Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 565 of 579|Showing 28201-28250 of 28909
B

Burger King

bk.com

0
RetailN/aenterpriseHIGH

Burger King's website at bk.com presents a minimalistic digital presence primarily built using modern web technologies such as React Native Web and Expo Router, hosted on AWS infrastructure with CloudFront CDN. The site includes a cookie consent mechanism via OneTrust, indicating some level of privacy compliance effort. However, the website lacks visible content such as privacy policies, terms of service, or contact information, which limits user trust and transparency. From a security perspective, the site is undermined by the absence of a valid SSL certificate and HTTPS support, exposing users to potential risks. While security headers are properly configured, the lack of encryption and presence of a subdomain takeover vulnerability on dev.bk.com represent significant security concerns. The DNS and WHOIS data indicate legitimate domain registration consistent with the brand, but the subdomain issue requires urgent remediation. Overall, the website's technical infrastructure is modern but incomplete in critical areas such as security and content completeness. The lack of essential legal and contact information, combined with security vulnerabilities, results in a moderate to low trust level. Strategic improvements in SSL deployment, vulnerability mitigation, and content enrichment are necessary to enhance security posture and user confidence.

-
-
-
50
-
65
100
fastfoodburgerrestaurantreact-native-webexpo-router+3 more
React Native WebExpo RouterAmazon S3CloudFront+3
2025-06-15T22:11:08.287Z
pelstudio.com favicon

Pel

pelstudio.com

0
TechnologyN/asmallHIGH

Pel is a small, bicoastal creative collective specializing in digital design services including website creation, branding, online advertising, mobile applications, and digital video. The company targets businesses seeking high-quality digital creative solutions and positions itself as a niche player with a focus on design excellence and interactivity. The website content is professional and consistent with the brand identity, featuring an interactive pixel-catching game as a unique user engagement element. Technically, the website runs on an Apache server with PHP 8.2 and uses jQuery 3.3.1 along with Google Fonts and Google Analytics. However, the site lacks a valid SSL certificate, serving content over HTTP only, and DNS records are missing, which raises concerns about domain configuration and reliability. Performance data is incomplete but suggests slow loading. Mobile optimization and accessibility are basic but functional. From a security perspective, the absence of HTTPS and missing DNS records are critical vulnerabilities that significantly reduce the site's trustworthiness. No privacy, cookie, or terms of service policies are present, and no incident response or security frameworks are disclosed. Google Analytics is used for tracking, but no cookie consent mechanism is implemented, indicating poor privacy compliance. Overall, while the business content and branding are solid, the technical and security shortcomings present risks to user trust and data protection. Strategic improvements in SSL deployment, DNS configuration, and privacy compliance are essential to enhance the site's credibility and security posture.

-
-
-
50
-
50
40
creativeagencydigitaldesignbrandingwebdevelopmentinteractive+1 more
Apache 2.4.62PHP 8.2.28OpenSSL 3.2.2jQuery 3.3.1+2
2025-06-15T22:07:58.279Z
M

metacure.com

metacure.com

0
OtherN/asmallHIGH

The website metacure.com currently serves only a minimal HTML page that immediately redirects visitors to a /lander path, with no visible content, metadata, or business information. The domain is registered and resolves to IP addresses likely hosted on Amazon AWS, but lacks a valid SSL certificate and does not support HTTPS, exposing visitors to security risks. No privacy, cookie, or terms of service policies are present, and no contact or company information is available on the site. The technical infrastructure is minimal and lacks modern security and performance optimizations, resulting in a poor user experience and low trustworthiness. From a security perspective, the absence of HTTPS and security headers, combined with no DNSSEC or CAA records, indicates a weak security posture. The domain's DNS configuration is incomplete, with no valid MX records, which may affect email deliverability and trust. No analytics or tracking technologies are detected, suggesting minimal digital maturity. Overall, the site appears to be either under development, abandoned, or a placeholder with no active business presence. Given these findings, the overall risk level is high due to lack of encryption, absence of policies, and no verifiable business identity. Strategic recommendations include obtaining and configuring a valid SSL certificate, implementing security best practices such as HSTS and security headers, publishing privacy and cookie policies to comply with regulations, and providing clear contact and business information to improve credibility and trust.

15
15
5
50
-
70
100
2025-06-15T22:05:14.600Z
alexanderhughes.com favicon

Alexander Hughes

alexanderhughes.com

0
OtherN/alargeHIGH

Alexander Hughes is a well-established global executive search and leadership advisory firm with over 60 years of experience and a presence in more than 50 offices across 51 countries. The company specializes in attracting top leadership talent and providing governance, human capital assessment, succession planning, and interim executive services to global firms. Their website reflects a professional and comprehensive business model targeting corporate clients worldwide. Technically, the website is built on WordPress and leverages modern JavaScript libraries such as jQuery and Lightslider, with analytics powered by Matomo. Hosting is provided by Cloudways, and the site employs a strong Content Security Policy and other security headers. However, the SSL certificate is invalid or missing, and no modern TLS protocols are enabled, which significantly impacts the security posture. Security-wise, while some best practices like CSP and HSTS are implemented, the lack of valid HTTPS and TLS support is a critical vulnerability. No explicit security or incident response policies are found, and no contact emails or phone numbers are directly listed on the site, which may affect user trust. Privacy and cookie policies are present and appear GDPR compliant. Overall, the site is professionally designed with excellent content quality and user experience but requires urgent remediation of SSL/TLS issues to improve security and trustworthiness.

50
18
-
50
-
85
20
executivesearchleadershipadvisoryprofessionalservicesglobalconsultants+2 more
nginxjQueryLightsliderParallax.js+2

Partner Domains:

agence-mentalo.fr
partnerpending
2025-06-15T22:03:45.136Z
C

Canon Production Printing

oce.com

0
TechnologyN/alargeHIGH

Canon Production Printing operates as a global leader in the production printing industry, specializing in continuous-feed, cut-sheet, and large-format printers for high-volume and specialized printing applications. The company targets business and professional customers in printing, publishing, and display graphics sectors, leveraging a B2B manufacturing and technology solutions business model. The website reflects a strong market position with comprehensive product and corporate information, supported by active social media channels and a clear corporate identity. Technically, the website is built on WordPress with a modern theme and SEO tools, indicating a mature digital infrastructure. However, performance metrics are lacking, and the site shows moderate mobile optimization and basic accessibility features. Hosting is via Microsoft Azure DNS, and the site uses common JavaScript libraries and plugins. From a security perspective, the absence of a valid SSL certificate and HTTPS is a critical vulnerability, severely impacting the site's security posture. Additional security features such as HSTS, DMARC, DNSSEC, and advanced security headers are missing, exposing the site to potential risks. The site does implement cookie consent mechanisms and has a vulnerability disclosure policy, indicating some security awareness. Overall, while the business and content quality are excellent, the security shortcomings present significant risks. Strategic improvements in SSL/TLS deployment and security hardening are essential to protect the brand and user trust.

-
-
-
50
-
75
100
productionprintingtechnologycorporatemanufacturingb2b+2 more
WordPress 6.8.1jQuery 3.7.1Enfold ThemeYoast SEO Premium+2
2025-06-15T22:02:53.265Z