Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 2868 of 2975|Showing 143351-143400 of 148702
donaora.it favicon

Fondazione Bambino Gesù ETS

donaora.it

0
Non-profitItalymediumHIGH

The website donaora.it serves as a fundraising platform for Fondazione Bambino Gesù ETS, a non-profit organization focused on pediatric healthcare support in Italy. The site aims to facilitate donations to support scientific research, medical care, and assistance to children and their families. The business model revolves around charitable giving and donor engagement, targeting individuals interested in supporting pediatric health causes. The organization is mature, with a domain age of 17 years, aligning with its founding date in 2007. Technically, the website employs basic modern web technologies such as Google Tag Manager and Google Fonts, with integration of GestPay for payment processing. However, the site suffers from significant performance issues, including a very slow load time and large page size. Mobile optimization and accessibility are basic, and SEO practices are minimal. The absence of a valid SSL certificate and HTTPS support is a critical flaw, exposing users to security risks. From a security perspective, the website lacks essential protections such as HTTPS, HSTS, DMARC, DNSSEC, and domain protection locks. The presence of exposed sensitive tokens or API keys in the HTML source is a severe vulnerability that could lead to exploitation. No privacy, cookie, or terms of service policies are present, indicating poor privacy compliance. The WHOIS data confirms the domain is mature and consistent with the organization's profile but highlights a high expiry risk and lack of domain locks. Overall, the website's risk profile is elevated due to critical security shortcomings and poor privacy compliance. Strategic improvements in SSL implementation, security headers, privacy policies, and domain management are urgently recommended to enhance trustworthiness and protect donor data.

15
15
17
50
50
45
100
non-profithealthcarefundraisingdonationpediatriccare+1 more
Google Tag ManagerGoogle FontsGestPay payment JavaScript
2025-06-15T13:11:26.316Z
try.be favicon

Five Nines Digital Ltd

try.be

0
HospitalityUnited KingdomsmallHIGH

Trybe is a specialized SaaS provider offering next-generation bookings and business management software tailored for the spa and leisure industry. The platform targets spa businesses seeking to streamline their booking processes, inventory management, team scheduling, and payment processing. Positioned as a cloud-based, open-API solution, Trybe emphasizes ease of use, integration capabilities, and operational efficiency. The company is UK-based, operating under Five Nines Digital Ltd, and holds ISO27001 certification, reinforcing its commitment to security standards. Technically, the website is built using modern web technologies including React and Gatsby, with Tailwind CSS for styling. Hosting appears to be on AWS infrastructure. While the site is well-designed, mobile-optimized, and rich in content, performance is hindered by slow load times and a high number of resources. SEO and accessibility features are well implemented, contributing to a positive user experience. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability impacting user trust and data protection. No major vulnerabilities or exposed sensitive data were detected, and the presence of ISO27001 certification and GDPR-compliant privacy policies indicate a mature security posture. However, improvements in SSL/TLS configuration and security headers are urgently recommended. Overall, Trybe presents a professional and credible business offering with strong market positioning in the hospitality sector. The main risk lies in its current SSL/TLS configuration, which should be addressed promptly to ensure secure communications and maintain customer trust.

15
-
25
75
50
85
100
spabookingsbusinessmanagementsoftwarecloud+2 more
ReactGatsbyTailwind CSSStripe+3
2025-06-15T13:11:16.135Z
arvenetternansen.com favicon

The Nansen Legacy

arvenetternansen.com

0
EducationNorwaymediumMEDIUM

The Nansen Legacy website represents a collaborative Arctic research project focused on the Barents Sea and related environmental studies. It serves as an information portal for research activities, team members, publications, and events. The project is supported by multiple Norwegian academic and governmental institutions, indicating a strong presence in the education and research sector. The website targets researchers, early career scientists, and stakeholders interested in Arctic science. Technically, the site is built on WordPress with Elementor and hosted on WordPress.com infrastructure. While the site uses HTTPS and modern web technologies, its performance is slow with a high number of resources loaded. Accessibility and SEO are basic to good, but there is room for improvement in security headers and advanced SSL configurations. Security posture is moderate with valid SSL but lacking HSTS and OCSP stapling. No explicit privacy or cookie policies were found, which is a compliance gap especially under GDPR. Contact information is limited to an email address, with no phone numbers or detailed business registration data visible. Social media presence is active on major platforms. Overall, the site is a credible academic project portal but would benefit from enhanced privacy compliance, improved security headers, and performance optimizations to strengthen trust and user experience.

