Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 110 of 579|Showing 5451-5500 of 28928
mirasvit.com favicon

Mirasvit

mirasvit.com

0
TechnologyN/amediumMEDIUM

Mirasvit is a well-established technology company specializing in developing Magento extensions and Shopify apps to enhance e-commerce store functionality. Founded in 2009, the company has built a strong market position with over 50,000 stores trusting their products. Their offerings include both free and paid modules, professional installation services, and a partnership program, targeting Magento store owners and e-commerce businesses globally. The website reflects a professional and consistent brand image with excellent content quality and user experience. Technically, the website is built on Magento with the modern Hyvä theme, leveraging Cloudflare for DNS and integrating multiple analytics and marketing tools such as Google Tag Manager, Mixpanel, Microsoft Clarity, and Facebook Pixel. The site is mobile-optimized, fast-loading, and accessible, demonstrating a mature digital infrastructure. Security best practices are observed with HTTPS enforcement, secure cookies, and anti-CSRF tokens, although some security headers could be explicitly implemented and DNSSEC enabled for enhanced protection. From a security perspective, the site shows a solid posture with no visible vulnerabilities or exposed sensitive data. However, there is no publicly available security policy or incident response contact, which could be improved to enhance transparency and readiness. Privacy compliance is good, with clear privacy and cookie policies and consent mechanisms in place, aligning with GDPR requirements. Overall, Mirasvit presents a low-risk profile with a trustworthy domain registration history, consistent business information, and no signs of malicious activity. Strategic recommendations include enabling DNSSEC, publishing a security policy, and adding a security.txt file to facilitate vulnerability disclosures. These steps would further strengthen their security posture and customer trust.

65
68
17
70
75
80
100
magentoe-commerceextensionssoftwaretechnology
MagentoHyvä ThemeCloudflare DNSGoogle Tag Manager+4
2025-10-13T17:49:42.494Z
earlywarningsforall.org favicon

World Meteorological Organization

earlywarningsforall.org

0
GovernmentN/alargeMEDIUM

The Early Warnings for All website represents a global initiative led by the World Meteorological Organization and partners to enhance multi-hazard early warning systems worldwide. The initiative focuses on disaster risk knowledge, hazard monitoring, communication, and preparedness to reduce the impact of climate-related hazards by 2027. The website serves as an informational and resource hub targeting governments, disaster management agencies, and the public. Technically, the site is built on Drupal 10, leveraging modern analytics and tracking tools such as Google Tag Manager, Hotjar, and Microsoft Clarity. The site is mobile-optimized, accessible, and well-structured with good SEO practices. Hosting and DNS are managed through reputable providers, ensuring stable and secure infrastructure. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks some security headers and a public security policy or incident response information. Privacy compliance is partial, with no visible cookie consent mechanism despite the use of tracking scripts, which may pose regulatory risks. Overall, the website is professional, trustworthy, and aligned with its mission. Strategic improvements in privacy compliance and security transparency would enhance its security posture and user trust.

55
53
10
60
85
75
100
climateweatherwaterearlywarningsystemsdisasterriskreduction+1 more
Drupal 10Google Tag ManagerMicrosoft ClarityHotjar+2

Partner Domains:

wmo.int
partner
undrr.org
partner

+2 more partners

2025-10-13T17:47:42.267Z
flagsapi.com favicon

FlagsAPI - Country Flags API

flagsapi.com

0
TechnologyN/asmallMEDIUM

FlagsAPI is a small technology service providing an API for country flag images in flat and shiny themes with multiple size options. The website is designed primarily for developers and web designers who need easy access to country flag images for integration into their projects. The business model is straightforward, offering a niche API service with a clear focus on flag image delivery. The domain is relatively new, registered in late 2021, which aligns with the business's apparent startup phase. Technically, the website uses standard web technologies including HTML5, CSS, JavaScript, and jQuery, with Google Fonts for typography. Hosting and DNS are managed via Cloudflare, providing some level of performance and security benefits, although DNSSEC is not enabled. The site is mobile-optimized and has a clear navigation structure, but lacks advanced frameworks or CMS platforms. Performance is moderate, and accessibility features are basic. From a security perspective, the site lacks important security headers and does not provide privacy or cookie policies, which are critical for GDPR compliance and user trust. No contact or incident response information is available, limiting transparency and responsiveness to security issues. The WHOIS data shows a legitimate domain registration with no privacy protection, consistent with the business profile. Overall, the security posture is basic and could be improved significantly. The overall risk is moderate given the lack of privacy and security policies, but no critical vulnerabilities or malicious indicators were found. Strategic improvements in security headers, policy disclosures, and contact transparency would enhance trust and compliance.

