Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 20 of 206|Showing 951-1000 of 10253
yodlee.com favicon

Envestnet | Yodlee

yodlee.com

0
FinanceUnited StatesenterpriseCRITICAL

Envestnet | Yodlee is a leading enterprise in the financial data aggregation and analytics sector, providing connected data products that empower financial institutions and fintech companies to deliver personalized financial experiences. Founded in 1999 and headquartered in San Mateo, California, Yodlee operates as a subsidiary of Envestnet and serves multiple countries including the US, Canada, UK, France, South Africa, Australia, and New Zealand. Their business model focuses on B2B SaaS offerings with key services spanning personal financial management, credit solutions, wealth management, business financial management, payment enablement, and open finance APIs. Technically, the website is built on Drupal 10 CMS and integrates a modern technology stack including Google Tag Manager, Marketo, OneTrust for cookie consent, and various analytics and marketing tools. The site demonstrates good performance, excellent mobile optimization, and accessibility features, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS, employs security headers, and uses CAPTCHA on forms to mitigate abuse. However, it lacks publicly available dedicated security policies, incident response contacts, and vulnerability disclosure programs, which are recommended for enterprise-grade security transparency. The absence of WHOIS data for the domain is a notable anomaly, though the website content and business information strongly indicate legitimacy. Overall, the website presents a professional, trustworthy, and secure front for a major financial technology enterprise. Strategic improvements in transparency around security policies and incident response would further enhance trust and compliance posture.

-
-
-
-
-
-
-
financetechnologydataaggregationfinancialservicesb2b+3 more
Drupal 10Google Tag ManagerMarketo FormsFont Awesome+4

Partner Domains:

envestnet.com
parent
2025-10-24T05:47:43.058Z
moneyguidepro.com favicon

MoneyGuide, Inc.

moneyguidepro.com

0
FinanceUnited StatesmediumMEDIUM

MoneyGuide, Inc., a subsidiary of Envestnet, is a leading provider of financial planning software designed to empower financial advisors and their clients through personalized, goal-based planning solutions. The website showcases a comprehensive platform with multiple configurable products such as MoneyGuide, MyBlocks, and Wealth Studios, targeting financial professionals seeking scalable and interactive planning tools. The company positions itself strongly in the finance sector with a medium-sized business profile and consistent branding across its digital presence. Technically, the website employs a mature digital infrastructure with modern marketing and analytics technologies including Google Tag Manager, Marketo, Salesforce LiveAgent, and multiple tracking pixels, indicating a high level of digital marketing sophistication. The site is mobile-optimized and provides a good user experience with clear navigation and professional design. Security-wise, the website enforces HTTPS and implements cookie consent mechanisms, though HTTP security headers are not explicitly detected in the source. No critical vulnerabilities or exposed sensitive data were found. WHOIS data is unavailable or protected, which is common for commercial entities but reduces transparency. Overall, the website demonstrates a strong security posture and privacy compliance with room for improvement in explicit security header implementation and incident response disclosures. Strategic recommendations include enhancing security headers, publishing incident response contacts, and improving accessibility compliance to further strengthen trust and security culture.

35
88
17
85
77
80
100
financialplanningsoftwareadvisortoolsclientengagementgoal-basedplanning+1 more
Google Tag ManagerGoogle AnalyticsFacebook PixelMarketo Munchkin+7

Partner Domains:

envestnet.com
parent
salesforceliveagent.com
service

+1 more partners

2025-10-24T04:51:29.051Z
tamaracinc.com favicon

Envestnet

tamaracinc.com

0
FinanceUnited StatesenterpriseLOW

Envestnet is a leading provider of integrated portfolio, practice management, and reporting solutions tailored for financial advisors and institutions. The company operates primarily in the finance and technology sectors, offering SaaS-based wealth management tools that support advisors in delivering comprehensive financial services. Their market position is strong, supported by enterprise-grade technology and recognized certifications such as SOC 2 and ISO 27001. The website reflects a mature digital presence with a focus on user experience and compliance. Technically, the website is built on Drupal 11, leveraging modern web technologies and integrating advanced marketing and analytics tools including Visual Website Optimizer and Google Tag Manager. The site demonstrates good performance, mobile optimization, and accessibility standards. Privacy and cookie policies are clearly presented with consent mechanisms in place, indicating a commitment to GDPR compliance. From a security perspective, the site enforces HTTPS, employs key security headers, and avoids exposing sensitive data. However, explicit security policies, incident response contacts, and vulnerability disclosure mechanisms are not publicly available, representing areas for improvement. The absence of WHOIS registration data limits domain trust verification but does not detract significantly from the overall professionalism and trustworthiness of the site. Overall, Envestnet's website presents a secure, compliant, and professional digital front that aligns with its enterprise stature in the financial technology market. Strategic enhancements in transparency around security policies and domain registration details would further strengthen trust and compliance posture.

