Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 125 of 579|Showing 6201-6250 of 28911
getyourguide.com favicon

GetYourGuide

getyourguide.com

0
HospitalityN/alargeLOW

GetYourGuide is a leading global online platform specializing in booking tours, attractions, and travel experiences worldwide. Founded in 2008, it serves a broad audience of travelers seeking cultural, nature, sports, and food-related activities. The company operates a large-scale marketplace model connecting travelers with local suppliers, emphasizing direct booking and competitive pricing. The website demonstrates a mature digital presence with excellent content quality, clear navigation, and strong branding consistency. Technically, the site employs modern web technologies including Vue.js, Google Tag Manager, Hotjar, and a consent management platform (Usercentrics), ensuring a responsive, fast, and accessible user experience. Security is well addressed with HTTPS, Content Security Policy, and fraud prevention mechanisms like Forter. Privacy compliance is robust, with comprehensive policies and user consent mechanisms in place. While the WHOIS data for the domain is unavailable, which slightly reduces trust, the overall digital footprint, certifications, and social media presence strongly support the legitimacy of the business. No critical security vulnerabilities or compliance gaps were detected. The site is safe for general audiences and does not contain adult or questionable content. Overall, GetYourGuide presents a professional, secure, and user-friendly platform with strategic strengths in the travel and hospitality sector.

50
95
17
98
75
90
100
traveltoursactivitiesbookinghospitality+1 more
JavaScriptGoogle Tag ManagerHotjarUsercentrics CMP+2

Partner Domains:

supplier.getyourguide.com
partner
partner.getyourguide.com
partner

+3 more partners

2025-10-11T22:19:31.791Z
L

LIFULL Connect

lifullconnect.com

0
Real EstateN/alargeMEDIUM

LIFULL Connect is a prominent global digital marketplaces group specializing in vertical search portals and transaction-based sites across homes, jobs, and cars sectors. The company aggregates millions of ads from thousands of websites, providing users with a streamlined and efficient search experience. Their extensive portfolio includes well-known brands such as Trovit, Mitula, Nestoria, and Dot Property, serving a significant global audience with over 180 million visits per month. Technically, the website is built on WordPress with modern plugins like WPBakery Page Builder and LayerSlider, leveraging Google Analytics and reCAPTCHA for analytics and security. The site employs HTTPS with strong security headers and a cookie consent mechanism, reflecting a mature digital infrastructure. Mobile optimization and SEO practices are good, though accessibility could be improved. From a security perspective, the site demonstrates good practices including HTTPS enforcement, security headers, and bot protection. However, it lacks publicly available security policies, incident response information, and vulnerability disclosure mechanisms, which are recommended for enhanced trust and compliance. Overall, the website is professional, trustworthy, and well-positioned in its market. The absence of WHOIS data reduces transparency but does not significantly detract from the site's credibility. Strategic improvements in security policy transparency and direct contact information would further strengthen its security posture and business credibility.

-
88
17
75
62
80
100
digitalmarketplacerealestateverticalsearchclassifiedadsglobalbrands+5 more
WordPressLayerSliderWPBakery Page BuilderjQuery+3

Partner Domains:

trovit.com
subsidiary
mitula.com
subsidiary

+3 more partners

2025-10-11T22:13:50.220Z
vacavista.com favicon

vacaVista

vacavista.com

0
HospitalityN/asmallMEDIUM

vacaVista operates as an online vacation rental search and booking platform offering over one million vacation homes and apartments worldwide. The website targets travelers seeking direct online booking options for holiday accommodations globally. The business model centers on aggregating vacation rental listings and facilitating user searches and bookings. The site appears to have been founded in 1998, indicating a long-standing presence in the hospitality sector, although domain registration data is unavailable to confirm this history. Technically, the website uses standard web technologies including HTML5, CSS, JavaScript, and jQuery 1.12.4. The site is moderately optimized for performance and mobile devices, with good SEO practices evident in meta tags and structured navigation. However, the use of an outdated jQuery version may pose security risks. There is no detected CMS or hosting provider information, and no advanced frameworks are identified. From a security perspective, the site lacks visible security headers and cookie consent mechanisms, and no HTTPS/SSL configuration details were provided. The absence of WHOIS registration data raises concerns about domain legitimacy and trustworthiness. No contact information or incident response policies are published, limiting transparency and user trust. The integration of Pipedrive Leadbooster chat indicates some marketing automation but no advanced analytics or tracking services were detected. Overall, vacaVista presents a professional and content-rich platform for vacation rental search but suffers from significant gaps in security posture, privacy compliance, and domain legitimacy. Strategic improvements in security headers, HTTPS enforcement, privacy mechanisms, and transparent contact information are recommended to enhance trust and compliance.

