Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 11 of 65|Showing 501-550 of 3226
metwork.co.uk favicon

Metropolitan Workshop

metwork.co.uk

0
Real EstateUnited KingdomsmallHIGH

Metropolitan Workshop is a well-established architectural and urban planning practice founded in 2005, with offices in London and Dublin. The company offers professional services in architecture, urbanism, and design, targeting clients interested in these sectors. Their website reflects a professional and consistent brand image, with clear navigation and relevant content tailored to their audience. The business operates primarily within the real estate sector and maintains a small company size with a focused market position. Technically, the website is built on WordPress and leverages modern web technologies including Google Analytics, Google Tag Manager, Vimeo embeds, and Google Maps API. The site is mobile-optimized and performs moderately well, though there is room for improvement in accessibility and SEO. Hosting is provided by GoDaddy, consistent with the domain registrar information. From a security perspective, the website uses HTTPS with an excellent SSL configuration but lacks several recommended security headers. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is basic, with a privacy and cookie policy present but no explicit cookie consent mechanism. Contact information is comprehensive, but no dedicated security policy or incident response details are available. Overall, the website presents a low-risk profile with strong business credibility and good technical implementation. Strategic improvements in security headers, privacy consent mechanisms, and incident response transparency would enhance the security posture and compliance standing.

15
68
2
70
72
70
-
architectureurbanismdesignprofessionalservicesuk+1 more
Google AnalyticsGoogle Tag ManagerVimeo embedGoogle Maps API+4
2025-10-24T08:41:28.464Z
morrisand.company favicon

Morris+Company

morrisand.company

0
Real EstateUnited KingdommediumMEDIUM

Morris+Company is a professional architecture and design firm with a strong portfolio covering housing, workplace, community, education, healthcare, placemaking, tall buildings, interiors, re-use, hospitality, and mission-critical projects. The firm operates primarily in the UK and Europe, with offices in London and Copenhagen, targeting clients seeking sustainable and innovative architectural solutions. The website reflects a medium-sized, established company with consistent branding and a professional online presence. Technically, the website employs modern web technologies including jQuery, SimpleBar, Google Analytics, Google Tag Manager, and Google Maps API. Hosting of media assets on Amazon S3 indicates a scalable infrastructure. The site is mobile-optimized with good design quality and navigation, though accessibility and SEO optimizations are basic. From a security perspective, the site uses HTTPS with good SSL configuration but lacks important security headers and privacy compliance elements such as privacy and cookie policies. No vulnerability disclosures or incident response contacts are provided. WHOIS data is unavailable due to privacy protection, which is common and likely justified for this business type. Overall, the website is professional and trustworthy but would benefit from enhanced privacy compliance and security best practices to reduce risk and improve user trust.

15
35
2
70
72
80
100
architecturedesignhousingworkplacecommunity+8 more
jQuerySimpleBarGoogle AnalyticsGoogle Tag Manager+1
2025-10-24T08:41:18.444Z
alliesandmorrison.com favicon

Allies and Morrison

alliesandmorrison.com

0
Real EstateUnited KingdommediumMEDIUM

Allies and Morrison is a London-based architectural and urbanist practice focused on designing beautiful buildings and shaping enduring places with attention to detail and context uniqueness. The firm serves clients interested in architecture, urban planning, and sustainable development, positioning itself as a reputable medium-sized player in the real estate and design sector. Their website showcases a comprehensive portfolio of projects, research, and talks, reflecting a mature and professional business model. Technically, the website employs modern web technologies including Google Analytics with IP anonymization, Imgix for image delivery, and JavaScript ES6, ensuring fast performance and excellent mobile optimization. The site is well-structured with good SEO and accessibility features, although no CMS or hosting provider details are explicitly identified. From a security perspective, the site uses HTTPS with a good SSL configuration and secure form handling for newsletter subscriptions. However, it lacks explicit security headers and a cookie consent mechanism, which are recommended for enhanced security and GDPR compliance. No vulnerability disclosures or incident response contacts are published, representing an area for improvement. Overall, the website is professional, trustworthy, and safe for general audiences. The absence of WHOIS data is a notable anomaly but does not detract significantly from the site's credibility given the quality of content and contact transparency. Strategic recommendations include implementing security headers, adding cookie consent, publishing security policies, and improving WHOIS transparency to strengthen trust and compliance.

