Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 191 of 206|Showing 9501-9550 of 10253
boxcar.com favicon

Boxcar

boxcar.com

0
TransportationUnited StatesmediumHIGH

Boxcar is a regional transportation company specializing in commuter bus services and complementary local services such as grill cleaning, knife sharpening, and auto detailing. The company targets commuters in the New Jersey and New York City metropolitan area, offering reserved seating, Wi-Fi, and other amenities to enhance the commuting experience. The website presents a professional and consistent brand image with clear service offerings and customer testimonials, positioning Boxcar as a trusted local transportation provider. Technically, the website is built on the Webflow platform, leveraging modern frontend technologies including jQuery and Google Fonts, and is hosted behind Cloudflare. While the site is mobile-optimized and well-structured, performance data is missing, and the SSL/TLS configuration is critically deficient, lacking a valid certificate and modern protocol support. This represents a significant security risk. From a security perspective, the absence of HTTPS and TLS protocols severely undermines the site's security posture, exposing users to potential data interception and undermining trust. Although privacy and terms of service policies are present and comprehensive, the lack of a cookie consent mechanism despite active tracking scripts indicates partial privacy compliance. Contact information is clearly provided, supporting business credibility. Overall, Boxcar's website demonstrates good content quality and business credibility but suffers from critical security shortcomings that must be addressed urgently to protect user data and maintain trust. Strategic improvements in SSL/TLS deployment and privacy compliance will significantly enhance the site's security and compliance posture.

30
43
17
50
-
50
100
commutingtransportationlocalservicesbusserviceparking+2 more
jQuery 3.6.0WebflowGoogle FontsCloudflare CDN+3
2025-06-16T16:06:47.862Z
pinterest.info favicon

Pinterest

pinterest.info

0
TechnologyUnited StatesenterpriseHIGH

Pinterest is a leading visual discovery and social media platform that enables users to explore and save creative ideas across various categories such as recipes, home decor, fashion, and more. The platform serves a broad audience including individual users, content creators, and businesses seeking advertising opportunities. Pinterest operates on an advertising-based business model with integrated e-commerce features, positioning itself as a key player in the technology and social media industry. The website demonstrates a high level of digital maturity with a modern tech stack primarily based on React and extensive use of cloud services and CDNs for content delivery. The design and user experience are professional and optimized for both desktop and mobile users, ensuring accessibility and SEO best practices are followed. Security-wise, the site implements several important HTTP security headers and a comprehensive content security policy, but it currently suffers from an invalid or missing SSL certificate and lacks support for modern TLS protocols, which significantly impacts its security posture. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms in place. Overall, Pinterest's website is trustworthy and professional, but immediate attention is required to resolve SSL and TLS issues to enhance security and user trust.

80
25
17
65
-
90
100
socialmediavisualdiscoveryadvertisinge-commercetechnology
ReactJavaScript ES6+WebAssemblyAmazon S3+4
2025-06-16T11:09:36.584Z
E

emfluence Digital Marketing

emfluence.com

0
TechnologyUnited StatesmediumHIGH

emfluence Digital Marketing is a well-established digital marketing agency based in the United States, specializing in a broad range of services including digital strategy, SEO, paid media, content marketing, and marketing automation. The company positions itself as a leading provider in the Midwest region, targeting businesses seeking personalized and effective digital marketing solutions. Their website reflects a mature digital presence with rich content, client testimonials, and case studies that demonstrate their expertise and client success. Technically, the site is built on WordPress and leverages modern marketing and SEO tools, including Gravity Forms, Yoast SEO, and Amazon Polly, hosted on AWS with CloudFront CDN for content delivery. However, the absence of a valid SSL certificate and HTTPS support is a critical security gap that undermines user trust and data protection. Privacy compliance is addressed with a clear privacy policy and cookie consent mechanism, but direct contact information such as emails and phone numbers are not explicitly provided, relying mainly on contact forms. Overall, the website is professional and content-rich but requires urgent security improvements to meet modern standards.

15
43
17
50
-
85
100
digitalmarketingmarketingautomationseocontentstrategywebdesign+3 more
WordPressApacheGravity FormsAmazon Polly+8

Partner Domains:

emarketingplatform.com
partnerpending
2025-06-16T10:47:23.656Z
familiesfirst.org favicon