30
25
25
50
67
80
100
arcticresearchscienceeducationenvironmentalstudiesresearchconsortium
WordPressElementorPHPjQuery+2

Partner Domains:

forskningsradet.no
partnerpending
regjeringen.no
partnerpending

+3 more partners

2025-06-15T13:10:49.588Z
framsenteret.no favicon

Framsenteret Drift AS

framsenteret.no

0
GovernmentNorwaymediumHIGH

Framsenteret Drift AS operates as a Norwegian Arctic research center focused on interdisciplinary climate and environmental research of high international standard. The organization collaborates with numerous research institutions and partners, positioning itself as a key player in Arctic research and policy support. The website serves as a platform for disseminating research findings, hosting events, and providing information about ongoing projects and collaborations. The target audience includes researchers, policymakers, environmental stakeholders, and the general public interested in Arctic issues. Technically, the website is built on WordPress with a modern tech stack including jQuery, Font Awesome, and Matomo analytics for privacy-conscious user tracking. The site is well-structured with good SEO metadata and accessibility features, though performance is slow with a load time exceeding 12 seconds. Mobile optimization is good, and navigation is clear and professional. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical vulnerability. No modern TLS protocols are enabled, and advanced security features like OCSP stapling and session resumption are missing. The site does implement HSTS but without HTTPS, this is ineffective. No explicit security or incident response policies are found, indicating gaps in security governance. Overall, the site is trustworthy and professionally maintained with strong business credibility and content quality. However, the lack of HTTPS and security policies significantly lowers its security posture and overall risk profile. Strategic improvements in SSL/TLS deployment and security governance are recommended to enhance trust and compliance.

70
25
17
60
82
85
-
researchclimateenvironmentarcticnorway+2 more
WordPressjQueryFont AwesomeMatomo Analytics+2

Partner Domains:

framforum.com
partnerpending
ifram.no
partnerpending

+3 more partners

2025-06-15T13:10:49.353Z
dln.com.hk favicon

DLN

dln.com.hk

0
Real EstateHong KonglargeHIGH

DLN is a well-established architectural and engineering firm founded in 1972 in Hong Kong, recognized for its high-profile projects across Asia and globally. The company specializes in designing skyscrapers and complex building complexes, shaping urban landscapes with a strong market reputation. The website reflects a professional business presence with consistent branding and relevant content targeting clients in the real estate and construction sectors. Technically, the website is built on a custom PHP platform running on an Apache server with older software versions. It uses common web technologies such as jQuery and Bootstrap for frontend responsiveness and styling. However, the website lacks modern security implementations, notably missing HTTPS support and valid SSL certificates, which significantly impacts its security posture. Performance data is unavailable, but the site appears to have basic mobile optimization and SEO practices. From a security perspective, the absence of HTTPS and security headers exposes users to risks such as data interception and man-in-the-middle attacks. No privacy, cookie, or terms of service policies are present, indicating poor privacy compliance. No contact information or incident response channels are provided, limiting user trust and regulatory compliance. The WHOIS data aligns well with the business claims, showing a consistent and legitimate domain registration. Overall, the website demonstrates moderate business credibility and good content quality but suffers from critical security shortcomings and lack of privacy compliance. Strategic improvements in SSL implementation, privacy policies, and security best practices are essential to enhance trust and protect users.

15
-
-
50
-
50
100
architectureengineeringrealestatehongkongconstruction+1 more
PHP 7.3.1Apache 2.4.6OpenSSL 1.0.2k-fipsjQuery 3.5.1+5
2025-06-15T13:07:58.820Z
supresencia.com favicon

Iglesia Cristiana El Lugar de Su Presencia

supresencia.com

0
Non-profitColombiamediumHIGH

Iglesia Cristiana El Lugar de Su Presencia is a medium-sized non-profit religious organization based in Bogotá, Colombia. The website serves as the official digital presence for the church, providing information about services, community groups, children's ministry, radio broadcasting, and donation options. The target audience is primarily Spanish-speaking Christians in Colombia. The organization maintains a multimedia presence including live streaming and social media engagement, supported by several subsidiary domains related to radio, media production, and community outreach. Technically, the website is built on Drupal 7 with common web technologies such as jQuery and Bootstrap, hosted on AWS infrastructure. However, the site lacks a valid SSL certificate and proper HTTPS configuration, which is a critical security shortfall. Privacy policies exist but lack comprehensive GDPR compliance and cookie consent mechanisms. Security headers are partially implemented but TLS protocols and modern security features are missing, exposing the site to potential risks. Overall, the website is functional and professionally presented but requires urgent improvements in security and privacy compliance to enhance trust and protect user data.

