Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 1200 of 2974|Showing 59951-60000 of 148696
O

Oribi

oribisoftware.com

0
EducationSwedenmediumMEDIUM

Oribi is a Swedish-based educational technology company specializing in assistive technology and edtech software designed to support reading, writing, language, and mathematics for students in both digital and physical environments. The company offers a suite of products including SkrivaText, LexiFlow, Equatio, EduLife, and OrbitNote, targeting schools and workplaces. Oribi is part of the global Texthelp Group and rebranded as Everway, reflecting its evolving market presence. The website demonstrates a strong market position in Sweden with endorsements from notable educational institutions and a Google Premium Partner status. Technically, the website is built on modern frameworks such as Next.js and React, utilizing Prismic CMS for content management. It integrates marketing automation via Mautic and accessibility tools like BrowseAloud. The site is well-optimized for performance, mobile responsiveness, and accessibility, with proper SEO and security headers implemented. Analytics are conducted through Google Analytics and Google Tag Manager, with moderate user tracking balanced by GDPR-compliant privacy and cookie policies. From a security perspective, the site employs HTTPS and a strict Content-Security-Policy, minimizing risks from common web vulnerabilities. However, it lacks explicit public security policies or incident response contacts, which could enhance trust and preparedness. The WHOIS data for the domain www.oribi.se is unavailable, likely due to querying the full hostname rather than the base domain, but the website's professional presentation and association with Texthelp support its legitimacy. Overall, Oribi's website reflects a mature digital presence with strong business credibility and security posture. Strategic improvements could include publishing vulnerability disclosure information and incident response contacts to further enhance transparency and trust.

30
25
17
80
77
70
100
educationassistivetechnologyedtechaccessibilitysweden+2 more
Next.jsReactPrismic CMSGoogle Analytics+3

Partner Domains:

texthelp.com
parent
everway.com
related

+1 more partners

2025-09-06T03:02:42.631Z
cloudlift.app favicon

cloudlift

cloudlift.app

0
TechnologySwitzerlandsmallMEDIUM

Cloudlift GmbH operates a Shopify-based e-commerce website offering specialized Shopify apps aimed at improving storefronts through personalized product upload and preview features, as well as B2B wholesale tools. The company targets Shopify merchants and e-commerce store owners, positioning itself as a niche technology provider within the Shopify ecosystem. The website demonstrates a good level of professionalism and branding consistency, leveraging modern web technologies and Shopify's platform capabilities to deliver a performant and user-friendly experience. Technically, the site is built on the Shopify platform using the Dawn theme and integrates several JavaScript libraries such as FilePond for file uploads, Doka for image editing, and Fabric.js for canvas manipulation. Hosting and content delivery are managed via Shopify's CDN, ensuring fast load times and good mobile optimization. SEO is supported through structured data (JSON-LD) and proper meta tags, while accessibility features are adequately implemented. From a security perspective, the site benefits from Shopify's robust HTTPS enforcement and platform security features. However, explicit security headers and published security policies are not evident in the content. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is limited due to the absence of visible privacy and cookie policies, which is a notable gap. Contact information for security incidents or general inquiries is also missing, reducing transparency. Overall, the website presents a moderate to high trust level with strong technical and security foundations but requires improvements in privacy compliance and contact transparency to enhance user trust and regulatory adherence.

75
50
17
75
75
80
100
shopifye-commercesaastechnologyapps+1 more
Shopify platformJavaScriptShopify Liquid templatesFilePond (file upload library)+5
2025-09-06T01:58:49.131Z
md.gov favicon

