Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 2909 of 2975|Showing 145401-145450 of 148701
mercadopago.com favicon

MercadoLibre S.R.L.

mercadopago.com

0
FinanceArgentinaenterpriseMEDIUM

Mercado Pago is a leading digital payments platform operating primarily in Latin America, with a strong presence in Argentina. It offers a comprehensive suite of financial services including digital accounts, prepaid Mastercard cards, money transfers, payment of services, loans, and seller tools such as Point devices and QR code payments. The platform is integrated with its parent company MercadoLibre, a major e-commerce player in the region, positioning Mercado Pago as a critical enabler of digital commerce and financial inclusion. Technically, the website leverages modern web technologies, including React-based frameworks, New Relic for performance monitoring, and Google Tag Manager for analytics and marketing. The SSL configuration is robust with a valid certificate and HSTS enabled, although DNSSEC is not enabled and CAA records appear misconfigured. No critical vulnerabilities were detected, but there is room for improvement in DNS security and explicit vulnerability disclosure. Overall, Mercado Pago demonstrates a mature digital infrastructure and a strong security posture, supporting its role as a trusted financial services provider.

70
25
25
100
100
90
100
financepaymentse-commercedigitalwalletfinancialservices+1 more
React (implied by nordic and pog-landings)New Relic monitoringIntersectionObserver for lazy loadingGoogle Tag Manager+6

Partner Domains:

mercadolibre.com
parentpending
adj.st
partnerpending
2025-06-14T13:25:02.684Z
ruttl.com favicon

Brucira Softwares Pvt. Ltd.

ruttl.com

0
TechnologyN/amediumMEDIUM

Ruttl, operated by Brucira Softwares Pvt. Ltd., is a technology company offering a comprehensive SaaS platform for visual and design feedback across websites, PDFs, images, and videos. Positioned as a trusted tool by over 40,000 businesses including major brands like Adobe and Atlassian, Ruttl provides key services such as website feedback, bug tracking, PDF annotation, and video annotation. The company targets product, marketing, sales, and support teams, as well as agencies and QA teams, with a subscription-based business model supported by free trials and demos. Technically, the website is built on a modern React and Gatsby framework hosted on Google Cloud infrastructure, leveraging multiple third-party analytics and marketing tools including Google Analytics, Hotjar, PostHog, and Facebook Pixel. While the site demonstrates good SEO, mobile optimization, and user experience, performance is somewhat slow likely due to resource count and page size. The site uses a valid SSL certificate but lacks modern TLS protocol support and DNS security enhancements. From a security perspective, Ruttl employs basic best practices such as HSTS and has no detected major SSL vulnerabilities. However, it lacks DNSSEC, CAA records, and a visible GDPR consent mechanism, indicating room for improvement in compliance and security posture. No explicit security policies or incident response contacts are publicly available, though ISO certification is referenced. Overall, Ruttl presents a professional and trustworthy digital presence with strong business positioning and technical maturity. Strategic improvements in security protocols, privacy compliance, and performance optimization would enhance its risk profile and user trust further.

30
43
25
90
92
85
100
designfeedbackbugtrackingpdfannotationvideoannotationcollaboration+2 more
ReactGatsbyGoogle FontsGoogle Tag Manager+8

Partner Domains:

calendly.com
partner70
slack.com
partner66

+1 more partners

2025-06-14T13:05:27.199Z
equals.com favicon

Equals

equals.com

0
TechnologyN/asmallMEDIUM

Equals is a technology company specializing in providing an all-in-one GTM analytics platform that integrates with Salesforce, HubSpot, Stripe, and SQL databases to deliver real-time insights on pipeline and ARR. Positioned as a trusted solution for RevOps, founders, and finance teams, Equals emphasizes clarity and actionable revenue insights to drive business growth. The company maintains a professional online presence with consistent branding and customer testimonials, reinforcing its market position in the SaaS analytics space. Technically, the website is hosted on Netlify and leverages modern JavaScript technologies, Google Tag Manager, and Intercom for analytics and customer engagement. While the site demonstrates good performance and mobile optimization, it lacks some advanced security configurations such as modern TLS protocols and DNSSEC. Security headers are properly implemented, and the SSL certificate is valid, but the absence of a cookie policy and explicit security or incident response policies indicates room for improvement. Overall, Equals exhibits a solid digital maturity with a focus on user experience and trust, though enhancements in security posture and compliance transparency would strengthen its risk management and customer confidence.