40
-
-
65
-
85
100
iglesiacristianabogotreligiousnon-profit+4 more
Drupal 7jQuery 2.1BootstrapArt Revolution Slider+4

Partner Domains:

supresenciaradio.com
subsidiarypending
coffeenjesus.com
subsidiarypending

+1 more partners

2025-06-15T13:07:58.053Z
E

ETTINGER GmbH

ettinger.de

0
ManufacturingGermanymediumHIGH

ETTINGER GmbH is a well-established German family-owned company specializing in fastening technology and electromechanical components, serving industrial and trade customers through a comprehensive B2B online shop. The company offers a wide range of over 25,000 products, including custom manufacturing and special procurement services, with a focus on quality and fast delivery. The website reflects a mature digital presence with professional design, clear navigation, and rich content tailored to its target audience of manufacturers and industrial clients. Technically, the site is built on the Shopware CMS platform, leveraging modern technologies like Algolia for search and Google Tag Manager for analytics. However, a critical security gap exists as the site lacks a valid SSL/TLS certificate, exposing users to potential risks and undermining trust. Security headers are partially implemented but ineffective without HTTPS. Privacy and cookie policies are present and compliant with GDPR, including consent mechanisms. The domain registration is consistent and legitimate, with no privacy protection or suspicious patterns, supporting the company's credibility. Overall, while the business and content aspects are strong, immediate attention is required to secure the website with HTTPS to protect user data and enhance trust.

60
-
-
50
-
70
40
b2be-commercemanufacturingelectromechanicsfasteningtechnology+1 more
Apache 2.4.62Debian LinuxShopware CMShtmx.js+4

Partner Domains:

portal.ettinger.de
service
katalog.ettinger.de
service
2025-06-15T13:07:57.644Z
aviva.com favicon

Aviva plc

aviva.com

0
FinanceUnited KingdomenterpriseHIGH

Aviva plc is a leading diversified insurer headquartered in the United Kingdom, offering a broad range of insurance, wealth management, and retirement services primarily across the UK, Ireland, and Canada. The company targets investors, shareholders, career seekers, and socially conscious individuals, positioning itself as a trusted financial services provider with a strong market presence and extensive subsidiary network. The website reflects a professional and comprehensive corporate portal with rich investor relations content, leadership profiles, and sustainability initiatives. Technically, the website leverages modern JavaScript frameworks, Adobe Experience Manager CMS, and Akamai CDN for content delivery. It integrates advanced analytics and marketing tools such as Adobe Helix RUM and OneTrust for privacy compliance. The site is mobile-optimized, accessible, and SEO-friendly, providing a high-quality user experience. From a security perspective, while several best practices are implemented including CSP, X-Content-Type-Options, and HSTS headers, the SSL certificate is invalid and no TLS protocols are enabled, representing a critical vulnerability that undermines secure communications. No WAF or blocking mechanisms are detected, and privacy policies are comprehensive and GDPR compliant. The domain registration data aligns well with the business claims, indicating high legitimacy. Overall, the website is professional and credible but requires urgent remediation of SSL and TLS issues to ensure secure user interactions and maintain trust.

65
33
5
50
-
85
100
insurancefinancecorporateinvestorrelationssustainability+2 more
JavaScriptReact componentsHandlebarsRequireJS+6

Partner Domains:

marsh.com
partner66
slipcase.com
partnerpending
2025-06-15T13:07:55.360Z
E

Empresas Polar

empresaspolar.com

0
OtherVenezuelalargeHIGH

Empresas Polar is a well-established Venezuelan food and beverage company with a mature domain age of 26 years, reflecting its longstanding market presence. The company operates primarily in the food and beverage sector, serving consumers and business partners in Venezuela. However, the website is currently inaccessible due to a Cloudflare security challenge, which prevents direct content analysis and limits visibility into the company's online presence and policies. From a technical perspective, the website relies on Cloudflare for DNS and security services and employs Google's Turnstile captcha for bot mitigation. Unfortunately, the site lacks a valid SSL/TLS certificate and does not serve content over HTTPS, which is a critical security deficiency. Performance is poor with slow load times, and no SEO or accessibility optimizations are evident in the accessible content. Security posture is weak due to the absence of HTTPS, missing security headers, and lack of modern TLS protocol support. No privacy, cookie, or terms of service policies are detectable, indicating potential compliance gaps. The WHOIS data is consistent and trustworthy, showing strong domain protection and a reputable registrar. Overall, the site requires significant improvements in security, accessibility, and content availability to meet modern standards. Strategic recommendations include immediate implementation of a valid SSL certificate, enabling HTTPS, enhancing security headers, and improving site accessibility and performance. Additionally, publishing clear privacy and cookie policies and ensuring compliance with GDPR and other regulations will strengthen trust and legal standing.

