Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 99 of 107|Showing 4901-4950 of 5311
nationwide.com favicon

Nationwide Mutual Insurance Company

nationwide.com

0
FinanceUnited StatesenterpriseMEDIUM

Nationwide Mutual Insurance Company operates a comprehensive and professionally designed website offering a wide range of insurance and financial services including auto, home, life, pet, business insurance, and investment products. The company is a Fortune 100 enterprise with a strong market position in the finance sector, targeting individuals, families, and businesses. The website demonstrates consistent branding and high content quality, supporting a positive user experience and clear navigation. Technically, the site uses modern JavaScript libraries, a proprietary design system (Bolt), and integrates multiple analytics and marketing tools, hosted primarily via Akamai CDN services. However, the SSL certificate is invalid or missing, significantly impacting the security posture. Security headers are well implemented, but the lack of valid HTTPS undermines trust and security. Privacy and cookie policies are present and indicate GDPR compliance, with clear contact phone numbers and social media presence enhancing business credibility. Overall, the site is highly professional but requires urgent remediation of SSL issues to improve security and user trust.

70
25
25
50
50
85
100
insurancefinancialservicesnationwideautoinsurancehomeinsurance+5 more
Apache serverNew Relic monitoringGoogle Tag ManagerTyped.js+9

Partner Domains:

nationwideexcessandsurplus.com
partneranalyzing...
nationwidefinancial.com
partnerpending

+1 more partners

2025-06-14T22:22:37.295Z
bluevine.com favicon

Bluevine Inc.

bluevine.com

0
FinanceUnited StateslargeMEDIUM

Bluevine Inc. operates a comprehensive business banking platform targeting small and medium-sized businesses, startups, and self-employed professionals in the United States. The company offers integrated financial products including business checking accounts, various types of business loans, credit cards, and invoicing/payment link solutions. Positioned as one of the largest small business banking platforms in the U.S., Bluevine emphasizes ease of use, lower fees, and access to working capital through partnerships with FDIC-insured banks and lending institutions. The website content is professionally designed, well-structured, and rich in relevant business information, targeting business owners seeking modern financial solutions. Technically, the site is built on a modern stack using Next.js and React, hosted on Netlify, and integrates multiple analytics and marketing tools. However, the security posture is weakened by the absence of a valid SSL certificate and disabled TLS protocols, which are critical for secure communications. Privacy compliance is well addressed with clear policies and consent mechanisms. Overall, Bluevine presents a credible and trustworthy business platform but must urgently address SSL/TLS issues to ensure secure user interactions.

80
43
25
50
50
90
100
businessbankingsmallbusinessfinancialtechnologybusinessloansbusinesschecking+3 more
Next.jsReactNetlifyStripe+5

Partner Domains:

coastalbank.com
partner59
celticbank.com
partneranalyzing...

+2 more partners

2025-06-14T22:16:37.654Z
veteransunited.com favicon

Veterans United Home Loans

veteransunited.com

0
FinanceUnited StateslargeMEDIUM

Veterans United Home Loans is a leading mortgage lender specializing in VA home loans, serving veterans and military families across the United States. The company holds a strong market position as the top VA purchase lender by volume for multiple consecutive years, offering a comprehensive suite of services including VA loans, refinancing, realty, insurance, and credit building. Their website reflects a professional and user-friendly digital presence with extensive educational content, customer reviews, and interactive tools such as mortgage calculators and eligibility forms. Technically, the site leverages a modern JavaScript stack with jQuery, Google Tag Manager, and custom form frameworks, hosted on AWS infrastructure. However, the security posture is currently weak due to the absence of a valid SSL certificate and disabled TLS protocols, which poses a significant risk to user data confidentiality and trust. Privacy policies and cookie consent mechanisms are well implemented, supporting compliance with general privacy standards. Overall, the site demonstrates strong business credibility and digital maturity but requires urgent remediation of its SSL/TLS configuration to ensure secure user interactions.

55
43
17
50
90
90
100
valoansmortgageveteranshomeloansfinance+1 more
PHP 7.4.33jQuery 3.6.0Tiny SliderMoment.js+4

Partner Domains:

mortgageresearchcenter.com
subsidiary53
neighborsbank.com
partner54

+2 more partners

2025-06-14T22:11:25.753Z
pomelo.com favicon

Pomelo International, Inc.

pomelo.com

0
FinanceUnited StatesmediumMEDIUM

Pomelo International, Inc. operates a specialized financial services platform focused on international money transfers primarily to the Philippines and Mexico. The company differentiates itself by offering no transfer fees, a proprietary Pomelo Mastercard® credit card designed for money transfer with rewards points, and 24/7 customer support. The website is professionally designed, mobile-optimized, and rich in content, targeting individuals sending money internationally from the US. Technically, the site leverages modern web technologies including Webflow CMS, Cloudflare CDN, and integrates multiple analytics and marketing tools such as Google Tag Manager, Segment, Facebook Pixel, and Reddit Pixel. Security features are prominently highlighted on the site, including biometric security and advanced encryption. However, a critical security weakness is the invalid or missing SSL certificate and lack of TLS protocol support, which significantly impacts the security posture and user trust. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Overall, the site presents a strong business credibility and user experience but requires urgent remediation of SSL/TLS issues to ensure secure transactions and maintain customer trust.