15
53
2
65
62
70
100
vacationrentalstravelholidayhomesbookingrealestate
jQuery 1.12.4JavaScriptCSSHTML5
2025-10-11T22:13:10.086Z
concursolutions.com favicon

SAP Concur

concursolutions.com

0
TechnologyN/aenterpriseMEDIUM

SAP Concur operates a professional and secure web portal at www.concursolutions.com, primarily serving as a login gateway for its business travel and expense management solutions. The website is well-branded, leveraging modern web technologies such as React and SAP CoreUI, and provides comprehensive privacy and cookie policies, indicating a mature approach to user data protection and compliance. Despite the absence of WHOIS data for the domain, the site aligns closely with SAP Concur's known digital assets and services, suggesting it functions as a branded subdomain or alias within the SAP Concur ecosystem. Technically, the site demonstrates a solid infrastructure with secure HTTPS usage, modern frontend frameworks, and integration of consent management tools like TrustArc. The presence of Bing Ads and tracking pixels indicates active marketing and analytics practices, balanced with user privacy considerations. However, the lack of explicit security headers and absence of direct contact information on the login page represent areas for improvement in transparency and security hardening. From a security perspective, the site shows good practices in secure form handling and cookie consent but would benefit from publishing explicit security policies, incident response contacts, and a vulnerability disclosure program to enhance trust and readiness. The domain's WHOIS inconsistency slightly reduces the overall trust score but does not detract significantly from the site's legitimacy given its association with SAP Concur. Overall, www.concursolutions.com is a professionally maintained enterprise portal with strong business credibility and technical maturity, suitable for its target audience of business users managing travel and expenses. Strategic enhancements in security transparency and contact availability would further strengthen its posture and user trust.

75
68
2
70
80
85
100
businesstravelexpensemanagementsapenterprise+2 more
ReactSAP CoreUIJavaScriptCSS+1

Partner Domains:

www.concur.com
partner
community.concur.com
partner

+1 more partners

2025-10-11T22:13:05.055Z
vanozoda.com favicon

COMING SOON

vanozoda.com

0
OtherN/asmallMEDIUM

The website vanozoda.com currently serves as a minimal placeholder with a 'Coming Soon' message and a single logo image. There is no substantive business content, contact information, or policies available, indicating the site is under development or not yet launched. The domain was registered recently in August 2023 with IONOS SE, a reputable registrar, and is set to expire in 2026. The lack of DNSSEC and security headers suggests basic security posture, but no immediate vulnerabilities or threats are evident given the minimal content. Overall, the site lacks privacy compliance elements and business credibility signals, limiting its current utility and trustworthiness. Technically, the site uses basic HTML with no detected CMS, frameworks, or analytics tools. Performance and mobile optimization are basic due to the simplicity of the page. Security best practices such as HTTPS are presumably in place (not explicitly stated but inferred from domain registrar and no warnings), but additional headers and DNSSEC would improve security. No tracking or advertising technologies are present. From a security perspective, the site shows no signs of active vulnerabilities or malicious content but lacks essential policies and contact mechanisms for incident response or data protection. The absence of privacy and cookie policies means GDPR compliance is not demonstrated. The domain registration data is consistent with a new business or project, with no suspicious patterns detected. Overall, the website is in an early stage with minimal content and limited security and compliance maturity. Strategic recommendations include implementing privacy and cookie policies, adding contact and security incident response information, enabling DNSSEC, and improving technical and content quality to build trust and compliance readiness.