55
43
25
90
62
85
100
gtmanalyticssalesforceintegrationhubspotintegrationstripeintegrationsqlsync+3 more
NetlifyGoogle Tag ManagerIntercomUnify Intent Tag+3

Partner Domains:

ashbyhq.com
partner70
2025-06-14T13:04:06.194Z
mercos.com favicon

Mercos

mercos.com

0
E-commerceBrazilmediumMEDIUM

Mercos is a Brazilian software company specializing in B2B sales automation and e-commerce solutions tailored for industries, distributors, and commercial representatives. Positioned as one of the most utilized sales systems in the market, Mercos offers a comprehensive suite of services including sales force automation, B2B e-commerce portals, AI-powered order processing, payment systems, and video call sales features. The company targets medium-sized businesses seeking to streamline their sales operations and integrate seamlessly with existing ERP systems. Their market presence is reinforced by over 8,700 clients and 52,000 users, highlighting strong adoption and trust within their niche. Technically, Mercos leverages modern web technologies such as React and JavaScript, hosted on Amazon Web Services infrastructure with CloudFront CDN for content delivery. The site integrates multiple marketing and analytics tools including Google Tag Manager, HubSpot, RD Station, and Visual Website Optimizer, indicating a mature digital marketing strategy. Performance is optimized with preloading scripts and responsive design, ensuring good mobile experience and SEO. From a security perspective, Mercos maintains a valid SSL certificate issued by Amazon but currently lacks support for modern TLS protocols and advanced security headers. DNS security features like DNSSEC and CAA are not enabled, and no explicit security or incident response policies are publicly disclosed. While no critical vulnerabilities are detected, the absence of cookie consent mechanisms and limited privacy compliance features suggest areas for improvement. Overall, Mercos presents a robust business and technical foundation with excellent user experience and market positioning. However, enhancing security configurations, privacy compliance, and transparency around incident response would strengthen their risk posture and customer trust.

15
25
25
100
85
85
100
b2bsalesautomatione-commerceerpintegrationpaymentsystem+4 more
ReactJavaScriptAmazon S3CloudFront+7

Partner Domains:

gupy.io
partnerpending
rdstation.com.br
partnerpending

+3 more partners

2025-06-14T13:04:06.187Z
vnda.com.br favicon

Olist Vnda

vnda.com.br

0
E-commerceBrazilenterpriseMEDIUM

Olist Vnda is a leading Brazilian omnichannel e-commerce platform designed to empower online retailers with integrated technology and marketing tools to accelerate business growth. The platform offers advanced features such as marketing automation, order management, and direct sales force digitalization, positioning itself strongly in the competitive e-commerce market. Technically, the website is built on modern frameworks like Next.js and React, leveraging Cloudflare for hosting and security. It integrates multiple analytics and marketing tools including Google Analytics, Mixpanel, LinkedIn Insight Tag, and Bing UET, indicating a mature digital marketing strategy. However, the security posture reveals critical gaps, notably the absence of a valid SSL/TLS certificate and disabled TLS protocols, which significantly undermine secure communications and user trust. While security headers are well configured, the lack of HTTPS is a major vulnerability. The website demonstrates excellent design, user experience, and content quality, with strong branding and trust signals such as customer case studies and comprehensive privacy policies. Strategic recommendations include immediate SSL/TLS deployment, enabling modern TLS protocols, and implementing cookie consent mechanisms to enhance compliance and security.

