Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 2945 of 2974|Showing 147201-147250 of 148699
dimco.mc favicon

Dimco

dimco.mc

0
professional kitchen equipment and servicesFRmediumHIGH

The website's overall security posture is critically weak, primarily due to the complete absence of HTTPS encryption, exposing all data transmissions to interception and manipulation. The lack of essential security headers such as Strict-Transport-Security and Content-Security-Policy further increases vulnerability to common web-based attacks like man-in-the-middle and cross-site scripting. Additionally, the site fails to comply with GDPR requirements by not providing a privacy policy, cookie policy, or consent mechanisms, risking significant regulatory penalties and reputational damage. From a NIS2 directive perspective, there is a notable absence of documented security policies, incident response procedures, and security contact information, indicating poor organizational readiness for cyber incidents. Although email and network security settings are strong, these strengths are overshadowed by foundational security and compliance gaps. DNS configurations are somewhat healthy but can be improved with DNSSEC and CAA records to enhance domain authenticity and prevent certificate misuse. Immediate remediation is crucial to mitigate data breach risks, regulatory fines, and loss of customer trust, which can severely impact business continuity and growth.

60
-
-
100
-
85
100
professional kitchenskitchen installationmaintenanceMonacohospitality+1 more
jQuerySweetAlert2GSAPSlick Carousel+6

Partner Domains:

auth0.com
servicepending
odice.info
partnerpending
2025-06-13T18:10:49.904Z
solamito-properties.mc favicon

Solamito Properties

solamito-properties.mc

0
real estateMonacosmallHIGH

The website's overall security posture is critically deficient, with multiple high and critical severity issues across key areas such as encryption, privacy compliance, and security policies. The absence of HTTPS encryption exposes all data transmissions to interception and manipulation, representing the most urgent risk to both users and business integrity. Critical gaps in GDPR compliance, including missing privacy and cookie policies as well as lack of cookie consent mechanisms, put the organization at risk of regulatory sanctions and reputational damage. Security headers essential for protecting against common web attacks are largely missing, increasing vulnerability to clickjacking, XSS, and other exploits. Furthermore, foundational governance elements like incident response procedures, security policies, and vulnerability disclosure frameworks are absent, indicating a lack of mature security management. DNS and email security posture are relatively strong, but these do not compensate for the critical failures in encryption and compliance. Immediate remediation is required to safeguard customer data, maintain trust, and meet legal obligations. Without prompt action, the organization faces significant operational, financial, and reputational risks.

30
-
5
90
-
85
100
real estateluxury propertiesMonacoFrench Rivierainvestment+1 more
jQueryjQuery UIBootstrap 3.3.1Font Awesome 4.2.0+11

Partner Domains:

ckc-net.com
servicepending
solamito-properties-real-estate.mc
subsidiarypending
2025-06-13T18:10:49.899Z
turassist.com favicon

Tur Assist

turassist.com

0
Assistance ServicesTurkeylargeHIGH

The website's overall security posture is critically weak, with multiple severe vulnerabilities primarily due to the absence of HTTPS encryption and inadequate security headers. The lack of HTTPS not only exposes sensitive data in transit but also results in non-compliance with GDPR and NIS2 regulations, posing significant legal and reputational risks. Key security headers such as Content-Security-Policy and X-Frame-Options are missing, increasing susceptibility to cross-site scripting and clickjacking attacks. Additionally, the absence of a privacy policy, cookie policy, and consent mechanisms indicates poor GDPR adherence, further risking regulatory penalties. The organization lacks foundational information security documentation, incident response procedures, and business continuity planning, undermining its ability to effectively manage and recover from security incidents. While email and network security appear strong, these do not compensate for the critical gaps in web and data protection. Immediate remediation is essential to protect customer data, maintain trust, and ensure compliance with legal frameworks. Overall, the current security posture exposes the business to high risk of data breaches, regulatory fines, and operational disruptions.

35
-
5
100
-
85
100
AssistanceInsuranceAutomotiveHealthLifestyle+1 more
Google Tag ManagerFacebook PixeljQueryTermsFeed Cookie Consent+2

Partner Domains:

rsotoekspertiz.com
partnerpending
rsboyasizonarim.com
partnerpending

+3 more partners

2025-06-13T18:10:49.882Z
mfo.org favicon

Multinational Force and Observers

mfo.org

0
International peacekeeping and securityEgypt/Israel (operational zones)mediumHIGH

The website currently exhibits critical vulnerabilities that severely compromise its security posture, most notably the complete absence of HTTPS encryption, which exposes all data transmissions to interception and manipulation. The lack of fundamental security headers such as Content-Security-Policy further increases the risk of cross-site scripting and other client-side attacks. Additionally, non-compliance with GDPR regulations due to missing privacy and cookie policies, as well as absence of cookie consent mechanisms, presents significant legal and reputational risks. Deficiencies in security governance, including missing information security frameworks, incident response procedures, and vulnerability disclosure policies, weaken the organization's ability to detect and respond to cyber threats effectively. Email security measures are partially implemented but require enforcement improvements to prevent phishing and spoofing attacks. DNS configurations lack advanced protections like DNSSEC, which could lead to domain hijacking risks. Overall, the combined technical and compliance gaps place the business at high risk of data breaches, regulatory penalties, and operational disruption.

