Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 790 of 870|Showing 39451-39500 of 43489
B

BFI Oberösterreich

bfi-ooe.at

0
EducationAustrialargeHIGH

BFI Oberösterreich is a leading adult education provider in Upper Austria offering a wide range of vocational training, adult education courses, and customized corporate training programs. The website is built on TYPO3 CMS and incorporates modern frontend technologies such as jQuery and Bootstrap, providing a professional and accessible user experience. The business targets both private individuals and companies, emphasizing lifelong learning and workforce development. The site includes comprehensive course catalogs, contact information, and trust signals such as certifications and partnerships with official bodies. From a technical perspective, the website demonstrates good content quality, SEO, and accessibility, but suffers from critical security shortcomings due to the absence of a valid SSL certificate and HTTPS support. Security headers are partially implemented, but the lack of TLS protocols and HSTS reduces the overall security posture significantly. Privacy compliance is well addressed with clear privacy and cookie policies and consent mechanisms. Overall, the website is professional and credible but requires urgent improvements in SSL/TLS configuration to ensure secure communications and protect user data. Addressing these security gaps will enhance trust and compliance with modern web security standards.

-
-
-
50
-
50
100
educationadulteducationvocationaltrainingonlinecoursescorporatetraining+5 more
TYPO3 CMSjQuery 1.11.2BootstrapShadowbox+2

Partner Domains:

leitbetriebe.at
partnerpending
arbeiterkammer.at
partnerpending

+3 more partners

2025-06-15T22:12:00.829Z
musicdirect.com favicon

Music Direct

musicdirect.com

0
RetailUnited StatesmediumHIGH

Music Direct operates as a specialized e-commerce retailer focusing on high-end audio equipment and audiophile music products, including vinyl records and turntables. The company positions itself as a leading online destination for audiophiles and music enthusiasts, offering a broad catalog of equipment and music media. Their business model centers on direct online sales, supported by customer service, trade-in programs, and financing options. The website reflects a mature digital presence with comprehensive product offerings and clear navigation tailored to their target audience. Technically, the website is built on the BigCommerce platform using the Stencil framework, leveraging modern web technologies such as jQuery, Bootstrap, and OwlCarousel. The site integrates multiple marketing and analytics tools including Google Analytics 4, Klaviyo, Lucky Orange, and Yotpo, indicating a sophisticated approach to customer engagement and data-driven marketing. Hosting is provided via Cloudflare, enhancing performance and availability. From a security perspective, the site exhibits significant weaknesses. Despite Cloudflare hosting, the SSL certificate is invalid or missing, and no TLS protocols are enabled, resulting in unencrypted HTTP traffic. Security headers such as X-Frame-Options and X-Content-Type-Options are present, but critical HTTPS enforcement and HSTS configurations are lacking. These deficiencies expose the site and its users to potential interception and downgrade attacks. Privacy and cookie policies are well implemented with consent mechanisms, reflecting compliance with GDPR and related regulations. Overall, while the business and technical infrastructure are solid and professional, the lack of proper SSL/TLS configuration is a critical security gap that undermines user trust and data protection. Addressing this issue should be a top priority to ensure secure transactions and compliance with industry standards.

-
-
5
50
-
90
100
e-commerceaudiovinylmusicretail+1 more
jQuery 3.6.0BigCommerce Stencil frameworkBootstrap 5.3.3OwlCarousel 2.3.4+7
2025-06-15T22:12:00.331Z
D

daheim-bremen.de

daheim-bremen.de

0
HospitalityGermanysmallHIGH

The website 'Das Viertel liefert' serves as a local food delivery platform targeting residents in Bremen, Germany. It aggregates various local restaurants offering diverse cuisines such as burgers, pasta, sushi, Italian pizza, and Syrian specialties. The business model focuses on online food ordering and delivery, leveraging third-party ordering platforms. The site content is basic but relevant, with a clear focus on local hospitality services. Technically, the website is minimalistic, using nginx as the server and Google Fonts for typography. There is no evidence of a CMS or advanced frameworks. The site lacks HTTPS, which is a critical security flaw, and no modern security headers or mechanisms are implemented. Performance metrics are unavailable, but the site appears to have basic mobile optimization and accessibility. From a security perspective, the absence of SSL/TLS encryption, security headers, and DNS security features exposes users to potential risks. No privacy or cookie policies are present, indicating non-compliance with GDPR. No contact or incident response information is provided, limiting trust and transparency. Overall, the website presents a low security posture and limited privacy compliance, which negatively impacts its trustworthiness and professional appearance. Strategic improvements in security, privacy policies, and contact transparency are recommended to enhance user trust and regulatory compliance.

-
-
5
50
-
85
100
fooddeliverylocalbusinessrestaurantaggregatorbremenhospitality
nginxGoogle Fonts
2025-06-15T22:11:57.035Z
B

Burger King

bk.com

0
RetailN/aenterpriseHIGH

Burger King's website at bk.com presents a minimalistic digital presence primarily built using modern web technologies such as React Native Web and Expo Router, hosted on AWS infrastructure with CloudFront CDN. The site includes a cookie consent mechanism via OneTrust, indicating some level of privacy compliance effort. However, the website lacks visible content such as privacy policies, terms of service, or contact information, which limits user trust and transparency. From a security perspective, the site is undermined by the absence of a valid SSL certificate and HTTPS support, exposing users to potential risks. While security headers are properly configured, the lack of encryption and presence of a subdomain takeover vulnerability on dev.bk.com represent significant security concerns. The DNS and WHOIS data indicate legitimate domain registration consistent with the brand, but the subdomain issue requires urgent remediation. Overall, the website's technical infrastructure is modern but incomplete in critical areas such as security and content completeness. The lack of essential legal and contact information, combined with security vulnerabilities, results in a moderate to low trust level. Strategic improvements in SSL deployment, vulnerability mitigation, and content enrichment are necessary to enhance security posture and user confidence.

-
-
-
50
-
65
100
fastfoodburgerrestaurantreact-native-webexpo-router+3 more
React Native WebExpo RouterAmazon S3CloudFront+3
2025-06-15T22:11:08.287Z
B

BERNARD Gruppe

bernard-ing.com

0
EnergyAustriamediumHIGH

The Bernard Gruppe is a medium-sized, owner-managed engineering group founded in 1983, specializing in interdisciplinary engineering services across energy, industry, infrastructure, and transportation sectors. With approximately 400 employees and operations in over 40 countries, the company offers comprehensive consulting, planning, and project realization services, including specialized software and hardware solutions. The website content reflects a professional engineering firm with a broad service portfolio and international presence. Technically, the website is built on WordPress using the Avada theme and includes a cookie consent mechanism from an external provider. However, the site lacks HTTPS support and modern security configurations, which significantly impacts its security posture. Performance data is missing, and SEO and accessibility features are basic. No analytics or tracking services beyond cookie consent are detected. From a security perspective, the absence of a valid SSL certificate and HTTPS is a critical vulnerability, exposing users to potential data interception risks. The site also lacks security headers, DNSSEC, and other modern protections. No privacy policy, terms of service, or incident response information is provided, indicating gaps in compliance and security transparency. Overall, the website presents a moderate business credibility but suffers from significant security and privacy shortcomings. Strategic improvements in SSL deployment, security headers, and privacy documentation are essential to enhance trust and compliance.

-
-
-
50
-
85
85
engineeringenergytransportationautomationinfrastructure+1 more
ApacheJavaScript (cookieconsent.at)CSSHTML5+1
2025-06-15T22:11:07.839Z