90
35
17
85
72
85
100
architectureurbanismdesignresearchlondon+2 more
Google AnalyticsGoogle Tag ManagerImgix (image CDN)JavaScript ES6+2
2025-10-24T08:40:53.372Z
derwentlondon.com favicon

Derwent London

derwentlondon.com

0
Real EstateUnited KingdomlargeMEDIUM

Derwent London is a prominent British property investment and development company headquartered in London, recognized as the largest London office-focused Real Estate Investment Trust (REIT) and a constituent of the FTSE 250 Index. The company manages a substantial portfolio of commercial real estate valued at £5.2 billion as of mid-2025, focusing on long-term value creation through property regeneration. Their services include office and retail space leasing, flexible furnished workspaces, and community-focused DL/Members lounges. The website reflects a mature digital presence with comprehensive content targeting investors, tenants, and partners. Technically, the website employs modern web technologies including Google Tag Manager, Google Analytics, and cookie consent management, ensuring compliance with privacy regulations such as GDPR. The site is mobile-optimized, accessible, and SEO-friendly, although no CMS or hosting provider details are explicitly identified. Performance is moderate with good user experience and navigation clarity. From a security perspective, the site enforces HTTPS and uses cookie consent mechanisms with granular controls. However, no explicit security headers were detected in the HTML source, and there is no published security policy or vulnerability disclosure program. The absence of WHOIS data limits domain trust verification, but the professional presentation and multiple industry certifications support legitimacy. Overall, Derwent London’s website demonstrates strong business credibility and privacy compliance, with room for improvement in security best practices and transparency. The domain’s WHOIS data absence warrants monitoring but does not currently undermine the site’s trustworthiness.

55
83
2
80
62
70
100
realestateinvestmentdevelopmentcorporatelondon+4 more
JavaScriptGoogle Tag ManagerMyFonts WebfontsCookie Consent Manager by Ten4+4
2025-10-24T08:40:33.329Z
A

Architectural Association, Inc.

aaschool.ac.uk

0
EducationUnited KingdommediumMEDIUM

The Architectural Association, Inc. operates a well-established educational website serving as the primary online portal for its architecture school based in London. The site provides comprehensive information about academic programmes ranging from foundation courses to PhD levels, public lectures, events, and publications. It targets students, architects, researchers, and the general public interested in architecture education and cultural programming. The institution holds a reputable market position as an independent and historic architecture school with a global reach. Technically, the website employs a modern technology stack including React, Google Analytics, Hotjar, and Bootstrap, ensuring a responsive and user-friendly experience. The site is served over HTTPS with asynchronous loading of scripts, contributing to moderate performance and good mobile optimization. However, some accessibility features could be enhanced, and security headers are not explicitly present. From a security perspective, the site demonstrates good practices such as HTTPS enforcement and no visible exposure of sensitive data. Privacy and cookie policies are comprehensive and GDPR compliant, though no explicit security or incident response policies are published. The absence of WHOIS data is attributed to privacy protection, which is reasonable for this type of institution. Overall, the site maintains a high trust level with clear contact information and charity registration disclosures. The overall risk profile is low, with recommendations focusing on improving security headers, publishing incident response contacts, and enhancing accessibility compliance. These steps would further strengthen the site's security posture and user trust.

