Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 16 of 579|Showing 751-800 of 28928
dalkiasolutions.com favicon

Dalkia

dalkiasolutions.com

0
EnergyN/alargeMEDIUM

Dalkia Solutions is a large energy efficiency solutions provider offering a comprehensive range of services including chiller services, combined heat and power, digital services, intelligent load management, LED lighting and controls, operations and maintenance, refrigeration, retail energy, smart infrastructure solutions, solar plus storage, and strategic energy management. The company targets commercial and industrial clients nationwide and is part of the EDF Group, a well-known energy conglomerate. The website demonstrates a professional and consistent brand presence with detailed service descriptions and active social media engagement. Technically, the website is built on WordPress with modern JavaScript libraries such as jQuery and OwlCarousel, and integrates Google Tag Manager for analytics. The site is mobile optimized with good SEO practices, though accessibility features are basic. Performance is moderate, with no critical errors detected. From a security perspective, the site uses HTTPS with CSRF tokens in forms, but lacks important security headers and a cookie consent mechanism. No explicit incident response or vulnerability disclosure policies are published, which could be improved to enhance trust and compliance. The absence of WHOIS data is a concern but the website content and branding align with a legitimate business. Overall, the site is professional and trustworthy but would benefit from enhanced security headers, explicit contact information, and improved privacy compliance mechanisms to strengthen its security posture and user trust.

55
58
2
78
72
80
20
energyenergyefficiencysustainabilitycommercialindustrial+2 more
jQueryOwlCarouselGoogle Tag ManagerGoogle Fonts

Partner Domains:

www.dalkia.com
parent
careers.hireology.com
partner
2025-10-31T07:56:40.020Z
signal.group favicon

Signal

signal.group

0
TechnologyN/alargeMEDIUM

Signal is a well-established nonprofit organization founded in 2013, providing secure messaging services through its Signal Messenger app and related group functionalities. The website signal.group serves as a gateway to join Signal groups and links users to official Signal resources, downloads, and support. The organization holds a strong market position as a leading privacy-focused messaging platform with a global user base. Technically, the website employs modern web technologies including Bulma CSS framework and JavaScript, with responsive design optimized for mobile devices. The site is served over HTTPS with no visible security vulnerabilities or exposed sensitive data. However, some security best practices such as security headers and cookie consent mechanisms are absent, which could be improved to enhance compliance and security posture. From a security perspective, the domain WHOIS data is limited due to registry restrictions, but the domain is actively maintained and consistent with the nonprofit's branding and operations. No WAF or blocking mechanisms are detected, and the site does not engage in advertising or tracking, aligning with privacy principles. Overall, the website demonstrates a strong security posture with room for improvement in transparency and compliance documentation. The overall risk assessment is low, with recommendations focusing on enhancing security headers, publishing security policies, and implementing cookie consent to meet GDPR requirements. These steps will further strengthen trust and compliance for the organization's global audience.

30
53
2
80
57
85
100
securemessagingnonprofitprivacysignaltechnology+1 more
Bulma CSSJavaScriptHTML5CSS3+2
2025-10-31T07:54:09.651Z
grizzlyads.com favicon

Grizzly Ads

grizzlyads.com

0
TechnologyN/asmallMEDIUM

Grizzly Ads is a technology startup offering an ad booking and management platform targeted at creative businesses and content creators. The platform is currently in beta, focusing on enabling creators to sell ad slots directly to sponsors with unlimited bookings and direct payments. The website reflects this early stage with clear but limited content and a focus on onboarding beta users. Technically, the site is built on the Bubble.io platform, leveraging modern JavaScript libraries and cloud hosting via AWS Cloudfront CDN. The site demonstrates moderate performance and good mobile optimization but lacks advanced SEO and accessibility features. The technical infrastructure is adequate for a startup but could benefit from enhanced security configurations. From a security perspective, the site uses HTTPS and has domain transfer protections but lacks DNSSEC and important security headers. There are no visible incident response or security policies, and cookie consent mechanisms are absent. Analytics usage is minimal, relying on plausible.io, which is privacy-focused. Overall, the security posture is moderate but requires improvements to meet best practices. The overall risk is moderate given the startup nature and limited exposure. Strategic recommendations include enabling DNSSEC, implementing security headers, adding cookie consent and privacy enhancements, and publishing incident response contacts to improve trust and compliance.