State of Maryland

md.gov

0
GovernmentUnited StatesenterpriseMEDIUM

Maryland.gov is the official digital portal for the State of Maryland, providing a centralized platform for residents, businesses, visitors, and government employees to access a wide range of state government services and information. The website serves as a comprehensive resource for online services, job listings, business registrations, government contacts, and educational resources, positioning itself as the authoritative source for Maryland state government digital interactions. The site demonstrates consistent branding and high content quality, reflecting its role as a trusted government entity. Technically, the website leverages a mature technology stack including Microsoft SharePoint, ASP.NET Web Forms, jQuery, Bootstrap, and integrates modern analytics and accessibility tools such as Google Analytics, Microsoft Clarity, and Monsido. The platform is well-optimized for mobile devices and incorporates accessibility best practices, ensuring broad usability. Hosting appears to be managed by state infrastructure with partial Cloudflare services for analytics. From a security perspective, the site enforces HTTPS with a strong SSL configuration and employs security tokens to protect form submissions. While some security headers like Content-Security-Policy and X-Frame-Options are not explicitly detected, the overall posture is strong with no visible vulnerabilities or exposed sensitive data. Privacy compliance is supported by a comprehensive privacy policy and terms of service, with GDPR considerations addressed. The domain's WHOIS data is incomplete, likely due to .gov domain registry policies, but the .gov TLD and website content strongly affirm legitimacy. Overall, Maryland.gov presents a secure, professional, and user-friendly government portal with robust technical infrastructure and compliance measures. Strategic recommendations include enhancing security headers, publishing a security.txt file for vulnerability disclosure, and continuous auditing of third-party scripts to maintain security integrity.

65
58
2
70
65
75
100
governmentpublicservicesstateportalmarylandofficial+2 more
jQuery 3.6.0BootstrapGoogle Tag ManagerGoogle Analytics+7
2025-09-06T01:58:08.709Z
O

Oribi

oribi.se

0
EducationSwedenmediumMEDIUM

Oribi is a Swedish educational technology company specializing in assistive technology and edtech software designed to support reading, writing, language, and mathematics for students in both digital and physical learning environments. The company is part of the global Texthelp Group and holds a strong market position in Sweden as a leading provider of inclusive learning tools. Their product suite includes SkrivaText, LexiFlow, Equatio, EduLife, and OrbitNote, targeting schools, educators, and students to enhance learning outcomes and accessibility. Technically, the website is built on modern frameworks such as Next.js and React, leveraging Prismic CMS for content management. It integrates various marketing and analytics tools including Google Analytics, Google Tag Manager, Mautic for marketing automation, and BrowseAloud for accessibility. The site demonstrates good mobile optimization, accessibility features, and SEO practices, delivering a professional and user-friendly experience. From a security perspective, the site employs a strict Content-Security-Policy and enforces HTTPS, reflecting a solid security posture. However, additional security headers could be implemented to further enhance protection. No vulnerabilities or exposed sensitive data were detected. Privacy compliance is well addressed with comprehensive GDPR and cookie policies, including user consent mechanisms. Overall, Oribi's website reflects a mature digital presence aligned with its business goals and compliance requirements. The absence of WHOIS data for the www subdomain is noted but does not detract significantly from the site's legitimacy given the association with Texthelp Group and the professional content presented. Strategic recommendations include enhancing security headers, publishing vulnerability disclosure information, and providing direct company contact details to improve trust and transparency.

30
25
17
80
77
65
100
educationassistivetechnologyedtechaccessibilitysweden+1 more
Next.jsReactPrismic CMSGoogle Analytics+3

Partner Domains:

texthelp.com
parent
oribisoftware.com
subsidiary

+1 more partners

2025-09-06T01:57:17.594Z
municode.com favicon

CivicPlus LLC

municode.com

0
GovernmentUnited StateslargeMEDIUM

CivicPlus LLC operates a comprehensive software platform focused on empowering local governments and public sector organizations with technology solutions that enhance operational efficiency and resident engagement. Their Municode Codification software and services provide municipalities with tools to manage municipal codes, ordinances, and related legislative documents effectively. The company holds a strong market position as a leader in integrated government technology, supported by over 70 years of codification experience and a large customer base exceeding 4,200 clerk customers. Technically, the website is built on a modern WordPress CMS with a robust tech stack including Yoast SEO, Google Analytics, HubSpot, and various marketing and tracking tools. The site demonstrates good performance, excellent mobile optimization, and strong SEO practices. Security posture is solid with HTTPS enforced and no visible vulnerabilities, though explicit security headers could be more clearly confirmed. From a security and compliance perspective, CivicPlus maintains a comprehensive privacy policy, cookie consent mechanisms, and a dedicated security page, indicating a mature approach to data protection and regulatory compliance. However, the absence of WHOIS registration details limits domain trust analysis, though the overall professionalism and market presence mitigate concerns. Overall, CivicPlus presents a trustworthy, professional, and well-structured digital presence aligned with its business objectives. Strategic recommendations include enhancing security header implementation, publishing incident response contacts, and continuous monitoring of third-party scripts to maintain security integrity.

