Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 21 of 65|Showing 1001-1050 of 3226
thetrainline.com favicon

Trainline.com Limited

thetrainline.com

0
TransportationUnited KingdomlargeLOW

Trainline.com Limited operates a leading independent rail and coach travel platform, providing users across Europe and the UK with the ability to search, compare, and purchase train and bus tickets. The company holds a strong market position as a trusted intermediary with over 270 operators and coverage in 45 countries. Their digital presence is supported by a modern, performant website and mobile app, enabling seamless journey management for millions of travelers. The platform emphasizes user convenience and competitive pricing, with a clear focus on the transportation sector. Technically, the website leverages contemporary web technologies including React, JavaScript, and integrates advanced analytics and monitoring tools such as New Relic and Google Tag Manager. The presence of anti-bot services like Datadome and tracking via Branch.io indicates a mature digital infrastructure designed for performance and security. The site is well optimized for mobile devices and accessibility, with good SEO practices evident from metadata and structured data. From a security standpoint, the website enforces HTTPS with strong SSL configuration and employs multiple security headers including CSP and HSTS. The use of bot mitigation and monitoring tools further strengthens its security posture. However, explicit security policies and incident response contacts are not publicly disclosed, representing an area for improvement. No vulnerabilities or exposed sensitive data were detected in the analysis. Overall, Trainline.com demonstrates a high level of professionalism, technical maturity, and business credibility. The lack of public WHOIS data is consistent with privacy protection practices common among large enterprises. The platform is safe for general audiences, with no adult or questionable content. Strategic recommendations include enhancing transparency around security policies and incident response to further build user trust and compliance.

85
88
2
85
82
85
100
traveltrainticketsbusticketsbookingtransportation+3 more
ReactJavaScriptGoogle Tag ManagerNew Relic+2

Partner Domains:

capitaine-train.com
subsidiary
2025-10-11T22:19:26.783Z
crozdesk.com favicon

Crozdesk Ltd

crozdesk.com

0
TechnologyUnited KingdommediumMEDIUM

Crozdesk Ltd operates a well-established business software search and review platform, founded in 2014 and based in the United Kingdom. The website offers extensive software categories, user and expert reviews, and free software buyer guides, targeting businesses seeking software solutions. The platform positions itself as a comprehensive marketplace facilitating software discovery and comparison, leveraging a broad catalog of over 41,000 software products and hundreds of expert reviews. Technically, the website employs a modern technology stack including jQuery, Bootstrap, Google reCAPTCHA, Cloudflare CDN, and New Relic monitoring, ensuring moderate performance and good mobile optimization. The site uses HTTPS with good SSL configuration and integrates cookie consent mechanisms compliant with GDPR. However, DNSSEC is not enabled, and no explicit CMS or security policy pages were detected. From a security perspective, the site demonstrates good practices such as HTTPS enforcement, Cloudflare protection, and reCAPTCHA integration. No critical vulnerabilities or exposed sensitive data were found. Privacy compliance is strong with detailed cookie declarations and consent banners. However, the absence of published incident response or vulnerability disclosure policies suggests room for improvement. Overall, Crozdesk presents a professional, trustworthy, and user-friendly platform with strong content quality and technical implementation. Strategic enhancements in security transparency and DNS security would further strengthen its posture.

70
83
17
80
75
85
100
softwarebusinessreviewsmarketplacesaas+4 more
jQuery 3.4.1jQuery UI 1.12.1Bootstrap 3.4.1Google reCAPTCHA+7
2025-10-11T22:19:16.756Z
brandcommsgroup.com favicon

BrandComms

brandcommsgroup.com

0
OtherUnited KingdommediumMEDIUM

BrandComms is an established international brand consultancy and communications agency founded in 2013, with a strong presence in London and emerging markets, particularly Africa. The company specializes in brand design, marketing communications, events, and digital services, serving high-profile clients in finance, energy, and other sectors. Their business model integrates local and global expertise to help clients capture market opportunities through iconic brand building and communications. Technically, the website is built on WordPress with modern technologies including React, jQuery, and Vimeo integration. SEO is well implemented using Yoast SEO, and the site is mobile-optimized with good user experience and navigation clarity. The hosting and domain registration are consistent with the company's UK base, and the domain is well secured with prohibitive domain status flags, though DNSSEC is not enabled. From a security perspective, the site uses HTTPS and Google reCAPTCHA for form protection, and has a cookie consent mechanism in place. However, no explicit security headers were detected, and DNSSEC is not enabled, representing areas for improvement. Privacy policies are comprehensive and GDPR compliant, enhancing user trust. Overall, the website is professional, secure, and compliant with privacy regulations, reflecting a mature business with a strong market position. Minor security enhancements are recommended to further strengthen the security posture.