15
68
17
70
77
60
100
architectureeducationpublicprogrammeacademiccoursesresearch+2 more
Google AnalyticsGoogle Tag ManagerHotjarjQuery+5

Partner Domains:

cdn.worldpay.com
partner
2025-10-24T07:45:03.329Z
architecturefoundation.org.uk favicon

Architecture Foundation

architecturefoundation.org.uk

0
OtherUnited KingdomsmallHIGH

The Architecture Foundation is a well-established UK-based non-profit organization dedicated to uniting the global architecture community through events, podcasts, tours, and publications. Founded in 1991, it operates as an independent charity with a strong presence in the architecture sector, supported by numerous reputable partners and supporters. The website reflects this mission with rich content targeting architects, clients, and professionals interested in the built environment. Technically, the website employs a modern yet straightforward technology stack including jQuery, Bootstrap, and Google reCAPTCHA Enterprise for form security. The site is mobile-optimized and uses HTTPS, ensuring secure communications. However, it lacks some advanced security headers and formal privacy and cookie policies, which are important for compliance and user trust. From a security perspective, the site demonstrates good baseline practices such as HTTPS enforcement and spam protection on forms. There are no visible vulnerabilities or exposed sensitive data. The WHOIS data confirms the domain's legitimacy and long-standing registration consistent with the organization's history. Overall, the Architecture Foundation's website is professional, trustworthy, and content-rich, though it would benefit from enhanced privacy compliance and additional security headers to further strengthen its posture.

20
35
17
70
62
45
40
architecturenon-profiteventspodcastseducation+2 more
jQuery 2.1.1Bootstrap 3.xFont Awesome 4.5.0Google Fonts (Lora)+2

Partner Domains:

shop.architecturefoundation.org.uk
partner
2025-10-24T07:44:43.276Z
ubiquity.pub favicon

Ubiquity Press Ltd

ubiquity.pub

0
EducationUnited KingdommediumMEDIUM

Ubiquity Press Ltd operates the website ubiquity.pub, providing a comprehensive platform for open publishing services that span the entire research lifecycle. Their offerings include open access journal and book publishing, cloud-hosted open source repositories, and infrastructure support for university presses and libraries. The company positions itself as a values-driven leader in open scholarship, emphasizing transparency, openness, and fair pricing. Their target audience primarily consists of academic societies, universities, libraries, and researchers. Technically, the website is built on a modern React and Next.js stack, hosted on cloud infrastructure with assets served via Google Cloud Storage. The site demonstrates excellent performance, mobile optimization, and accessibility. Security is a key focus, with ISO 27001 certification prominently noted, HTTPS enforced, and no visible security vulnerabilities or exposed sensitive data. Privacy compliance is well addressed with a comprehensive cookie policy and consent mechanism. The security posture is strong, though the site could improve by adding explicit security headers and publishing a vulnerability disclosure policy. No WHOIS registrant details are publicly available due to privacy protection, but the domain is consistent with the company's UK registration and business operations, indicating legitimacy. Overall, the website is professional, trustworthy, and well-aligned with its mission to support open scholarship. Strategic recommendations include enhancing security headers, publishing incident response and vulnerability disclosure information, and improving direct contact options to further build trust and compliance.

15
50
47
40
-
75
100
openaccessacademicpublishingopeninfrastructureiso27001cloudhosting+4 more
ReactNext.jsGoogle FontsCloud hosting+1
2025-10-24T04:56:00.464Z
efwconference.com favicon

Mark Allen Group

efwconference.com

0
EnergyUnited KingdommediumCRITICAL

The Energy from Waste Conference website represents a well-established industry event organized by Mark Allen Group, focusing on the global waste to energy sector. The site effectively communicates the conference's purpose, target audience, and key services such as networking, knowledge sharing, and sponsorship opportunities. The business is positioned as a reputable event organizer with a medium-sized presence in the energy sector, supported by a domain registered since 2015 and consistent branding. Technically, the website leverages modern JavaScript libraries, Google Analytics, Google Tag Manager, and the Evessio event management platform. Hosting is distributed with Amazon S3 for static assets and UKFast for DNS services. The site demonstrates good mobile optimization and SEO practices, though accessibility is basic. Security measures include HTTPS, CSRF tokens, and reCAPTCHA, but could be improved by enabling DNSSEC and adding security headers. From a security perspective, the site shows a mature posture with no critical vulnerabilities detected. Privacy and cookie policies are comprehensive and GDPR compliant, with clear user consent mechanisms. No incident response or security policy pages were found, indicating an area for potential enhancement. Overall, the site is trustworthy, professional, and safe for general audiences. The overall risk is low, with recommendations focusing on enhancing DNS security, adding security headers, and maintaining regular audits of third-party scripts to sustain a strong security posture.