Families First

familiesfirst.org

0
Non-profitUnited StatesmediumMEDIUM

Families First is a well-established non-profit organization founded in 1890, dedicated to strengthening families through a holistic approach that includes mental health services, navigator programs, parenting education, and adoption support. The organization maintains a strong market position with recognized certifications such as the Candid Platinum Seal and Charity Navigator Four-Star Rating, reflecting its credibility and trustworthiness in the community. Their target audience primarily includes families in need of psychosocial support and community members interested in contributing to family resilience. Technically, the website is built on a modern WordPress infrastructure utilizing popular plugins like Elementor, JetEngine, GiveWP, and Gravity Forms, which facilitate content management and donation processing. The site demonstrates good mobile optimization, accessibility, and SEO practices, although performance is moderate and could benefit from further optimization. Analytics are implemented via Google Analytics and Matomo, indicating a moderate level of user tracking. From a security perspective, the site enforces HTTPS and employs some security best practices, including Content Security Policy monitoring and secure payment processing through Stripe. However, it lacks explicit security headers and a visible security or incident response policy, which are recommended for enhanced protection. No critical vulnerabilities or exposed sensitive data were detected. Overall, Families First presents a professional and trustworthy online presence with a solid business model and community impact. Strategic improvements in privacy compliance, security policy transparency, and performance optimization would further strengthen their digital maturity and user trust.

15
33
13
65
-
75
100
non-profitfamilysupportmentalhealthdonationscommunityservices+3 more
WordPressElementorJetEngineGiveWP+4

Partner Domains:

secure.givelively.org
service
app.candid.org
partner

+3 more partners

2025-06-15T22:28:37.265Z
terh.com.mx favicon

TERH

terh.com.mx

0
OtherUnited StatesmediumMEDIUM

TERH is a boutique talent attraction and executive search consulting company founded in 2019, positioned as a leader in providing tailored recruitment solutions for strategic roles across diverse industries including banking, construction, pharmaceuticals, and technology. Their website reflects a professional and consistent brand image, targeting companies seeking executive talent and candidates pursuing new career challenges. The business model emphasizes personalized service delivered by experienced head hunters with deep market knowledge. Technically, the website is built on WordPress using modern plugins such as WPBakery, Slider Revolution, and Yoast SEO, ensuring good SEO optimization and mobile responsiveness. Security measures include HTTPS and Google reCAPTCHA on forms, though some security headers are missing. Privacy compliance is basic with presence of privacy and cookie policies but lacks detailed GDPR indicators or incident response information. The security posture is solid but could be improved by implementing additional security headers and formalizing incident response and vulnerability disclosure policies. No critical vulnerabilities or suspicious content were detected. Overall, the site demonstrates a mature digital presence suitable for its business scope. Strategic recommendations include enhancing security headers, expanding privacy and incident response documentation, and improving accessibility features to strengthen compliance and trust. These steps will support TERH's market position and protect its digital assets effectively.

60
65
10
70
74
80
-
executivesearchtalentattractionheadhuntingrecruitmentconsulting
WordPressYoast SEOWPBakery Page BuilderSlider Revolution+7

Partner Domains:

terhinternational.com
related
terh.international
related
2025-06-15T22:27:44.951Z
J

Jeld-Wen Windows & Doors

jeld-wen.com

0
ManufacturingUnited StatesenterpriseMEDIUM

Jeld-Wen Windows & Doors is a well-established enterprise specializing in the manufacturing and retail of interior and exterior doors, windows, and patio doors. The company targets homeowners, builders, architects, and construction professionals, offering a broad product portfolio with a strong market presence in the United States. Their website reflects a mature digital presence with comprehensive product information, dealer locators, and project support services. Technically, the site leverages modern web technologies including React, jQuery, and integrates multiple third-party marketing and analytics tools such as Google Analytics, Cookiebot, and Drift chat, indicating a high level of digital maturity. Security-wise, the website enforces HTTPS, employs a robust Content Security Policy, and manages cookie consent effectively, although it lacks explicit incident response and vulnerability disclosure pages. Overall, the site demonstrates a strong security posture with room for improvement in publishing security policies and terms of service. Strategic recommendations include implementing a security.txt file, enhancing security headers, and publishing incident response information to further strengthen trust and compliance.

20
63
5
85
-
80
100
doorswindowsmanufacturinghomeimprovementconstruction+5 more
React (implied by data-react-helmet)jQuery 3.3.1Google Tag ManagerGoogle Analytics+6

Partner Domains:

bringithome.jeld-wen.com
subsidiary
menards.jeld-wen.com
subsidiary

+3 more partners

2025-06-15T22:27:10.445Z
J

Johnson & Johnson Vision

amo-inc.com

0
HealthcareUnited StatesenterpriseMEDIUM

Johnson & Johnson Vision operates a professional website focused on refractive surgery and related eye health products. The company is a recognized leader in the ophthalmology healthcare sector, offering advanced surgical technologies such as iLASIK and femtosecond lasers. The website targets eye health professionals, providing detailed product information, educational resources, and access to ordering and support services. The business is positioned as a market leader with a strong brand presence and extensive industry experience under the Johnson & Johnson umbrella. Technically, the website leverages modern web frameworks including Next.js and React, integrates advanced analytics and marketing tools such as Google Tag Manager, Optimizely, and WalkMe, and employs robust cookie consent management via OneTrust. The site is well-optimized for mobile devices and accessibility, with good SEO practices and performance metrics. From a security perspective, the site enforces HTTPS, uses security headers, and integrates Google reCAPTCHA Enterprise to protect forms. Privacy compliance is strong, with clear privacy and cookie policies and user consent mechanisms. However, there is no explicit security policy or incident response contact information published, which could be improved. Overall, the website demonstrates a mature digital presence with strong business credibility and security posture. Strategic recommendations include publishing a dedicated security policy, providing incident response contacts, and considering a vulnerability disclosure program to enhance transparency and trust.

70
63
5
70
-
80
100
refractivesurgeryhealthcareophthalmologymedicaldevicesprivacy+2 more
ReactNext.jsGoogle Tag ManagerGoogle reCAPTCHA Enterprise+3

Partner Domains:

productcomplaintcenter.jnj.com
service
jjvisionmedicalaffairs.com
service

+1 more partners

2025-06-15T22:26:26.899Z
oliverwyman.com favicon

Oliver Wyman

oliverwyman.com

0
FinanceUnited StatesenterpriseMEDIUM

Oliver Wyman is a globally recognized management consulting firm specializing in strategy, risk management, digital transformation, and sustainability consulting. As part of the Marsh McLennan group, it holds a strong market position serving corporate clients across multiple industries including finance, healthcare, energy, and government. The website reflects a mature enterprise with comprehensive service offerings and a clear focus on delivering impactful client solutions. Technically, the website leverages Adobe Experience Manager CMS and integrates modern JavaScript libraries and frameworks such as jQuery, Lodash, and Axios. It employs Adobe Helix RUM for performance monitoring and Osano for cookie consent management, indicating a commitment to user experience and privacy compliance. The site is mobile-optimized, accessible, and SEO-friendly, with a moderate performance profile. From a security perspective, the site enforces HTTPS and includes a Content-Security-Policy header, though additional security headers could enhance protection. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong with clear privacy and cookie policies and consent mechanisms. However, the absence of a public security policy or incident response contact is noted. Overall, Oliver Wyman's website demonstrates high professionalism, trustworthiness, and compliance with privacy standards. The domain registration details align well with the company's identity and history, supporting legitimacy. Strategic recommendations include enhancing security headers, publishing security policies, and implementing vulnerability disclosure mechanisms to further strengthen security posture.

90
83
25
88
77
85
100
managementconsultingstrategyriskmanagementdigitaltransformationsustainability+3 more
Adobe Helix RUMOsano Consent ManagementAxiosjQuery+5

Partner Domains:

www.mmc.com
parent
www.marsh.com
partner

+3 more partners

2025-06-15T22:25:06.604Z
S

Stepan Company

stepan.com

0
ManufacturingUnited StateslargeHIGH

Stepan Company operates as a global specialty and intermediate chemical supplier, providing chemical ingredients and formulations tailored to consumer and industrial markets. The company emphasizes innovation, sustainability, and extensive R&D capabilities, positioning itself as a large, reputable player in the manufacturing sector. Their website reflects a professional and comprehensive digital presence with clear navigation and rich content targeting B2B customers seeking chemical solutions. Technically, the website leverages Adobe Experience Manager as its CMS, integrates Salesforce platforms, and uses modern marketing and analytics tools such as Pardot, Adobe DTM, and Google Tag Manager. The site is hosted on Microsoft Azure DNS infrastructure and employs standard security headers and content security policies. However, a critical security gap exists due to the absence of a valid SSL certificate and HTTPS support, which significantly impacts the site's security posture. From a security perspective, while some best practices like CSP and secure cookies are implemented, the lack of HTTPS and modern TLS protocols exposes the site to risks and undermines user trust. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Contact information is primarily available via web forms, with no direct emails or phone numbers published. Overall, the site is trustworthy and professionally managed but requires urgent remediation of its SSL/TLS configuration to meet modern security standards and improve user confidence.

