Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 482 of 516|Showing 24051-24100 of 25766
duckdiverllc.com favicon

Duck Diver Marketing

duckdiverllc.com

0
OtherN/asmallHIGH

Duck Diver Marketing is a specialized marketing agency offering on-demand marketing services primarily targeting the dive industry. Their key offerings include social media management, SEO services, website creation, and online advertising management. The company positions itself as a flexible marketing partner for small to medium businesses, providing à la carte and full-service marketing solutions. The website content and branding are consistent and professional, reflecting a niche market focus with a history dating back to at least 2011. Technically, the website is built on WordPress using CherryFramework and Bootstrap, integrating WooCommerce and popular plugins like Contact Form 7 and Yoast SEO. The site employs Google Analytics and Jetpack for tracking, indicating moderate digital maturity. Performance and mobile optimization are good, though accessibility features are basic. The site uses HTTPS but lacks advanced security headers, which could be improved to enhance security posture. From a security perspective, the site shows no critical vulnerabilities or exposed sensitive data. However, the absence of privacy and cookie policies, as well as missing WHOIS registration data, raises concerns about compliance and domain legitimacy. No incident response or security policy information is provided, limiting transparency. Overall, the security posture is moderate but could benefit from enhancements in policy visibility and technical safeguards. The domain WHOIS data is unavailable or unregistered according to the raw WHOIS output, which is inconsistent with the active website presence. This discrepancy reduces trustworthiness and suggests the need for further verification. The website is accessible without WAF or security challenges, allowing full content analysis. Strategic recommendations include implementing privacy and cookie policies, improving security headers, verifying domain registration, and enhancing accessibility and compliance measures.

15
50
17
85
62
75
20
marketingseosocialmediawebsitecreationdiveindustry+1 more
WordPressWooCommercejQueryBootstrap+3
2025-06-23T10:21:25.258Z
ucimtbworldseries.com favicon

WHOOP UCI Mountain Bike World Series

ucimtbworldseries.com

0
OtherN/asmallMEDIUM

The WHOOP UCI Mountain Bike World Series website serves as the official digital hub for the UCI Mountain Bike World Series, providing event calendars, news, results, rankings, and rider registration. The site targets mountain bike enthusiasts, athletes, and fans, positioning itself as a key information source within the mountain biking sports domain. The business model revolves around event promotion and community engagement within the mountain biking sport sector. Technically, the website employs modern web technologies including Tailwind CSS, Alpine.js, and Vite, hosted on AWS infrastructure, with Google Analytics and OneTrust for tracking and cookie consent respectively. The site is mobile optimized and features good SEO practices. Security posture is solid with HTTPS, CSRF tokens, and content security policies, though it lacks some advanced security disclosures such as a security.txt file or explicit incident response contacts. Privacy compliance is partial, with a cookie consent mechanism but no visible privacy policy or terms of service. Overall, the domain registration is consistent and legitimate, with no suspicious indicators. Strategic recommendations include publishing comprehensive privacy and terms policies, enabling DNSSEC, and adding vulnerability disclosure information to enhance trust and compliance.

65
88
2
85
67
85
100
uciucimtbworldseriesewsenduroworldseries+3 more
JavaScriptTailwind CSSAlpine.jsGoogle Tag Manager+1
2025-06-23T10:21:20.216Z
J