75
25
25
80
50
85
100
e-commerceomnichannelmarketingautomationintegrationplatform+2 more
Next.jsReactCloudflareGoogle Tag Manager+7

Partner Domains:

olist.com
parent57
tiny.com.br
partner61

+1 more partners

2025-06-14T13:04:06.179Z
engitechs.com favicon

Engitechs

engitechs.com

0
EnergyFrancemediumMEDIUM

Engitechs is a French SME specializing in the distribution of LED lighting products, with over 20 years of market presence. The company offers a wide range of LED strips, profiles, controllers, and accessories, targeting customers across metropolitan France and overseas territories. Their business model focuses on providing quality products combined with technical expertise and customer support, positioning themselves as a trusted partner in the LED lighting sector. Technically, the website is built on WordPress with WooCommerce, enhanced by popular plugins such as Yoast SEO for search optimization and WP Rocket for performance. The site demonstrates good mobile optimization and SEO practices, with structured data and social media integration. However, the SSL configuration lacks modern TLS protocol support, which is a security concern. From a security perspective, the site uses a valid SSL certificate and has SPF records configured for email protection. No critical vulnerabilities were detected, but the absence of modern TLS versions and security headers reduces the overall security posture. There is no explicit security policy or incident response information publicly available, which could be improved to enhance trust and compliance. Overall, Engitechs presents a professional and trustworthy online presence with solid business and technical foundations. Strategic improvements in security protocols and transparency around security policies would further strengthen their risk management and customer confidence.

15
25
25
85
70
85
100
ledlightingrubanleddistributeurclairagefrance+5 more
WordPressWooCommerceYoast SEOWP Rocket+4

Partner Domains:

a3web.fr
partner53
2025-06-14T13:03:52.442Z
ffmoto.org favicon

Fédération Française de Motocyclisme

ffmoto.org

0
TransportationFrancelargeMEDIUM

The Fédération Française de Motocyclisme (FFM) is the official governing body for motorcycling sports and activities in France. The organization provides a comprehensive digital platform offering licensing, competition results, live event streaming, and educational resources to a broad audience including riders, clubs, officials, and volunteers. The website demonstrates a strong market position as a large, well-established non-profit federation with multiple dedicated subdomains serving different community segments. Technically, the FFM website is built on Drupal 8 CMS and leverages a variety of modern web technologies and analytics tools such as Google Analytics, Matomo, Facebook Pixel, and Hotjar. The site is hosted on infrastructure managed by Gandi and employs good security practices including valid SSL certificates and security headers. However, it lacks support for modern TLS protocols and DNS security enhancements like DNSSEC and CAA records. From a security perspective, the site is well-configured with HSTS enabled and no known SSL vulnerabilities. Privacy and cookie policies are present and GDPR compliant, with a clear consent mechanism. Contact information is transparent and easily accessible. There is no explicit incident response or security policy published, which could be an area for improvement. Overall, the FFM website is a professional, trustworthy, and well-maintained platform that effectively serves its community. Strategic improvements in security protocols and transparency around incident response would further enhance its security posture and stakeholder trust.

50
25
25
75
62
85
100
motocyclismeffmmotorsportsportsfederationfrance+4 more
Drupal 8jQueryGoogle AnalyticsMatomo+7

Partner Domains:

franceolympique.com
partnerpending
fim-live.com
partner81

+3 more partners

2025-06-14T13:03:52.439Z
protectedtomorrows.com favicon

Protected Tomorrows Inc.

protectedtomorrows.com

0
Non-profitUnited StatessmallMEDIUM

Protected Tomorrows Inc. is a specialized non-profit organization dedicated to providing compassionate guidance and resources for families and caregivers of individuals with special needs. Their market position is focused on niche services including advocacy, financial advisory, educational programs, and membership-based community support. The website offers a comprehensive range of services and resources, including free tools, expert Q&A, and a shop with educational materials, positioning them as a trusted ally in future planning for special needs families. Technically, the website is built on WordPress with WooCommerce and integrates multiple plugins for events, forms, payments, and analytics. The hosting is managed via WP Engine with Cloudflare CDN, ensuring good performance and availability. Security-wise, the site has a valid SSL certificate but lacks modern TLS protocol support and some advanced security headers. Cookie consent and privacy policies are implemented with GDPR compliance in mind, and accessibility is addressed via an ADA widget. Overall, the site demonstrates a good balance of business focus, technical maturity, and security awareness, though there is room for improvement in security hardening and transparency.

