Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 23 of 24|Showing 1101-1150 of 1153
copolad.eu favicon

Copolad

copolad.eu

0
GovernmentSpainmediumHIGH

Copolad is a government and non-profit cooperation program focused on drug policy collaboration between Latin America, the Caribbean, and the European Union. The website serves as an information portal offering news, publications, training, and event details to stakeholders involved in drug policy. The business model is based on international cooperation funded by the EU and partner organizations, positioning Copolad as a reputable program in its sector. Technically, the website is built on WordPress with multiple plugins and frameworks including WP Rocket, WPML for multilingual support, and various marketing and analytics tools such as Google Analytics and Mailchimp. The site is hosted by Arsys Internet S.L.U. but suffers from slow load times and lacks a valid SSL certificate, which impacts security and user trust. From a security perspective, the absence of a valid SSL certificate is a critical vulnerability, exposing users to potential data interception. No security headers or incident response policies are evident, indicating room for significant improvement in security posture. Privacy and cookie policies are present and appear comprehensive, supporting GDPR compliance. Overall, while the website provides valuable content and maintains good business credibility, the lack of HTTPS and security best practices lowers its security score and user trust. Strategic improvements in SSL deployment, security headers, and incident response readiness are recommended to enhance the site's security and compliance standing.

15
18
17
50
50
85
100
governmentnon-profitdrugpolicyinternationalcooperationeu+3 more
WordPressPHPjQueryWP Rocket+8

Partner Domains:

fiiapp.org
partner49
iila.org
partner38

+2 more partners

2025-06-15T10:15:43.937Z
C

Consorci Administració Oberta De Catalunya

seu-e.cat

0
GovernmentSpainmediumMEDIUM

EACAT is a mature government-operated digital platform serving the Catalan public administrations by providing electronic administration services and facilitating inter-administrative communication. The platform targets public sector entities within Catalonia and has been operational for over 15 years, reflecting a stable market position within the regional government sector. The website content and branding are consistent with official government services, supported by domain registration details matching the registrant organization and country. Technically, the website employs legacy JavaScript libraries such as jQuery 1.8.2 and Modernizr 2.6.2, with backend technologies based on Microsoft Visual Studio .NET and C#. Hosting is via Amazon AWS DNS infrastructure. Performance is suboptimal with a slow load time and large page size. Mobile optimization and accessibility are basic, and SEO practices are minimal. The site lacks a CMS and uses custom-built code. From a security perspective, the site has critical deficiencies including the absence of a valid SSL/TLS certificate, no HTTPS support, and no security headers. DNS records show valid SPF and DMARC configurations, but CAA records are malformed. No incident response or security policy information is provided. Sensitive login forms transmit credentials without encryption, posing significant risk. Privacy compliance is weak, with no cookie consent mechanism despite use of tracking scripts like Google Tag Manager and Lucky Orange. Overall, the website presents moderate business credibility as a government service but suffers from critical security and privacy shortcomings. Immediate remediation of SSL/TLS configuration and implementation of security best practices is essential to protect user data and maintain trust. Enhancing privacy compliance and modernizing technical infrastructure would further improve the platform's digital maturity and user experience.

15
25
17
60
75
70
100
governmente-administrationcataloniapublicservicesauthentication
JavaScriptjQuery 1.8.2Modernizr 2.6.2Google Tag Manager+2
2025-06-15T10:01:56.556Z
atm.cat favicon

Generalitat de Catalunya

atm.cat

0
TransportationSpainmediumMEDIUM

Autoritat del Transport Metropolità (ATM) is a public consortium under the Generalitat de Catalunya, managing integrated transport tariffs and mobility projects in the Barcelona metropolitan area. The website serves as an official portal providing comprehensive information about transport tariffs, mobility plans, transparency, and customer support. It targets residents and public transport users in Catalonia, offering multilingual content and links to related government services. The business model is public sector focused, emphasizing transparency and service delivery rather than commercial revenue. Technically, the website is built on the Liferay CMS platform with modern web technologies including React and Bootstrap. While the site is content-rich and accessible, performance is hindered by a high load time and large page size. The site is mobile optimized and includes accessibility features. SEO and metadata are well implemented, including Open Graph tags. Security posture is adequate with HTTPS enforced, valid SSL certificates, and email authentication via DMARC and SPF. However, advanced security headers like HSTS and DNSSEC are missing, and domain protection locks are not enabled, which could be improved. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with clear cookie and privacy policies and consent mechanisms. Overall, the site is trustworthy and professionally maintained, reflecting its governmental nature. Recommendations include enhancing security headers, enabling DNSSEC, improving performance, and adding explicit security and incident response policies to further strengthen trust and compliance.