65
68
17
75
75
80
100
governmentmunicipalcodificationsoftwareservices+3 more
WordPress 6.8.2Yoast SEO PremiumjQuery 3.7.1Google Tag Manager+9

Partner Domains:

library.municode.com
subsidiary
apps.alertsense.com
partner

+2 more partners

2025-09-06T01:56:57.551Z
archivesocial.com favicon

CivicPlus LLC

archivesocial.com

0
GovernmentUnited StateslargeMEDIUM

CivicPlus LLC operates a comprehensive software platform focused on empowering government agencies and public sector organizations with technology solutions that enhance efficiency and resident engagement. Their flagship product featured on this site is the Social Media Archiving software, formerly known as ArchiveSocial, designed to help government entities comply with public records laws by capturing and preserving social media content in real-time. CivicPlus holds a strong market position as a leader in government compliance technology, offering a broad suite of integrated products including municipal websites, mass notification systems, and public records request management tools. Technically, the website is built on a modern WordPress CMS with extensive use of SEO and analytics tools such as Yoast SEO, Google Analytics, HubSpot, and Microsoft Clarity. The site demonstrates good mobile optimization, accessibility, and performance characteristics. The use of multiple trusted third-party services for marketing and analytics reflects a mature digital infrastructure. From a security perspective, the site enforces HTTPS and employs secure login portals for its services. While explicit security headers were not detected in the provided data, no vulnerabilities or exposed sensitive data were found. Privacy and cookie policies are present and include consent mechanisms, indicating compliance with GDPR and related regulations. However, WHOIS data is incomplete or unavailable, which slightly impacts trust but is likely due to privacy protection common in enterprise environments. Overall, CivicPlus presents a professional, trustworthy, and well-maintained online presence with a strong focus on government compliance and digital service delivery. Strategic recommendations include enhancing security headers, publishing incident response policies, and maintaining transparency around data protection practices.

65
68
17
75
75
80
100
socialmediaarchivinggovernmentcompliancepublicrecordscivicplusarchivesocial+3 more
WordPress 6.8.2Yoast SEO PremiumjQuery 3.7.1HubSpot scripts+5

Partner Domains:

secure.archivesocial.com
service
apps.alertsense.com
partner

+2 more partners

2025-09-06T01:56:52.542Z
seeclickfix.com favicon

CivicPlus

seeclickfix.com

0
GovernmentUnited StatesmediumMEDIUM

SeeClickFix, powered by CivicPlus, is a mature and established SaaS platform providing 311 request and work management solutions that bridge communication between residents and local governments. The platform supports efficient workflows and fosters transparency and accountability, serving hundreds of governments and engaging over one million residents. The website reflects a professional and consistent brand presence, targeting local governments and residents with clear calls to action for sign-up and engagement. Technically, the website employs modern web technologies including Bootstrap for responsive design, Google Analytics and Tag Manager for analytics, Google reCAPTCHA for bot protection, and New Relic for performance monitoring. The domain is hosted with Cloudflare DNS and registered via Amazon Registrar, indicating a stable and reliable infrastructure. The site is mobile-optimized and SEO-friendly, though accessibility features are basic. From a security perspective, the site enforces HTTPS and uses security best practices such as CSRF tokens and bot mitigation. However, DNSSEC is not enabled and some security headers are not explicitly detected, representing areas for improvement. Privacy compliance is partial; while a comprehensive privacy policy is linked via the parent company CivicPlus, no explicit cookie consent mechanism is present on the site. Incident response and vulnerability disclosure information are not publicly available. Overall, the website demonstrates a solid security posture and business credibility with room for enhancements in privacy compliance and security header implementation. The domain WHOIS data is consistent with the business history and shows no suspicious patterns. Strategic recommendations include enabling DNSSEC, implementing cookie consent, publishing vulnerability disclosure policies, and enhancing security headers to strengthen trust and compliance.