DNS points to prohibited IP | joma-sport.com | Cloudflare

joma-sport.com

0
OtherN/asmallHIGH

The website joma-sport.com is currently inaccessible due to a Cloudflare error 1000 indicating that the DNS resolves to a prohibited IP address. This prevents any meaningful content from being served to visitors, resulting in a complete block of the website's front-end. The domain is registered since 1997 with Acens Technologies, S.L.U. as the registrar, indicating a long-standing domain ownership. However, the current DNS misconfiguration severely impacts the website's availability and trustworthiness. From a technical perspective, the site relies on Cloudflare for DNS and security services, but the misconfiguration causes a critical failure. No content, metadata, or business information is accessible, and no privacy or security policies are published. The lack of security headers and absence of SSL configuration details further highlight the immature security posture, although this cannot be fully assessed due to the block. Security-wise, the primary issue is the DNS misconfiguration causing Cloudflare to block access. This is a critical vulnerability that must be resolved immediately to restore service. No other security or compliance information is available. Overall, the website's risk profile is high due to unavailability and lack of transparency. Strategic remediation should focus on correcting DNS settings, enabling DNSSEC, publishing privacy and security policies, and implementing standard security headers to improve trust and compliance.

15
35
2
60
57
80
100
Cloudflare
2025-06-23T10:20:40.044Z
fdprealvalladolid.com favicon

Federación de Peñas del Real Valladolid

fdprealvalladolid.com

0
OtherSpainsmallHIGH

Federación de Peñas del Real Valladolid is a non-profit organization founded in 1995 that serves as the official federation of fan clubs (peñas) supporting the Real Valladolid football club in Spain. The website provides news, event information, and resources for fans and collaborators, reinforcing community identity and engagement around the club. The organization maintains active social media channels and offers clear contact information and policies, reflecting a mature community-focused entity. Technically, the website is built on WordPress with common plugins such as Yoast SEO and MasterSlider, and integrates Google Analytics and ShareThis for analytics and social sharing. The site is served over HTTPS with good SSL configuration, and the content is well-structured with SEO and mobile optimization considered. However, some security headers are missing, and no explicit security or incident response policies are published. From a security perspective, the website shows good practices like HTTPS enforcement and secure forms but lacks advanced security headers and vulnerability disclosure mechanisms. The absence of WHOIS registration data for the domain is a notable anomaly that reduces trustworthiness, although the website content and affiliations suggest legitimacy. Overall, the site is functional, professional, and compliant with privacy regulations, but the domain registration inconsistency warrants further investigation. Strategic improvements in security policies and WHOIS transparency would enhance trust and security posture.

15
50
17
55
42
80
-
sportsfootballfanclubrealvalladolidcommunity+1 more
WordPressYoast SEOMasterSliderjQuery+2

Partner Domains:

realvalladolid.es
partner
diariodeaficionesunidas.es
partner
2025-06-23T10:17:33.353Z
realsociedad.eus favicon

Real Sociedad de Fútbol S.A.D.

realsociedad.eus

0
OtherSpainlargeMEDIUM

Real Sociedad de Fútbol S.A.D. is a professional football club based in Spain, operating an official website that serves as a hub for club news, match information, ticket sales, and fan engagement. The website targets football fans and supporters of the club, providing content primarily in Spanish with multiple language alternatives. The business model centers on sports entertainment and merchandising, positioning the club as a well-established entity in the Spanish football market. The website branding is consistent and professional, reinforcing the club's identity and trustworthiness. Technically, the website employs modern web technologies including Google Tag Manager, Cookiebot for cookie consent management, and Google DoubleClick for advertising. The site is mobile-optimized and includes SEO best practices such as Open Graph and Twitter Card metadata. Performance is moderate, with good mobile responsiveness and basic accessibility features. Hosting and CMS details are not explicitly identified but the infrastructure supports a professional online presence. From a security perspective, the website enforces HTTPS with strong SSL configuration and includes security headers inferred from scripts. Cookie consent mechanisms comply with GDPR, and no exposed sensitive data or vulnerable libraries were detected in the analyzed HTML. However, the site lacks explicit security policy pages, incident response contacts, and vulnerability disclosure mechanisms, which are recommended for enhanced security posture. Overall, the website is legitimate and professionally maintained, with privacy-protected WHOIS data typical for such organizations. The absence of public WHOIS details does not detract from the site's credibility given the consistent branding and security practices. Strategic recommendations include publishing clear security and incident response policies, improving accessibility, and providing explicit contact information for security and abuse reporting to further strengthen trust and compliance.

