company offers a SaaS model with free and paid subscription plans, including a Pro AI plan with advanced features. Their platform supports multiple integrations with popular CMS and e-commerce systems and provides native mobile applications for Android and iOS, indicating a mature and versatile product offering. The website is professionally designed, mobile-optimized, and rich in relevant content, targeting businesses seeking to improve customer engagement through AI-driven chat solutions. Technically, the site uses modern web technologies including jQuery, Socket.IO, Bootstrap, and Google Tag Manager, ensuring a responsive and interactive user experience. Security-wise, the site enforces HTTPS with a reputable SSL certificate and implements cookie consent mechanisms, but lacks visible security headers and explicit incident response policies. The absence of WHOIS registration data reduces transparency but does not significantly detract from the site's legitimacy given the professional presentation and trust indicators such as user testimonials and social media presence. Overall, onWebChat demonstrates a solid digital maturity with room for improvement in security policy transparency and WHOIS data availability.

35
80
17
70
72
80
100
livechataichatbotcustomersupportbusinesssoftwaresaas+2 more
jQuery 2.2.4Socket.IO 4.5.4Google Tag ManagerBootstrap+4
2025-10-15T12:26:16.937Z
altcha.org favicon

ALTCHA

altcha.org

0
TechnologyN/asmallMEDIUM

ALTCHA is a technology company specializing in next-generation Captcha and bot protection solutions designed with privacy, accessibility, and compliance in mind. The company offers a SaaS platform and self-hosted options that provide adaptive, frictionless Captcha alternatives compliant with GDPR, CCPA, HIPAA, and other global data protection laws. Their solutions target website owners, app developers, enterprises, and government organizations seeking robust bot and spam protection without compromising user experience or privacy. ALTCHA is positioned as a privacy-first alternative to traditional Captcha providers like reCAPTCHA and hCaptcha, with a strong emphasis on accessibility and multilingual support. Technically, ALTCHA leverages modern web technologies including JavaScript, TypeScript, and the Astro framework, with a modular UI built on Starlight components. The platform supports multiple front-end frameworks and offers extensive integration options including WordPress plugins and server libraries in various programming languages. Performance is optimized with a small bundle size and fast load times, and the platform is designed for mobile responsiveness and accessibility compliance (WCAG 2.2 AA, European Accessibility Act 2025). From a security perspective, ALTCHA enforces HTTPS and employs multi-layered bot detection techniques including threat intelligence, device validation, input data analysis, and rate limiting. However, DNSSEC is not enabled for the domain, and no explicit security headers or incident response policies are published on the site. Privacy compliance is strong, with comprehensive documentation on GDPR and other regulations, though no cookie consent mechanism was detected. The domain registration is transparent and consistent with the business profile, though the domain is relatively new, matching the company's recent founding in 2023. Overall, ALTCHA presents a professional, trustworthy, and technically mature platform with a strong focus on privacy and compliance. Strategic recommendations include enabling DNSSEC, publishing security policies and incident response contacts, implementing cookie consent mechanisms, and adding security headers to enhance the security posture further.

70
65
17
67
95
75
40
captchabotprotectionprivacygdprantispam+3 more
JavaScriptTypeScriptAstro frameworkStarlight UI components+1
2025-10-15T12:23:04.966Z
jsonformatter.org favicon