55
15
5
85
-
85
100
blockedcloudflaresecurity-challengefood-beveragevenezuela
CloudflareGoogle Turnstile Captcha
2025-06-15T13:07:52.666Z
dmdiocese.org favicon

Diocese of Des Moines

dmdiocese.org

0
Non-profitUnited StatesmediumHIGH

The Diocese of Des Moines website serves as the official online presence for the Catholic Diocese in southwest Iowa, providing comprehensive information about its ministries, schools, events, and community services. The site targets the local Catholic community and families interested in faith formation and education. It offers key services such as Catholic schooling, mental health ministry, worship schedules, and charitable giving opportunities. The organization maintains a consistent brand and provides clear contact information, enhancing its credibility as a regional non-profit religious entity. Technically, the website is built on an ASP.NET framework with modern JavaScript libraries like jQuery and uses Google Tag Manager for analytics. The site employs asynchronous script loading and lazy loading for images, indicating a focus on performance and user experience. However, performance data is missing, and the site is rated as slow based on available indicators. Mobile optimization and SEO practices are good, but accessibility is basic. From a security perspective, the site lacks a valid SSL certificate and does not support modern TLS protocols, which is a critical vulnerability. While several security headers are present, the absence of HTTPS and weak SSL configuration significantly reduce the site's security posture. There are no visible privacy policies, cookie consent mechanisms, or incident response contacts, indicating compliance gaps with GDPR and other privacy regulations. Overall, the website is functional and professional but requires urgent improvements in security and privacy compliance to protect users and enhance trust. Strategic recommendations include implementing a valid SSL certificate, enabling modern TLS, adding privacy and cookie policies, and establishing incident response protocols.

70
-
5
50
-
85
100
educationnon-profitreligioncatholiccommunity+3 more
ASP.NETjQuery 3.7.1Google Tag ManagerGoogle Marketing Platform (gtag.js)+2

Partner Domains:

catholiccharitiesdm.org
partnerpending
catholicfoundationiowa.org
partnerpending
2025-06-15T13:07:50.206Z
abtassociates.com favicon

Abt Global

abtassociates.com

0
GovernmentUnited StateslargeHIGH

Abt Global is a well-established international consulting and social impact organization with over 60 years of history and a large workforce. The company focuses on leveraging data, innovation, and expertise across multiple sectors including health, environment, governance, and economic growth to improve lives worldwide. Their business model centers on providing consulting, technical assistance, and digital solutions to governments, organizations, and communities. The website reflects a professional and comprehensive digital presence with strong branding and relevant content targeting global development stakeholders. Technically, the website is built on Drupal 10 and uses modern JavaScript libraries and marketing/analytics tools such as Google Tag Manager, Google Analytics, LinkedIn Insight Tag, and HubSpot. However, the site suffers from slow load times and lacks a valid SSL certificate, resulting in no HTTPS support. Mobile optimization and SEO are good, but accessibility is basic. The hosting appears to be via Fastly CDN. From a security perspective, the absence of a valid SSL certificate and HTTPS is a critical vulnerability, severely impacting the security posture. No security headers or advanced TLS configurations are present, and no incident response or security policies are published. Cookie consent mechanisms are implemented, indicating GDPR awareness, but no terms of service or vulnerability disclosure pages are found. Overall, the security maturity is low and requires urgent improvements. The overall risk assessment highlights the critical need for SSL/TLS implementation to protect user data and improve trust. Strategic recommendations include securing the site with HTTPS, enabling security headers, optimizing performance, and publishing clear security and incident response policies. The business credibility and content quality are strong, but technical and security shortcomings reduce the overall trust score.

75
18
5
50
-
80
100
globaldevelopmentsolutionsdata-drivensocialimpacthealthpolicyresearcheconomicpolicyanalysisclimatechangesolutions
Drupal 10JavaScriptjQueryGoogle Tag Manager+4
2025-06-15T13:07:49.673Z