80
73
47
85
82
85
100
financetechnologywealthmanagementportfoliomanagementsaas+4 more
Drupal 11Visual Website Optimizer (VWO)Google Tag ManagerFontAwesome+1
2025-10-24T04:51:19.026Z
climatec.com favicon

Climatec, LLC

climatec.com

0
EnergyUnited StateslargeMEDIUM

Climatec, LLC is a well-established provider of building technology and energy efficiency solutions, serving primarily commercial and public sector clients. Founded in 1975 and a member of the Robert Bosch family since 2015, Climatec offers key services including Energy Services, Building Automation, and Security + Life Safety. The company positions itself as a trusted partner for building safety, comfort, and efficiency across the United States. Technically, the website is built on modern web technologies including Webflow CMS, jQuery, and Google Tag Manager, with good mobile optimization and moderate performance. The site uses HTTPS and Google reCAPTCHA for form security, but lacks explicit HTTP security headers and publicly available security policies, which could be improved to enhance security posture. From a security perspective, the site shows a moderate maturity level with no critical vulnerabilities detected in the provided data. However, the absence of WHOIS domain registration data raises concerns about domain transparency and trustworthiness. The presence of a suspicious external script domain also suggests the need for further security review. Overall, Climatec's website is professional and trustworthy in content and design, but improvements in domain registration transparency and security headers are recommended to strengthen its security posture and compliance. Strategic focus on publishing security policies and incident response information would further enhance trust and compliance.

60
53
2
70
62
80
100
energybuildingautomationsecuritytechnologyrobertbosch+1 more
jQuery 3.5.1Google Tag ManagerGoogle reCAPTCHAWebflow CMS

Partner Domains:

bosch.com
parent
2025-10-24T04:48:03.843Z
scienceconnect.io favicon

John Wiley & Sons, Inc

scienceconnect.io

0
TechnologyUnited StateslargeMEDIUM

ScienceConnect.io is a digital platform operated under John Wiley & Sons, Inc, designed to provide researchers with a unified account system to access, discover, organize, and publish scholarly research across multiple publisher platforms. The platform leverages modern web technologies including React and Material-UI, and is built by Atypon, a Wiley brand recognized as a leader in digital scientific publishing technology. The website demonstrates a professional and consistent brand presence, targeting academic researchers and scholarly publishers. Technically, the site is hosted behind Cloudflare DNS and CDN services, ensuring good performance and security. The platform supports secure authentication mechanisms such as Passkeys and centralized privacy controls, enhancing user security and experience. Security posture is strong with HTTPS enforced and domain transfer protections in place, although DNSSEC is not enabled and explicit security policies are not published. Privacy compliance is partially met with privacy and terms of use pages available, but lacks a cookie consent mechanism. Overall, the website is trustworthy, well-structured, and serves a critical role in the academic publishing ecosystem.

60
53
2
85
75
80
100
academicresearchpublishingidentitymanagementsinglesign-on+3 more
ReactMaterial-UICloudflare DNSOpenID Connect+2

Partner Domains:

atypon.com
partner
support.scienceconnect.io
service
2025-10-24T03:40:41.681Z
portfolium.com favicon