80
83
2
60
62
80
100
brandingmarketingcommunicationseventsafrica+3 more
WordPressjQueryReactVimeo Player+3
2025-10-11T22:18:06.524Z
vibe.travel favicon

Vibe Systems Ltd.

vibe.travel

0
TechnologyUnited KingdommediumMEDIUM

Vibe Systems Ltd. is a UK-based travel technology company specializing in providing tailored travel booking platforms and software solutions for travel agents, travel management companies (TMCs), and tour operators. Their platform supports both corporate and leisure travel sectors, offering scalable, secure, and user-friendly technology designed to enhance customer booking experiences. The company positions itself as a trusted partner in the travel industry with a focus on flexibility and customer-centric solutions. Technically, the website employs modern JavaScript libraries such as jQuery and Slick Carousel, and integrates Google reCAPTCHA for form security. The site is mobile-optimized with a responsive design and includes cookie consent mechanisms indicating GDPR compliance. However, some security best practices such as implementing security headers are not evident, and WHOIS data is privacy-protected, limiting transparency. From a security perspective, the site uses HTTPS and has implemented CAPTCHA on forms to mitigate spam and abuse. The absence of security headers and incomplete WHOIS information are areas for improvement. No critical vulnerabilities or exposed sensitive data were detected. Privacy policies and cookie policies are present and comprehensive, supporting regulatory compliance. Overall, Vibe Systems presents a professional and credible online presence consistent with a legitimate travel technology provider. Strategic recommendations include enhancing security headers, improving transparency of domain registration, and publishing explicit security and incident response policies to strengthen trust and compliance.

70
68
2
70
72
80
100
traveltechnologytravelsoftwaretravelbookingplatformb2bsaas+3 more
jQuery 3.7.1jQuery UISlick CarouselGoogle reCAPTCHA v2
2025-10-11T21:11:55.883Z
devitjobs.uk favicon

DevITJobs

devitjobs.uk

0
TechnologyUnited KingdomsmallMEDIUM

DevITJobs.uk operates as a specialized online job board focusing on IT and software developer roles within the United Kingdom. Established in 2021, the platform distinguishes itself by offering transparent job listings that include detailed tech stacks and salary ranges, catering primarily to IT professionals seeking employment opportunities. The website maintains a consistent brand presence and leverages modern web technologies such as React and JSON-LD structured data to enhance user experience and SEO performance. Social media integration across LinkedIn, Telegram, Facebook, and Twitter supports community engagement and outreach. From a technical perspective, the site demonstrates moderate performance with good mobile optimization and basic accessibility features. The use of HTTPS and DNSSEC indicates a commitment to secure communications, although the absence of explicit security headers and privacy policies suggests room for improvement in security posture and compliance. Analytics are implemented via privacy-focused services like Plausible Analytics, reflecting a moderate approach to user tracking and data collection. Security-wise, the platform benefits from encrypted connections and domain security measures but lacks visible incident response protocols, vulnerability disclosures, and comprehensive privacy or cookie policies. These gaps present potential compliance and trust challenges, particularly under GDPR regulations. The domain registration data aligns well with the business profile, showing transparency and legitimacy without privacy protection, which is appropriate for this business type. Overall, DevITJobs.uk is a credible and professionally presented job board with a solid foundation but would benefit from enhanced privacy, security policies, and compliance documentation to strengthen user trust and regulatory adherence.

30
83
17
72
65
85
100
itjobssoftwaredeveloperukjobstechjobssalarytransparency+1 more
ReactJavaScriptCSSHTML5+2