-
-
-
-
-
-
-
energyconferencewastetoenergyeventsustainability+2 more
JavaScriptjQueryGoogle AnalyticsGoogle Tag Manager+3

Partner Domains:

network.efwconference.com
partner
efwconference-me.com
related

+1 more partners

2025-10-24T04:47:07.169Z
opopworkshop.com favicon

Mark Allen Group

opopworkshop.com

0
EnergyUnited KingdommediumMEDIUM

Operational Optimisation 2026 is a specialized event organized by Mark Allen Group targeting operational decision-makers in the energy from waste and biomass sectors. The website presents a professional and well-structured platform for event information, networking, and industry engagement. The business model focuses on event organization, sponsorship, and industry knowledge exchange, positioning itself as a niche leader in this technical sector. The website content is relevant and well-maintained, with clear calls to action and supporting testimonials enhancing credibility. Technically, the website leverages modern JavaScript libraries, Google Analytics, Google Tag Manager, and a proprietary event platform (Evessio CMS) hosted on AWS infrastructure. The site demonstrates moderate performance and good mobile optimization, though accessibility features are basic. SEO practices are adequately implemented with proper meta tags and Open Graph data. From a security perspective, the site uses HTTPS and includes CSRF tokens, but lacks visible security headers and DNSSEC is not enabled. No explicit security policies or incident response contacts are published, which could be improved. The domain registration is consistent with the business claims, showing no suspicious patterns and a reasonable domain age. Overall, the website is trustworthy and professional with moderate security posture and privacy compliance. Strategic improvements in security headers, DNSSEC, and published security policies would enhance the site's resilience and user trust.

40
35
17
40
62
75
100
energyeventconferencebiomasswaste-to-energy+2 more
JavaScriptjQueryFontAwesomeGoogle Tag Manager+3

Partner Domains:

efwconference.com
partner
efwconference-me.com
partner

+1 more partners

2025-10-24T04:47:02.159Z
claymatic.games favicon

Claymatic Games Ltd

claymatic.games

0
TechnologyUnited KingdomsmallMEDIUM

Claymatic Games Ltd is a small independent game development company based in the United Kingdom, specializing in cooperative and couch-play games for PC and console platforms. Their flagship project is Clodhoppers, featuring the character Cletus Clay. The company emphasizes bringing friends together through fun and laughter in gaming experiences. The website is professionally designed using Squarespace CMS and includes essential business documents such as privacy policy and terms and conditions, indicating a basic level of compliance and professionalism. Social media presence across multiple platforms supports their market engagement and community building. Technically, the website uses modern web technologies including Google Analytics and Tag Manager for tracking, Typekit fonts for typography, and is hosted on Squarespace. The site is mobile optimized with good SEO practices but lacks some advanced security headers which could enhance its security posture. HTTPS is enforced, but HSTS and other headers like Content-Security-Policy are missing. From a security perspective, the site shows no signs of vulnerabilities or malicious content. Privacy compliance is basic but present, with a cookie consent banner and accessible privacy documents. The WHOIS data is privacy protected, common for small businesses, and does not raise immediate concerns. Overall, the site is trustworthy with room for security improvements. Strategically, the company should focus on enhancing security headers, improving contact information availability, and possibly expanding privacy and security policies to strengthen trust and compliance. The technical infrastructure is solid for their size and market position, supporting their business goals effectively.

