
Is muzeum-km.cz Safe? Security Analysis for Muzeum Kroměřížska, p. o.
Check if muzeum-km.cz is a scam or legitimate. Free security scan and reviews.

AI Summary
Muzeum Kroměřížska is a regional cultural and educational institution located in Kroměříž, Czech Republic. Founded in 1933 and operated as a contributory organization of the Zlínský kraj since 2003, it offers a variety of permanent and temporary exhibitions, educational programs, and cultural events. The museum manages extensive collections including works by the notable Czech artist Max Švabinský and serves a broad audience including schools and the general public. The website reflects a well-established institution with a clear mission and strong regional ties. Technically, the website employs modern JavaScript libraries such as jQuery, bxSlider, and FancyBox, alongside Google services for analytics and security (reCAPTCHA). The site is mobile-optimized, accessible, and SEO-friendly with proper metadata and social media integration. Cookie consent and privacy policies are implemented in compliance with GDPR, enhancing user trust and legal compliance. From a security perspective, the site uses HTTPS with good SSL configuration and includes protections such as reCAPTCHA on forms. However, explicit security headers like Content-Security-Policy and X-Frame-Options are not detected, and no public security or incident response policies are published. No vulnerabilities or exposed sensitive data were found in the HTML content. Overall, the security posture is solid but could be improved with additional headers and transparency. The website is fully accessible without any WAF or blocking mechanisms, indicating good availability. Contact information is clearly provided, including emails, phone number, and physical address, along with active social media profiles. The domain WHOIS data aligns well with the museum's identity and history, supporting legitimacy and trustworthiness. Strategic recommendations include enhancing security headers, publishing incident response contacts, and maintaining regular security audits to sustain and improve the security posture.
Detected Technologies
🧠AI Business Intelligence
Technology stack, business insights, and market analysis powered by AI.
Business Intelligence
Market & Strategic Analysis
Muzeum Kroměřížska operates as a government-affiliated non-profit cultural institution serving the Zlínský kraj region. Its competitive advantage lies in its historical significance, extensive collections, and educational outreach. Revenue streams likely include government funding, event hosting, and educational program fees. The target customer segments include local residents, tourists, schools, and cultural enthusiasts. The museum maintains a broad partnership ecosystem with regional government bodies, cultural organizations, and educational institutions, as evidenced by partner logos and external links. The website's content and structure reflect a mature operation with a focus on accessibility and user engagement, supporting growth and community presence.
Extracted Contact Information
Marketing Intelligence Data
Email Addresses (2)
Phone Numbers (1)
Physical Addresses (1)
Security Posture Analysis
Comprehensive Security Assessment
The website demonstrates a moderate to high security maturity level with HTTPS enforced and Google reCAPTCHA protecting forms. The absence of explicit security headers such as Content-Security-Policy and X-Frame-Options represents a gap that could expose the site to clickjacking or content injection risks. No incident response or security policy pages were found, indicating a potential compliance gap. Data protection practices are evident through GDPR-compliant privacy and cookie policies. No vulnerabilities or sensitive data exposures were detected in the HTML. Incident response readiness and security culture indicators are not publicly visible, suggesting room for improvement in transparency and preparedness. Overall, the security posture is adequate for the institution's risk profile but would benefit from enhanced headers and published policies.
Strategic Recommendations
Priority Actions for Security Improvement
Implement and enforce security headers including Content-Security-Policy, X-Frame-Options, and X-Content-Type-Options to mitigate common web attacks.
✨Observations
AI-powered comprehensive website and business analysis.
AI-Enhanced Website Analysis
Business Insights
Muzeum Kroměřížska, p. o.
Muzeum na Velkém náměstí v Kroměříži nabízí celoroční návštěvy stálých expozic, krátkodobých výstav, tvořivých dílen, programů pro školní děti a mládež, přednášek a konferencí. Muzeum bylo založeno v roce 1933 a je příspěvkovou organizací Zlínského kraje od roku 2003. Odborně spravuje rozsáhlé sbírky včetně díla Maxe Švabinského a má edukační oddělení pro školy a veřejnost.
excellent
consistent
Technical Stack
moderate
good
good
good
Security Assessment
- HTTPS enforced
- Cookie consent mechanism implemented
- Google reCAPTCHA for form protection
- No exposed sensitive data in HTML
Analytics & Tracking
Advertising & Marketing
Website Quality Assessment
Key Observations
Website is fully accessible with no blocking or WAF challenges.