30
40
2
70
52
75
100
comingsoonplaceholderminimalcontent
2025-10-11T21:11:40.846Z
I

Indeed

indeed.nl

0
TechnologyN/aenterpriseMEDIUM

Indeed is a globally recognized online job search and recruitment platform that connects job seekers with employers. The platform offers services such as job listings, company reviews, salary information, resume uploads, and employer job postings. It targets a broad audience including individuals seeking employment and companies looking to hire. The website analyzed is a regional subdomain (nl.indeed.com) of the main Indeed.com site. Technically, the site is protected by Cloudflare's security infrastructure, including a Web Application Firewall (WAF) and Turnstile CAPTCHA challenge, which currently blocks direct access to the site's content. The site uses modern web technologies such as JavaScript, CSS, and Cloudflare analytics. However, due to the WAF challenge, detailed technical and content analysis is limited. From a security perspective, the presence of Cloudflare's WAF and CAPTCHA indicates a strong security posture aimed at mitigating automated attacks and abuse. However, the inability to access the full site content restricts the ability to assess security headers, privacy policies, and other compliance measures. No vulnerabilities or exposed sensitive data were detected on the challenge page. Overall, the site is a legitimate, enterprise-level platform with strong security controls in place. The current WAF challenge limits the ability to perform a full analysis. It is recommended to access the site without WAF interference for a comprehensive evaluation.

55
35
17
80
52
85
100
jobsearchemploymentrecruitmentcloudflaresecuritychallenge
CloudflareJavaScriptCSSHTML5
2025-10-11T21:09:34.920Z
issgovernance.com favicon

Institutional Shareholder Services

issgovernance.com

0
FinanceN/aenterpriseMEDIUM

Institutional Shareholder Services (ISS) is a globally recognized leader in providing corporate governance and responsible investment solutions. The company targets institutional investors and governance professionals, offering services that help clients make informed investment decisions and promote sustainable business practices. ISS holds a strong market position as a trusted provider in the finance sector, with a business model focused on B2B service delivery. The website reflects this professionalism with comprehensive content, clear branding, and a user-friendly interface. Technically, the website is built on WordPress using the Jupiter theme and WPBakery Page Builder, enhanced with Yoast SEO for search optimization. It integrates multiple marketing and analytics tools such as HubSpot and Google Analytics, and employs OneTrust for cookie consent management, indicating a mature digital infrastructure. The site is mobile-optimized and performs moderately well, though accessibility features could be improved. From a security perspective, the site enforces HTTPS, uses standard security headers, and implements cookie consent mechanisms, demonstrating good security hygiene. No critical vulnerabilities or exposed sensitive data were detected. However, the absence of a public security policy or incident response contact suggests areas for improvement in transparency and readiness. Overall, ISS's website presents a low-risk profile with strong business credibility and technical implementation. The missing WHOIS data is likely due to privacy protection and does not detract significantly from the site's legitimacy. Strategic recommendations include publishing a security policy, adding vulnerability disclosure information, and enhancing accessibility to further strengthen trust and compliance.

70
88
17
80
77
85
100
corporategovernanceresponsibleinvestmentfinanceinstitutionalinvestorsprivacypolicy+4 more
WordPressWPBakery Page BuilderYoast SEO PremiumGoogle Analytics+2
2025-10-11T21:08:04.447Z
employinc.com favicon

Employ, Inc.

employinc.com

0
TechnologyN/aenterpriseLOW

Employ, Inc. is a prominent technology company specializing in AI-powered hiring solutions and applicant tracking systems. As the parent company of well-known ATS platforms such as JazzHR, Lever, and Jobvite, Employ positions itself as a leader in the recruitment technology space, offering adaptable and intelligent hiring tools to enterprises and HR professionals. The website reflects a mature digital presence with comprehensive content, clear branding, and a focus on AI integration in hiring workflows. Technically, the website is built on WordPress with modern plugins and integrations including Google Tag Manager, Google Analytics, and CookieYes for consent management. The site demonstrates good performance, mobile optimization, and accessibility, supported by structured data for SEO and rich metadata. Security practices include HTTPS enforcement and cookie consent mechanisms, although explicit security headers and vulnerability disclosure policies are not evident. From a security standpoint, the site shows a solid posture with no visible vulnerabilities or exposed sensitive data. The absence of WHOIS data suggests privacy protection, which is common for commercial entities, though it slightly reduces transparency. Overall, the site is trustworthy, professional, and compliant with privacy regulations such as GDPR. Strategically, Employ should enhance its security posture by implementing recommended HTTP security headers, publishing a security policy, and establishing a vulnerability disclosure program. These steps will strengthen trust and compliance while supporting its enterprise market position.