Partner Domains:

germantechjobs.de
partner
devitjobs.nl
partner

+3 more partners

2025-10-11T19:58:38.989Z
ebrd.com favicon

European Bank for Reconstruction and Development

ebrd.com

0
FinanceUnited KingdomenterpriseMEDIUM

The European Bank for Reconstruction and Development (EBRD) is a prominent international financial institution focused on fostering economic transition and sustainable development across more than 40 economies in three continents. The organization leverages a unique business model combining financing, advisory services, and policy reform to support private sector growth and environmental sustainability. With over €210 billion invested since its founding in 1991, EBRD holds a strong market position as a key development financier. Technically, the website is built on Adobe Experience Manager, utilizing modern web technologies including Adobe Analytics and Adobe Launch for marketing and data collection. The site demonstrates good performance, mobile optimization, and accessibility features, reflecting a mature digital infrastructure. The presence of comprehensive metadata, structured data, and SEO best practices further enhances its digital maturity. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms aligned with GDPR compliance. While explicit security headers are not visible in the HTML, the use of Adobe's secure platforms and absence of exposed sensitive data indicate a solid security posture. However, the lack of WHOIS data for the domain is unusual and warrants further verification to confirm domain registration legitimacy. Overall, the website presents a professional, trustworthy, and well-maintained digital presence consistent with a large international financial institution. Strategic recommendations include verifying WHOIS registration details, enhancing visible security headers, and implementing a security.txt file to improve vulnerability disclosure transparency.

85
65
2
75
-
85
100
financedevelopmentinvestmentsustainabilityinternationalorganization+2 more
Adobe Experience Manager (AEM)Adobe AnalyticsjQueryAdobe Launch (Tag Manager)+3
2025-10-11T18:49:02.136Z
whistleb.com favicon

NAVEX

whistleb.com

0
TechnologyUnited KingdomenterpriseMEDIUM

NAVEX is a global enterprise specializing in governance, risk, and compliance (GRC) solutions, with a strong focus on whistleblowing systems tailored for European regulatory compliance. Their WhistleB product offers a secure, fast, and compliant whistleblowing reporting channel designed to empower employees, third parties, and compliance teams with multilingual support and encrypted, anonymous reporting. The company positions itself as a trusted provider with a comprehensive suite of compliance tools and a strong emphasis on data security and privacy. Technically, the website leverages modern JavaScript frameworks and integrates multiple third-party services such as Wistia for video hosting, Google Tag Manager, Microsoft Clarity, and Marketo for marketing automation and analytics. The site is well-optimized for mobile devices, accessible, and SEO-friendly, reflecting a mature digital infrastructure. The use of consent management tools and compliance with GDPR further demonstrate their commitment to privacy. From a security perspective, NAVEX employs HTTPS with strong SSL configurations and security headers, ensuring secure data transmission and protection against common web vulnerabilities. The whistleblowing system emphasizes anonymity and encryption, with no IP tracking and multifactor authentication for case management. However, explicit security policies and incident response contacts are not prominently published, representing an area for improvement. Overall, NAVEX presents a professional, trustworthy, and technically sound online presence with a strong compliance focus. The lack of public WHOIS data is consistent with privacy protection practices common among enterprises. The website is safe, business-oriented, and free from suspicious content, making it a reliable resource for organizations seeking whistleblowing and compliance solutions.

30
85
47
95
72
80
100
whistleblowingcompliancegrcemployeecompliancewhistleblowersystem+2 more
JavaScriptWistia video embedsGoogle Tag ManagerMicrosoft Clarity+6
2025-10-11T18:47:06.828Z
O

Ovarro

ovarro.com

0
TechnologyUnited KingdommediumLOW

Ovarro is a UK-based technology company specializing in monitoring, control, analytics, and SCADA solutions for critical infrastructure sectors including water, oil & gas, broadcast, transportation, energy, and process industries. The company positions itself as a trusted partner with over 25 years of experience and a global network of certified channel partners. Their business model focuses on providing B2B technology solutions that enhance operational efficiency, safety, and security through data-driven insights. The website reflects a mature digital presence with professional design, clear navigation, and multilingual support, targeting industrial clients worldwide. Technically, the website is built on a custom ASP.NET WebForms platform, leveraging Microsoft Ajax and Bootstrap 4.3.1 for responsive design. Hosting and DNS services are supported by Cloudflare, ensuring reliable performance and security. The site implements GDPR-compliant cookie consent mechanisms and maintains good SEO and accessibility standards, although some accessibility features could be enhanced. From a security perspective, the site enforces HTTPS and uses domain locking statuses to prevent unauthorized changes. However, DNSSEC is not enabled, and there is no publicly available security policy or incident response information. No vulnerabilities or exposed sensitive data were detected in the analysis. Privacy compliance is strong with clear privacy and cookie policies. The absence of a vulnerability disclosure program or security.txt file is noted as an area for improvement. Overall, Ovarro's website demonstrates a high level of professionalism, security awareness, and compliance suitable for its industry and clientele. The risk profile is low, with recommendations to enhance DNS security and publish explicit security policies to further strengthen trust and transparency.