15
35
17
60
75
75
100
HTML5CSSJavaScriptjQuery+1
2025-10-13T17:47:07.097Z
D

D-EDGE

d-edgeconnect.media

0
HospitalityN/alargeHIGH

D-EDGE is a technology and marketing company focused on providing solutions to the hospitality industry, specifically targeting hoteliers. Their offerings include central reservation systems, booking engines, channel management, big data analytics, hotel website design, and digital marketing services. The company serves a large client base of approximately 17,000 hoteliers, positioning itself as an established player in the hotel technology market. The website content is minimal but clearly communicates the business purpose and directs users to the main corporate site for more information. Technically, the website employs Microsoft Application Insights for telemetry and monitoring, indicating some level of digital maturity in tracking performance and usage. The site is mobile responsive with basic design quality and SEO optimization. However, there is a lack of advanced security headers and no visible cookie consent mechanisms, which suggests room for improvement in security and privacy compliance. From a security perspective, the site is accessible without WAF or blocking mechanisms detected. The absence of WHOIS data due to unsupported TLD or privacy protection limits transparency but does not inherently indicate malicious intent. No contact information or security policies are provided, which could hinder incident response and user trust. Overall, the security posture is moderate but could be enhanced by implementing standard security headers, visible privacy controls, and contact channels for security incidents. The overall risk assessment indicates a legitimate business with a moderate security and privacy posture. Strategic recommendations include improving transparency by publishing contact and security policies, enhancing security headers and SSL configurations, and implementing cookie consent mechanisms to align with GDPR and other privacy regulations.

25
58
2
70
-
60
100
hoteltechnologyhotelmarketingcentralreservationsystembookingenginechannelmanager+2 more
Microsoft Application InsightsJavaScript
2025-10-13T16:39:57.758Z
R

Revobits

revobits.com

0
OtherN/asmallMEDIUM

Revobits.com is a minimally developed website with very limited content, primarily consisting of a single email contact link and Google Tag Manager integration. The domain is well-established, having been registered since 2009 with Cloudflare, Inc. as the registrar, indicating a legitimate registration history. However, the lack of substantive content, absence of privacy or cookie policies, and no visible business or branding information limit the website's credibility and user trust. Technically, the site uses HTTPS and is hosted behind Cloudflare, but it lacks DNSSEC and important security headers, which are recommended to enhance security posture. The use of Google Tag Manager suggests some level of analytics tracking, but no explicit privacy compliance mechanisms are present. The website does not employ any CMS or frameworks and shows poor mobile optimization and accessibility. From a security perspective, the site has a basic SSL configuration but misses critical security headers and DNS security enhancements. No incident response or security policy information is provided, and no vulnerability disclosure or security.txt files are found. The overall security posture is moderate but could be significantly improved with standard best practices. Overall, the website presents a low-risk profile due to minimal content and no suspicious elements but suffers from poor content quality, lack of transparency, and weak privacy compliance. Strategic recommendations include enhancing website content, implementing privacy and cookie policies, improving security headers and DNS security, and providing clear business and contact information to build trust and compliance.