60
-
-
85
-
85
90
peacekeepingsecurityinternational treatySinaiMFO+3 more
Vimeo (video provider)Mapbox GL JS (map library)Google Tag ManagerVue.js (implied by vue-ssr-id and nuxt-progress)+6
2025-06-13T18:10:49.864Z
peugeot.com favicon

Peugeot

peugeot.com

0
automotivenot determinablelargeHIGH

The website's overall security posture is critically weak, primarily due to the absence of HTTPS encryption, exposing all data in transit to interception and undermining user trust and regulatory compliance. Multiple critical and high-severity issues related to missing essential security headers such as Content-Security-Policy and X-Frame-Options further increase the risk of cross-site scripting and clickjacking attacks. The lack of GDPR compliance artifacts, including privacy policies, cookie consent mechanisms, and third-party privacy transparency, poses significant legal and reputational risks. From a regulatory perspective, the absence of a structured information security framework, incident response, and business continuity plans indicates unpreparedness for security incidents, risking operational disruptions. While network security and email security controls are strong, these positives do not offset fundamental web security deficiencies. DNS security is moderately addressed but can be improved by enabling DNSSEC and configuring CAA records. Immediate remediation is necessary to protect customer data, maintain compliance, and secure business operations. Without urgent action, the organization faces elevated risks of data breaches, regulatory penalties, and customer trust erosion.

35
-
5
100
-
85
100
peugeotautomotivedigital landing pagemulti language
Google AnalyticsAdobe Helix RUMAB Tasty (mentioned as third party script)Google Tag Manager+2

Partner Domains:

stellantis.com
subsidiarypending
ingenico.com
paymentpending

+1 more partners

2025-06-13T18:10:49.858Z
centurionbulk.com favicon

Centurion Bulk

centurionbulk.com

0
shipping and maritimeSingaporemediumHIGH

The website's overall security posture is critically weak, exposing the business to significant risks including data breaches, regulatory non-compliance, and service disruptions. The absence of HTTPS encryption is a critical vulnerability that undermines all data confidentiality and integrity, putting customer data and business communications at risk. Missing essential security headers such as Strict-Transport-Security and Content-Security-Policy increase susceptibility to common web attacks like man-in-the-middle, clickjacking, and cross-site scripting. Non-compliance with GDPR is evident due to missing privacy policies, cookie consent mechanisms, and third-party privacy disclosures, which can result in heavy fines and reputational damage. Several NIS2 directive requirements are unmet, including lack of incident response, security policies, and business continuity planning, exposing the company to operational risks and regulatory penalties. Network security is compromised by exposing critical services like FTP and MySQL publicly, heightening the risk of unauthorized access. Email security is moderately implemented but lacks enforcement and reporting mechanisms, potentially increasing phishing and spoofing risks. Overall, urgent remediation is needed to protect sensitive data, comply with regulations, and maintain customer trust.

15
-
5
70
-
85
50
shippingcharteringbulk carriersmaritimelogistics+1 more
WordPressYoast SEOElementorUltimate Elementor+5
2025-06-13T18:10:49.569Z
hoozin.com favicon

Hoozin

hoozin.com

0
software / digital workplace solutionsUSAmediumHIGH

The website's overall security posture is critically weak, exposing the business to significant risks including data breaches, regulatory non-compliance, and operational disruptions. The absence of HTTPS encryption is a critical vulnerability that undermines data confidentiality and trust, while missing essential security headers leave the site open to common web attacks such as clickjacking and cross-site scripting. GDPR compliance is severely lacking, with no cookie policy or consent mechanisms, creating legal exposure and reputational damage risks. Network security is compromised by the exposure of high-risk services like FTP and MySQL without adequate protections, increasing the attack surface. The lack of incident response, security policies, and business continuity planning under the NIS2 framework indicates immature security governance. Although email security and DNS health score relatively well, these strengths do not offset the critical deficiencies elsewhere. Immediate remediation is required to protect customer data, maintain regulatory compliance, and safeguard business continuity. Without urgent action, the organization risks financial penalties, loss of customer trust, and potential service outages.

15
18
5
85
-
85
50
digital workplaceworkflowssocial intranetemployee collaborationintegration+1 more
WordPress 6.8.1W3 Total CacheRodller BlocksContact Form 7+8

Partner Domains:

rodller.com
partnerpending
2025-06-13T18:10:49.566Z