Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 2920 of 2974|Showing 145951-146000 of 148700
cybusinessonline.co.uk favicon

Virgin Money UK

cybusinessonline.co.uk

0
bankingUKlargeLOW

The website demonstrates a generally strong technical security foundation with high scores in email security, SSL/TLS, DNS health, and network security. However, significant gaps exist in compliance and governance areas, particularly related to GDPR and NIS2 regulations, which pose notable legal and operational risks. The absence of a cookie policy, consent banner, and incomplete privacy documentation expose the business to potential regulatory penalties and customer trust issues. Critical deficiencies in information security framework, incident response, and security policy documentation under NIS2 further elevate the risk of unmanaged security incidents and business disruption. While no critical vulnerabilities were identified, the combination of high and medium severity findings indicates an urgent need to address compliance and governance controls. Proactively remediating these issues will reduce regulatory exposure, improve stakeholder confidence, and strengthen the overall security posture. Immediate focus on policy implementation and GDPR compliance will deliver the greatest business value and risk mitigation. Ongoing monitoring of SSL certificates and DNS configurations ensures continued protection of core infrastructure components.

85
43
25
100
95
90
100
business bankingVirgin Moneybusiness accountsfinanceSME banking+1 more
jQuery 3.5.1Visual Website Optimizer (VWO)Adobe DTM (Dynamic Tag Manager)CSS Custom Properties (with fallback)+7

Partner Domains:

virginmoneyukplc.com
subsidiary74
virginmoney.com.au
sister company67

+1 more partners

2025-06-13T21:51:18.215Z
velocityfrequentflyer.com favicon

Velocity Frequent Flyer Pty Limited

velocityfrequentflyer.com

0
airline loyalty programAustralialargeMEDIUM

The website demonstrates a moderate security posture with no critical vulnerabilities detected but multiple high and medium-risk issues that expose the organization to regulatory, reputational, and operational risks. Key weaknesses lie in missing essential security headers, lack of compliance with GDPR requirements, and absence of fundamental NIS2 cybersecurity governance frameworks. While foundational network and email security measures are strong, gaps in security policy documentation, incident response readiness, and privacy transparency present significant business risks. Failure to implement privacy policies and consent mechanisms may lead to regulatory fines and loss of customer trust. Additionally, missing headers like Strict-Transport-Security and Content-Security-Policy increase exposure to man-in-the-middle and cross-site scripting attacks. The organization should prioritize closing these gaps to protect sensitive information, ensure regulatory compliance, and maintain customer confidence. Immediate remediation combined with policy development and communication enhancements is essential to strengthen overall security posture.

50
25
25
100
85
85
100
frequent flyerloyalty programVirgin Australiatravelpoints+2 more
Adobe Helix RUMGoogle Fonts (Montserrat)Salesforce Embedded Service (Live Chat)New Relic Browser Agent+6

Partner Domains:

virginaustralia.com
partnerpending
flybuys.com.au
partnerpending

+1 more partners

2025-06-13T21:50:33.814Z
eversign.com favicon

Xodo

eversign.com

0
Electronic Signature / Business ApplicationNot explicitly statedmediumMEDIUM

The website currently exhibits a moderate to low overall security posture, with critical issues notably absent but several high and medium severity vulnerabilities present. Key deficiencies exist in security header implementations, GDPR compliance, and adherence to NIS2 regulatory frameworks, indicating significant gaps in both technical and organizational security controls. The absence of fundamental headers such as Strict-Transport-Security and Content-Security-Policy increases risk exposure to common web attacks like man-in-the-middle and cross-site scripting. GDPR-related shortcomings, including lack of a cookie consent banner and incomplete privacy policies, expose the business to regulatory penalties and undermine customer trust. The failure to establish an information security framework, incident response procedures, and security documentation highlights weaknesses in governance and risk management. However, strengths are noted in email security, SSL/TLS configurations, DNS health, and network security, which provide a solid foundation for secure communications and infrastructure. Addressing the highlighted issues will substantially reduce risk, improve compliance, and safeguard brand reputation. Immediate focus on regulatory compliance and security policy development is crucial for sustainable business operations.

30
58
25
100
85
90
100
eSignaturedigital signaturesbusiness applicationonline signingdocument automation+1 more
256-bit SSL encryptionjQuery 3.6.0Google Tag ManagerGoogle Consent Mode+8

Partner Domains:

xodo.com
subsidiaryanalyzing...
2025-06-13T21:34:53.118Z
ccavenue.ae favicon

CCAvenue

ccavenue.ae

0
financial technologyUAEmediumMEDIUM

The website demonstrates a moderate overall security posture with no critical issues detected but several high and medium-severity vulnerabilities that could expose the business to regulatory, reputational, and operational risks. Notably, GDPR compliance is weak, lacking essential cookie policies and consent mechanisms, increasing potential legal liabilities in privacy regulations. The absence of a formal information security framework, incident response procedures, and security policies indicates immature governance and preparedness, which could hinder effective breach management. Security headers are partially implemented but missing key protections like Content-Security-Policy, leaving the site vulnerable to client-side attacks. Email security configurations such as DMARC and DKIM require improvement to prevent phishing and spoofing threats. While SSL/TLS and DNS health scores are relatively strong, mixed content issues and missing DNSSEC reduce overall trustworthiness. Network exposure of services like SSH presents an additional attack surface. Addressing these issues will significantly enhance the security posture and reduce business risks related to compliance, data breaches, and service disruption.

65
43
17
75
85
85
90
payment gatewaymerchant accountcredit card processingonline paymentsUAE+1 more
Google Tag ManagerGoogle Ads (gtag.js)jQueryjQuery bxSlider+9

Partner Domains:

ccavenue.sa
subsidiary65
ccavenue.us
subsidiary61

+1 more partners

2025-06-13T21:30:20.155Z
ccavenue.com favicon

CCAvenue

ccavenue.com

0
financial technologyIndialargeMEDIUM

The website demonstrates a moderate to low overall security posture with no critical vulnerabilities but several high and medium risk issues that could expose the business to significant threats. Key deficiencies exist in foundational web security headers, GDPR compliance, and adherence to NIS2 regulations, indicating potential legal and operational risks. Missing security headers like Content-Security-Policy and X-Frame-Options increase vulnerability to common web attacks such as clickjacking and cross-site scripting. GDPR gaps, including absent cookie policies and consent mechanisms, expose the business to regulatory fines and reputational damage. The lack of documented security policies, incident response, and business continuity plans points to unpreparedness for cyber incidents, potentially leading to extended downtime or data breaches. SSL certificate expiration soon poses imminent risk of service disruption and loss of customer trust. While email security and network security are relatively strong, enhancements like enabling DNSSEC and securing exposed services are needed. Overall, urgent remediation is required to protect business operations, ensure regulatory compliance, and maintain customer confidence.

35
43
25
85
85
85
90
payment gatewaymerchant accountscredit card processingonline paymentsPCI-DSS compliant
PCI-DSS CompliantGoogle Tag ManagerGoogle AdsjQuery+7

Partner Domains:

ccavenue.sa
subsidiarypending
ccavenue.ae
subsidiarypending

+1 more partners

2025-06-13T21:28:49.165Z