65
25
25
50
92
70
100
transportpublicsectormobilitygovernmentcatalonia+2 more
Liferay PortaljQueryBootstrapFont Awesome+9
2025-06-15T09:59:21.656Z
G

Generalitat de Catalunya

gencat.net

0
GovernmentSpainlargeMEDIUM

The website gencat.net serves as an official domain for the Generalitat de Catalunya, the regional government of Catalonia, Spain. However, the site itself contains only a minimal HTML page that immediately redirects visitors to the main government portal at web.gencat.cat. This indicates that gencat.net functions primarily as a redirect domain rather than a content-rich site. The domain is mature, registered since 2000, and aligns with the official government entity, supporting its legitimacy. The target audience includes Catalan citizens and others seeking official government information. From a technical perspective, the site is hosted on an Apache server but lacks modern security and performance features. Critically, there is no SSL/TLS certificate configured, resulting in unencrypted HTTP traffic. The site does not implement DNSSEC, HSTS, or security headers, and no privacy or cookie policies are present. The minimal content and lack of technical sophistication suggest low digital maturity and poor user experience. Security posture is weak due to the absence of HTTPS and security best practices, exposing users to potential interception risks. The lack of privacy compliance measures and contact information further reduces trust and compliance with regulations such as GDPR. Despite these issues, the domain's WHOIS data is consistent and trustworthy, registered to a reputable registrar with no privacy protection, which is appropriate for a government domain. Overall, the website's primary function as a redirect limits its content and utility. Strategic improvements should focus on securing the domain with HTTPS, enhancing security headers, and providing clear privacy and contact information to improve trust and compliance.

15
40
25
55
100
65
100
governmentredirectminimalcontentnosslofficial
Apache
2025-06-15T09:58:56.172Z
guggenheim-bilbao.eus favicon

FUNDACION DEL MUSEO GUGGENHEIM BILBAO

guggenheim-bilbao.eus

0
Non-profitSpainlargeHIGH

The Museo Guggenheim Bilbao is a prominent non-profit cultural institution based in Bilbao, Spain, managed by the FUNDACION DEL MUSEO GUGGENHEIM BILBAO. The website serves as a comprehensive portal for visitors to plan their visits, explore exhibitions, and access educational resources. It targets a broad audience interested in art, culture, and museum experiences. The museum holds a strong market position as an internationally recognized art venue with strategic partnerships and sponsorships from government and corporate entities. Technically, the website leverages modern web technologies including Next.js and React, with a headless WordPress CMS backend. It integrates accessibility tools and multimedia content hosted on Vimeo. The site is mobile-optimized and SEO-friendly, providing a good user experience and navigation clarity. From a security perspective, the site currently lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability impacting user trust and data security. Other security headers and best practices are partially implemented, but the absence of HTTPS significantly lowers the security posture. Overall, the website is professionally designed and content-rich, but the lack of HTTPS is a major risk. Strategic recommendations include immediate SSL/TLS deployment, enabling HSTS, and improving certificate management to enhance security and user trust.

15
25
25
50
50
70
-
museumartcultureeducationnon-profit+2 more
Next.jsReactJavaScriptVimeo (video hosting)+2

Partner Domains:

guggenheim.org
parentpending
guggenheim-venice.it
sisterpending
2025-06-15T09:03:17.984Z
paeria.cat favicon

AJUNTAMENT DE LLEIDA

paeria.cat

0
GovernmentSpainlargeMEDIUM

The website paeria.cat is the official digital presence of the Ajuntament de Lleida, the municipal government of Lleida, Spain. It serves as a comprehensive portal for residents and visitors to access city information, municipal services, online procedures, news, events, and citizen participation platforms. The site is well-positioned as a trusted government resource with a broad range of public services and cultural content. Technically, the website is built on the Plone CMS platform, leveraging modern web technologies such as jQuery, Owl Carousel, and Google Fonts, hosted on Microsoft Azure infrastructure. While the site offers good accessibility and SEO features, its performance is somewhat slow due to a large page size and high resource count. Security posture is solid with HTTPS enforced using TLS 1.3 and 1.2, OCSP stapling, and valid SPF and DMARC DNS records. However, improvements are recommended in enabling HSTS, DNSSEC, domain protection locks, and additional security headers. Privacy compliance is strong with clear privacy and cookie policies and GDPR adherence. Contact information is readily available, including phone numbers, physical address, and online forms, complemented by active social media channels. Overall, the website demonstrates a mature, professional, and trustworthy government digital service with room for technical and security enhancements.