55
33
-
50
-
85
100
chemicalmanufacturingspecialtychemicalssustainabilityinnovation+2 more
jQuery 3.7.0Adobe Dynamic Tag ManagerGoogle Tag ManagerPardot marketing automation+3

Partner Domains:

gcs-web.com
partner91
2025-06-15T22:12:25.850Z
musicdirect.com favicon

Music Direct

musicdirect.com

0
RetailUnited StatesmediumHIGH

Music Direct operates as a specialized e-commerce retailer focusing on high-end audio equipment and audiophile music products, including vinyl records and turntables. The company positions itself as a leading online destination for audiophiles and music enthusiasts, offering a broad catalog of equipment and music media. Their business model centers on direct online sales, supported by customer service, trade-in programs, and financing options. The website reflects a mature digital presence with comprehensive product offerings and clear navigation tailored to their target audience. Technically, the website is built on the BigCommerce platform using the Stencil framework, leveraging modern web technologies such as jQuery, Bootstrap, and OwlCarousel. The site integrates multiple marketing and analytics tools including Google Analytics 4, Klaviyo, Lucky Orange, and Yotpo, indicating a sophisticated approach to customer engagement and data-driven marketing. Hosting is provided via Cloudflare, enhancing performance and availability. From a security perspective, the site exhibits significant weaknesses. Despite Cloudflare hosting, the SSL certificate is invalid or missing, and no TLS protocols are enabled, resulting in unencrypted HTTP traffic. Security headers such as X-Frame-Options and X-Content-Type-Options are present, but critical HTTPS enforcement and HSTS configurations are lacking. These deficiencies expose the site and its users to potential interception and downgrade attacks. Privacy and cookie policies are well implemented with consent mechanisms, reflecting compliance with GDPR and related regulations. Overall, while the business and technical infrastructure are solid and professional, the lack of proper SSL/TLS configuration is a critical security gap that undermines user trust and data protection. Addressing this issue should be a top priority to ensure secure transactions and compliance with industry standards.

-
-
5
50
-
90
100
e-commerceaudiovinylmusicretail+1 more
jQuery 3.6.0BigCommerce Stencil frameworkBootstrap 5.3.3OwlCarousel 2.3.4+7
2025-06-15T22:12:00.331Z
B

Boston Scientific Corporation

bostonscientific.com

0
HealthcareUnited StatesenterpriseHIGH

Boston Scientific Corporation is a leading global healthcare company specializing in innovative medical devices and solutions aimed at improving patient outcomes. The website targets healthcare professionals, patients, caregivers, investors, and other stakeholders, offering comprehensive product information, educational resources, and corporate responsibility content. The company is well-established with a mature domain and strong brand presence. Technically, the website leverages Adobe Experience Manager as its CMS, integrates modern marketing and analytics tools such as Adobe Target and Google Tag Manager, and provides a responsive, accessible user experience. However, a critical security gap exists due to the absence of a valid SSL certificate and HTTPS support, which significantly impacts the site's security posture. Security headers and content security policies are implemented but their effectiveness is limited without HTTPS. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Overall, the site demonstrates high business credibility and professionalism but requires urgent remediation of its SSL/TLS configuration to ensure user trust and data protection.

-
18
5
50
-
85
100
healthcaremedicaldevicescorporateeducationinvestorrelations+1 more
Adobe TargetGoogle Tag ManagerjQuery 3.7.1Coveo Search UI+2

Partner Domains:

relievant.com
subsidiarypending
intracept.com
subsidiarypending
2025-06-15T22:09:05.065Z
panoramabustours.com favicon

Panorama Tours, Inc.

panoramabustours.com

0
TransportationUnited StatesmediumCRITICAL

Panorama Tours, Inc. is a well-established private transportation company based in New Jersey, specializing in private bus charters and shuttle services for a variety of group travel needs. With nearly three decades of experience, the company serves clients primarily in New York and New Jersey, offering a broad range of services including casino trips, athletic transportation, and sightseeing tours. Their business model focuses on providing safe, comfortable, and reliable transportation solutions for groups of all sizes. The website reflects a professional and consistent brand image with detailed service descriptions and client testimonials, positioning Panorama Tours as a trusted regional leader in the transportation sector. Technically, the website is built on WordPress using popular plugins such as Yoast SEO, Contact Form 7, and WPBakery Page Builder, indicating a mature digital infrastructure. However, performance data is missing, and the site shows signs of moderate mobile optimization and basic accessibility features. SEO is well addressed through structured data and meta tags, enhancing search visibility. From a security perspective, the site lacks HTTPS encryption, which is a critical vulnerability exposing users to potential data interception. There are no security headers or advanced protections like DNSSEC or HSTS enabled. Privacy compliance is weak, with no visible privacy or cookie policies, which could pose regulatory risks especially under GDPR. Contact information is clearly provided, but incident response and security policies are absent. Overall, while the business and website content are credible and professional, the lack of fundamental security measures and privacy compliance significantly lowers the site's trustworthiness and user safety. Immediate implementation of SSL/TLS and privacy policies is recommended to mitigate risks and improve compliance.

-
-
-
50
-
50
-
transportationbuschartershuttleservicenewjerseywordpress+2 more
WordPressPHPjQueryGoogle Maps API+5

Partner Domains:

fareharbor.com
partner71
boxcar.com
partnerpending
2025-06-15T22:08:01.626Z