95
83
17
80
95
85
100
hiringairecruitmentatstechnology+3 more
WordPressGoogle Tag ManagerGoogle AnalyticsCookieYes Consent Management+3

Partner Domains:

jazzhr.com
subsidiary
lever.co
subsidiary

+1 more partners

2025-10-11T21:07:22.941Z
ortto.app favicon

Ortto

ortto.app

0
TechnologyN/amediumMEDIUM

Ortto is a technology company specializing in marketing automation solutions, offering a SaaS platform that integrates with various e-commerce and CRM systems. The website analyzed is primarily a login page, indicating a mature digital presence with a focus on customer engagement and campaign management. The platform supports multiple integrations, reflecting a comprehensive service offering for business clients seeking marketing automation. Technically, the website employs modern JavaScript frameworks, likely React, and uses several third-party analytics and tracking services including Google Tag Manager, Facebook Pixel, and Mouseflow. The site is hosted on secure infrastructure with HTTPS enforced, and the design is responsive and professional. However, there is a lack of visible privacy and cookie policies on the login page, which may impact compliance perceptions. From a security perspective, the site demonstrates good practices such as HTTPS usage and no exposed sensitive data in the HTML. However, the absence of explicit security headers and incident response information suggests room for improvement. The extensive use of tracking scripts without clear privacy disclosures may also pose compliance risks under regulations like GDPR. Overall, the website is functional, professional, and secure at a basic level but would benefit from enhanced transparency regarding privacy, security policies, and compliance measures to improve trust and regulatory adherence.

50
35
2
85
77
75
100
saasmarketingautomationlogintechnologycustomerengagement
JavaScriptGoogle Tag ManagerFacebook PixelMouseflow+3
2025-10-11T21:06:47.589Z
icons8.com favicon

Icons8

icons8.com

0
TechnologyN/alargeMEDIUM

Icons8 is a well-established technology company founded in 2011 that provides a comprehensive suite of design assets including icons, illustrations, photos, music, and AI-powered design tools. The website targets creatives and developers seeking high-quality, consistent design elements and tools to enhance their projects. Icons8 maintains a strong market position with a professional and consistent brand presence, supporting multiple languages and offering a variety of services that cater to a global audience. Technically, the website leverages modern web technologies such as Vue.js and Nuxt.js, hosted on AWS infrastructure, ensuring fast performance and excellent mobile optimization. The site demonstrates good SEO and accessibility practices, although some security headers and privacy compliance elements are missing. The domain is long-standing and registered with clear and consistent WHOIS data, indicating a legitimate and trustworthy business. From a security perspective, the site uses HTTPS and has domain status protections but lacks DNSSEC and visible security headers. There is no public security policy, incident response information, or vulnerability disclosure program, which are areas for improvement. Privacy compliance is weak due to the absence of privacy and cookie policies and consent mechanisms. Overall, Icons8 presents a low-risk profile with a strong business and technical foundation but should enhance its privacy and security posture to align with best practices and regulatory requirements.

40
53
2
85
62
65
100
iconsillustrationsphotosmusicdesign+2 more
Vue.jsNuxt.jsJavaScriptCSS+2

Partner Domains:

igoutu.cn
partner
icones8.fr
partner

+3 more partners

2025-10-11T21:06:42.576Z
streamwork.com favicon

StreamWork

streamwork.com

0
TechnologyN/asmallMEDIUM

StreamWork is a SaaS company specializing in online proofing software designed for creative teams, agencies, marketing teams, and enterprises. Their platform simplifies reviews, approvals, and project management tailored to creative workflows. The company positions itself as a niche provider in the creative technology sector, offering services such as design review and approval management. The website demonstrates a professional digital presence with clear branding and comprehensive content aimed at its target audience. Technically, the website is built on Webflow CMS and integrates multiple marketing and analytics tools including HubSpot, Google Analytics, Facebook Pixel, and Hotjar. The infrastructure supports good performance and mobile optimization, with modern security practices such as HTTPS and security headers in place. However, the absence of WHOIS registrant data raises some concerns about domain registration transparency. From a security perspective, the site employs standard best practices but lacks a publicly available security policy or incident response contact information. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. The extensive use of tracking and marketing tools indicates a mature digital marketing strategy but requires ongoing vigilance to maintain privacy compliance. Overall, StreamWork presents a trustworthy and professional online presence with minor gaps in domain transparency and explicit security disclosures. Strategic recommendations include publishing a security policy, adding vulnerability disclosure information, and enhancing accessibility compliance to further strengthen trust and security posture.

30
85
22
72
42
85
100
onlineproofingcreativeworkflowsaasprojectmanagementdesignreview+1 more
WebflowHubSpot (analytics, forms, ads pixel, messages)Google Tag ManagerFacebook Pixel+3
2025-10-11T21:06:12.287Z
ethicaltrade.org favicon

Ethical Trading Initiative

ethicaltrade.org

0
Non-profitN/amediumHIGH

The Ethical Trading Initiative (ETI) is a well-established non-profit alliance comprising trade unions, NGOs, and businesses focused on promoting ethical trade and human rights in global supply chains. The website positions ETI as a leading organization in this space, offering membership, training, transparency frameworks, and resources to support responsible business practices. The presence of major retail and NGO members underscores its market position and credibility. Technically, the website is built on Drupal 10, leveraging modern web technologies including Google Analytics with IP anonymization, CookiesJSR for cookie consent management, and Vimeo for video content. The site demonstrates good mobile optimization, accessibility, and SEO practices, though some security headers are missing which could be improved. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms aligned with GDPR requirements. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not present, representing areas for enhancement. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website is professional, trustworthy, and safe for general audiences. The lack of WHOIS data due to privacy protection is justified given the non-profit nature of the organization. Strategic recommendations include enhancing security headers, publishing security and incident response policies, and providing direct security contact information to strengthen trust and compliance.

40
68
17
40
27
70
40
ethicaltradehumanrightscorporatetransparencynon-profitsupplychain+2 more
Drupal 10Google AnalyticsCookiesJSRVimeo Player+1

Partner Domains:

community.ethicaltrade.org
partner
etibd.org
partner

+3 more partners

2025-10-11T20:02:02.456Z
iris-rail.org favicon

International Railway Industry Standard (IRIS)

iris-rail.org

0
TransportationN/amediumMEDIUM

The IRIS Portal website represents the International Railway Industry Standard, a globally recognized certification system for rail sector companies. The organization provides certification, audit, and training services aligned with ISO/TS 22163 standards. The website targets rail industry companies and certification bodies, offering resources such as certificate searches, news updates, and membership applications. The business is well-established, with a domain age dating back to 2005, indicating a mature presence in the railway certification market. Technically, the website employs a custom CMS with a technology stack including HTML5, CSS3, JavaScript, jQuery, and Google Maps API. The site is hosted via Hostbasket and uses HTTPS with a good SSL configuration. Performance and mobile optimization are moderate, with room for improvement in accessibility and modern framework adoption. The site includes interactive elements such as charts and maps, enhancing user engagement. From a security perspective, the website demonstrates basic best practices including HTTPS enforcement and CAPTCHA on login forms. However, DNSSEC is not enabled, and no explicit security headers were detected, representing areas for enhancement. No incident response or security policy pages are present, which could improve transparency and trust. No vulnerabilities or exposed sensitive data were found in the content. Overall, the website is professional, trustworthy, and focused on its niche market. It scores well on content quality and business credibility but could improve technical implementation and security posture. Strategic recommendations include enabling DNSSEC, adding security headers, updating libraries regularly, and publishing security and incident response policies to strengthen compliance and user trust.

