Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 543 of 579|Showing 27101-27150 of 28928
fatf-gafi.org favicon

Financial Action Task Force (FATF)

fatf-gafi.org

0
GovernmentN/alargeMEDIUM

The Financial Action Task Force (FATF) website serves as the global platform for the international standard-setting body focused on combating money laundering, terrorist financing, and proliferation financing. The site provides comprehensive resources including reports, guidance, mutual evaluations, and lists of high-risk jurisdictions, targeting governments, regulatory bodies, and financial institutions worldwide. The organization holds a strong market position as a trusted global watchdog with a large-scale presence and authoritative content. Technically, the website is built on Adobe Experience Manager hosted on Adobe AEM Cloud, leveraging modern web technologies and Google Tag Manager for analytics. The site demonstrates good performance, mobile optimization, and accessibility, with a professional and consistent branding approach. From a security perspective, the site enforces HTTPS and uses deferred and asynchronous script loading, but lacks explicit security headers and visible incident response or vulnerability disclosure policies. No WHOIS data was available to verify domain registration details, which slightly reduces trust but the content and domain name strongly indicate legitimacy. Overall, the site is content-rich, professionally designed, and highly credible, though it would benefit from enhanced privacy compliance, explicit contact information, and improved security header implementation to strengthen its security posture and user trust.

55
53
17
85
65
80
100
fatfanti-moneylaunderingterroristfinancingproliferationfinancingfinancialactiontaskforce+3 more
Adobe Experience ManagerGoogle Tag ManagerAdobe Helix RUM
2025-06-24T16:07:40.403Z
T

Twofold Health

trytwofold.com

0
HealthcareN/asmallMEDIUM

Twofold Health operates a specialized AI-driven medical scribe platform designed to automate and streamline clinical documentation for healthcare professionals such as therapists, physicians, and nurses. The company positions itself as a leading ambient AI solution trusted globally, offering a SaaS model with free, personal, and group subscription plans. Their platform emphasizes accuracy, compliance, and ease of use, targeting clinicians seeking to reduce administrative burden and improve patient care. Technically, the website is built using modern frameworks like Astro, hosted on Microsoft Azure with a strong focus on security and compliance. The site integrates advanced analytics tools including PostHog, Google Tag Manager, and social media pixels to monitor user engagement and optimize marketing efforts. The site is mobile-optimized, fast-loading, and well-structured for SEO. Security posture is robust with HIPAA and HITECH compliance, encrypted data handling, and no storage of audio recordings. The company maintains a formal Business Associate Agreement with Microsoft Azure and enforces internal security practices such as background checks and training. However, there is room for improvement in explicit security headers and cookie consent mechanisms. Overall, the website and business demonstrate a high level of professionalism and trustworthiness, though the absence of WHOIS domain registration data raises some concerns about domain legitimacy. Strategic recommendations include enhancing privacy compliance with cookie consent, publishing vulnerability disclosure policies, and improving transparency on incident response.

30
53
2
70
72
80
100
aimedicalscribehealthcaretechnologyhipaacompliantclinicaldocumentationmentalhealth+2 more
JavaScriptPostHog analyticsGoogle Tag ManagerFacebook Pixel+1
2025-06-24T16:05:24.890Z
colorize.design favicon

Extract Color Palettes from Any Website - Free Color Palette Generator

colorize.design

0
TechnologyN/asmallMEDIUM

The website 'colorize.design' is a newly launched online tool designed to extract color palettes from any website for free. It targets designers, developers, and creatives who need quick access to color schemes from existing web pages. The business model is straightforward, offering a free service without evident monetization or advertising. The site is built with modern web technologies including Tailwind CSS and is hosted with Cloudflare DNS services, indicating a focus on performance and reliability. The domain was registered very recently in July 2024 and uses privacy protection, which is typical for new startups or small online services. From a technical perspective, the website demonstrates good mobile optimization, fast loading times, and a clean design. However, it lacks several important compliance and security features such as privacy and cookie policies, security headers, and contact information. No analytics or tracking scripts were detected, which may be positive for user privacy but also limits business intelligence capabilities. Security posture is adequate with HTTPS enabled and domain status marked as OK, but the absence of DNSSEC and security headers reduces the overall security robustness. The lack of published incident response or vulnerability disclosure policies suggests limited readiness for security incidents. Business credibility is moderate due to the absence of verifiable company information or trust signals. Overall, the website is functional and professionally designed but requires improvements in privacy compliance, security best practices, and transparency to enhance trustworthiness and regulatory adherence.

