Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 562 of 579|Showing 28051-28100 of 28909
patchstack.com favicon

Patchstack

patchstack.com

0
TechnologyN/amediumMEDIUM

Patchstack is a leading technology company specializing in open-source vulnerability intelligence and security solutions for WordPress ecosystems. Their platform offers comprehensive services including virtual patching, managed vulnerability disclosure programs, bug bounty initiatives, and compliance support for emerging regulations such as the Cyber Resilience Act. Positioned as a market leader, Patchstack targets web developers, hosting providers, plugin developers, and security researchers, providing them with tools to proactively mitigate vulnerabilities and enhance security posture. The website is built on a modern WordPress infrastructure enhanced with Oxygen builder, Alpine.js, GSAP animations, and integrates advanced analytics and consent management tools. The technical implementation reflects a mature digital presence with fast performance, mobile optimization, and strong SEO practices. Hosting is inferred to be via Cloudflare, providing additional security and performance benefits. Security posture is robust, with enforced HTTPS, bot management, cookie consent with granular controls, and sanitization measures to prevent common web vulnerabilities. While explicit security policies and incident response contacts are not prominently published, the platform demonstrates a strong commitment to security through its bug bounty program and vulnerability database. Overall, Patchstack presents a trustworthy and professional online presence with a high level of technical and security maturity. Strategic recommendations include publishing detailed security policies, incident response procedures, and security.txt files to further enhance transparency and trust.

55
83
43
70
77
80
100
wordpresssecurityvulnerabilitymanagementbugbountycompliance+2 more
WordPressYoast SEO pluginOxygen builderjQuery+6
2025-06-18T08:27:17.865Z
happypay.com favicon

Dan.com an Undeveloped BV subsidiary

happypay.com

0
TechnologyN/amediumHIGH

Dan.com operates as a domain marketplace platform specializing in the buying, selling, leasing, and renting of domain names. The platform emphasizes secure transactions through its Buyer Protection Program, fast domain ownership transfers, and integration with trusted payment processors like Adyen. The website content is professionally presented with clear navigation and a focus on trust and security, targeting domain investors, businesses, and individuals interested in domain trading. The platform is a subsidiary of Undeveloped BV, with a domain history dating back to 2003, indicating a mature presence in the domain marketplace industry. Technically, the website employs modern JavaScript libraries, Google reCAPTCHA v3 for bot protection, and Google Tag Manager for analytics and marketing. The site is mobile-optimized and uses secure payment integrations. However, explicit security headers are not visible in the provided data, and no cookie consent mechanism is present despite a cookie policy page. The technical implementation is solid but could benefit from enhanced security header configurations and improved privacy compliance features. From a security perspective, the platform demonstrates good practices including secure payments, buyer protection with refund guarantees, and form protection via reCAPTCHA. There are no visible vulnerabilities or exposed sensitive data. However, the absence of incident response contact information and security headers suggests room for improvement in transparency and defense-in-depth. Overall, the security posture is good but not exemplary. The overall risk assessment is moderate with a strong business credibility and technical foundation. Strategic recommendations include implementing security headers, adding explicit incident response contacts, and introducing a cookie consent mechanism to enhance GDPR compliance and user trust. These improvements will strengthen the platform's security posture and regulatory adherence, supporting its market position as a trusted domain marketplace.

15
43
-
40
-
75
100
domainsalesdomainmarketplacebuyerprotectionsecurepaymentsdomainleasing+1 more
Google reCAPTCHAGoogle Tag ManagerAdyen payment processorSVG4Everybody+3

Partner Domains:

undeveloped.com
parent
adyen.com
partner
2025-06-18T08:07:10.597Z
continent8.com favicon

Continent 8

continent8.com

0
TechnologyN/alargeMEDIUM

Continent 8 is a well-established global service provider specializing in managed hosting, connectivity, cloud, and cybersecurity solutions primarily targeting the iGaming and regulated markets. With over 25 years of experience and a presence in more than 100 locations worldwide, the company positions itself as a trusted technology and security partner for major online sports betting and gaming brands. Their service portfolio includes resilient network connectivity, cloud solutions including AWS, and comprehensive cybersecurity offerings such as DDoS protection, managed endpoint security, and compliance audits. Technically, the website is built on WordPress with modern frameworks like Bootstrap and integrates advanced marketing and analytics tools such as HubSpot and Google Analytics. The site demonstrates good SEO practices, mobile optimization, and a professional design that supports a positive user experience. Performance is moderate, with room for improvement in accessibility features. From a security perspective, the site enforces HTTPS and employs a robust cookie consent mechanism compliant with GDPR and CCPA regulations. However, explicit security policies and incident response information are not publicly detailed, and HTTP security headers are not visibly implemented. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website and business exhibit a high level of professionalism, trustworthiness, and compliance. Strategic recommendations include enhancing security transparency by publishing dedicated security policies, implementing security headers, and providing clear incident response contacts to further strengthen their security posture and trust with clients.