75
88
17
85
65
75
100
sportsfootballrealsociedadcookieconsentgdpr+3 more
Google Tag ManagerCookiebotDoubleClick GPTFacebook Pixel
2025-06-23T09:11:24.932Z
athletic-club.eus favicon

Athletic Club

athletic-club.eus

0
OtherSpainlargeMEDIUM

Athletic Club operates a comprehensive official website serving as the primary digital presence for the historic football club based in Bilbao, Spain. The site offers extensive content including latest news, team rosters, ticket sales for matches and tours, official merchandise stores, and membership information. It targets football fans, club members, and tourists interested in the club's activities and heritage. The business model revolves around fan engagement, ticketing, merchandising, and exclusive experiences, positioning Athletic Club as a prominent sports entity with a large and loyal audience. Technically, the website leverages modern web technologies such as the Astro framework, Google Tag Manager, Microsoft Clarity, and Cookiebot for analytics and privacy compliance. The site is well-optimized for mobile devices, features good accessibility practices, and maintains strong SEO fundamentals. Performance is fast, and the site structure supports multilingual content in Spanish, Basque, and English, enhancing its reach. From a security perspective, the site enforces HTTPS with excellent SSL configuration and implements multiple security headers to protect users. Privacy compliance is robust with clear cookie consent mechanisms and a comprehensive privacy policy. However, there is a lack of publicly available security policies or incident response contacts, which could be improved to enhance transparency and trust. Overall, Athletic Club's website demonstrates a mature digital presence with strong business credibility and security posture. The domain is privacy protected, which is typical and justified for this type of organization. The site is trustworthy, professional, and well-maintained, supporting the club's brand and operational goals effectively.

35
65
17
65
100
75
100
sportsfootballclubticketsmerchandise+3 more
Astro frameworkGoogle Tag ManagerMicrosoft ClarityCookiebot+1

Partner Domains:

shop.athletic-club.eus
partner
tienda.athletic-club.eus
partner

+3 more partners

2025-06-23T09:10:14.525Z
alpcot.se favicon

alpcot.se

alpcot.se

0
OtherN/asmallMEDIUM

The website www.alpcot.se currently presents minimal accessible content, displaying an error message indicating the page could not be loaded. The site is built using modern technologies such as Blazor server-side framework, Radzen components, and Bootstrap CSS for styling. PostHog analytics is integrated for user behavior tracking. However, the lack of visible business information, contact details, and policy documents significantly limits the ability to assess the company's market position or business model. The domain queried (www.alpcot.se) is a subdomain, with no WHOIS data found, which reduces trustworthiness and raises questions about domain registration consistency. From a technical perspective, the site implements a Content-Security-Policy header and enforces HTTPS, which are positive security indicators. Nevertheless, the absence of privacy and cookie policies, incident response information, and vulnerability disclosure mechanisms highlights compliance gaps. The user experience is poor due to the error page and lack of navigable content, and SEO and accessibility optimizations are minimal. Security posture is moderate with basic best practices in place but lacks comprehensive policies and contact channels for security incidents. Overall, the website's risk profile is elevated due to minimal content, lack of transparency, and incomplete compliance documentation. Strategic improvements are needed to enhance trust, compliance, and user experience.

30
10
17
70
82
75
100
blazorradzenposthogbootstrapanalytics+2 more
BlazorRadzen.BlazorBootstrapPostHog
2025-06-23T09:09:29.293Z
T

triggle.app

triggle.app

0
OtherN/asmallHIGH

The website at triggle.app is currently inaccessible or blocked, displaying only a minimal JSON error message indicating a missing authentication token. This suggests the URL may be an API endpoint or a backend service requiring authentication rather than a public-facing website. Due to the lack of accessible content, no business description, contact information, or policies are available for analysis. The technical infrastructure cannot be assessed beyond the indication that the site is not publicly accessible without credentials. From a security perspective, the absence of HTTPS confirmation, security headers, and any visible security or privacy policies indicates a very low security posture. The lack of accessible content also prevents evaluation of compliance with GDPR or other regulations. The domain's WHOIS data is privacy protected, which is common but, combined with the lack of public business information, reduces trustworthiness. Overall, the site scores very low on content quality, technical implementation, security posture, privacy compliance, and business credibility. The primary risk is the inability to verify the legitimacy or security of the service behind the domain. Strategic recommendations include enabling public access to a landing page with business and compliance information, implementing HTTPS and security headers, and publishing privacy and cookie policies to improve trust and compliance.