15
35
2
70
75
80
100
minimalplaceholderanalyticsemailcontact
Google Tag Manager
2025-10-13T15:32:57.387Z
ifsc-climbing.org favicon

International Federation of Sport Climbing

ifsc-climbing.org

0
OtherN/amediumMEDIUM

The International Federation of Sport Climbing (IFSC) operates the official website for the global sport climbing community, providing comprehensive information on events, athlete rankings, multimedia content, and organizational details. The website targets athletes, fans, and stakeholders in the sport climbing ecosystem and positions itself as the authoritative source for climbing-related competitive information worldwide. The site demonstrates a professional and consistent brand presence with a modern, mobile-optimized design and clear navigation. Technically, the website leverages modern frameworks such as Next.js and React, with performance monitoring tools like Boomerang and analytics via Google Tag Manager. The infrastructure supports responsive design and multimedia content delivery, indicating a mature digital presence. However, some technical improvements are recommended, including the addition of explicit security headers and enhanced privacy compliance features. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data or vulnerable libraries. Nonetheless, the absence of visible security policies, incident response contacts, and vulnerability disclosure mechanisms suggests room for improvement in security transparency and governance. The lack of WHOIS data limits domain trust verification, although the website content and social media presence support its legitimacy. Overall, the IFSC website is a well-designed, content-rich platform serving its community effectively but would benefit from enhanced privacy and security disclosures to strengthen trust and compliance.

30
73
17
70
95
80
100
sportsclimbingfederationeventsmultimedia+2 more
Next.jsReactWebpackGoogle Tag Manager+1
2025-10-13T15:31:52.240Z
theuiaa.org favicon

UIAA

theuiaa.org

0
Non-profitN/amediumHIGH

The UIAA website represents the International Climbing and Mountaineering Federation, a globally recognized non-profit organization dedicated to promoting safety, sustainability, and community in mountain sports. The site offers comprehensive resources including safety standards, training, event calendars, and member directories, positioning UIAA as a central authority in the mountaineering sector. The website is well-designed, mobile-optimized, and rich in relevant content, targeting climbers, mountaineers, and affiliated organizations worldwide. Technically, the site is built on WordPress with modern plugins and libraries such as WPBakery Page Builder, Ultimate VC Addons, and Google Analytics integration. It demonstrates good SEO practices, mobile responsiveness, and moderate performance. Security posture is solid with HTTPS enforced and cookie consent mechanisms in place, though explicit security headers and incident response policies could be enhanced. No blocking or WAF challenges were detected, allowing full content access. WHOIS data is privacy protected, which is typical for non-profit organizations, and does not detract from the site's legitimacy given the professional presentation and consistent branding. The site maintains GDPR compliance with clear privacy and cookie policies. Overall, the UIAA website is a trustworthy, professional platform serving its community effectively, with recommendations to strengthen security headers and publish vulnerability disclosure information to further enhance trust and compliance.

15
80
2
70
65
80
-
mountaineeringclimbingsafetysustainabilitynon-profit+3 more
WordPressWPBakery Page BuilderUltimate VC AddonsGoogle Analytics+3

Partner Domains:

skyrunning.com
partner
iceclimbing.sport
partner
2025-10-13T15:31:47.230Z
xero.com favicon

Xero Limited

xero.com

0
FinanceN/alargeMEDIUM

Xero Limited operates a leading cloud-based accounting software platform tailored for small businesses, sole traders, accountants, and bookkeepers. The company offers a SaaS subscription model with key services including invoicing, payroll, expense management, and app integrations, enhanced by AI capabilities such as the JAX financial assistant. The website reflects a strong market position with over 4.4 million subscribers and multiple industry awards, emphasizing ease of use and connectivity with financial institutions and business apps. Technically, the site employs modern frameworks like Next.js and React, integrates performance and error monitoring via New Relic, and uses Stripe for payment processing. The site is well-optimized for mobile and SEO, providing a professional user experience. Security posture is strong with HTTPS enforcement and standard security headers, though explicit public security policies and incident response contacts are not prominently available. WHOIS data is unavailable likely due to registry restrictions, but the brand's global recognition and trust signals mitigate concerns. Overall, Xero's digital presence is mature, secure, and business-focused, supporting its leadership in the cloud accounting market.