55
35
2
70
75
60
100
colorpalettedesigntoolfreetoolwebdesigncolorextraction
Tailwind CSSCloudflare DNS
2025-06-24T16:05:04.840Z
skipcut.com favicon

SkipCut Team

skipcut.com

0
TechnologyN/asmallMEDIUM

SkipCut is a small technology-focused web service offering a free, ad-free YouTube player that works across multiple devices without requiring installation or login. It targets users seeking a clean, distraction-free YouTube viewing experience with features like SponsorBlock integration, playlist support, background audio playback, and dark mode. The business model relies on ethical partnerships, affiliate links, and community donations to sustain operations. Technically, SkipCut leverages modern web technologies including the official YouTube iframe API, Microsoft Clarity, Google Tag Manager, and Cloudflare DNS hosting. The site is well optimized for mobile and desktop with excellent SEO and accessibility features. Security posture is good with HTTPS enforced and domain transfer protection, but lacks visible security headers and formal security policies. Privacy compliance is limited due to absence of explicit privacy and cookie policies. WHOIS data shows some inconsistencies in domain creation date, which may be a data error but slightly impacts trust. Overall, SkipCut presents a professional, user-friendly service with strong technical foundations but would benefit from enhanced privacy and security documentation.

30
35
2
75
65
85
100
youtubewithoutadsadfreeyoutubeyoutubevideoplayeryoutubenocommercialsyoutubebackgroundplay+3 more
YouTube iframe APISponsorBlock integrationFont AwesomeMicrosoft Clarity+3

Partner Domains:

buymeacoffee.com
partner
t.me
partner
2025-06-24T16:04:54.749Z
qrtiger.com favicon

QR TIGER

qrtiger.com

0
TechnologyN/asmallMEDIUM

QR TIGER operates as a technology-focused online service specializing in QR code generation, including customized QR codes with logos. The website analyzed is a minimal landing page that directs users to the main service site and blog, indicating a supporting or redirect domain rather than a full-featured platform. The business appears to be a small-sized SaaS provider founded in 2019, targeting businesses and individuals needing QR code solutions. The market position is niche with a focus on QR code customization and related content. Technically, the website uses standard web technologies such as Bootstrap 4.1.1, FontAwesome, and Google Fonts, hosted behind Cloudflare DNS services. The site is mobile responsive at a basic level but lacks advanced SEO and accessibility features. No CMS or complex frameworks are detected, suggesting a lightweight and straightforward implementation. Performance is moderate given the minimal content. From a security perspective, the domain benefits from clientTransferProhibited status and Cloudflare DNS, but lacks visible security headers and privacy or cookie policies. No HTTPS status was explicitly provided but is assumed given Cloudflare usage. The absence of security policies, incident response contacts, and vulnerability disclosures indicates a low maturity in security governance. No forms or user data collection mechanisms are present to assess input security. Overall, the website presents a moderate risk profile with no critical security issues detected but notable gaps in privacy compliance and security best practices. Strategic improvements in security headers, privacy policies, and SEO would enhance trust and compliance. The domain WHOIS data is consistent and supports legitimacy, with no suspicious patterns or privacy protection masking registrant details.

15
35
2
75
75
75
100
qrcodeqrcodegeneratorqrtigertechnologysaas
Bootstrap 4.1.1FontAwesome 5.3.1Google Fonts (Merriweather)

Partner Domains:

www.qrcode-tiger.com
partner
2025-06-24T16:04:24.659Z
D

Force24 Portal

data-crypt.com

0
OtherN/asmallHIGH

The website 'Force24 Portal' appears to be a login portal for a service likely related to Force24, a company known for marketing automation solutions. The site is minimalistic with a focus on user authentication and integrates several third-party marketing and analytics tools such as Intercom, Microsoft Clarity, Appcues, Freshsuccess, and Datadog. However, there is a lack of publicly available business descriptive content, contact information, and legal policies such as privacy or cookie policies, which limits transparency and user trust. Technically, the site uses modern JavaScript frameworks and analytics platforms, indicating a moderate level of digital maturity. The performance and mobile optimization are basic but functional. Security posture is moderate with HTTPS enabled but lacking advanced security headers and explicit security policies. No vulnerabilities or exposed sensitive data were detected in the provided content. The WHOIS data for the domain platform.data-crypt.com is unavailable, with the raw WHOIS output indicating no match for the domain. This raises concerns about the domain's registration legitimacy or privacy protection usage. This lack of registration data negatively impacts the trustworthiness and business credibility scores. Overall, the site serves its purpose as a portal but lacks comprehensive business and privacy transparency. Strategic improvements in legal policy disclosures, contact availability, and security hardening are recommended to enhance trust and compliance.

