Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 859 of 870|Showing 42901-42950 of 43468
M

My Health Toolkit, LLC

myhealthtoolkit.com

0
HealthcareUnited StatesmediumHIGH

My Health Toolkit, LLC operates a healthcare benefits management platform targeting members of various Blue Cross and Blue Shield plans across multiple states in the United States. The platform offers services such as claims status checking, digital ID card management, coverage confirmation, provider search, and medical spending account management. It serves as a centralized portal for eligible members to manage their health insurance benefits efficiently. Technically, the website relies on the Dojo Toolkit 1.13.0 for frontend functionality and integrates Google Analytics and Google Tag Manager for user tracking and analytics. The site is hosted on infrastructure associated with Level3. However, the website suffers from slow load times and basic mobile optimization. SEO and accessibility features are present but minimal. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, exposing users to significant risks. No security headers or advanced security configurations are implemented. Privacy and cookie policies are absent, and no GDPR compliance indicators are present. These deficiencies represent critical vulnerabilities and compliance gaps that must be addressed to protect user data and build trust. Overall, while the business model and service offerings are clear and well-targeted, the technical and security posture of the website is weak. Immediate remediation of SSL/TLS issues and implementation of privacy policies are recommended to improve security and compliance. Enhancements in performance and mobile responsiveness would also benefit user experience and trust.

65
25
25
50
50
75
100
healthcareinsurancebluecrossbenefitsmanagementhealthplan+3 more
Dojo Toolkit 1.13.0Google AnalyticsGoogle Tag ManagerSmartBanner.js+1
2025-06-14T20:53:29.658Z
vrm-mediasales.de favicon

VRM Holding GmbH & Co. KG

vrm-mediasales.de

0
MediaGermanymediumHIGH

VRM Media Sales is a regional media sales company operating primarily in the Rhein-Main and Mittelhessen regions of Germany. They specialize in developing tailored advertising solutions and media campaigns for local businesses, leveraging print and online media channels. The company positions itself as a competent partner for marketing strategies, offering services such as campaign planning, mediamix consulting, and corporate publishing. Their website reflects a medium-sized enterprise with a professional digital presence, targeting businesses seeking regional advertising opportunities. Technically, the site uses JavaScript, Google Analytics, Google Tag Manager, and a consent management platform, hosted on Versatel infrastructure and built on the ecomaXL CMS platform. However, the website suffers from a lack of a valid SSL certificate and HTTPS support, which significantly impacts its security posture. Other security best practices such as DNSSEC, DMARC, and security headers are missing, exposing the site to potential risks. Privacy compliance is well addressed with a comprehensive privacy policy, cookie consent mechanism, and GDPR notices. Overall, the website is content-rich and professionally designed but requires urgent security improvements to protect user data and enhance trust.

70
18
25
70
100
75
-
mediaadvertisingmarketingregionalgerman
JavaScriptGoogle AnalyticsGoogle Tag ManagerConsentmanager.net
2025-06-14T20:53:07.864Z
uppy.io favicon

Transloadit

uppy.io

0
TechnologyN/amediumHIGH

Uppy is an open source JavaScript file uploader developed and maintained by Transloadit. It provides a modular and extensible solution for uploading files from local devices and various remote sources such as Dropbox, Google Drive, Instagram, and more. The platform targets developers and businesses seeking reliable and easy-to-integrate file upload capabilities. Uppy enjoys a solid market position as a community-driven project with commercial backing, supported by endorsements from notable technology communities and publications. Technically, the website leverages modern web technologies including React and Docusaurus for documentation, and integrates the Tus protocol for resumable uploads. Hosting and DNS services are provided by Cloudflare, ensuring robust infrastructure. However, the website suffers from a critical security shortfall due to the absence of a valid SSL certificate and HTTPS support, which significantly impacts its security posture. From a security perspective, while the site avoids known SSL vulnerabilities and uses secure protocols in its backend services, the lack of HTTPS and security headers exposes users to potential risks. Privacy compliance is basic, with a privacy policy present but no cookie consent mechanism or GDPR compliance indicators. Contact and incident response information are not publicly available, limiting transparency. Overall, the website demonstrates good content quality, technical sophistication, and business credibility but is hampered by critical security deficiencies. Strategic improvements in SSL deployment, privacy compliance, and contact transparency are recommended to enhance trust and security.