15
68
2
82
62
85
100
accountingsmallbusinessfinancesaascloudsoftware+2 more
ReactNext.jsNew Relic monitoringStripe payments+1

Partner Domains:

apps.xero.com
partner
developer.xero.com
partner
2025-10-13T15:27:51.195Z
geocaching.com favicon

Groundspeak, Inc.

geocaching.com

0
TechnologyN/amediumMEDIUM

Geocaching.com is operated by Groundspeak, Inc., a company founded in 2000, providing the world's largest geocaching platform and official app for outdoor treasure hunting. The website targets outdoor enthusiasts and families, offering a comprehensive service for discovering geocaches globally. The platform is well-established with a consistent brand presence and professional content quality. Technically, the website employs modern web technologies including Google Tag Manager and Cookiebot for consent management, ensuring compliance with privacy regulations. The site is mobile-optimized, accessible, and SEO-friendly, with good performance indicators. However, some security headers are not explicitly detected and could be improved. Security posture is solid with HTTPS enforced and CSRF protection cookies in place. The use of Cookiebot indicates a strong commitment to privacy compliance, though explicit security policies and incident response contacts are not publicly visible. No vulnerabilities or suspicious content were detected in the analysis. Overall, the website presents a low risk profile with strong business credibility and privacy practices. Strategic recommendations include enhancing security headers, publishing a security.txt file, and providing clearer contact and policy information to further improve trust and compliance.

65
100
17
80
67
80
100
geocachingoutdooradventuregpshiking+4 more
Google Tag ManagerCookiebot Consent ManagementGoogle Fonts (Noto Sans)HTML5+1
2025-10-13T14:24:25.294Z
C

Welcome to nginx!

ctnsnet.com

0
OtherN/asmallHIGH

The website at ctnsnet.com currently serves only a default nginx welcome page, indicating that the site is not yet configured or actively maintained. There is no business-related content, contact information, or policies present, which severely limits the ability to assess the company's market position or services. The domain is registered since 2012 with Name.com, Inc., but the lack of active content suggests the website is either under development or abandoned. From a technical perspective, the site uses the nginx web server, but no further technologies, CMS, or frameworks are detected. The hosting provider is Name.com, Inc., and DNSSEC is not enabled. No security headers or HTTPS configuration details are available, which raises concerns about the security posture. The absence of privacy and cookie policies also indicates non-compliance with GDPR and related regulations. Security-wise, the site shows no evidence of security best practices or incident response mechanisms. The lack of HTTPS and security headers, combined with no visible contact or business information, results in a low security score. There are no signs of vulnerabilities or malicious content, but the minimal content and configuration represent a risk if the site were to be used for business purposes without proper setup. Overall, the website is currently non-functional as a business or service platform. It is recommended to fully configure the site with secure HTTPS, implement privacy and cookie policies, add clear business and contact information, and apply security best practices to improve trust and compliance.

15
40
2
70
67
70
100
nginxdefaultpageplaceholder
nginx
2025-10-13T14:21:06.606Z
energyogre.com favicon

Energy Ogre

energyogre.com

0
EnergyN/amediumMEDIUM

Energy Ogre operates as a service provider specializing in finding and managing the best electricity plans for consumers in Texas, aiming to reduce electricity bills by up to 40%. The company positions itself as a trusted intermediary that simplifies the complex electricity market for its customers. The website features professional design elements, testimonial videos, and a clear business proposition targeting Texas residents seeking energy savings. Technically, the website employs a modern technology stack including Google Tag Manager, HubSpot, TikTok Pixel, Facebook Pixel, and other marketing and analytics tools. The site is mobile-optimized and demonstrates good SEO practices, although accessibility features are basic. HTTPS is enabled, ensuring secure communication, but security headers are not evident in the provided data. From a security perspective, the site shows strengths such as HTTPS usage and absence of visible vulnerabilities. However, the lack of explicit privacy and cookie policies, absence of security headers, and missing WHOIS domain registration data present compliance and trust concerns. The domain's WHOIS information is unavailable, which raises questions about domain legitimacy and ownership transparency. Overall, the website is functional and professional but would benefit from enhanced privacy compliance, security best practices, and verification of domain registration to improve trustworthiness and regulatory adherence.