40
35
17
50
-
80
100
loginportalauthenticationanalyticsmarketing+1 more
AngularJSAppcuesIntercomMicrosoft Clarity+4
2025-06-24T16:03:09.423Z
regprog.com favicon

Regular Programming

regprog.com

0
TechnologyN/asmallMEDIUM

The website 'Regular Programming' is a podcast platform focused on delivering conversations about programming topics, hosted by Lars Wikman and Andreas Ekeroot, and funded by Underjord.io. The site targets programmers and software developers interested in technology discussions. It operates primarily as a content distribution platform for podcast episodes, leveraging Transistor.fm for hosting and media delivery. The website presents a clean, consistent brand with good content quality and user experience, though it lacks comprehensive business and contact information. From a technical perspective, the site uses modern JavaScript frameworks such as Alpine.js and integrates with Transistor.fm's platform. The performance and mobile optimization are adequate, with basic accessibility features. However, the site lacks visible security headers and formal privacy or cookie policies, which are important for compliance and user trust. Security posture is moderate; no critical vulnerabilities or exposed sensitive data were detected, but the absence of security headers and incident response information indicates room for improvement. The lack of WHOIS data for the domain is a notable concern, reducing trustworthiness and raising questions about domain registration legitimacy. Overall, the site is functional and professional but would benefit from enhanced security practices, privacy compliance, and transparent business information to improve trust and compliance posture.

80
50
2
70
57
55
100
technologyprogrammingsoftwaredeveloperscode+5 more
JavaScriptAlpine.jsTransistor.fm podcast hosting
2025-06-24T16:03:04.414Z
beamrad.io favicon

Beam Radio

beamrad.io

0
TechnologyN/asmallMEDIUM

Beam Radio is a niche podcast platform focused on the Elixir programming language, Erlang, and the BEAM virtual machine ecosystem. It features a panel of expert hosts and delivers educational and conversational content to developers and enthusiasts interested in functional programming technologies. The business model is content-driven, supported by sponsorships from companies like Grox.io and Underjord. The website is professionally designed, with consistent branding and high-quality content that appeals to its target audience. Technically, the site is built on the Fireside CMS platform, leveraging modern web technologies such as Typekit fonts, FontAwesome icons, and Turbolinks for enhanced user experience. The site is served over HTTPS, ensuring secure communication. Performance and mobile optimization are good, though accessibility features are basic. SEO is well addressed with proper meta tags and Open Graph data. From a security perspective, the site enforces HTTPS and does not expose sensitive data in its HTML content. However, it lacks several security headers that could improve protection against common web attacks. There is no visible privacy policy, cookie consent mechanism, or contact information for security incidents, which are gaps in compliance and user trust. The WHOIS data is unavailable due to privacy protection, which is typical for small content sites and does not raise immediate concerns. Overall, Beam Radio presents a low-risk profile with strong content and technical foundations but would benefit from enhanced privacy compliance and security best practices to improve trust and regulatory adherence.

50
50
2
70
72
55
100
podcastelixirbeamerlangtechnology+1 more
Fireside CMSTypekit fontsFontAwesome iconsTurbolinks+1
2025-06-24T16:02:59.402Z
civo.com favicon

Civo

civo.com

0
TechnologyN/amediumMEDIUM

Civo is a cloud computing service provider specializing in Kubernetes-powered infrastructure and cloud native services. Their platform emphasizes speed, simplicity, and transparent pricing, targeting developers and businesses seeking efficient and scalable cloud solutions. Key offerings include managed Kubernetes, compute instances, managed databases, private cloud software, and GPU-powered machine learning environments. The company positions itself as an innovative alternative to traditional cloud providers with a focus on developer experience and sustainability. Technically, the website employs a modern tech stack with Google Tag Manager, Google Analytics, Facebook Pixel, HubSpot, Intercom, and Mouseflow for analytics and marketing. The site is well-optimized for performance, mobile responsiveness, and accessibility, with comprehensive SEO metadata and structured data. Security best practices are observed with HTTPS, reCAPTCHA on forms, and cookie consent mechanisms, although explicit security policies and incident response information are not published. The security posture is strong with no visible vulnerabilities or exposed sensitive data. Privacy compliance is good, with GDPR-aligned cookie consent and privacy policy. However, the absence of WHOIS data and domain registration details introduces a moderate trust concern. The website demonstrates high professionalism, clear navigation, and strong trust indicators such as customer testimonials and industry partnerships. Overall, Civo presents a credible and professional cloud service platform with a strong technical foundation and user-centric design. Strategic improvements include publishing detailed security policies, incident response contacts, and improving transparency around domain registration to enhance trustworthiness.