15
58
25
100
60
85
100
specialneedsfutureplanningadvocacyfinancialadvisorymembership+2 more
WordPressWooCommercejQueryGoogle Analytics+8

Partner Domains:

gofortress.com
partnerpending
2025-06-14T13:03:51.488Z
L

LexisNexis Risk Solutions

zetx.com

0
GovernmentUnited StatesenterpriseMEDIUM

LexisNexis Risk Solutions, operating the Accurint® TraX™ platform, provides advanced investigative solutions primarily targeting law enforcement and government agencies. Their platform integrates call detail records with law enforcement and identity data to enable efficient device geolocation investigations. The company is positioned as a trusted, enterprise-level provider with a comprehensive suite of services including investigative support, training, and single sign-on capabilities with related products. The website reflects a mature digital presence with extensive content, strong branding, and a focus on compliance and privacy. Technically, the website employs a robust technology stack including JavaScript frameworks, VWO for optimization, Adobe DTM for tag management, and OneTrust for cookie consent management. Hosting is on Amazon AWS with a valid SSL certificate, though some TLS protocol support appears limited. Performance is moderate to slow due to large page size and resource count, but mobile optimization and accessibility are well addressed. From a security perspective, the site implements key best practices such as HSTS and valid SSL, but lacks DNSSEC and CAA records, which are recommended for enhanced security. No explicit security policy or incident response information is publicly available, indicating an area for improvement. The site demonstrates good privacy compliance with clear policies and consent mechanisms. Overall, LexisNexis Risk Solutions maintains a high level of professionalism and trustworthiness in its online presence, supporting its role as a critical provider of investigative and risk management solutions. Strategic enhancements in security posture and transparency could further strengthen its market position and customer confidence.

80
40
30
85
97
85
100
accurinttraxlexisnexisrisksolutionslawenforcementdevicegeolocationcalldetailrecords+7 more
JavaScriptjQueryBootstrapVWO (Visual Website Optimizer)+7

Partner Domains:

lexisnexis.com
partneranalyzing...
accurint.com
partner60
2025-06-14T13:03:35.492Z
L

LexisNexis

nexis.com

0
OtherUnited StatesenterpriseMEDIUM

LexisNexis operates as a leading provider of legal, regulatory, and business information services, targeting primarily legal professionals and researchers. The website analyzed is a secure sign-in portal for accessing their research services, reflecting a mature enterprise-level business model with a strong market position. The company provides comprehensive customer support with multiple international phone numbers and maintains clear links to privacy and terms of service policies, demonstrating regulatory awareness and user transparency. Technically, the site employs standard web technologies including jQuery and OneTrust for cookie consent management. While the SSL certificate is valid and issued by a reputable CA, the absence of modern TLS protocols and security headers indicates room for improvement in security hardening. Performance is moderate to slow, and mobile optimization is basic, suggesting potential areas for technical enhancement. From a security perspective, the site shows good foundational practices such as valid SSL and cookie consent but lacks advanced security headers, DNSSEC, and CAA records. No explicit security policies, incident response contacts, or vulnerability disclosure mechanisms were found, which could be addressed to improve security posture and user trust. Overall, the website is professional and trustworthy but would benefit from technical and security upgrades to align with best practices and compliance standards.