50
58
17
75
100
80
100
government311residentengagementcrmlocalgovernment+1 more
Google AnalyticsGoogle Tag ManagerGoogle reCAPTCHABootstrap+3

Partner Domains:

www.civicplus.com
parent
2025-09-06T01:56:47.534Z
S

Sfera

sfera.com

0
RetailSpainlargeHIGH

Sfera is a retail fashion brand operating an online platform primarily targeting Spanish-speaking countries with some English-speaking markets. The website serves as a login and country selection portal for customers. The business model focuses on e-commerce sales of apparel and accessories. The website's market position appears established but lacks visible trust signals or detailed business information on the landing page. Technically, the site uses common web technologies such as jQuery, Google Tag Manager, and Ensighten for tracking and tag management, with Akamai as a CDN provider. The site shows basic mobile optimization and moderate performance but lacks advanced SEO optimization due to restrictive meta robots tags. No CMS or specific frameworks were detected. From a security perspective, the site lacks visible security headers and privacy or cookie policies, which are critical for GDPR compliance. The WHOIS data is missing, raising concerns about domain legitimacy. No WAF or blocking mechanisms were detected, and the site content is accessible. The security posture is moderate but requires improvements in SSL configuration, header implementation, and privacy compliance. Overall, the site scores moderately low on AI scoring due to missing WHOIS data, lack of privacy policies, and poor SEO. Strategic recommendations include improving transparency with privacy and cookie policies, enhancing security headers, and verifying domain registration details to build trust.

-
35
2
70
-
85
100
fashionretaile-commerceloginmultilingual
jQueryGoogle Tag ManagerEnsightenAkamai
2025-09-06T01:55:57.436Z
E

El Corte Inglés S.A.

hipercor.es

0
RetailSpainenterpriseMEDIUM

El Corte Inglés S.A., operating the Hipercor brand, is a leading Spanish retail and e-commerce enterprise specializing in supermarkets, fashion, electronics, and home goods. The website hipercor.es serves as a comprehensive online platform offering a wide range of products to general consumers in Spain, supported by a strong brand presence and multiple subsidiaries. The company has a long-standing history since 1940 and maintains a significant market position in the retail sector. Technically, the website employs modern web technologies including Vue.js, Google Tag Manager, Adobe DTM, and OneTrust for cookie compliance, hosted on Akamai CDN ensuring fast and reliable performance. The site is well optimized for mobile and accessibility standards, with good SEO practices and structured data enhancing search visibility. Security posture is strong with HTTPS enforcement, security headers, and no visible vulnerabilities, although explicit security policies and incident response information are not publicly detailed. Privacy compliance is robust, featuring comprehensive privacy and cookie policies aligned with GDPR requirements. Overall, the website demonstrates high professionalism, trustworthiness, and digital maturity, supporting the enterprise's business objectives effectively.

-
40
17
70
-
85
100
retaile-commercesupermarketfashionelectronics+4 more
Vue.jsGoogle Tag ManagerGoogle AnalyticsAdobe DTM+3

Partner Domains:

www.elcorteingles.es
parent
www.supercor.es
subsidiary

+2 more partners

2025-09-06T01:55:47.418Z
E

El Corte Inglés, S.A.

primeriti.es

0
RetailSpainenterpriseHIGH

Primeriti is a flash sales e-commerce platform operated by El Corte Inglés, S.A., a leading retail company in Spain. The website offers discounted branded fashion, sportswear, accessories, and home products targeting consumers looking for exclusive deals. The platform leverages the strong brand reputation of El Corte Inglés and integrates secure user authentication via the parent company's OAuth system. The site is well-branded, professionally designed, and provides comprehensive privacy and cookie policies in Spanish, demonstrating compliance with GDPR requirements. Contact information and a designated Data Protection Officer are clearly provided, enhancing trust and transparency. Technically, the website employs modern JavaScript libraries, tag management tools like Google Tag Manager and Adobe DTM, and a content delivery network associated with the parent company. The site is mobile-optimized, accessible, and SEO-friendly, with moderate performance. Security posture is strong with HTTPS enforced, encrypted data transmission, and secure login mechanisms. However, explicit security headers and a public incident response policy are not evident, and a cookie consent mechanism is missing, which are areas for improvement. Overall, the website presents a high level of professionalism, security, and compliance suitable for an enterprise retail business. The domain registration data aligns with the business entity, confirming legitimacy. Strategic recommendations include implementing explicit cookie consent, publishing a security policy, and enhancing security headers to further strengthen the security posture and compliance.