Instructure

portfolium.com

0
EducationUnited StatesenterpriseMEDIUM

Instructure is a leading educational technology company specializing in learning management systems (LMS) and edtech solutions for K–12, higher education, and business sectors. Their flagship product, Canvas LMS, is widely adopted and supported by a robust ecosystem of partners and community engagement. The company positions itself as a comprehensive provider of digital learning tools that empower educators and learners alike. Technically, the website is built on Drupal 10 CMS and leverages a modern technology stack including Google Tag Manager, Marketo, Microsoft Clarity, and various front-end libraries for performance and user experience. The site is mobile-optimized, accessible, and SEO-friendly, reflecting a mature digital infrastructure. From a security perspective, the site enforces HTTPS, employs multiple security headers, and integrates cookie consent mechanisms indicating GDPR compliance. Certifications such as SOC 2 and ISO 27001 further demonstrate a commitment to security standards. However, the absence of a publicly accessible security policy and incident response contact details suggests room for improvement in transparency and readiness. Overall, Instructure's website reflects a professional, trustworthy, and well-maintained digital presence aligned with its enterprise market position. The missing WHOIS data is a notable anomaly but does not significantly detract from the overall credibility given the strong branding and operational indicators.

60
88
22
85
62
85
100
educationedtechlearningmanagementsystemcanvask-12+2 more
Drupal 10Google Fonts (Manrope)Google Tag ManagerMarketo+7

Partner Domains:

portfolium.com
partner
app.masteryconnect.com
partner

+2 more partners

2025-10-24T02:34:11.450Z
stronghold.co favicon

Stronghold

stronghold.co

0
FinanceUnited StatesmediumMEDIUM

Stronghold is a fintech company specializing in providing modern payment and financial infrastructure solutions for businesses. Their platform enables instant settlement and interoperability between legacy and new payment networks, positioning them as an innovative player in the financial services sector. The company is recognized by industry leaders such as Visa and IBM, highlighting their market credibility and technological expertise. Their product suite includes ACH payments, merchant financing, card processing, and virtual payment networks, targeting businesses seeking efficient payment tools. Technically, the website is built on the Webflow CMS platform, leveraging a modern tech stack including Google Analytics, Facebook Pixel, Amplitude, and Segment for analytics and marketing. The site is well-optimized for performance, mobile responsiveness, and SEO, with a professional design and clear navigation. Hosting is managed via Webflow's CDN, ensuring fast content delivery. From a security perspective, Stronghold employs HTTPS with strong SSL configuration and security headers, demonstrating good security hygiene. However, the absence of a dedicated security policy, incident response information, and vulnerability disclosure mechanisms indicates areas for improvement in transparency and security readiness. Privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanisms, aligning with GDPR requirements. Overall, Stronghold presents a high-quality, trustworthy online presence with strong business credibility and technical maturity. The main risks relate to enhancing security transparency and incident response readiness to further strengthen stakeholder trust and compliance posture.

60
53
2
75
75
85
100
financepaymentsfintechblockchainb2b+2 more
WebflowGoogle AnalyticsFacebook PixelAmplitude+6

Partner Domains:

primetrust.com
partner
ibm.com
partner

+3 more partners

2025-10-24T00:03:31.975Z
prosegur.us favicon

Prosegur

prosegur.us

0
OtherUnited StatesenterpriseMEDIUM

Prosegur is a global security services provider offering integrated solutions including manned guarding, cybersecurity, and risk management, now operating in the USA. The company is recognized internationally for trustworthiness and excellence, holding awards from Newsweek and TIME. Their business model emphasizes hybrid security combining human expertise with advanced technology to deliver adaptive and scalable security solutions tailored to diverse industries. The website targets B2B clients seeking comprehensive security services. Technically, the website employs modern technologies such as Google Tag Manager, HubSpot forms, and Didomi consent management, hosted likely on SAP Commerce Cloud. The site is well-optimized for mobile and accessibility, with good SEO practices and performance. Privacy compliance is robust with clear cookie consent mechanisms and a comprehensive privacy policy hosted on a partner domain. Security posture is strong with HTTPS enforced, security headers present, and no visible vulnerabilities or exposed sensitive data. However, the site lacks explicit security policies or incident response contacts, which could be improved. WHOIS data is unavailable, which slightly reduces trust signals, but the overall legitimacy is supported by branding and external recognitions. Overall, Prosegur's website presents a professional, secure, and privacy-conscious digital presence suitable for its enterprise security services business, with recommendations to enhance transparency around security policies and incident response.

