Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 205 of 206|Showing 10201-10250 of 10253
djreprints.com favicon

Dow Jones

djreprints.com

0
media and publishingUnited StatesmediumMEDIUM

The website exhibits a concerning security posture with no critical issues but multiple high and medium severity vulnerabilities, primarily related to missing security headers, GDPR compliance gaps, and lack of foundational NIS2 security documentation. The absence of key HTTP security headers such as Strict-Transport-Security, X-Frame-Options, and Content-Security-Policy exposes the site to common web-based attacks like clickjacking, content injection, and downgrade attacks. GDPR compliance deficiencies, including missing cookie consent and incomplete privacy policies, present legal and reputational risks. Furthermore, the lack of an information security framework, incident response procedures, and security policy documentation indicates immature security governance. While email security, SSL/TLS, DNS health, and network security show relatively strong scores, the overall low NIS2 compliance score signals significant gaps in regulatory adherence and operational readiness. Immediate focus on governance, policy implementation, and security header configuration will mitigate business risks and enhance trust. Addressing these issues is critical to safeguarding customer data, ensuring regulatory compliance, and maintaining brand reputation.

15
58
25
85
85
85
100
reprintslicensingmediapublishingDow Jones
WordPressGenesis Blocks PluginAstra ThemejQuery+2

Partner Domains:

dowjones.com
subsidiary93
wsj.com
sister companyanalyzing...

+1 more partners

2025-06-13T20:15:22.289Z
R

Restoration Hardware

restorationhardware.com

0
home furnishingsUnited StateslargeMEDIUM

The website demonstrates a mixed security posture with no critical vulnerabilities but several high and medium-risk issues that could expose the business to significant threats. Major gaps exist in security headers, GDPR compliance, and adherence to the NIS2 directive, particularly around incident response and information security frameworks. The absence of essential security headers like Content-Security-Policy and X-Frame-Options increases the risk of web-based attacks such as clickjacking and cross-site scripting. GDPR compliance weaknesses, including missing cookie consent and privacy policy concerns, expose the business to regulatory penalties and reputational damage. Key NIS2 deficiencies highlight a lack of documented security policies and incident management, which could impair response to cyber incidents. SSL/TLS weaknesses and missing DNS security measures further elevate risk by potentially allowing interception or manipulation of data. Positively, email security and network security postures are strong, reducing some risks related to email spoofing and network-based attacks. Overall, urgent remediation is needed to protect the business, customer data, and ensure regulatory compliance while maintaining stakeholder trust.

30
58
25
90
72
85
100
Restoration Hardwarefurniturehome accessorieslightingluxury+1 more
ReactGoogle Analytics

Partner Domains:

rh.com
servicepending
adyen.com
payment68

+2 more partners

2025-06-13T18:10:51.514Z
fmssolutions.com favicon

FMS Solutions

fmssolutions.com

0
Profit maximization, technology, outsourcingUnited StatesmediumMEDIUM

The website demonstrates significant security weaknesses, particularly in critical HTTP security headers, GDPR compliance, and adherence to NIS2 cybersecurity requirements. No critical vulnerabilities were found, but twelve high-severity issues indicate substantial risk exposure, especially related to missing security headers and lack of privacy policies. The absence of key headers like Strict-Transport-Security, X-Frame-Options, and Content-Security-Policy increases susceptibility to common web attacks such as clickjacking, man-in-the-middle, and cross-site scripting. GDPR compliance gaps, including missing privacy and cookie policies and consent mechanisms, expose the business to regulatory penalties and reputational damage. Additionally, the lack of documented information security frameworks, incident response, and business continuity plans under NIS2 requirements presents operational risks. SSL/TLS implementation is weak due to expiring certificates, weak key lengths, and mixed content, which may undermine user trust and data confidentiality. DNS and network security are relatively strong, but DNSSEC and CAA records should be configured to enhance domain integrity. Immediate remediation is necessary to protect customer data, maintain compliance, and safeguard business continuity.

25
25
25
100
50
85
100
profit maximizationtechnologyoutsourcingBPOtax management+2 more
WordPress 6.8.1jQuery 3.7.1Google Tag Manager (gtag.js)Formsite embed+5
2025-06-13T18:10:51.492Z
johnsoncontrols.com favicon

Johnson Controls

johnsoncontrols.com

0
Building Automation and ControlsUnited StatesenterpriseMEDIUM

The website demonstrates a moderate security posture with no critical vulnerabilities found; however, several high and medium-risk issues significantly impact compliance and risk management. Key deficiencies exist in GDPR compliance, including the absence of privacy and cookie policies and lack of user consent mechanisms, exposing the business to regulatory penalties and reputational damage. The absence of a documented information security framework, incident response procedures, and security policies under NIS2 guidance further increases organizational risk and may hinder regulatory adherence. Security headers are inconsistently implemented, reducing protection against common web threats like XSS and content sniffing. SSL/TLS configurations are generally strong but require timely certificate renewal and elimination of mixed content to maintain secure communications. DNS settings are mostly healthy but can be improved by enabling DNSSEC to prevent domain spoofing. Positively, email and network security postures are robust, mitigating some external attack vectors. Overall, urgent attention to compliance and governance-related controls is critical to safeguard the business and maintain trust with users and regulators.

60
25
25
100
80
85
100
OpenBlueArtificial IntelligenceHealthy BuildingsAI in Building ManagementNet Zero Buildings+4 more
jQueryBootstrap 4Coveo SearchGoogle Maps API+15
2025-06-13T18:10:48.990Z