-
40
17
-
77
85
100
2025-06-23T07:43:06.628Z
igc.services favicon

iGaming Content Services

igc.services

0
OtherN/asmallMEDIUM

iGaming Content Services is a specialized B2B agency focused exclusively on providing content, SEO, translations, localisation, and outreach services tailored for the iGaming industry. Established in 2016, the company leverages native language experts and industry veterans to deliver high-quality, non-AI-generated content across over 40 languages and multiple global markets. Their market position is that of a niche expert with a strong reputation for transparency, efficiency, and long-term client relationships. Technically, the website is built on WordPress using Oxygen Builder, enhanced with modern tools such as Google Tag Manager, Google Analytics, and GDPR-compliant cookie management via Complianz. The site features interactive elements like Lottie animations and uses CAPTCHA for form security, reflecting a mature digital infrastructure. Performance and mobile optimization are good, though accessibility could be improved. From a security perspective, the site enforces HTTPS and employs consent mechanisms for cookies, but lacks explicit security headers and published security policies. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is strong, with clear privacy and cookie policies and GDPR adherence. Business credibility is supported by professional content, consistent branding, and social media presence, though direct contact emails and phone numbers are not publicly listed. Overall, the website presents a low-risk profile with solid security and privacy practices, a clear business focus, and a professional digital presence. Strategic improvements in security headers, incident response transparency, and accessibility would further enhance trust and compliance.

70
80
17
85
75
85
100
igamingcontentservicesseotranslationslocalisation+2 more
WordPressOxygen BuilderGoogle Tag ManagerGoogle Analytics+4
2025-06-23T07:42:51.587Z
C

Access Denied

carwise.com

0
OtherN/asmallCRITICAL

The website carwise.com is currently inaccessible due to a security block or Web Application Firewall (WAF) restriction, as evidenced by the 'Access Denied' page and reference to errors.edgesuite.net. This prevents any meaningful extraction of business, technical, or security information from the site content. Consequently, no metadata, structured data, contact details, or policy documents are available for analysis. The lack of accessible content severely limits the ability to assess the company's market position, services, or compliance posture. From a technical perspective, the site appears to be protected by a generic WAF or security mechanism, which is effectively blocking access. No information about the technology stack, hosting provider, or performance characteristics can be determined. Security headers, SSL configuration, and other best practices cannot be evaluated due to the absence of accessible content. Security posture evaluation is constrained by the lack of data. No vulnerabilities, incident response contacts, or certifications are visible. The domain's WHOIS data is privacy protected, which is common but limits trust assessment. Overall, the site scores very low on all AI scoring metrics due to inaccessibility. Given these limitations, the overall risk assessment is that the site cannot be reliably analyzed in its current state. Strategic recommendations include working with the hosting or security provider to allow safe access for analysis and ensuring that public-facing content is accessible for transparency and trust building.