70
83
53
70
72
70
100
cloudcomputingkubernetesmanagedservicescloudnativemachinelearning+3 more
Google Tag ManagerGoogle AnalyticsFacebook PixelIntercom+3

Partner Domains:

www.relax.ai
partner
2025-06-24T16:02:49.381Z
givingpage.org favicon

FinDock

givingpage.org

0
TechnologyN/asmallMEDIUM

FinDock is a technology company specializing in providing payment page and form solutions integrated within Salesforce, enabling businesses to create seamless payment experiences and unify payment data within their CRM systems. The company operates primarily in the B2B SaaS space, targeting Salesforce users and organizations seeking efficient payment processing solutions. The website demonstrates a professional design with good content relevance and clear navigation, reflecting a mature digital presence consistent with a company founded in 2017. Technically, the website is built on WordPress using the Divi theme and several plugins including Yoast SEO and GDPR Cookie Compliance, indicating a modern and extensible infrastructure. The site is mobile optimized and performs moderately well, though accessibility features are basic. The domain is registered with a reputable registrar without privacy protection, and SSL is properly configured, enhancing trustworthiness. From a security perspective, the site uses HTTPS and implements cookie consent mechanisms, but lacks visible security headers and publicly available security policies or incident response contacts. No vulnerabilities or exposed sensitive data were detected in the analyzed content. The absence of privacy and terms of service documents is a compliance gap that should be addressed. Overall, FinDock's website presents a solid business and technical foundation with room for improvement in privacy compliance and security best practices. Strategic enhancements in these areas will strengthen trust and regulatory adherence, supporting the company's market position and growth.

45
85
22
70
77
65
100
paymentsalesforcecrmgivingpagesfintech+2 more
WordPressDivi ThemejQueryYoast SEO+2
2025-06-24T16:02:14.311Z
K

Koentopp Guitars

koentoppguitars.com

0
OtherN/asmallMEDIUM

Koentopp Guitars is a small artisanal business specializing in handcrafted guitars by luthier Dan Koentopp. The website serves as a showcase for their custom guitar offerings, testimonials, and blog content, targeting musicians and guitar enthusiasts seeking high-quality custom instruments. The business appears well-established with a domain age consistent with its founding year, positioning itself as a niche player in the custom guitar market. Technically, the website uses a basic but functional technology stack including HTML5, CSS3, jQuery 1.9.1, and Bootstrap for UI components like the carousel. Hosting is provided by GoDaddy. The site shows moderate performance and basic mobile optimization but lacks advanced SEO and accessibility features. No CMS is detected, suggesting a custom or static site build. From a security perspective, the site uses HTTPS but lacks important security headers such as Content-Security-Policy and HSTS. DNSSEC is not enabled, and no privacy or cookie policies are present, indicating compliance gaps with GDPR and other privacy regulations. Forms exist for newsletter subscription but no explicit security controls are visible. Contact information is clearly provided, enhancing trust. Overall, the website is functional and professional but could improve significantly in privacy compliance and security posture. Strategic improvements in these areas would reduce risk and enhance user trust.

65
35
2
70
67
75
100
handmadeguitarsluthiercustomguitarsmusic+1 more
HTML5CSS3JavaScriptjQuery 1.9.1+1
2025-06-24T14:58:50.903Z
G

Gitte Klitgaard

nativewired.com

0
OtherN/asmallHIGH

The website nativewired.com serves as the personal homepage for Gitte Klitgaard, focusing on consulting, speaking engagements, and workshops aimed at helping individuals and organizations achieve growth and development. The site positions itself as a niche personal and organizational development resource with a small business model. The content is well-structured and professionally presented, though it lacks comprehensive privacy and security policies. Technically, the site is built on WordPress using the Twenty Sixteen theme, leveraging jQuery and standard web technologies. The hosting provider is not explicitly identified, but DNS servers indicate a Polish hosting environment. Performance and mobile optimization are moderate, with basic accessibility and SEO features implemented. From a security perspective, the site uses HTTPS but lacks DNSSEC and security headers, which are recommended for enhanced protection. No privacy or cookie policies are present, and no incident response or vulnerability disclosure information is provided. The WHOIS data indicates a stable and legitimate domain registration with no privacy protection, consistent with the business age and nature. Overall, the site is functional and professional but would benefit from improved privacy compliance, enhanced security headers, and clearer contact information to increase trust and security posture.