60
43
25
50
50
85
100
moneytransferfinanceremittancecreditcardpomelomastercard+4 more
Webflow CMSGoogle Tag ManagerFacebook PixelReddit Pixel+6

Partner Domains:

coastalbank.com
partnerpending
2025-06-14T22:02:07.065Z
complyadvantage.com favicon

ComplyAdvantage

complyadvantage.com

0
FinanceN/aenterpriseMEDIUM

ComplyAdvantage is a leading enterprise SaaS provider specializing in AI-driven fraud and Anti-Money Laundering (AML) risk detection solutions. The company offers a comprehensive risk intelligence platform that automates manual compliance processes, significantly reduces false positives, and accelerates onboarding cycles. With a strong market position and recognition as a category leader in KYC solutions, ComplyAdvantage serves over 3000 global businesses across the financial sector and fintech industries. Technically, the website is built on WordPress with modern frontend technologies including jQuery and Bootstrap. It leverages Cloudflare for hosting and CDN services and integrates Google Tag Manager and Cookiebot for analytics and consent management. The site demonstrates good mobile optimization, accessibility, and SEO practices, though performance metrics are moderate. From a security perspective, while several security headers are properly configured, the absence of a valid SSL certificate and lack of HTTPS support represent critical vulnerabilities. This significantly lowers the security posture and exposes the site to risks. Privacy compliance is strong with clear policies and consent mechanisms in place. Overall, the website is professional, content-rich, and trustworthy but requires urgent remediation of SSL/TLS issues to ensure secure user interactions and maintain compliance with industry standards.

90
40
25
85
50
90
100
amlfrauddetectionfinancialcrimecomplianceriskintelligence+3 more
jQuery 3.6.4Google Tag ManagerCookiebotMutiny personalization client+4
2025-06-14T21:49:58.744Z
thoughtmachine.net favicon

Thought Machine Group Limited

thoughtmachine.net

0
FinanceUnited KingdomlargeMEDIUM

Thought Machine Group Limited is a leading provider of cloud-native core banking and payments platforms, offering innovative solutions such as Vault Core and Vault Payments. Their technology empowers banks and fintechs worldwide to build flexible, scalable financial products and payment schemes. Recognized as a leader in the 2025 Gartner Magic Quadrant for Retail Core Banking Systems, Thought Machine serves a global clientele including major financial institutions and investors. The website reflects a mature digital presence with comprehensive content, multi-language support, and strong branding. Technically, the site leverages modern web technologies including Webflow CMS, JavaScript libraries, and integrates marketing and analytics tools such as HubSpot, Google Analytics, and LinkedIn Insight. However, the site suffers from a lack of a valid SSL certificate and absence of key security headers, which significantly impacts its security posture. Performance is suboptimal with slow load times and a large number of resources. Security-wise, while no critical vulnerabilities or malware indicators were found, the missing HTTPS and security headers represent a major risk that should be addressed promptly. Privacy compliance is well-handled with a clear privacy policy and cookie consent mechanism via Cookiebot. Contact information is detailed with multiple global office addresses and a contact form, but no direct company emails or phone numbers were found. Overall, Thought Machine's website is professional and content-rich, supporting its position as a trusted technology provider in the finance sector. Addressing the SSL and security header issues would greatly enhance trust and security for visitors and clients.

45
43
25
50
50
85
100
corebankingcloudnativefinancepaymentsbankingtechnology+2 more
JavaScriptjQueryWebflowGoogle Tag Manager+9