60
68
2
55
77
65
100
certificationrailisots22163auditrailwayindustry+1 more
HTML5CSS3JavaScriptjQuery 3.6.0+3
2025-10-11T20:00:34.874Z
uicore.co favicon

UiCore PRO

uicore.co

0
TechnologyN/amediumMEDIUM

UiCore PRO is a professional WordPress theme provider offering a comprehensive subscription-based service that includes unlimited website creation, a powerful theme and page builder, and a vast design cloud library. The company targets marketers and agencies seeking modern, customizable WordPress themes with WooCommerce support and white-label capabilities. The website is well-positioned in the market with over 20,000 users and endorsements from reputable web design blogs, indicating strong market presence and trust. The technical infrastructure is built on WordPress with Elementor as the page builder, enhanced by modern JavaScript libraries and marketing tools such as Google Tag Manager, Facebook Pixel, Hotjar, and Sendinblue. The site demonstrates excellent performance, mobile optimization, and SEO practices, reflecting a mature digital presence. Hosting details are not explicit, but the site uses HTTPS with a good SSL configuration. Security posture is solid with HTTPS enforced and no visible sensitive data exposure. However, explicit security headers are not detected, and no cookie consent mechanism is present, indicating areas for improvement in compliance and security hardening. The absence of WHOIS registrant data is due to TLD limitations but is mitigated by the professional nature of the site and privacy protection justification. Overall, UiCore PRO presents a low-risk profile with strong business credibility and technical maturity. Strategic recommendations include implementing explicit security headers, adding cookie consent for privacy compliance, and publishing a security policy with incident response contacts to enhance trust and compliance.

45
65
17
85
75
75
100
wordpressthemepagebuilderwoocommercedesigncloud+3 more
WordPressElementorjQueryGoogle Tag Manager+3

Partner Domains:

uicore.co
partner
my.uicore.co
service

+1 more partners

2025-10-11T20:00:04.822Z
albankaldawli.org favicon

مجموعة البنك الدولي

albankaldawli.org

0
GovernmentN/aenterpriseMEDIUM

The website represents the Arabic language portal of the World Bank Group, a globally recognized international financial institution focused on providing financial and technical assistance to developing countries. The site offers extensive content including news, research publications, data resources, and project information tailored for Arabic-speaking audiences. The business model is that of a non-profit international organization delivering loans, credits, and advisory services to over 100 developing and transitional countries. The site is professionally designed, mobile-optimized, and uses modern web technologies including JavaScript ES modules and Adobe Experience Manager CMS. From a technical perspective, the site demonstrates good SEO, accessibility, and performance characteristics, though some improvements could be made in security headers and cookie consent mechanisms. The security posture is strong with HTTPS enforced and secure form handling, but lacks published incident response or vulnerability disclosure policies. WHOIS data is unavailable or privacy protected, which is typical for such organizations, and does not detract from the site's legitimacy given the strong alignment with World Bank branding and content. Overall, the website is a trustworthy, professional, and comprehensive resource for development-related information in Arabic. Strategic recommendations include enhancing security headers, implementing cookie consent, publishing security policies, and providing clearer contact information for security incidents to further improve trust and compliance.

65
53
2
70
75
85
100
worldbankdevelopmentarabicfinancenon-profit+1 more
HTML5CSS3JavaScript ES Modules

Partner Domains:

www.worldbank.org
partner
blogs.worldbank.org
partner

+2 more partners

2025-10-11T19:57:48.823Z
banquemondiale.org favicon

Le Groupe de la Banque mondiale

banquemondiale.org

0
GovernmentN/aenterpriseMEDIUM

The website for Le Groupe de la Banque mondiale serves as the French language portal for the World Bank Group, a leading international development finance institution with 189 member countries. The site provides comprehensive information on the organization's mission to end poverty and promote sustainable development globally. It offers access to economic research, data resources, project information, and upcoming events, targeting policymakers, development professionals, and the general public interested in global development issues. The website is well-branded, professionally designed, and content-rich, reflecting the organization's authoritative position in the development sector. Technically, the site is built on Adobe Experience Manager, utilizing modern web standards such as responsive images, CSS Grid, and JavaScript ES modules. The site is mobile-optimized and accessible, with good SEO practices evident in meta tags and structured content. Performance is moderate, with no critical technical issues detected. However, some security headers are not explicitly visible in the provided data, and no explicit cookie consent mechanism was found. From a security perspective, the site enforces HTTPS and uses secure forms with user consent for newsletter subscriptions. There is no exposed sensitive data or known vulnerabilities in the analyzed content. The WHOIS data is unavailable due to privacy or query failure, but the domain and content strongly align with the official World Bank Group branding, indicating high legitimacy. Privacy compliance is strong with a comprehensive privacy policy and GDPR adherence, though cookie consent could be improved. Overall, the website presents a low-risk profile with strong business credibility and technical maturity. Strategic recommendations include enhancing security headers, implementing explicit cookie consent, publishing security policies and incident response contacts, and providing vulnerability disclosure information to further strengthen trust and compliance.