75
53
17
40
52
55
100
adbookingcreatorplatformbetatechnologybubbleio
Bubble.ioJavaScriptGoogle FontsSlim Select+2
2025-10-31T07:23:49.110Z
assemblag.es favicon

assemblag.es

assemblag.es

0
TechnologyN/asmallCRITICAL

assemblag.es operates as a niche Mastodon instance dedicated to individuals interested in creative and critical discussions about technology. The platform emphasizes a strong community code of conduct and privacy awareness, positioning itself as a thoughtful and moderated decentralized social media environment. The service is small-scale but maintains a clear focus on its target audience, leveraging the Mastodon and Hometown software stack to deliver its offerings. The website content is well-organized and professional, with clear administrative contact details and policies, although some standard compliance elements like cookie consent are missing. Technically, assemblag.es uses modern open-source technologies including Mastodon version 4.2.17 with the Hometown frontend, hosted via a CDN provider. The site is mobile-optimized and provides a good user experience, though accessibility and SEO optimizations are basic. Security posture is moderate with HTTPS implied but lacking explicit security headers and published security policies. The absence of WHOIS data due to registrar restrictions limits external verification of domain legitimacy, but the site content and operational transparency support trustworthiness. Security-wise, the platform enforces a strict code of conduct and privacy policy, but lacks formal incident response and vulnerability disclosure mechanisms. No tracking or advertising is present, enhancing privacy. The overall risk is moderate, with recommendations to improve security headers, cookie consent, and publish explicit security policies to strengthen compliance and user trust. Strategically, assemblag.es should focus on enhancing its security posture and privacy compliance to maintain and grow its user base in a competitive decentralized social media landscape.

-
-
-
-
-
-
-
mastodondecentralizedsocialmediatechnologyprivacy+1 more
Mastodon 4.2.17+hometown-1.1.2Hometown frontendJavaScriptCSS
2025-10-31T07:23:13.990Z
golangweekly.com favicon

Cooperpress

golangweekly.com

0
TechnologyN/asmallCRITICAL

Golang Weekly is a niche technology newsletter focused on the Go programming language, published by Cooperpress. It targets developers and enthusiasts interested in Go, providing weekly curated content and an RSS feed. The business model centers on subscription-based newsletter distribution, with a long-standing presence since 2012, indicating stable market positioning within its niche. The website branding is consistent and professional, supporting trust and engagement within its target audience. Technically, the website employs modern web technologies including Google Analytics, Google Tag Manager, and Cloudflare Turnstile CAPTCHA for form security. DNS hosting is managed via DNSimple, and the site uses standard HTML5, CSS, and JavaScript. Mobile optimization and SEO practices are good, though accessibility is basic. Performance is moderate, with no major technical debt or CMS detected. From a security perspective, the site uses HTTPS (implied by Google Analytics and Turnstile usage), includes CSRF protection on forms, and employs CAPTCHA to mitigate spam. However, DNSSEC is not enabled, and no explicit security headers or incident response policies are published. Privacy compliance is partially addressed with clear privacy and GDPR policies, but no cookie consent mechanism is present despite tracking scripts. No vulnerabilities or suspicious content were detected. Overall, the website presents a low-risk profile with good business credibility and technical implementation. Strategic improvements in security headers, cookie consent, and incident response transparency would enhance its security posture and compliance maturity.

-
-
-
-
-
-
-
newslettergolangprogrammingtechnologysubscription
Google AnalyticsGoogle Tag ManagerCloudflare Turnstile CAPTCHADNSimple DNS hosting+3
2025-10-31T07:22:48.928Z
gewexevents.org favicon

Global Energy and Water cycle Exchanges (GEWEX)

gewexevents.org

0
EnergyN/asmallHIGH

The Global Energy and Water cycle Exchanges (GEWEX) website serves as an informational and event platform for a core project under the World Climate Research Programme (WCRP). It focuses on scientific research related to Earth's water and energy cycles, providing resources, reports, and organizing meetings and webinars for the scientific community. The site targets researchers and professionals in climate science and related fields, positioning itself as a reputable non-profit scientific network. Technically, the website is built on WordPress 6.7.4, utilizing jQuery and Google Tag Manager for analytics. The site is moderately optimized for performance and mobile use, with basic accessibility and SEO features. Security is enforced through HTTPS, but lacks advanced security headers and cookie consent mechanisms, which could be improved for better compliance and protection. From a security perspective, the site shows no signs of vulnerabilities or malicious content. However, the absence of WHOIS data due to privacy or registry restrictions limits full domain trust verification. Contact information is clearly provided, and the site maintains a professional appearance with consistent branding and affiliation to recognized organizations. Overall, the website is trustworthy and serves its purpose well, but could benefit from enhanced privacy compliance and security best practices to strengthen its posture and user trust.