-
25
17
70
-
70
100
e-commercefashionflashsalesretailelcorteingls+4 more
JavaScriptAdobe DTM (Adobe Dynamic Tag Management)Google Tag ManagerInsider SDK+2

Partner Domains:

cuenta.elcorteingles.es
partner
cdn.grupoelcorteingles.es
partner
2025-09-06T01:55:32.175Z
1inch.io favicon

1inch Foundation

1inch.io

0
FinanceCayman IslandslargeMEDIUM

1inch Network is a prominent decentralized finance (DeFi) platform founded in 2019, offering a comprehensive ecosystem of products including token swapping, wallet services, portfolio tracking, and cross-chain swaps. The platform aggregates liquidity from multiple decentralized exchanges (DEXes) to provide users with optimal rates and secure execution. Positioned as a leading DeFi aggregator, 1inch serves a broad audience of crypto traders, Web3 developers, and DeFi enthusiasts, supported by a strong foundation entity registered in the Cayman Islands. The company maintains active partnerships with major crypto projects and financial institutions, enhancing its market presence and credibility. Technically, the website leverages modern web technologies such as React and Next.js, hosted behind Cloudflare DNS and CDN services, ensuring fast performance and excellent mobile optimization. The platform integrates multiple analytics and marketing tools including Google Analytics, TikTok Pixel, Facebook Pixel, and LinkedIn Insight Tag, with a clear cookie consent mechanism in place. The website demonstrates good SEO and accessibility practices, contributing to a professional and user-friendly experience. From a security perspective, 1inch enforces HTTPS, employs clientTransferProhibited domain status, and publishes a security whitepaper outlining its defense strategies. However, DNSSEC is not enabled, and no security.txt or explicit incident response contacts are publicly available, representing areas for improvement. No vulnerabilities or exposed sensitive data were detected in the analysis. Overall, the security posture is strong but could benefit from enhanced DNS security and formalized vulnerability disclosure mechanisms. The overall risk assessment indicates a trustworthy and mature platform with high business credibility and technical sophistication. Strategic recommendations include enabling DNSSEC, publishing a security.txt file, adding explicit security headers, and providing clear incident response contacts to further strengthen security and compliance. These measures will enhance user trust and align the platform with best practices in the rapidly evolving DeFi landscape.

30
58
43
82
57
80
100
defiweb3cryptocurrencyfinanceblockchain+4 more
ReactNext.jsCloudflare DNSGoogle Analytics+5

Partner Domains:

near.org
partner
metamask.io
partner

+3 more partners

2025-09-06T01:53:56.697Z
crossmint.com favicon

Crossmint, Inc.

crossmint.com

0
FinanceN/aenterpriseMEDIUM

Crossmint, Inc. is an enterprise-grade fintech technology company specializing in blockchain-based wallet infrastructure, stablecoin payments, tokenization, and agentic finance solutions. The company offers a comprehensive suite of APIs and tools designed to enable enterprises and developers to embed programmable wallets, convert fiat to crypto, and manage digital asset payments seamlessly. Positioned as a trusted platform with over 40,000 users and backed by prominent investors, Crossmint targets fintech companies, AI agents, and enterprises seeking to integrate stablecoin rails and blockchain backend infrastructure without friction. Technically, the website is built on Webflow CMS with modern JavaScript libraries and analytics tools such as PostHog, Datadog RUM, and Google Analytics. The site is mobile-optimized, fast-loading, and employs security best practices including reCAPTCHA and cookie consent mechanisms. The presence of SOC2 and VASP compliance, along with GDPR and CCPA adherence, reflects a mature security posture suitable for enterprise clients. Security-wise, Crossmint demonstrates strong controls with no evident vulnerabilities or exposed sensitive data. The site uses HTTPS exclusively and integrates multiple security and privacy policies, including a vulnerability disclosure policy. However, explicit security headers could be more visible, and a security.txt file is absent. The WHOIS data is missing or privacy-protected, which slightly reduces transparency but is common in fintech sectors. Overall, Crossmint presents a high-quality, professional, and trustworthy digital presence with a strong focus on compliance and enterprise readiness. The risk profile is low, with recommendations to enhance header security and transparency. The website is safe for general audiences and does not contain any adult or questionable content.