35
80
17
55
62
80
100
indiegamesgamedevelopmentco-opgamescouch-playsquarespace+2 more
Squarespace CMSGoogle AnalyticsGoogle Tag ManagerTypekit fonts+1
2025-10-24T00:50:49.025Z
C

Catholic Bishops' Conference of England and Wales

liturgyoffice.org.uk

0
GovernmentUnited KingdomsmallHIGH

The Liturgy Office website serves as the official online presence for the Department for Christian Life and Worship under the Catholic Bishops' Conference of England and Wales. It provides liturgical resources, calendars, prayers, and news relevant to the Catholic community in England and Wales. The site targets clergy, church members, and those interested in Catholic liturgy, positioning itself as a trusted non-profit religious resource provider with a long-standing domain since 2001. Technically, the website employs basic web technologies including HTML5, CSS, Google Fonts, and Google Analytics for tracking. The site lacks a modern CMS and advanced frameworks, indicating a simple but functional technical infrastructure. Performance and mobile optimization are basic, with room for improvement in accessibility and SEO. From a security perspective, the site uses HTTPS (implied but not explicitly confirmed), but lacks visible security headers and published privacy or cookie policies, which are compliance gaps especially under GDPR. No forms collecting sensitive data are present, reducing attack surface. The WHOIS data confirms domain legitimacy and consistency with the organization's history, supporting trustworthiness. Overall, the website is a credible, safe, and content-relevant resource for its audience but would benefit from enhanced privacy compliance, security hardening, and technical modernization to improve user trust and regulatory adherence.

15
35
17
60
62
60
20
religioncatholicliturgychurchresources+2 more
Google FontsGoogle Analytics (gtag.js)HTML5CSS
2025-10-24T00:05:29.193Z
C

catholicsinhealthcare.co.uk

catholicsinhealthcare.co.uk

0
HealthcareUnited KingdomsmallHIGH

The website Catholicsinhealthcare.co.uk serves as a resource hub for lay Catholics, priests, and chaplains working in healthcare across various disciplines. It is positioned as a niche informational platform within the healthcare sector, specifically targeting the Catholic community in the United Kingdom. The domain has been registered since 2006, indicating a long-standing presence, but the current site is under maintenance, limiting content accessibility and user engagement. Technically, the site is built on WordPress with Bootstrap 3.3.7, indicating a standard CMS-based infrastructure with moderate technical maturity. The site lacks advanced security headers and privacy compliance features, and no analytics or tracking tools are detected. Mobile optimization and accessibility are basic, and the overall design and user experience are poor due to the maintenance page blocking content. From a security perspective, the absence of security headers and privacy policies, combined with the lack of contact or incident response information, suggests a low security posture. The SSL configuration is basic but present. The domain registration is consistent and legitimate, with no suspicious patterns detected. Overall, the site currently presents a low risk but also low utility due to its maintenance status. Strategic recommendations include publishing privacy and cookie policies, implementing security best practices, improving accessibility and mobile responsiveness, and providing clear contact and incident response channels to enhance trust and compliance.

15
35
10
60
72
60
20
healthcarecatholicchaplainsresourcesuk
WordPressBootstrap 3.3.7jQueryYoast SEO
2025-10-23T20:35:03.850Z
C

Catholic Bishops' Conference of England and Wales (CBCEW)