85
95
17
80
72
85
100
rtusdataloggersleakdetectionscadamonitoring+10 more
ASP.NETMicrosoft AjaxBootstrap 4.3.1Cloudflare DNS

Partner Domains:

citplatform.com
partner
atriumiot.com
partner
2025-10-11T17:38:23.831Z
greenandresilienteconomics.org favicon

Macroeconomics of Green and Resilient Transitions

greenandresilienteconomics.org

0
GovernmentUnited KingdommediumMEDIUM

The Macroeconomics of Green and Resilient Transitions website serves as a collaborative platform primarily aimed at Ministries of Finance and associated researchers and practitioners focused on climate finance and economic policy. It provides a compendium of practical tools, publications, and community engagement to support green and resilient economic transitions. The site is backed by reputable academic and governmental institutions, notably the London School of Economics and the Coalition of Finance Ministers for Climate Action, positioning it as a trusted resource in its niche. Technically, the website is built on WordPress with modern web technologies including Bootstrap and jQuery, enhanced by SEO plugins and Adobe Fonts. It employs Google Analytics for user tracking but lacks a cookie consent mechanism, which is a privacy compliance gap. The site is mobile-optimized and demonstrates good accessibility and SEO practices, though performance is moderate. From a security perspective, the site uses HTTPS and domain registration protections but lacks DNSSEC and explicit security headers, which are recommended for enhanced security. No direct contact emails or phone numbers are publicly listed, with contact facilitated via a form. There is no visible security policy or incident response information, which could be improved to bolster trust and compliance. Overall, the website is professional, content-rich, and trustworthy, with minor technical and compliance improvements recommended to enhance security posture and privacy adherence.

15
53
25
60
-
75
100
greeneconomyclimateactioneconomicanalysisfinanceministriessustainability+5 more
WordPressYoast SEO pluginjQueryBootstrap (implied by navbar classes)+2

Partner Domains:

www.lse.ac.uk
partner
www.financeministersforclimate.org
partner

+2 more partners

2025-10-11T16:33:26.943Z
climate-laws.org favicon

Climate Policy Radar / Grantham Research Institute at LSE

climate-laws.org

0
GovernmentUnited KingdommediumMEDIUM

Climate Change Laws of the World is a comprehensive academic and research platform hosted by the London School of Economics and powered by Climate Policy Radar. It provides a global database of over 5000 climate laws, policies, and UNFCCC submissions from 196 countries and territories, serving researchers, policymakers, and NGOs focused on climate governance. The platform offers advanced search capabilities including contextual highlighting and English translations, enhancing accessibility and usability. Technically, the website is built on a modern React and Next.js stack, leveraging AWS infrastructure and integrating analytics tools such as Google Tag Manager, PostHog, and Plausible. The site is well-optimized for performance, mobile responsiveness, and accessibility, reflecting a mature digital infrastructure suitable for academic and policy research use. From a security perspective, the site enforces HTTPS and employs cookie consent mechanisms, but lacks explicit security headers and a published security policy or incident response page. No vulnerabilities or sensitive data exposures were detected. Privacy compliance is strong with clear policies and GDPR adherence. Contact is primarily via email and web forms, with no phone or physical address listed. Overall, the website demonstrates a high level of professionalism, trustworthiness, and technical maturity, making it a reliable resource for climate law and policy data. Strategic improvements in security policy transparency and header implementation could further enhance its security posture.

15
83
17
40
77
75
100
climatechangelawpolicyresearchdatabase+4 more
ReactNext.jsTypekit fontsGoogle Tag Manager+2