35
80
35
75
75
85
100
fintechblockchainstablecoinswalletinfrastructurepayments+5 more
Webflow CMSGoogle Fonts (Inter, Inconsolata)Google reCAPTCHADatadog RUM+5

Partner Domains:

help.crossmint.com
service
status.crossmint.com
service

+3 more partners

2025-09-06T01:53:26.587Z
maryland.gov favicon

State of Maryland

maryland.gov

0
GovernmentUnited StatesenterpriseMEDIUM

Maryland.gov is the official website of the State of Maryland, serving as a comprehensive portal for residents, businesses, government employees, and visitors. It provides access to a wide range of state services including online applications, job listings, business resources, and government information. The site is well-positioned as a trusted government resource with a strong focus on accessibility, user experience, and service delivery. Technically, the website leverages a mature technology stack including Microsoft SharePoint as the CMS platform, jQuery, Bootstrap, and integrates analytics tools such as Google Analytics and Microsoft Clarity. The site demonstrates good mobile optimization, accessibility compliance, and modern web practices, although performance is moderate likely due to the complexity and volume of content. From a security perspective, the site enforces HTTPS, uses secure form tokens, and includes standard security headers, though explicit Content-Security-Policy headers and vulnerability disclosure mechanisms are absent. Privacy policies are comprehensive and GDPR compliant, but cookie consent mechanisms could be enhanced. The WHOIS data is privacy protected or unavailable, which is typical for government domains, and does not raise legitimacy concerns. Overall, Maryland.gov presents a secure, professional, and user-friendly government portal with strong business credibility and technical maturity. Strategic improvements could focus on enhancing security headers, publishing vulnerability disclosure information, and implementing cookie consent to further strengthen privacy compliance and user trust.

65
58
2
70
65
75
100
governmentstatemarylandofficialservices+3 more
jQuery 3.6.0BootstrapGoogle Tag ManagerGoogle Analytics+5
2025-09-06T00:51:50.379Z
mammoth.bio favicon

Mammoth Biosciences

mammoth.bio

0
HealthcareUnited StatesmediumMEDIUM

Mammoth Biosciences is a biotechnology company specializing in developing in vivo gene editing therapeutics, protein discovery, and CRISPR-based diagnostics. The company leverages novel CRISPR-Cas enzymes and innovative technologies to address unmet patient needs in genetic medicine. With a distinguished team including co-founder Jennifer Doudna, Mammoth Biosciences positions itself as an innovative leader in the gene editing space. The website reflects a professional and consistent brand image targeting biotech professionals, healthcare partners, and potential employees. Technically, the website is built on WordPress with modern plugins such as Yoast SEO and Google Analytics. It employs Google reCAPTCHA for form security and uses jQuery and Slick Slider for interactive elements. The site is mobile optimized and SEO friendly, though some accessibility features could be improved. Performance is moderate with room for optimization. From a security perspective, the site enforces HTTPS and uses reCAPTCHA, but lacks explicit security headers and publicly available security or incident response policies. WHOIS data is privacy protected, which is common for biotech firms but limits transparency. No cookie consent mechanism was detected, which may impact GDPR compliance. Overall, Mammoth Biosciences' website is trustworthy, professional, and content-rich, supporting its business credibility. Strategic improvements in security headers, privacy compliance, and transparency would enhance its security posture and regulatory adherence.

30
58
25
75
72
85
100
crisprgeneeditingbiotechnologyhealthcarediagnostics+1 more
WordPressYoast SEOGoogle AnalyticsjQuery+2
2025-09-06T00:50:22.593Z