25
73
25
75
77
80
100
energyelectricitytexasenergyplansaccountmanagement+1 more
Google Tag ManagerHubSpotTikTok PixelFacebook Pixel+11
2025-10-13T14:18:10.356Z
kroscloud.com favicon

Krosapp s.r.o.

kroscloud.com

0
TechnologyN/asmallMEDIUM

Kroscloud is a specialized web-based platform offering interactive 3D model viewing and hosting services, primarily targeting users who work with photogrammetry 3D scans and panoramic images. The platform supports advanced features such as multi-layer visualization, audio guides, multilingual interfaces, and protected content access, positioning itself as a niche SaaS provider in the 3D visualization technology sector. The website is professionally designed with clear navigation and good content relevance, supporting a positive user experience for its target audience. Technically, the site uses a modern technology stack including jQuery, Bootstrap, and various JavaScript libraries, with integration of Google Analytics and Facebook Pixel for marketing and analytics purposes. The site is mobile-optimized and implements GDPR-compliant privacy and cookie policies with consent mechanisms. Security posture is generally good with HTTPS enforced and no visible sensitive data exposure, though the absence of explicit security headers and incident response information suggests room for improvement. The lack of WHOIS data for the domain is a notable concern, as it reduces transparency and trust from a domain registration perspective, despite the professional appearance and functionality of the website. Overall, the site scores well in content quality, technical implementation, and privacy compliance, but domain registration opacity and minor security header gaps moderate the overall trust score.

15
68
2
85
67
75
100
3dphotogrammetryvirtualtoursinteractivepresentationsmultilingual+2 more
jQueryBootstrapFeather IconsSweetAlert2+7
2025-10-13T13:07:27.987Z
un-glaciers.org favicon

International Year of Glaciers’ Preservation

un-glaciers.org

0
GovernmentN/amediumMEDIUM

The website www.un-glaciers.org is an official United Nations initiative co-chaired by UNESCO and WMO, dedicated to the International Year of Glaciers' Preservation in 2025. It serves as an authoritative platform to raise global awareness about the critical role of glaciers in climate regulation and freshwater supply, targeting policymakers, researchers, and the general public. The site offers rich multimedia content, event information, and partner collaboration opportunities, reflecting a strong commitment to environmental education and international cooperation. Technically, the website is built on Drupal CMS with modern web technologies including responsive design, Google Tag Manager, and structured data for SEO. It demonstrates good mobile optimization and accessibility, although some security headers are not visibly implemented. HTTPS is enforced, and privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanisms. From a security perspective, the site shows a mature posture with no visible vulnerabilities or exposed sensitive data. However, it lacks explicit security policies, incident response contacts, and vulnerability disclosure information, which are recommended for further strengthening trust and compliance. Overall, the domain appears legitimate and trustworthy despite the absence of WHOIS data, likely due to privacy protection. The website's professional design, authoritative content, and UN affiliation position it as a credible source for glacier preservation information. Strategic recommendations include enhancing security headers, publishing security policies, and providing clearer contact information for incident response.

30
68
2
70
52
70
100
unescowmoglaciersclimatechangeinternationalyear+2 more
Drupal CMSGoogle Tag ManagerGoogle Analytics (gtag.js)Bootstrap (navbar classes)+2
2025-10-13T12:02:55.472Z
carto.com favicon