Partner Domains:

lse.ac.uk
partner
granthaminstitute.lse.ac.uk
partner

+3 more partners

2025-10-11T16:33:21.907Z
transitionpathwayinitiative.org favicon

Transition Pathway Initiative

transitionpathwayinitiative.org

0
EnergyUnited KingdommediumMEDIUM

The Transition Pathway Initiative (TPI) is a globally recognized, asset-owner led initiative focused on assessing companies' preparedness for the transition to a low carbon economy. The organization provides assessment tools for corporates, bond issuers, banks, and sovereigns, supported by a strong academic research center affiliated with the London School of Economics. The initiative enjoys a solid market position with over 150 supporters and assets under management exceeding $80 trillion, indicating significant influence in the sustainability and investment sectors. Technically, the website is built on a modern stack including React and Ruby on Rails, with integration of multiple analytics platforms such as Google Analytics, Google Tag Manager, and Plausible Analytics. The site demonstrates good mobile optimization, accessibility, and SEO practices, although performance is moderate. Hosting appears to be managed through GoDaddy, with no DNSSEC enabled, which is a potential area for security enhancement. From a security perspective, the site enforces HTTPS and avoids exposing sensitive data. However, it lacks visible security headers and a formal security or incident response policy publicly available. Privacy compliance is strong with clear privacy and cookie policies linked to the London School of Economics domain, though no explicit cookie consent mechanism is implemented. Contact information is limited to a professional email address, with no phone or physical address provided on the homepage. Overall, the website presents a high level of professionalism, trustworthiness, and content quality, with minor technical and security improvements recommended. The domain registration data aligns well with the business history, supporting legitimacy. Strategic recommendations include enabling DNSSEC, implementing security headers, publishing security policies, and enhancing cookie consent mechanisms to further strengthen security and compliance posture.

70
68
2
60
-
80
40
low-carboneconomyclimatechangeassetmanagersglobalinitiativesustainability+1 more
Google AnalyticsGoogle Tag ManagerPlausible AnalyticsJavaScript+1
2025-10-11T16:33:16.820Z
justtransitionfinance.org favicon

Just Transition Finance

justtransitionfinance.org

0
FinanceUnited KingdomsmallMEDIUM

Just Transition Finance is an academic research lab hosted by the London School of Economics, focused on transforming the global financial system to support climate and environmental goals through a people-centered approach. The website serves as a platform for disseminating research, policy guidance, and case studies related to just transition finance. The lab targets financial institutions, policymakers, and researchers interested in sustainable finance and social impact. Technically, the site is built on WordPress with modern SEO and accessibility features, leveraging plugins like Yoast SEO and Plausible Analytics for privacy-respecting user tracking. The site is well-structured, mobile-optimized, and professionally designed, reflecting a high level of digital maturity for an academic initiative. Security posture is solid with HTTPS enforced and domain transfer protections, though DNSSEC is not enabled and explicit security policies or incident response information are not published. Privacy compliance is strong with a clear cookie consent mechanism and links to comprehensive privacy and terms policies hosted by LSE. Overall, the site is trustworthy, professional, and aligned with its academic and non-profit mission.

25
68
10
70
52
70
100
financeclimatejusttransitionpolicyresearch+4 more
WordPressYoast SEO pluginjQueryPlausible Analytics+1

Partner Domains:

lse.ac.uk
partner
transitionpathwayinitiative.org
partner

+2 more partners

2025-10-11T16:33:11.810Z
globalinsightconferences.com favicon

Global Insight Conferences Ltd

globalinsightconferences.com

0
OtherUnited KingdomsmallMEDIUM

Global Insight Conferences Ltd is a UK-based company specializing in organizing high-quality, tailored conferences across various sectors. Their business model focuses on delivering personalized conference experiences that emphasize value for time and money, targeting professionals and organizations seeking effective knowledge exchange and networking opportunities. The company positions itself as a niche provider with a strong emphasis on quality and client-centric event design. Technically, the website is built on WordPress using the Elementor framework, leveraging modern web technologies such as jQuery and Font Awesome. The site is mobile-optimized and demonstrates good SEO practices, although some accessibility features could be improved. Performance is moderate, with no critical technical issues detected. From a security perspective, the site enforces HTTPS but lacks several important security headers, which could improve protection against common web attacks. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is partially addressed with visible privacy and cookie policies, but the absence of a cookie consent mechanism and incomplete Google Analytics configuration indicate room for improvement. Overall, the website presents a professional and trustworthy front for the business, but the lack of WHOIS data and unclear domain registration status introduces some risk. Strategic recommendations include enhancing security headers, verifying domain registration, implementing cookie consent, and configuring analytics properly to strengthen compliance and trust.