50
75
43
80
-
80
100
hostingcybersecuritycloudigamingconnectivity+5 more
WordPressYoast SEO PremiumBootstrap 5Swiper.js+5
2025-06-18T08:07:10.524Z
C

DNS resolution error | crowecw.im | Cloudflare

crowecw.im

0
OtherN/asmallHIGH

The website crowecw.im is currently inaccessible due to a DNS resolution error as indicated by the Cloudflare error page. This suggests that the domain is either newly registered and not fully propagated or misconfigured at the DNS level. No actual business content, policies, or contact information is available on the site, preventing any meaningful analysis of the company's operations or services. The site relies on Cloudflare for DNS and security services but is currently blocked from public access. From a technical perspective, the site uses Cloudflare's infrastructure and includes JavaScript for error feedback reporting. However, no CMS, frameworks, or additional technologies are detected. The site lacks HTTPS content delivery, security headers, or any SEO or accessibility optimizations. The overall digital maturity is very low. Security posture is weak due to the lack of HTTPS, absence of security headers, and no visible privacy or incident response policies. The DNS resolution failure itself is a critical issue preventing access and undermining trust. No contact or business information is provided, which further reduces credibility and compliance confidence. Overall, the site is non-functional and presents a high risk from a security and business credibility standpoint. Strategic remediation should focus on resolving DNS issues, establishing secure HTTPS delivery, publishing privacy and security policies, and providing clear business contact information to improve trust and compliance.

35
10
-
55
-
80
100
errorcloudflarednsblockedsecurity
CloudflareJavaScriptXMLHttpRequest
2025-06-18T08:07:09.452Z
diy.org favicon

DIY.ORG - Where every kid is a maker & creator!

diy.org

0
EducationN/amediumMEDIUM

DIY.org is a well-established online educational platform focused on providing a safe and engaging community for kids to learn creative skills through hands-on projects, video challenges, and courses. The platform targets children and families, offering a subscription-based model with a free trial to encourage skill development in areas such as art, coding, and gaming. The website demonstrates a strong market position with over 500,000 families trusting the service and more than 2 million projects completed. Technically, the site is built on modern web technologies including React and Next.js, with integrations for Stripe payments and analytics tools like PostHog and Google Tag Manager. The site is optimized for performance and mobile responsiveness, providing an excellent user experience with clear navigation and professional design. From a security perspective, the website enforces HTTPS, employs security headers, and avoids exposing sensitive data. However, it lacks publicly available security policies, incident response plans, and vulnerability disclosure mechanisms, which are recommended for enhanced transparency and trust. Privacy compliance is generally good, with a comprehensive privacy policy present, though a visible cookie consent mechanism is missing. Overall, DIY.org presents a trustworthy and professional online learning environment for kids, with strong content quality and technical implementation. Strategic improvements in privacy consent and security transparency would further strengthen its security posture and compliance.

35
28
5
85
-
60
100
educationkidslearningcreativecommunity+4 more
ReactNext.jsStripePostHog analytics+2
2025-06-18T08:07:09.444Z
P

Security Verification

prospero.im

0
OtherN/asmallHIGH

The website at prospero.im currently serves as a security verification gateway, employing Google reCAPTCHA v3 to prevent automated access. This indicates a protective measure likely implemented to mitigate bot traffic or abuse. Due to this gating, the actual business content is inaccessible, limiting the ability to analyze the company's services, market position, or detailed business information. The page itself is minimal, containing only the necessary elements to perform the CAPTCHA verification, with no visible contact information, policies, or branding elements. Technically, the site uses modern frontend technologies such as Bootstrap 5.3.3 and Google's reCAPTCHA service, indicating some level of technical maturity in terms of frontend frameworks and security tooling. However, the absence of visible security headers and metadata suggests room for improvement in security hardening and SEO optimization. The performance is likely moderate given the use of CDN-hosted resources, but the user experience is limited due to the blocking verification step. From a security posture perspective, the use of reCAPTCHA is a positive indicator of bot mitigation efforts. However, the lack of visible security policies, contact channels for incident response, and absence of privacy or cookie policies highlight compliance gaps. The domain registration is privacy protected, which is common but reduces transparency and trustworthiness. No suspicious patterns were detected, but the limited data restricts a full trust assessment. Overall, the site scores low on content quality, business credibility, and privacy compliance due to the blocking mechanism and lack of visible information. Strategic recommendations include removing or minimizing the gating for legitimate users, publishing comprehensive privacy and cookie policies, adding clear contact and business information, and enhancing security headers and SEO features to improve trust and compliance.