-
-
-
-
-
-
-
2025-06-23T06:39:29.194Z
religioussistersofcharity.ie favicon

Religious Sisters of Charity

religioussistersofcharity.ie

0
OtherIrelandmediumCRITICAL

The Religious Sisters of Charity website represents a well-established non-profit religious organization engaged in education, healthcare, social and pastoral care, and human rights advocacy. Founded in 1815 in Dublin, Ireland, the organization maintains an international presence with communities in multiple countries. The website provides comprehensive information about their mission, history, vocations, and current activities, targeting supporters, potential vocations, and the general public interested in their charitable works. Technically, the website is built on WordPress using the Genesis Framework and several plugins including Yoast SEO and MonsterInsights for analytics. The site is moderately performant, mobile-optimized, and SEO-friendly, though accessibility features are basic. Security posture is good with HTTPS enforced and no exposed sensitive data, but lacks security headers and a cookie consent mechanism, which are areas for improvement. Overall, the security posture is solid but could be enhanced by implementing additional security headers and formalizing privacy and incident response policies. The domain registration details align well with the organization's identity, supporting legitimacy and trustworthiness. The site effectively supports the organization's mission and outreach but should address privacy compliance gaps to reduce regulatory risk.

-
-
-
-
-
-
-
non-profitreligiouscharityeducationhealthcare+2 more
WordPressYoast SEO pluginGoogle Analytics (MonsterInsights)jQuery+4
2025-06-23T03:14:01.455Z
weeeireland.ie favicon

WEEE Ireland

weeeireland.ie

0
OtherIrelandmediumCRITICAL

WEEE Ireland is a well-established Irish compliance scheme focused on the recycling of electrical and battery waste. The organization supports householders, producers, and retailers by providing free recycling services and promoting environmental sustainability. The website reflects a medium-sized organization with a clear market position as a leader in electrical waste recycling in Ireland. Their key services include collection, delivery, and support for members in compliance with environmental regulations. The company is ISO certified, enhancing its credibility and trustworthiness. Technically, the website is built on WordPress with modern SEO and privacy compliance plugins such as Yoast SEO and Complianz GDPR Cookie Consent. It uses Google reCAPTCHA for form security and integrates social media platforms for broader engagement. The site is mobile-optimized and performs moderately well, with good SEO and basic accessibility features. From a security perspective, the site enforces HTTPS, uses reCAPTCHA to protect forms, and manages cookie consent effectively. However, it lacks explicit security headers and a published security policy or incident response contact, which are recommended for enhanced security posture. No vulnerabilities or exposed sensitive data were detected. Overall, the website is professional, trustworthy, and compliant with GDPR requirements. It serves its target audience effectively with clear navigation and relevant content. Strategic recommendations include improving security headers, publishing a security policy, and enhancing accessibility to further strengthen the site's security and compliance posture.

-
-
-
-
-
-
-
recyclingenvironmentcomplianceirelandelectricalwaste+2 more
WordPressYoast SEOContact Form 7Complianz GDPR Cookie Consent+2
2025-06-23T03:13:46.341Z
N

Attention Required! | Cloudflare

nssdh.com.au

0
OtherN/asmallCRITICAL

The website nssdh.com.au is currently inaccessible due to a Cloudflare Web Application Firewall (WAF) block. The page presented is a standard Cloudflare block page indicating that the visitor's request triggered security rules, preventing access to the site content. Consequently, no business information, contact details, or policy documents are available for review. The site appears to rely on Cloudflare for security and performance, but the actual content and services cannot be evaluated. From a technical perspective, the site is protected by Cloudflare, which provides robust security infrastructure. However, the blocking prevents any assessment of the site's technology stack, content quality, or compliance posture. No metadata, structured data, or external business links are visible, limiting the ability to analyze SEO, accessibility, or user experience. Security posture evaluation is constrained by the lack of accessible content. The presence of Cloudflare indicates a baseline security measure, but no further details on security headers, SSL configuration, or incident response capabilities can be determined. The absence of privacy, cookie, or terms of service policies suggests potential compliance gaps, though this cannot be confirmed without access. Overall, the site currently presents a high risk from an analysis perspective due to inaccessibility. Strategic recommendations include resolving the Cloudflare blocking issues to allow legitimate access, publishing clear privacy and security policies, and ensuring transparency in contact and business information to improve trust and compliance.

-
-
-
-
-
-
-
Cloudflare
2025-06-23T02:05:19.555Z