35
58
25
85
75
85
100
legalresearchsigninlexisnexisprivacy+2 more
jQueryOneTrust Cookie ConsentHTML5CSS3+1

Partner Domains:

relxgroup.com
parentpending
2025-06-14T13:03:35.484Z
ad-agents.com favicon

ad agents GmbH

ad-agents.com

0
TechnologyGermanymediumMEDIUM

ad agents GmbH is a well-established digital marketing agency based in Germany, specializing in online and performance marketing services. Founded in 2006, the company offers a comprehensive portfolio including search engine advertising, SEO, Amazon marketplace services, affiliate management, social media advertising, consulting, analytics, and product data management. The agency serves a broad business audience seeking to enhance their digital marketing performance nationally and internationally. The website reflects a mature digital presence with excellent content quality, strong branding consistency, and multiple trust indicators such as client testimonials and industry certifications. Technically, the site is built on WordPress with modern performance optimizations and integrates advanced marketing and analytics tools like HubSpot, Usercentrics CMP, and eTracker. Security posture is good with valid SSL, HSTS enabled, and SPF records configured, though TLS protocols are currently disabled, which is a notable gap. Privacy compliance is well addressed with GDPR-aligned cookie consent mechanisms. Overall, the company demonstrates a strong market position with a professional and trustworthy online presence.

25
43
17
100
85
85
75
digitalmarketingperformancemarketingseoseaaffiliate+4 more
WordPressYoast SEOWP RocketHubSpot+6

Partner Domains:

adtraction.com
partnerpending
amalytix.com
partnerpending

+3 more partners

2025-06-14T13:03:27.397Z
solarisgroup.com favicon

Solarisbank AG

solarisgroup.com

0
FinanceGermanylargeMEDIUM

Solarisbank AG operates as a leading embedded finance platform in Europe, providing a comprehensive Banking-as-a-Service solution that enables businesses to integrate digital banking, payments, lending, and identification services via advanced APIs. The company holds a full German banking license, allowing it to operate across the EU with a strong compliance and regulatory framework. Solarisbank's market position is reinforced by partnerships with notable clients such as American Express and Tomorrow, and a clear focus on customer-centric financial product innovation. Technically, Solarisbank employs modern web technologies including React and Gatsby, hosted on AWS infrastructure, with a cloud-based banking platform emphasizing scalability and international expansion. The website demonstrates good performance, mobile optimization, accessibility, and SEO practices, supported by a robust API-driven backend. From a security perspective, Solarisbank maintains a valid SSL certificate, enforces HSTS with preload, and implements SPF DNS records. However, the absence of enabled TLS 1.2 or higher protocols and lack of DNSSEC and CAA records present areas for improvement. The company provides clear privacy policies, cookie consent mechanisms, and incident response contact channels, reflecting a mature security posture. Overall, Solarisbank presents a high-trust, professional digital presence with strong business and technical foundations. Strategic enhancements in security protocols and transparency around vulnerability disclosures would further strengthen its risk profile and customer confidence.

80
43
25
95
75
85
100
solarisbankbankbankingplatformdigital+6 more
ReactGatsbyRESTful APIsCloud-based infrastructure+1

Partner Domains:

whispli.com
serviceanalyzing...
americanexpress.com
partner72

+1 more partners

2025-06-14T13:03:15.572Z
arrirental.com favicon

ARRI GmbH

arrirental.com

0
MediaUnited StateslargeMEDIUM

ARRI Rental Group is a globally recognized leader in the motion picture equipment rental industry, offering exclusive cameras, lenses, lighting, and grip equipment. The company operates through a network of facilities across North America, Europe, and the UK, serving professional filmmakers and production companies with high-end technology and personalized service. Their website reflects a strong brand presence with comprehensive product showcases and project highlights, targeting a professional audience in the media sector. Technically, the site is built on CoreMedia CMS and integrates modern marketing and tracking tools such as Google Tag Manager and Facebook Pixel, alongside a user consent management platform (Usercentrics). However, performance is somewhat slow, and there are opportunities to enhance security by enabling modern TLS protocols and implementing additional security headers. The security posture is moderate with a valid SSL certificate but lacks advanced configurations like HSTS and DNSSEC. Privacy and cookie policies are present and GDPR compliant, but no explicit security or incident response policies are found. Overall, ARRI Rental demonstrates a mature digital presence with room for technical and security improvements to further strengthen trust and compliance.