15
50
2
70
62
55
20
personalconsultingspeakingworkshopswordpress
WordPressjQueryPHP
2025-06-24T13:48:10.736Z
appfigures.com favicon

Appfigures

appfigures.com

0
TechnologyN/amediumMEDIUM

Appfigures is a mature and reputable technology company founded in 2009, specializing in app analytics, App Store Optimization (ASO) tools, and competitive app intelligence. The company serves a broad audience including app developers, publishers, investors, and analysts, offering a SaaS platform with both free and paid subscription plans. Their market position is strong, trusted by over 200,000 companies worldwide, and they provide a comprehensive suite of services to optimize app performance and growth. Technically, the website is well-constructed using modern web technologies and hosted on AWS infrastructure with CDN support for fast performance. The site integrates multiple analytics and marketing tools such as Google Analytics, Matomo, Clearbit, and Crisp Chat, indicating a mature digital marketing and analytics strategy. The website is mobile-optimized, accessible, and SEO-friendly, with clear navigation and professional design. From a security perspective, the site enforces HTTPS and employs domain status locks to protect against unauthorized domain changes. However, DNSSEC is not enabled, and there is no publicly available dedicated security policy or incident response information. Privacy compliance is partially addressed with a comprehensive privacy policy and terms of service, but lacks a cookie consent mechanism, which could be a GDPR compliance gap. Overall, Appfigures presents a low-risk profile with strong business credibility and technical maturity. Strategic improvements in privacy compliance and security transparency would further enhance trust and regulatory adherence.

75
53
17
85
62
85
100
appanalyticsasotoolsappintelligencemobileappsappstoreoptimization+4 more
Google AnalyticsMatomoClearbitCrisp Chat+5
2025-06-24T13:47:35.590Z
B

Boardio

boardio.com

0
OtherN/asmallMEDIUM

Boardio is a platform that connects companies with a global network of over 10,000 advisors and board members to facilitate market entry, funding access, and strategic growth. The business model is success-based, charging companies only when collaborations with advisors commence. The website presents a professional and modern interface, targeting growth companies seeking expert advisory services worldwide. The platform emphasizes flexibility, cost-effectiveness, and global reach with presence in over 110 countries. Technically, the website employs modern frontend technologies including Tailwind CSS, Alpine.js, and Livewire, supported by Google Analytics and Tag Manager for analytics. Hosting appears to be via Cloudflare, ensuring good performance and security. The site is mobile-optimized and accessible with clear navigation and structured content. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms aligned with privacy best practices. However, explicit security headers like Content-Security-Policy are not evident, and no dedicated security or incident response policies are published. The absence of WHOIS registration data is a notable concern, potentially indicating privacy protection or data unavailability, which impacts domain trustworthiness. Overall, the website is well-designed and functional with good business credibility but would benefit from enhanced transparency in domain registration and security policies to improve trust and compliance posture.

15
50
2
75
75
80
100
advisorsboardmembersmarketentryfundingbusinessgrowth+2 more
JavaScriptTailwind CSSAlpine.jsLivewire+2
2025-06-24T13:46:50.386Z
Y

Attention Required! | Cloudflare

yeu88.games

0
OtherN/asmallHIGH

The website www.yeu88.games is currently inaccessible due to a Cloudflare Web Application Firewall (WAF) block, which prevents any meaningful content or business information from being retrieved or analyzed. The page presented is a standard Cloudflare security challenge page indicating that the visitor has been blocked, likely due to security rules triggered by the request. No metadata, structured data, or contact information is available, and the WHOIS data query returned a malformed response, providing no registrant or domain registration details. This severely limits the ability to assess the legitimacy, business model, or security posture of the site. From a technical perspective, the site is protected by Cloudflare, which provides security and performance services, but the block indicates either suspicious activity or misconfiguration. No other technologies, CMS, or frameworks are detectable due to the lack of accessible content. The absence of privacy policies, cookie consent mechanisms, or terms of service further reduces compliance and trustworthiness. Security-wise, the inability to access the site prevents a full security assessment. The presence of Cloudflare indicates some level of security infrastructure, but the lack of visible security headers or policies and the WHOIS data unavailability raise concerns. The domain's legitimacy cannot be verified, and the overall risk is high due to these unknowns. Overall, the site scores very low on content quality, technical implementation, security posture, privacy compliance, and business credibility due to the blocking and lack of data. Strategic recommendations include resolving the Cloudflare block to allow legitimate access, publishing clear privacy and cookie policies, providing contact and incident response information, and ensuring proper WHOIS data availability for trust verification.

35
35
2
60
57
75
100
Cloudflare
2025-06-24T13:45:35.153Z