Skip to main content

Is novyvyskov.cz a Scam? Security Check Results - Městský úřad Vyškov Reviews

novyvyskov.cz favicon

Is novyvyskov.cz Safe? Security Analysis for Městský úřad Vyškov

Check if novyvyskov.cz is a scam or legitimate. Free security scan and reviews.

GovernmentCzech Republicmedium
Webflow CMSGoogle Maps APILeaflet.jsNo Code Flow Dynamic MapjQuery 3.5.1+2 more
Analyzed 8/1/2025Completed 10:14:37 AM
59
Security Score
MEDIUM RISK

AI Summary

The website www.novyvyskov.cz serves as an official municipal information portal for the city of Vyškov in the Czech Republic, focusing on urban development projects, particularly related to the modernization of the railway and associated construction initiatives. It provides residents and stakeholders with detailed project information, news updates, and contact channels to engage with city officials. The site is well-branded with official municipal logos and partners, indicating a credible government-backed initiative. Technically, the site is built on the Webflow platform, leveraging modern web technologies including Google Fonts, Google Maps API, Leaflet.js, and integrates Google Analytics for visitor tracking. The site is mobile optimized and features cookie consent mechanisms compliant with GDPR. However, a dynamic map component displays an invalid license error, suggesting incomplete configuration. No major technical vulnerabilities were detected, but security headers are absent, and no explicit security or incident response policies are published. From a security perspective, the site enforces HTTPS and uses secure forms with required fields, but lacks detailed security policies and incident response contacts. The absence of WHOIS data for the domain raises concerns about domain registration legitimacy, although the official nature of the content and branding mitigates some risk. Overall, the site demonstrates a moderate security posture with room for improvement in transparency and technical hardening. Strategically, the site effectively supports the city’s communication goals for urban development projects but should address the WHOIS registration gap, fix the dynamic map licensing issue, and enhance security headers and policy disclosures to improve trust and compliance.

Detected Technologies

Webflow CMSGoogle Maps APILeaflet.jsNo Code Flow Dynamic MapjQuery 3.5.1Google Tag Manager (gtag.js)Finsweet Cookie Consent

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

The website positions itself as a key communication channel for the Vyškov municipal government, focusing on urban planning and infrastructure modernization. Its competitive advantage lies in being the official source of information for a major state investment project in railway modernization and urban renewal. The business model is informational and public service oriented, targeting local residents, investors, and stakeholders interested in city development. Revenue streams are not applicable as it is a government portal. The partnership ecosystem includes architectural and engineering firms, enhancing project credibility. Growth indicators include ongoing and planned construction projects with state funding. The site’s operations reflect a strategic focus on transparency and citizen engagement in urban development.

Extracted Contact Information

Marketing Intelligence Data

Security Posture Analysis

Comprehensive Security Assessment

The security maturity of the website is moderate. HTTPS is enforced, and cookie consent mechanisms are implemented with opt-in features, supporting GDPR compliance. However, the absence of security headers such as Content-Security-Policy and X-Frame-Options reduces protection against common web attacks. No incident response or security policy information is published, limiting transparency and preparedness. The invalid license error on the dynamic map component indicates a configuration oversight but does not pose a direct security threat. No exposed sensitive data or vulnerable libraries were detected. Overall, the site would benefit from enhanced security controls and policy disclosures to strengthen its security posture.

Strategic Recommendations

Priority Actions for Security Improvement

1

Implement and configure standard security headers including Content-Security-Policy, X-Frame-Options, and X-XSS-Protection.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

Městský úřad Vyškov

Description:

Informational website providing details about planned construction, investments, and urban development projects in Vyškov, Czech Republic, driven by state investment in railway modernization.

Key Services:
Information dissemination about urban projectsContact and inquiry formsNews and updates on city development
Content Quality:

good

Branding:

consistent

Technical Stack

Technologies:
Webflow CMSGoogle Maps APILeaflet.jsNo Code Flow Dynamic MapjQuery 3.5.1Google Tag Manager (gtag.js)Finsweet Cookie Consent
Frameworks:
Webflow
Platforms:
Webflow Hosting
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

good

Security Assessment

Security Score:
75/100
Best Practices:
  • HTTPS enforced
  • Cookie consent with opt-in mechanism
  • No exposed sensitive data in HTML
  • Secure contact forms with required fields

Analytics & Tracking

Services:
Google Analytics
Tracking Level:moderate
Privacy Compliance:good

Advertising & Marketing

Tracking Pixels:
Google Analytics (gtag.js)
Marketing Tools:
Finsweet Cookie Consent
Transparency Level:good

Website Quality Assessment

Design Quality:good
User Experience:good
Content Relevance:good
Navigation Clarity:good
Professionalism:good
Trustworthiness:high

Key Observations

1

Website is an official municipal information portal for Vyškov urban development projects.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

60/100
Score

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing X-XSS-Protection header

MEDIUM

Legacy XSS protection (deprecated but still recommended)

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

25/100
Score

No Privacy Policy found

HIGH

GDPR requires a clear and accessible privacy policy

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

EU business without adequate privacy measures

CRITICAL

EU businesses are subject to strict GDPR requirements

Third-party services without privacy policy

HIGH

Detected services: Google Analytics, Facebook, Google APIs

GDPR Compliance Analysis

Privacy Policy0% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
emailphone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

17/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

55/100
Score

DMARC not enforcing

MEDIUM

DMARC policy is set to "none"

No DMARC reporting

LOW

DMARC aggregate reports not configured

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
SPF Details
Record:
v=spf1 a mx include:_spf.webglobe.cz -all
DNS Lookups:3/10
Policy:-all
DMARC Details
Policy:none

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

57/100
Score

Weak Protocols Supported

HIGH

Server supports weak protocols: TLSv1.1

Certificate Transparency Not Implemented

LOW

Certificate is not logged in Certificate Transparency logs

SSL Certificate Expires Within 90 Days

MEDIUM

SSL certificate expires in 69 days

Weak SSL Key Length

HIGH

SSL certificate uses 256-bit key, which is considered weak

Partial SSL/TLS Assessment

LOW

Completed 3 of 4 security checks due to time constraints

Protocol Support

TLSv1.3TLSv1.2TLSv1.1

OCSP Status

OCSP Stapling Enabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

80/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

DMARC Policy Set to None

LOW

DMARC is configured but not enforcing any policy

Domain Registration Details

Domain Age
2 years(established)

DNS Records

A Records:75.2.70.75, 99.83.190.102
Name Servers:
ns1.webglobe.czDNS only
ns2.webglobe.czDNS only
ns3.webglobe.com
MX Records:
10: email.webglobe.cz
10: email4.webglobe.cz
10: email2.webglobe.cz
10: email3.webglobe.cz
SOA:Serial: 2025072701, TTL: 3600s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:162ms

SPF Analysis

SPF Record:
v=spf1 a mx include:_spf.webglobe.cz -all

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website is built on the Webflow CMS platform, utilizing modern front-end technologies such as Google Fonts and Leaflet.js for mapping. It integrates Google Maps API and Google Tag Manager for analytics and tracking. Hosting is provided by Webflow’s CDN infrastructure, ensuring reliable delivery. Performance is moderate with good mobile optimization and SEO practices including meta tags and Open Graph data. The site uses jQuery 3.5.1 and includes a cookie consent solution from Finsweet. Technical debt is minimal but the invalid license error for the dynamic map indicates a need for configuration review. Opportunities exist to improve security headers and accessibility compliance to reduce technical risks.
Analyze Another Website