liturgyoffice.org

0
GovernmentUnited KingdomsmallHIGH

The Liturgy Office website serves as the official online presence for the Department for Christian Life and Worship under the Catholic Bishops' Conference of England and Wales. It provides liturgical resources, calendar information, prayers, and news relevant to the Catholic community in England and Wales. The site targets clergy, church members, and religious scholars, positioning itself as a trusted resource within the religious non-profit sector. The business model is non-commercial, focusing on service and information dissemination. Technically, the website employs basic web technologies including HTML5, CSS, Google Fonts, and Google Tag Manager for analytics. The site lacks a modern CMS and advanced frameworks, indicating a relatively simple infrastructure. Performance and mobile optimization are basic, with room for improvement in accessibility and SEO. No forms or user input fields reduce complexity and security risks. From a security perspective, the site uses HTTPS (assumed but not explicitly confirmed), but lacks DNSSEC and security headers, which are recommended for enhanced protection. No privacy or cookie policies are present, indicating compliance gaps with GDPR and related regulations. The WHOIS data is transparent and consistent with the organization's identity, supporting legitimacy. No critical vulnerabilities or suspicious patterns were detected. Overall, the website is a reliable and safe resource with good business credibility but requires improvements in privacy compliance, security hardening, and technical modernization to enhance user trust and regulatory adherence.

15
35
17
60
62
60
20
religioncatholicliturgychurchengland+2 more
Google FontsGoogle Tag Manager (gtag.js)HTML5CSS

Partner Domains:

cbcew.org.uk
partner
catholicchurch.org.uk
partner
2025-10-23T20:23:04.596Z
dayforlife.org favicon

Catholic Bishops' Conference of England and Wales

dayforlife.org

0
GovernmentUnited KingdommediumHIGH

The Catholic Bishops' Conference of England and Wales operates a professional and authoritative website dedicated to religious advocacy and raising awareness on life issues. The site provides comprehensive resources including messages, prayer booklets, and grant information, targeting Catholics and interested individuals in England and Wales. The organization holds a strong market position as a recognized religious authority with consistent branding and a clear mission. Technically, the website is built on WordPress with modern technologies such as Bootstrap, Yoast SEO, and Google Analytics, hosted with CDN support for performance. The site demonstrates good mobile optimization, accessibility, and SEO practices, reflecting a mature digital infrastructure. From a security perspective, the site uses HTTPS and employs security best practices, although explicit security headers are not detected in the provided data. No vulnerabilities or exposed sensitive data were found. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Overall, the website presents a low risk profile with strong business credibility and technical maturity. The main limitation is the lack of WHOIS data due to querying the 'www' subdomain, but this does not detract from the site's legitimacy. Strategic recommendations include enhancing security headers and publishing explicit security and incident response policies.

15
68
25
55
62
65
20
catholiclifeissuesreligiousnon-profitadvocacy+3 more
WordPressYoast SEO pluginjQueryBootstrap+4
2025-10-23T20:22:59.203Z
taking-stock.org.uk favicon

Catholic Bishops' Conference of England and Wales

taking-stock.org.uk

0
GovernmentUnited KingdomsmallHIGH

Taking Stock is a non-profit project managed by the Catholic Bishops' Conference of England and Wales, focusing on the architectural and historical review of Catholic churches and chapels across England and Wales. The website serves as an informational resource and partnership platform involving dioceses and Historic England. The target audience includes researchers, heritage professionals, and the Catholic community. The business model is collaborative and heritage-focused, with a niche market position in religious architectural documentation. Technically, the website is built on WordPress with a modern tech stack including Bootstrap, jQuery, and advanced SEO plugins like Yoast. Hosting utilizes a CDN for performance, and Google Analytics is implemented for visitor tracking. The site demonstrates good mobile optimization and basic accessibility features, though there is room for improvement in security headers and cookie consent mechanisms. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data or vulnerable libraries. However, it lacks explicit security policies, incident response information, and cookie consent banners, which are important for GDPR compliance and user trust. No critical vulnerabilities or suspicious activities were detected. Overall, the website is professionally maintained with a strong business credibility and good content quality. Strategic recommendations include enhancing privacy compliance with cookie consent, implementing security headers, and publishing security and incident response policies to improve trust and compliance posture.