65
53
17
70
75
85
100
internationaldevelopmentworldbankeconomicresearchdatafordevelopmentpovertyreduction+1 more
Adobe Experience Manager (AEM)JavaScript ES ModulesResponsive images with WebP and JPEGCSS Grid+1

Partner Domains:

www.worldbank.org
partner
scorecard.worldbank.org
partner

+1 more partners

2025-10-11T19:57:43.811Z
ifc.org favicon

International Finance Corporation (IFC)

ifc.org

0
FinanceN/aenterpriseMEDIUM

The International Finance Corporation (IFC) is a leading global development institution focused on fostering private sector growth in developing countries. As a member of the World Bank Group, IFC operates in over 100 countries, providing investment, advisory, and asset management services to catalyze economic development and job creation. The website reflects IFC's authoritative market position with comprehensive sector expertise and a broad range of financial products and services tailored to emerging markets. The target audience includes private sector companies, investors, governments, and development partners worldwide. Technically, the website is built on Adobe Experience Manager (AEM) and incorporates modern web technologies such as jQuery, Bootstrap, and various analytics and tracking tools including Microsoft Application Insights and Adobe Analytics. The site is mobile-optimized, accessible, and SEO-friendly, with a professional design and clear navigation. Security posture is strong with HTTPS enforced and no visible vulnerabilities, though explicit security headers and a dedicated security policy page are absent. Privacy compliance is robust, with clear privacy and cookie policies and GDPR adherence. Contact information is primarily provided via inquiry forms and directories rather than direct emails or phone numbers, consistent with large international organizations. Social media presence is active across major platforms, enhancing trust and engagement. Overall, the IFC website demonstrates a mature digital presence with high content quality, strong business credibility, and good security practices. Recommendations include publishing a dedicated security policy, enhancing security headers, and providing vulnerability disclosure information to further strengthen trust and compliance.

65
53
17
85
75
85
100
financedevelopmentprivatesectorinvestmentemergingmarkets+3 more
Adobe Experience Manager (AEM)jQueryBootstrapPopper.js+5

Partner Domains:

worldbank.org
parent
disclosures.ifc.org
related

+1 more partners

2025-10-11T19:57:33.788Z
ngosource.org favicon

NGOsource

ngosource.org

0
Non-profitN/amediumMEDIUM

NGOsource is a well-established non-profit service project operated by TechSoup Global and the Council on Foundations, specializing in streamlining equivalency determination for international grantmaking. The website presents a professional, content-rich platform targeting foundations, donor advised funds, and NGOs, offering legal and administrative support to facilitate cross-border philanthropy. The site demonstrates a strong market position with a decade of operational history and trusted partnerships. Technically, the website is built on Drupal 10 with modern front-end frameworks such as Bootstrap and FontAwesome, ensuring good mobile responsiveness and accessibility. Integration with Google Analytics and Tag Manager indicates a moderate level of user tracking and marketing insight. Performance is moderate with no critical technical issues detected. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, the absence of visible security headers and cookie consent mechanisms suggests room for improvement in compliance and security best practices. The lack of direct contact information and incident response policies limits transparency but is consistent with the organization's operational model. Overall, NGOsource presents a trustworthy and professional online presence with a solid business model and technical foundation. Strategic enhancements in privacy compliance and security policy publication would further strengthen its posture and user trust.

20
53
17
65
57
75
100
non-profitphilanthropyequivalencydeterminationinternationalgrantslegalservices+2 more
Drupal 10Bootstrap 4.6.2jQuery 3.7.1FontAwesome 6.6.0+2

Partner Domains:

www.techsoup.org
partner
members.ngosource.org
service

+1 more partners

2025-10-11T19:57:18.758Z