JSON Formatter

jsonformatter.org

0
TechnologyN/asmallMEDIUM

JSON Formatter is a specialized online tool providing JSON formatting, validation, and conversion services primarily targeted at developers and data professionals. The website offers a suite of utilities including JSON to XML, CSV, and YAML converters, along with editing and viewing capabilities. It operates on a free, ad-supported model and has been active since 2015, indicating a mature presence in its niche market. The platform is designed for ease of use with features like file upload, online saving, and sharing of JSON data, catering to a technical audience requiring quick and reliable JSON manipulation tools. Technically, the site employs a modern web stack including jQuery, Bootstrap 3, Ace Editor, and Font Awesome, hosted and registered via Cloudflare. It uses HTTPS with a good SSL configuration but lacks DNSSEC. The site is moderately optimized for performance and mobile use, with basic accessibility and good SEO practices. Advertising and tracking are present through FreeStar, Google Tag Manager, and Quantcast, reflecting a moderate level of user tracking. From a security perspective, the site enforces HTTPS and has domain transfer protections but lacks explicit security policies, incident response contacts, and advanced DNS security features. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is basic, with a privacy policy present but no explicit cookie policy or GDPR compliance indicators. Contact information is limited to a web form, with no direct emails or phone numbers provided. Overall, JSON Formatter presents a low-risk profile with a solid technical foundation and clear business purpose. Strategic improvements in security transparency, privacy compliance, and contact information could enhance trust and compliance posture.

25
70
2
65
75
80
100
jsonformattervalidatoronlinetooldeveloper+3 more
jQueryBootstrap 3Ace EditorFont Awesome+2
2025-10-15T12:22:49.936Z
curl.to favicon

curl.to | Convert curl commands to code

curl.to

0
TechnologyN/asmallMEDIUM

curl.to is a specialized developer tool website that provides an online utility for converting curl commands into code snippets in multiple programming languages. It targets developers working with APIs and web services, offering support for languages such as JavaScript, Python, PHP, Go, Ruby, C#, and Java. The site positions itself as a free resource to improve developer productivity by reducing errors and saving time during API development. Technically, the website is built using modern web technologies including React and Next.js, with Google Fonts for typography. The site appears to be moderately optimized for performance and mobile responsiveness, with a clean and professional design. However, accessibility features are basic, and no CMS or hosting provider information is evident from the HTML content. From a security perspective, the site uses HTTPS as indicated by the URL, but no explicit security headers are detected in the HTML content. There are no visible privacy, cookie, or terms of service policies, nor any contact information for security incidents or data protection officers. No analytics or advertising scripts were found, indicating minimal user tracking. The absence of these policies and contact details suggests room for improvement in privacy compliance and security transparency. Overall, the website is safe and professional with a clear focus on developer utility. The lack of privacy and security policies, as well as contact information, lowers its trustworthiness and compliance posture. Strategic improvements in these areas would enhance user trust and regulatory compliance.

30
35
17
40
75
75
100
curlconverterapidevelopertoolcodegeneration+3 more
ReactNext.jsJavaScriptGoogle Fonts
2025-10-15T12:22:44.879Z
riceforce.eu favicon

Sedo.com

riceforce.eu

0
TechnologyN/alargeMEDIUM

Sedo.com operates as a well-established domain marketplace platform, offering domain sales and transfer services globally. The analyzed page is a sales landing page for the domain riceforce.eu, providing options to buy immediately or submit an offer. Sedo emphasizes its 26 years of experience, high volume of domain transfers, and multilingual support, positioning itself as a trusted intermediary in the domain brokerage market. The platform supports multiple payment methods and provides personal assistance to buyers, targeting domain investors and businesses seeking domain acquisitions. Technically, the website employs modern web technologies including JavaScript ES modules and Cloudflare DNS services, ensuring good performance and mobile optimization. The SSL configuration is excellent, and the domain registration is consistent and legitimate, with no privacy protection masking ownership details. However, DNSSEC is not enabled, and some security headers are missing, which could be improved to enhance security posture. From a security perspective, the site enforces HTTPS and uses domain status protections to prevent unauthorized transfers. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is basic, with a cookie consent mechanism present but no visible privacy or terms of service policies on this page. Contact information is clearly provided, enhancing business credibility and user trust. Overall, the website is professional, trustworthy, and safe, with good technical and security foundations. Strategic recommendations include enabling DNSSEC, publishing comprehensive privacy and security policies, and adding security headers to further strengthen the security posture.

50
65
2
70
100
90
100
domainsalesmarketplacedomaintransfersedodomainbrokerage
JavaScript ES ModulesCloudflare DNSHTML5CSS3
2025-10-15T12:20:49.130Z