15
53
10
60
62
60
20
catholicchurchesheritageenglandwales+3 more
WordPressBootstrapjQueryYoast SEO+4
2025-10-23T20:22:54.189Z
npsa.gov.uk favicon

National Protective Security Authority

npsa.gov.uk

0
GovernmentUnited KingdommediumLOW

The National Protective Security Authority (NPSA) is the UK government's National Technical Authority for physical and personnel protective security, operating as part of MI5. The website serves as a comprehensive resource offering guidance, tools, and risk management information targeted at security professionals, government entities, industry sectors, and high-risk individuals. It holds a strong market position as an authoritative government agency providing protective security expertise. Technically, the website is built on Drupal CMS with modern JavaScript libraries and integrates analytics and tracking tools such as Google Tag Manager, Facebook Pixel, Hotjar, and LinkedIn Insight. The site demonstrates good mobile optimization, accessibility, and SEO practices, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS and implements cookie consent mechanisms, though it lacks explicit security headers and a public security policy or incident response contact. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is robust with clear privacy and cookie policies aligned with GDPR requirements. Overall, the website presents a low risk profile with strong trust indicators including official UK government domain usage, Crown copyright, and consistent branding. The absence of WHOIS data is typical for government domains and does not detract from legitimacy. Strategic recommendations include enhancing security headers, publishing a security policy, and providing clear incident response contacts to further strengthen security posture.

65
80
47
88
85
70
100
governmentsecurityprotectivesecurityriskmanagementuk+3 more
Drupal CMSjQueryGoogle Tag ManagerFacebook Pixel+4
2025-10-23T20:22:28.450Z
sis.gov.uk favicon

Secret Intelligence Service (SIS) / MI6

sis.gov.uk

0
GovernmentUnited KingdomlargeMEDIUM

The website www.sis.gov.uk represents the UK Secret Intelligence Service (SIS), commonly known as MI6. It serves as the official digital presence of the UK's foreign intelligence agency, providing detailed information about its mission, history, leadership, recruitment opportunities, and partnerships. The site targets potential recruits, government partners, and the general public interested in intelligence services. The business model is that of a government agency focused on intelligence gathering and national security. The website is well-branded, professionally designed, and consistent with government standards, reflecting a high level of trustworthiness and authority. Technically, the site is built on the Drupal CMS platform and employs Matomo for privacy-conscious analytics. It demonstrates good mobile optimization, accessibility, and SEO practices. The site uses HTTPS with strong SSL configuration, though no explicit security headers were detected in the provided data. Privacy compliance is robust, with clear privacy and cookie policies and a consent mechanism in place. Contact information is limited to a contact form, with no direct emails or phone numbers publicly listed, which aligns with the sensitive nature of the organization. From a security perspective, the site shows good practices such as HTTPS enforcement and privacy-respecting analytics. However, it lacks publicly visible security policies or incident response contacts, and no security.txt file was found. The WHOIS data is unavailable, which is typical for sensitive government domains and is justified in this context. Overall, the site presents a strong security posture with room for improvement in transparency around security policies. The overall risk assessment is low given the official nature of the site, its consistent branding, and government affiliation. Strategic recommendations include enhancing security header implementation, publishing a dedicated security policy and incident response information, and adding a security.txt file to facilitate vulnerability disclosures. These steps would further strengthen trust and security culture while maintaining operational security.

70
68
2
65
95
70
-
governmentintelligencemi6securityrecruitment+2 more
Drupal CMSMatomo AnalyticsJavaScriptCSS

Partner Domains:

www.mi5.gov.uk
partner
www.gchq.gov.uk
partner
2025-10-23T20:22:22.958Z
gchq.gov.uk favicon