15
68
2
70
100
85
100
conferenceeventsbusinessprofessionaluk
WordPressElementorPHPjQuery+2
2025-10-11T16:29:47.669Z
greenhousesports.org favicon

Greenhouse Sports

greenhousesports.org

0
Non-profitUnited KingdommediumMEDIUM

Greenhouse Sports is a UK-based non-profit charity dedicated to developing young people through sport and mentoring. The organization focuses on embedding trusted Coach-Mentors in schools and communities to help young people overcome barriers related to poverty, education, and wellbeing. Their market position is that of a well-established charity with a strong community and school partnership network, supported by donors and corporate partners. The website reflects a professional and consistent brand image with comprehensive content about their mission, impact, and ways to support. Technically, the website is built on WordPress with modern SEO and performance optimizations including Yoast SEO, Google Tag Manager, and ShortPixel image optimization. It is mobile-optimized and accessible, with a cookie consent mechanism compliant with GDPR. Security posture is good with HTTPS enforced and bot management cookies present, though explicit security headers could be improved. No critical vulnerabilities or exposed sensitive data were detected. Overall, the site demonstrates a strong security and privacy posture for a non-profit, with clear privacy and cookie policies. However, it lacks publicly visible security policies or incident response contacts. The WHOIS data is privacy protected, which is justified for this type of organization. The domain appears legitimate based on website content and trust indicators. Recommendations include enhancing security headers, publishing a security policy and incident response information, and considering a vulnerability disclosure policy to further improve trust and security maturity.

15
83
2
80
-
85
100
charitysportsyouthdevelopmentmentoringnon-profit+2 more
WordPressYoast SEO pluginGoogle Tag ManagerCookieYes consent management+2
2025-10-11T15:26:00.692Z
environmentbank.com favicon

Environment Bank

environmentbank.com

0
Real EstateUnited KingdommediumMEDIUM

Environment Bank is a UK-based specialist in biodiversity net gain (BNG) and habitat restoration, operating England’s largest network of BNG Habitat Banks. The company targets developers, landowners, BNG partners, and responsible businesses, providing services such as habitat bank creation, biodiversity unit supply, and nature shares investment. Their market position is strong within the environmental and real estate sectors, supported by professional branding and partnerships with notable clients like Aldi, Tesco, and National Grid. Technically, the website is built on WordPress with modern SEO and analytics tools including Yoast SEO, Google Tag Manager, HubSpot, and Microsoft Clarity. The site is mobile-optimized, accessible, and performs moderately well. Security posture is good with HTTPS enforced and cookie consent implemented, though explicit security headers and incident response information are not visible. The WHOIS data is unavailable or protected, which slightly impacts trust but the professional website content and client references mitigate concerns. No critical vulnerabilities or compliance gaps were detected, and the site maintains good privacy compliance with a detailed cookie consent mechanism. Overall, the website presents a credible, professional business with a solid digital presence and good security hygiene, though improvements in transparency around privacy policies and security disclosures are recommended.

55
83
2
85
75
85
100
biodiversityhabitatbankbiodiversitynetgainenvironmentsustainability+2 more
WordPressYoast SEO pluginGoogle Tag ManagerCookieYes cookie consent+6
2025-10-11T15:25:40.651Z
heycargroup.com favicon

Mobility Trader UK Limited

heycargroup.com

0
TransportationUnited KingdommediumMEDIUM

Heycar UK, operated by Mobility Trader UK Limited, is a reputable online marketplace specializing in used car sales and car finance services within the United Kingdom. The platform offers thousands of quality-checked used cars, either directly or through trusted dealers, backed by a 10-day money-back guarantee. The website targets UK consumers seeking reliable used vehicles and financing options, positioning itself as a trusted intermediary in the automotive resale market. The company was founded in 2019 and leverages a mature domain registered since 2008, indicating a stable online presence. Technically, the website is built on modern frameworks such as Next.js and React, hosted on Amazon AWS infrastructure, and integrates multiple third-party services including Stripe for payments, Google Maps for location services, and a consent management platform for GDPR compliance. The site demonstrates good performance, mobile optimization, and SEO practices, contributing to a positive user experience. From a security perspective, heycar.com enforces HTTPS, employs clientTransferProhibited domain status to prevent unauthorized transfers, and uses reCAPTCHA and CMP scripts to enhance security and privacy compliance. However, it lacks explicit security policies, incident response contacts, and DNSSEC, which are areas for improvement. No critical vulnerabilities or suspicious activities were detected. Overall, heycar.com presents a professional, trustworthy, and user-friendly platform with a solid technical foundation and moderate privacy compliance. Strategic enhancements in transparency around privacy, security policies, and DNS security would further strengthen its security posture and user trust.