Partner Domains:

avature.net
partner98
2025-06-14T21:41:56.489Z
D

DZ BANK AG Deutsche Zentral-Genossenschaftsbank

vr-bankenportal.de

0
FinanceGermanyenterpriseHIGH

The VR-BankenPortal website is a secure login portal designed for cooperative banks affiliated with DZ BANK AG, one of Germany's leading cooperative central banks. It provides customers and members with access to online banking services, including account management and password reset functionalities. The portal is clearly branded with DZ BANK's identity and targets banking customers within the cooperative banking sector in Germany. The business model focuses on providing secure digital access to banking services rather than direct customer engagement or marketing. From a technical perspective, the website employs modern TLS protocols (TLS 1.3 and 1.2) and is hosted on Google Cloud infrastructure. However, the site exhibits slow load times and lacks advanced security headers and cookie consent mechanisms. The absence of structured data and analytics scripts suggests a minimalistic approach focused solely on secure login functionality. Mobile optimization and accessibility are basic, indicating room for improvement in user experience. Security posture is adequate but not robust. HTTPS is enforced with a valid certificate, but critical security enhancements such as HSTS, OCSP stapling, DMARC records, and security headers are missing. The login form posts credentials securely to a DZ BANK domain, reducing phishing risk. No vulnerabilities or exposed sensitive data were detected, but the lack of certain security best practices lowers the overall security score. Overall, the website is functional and trustworthy for its intended purpose but would benefit from performance optimization, enhanced security configurations, and improved privacy compliance measures. Strategic improvements in these areas would strengthen user trust and regulatory adherence.

90
18
25
70
87
80
100
bankinglogincooperativebanksfinancesecureportal
HTML5CSSTLS 1.3TLS 1.2

Partner Domains:

dzbank.de
partner40
2025-06-14T20:56:27.692Z
vr-payment.de favicon

VR Payment GmbH

vr-payment.de

0
FinanceGermanymediumHIGH

VR Payment GmbH is a specialized payment solutions provider serving the Volksbanken Raiffeisenbanken network and their merchants. The company offers a broad range of services including card readers, terminals, cashless payment methods, e-commerce payment integration, and value-added services such as digital receipt management and mobile payment solutions. The website reflects a professional and consistent brand presence targeting merchants, banks, and resellers within the financial and payment technology sectors in Germany. The company maintains a medium-sized market presence with a focus on innovation and customer-centric payment solutions. Technically, the website is built on the Contao CMS platform and leverages modern JavaScript libraries such as jQuery, jQuery UI, and Swipe.js for UI interactions. It uses Matomo for analytics and Usercentrics for consent management, indicating a mature approach to user privacy and data tracking. However, the website suffers from a critical security deficiency due to an invalid or missing SSL certificate and lack of enabled TLS protocols, which severely undermines HTTPS security and user trust. From a security perspective, while the site has HSTS enabled with preload and a valid SPF record, the absence of a valid SSL certificate and TLS support is a major vulnerability. No incident response or explicit security policy information is found, and no vulnerability disclosure or security.txt file is present. Privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanism. Contact information is readily available through multiple channels including email, phone, and detailed contact forms. Overall, the website is content-rich, professionally designed, and privacy-conscious but critically impaired by its SSL/TLS configuration issues. Immediate remediation of the SSL certificate and enabling modern TLS protocols is essential to restore security posture and trustworthiness.

85
18
25
70
100
80
20
paymentfinancee-commerceposgdpr+3 more
jQueryjQuery UISwipe.jsMatomo Analytics+2

Partner Domains:

vr-pay-ecommerce.de
partnerpending
vr-payment-webportalpos.de
partnerpending

+1 more partners

2025-06-14T20:54:15.707Z
S

Sparkassen-Finanzgruppe (implied)

sparkassen-mediacenter.de

0
FinanceGermanymediumHIGH

The website sparkassen-mediacenter.de serves as a centralized media management platform primarily targeting the Sparkassen-Finanzgruppe, a major financial group in Germany. It offers a suite of services including video content management, podcasts, interactive videos, and playlist creation, aimed at enhancing digital content distribution within the group's online platforms. The platform is positioned as an internal tool to streamline media content handling and ensure secure access to both public and internal video assets. Technically, the site is built on a traditional Apache server with standard HTML, CSS, and JavaScript assets. However, it lacks modern security infrastructure, notably missing a valid SSL/TLS certificate and HTTPS support, which significantly undermines its security posture. The site includes multiple JavaScript libraries and CSS bundles but does not leverage modern frameworks or CMS platforms. Security headers are partially implemented, but critical HTTPS and TLS configurations are absent. Privacy compliance is minimal, with a privacy policy present but no cookie consent mechanism or GDPR compliance indicators. Contact information is limited to a phone number and support ticket instructions, with no email addresses or social media presence. Overall, the site demonstrates moderate business credibility and good content relevance but suffers from critical security shortcomings that must be addressed to protect user data and maintain trust.

55
18
25
50
50
85
100
mediavideopodcastfinancesparkassen
ApacheJavaScriptCSSHTML5

Partner Domains:

dbc-gmbh.com
partnerpending
2025-06-14T20:04:09.295Z