100
83
47
40
65
45
100
securitycybersecuritymannedguardingriskmanagementhybridsecurity+1 more
Google Tag ManagerHubSpot Collected FormsDidomi Consent Management SDKjQuery (implied by owl-carousel usage)+3

Partner Domains:

www.cipher.com
partner
www.prosegurresearch.com
related
2025-10-23T23:11:36.799Z
moneyyy.me favicon

1&1 Internet Inc

moneyyy.me

0
FinanceUnited StatessmallMEDIUM

moneyyy.me is an online platform launched in 2018 that facilitates users in requesting money via multiple popular payment platforms such as Venmo, PayPal, Cash App, Patreon, and OnlyFans through a single aggregated link. The service targets individuals and content creators who receive payments across these platforms, offering convenience and streamlined payment requests. The website is professionally designed with good user experience and mobile optimization, leveraging common web technologies including jQuery, Bootstrap, and FontAwesome, and integrates Google Analytics for user tracking. From a technical perspective, the site is hosted under the registrar IONOS SE (1&1 Internet Inc), with a domain age consistent with the business timeline. The technical stack is modern but lacks advanced security configurations such as DNSSEC and security headers. The site uses HTTPS, but no explicit security headers were detected in the HTML content. Privacy and cookie policies are absent, which impacts compliance and user trust. The registration form collects sensitive user data including email, username, password, and payment platform links, but no visible security or privacy disclosures are provided. Security posture is moderate with room for improvement. The absence of DNSSEC, security headers, and privacy policies are notable gaps. No incident response or vulnerability disclosure information is available. The domain registration is transparent and consistent with the website content, indicating legitimacy. No adult or explicit content is present, making the site safe for general audiences. Overall, moneyyy.me presents a niche financial service with a good user interface and functional design but requires enhancements in privacy compliance, security best practices, and transparency to improve trust and regulatory adherence.

20
35
2
70
85
70
100
paymentmoneyrequestvenmopaypalcashapp+4 more
jQuery 3.2.1jQuery UIFontAwesomeGoogle Analytics+1
2025-10-23T23:05:52.964Z
graphly.io favicon

Graphly

graphly.io

0
TechnologyUnited StatessmallCRITICAL

Graphly is a specialized SaaS platform providing advanced reporting and analytics tools tailored for Keap and Infusionsoft users. Established in 2014 and operating under the parent company LEAP, Graphly positions itself as a market leader with a strong focus on business growth through data visualization and actionable insights. The platform targets small to medium businesses seeking to optimize marketing, sales, and customer service performance through comprehensive reporting. The website reflects a professional and consistent brand image, supported by customer testimonials and a clear call to action for trial usage. Technically, the website is built on WordPress using the GeneratePress theme, leveraging modern JavaScript libraries and third-party analytics and marketing tools such as Google Analytics, Facebook Pixel, Inspectlet, and Crisp Chat. The site demonstrates good performance, mobile optimization, and SEO practices. Hosting appears to be managed via GoDaddy, consistent with the domain registrar information. From a security perspective, the site enforces HTTPS and employs domain status protections but lacks DNSSEC and some recommended security headers like Content-Security-Policy. No explicit security policy or incident response information is publicly available, which could be improved. Privacy compliance is partially addressed with a GDPR compliance badge and a privacy policy, but no cookie consent mechanism is detected. Overall, Graphly presents a trustworthy and professional online presence with a solid business model and technical foundation. Strategic improvements in security headers, cookie consent, and incident response transparency would enhance its security posture and compliance standing.

-
-
-
-
-
-
-
reportinganalyticskeapinfusionsoftsaas+4 more
WordPressGeneratePress themejQueryGoogle Tag Manager+6

Partner Domains:

leapmade.com
partner
parsey.com
partner

+1 more partners

2025-10-23T20:37:40.282Z
googlemaps.com favicon

Google LLC

googlemaps.com

0
TechnologyUnited StatesenterpriseMEDIUM

This website is a Google consent management page designed to handle user consent preferences for Google services, specifically Google Maps, targeting German users. It is part of Google's extensive ecosystem for privacy compliance and user data management. The page is professionally designed, mobile optimized, and uses modern web technologies consistent with Google's standards. The domain is a subdomain of google.com, which is a well-established and trusted domain owned by Google LLC, a subsidiary of Alphabet Inc. The WHOIS data for the subdomain is not separately registered, which is typical for such subdomains. Technically, the site employs Google's proprietary scripts and Material Design Components, hosted on Google Cloud Platform, ensuring fast performance and high availability. Security is robust with HTTPS enforced, comprehensive security headers, and no visible vulnerabilities. Privacy compliance indicators are moderate on this page alone, as explicit privacy and cookie policy links are not present here but are expected on parent domains. No contact information is directly provided on this page. Overall, the security posture is strong, with no detected vulnerabilities or suspicious elements. The site is safe for general audiences, with no adult or explicit content. The domain and content are consistent with a legitimate Google service, supporting a high trustworthiness rating. Strategic recommendations include maintaining security best practices, enhancing explicit privacy and cookie policy visibility, and continuous monitoring of third-party scripts.