90
85
2
65
-
85
100
usedcarscarfinanceukautomotiveonlinemarketplace
ReactNext.jsStripeGoogle Maps API+4

Partner Domains:

app.carsale24.com
partner
cmp.inmobi.com
partner

+1 more partners

2025-10-11T15:20:12.716Z
heycar.com favicon

Mobility Trader UK Limited

heycar.com

0
TransportationUnited KingdommediumLOW

heycar UK, operated by Mobility Trader UK Limited, is a well-established online marketplace specializing in quality checked used cars from trusted dealers across the United Kingdom. Founded in 2019, the company leverages a modern digital platform to provide car buyers with extensive listings, dealer access, car valuation tools, finance information, and expert reviews. The website demonstrates a strong market position within the UK automotive sector, targeting consumers seeking reliable used vehicles with transparent dealer relationships. The technical infrastructure is robust, utilizing Next.js and React frameworks hosted on AWS, integrating multiple third-party services such as Stripe for payments, Google Maps for location services, and advanced analytics platforms including Snowplow and Quantcast. The site is optimized for performance, mobile responsiveness, and accessibility, reflecting a mature digital presence. From a security perspective, heycar enforces HTTPS with a solid SSL configuration and employs a comprehensive cookie consent mechanism compliant with GDPR. While explicit security policies and incident response contacts are not publicly found, the domain registration is consistent and trustworthy, with no suspicious indicators. The absence of DNSSEC is a minor security gap. Overall, the security posture is strong but could be enhanced by publishing formal security and vulnerability disclosure policies. The overall risk assessment is low, with the website presenting a professional, secure, and user-friendly experience. Strategic recommendations include enabling DNSSEC, publishing privacy and security policies, and enhancing transparency around incident response to further strengthen trust and compliance.

90
85
17
80
82
85
100
usedcarscarsalesukautomotiveonlinemarketplace+3 more
ReactNext.jsStripeGoogle Maps API+4

Partner Domains:

app.carsale24.com
partner
cmp.inmobi.com
partner

+1 more partners

2025-10-11T15:19:52.631Z
M

MoodleMoot Global

moodlemoot.org

0
EducationUnited KingdommediumCRITICAL

MoodleMoot Global 2025 is a well-established international education conference focused on the Moodle learning platform, scheduled to be held in Edinburgh, UK. The website serves as the main portal for event information, ticket sales, agenda, and sponsorship opportunities. It targets educators, developers, and education technology professionals globally. The business model centers on event organization and ticketing, supported by partnerships with payment processors and marketing platforms. Technically, the site is built on WordPress with a modern plugin ecosystem, including WooCommerce and Tickera for e-commerce and ticket management. The infrastructure leverages Cloudflare DNS and integrates analytics and marketing tools such as HubSpot, Google Tag Manager, and Facebook Pixel. Security posture is solid with HTTPS enforced and cookie consent implemented, though DNSSEC is not enabled and some advanced security headers are missing. Privacy compliance is good, with a clear cookie consent mechanism and a basic privacy policy. No contact emails or phone numbers are explicitly published, which is a minor gap in business credibility. Overall, the site is professional, trustworthy, and suitable for its audience, with no signs of malicious activity or content safety concerns.

-
-
-
-
-
-
-
educationconferencemoodleeventticketing+2 more
WordPressPHPWooCommerceTickera (ticketing plugin)+5

Partner Domains:

stripe.com
partner
calendly.com
partner

+1 more partners

2025-10-11T10:49:32.329Z
int-comp.org favicon

International Compliance Association

int-comp.org

0
EducationUnited KingdommediumMEDIUM

The International Compliance Association (ICA) is a leading professional body specializing in qualifications, training, and membership services for professionals in Anti Money Laundering (AML), Compliance, Customer Due Diligence (CDD), Sanctions, and Financial Crime Prevention. The organization targets a global regulatory and financial crime compliance community, offering a comprehensive portfolio of educational products and corporate solutions. ICA is positioned as a reputable and established entity within the compliance education sector, supported by its parent company Wilmington PLC. Technically, the ICA website is built on the Umbraco CMS platform and integrates a modern technology stack including Google Tag Manager, multiple analytics and tracking pixels (Google Analytics, TikTok, Twitter, Bing, Crazy Egg, LinkedIn), and marketing tools such as Shareaholic and Cookie Script for consent management. The site demonstrates good performance, mobile optimization, accessibility, and SEO practices, reflecting a mature digital infrastructure. From a security perspective, the website enforces HTTPS with excellent SSL configuration and employs secure forms with validation. While explicit security headers are not fully visible in the HTML content, the site follows best practices including cookie consent mechanisms and no visible exposure of sensitive data. The lack of a published incident response or vulnerability disclosure page is noted as an area for improvement. The domain WHOIS data is privacy protected, but the association with Wilmington PLC and consistent business information supports the domain's legitimacy. Overall, the ICA website presents a low-risk profile with strong business credibility, professional content, and a secure technical foundation. Strategic recommendations include enhancing security header implementation, publishing incident response contacts, and improving transparency on data retention policies to further strengthen trust and compliance posture.