15
25
-
85
-
25
100
securitycaptchabotprotectionverificationrecaptcha
Bootstrap 5.3.3Google reCAPTCHA v3
2025-06-18T08:07:09.390Z
O

Ocorian

ocorian.com

0
FinanceN/alargeMEDIUM

Ocorian is a globally recognized leader in fund administration, compliance, corporate, and fiduciary services, serving over 8,000 clients worldwide with a workforce exceeding 1,800 employees across more than 20 countries. The company offers a broad range of specialized services including fund administration, capital markets support, corporate services, and regulatory compliance solutions, targeting asset managers, financial institutions, corporates, high net-worth individuals, and family offices. Their business model emphasizes trusted partnerships, global scale with local expertise, and technology-enabled service delivery. Technically, the website is built on Drupal 10 and integrates advanced marketing and analytics tools such as HubSpot, Google Analytics, Hotjar, and LinkedIn Insight Tag. The site demonstrates good performance, excellent mobile optimization, and strong SEO and accessibility features. Security-wise, the site enforces HTTPS, employs cookie consent mechanisms compliant with GDPR, and uses reputable third-party services, although explicit security headers could be further verified. The security posture is robust with no visible vulnerabilities or exposed sensitive data. The company maintains compliance with privacy regulations, evidenced by comprehensive privacy and cookie policies and active consent management. Overall, the website reflects a mature, professional, and trustworthy digital presence aligned with the company's market position. Strategically, Ocorian should continue to enhance security header implementations, publish explicit security and incident response policies, and maintain vigilance over third-party integrations to sustain its strong security and compliance posture.

50
70
5
73
-
75
100
fundadministrationcompliancecorporateservicescapitalmarketsprivateclient+5 more
Drupal 10HubSpotGoogle Tag ManagerGoogle Analytics+6
2025-06-18T08:07:09.076Z
alinda.com favicon

Astatine Investment Partners

alinda.com

0
TransportationN/amediumHIGH

Astatine Investment Partners is a private equity firm specializing in mid-market infrastructure investments and equipment leasing. The company positions itself as a leading player in this niche, targeting investors and infrastructure market participants. Their website reflects a professional and consistent brand image with a focus on delivering value through innovative investment strategies. The business model centers on private equity investments in infrastructure sectors, supported by a medium-sized organizational footprint and a founding date of 2022. Technically, the website is built on WordPress with modern SEO practices implemented via the Yoast SEO plugin. The site uses jQuery and Google Fonts, and it demonstrates good mobile optimization and moderate performance. Accessibility is basic but functional, and SEO optimization is good. Hosting details are not explicitly disclosed. From a security perspective, the site uses HTTPS with good SSL configuration but lacks several recommended security headers. There is no visible security policy or incident response contact information, and no vulnerability disclosure mechanism is present. No exposed sensitive data or vulnerable libraries were detected. Privacy compliance is partial, with a comprehensive privacy policy present but no cookie consent mechanism. Overall, the website is trustworthy and professionally maintained, with a strong business credibility score. Recommendations include enhancing security headers, adding cookie consent for GDPR compliance, publishing security policies, and implementing a vulnerability disclosure process to improve the security posture and compliance maturity.

25
28
-
70
-
80
100
privateequityinfrastructureinvestmentequipmentleasingfinance
WordPressYoast SEOjQueryGoogle Fonts
2025-06-18T08:07:09.075Z
10eqs.com favicon

10EQS

10eqs.com

0
OtherN/amediumHIGH

10EQS is a professional services firm specializing in providing on-demand strategic insights and expertise through virtual teams of industry experts. The company serves a diverse clientele including Fortune 500 companies, investment firms, and SMEs, delivering high-quality consulting services such as market assessment, customer insights, benchmarking, technology landscape analysis, M&A due diligence, and partner assessment. Recognized by the Financial Times and Statista as a leading consulting network, 10EQS positions itself as a fast, efficient, and quality-driven alternative to traditional consulting models. Technically, the website is built on WordPress with modern frameworks like Bootstrap and integrates multiple marketing and analytics tools including Google Analytics, HubSpot, and Facebook Pixel. The site is mobile optimized and SEO friendly, though performance is moderate. Security posture is adequate with HTTPS enforced, but lacks some recommended security headers, which could expose the site to certain web vulnerabilities. From a security perspective, the site does not show signs of WAF or blocking mechanisms and does not expose sensitive data. However, improvements in security headers and explicit incident response policies would enhance the security maturity. Privacy compliance is good with a clear privacy policy and cookie consent mechanisms, but no visible terms of service or vulnerability disclosure policy. Overall, 10EQS presents a credible and professional online presence with strong business credibility and trust indicators. Strategic recommendations include enhancing security headers, publishing terms of service, and providing clearer contact information to improve user trust and compliance.

15
43
5
70
-
70
40
consultingmarketintelligenceprofessionalservicesbusinesssolutionsvirtualteams+1 more
WordPress 6.6.2Bootstrap 4.2.1jQuery 3.7.1Swiffy Slider 1.5.3+5

Partner Domains:

10eqs.apps.10eqs.com
service
www.ft.com
partner
2025-06-18T08:07:09.045Z