35
68
2
83
75
90
100
consentprivacygooglemapsgdpr+2 more
JavaScriptHTML5CSS3Google proprietary scripts
2025-10-23T20:34:43.575Z
evidence.io favicon

Evidence

evidence.io

0
TechnologyUnited StatessmallHIGH

Evidence.io is a US-based SaaS company founded in 2018 that provides real-time social proof notification services designed to boost conversions and sales for marketers, e-commerce businesses, SaaS companies, agencies, and booking services. The platform integrates with popular tools such as Zapier, WordPress, Shopify, and others, positioning itself as a leading solution in social proof marketing. The website is professionally designed, mobile-optimized, and offers a free 14-day trial to attract users. Technically, the site is built on WordPress using Oxygen Builder, with a modern tech stack including various marketing and analytics tools such as Google Tag Manager, Facebook Pixel, and Inspectlet. Hosting is via AWS, ensuring reliable infrastructure. Security posture is solid with HTTPS enforced and domain transfer protection, though DNSSEC is not enabled and security headers are missing, which are recommended improvements. Privacy compliance is basic with a privacy policy and GDPR compliance badge present, but no cookie consent mechanism detected. Overall, the site is trustworthy, with consistent WHOIS data and clear business contact information. Strategic recommendations include enhancing DNS security, adding security headers, and improving privacy compliance mechanisms.

50
35
2
55
52
75
40
socialproofmarketingsaase-commerceconversionoptimization+5 more
WordPressYoast SEO pluginOxygen BuilderjQuery+7

Partner Domains:

leapmade.com
partner
graphly.io
partner

+1 more partners

2025-10-23T17:05:57.272Z
cartloom.com favicon

Cartloom

cartloom.com

0
E-commerceUnited StatessmallMEDIUM

Cartloom is a specialized ecommerce platform founded in 2007, offering easy-to-integrate shopping cart solutions and hosted storefronts for selling physical and digital products. The company targets website owners and online sellers seeking quick ecommerce enablement with minimal technical overhead. Cartloom maintains a niche market position with a focus on simplicity, digital goods delivery, and integration with major payment processors such as PayPal, Stripe, and AuthorizeNet. The website demonstrates strong branding consistency, professional design, and clear navigation, supporting a positive user experience. Technically, Cartloom employs modern frontend technologies including AlpineJS and uses privacy-conscious analytics via Fathom. The site is mobile-optimized and performs well, with good SEO and accessibility features. However, there is no detected CMS or explicit hosting provider information. The domain is well aged and consistent with the business history, registered since 2007 with no privacy protection, indicating transparency. From a security perspective, the site enforces HTTPS and has domain transfer protections but lacks DNSSEC and security headers such as Content-Security-Policy or X-Frame-Options. No explicit security or incident response policies are published, and no vulnerability disclosure or security.txt files are found. Privacy compliance is basic; a privacy policy and terms of service exist but lack explicit GDPR compliance statements and no cookie consent mechanism is present. Contact information is not explicitly provided on the site, which may impact user trust. Overall, Cartloom presents a professional and trustworthy ecommerce platform with solid technical foundations and a clear business model. To enhance security posture and privacy compliance, the company should implement security headers, cookie consent, GDPR statements, and publish incident response and vulnerability disclosure policies. Adding clear contact information would further improve business credibility and user trust.

40
53
2
85
77
85
100
ecommerceshoppingcartdigitalgoodsonlinestorepayments+3 more
AlpineJSFathom AnalyticsSVG graphicsCustom CSS

Partner Domains:

paypal.com
partner
stripe.com
partner

+2 more partners

2025-10-23T11:57:11.015Z