90
68
10
50
57
85
100
complianceeducationfinancialcrimeamltraining+5 more
Google Tag ManagerGoogle Analytics (gtag.js)TikTok PixelTwitter Universal Website Tag+6

Partner Domains:

wilmingtonplc.com
parent
events.int-comp.org
service
2025-10-11T08:32:02.746Z
skoda-connect.com favicon

Škoda Auto a.s.

skoda-connect.com

0
TransportationUnited KingdomlargeCRITICAL

Škoda Connect is a digital platform operated by Škoda Auto a.s., a well-established automotive manufacturer under the Volkswagen Group umbrella. The website serves as a portal for connected car services and promotes the transition to the new MyŠkoda mobile app, enhancing the driving experience for Škoda vehicle owners. The platform targets Škoda customers primarily in the United Kingdom and provides access to service purchases via the Škoda Connect Shop and official retailer links. Technically, the website is built using modern web technologies including React and Next.js, ensuring a responsive and user-friendly experience. The site is moderately optimized for performance and mobile devices, with a clean design and clear navigation. However, some accessibility and SEO optimizations could be improved. No CMS or hosting provider details were explicitly identified. From a security perspective, the site uses HTTPS but lacks visible security headers and explicit incident response or vulnerability disclosure information. No WHOIS data was found for the domain, which is unusual and may indicate privacy protection or registration issues. Despite this, the website content and branding strongly suggest legitimacy as an official Škoda service portal. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website presents a professional and trustworthy front for Škoda's connected car services, though improvements in security transparency and domain registration clarity are recommended to enhance trust and compliance.

-
-
-
-
-
-
-
automotiveconnectedcarkodamobileappvehicleservices+1 more
ReactNext.jsJavaScriptWeb fonts (woff2)

Partner Domains:

shop.skoda-connect.com
partner
retailers.skoda-auto.com
partner

+2 more partners

2025-10-11T06:41:00.474Z
osborneclarke.com favicon

Osborne Clarke LLP

osborneclarke.com

0
OtherUnited KingdomlargeLOW

Osborne Clarke LLP is a well-established international legal practice with a history dating back to 1748. The firm provides a broad range of legal services across multiple sectors including energy, financial services, healthcare, transportation, retail, technology, and real estate. Their website reflects a professional and comprehensive approach to legal services, targeting corporate clients and businesses globally. The firm positions itself as a forward-looking legal partner, focusing on transformational trends and regulatory compliance. Technically, the website is built on Drupal 11, leveraging modern web technologies such as HTML5 video and slick carousels for dynamic content presentation. The site is mobile-optimized, accessible, and SEO-friendly, indicating a mature digital infrastructure. Security best practices are observed with HTTPS enforcement and standard security headers, although explicit security policies and incident response information are not publicly detailed. The security posture is strong with no visible vulnerabilities or exposed sensitive data. However, the absence of a vulnerability disclosure policy and data protection officer contact details suggests areas for improvement in transparency and compliance. The WHOIS data for the domain is missing or not publicly available, which raises some concerns about domain registration consistency relative to the firm's claimed long history. Overall, Osborne Clarke's website demonstrates a high level of professionalism and digital maturity, supporting its market position as a leading international law firm. Strategic recommendations include enhancing security transparency, publishing incident response and vulnerability disclosure information, and clarifying domain registration details to strengthen trust and compliance.

55
85
17
85
100
85
100
legalinternationallawfirmprofessionalservicesconsulting+3 more
Drupal 11AddToAny sharingSlick carouselHTML5 video

Partner Domains:

wave.osborneclarke.com
partner
digitalregulation.osborneclarke.com
partner

+2 more partners

2025-10-11T05:34:40.273Z