75
25
25
80
87
70
100
governmentmunicipalpublicservicesplonecatalan+5 more
Plone CMSjQueryOwl CarouselKlaro (cookie consent)+4

Partner Domains:

gencat.cat
partneranalyzing...
moventis.es
partnerpending

+3 more partners

2025-06-15T09:02:22.882Z
ree.es favicon

Red Eléctrica

ree.es

0
EnergySpainlargeHIGH

Red Eléctrica is the Spanish Transmission System Operator (TSO) responsible for the operation, development, and maintenance of the national electricity grid. The company plays a critical role in ensuring the quality and security of electricity supply across Spain and supports the country's ecological transition by integrating renewable energy sources and developing infrastructure projects. The website reflects a mature digital presence with comprehensive content, clear navigation, and professional design, targeting energy sector stakeholders and the general public interested in electricity data and sustainability. Technically, the site is built on Drupal 10 with modern front-end libraries and uses Akamai and Imperva for DNS and CDN services. However, a critical security shortcoming is the absence of a valid SSL certificate and proper HTTPS configuration, which significantly impacts the site's security posture. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Business credibility is strong, supported by consistent branding, corporate governance links, and trust signals. Overall, the site scores well in content and business credibility but requires urgent improvements in SSL/TLS security to enhance trust and protect users.

30
-
25
75
50
80
100
energyelectricitytransmissionsustainabilityecologicaltransition+3 more
Drupal 10Bootstrap 5.3.1HighchartsFont Awesome 4.3.0+5

Partner Domains:

redeia.com
parent68
2025-06-14T19:28:10.925Z
dekra-certification.es favicon

DEKRA Certificación

dekra-certification.es

0
OtherSpainlargeMEDIUM

DEKRA Certificación is a leading European certification body accredited by ENAC, specializing in audits and certifications across quality, environmental management, occupational health and safety, sustainability, and cybersecurity sectors. The company offers a broad portfolio of certifications including ISO 9001, ISO 14001, ISO 45001, and industry-specific certifications such as SERMI and TISAX, targeting businesses aiming to improve compliance and operational excellence. Their market position is strong, supported by recognized accreditations and a comprehensive service offering tailored to various industries in Spain and beyond. Technically, the website is built on modern frameworks like Nuxt.js and Vue.js, hosted on Azure, and integrates multiple analytics and marketing tools such as Matomo, Hotjar, and Google Tag Manager. The site demonstrates good performance, mobile optimization, and accessibility, reflecting a mature digital infrastructure. However, the SSL/TLS configuration shows no enabled TLS protocols, which is unusual and should be addressed for secure communications. From a security perspective, the site implements robust HTTP security headers including HSTS, CSP, and X-Frame-Options, but the lack of TLS 1.2 or higher and the disabled X-XSS-Protection header indicate areas for improvement. No explicit security policy or incident response information is publicly available, which could be a gap in transparency and readiness. The site complies with GDPR, featuring comprehensive privacy and cookie policies with consent mechanisms. Overall, DEKRA Certificación presents a professional and trustworthy online presence with strong business credentials and technical maturity. Addressing the TLS configuration and enhancing security transparency would further strengthen their security posture and user trust.

80
58
25
55
100
85
100
certificationauditsENACISO 9001ISO 14001+6 more
Nuxt.jsVue.jsTailwind CSSAzure Application Insights+9

Partner Domains:

e-spirit.hosting
partner67
2025-06-14T12:46:39.956Z
balearicmarinecluster.com favicon

Balearic Marine Cluster

balearicmarinecluster.com

0
nautical/marineSpainmediumMEDIUM

The website’s security posture reveals significant gaps in foundational security controls and regulatory compliance, posing risks to both business operations and customer trust. While there are no critical vulnerabilities, multiple high and medium severity issues indicate a lack of essential security headers, incomplete GDPR compliance, and absence of key information security policies aligned with NIS2 requirements. The missing security headers expose the site to common web-based attacks like clickjacking, content injection, and cross-site scripting. GDPR non-compliance, including the absence of a privacy policy and cookie consent, risks regulatory penalties and reputational damage. The lack of incident response, security policies, and vulnerability disclosure procedures undermines the organization’s ability to manage and mitigate security incidents effectively. Exposure of high-risk services such as FTP further increases attack surface and potential data breaches. Although email security and DNS health are relatively strong, SSL/TLS and network security require immediate attention to prevent service disruptions and data interception. Overall, addressing these deficiencies is critical to protect customer data, maintain regulatory compliance, and safeguard business continuity.

15
40
17
85
80
85
85
nauticalmarineclusterinnovationBalearic Islands+3 more
WordPressYoast SEOWPBakery Page BuilderEventON+12

Partner Domains:

balearicmarine.org
partnerpending
2025-06-13T18:13:38.995Z