🛡️Security Headers
HTTP security headers analysis and recommendations.
Security Headers
HTTP security headers analysis
Missing Strict-Transport-Security header
HIGHForces HTTPS connections
Missing X-Frame-Options header
HIGHPrevents clickjacking attacks
Missing X-Content-Type-Options header
MEDIUMPrevents MIME type sniffing
Missing Content-Security-Policy header
HIGHControls resources the browser is allowed to load
Missing X-XSS-Protection header
MEDIUMLegacy XSS protection (deprecated but still recommended)
Missing Referrer-Policy header
LOWControls referrer information sent with requests
Missing Permissions-Policy header
MEDIUMControls browser features and APIs
Sensitive data may be cached
LOWCache-Control header should include "no-store" for sensitive pages
👤GDPR Compliance
Privacy and data protection assessment under GDPR regulations.
GDPR Compliance
Privacy and data protection assessment
No Data Protection Officer mentioned
LOWLarge organizations may need to designate a DPO under GDPR
Privacy policy may not be GDPR compliant
MEDIUMPrivacy policy lacks explicit GDPR compliance elements
GDPR Compliance Analysis
🛡️NIS2 Compliance
Network & Information Security Directive compliance assessment.
NIS2 Compliance
Network & Information Security Directive
No information security framework found
HIGHNIS2 requires documented cybersecurity and information security measures
No vulnerability disclosure policy
MEDIUMNIS2 encourages coordinated vulnerability disclosure
No security policy documentation found
HIGHNIS2 requires documented cybersecurity governance and risk management
No incident response procedures found
HIGHNIS2 requires documented incident response and business continuity plans
No business continuity planning found
MEDIUMNIS2 emphasizes operational resilience and business continuity
No security contact information
HIGHNIS2 requires clear incident reporting channels
No vulnerability reporting mechanism
MEDIUMClear vulnerability reporting supports coordinated disclosure
No NIS2 reference found
LOWConsider explicitly mentioning NIS2 compliance efforts
📧Email Security
SPF, DKIM, and DMARC validation and email security assessment.
Email Security
SPF, DKIM, and DMARC validation
DMARC not enforcing
MEDIUMDMARC policy is set to "none"
No DMARC reporting
LOWDMARC aggregate reports not configured
No DKIM record found
MEDIUMDKIM adds cryptographic signatures to emails
No BIMI Record
LOWBIMI displays brand logos in email clients
No MTA-STS Policy
MEDIUMMTA-STS enforces TLS for email delivery
No TLS-RPT Record
LOWTLS-RPT provides reporting for email TLS issues
SPF Details
DMARC Details
🏆SSL/TLS Security
Certificate validity and encryption analysis.
SSL/TLS Security
Certificate validity and encryption analysis
SSL Certificate Expires Within 90 Days
MEDIUMSSL certificate expires in 74 days
Partial SSL/TLS Assessment
LOWCompleted 2 of 4 security checks due to time constraints
Certificate Details
OCSP Status
📊DNS Health
DNS configuration and security assessment.
DNS Health
DNS configuration and security assessment
DNSSEC Not Enabled
MEDIUMDNSSEC is not configured for this domain
CAA Records Not Configured
LOWCertificate Authority Authorization (CAA) records not found
DMARC Policy Set to None
LOWDMARC is configured but not enforcing any policy
Domain Registration Details
DNS Records
DNSSEC Status
DNS Performance
SPF Analysis
⚡Network Security
Port scanning and network exposure analysis.
Network Security
Port scanning and network exposure analysis
High-Risk Service Exposed: FTP
HIGHPort 21 (FTP) is publicly accessible - FTP - Often unencrypted file transfer
Service Exposed: SSH
MEDIUMPort 22 (SSH) is publicly accessible - SSH - Secure but can be brute-forced
🔧Technical Analysis
Detailed technical findings and analysis from AI assessment.
Technical Analysis
Comprehensive security assessment findings