60
25
25
100
75
85
90
motionpictureequipmentcamerarentallenseslightinggrip+2 more
CoreMedia CMSGoogle Tag ManagerFacebook PixelUsercentrics CMP+2

Partner Domains:

arri.com
partner69
illuminationdynamics.com
partnerpending
2025-06-14T13:03:13.332Z
fordheritagevault.com favicon

The Ford Motor Company

fordheritagevault.com

0
TransportationUnited StatesenterpriseMEDIUM

The Ford Heritage Vault website serves as an official digital archive for The Ford Motor Company, showcasing a century-long collection of brochures, photographs, and historical automotive content from 1903 to 2003. It targets automotive enthusiasts, historians, and researchers by providing advanced search and filtering tools to access a rich repository of Ford, Lincoln, Mercury, and Edsel heritage materials. The platform positions itself as an authoritative source for Ford's historical assets, reinforcing brand legacy and customer engagement. Technically, the website is built on Microsoft IIS with ASP.NET backend, leveraging modern JavaScript libraries such as jQuery, Axios, and AOS for enhanced user experience. Hosting appears to be on Amazon AWS infrastructure. While the site demonstrates good mobile optimization and performance, it lacks some modern security configurations such as enabled TLS protocols and HSTS, which are critical for secure communications. From a security perspective, the site employs a valid GlobalSign SSL certificate and anti-clickjacking measures but does not enable modern TLS versions or security headers like Content-Security-Policy. No explicit security or incident response policies are published, and no vulnerability disclosure or security.txt files are found. Privacy policies and terms of service are linked to official Ford corporate domains, indicating compliance with GDPR and other regulations. Overall, the website is professionally designed with consistent branding and trustworthy content. However, security posture can be improved by enabling modern TLS protocols, implementing HSTS, and adding comprehensive security headers. Enhancing accessibility and cookie consent mechanisms would also strengthen compliance and user trust.

15
43
9
75
80
85
100
fordheritagearchiveautomotivebrochures+5 more
ASP.NETMicrosoft-IIS/10.0jQuery 3.6.0FontAwesome+7
2025-06-14T13:02:55.547Z
volkswagen-versicherungsdienst.de favicon

Volkswagen Financial Services

volkswagen-versicherungsdienst.de

0
FinanceGermanyenterpriseMEDIUM

Volkswagen Financial Services AG operates the volkswagen-versicherungsdienst.de website, providing a comprehensive portfolio of automotive insurance products including liability, partial and full coverage, warranty extensions, leasing rate insurance, credit protection, and travel insurance. The site targets primarily German private and business customers, leveraging the strong Volkswagen brand and integrated financial services ecosystem. The website is built on Adobe Experience Manager with extensive use of modern web technologies and content delivery networks, ensuring excellent performance and user experience. However, the SSL configuration is critically flawed with a self-signed certificate and no enabled TLS protocols, which undermines secure communications. Security headers are well implemented, but the absence of a cookie consent mechanism and explicit security or incident response policies indicates gaps in compliance and transparency. The site integrates multiple marketing and analytics tools, including Adobe Analytics, Google Tag Manager, and UserZoom, reflecting extensive user tracking. Overall, the site is professional, content-rich, and trustworthy from a business perspective but requires urgent security improvements to protect user data and comply with best practices.

80
18
25
85
72
85
100
insuranceautomotiveleasingfinancingvolkswagen+5 more
Adobe Experience Manager (AEM)Adobe Launch (Tag Manager)Helix RUM (Adobe Helix Real User Monitoring)UserZoom (UX feedback tool)+7

Partner Domains:

volkswagenbank.de
partner69
vwfs.de
partner69

+2 more partners

2025-06-14T13:02:51.574Z