GCHQ

gchq.gov.uk

0
GovernmentUnited KingdomenterpriseMEDIUM

GCHQ is the United Kingdom's official intelligence, security, and cyber agency, tasked with protecting the country from threats both in the physical and digital realms. The website clearly communicates its mission, key services, and organizational culture, targeting UK citizens, government stakeholders, and cybersecurity professionals. The site is well-branded and professionally designed, reflecting its authoritative government status. Technically, the website employs modern web technologies including React and JSON-LD structured data for SEO and accessibility. The site is mobile-optimized and provides a smooth user experience with clear navigation and relevant content. While no explicit CMS or hosting provider is identified, the site demonstrates good performance and technical maturity. From a security perspective, the site uses HTTPS and implements cookie consent mechanisms, but lacks explicit security headers and a public security policy or vulnerability disclosure program. No contact information for security incidents is provided, which is common for government sites but could be improved for transparency. The absence of WHOIS data is typical for UK government domains, and the domain's legitimacy is supported by its .gov.uk TLD and consistent official content. Overall, the website is trustworthy, secure, and professionally maintained, with minor recommendations to enhance security headers and incident response transparency. The risk level is low, and the site effectively serves its purpose as a government intelligence agency portal.

80
68
2
88
77
70
100
governmentintelligencecybersecurityuksecurity+2 more
JavaScriptCSSWeb fonts (Poppins)JSON-LD structured data
2025-10-23T20:22:11.444Z
zonal.co.uk favicon

Zonal

zonal.co.uk

0
HospitalityUnited KingdomlargeMEDIUM

Zonal is a UK-based leading provider of integrated hospitality technology solutions, offering a comprehensive ecosystem that connects front- and back-of-house operations. Their product portfolio includes EPoS systems, online ordering, reservation management, inventory control, kitchen management, property management, business analytics, and marketing CRM solutions. Positioned as the UK's number one technology ecosystem for hospitality, Zonal targets a broad range of hospitality sectors including pubs, bars, restaurants, hotels, and leisure venues. Technically, the website is built on WordPress with modern optimization tools such as NitroPack and uses various marketing and analytics integrations including Google Tag Manager, HubSpot forms, and Visual Website Optimizer. The site demonstrates excellent mobile optimization, accessibility, and SEO practices, providing a fast and professional user experience. From a security perspective, the site enforces HTTPS and includes standard security headers, alongside a robust cookie consent mechanism compliant with GDPR. However, explicit security policies, incident response information, and vulnerability disclosure mechanisms are not published, representing areas for improvement. Overall, the website is professional, trustworthy, and well-structured, though the lack of WHOIS data due to domain registration anomalies introduces some uncertainty regarding domain legitimacy. Strategic recommendations include publishing detailed security and incident response policies and clarifying domain registration details to enhance trust.

70
88
17
80
77
70
100
hospitalitytechnologyeposonlineorderingreservationsystems+4 more
WordPressWPBakery Page BuilderNitroPack optimizationGoogle Tag Manager+4

Partner Domains:

careers.zonal.co.uk
service
2025-10-23T19:16:12.136Z
cbcew.org.uk favicon

Catholic Bishops' Conference of England and Wales

cbcew.org.uk

0
GovernmentUnited KingdommediumHIGH

The Catholic Bishops' Conference of England and Wales operates an official website providing authoritative information about the Catholic Church's activities, leadership, safeguarding, and community engagement within England and Wales. The site serves a broad audience including clergy, laity, and the general public interested in religious affairs. It offers news, events, podcasts, and educational resources, positioning itself as a trusted source for Catholic-related content in the region. Technically, the website is built on WordPress with modern frameworks like Bootstrap and integrates SEO and analytics tools such as Yoast SEO and Google Analytics, reflecting a mature digital infrastructure. The site is hosted on reliable CDN services ensuring moderate to good performance and mobile responsiveness. Security posture is solid with HTTPS enforced and cookie consent mechanisms in place, although some security headers could be improved. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website demonstrates high professionalism, trustworthiness, and compliance with privacy regulations including GDPR. The lack of WHOIS data for the exact subdomain queried is explained by it being a subdomain, with the main domain being legitimate and well-established. Strategic recommendations include enhancing security headers and maintaining regular updates to sustain security and compliance.

15
68
25
55
62
65
20
catholicreligionchurchenglandwales+5 more
WordPressYoast SEO pluginBootstrapjQuery+5
2025-10-23T19:12:32.272Z