CARTO

carto.com

0
TechnologyN/aenterpriseLOW

CARTO is a well-established enterprise technology company specializing in advanced GIS and spatial analytics platforms that integrate seamlessly with cloud ecosystems. Founded in 1995, CARTO positions itself as a leader in scalable spatial data visualization and analysis, targeting businesses across multiple sectors including telecommunications, transportation, real estate, financial services, and healthcare. Their platform supports AI agents and data enrichment, catering to data analysts, scientists, and developers. The website reflects a mature digital presence with professional design, clear navigation, and comprehensive content describing their products and solutions. Technically, the website is built on modern web technologies including Webflow CMS, HubSpot forms, and integrates with major cloud providers such as AWS, Google Cloud, Azure, Snowflake, and Databricks. The site is hosted on AWS infrastructure with DNS managed by Amazon's DNS services. Performance is moderate with good mobile optimization and basic accessibility features. SEO practices are well implemented with proper meta tags and Open Graph data. From a security perspective, CARTO employs HTTPS with strong SSL configuration and implements key security headers. Domain registration is consistent and long-standing, enhancing trustworthiness. However, DNSSEC is not enabled, and there is no publicly available security policy or incident response information. No vulnerability disclosure or security.txt file is present, which could be improved to enhance transparency and security posture. Overall, CARTO demonstrates a high level of professionalism, security, and compliance with privacy regulations such as GDPR. The site is safe for general audiences with no adult or questionable content. Strategic recommendations include enabling DNSSEC, publishing explicit security and incident response policies, and adding a vulnerability disclosure program to further strengthen trust and security maturity.

85
70
22
95
62
90
100
gisspatialanalyticscloudenterprisedatavisualization+2 more
Webflow CMSGoogle Tag ManagerLottie animationsHubSpot forms+1
2025-10-13T12:01:50.328Z
worldloppet.com favicon

Worldloppet

worldloppet.com

0
OtherN/amediumMEDIUM

Worldloppet is a global federation uniting 19 major cross-country ski marathons worldwide, fostering a large and active skiing community. The website serves as a comprehensive platform offering race calendars, results, rankings, and membership programs such as Passports and Masters. It targets skiing enthusiasts globally and operates primarily as a non-profit organization promoting the sport. Technically, the website is built on WordPress with WooCommerce for e-commerce functionality, enhanced by plugins like Slider Revolution and GDPR compliance tools. It uses Google Analytics and Facebook Pixel for user tracking and marketing insights. The site is mobile-optimized with good SEO practices and a moderate performance profile. From a security perspective, the site enforces HTTPS and includes cookie consent mechanisms, but lacks explicit security headers and visible security policies. The absence of WHOIS registration data for the domain raises concerns about domain legitimacy, although the website content and social media presence indicate a professional and trustworthy organization. Overall, the site is well-structured and content-rich, serving its community effectively. However, it would benefit from improved transparency in domain registration, enhanced security headers, and explicit privacy and security policies to strengthen trust and compliance.

20
100
17
75
75
75
100
cross-countryskiingskimarathonsportscommunityskieventsworldloppet+2 more
WordPressWooCommerceSlider RevolutionGoogle Analytics+6

Partner Domains:

dobbiacocortina.org
partner
2025-10-13T12:00:35.110Z
freelo.io favicon

Freelo

freelo.io

0
TechnologyN/asmallMEDIUM

Freelo is a SaaS project and task management platform designed primarily for independent professionals and small teams seeking efficient collaboration and control over their projects. The website demonstrates a strong market position with numerous client case studies and testimonials, indicating trust and adoption by thousands of teams. The platform offers a comprehensive suite of features including task management, Kanban boards, Gantt timelines, mind maps, and mobile/desktop applications, catering to a broad range of project management needs. Technically, the website employs modern web technologies such as JavaScript, Google Tag Manager, Sentry for error monitoring, and integrates advertising and tracking tools like Bing Ads and Google Analytics. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. However, explicit CMS or hosting provider details are not evident from the content. From a security perspective, the site uses HTTPS and integrates monitoring tools but lacks visible security headers and a published security policy or incident response contacts. Privacy compliance is partially addressed with a cookie consent mechanism, but no explicit privacy policy or terms of service pages were detected in the provided content. WHOIS data is unavailable due to privacy protection, but the domain and website content indicate legitimacy. Overall, Freelo presents a professional, trustworthy, and well-structured online presence with minor gaps in explicit privacy and security disclosures. Strategic improvements in publishing comprehensive privacy and security policies and enhancing security headers would strengthen its security posture and compliance.

55
83
17
80
62
70
-
projectmanagementtaskmanagementcollaborationsaasteamwork+1 more
JavaScriptGoogle Tag ManagerSentryBing Ads+3
2025-10-13T12:00:30.098Z