35
43
25
40
90
75
100
fileuploaderjavascriptopensourcecloudstoragefileupload+3 more
JavaScriptReactDocusaurusTus protocol+2

Partner Domains:

transloadit.com
parent65
2025-06-14T20:44:30.230Z
fuertenetwork.com favicon

CACHINA PE E.I.R.L.

fuertenetwork.com

0
Real EstatePerusmallHIGH

Cachina Pe operates as a local Peruvian online marketplace platform focused on classified ads for services, rentals, and sales. The website targets the general public in Peru seeking an easy-to-use platform for posting and browsing ads. The business is small-sized and operates under the legal entity CACHINA PE E.I.R.L., with clear contact information and basic trust indicators such as company registration and privacy policies. Technically, the site is built using modern web technologies including Next.js and React, served via an Nginx server. However, the absence of a valid SSL certificate and HTTPS support significantly undermines the security posture. Performance data is missing, but the site appears to have basic mobile optimization and accessibility features. SEO is basic with proper meta tags but lacks advanced optimization. From a security perspective, the site lacks critical protections such as HTTPS, HSTS, security headers, and domain security configurations like DNSSEC and DMARC. No incident response or vulnerability disclosure policies are present. Privacy compliance is minimal with no cookie consent mechanism detected. Contact information is available but no dedicated security or data protection contacts are found. Overall, the website presents moderate business credibility but suffers from critical security deficiencies that expose users to risks. Strategic improvements in SSL deployment, security headers, and privacy compliance are essential to enhance trust and protect user data.

15
40
17
60
85
75
90
marketplaceclassifiedsrealestateperunextjs
Next.jsReactNginx
2025-06-14T20:35:58.121Z
A

Axel-Bourjau-Stiftung

axel-bourjau-stiftung.de

0
Non-profitGermanysmallHIGH

The Axel-Bourjau-Stiftung website represents a small regional non-profit foundation focused on supporting children and youth work through cultural, educational, and social projects in Büchen, Germany. The foundation was established in 2005 and primarily serves local communities, churches, and schools. The website content is well-structured and provides clear information about the foundation's mission, projects, and history, targeting local stakeholders and potential supporters. Technically, the website uses Bootstrap and jQuery for frontend development and is hosted with GoDaddy services. The site performance is moderate with a page load time of approximately 3.3 seconds and basic mobile responsiveness. However, the site lacks a valid SSL certificate, resulting in no HTTPS support, which significantly impacts security posture and user trust. From a security perspective, the absence of HTTPS, security headers, and cookie consent mechanisms are critical vulnerabilities. No forms or direct contact emails are present on the homepage, limiting direct user engagement. The site does not implement modern security best practices such as HSTS or OCSP stapling. Privacy compliance is minimal, with a privacy policy page present but no cookie consent or GDPR indicators. Overall, the website is functional and informative but requires urgent security improvements, especially enabling HTTPS and implementing privacy compliance features, to enhance trustworthiness and protect user data.

15
18
25
65
100
85
50
non-profitfoundationsocialcultureeducation+1 more
BootstrapjQuery
2025-06-14T20:34:33.642Z
4

403 Forbidden

etosoftwareau.com

0
OtherN/asmallHIGH

The website etosoftwareau.com is currently inaccessible, returning a 403 Forbidden error page with minimal HTML content. This indicates that the site is either restricted or blocked from public access, preventing any meaningful content or metadata extraction. The domain is registered and hosted on Amazon AWS infrastructure, specifically behind an AWS Elastic Load Balancer, but no valid SSL/TLS certificate is configured, resulting in no HTTPS support. Due to the lack of accessible content, no business information, contact details, or privacy and security policies could be identified. From a technical perspective, the site lacks modern security configurations such as HTTPS, security headers, and HSTS, which significantly lowers its security posture. The absence of analytics, marketing tools, or external links further indicates minimal or no active web presence at this URL. The DNS setup is standard with AWS Route53 nameservers, but DNSSEC and CAA records are not enabled, which could be improved for better domain security. Overall, the security posture is weak due to missing SSL and security headers, and the site is effectively blocked from public access, limiting any user or automated interaction. This results in a very low AI score reflecting poor content quality, technical implementation, security, privacy compliance, and business credibility. Strategic recommendations include obtaining and configuring a valid SSL certificate, enabling HTTPS, implementing security headers, and ensuring the site is accessible to users and crawlers to improve trust and compliance.

15
40
17
50
85
85
100
2025-06-14T20:31:11.366Z