15
53
2
60
62
80
20
climateenergywatercyclescientificresearchevents+2 more
jQueryGoogle Tag ManagerWordPress 6.7.4

Partner Domains:

www.gewex.org
partner
www.wcrp-climate.org
partner
2025-10-31T07:21:43.733Z
clesto.com favicon

Codalex AB

clesto.com

0
OtherN/asmallHIGH

Clesto.com is a niche website dedicated to promoting and providing access to the Clesto board game, a simplified and engaging chess variant themed around jungle animals. The site offers educational content including rules, videos, notation, and an online play option, targeting children, teens, and adults interested in strategy games. The business behind the site is Codalex AB, a small entity with a domain registration dating back to 2006, indicating a stable online presence. Technically, the website is built on a simple HTML/CSS/JavaScript stack with Google Fonts and hosted behind Cloudflare DNS services. The site is mobile-optimized and provides a good user experience with clear navigation and relevant content. However, it lacks advanced technical frameworks or CMS beyond the N.nu generator. Performance is moderate, and accessibility is basic. From a security perspective, the site uses HTTPS but lacks DNSSEC and security headers, which are recommended for enhanced protection. No privacy or cookie policies are present, representing a compliance gap with GDPR and other privacy regulations. No contact or incident response information is provided, limiting transparency. The presence of a third-party tracking script (Redistats) indicates moderate user tracking without clear privacy disclosures. Overall, the website is functional and trustworthy with a good business credibility score but requires improvements in privacy compliance and security best practices to enhance user trust and regulatory adherence.

15
35
2
40
57
70
100
boardgamestrategygamechessvariantfamilygameonlineplay+3 more
HTML5CSS3Google Fonts (Merienda)JavaScript
2025-10-31T06:48:26.949Z
hostedpiwik.de favicon

Sign in - Matomo

hostedpiwik.de

0
TechnologyN/asmallMEDIUM

The website hostedpiwik.de serves as a login portal for the Matomo hosted analytics platform, a free/libre web analytics service. It primarily targets website owners and administrators who use Matomo for tracking and analyzing web traffic. The business model is SaaS-based, providing hosted analytics services leveraging the Matomo platform. The site is technically built using AngularJS and jQuery, hosted on German infrastructure, and employs HTTPS for secure communications. However, the site content is minimal, focusing solely on user authentication without public-facing business or legal information. From a security perspective, the site enforces HTTPS and includes basic anti-framing measures to prevent clickjacking. The login form uses POST method and includes nonce tokens, indicating some protection against CSRF. However, the absence of security headers and visible privacy or cookie policies indicates room for improvement in security posture and compliance. No WAF or blocking mechanisms were detected, and no vulnerabilities were apparent from the content. Overall, the site demonstrates a moderate level of technical maturity but lacks comprehensive privacy, security, and business transparency information. This limits trust and compliance confidence. Strategic improvements in security headers, privacy disclosures, and contact information would enhance the site's credibility and compliance stance.

35
25
25
70
72
60
100
analyticsmatomologinwebanalyticsprivacy
AngularJS (ng-app)jQuery (jquery.placeholder.js)Matomo analytics platformJavaScript+1
2025-10-31T06:34:00.002Z
esep-support.eu favicon

European School Education Platform Support

esep-support.eu

0
EducationN/amediumMEDIUM

The European School Education Platform Support website serves as an official support portal for the European School Education Platform, targeting school teachers and education professionals across Europe. It offers a comprehensive set of guides, knowledgebase articles, and release announcements to assist users in navigating and utilizing the platform effectively. The site is multilingual, supporting a wide range of European languages, enhancing accessibility for its diverse audience. The business model focuses on providing informational and support services rather than direct commercial transactions. Technically, the website is built on the DeskPRO helpdesk platform, leveraging modern web technologies including FontAwesome, Google Fonts, and polyfills for broad browser compatibility. The hosting provider is OVH SAS, a reputable European hosting company. The site demonstrates good mobile optimization, accessibility, and SEO practices, although performance is moderate. The technical infrastructure is solid but could benefit from additional security headers and enhanced privacy compliance features. From a security perspective, the site enforces HTTPS and uses secure login forms, indicating a baseline security posture. However, it lacks explicit security headers such as Content Security Policy and HSTS, and does not provide publicly accessible security policies or vulnerability disclosure mechanisms. No direct contact emails or phone numbers are provided, limiting direct communication channels. There are no signs of tracking or advertising scripts, which supports user privacy but also indicates limited analytics usage. Overall, the website is trustworthy and professional, serving its educational support purpose well. The main risks relate to the absence of privacy and cookie policies, lack of explicit security headers, and missing incident response information. Addressing these gaps would enhance compliance and security posture, further strengthening user trust and regulatory alignment.

60
10
17
60
52
80
100
educationsupporthelpdeskknowledgebaseguides+1 more
DeskPRO HelpcenterFontAwesomeGoogle FontsCSS Vars Ponyfill+3
2025-10-31T06:17:08.263Z