Skip to main content

Is who.int a Scam? Security Check Results - World Health Organization Reviews

who.int favicon

Is who.int Safe? Security Analysis for World Health Organization

Check if who.int is a scam or legitimate. Free security scan and reviews.

HealthcareN/aenterprise
JavaScriptGoogle AnalyticsMicrosoft ASP.NET (ScriptResource.axd)Fundraise Up widgetFontAwesome+2 more
Analyzed 9/7/2025Completed 9:21:29 AM
73
Security Score
MEDIUM RISK

AI Summary

The World Health Organization (WHO) is a globally recognized United Nations agency dedicated to promoting health, ensuring safety, and serving vulnerable populations worldwide. The website serves as a comprehensive portal for health topics, emergencies, data, and organizational information, targeting a broad international audience. WHO holds a leadership position in global public health, providing authoritative guidance and data to governments and health professionals. The site is well-branded, multilingual, and professionally maintained, reflecting WHO's stature and mission. Technically, the website employs a mature infrastructure using ASP.NET CMS (Sitefinity), modern JavaScript libraries, and integrates analytics and fundraising tools. The site is mobile-optimized, accessible, and SEO-friendly, with good performance metrics. Hosting appears to be managed by WHO or UN infrastructure with CDN support for global delivery. From a security perspective, the site enforces HTTPS, employs standard security headers, and integrates cookie consent mechanisms aligned with GDPR. No critical vulnerabilities or exposed sensitive data were detected. However, explicit vulnerability disclosure and incident response contacts are not publicly available, which could be improved to enhance transparency. Overall, the WHO website demonstrates a high level of professionalism, security, and compliance suitable for an international health authority. Strategic recommendations include publishing a vulnerability disclosure policy, providing dedicated security contact channels, and enhancing transparency on security certifications to further strengthen trust and security posture.

Detected Technologies

JavaScriptGoogle AnalyticsMicrosoft ASP.NET (ScriptResource.axd)Fundraise Up widgetFontAwesomeGoogle FontsKendo UI

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

WHO operates as a non-profit international organization with a mandate to lead global health efforts. Its market positioning is unique as the authoritative source for health standards and emergency responses worldwide. Revenue streams primarily come from member state contributions and donations, supported by fundraising efforts visible on the site. The target audience includes governments, health professionals, researchers, and the general public globally. WHO maintains a strong partnership ecosystem with regional offices and health bodies such as PAHO and AFRO. The website reflects WHO's operational scale and global reach, supporting its mission through extensive content and data dissemination.

Extracted Contact Information

Marketing Intelligence Data

Email Addresses (2)

i*****@who.int
w*****@who.int

Phone Numbers (1)

+4122791****

Security Posture Analysis

Comprehensive Security Assessment

The WHO website exhibits a mature security posture with enforced HTTPS, comprehensive security headers, and privacy compliance mechanisms. The use of cookie consent and GDPR-aligned privacy policies indicates attention to data protection. No critical security flaws or vulnerabilities were identified in the public content. The absence of a public vulnerability disclosure policy and incident response contacts is a minor gap. Overall, WHO demonstrates a strong security culture appropriate for a global health authority, though transparency in security processes could be enhanced.

Strategic Recommendations

Priority Actions for Security Improvement

1

Publish a formal vulnerability disclosure policy and security.txt file to encourage responsible reporting.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

World Health Organization

Description:

The United Nations agency working to promote health, keep the world safe and serve the vulnerable.

Key Services:
Health promotionHealth emergencies responseHealth data and statisticsPolicy advocacyTechnical guidance
Content Quality:

excellent

Branding:

consistent

Technical Stack

Technologies:
JavaScriptGoogle AnalyticsMicrosoft ASP.NET (ScriptResource.axd)Fundraise Up widgetFontAwesomeGoogle FontsKendo UI
Frameworks:
ASP.NET
Performance:

moderate

Mobile:

good

Accessibility:

good

SEO:

good

Security Assessment

Security Score:
90/100
Best Practices:
  • HTTPS enforced
  • Cookie consent mechanism
  • No exposed sensitive data in HTML
  • Use of security headers

Analytics & Tracking

Services:
Google AnalyticsMicrosoft Clarity
Tracking Level:moderate
Privacy Compliance:good

Advertising & Marketing

Tracking Pixels:
Microsoft ClarityFundraise Up
Marketing Tools:
Fundraise Up
Transparency Level:good

Website Quality Assessment

Design Quality:excellent
User Experience:excellent
Content Relevance:excellent
Navigation Clarity:excellent
Professionalism:excellent
Trustworthiness:high

Key Observations

1

Website is official WHO site with comprehensive health information.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

80/100
Score

Weak Referrer-Policy configuration

LOW

Current value: "no-referrer-when-downgrade"

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

53/100
Score

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

No Data Protection Officer mentioned

LOW

Large organizations may need to designate a DPO under GDPR

Privacy policy may not be GDPR compliant

MEDIUM

Privacy policy lacks explicit GDPR compliance elements

GDPR Compliance Analysis

Privacy Policy85% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
phone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

47/100
Score

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

85/100
Score

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
SPF Details
Record:
v=spf1 ip4:158.232.12.0/24 include:spf.protection.outlook.com include:_spfincludes.who.int -all
DNS Lookups:2/10
Policy:-all
DKIM Selectors Found
Selector:selector1(1296-bit rsa)
DMARC Details
Policy:reject
Aggregate Reports:422b6d07@inbox.ondmarc.com

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

47/100
Score

Weak Protocols Supported

HIGH

Server supports weak protocols: TLSv1.1

Certificate Transparency Not Implemented

LOW

Certificate is not logged in Certificate Transparency logs

SSL Certificate Expires Within 90 Days

MEDIUM

SSL certificate expires in 63 days

Weak SSL Key Length

HIGH

SSL certificate uses 256-bit key, which is considered weak

Mixed Content Detected

MEDIUM

2 resources loaded over insecure HTTP

Partial SSL/TLS Assessment

LOW

Completed 3 of 4 security checks due to time constraints

Protocol Support

TLSv1.3TLSv1.2TLSv1.1

OCSP Status

OCSP Stapling Enabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

85/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

Domain Registration Details

Domain Age
27 years(mature)

DNS Records

A Records:192.133.11.1
Name Servers:
ext-dns-2.cern.chDNS only
ns1.wpro.who.intDNS only
whqdns1.who.intDNS only
whqdns2.who.intDNS only
whqdns3.who.intDNS only
MX Records:
10: who-int.mail.protection.outlook.com
SOA:Serial: 2025090200, TTL: 10800s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:71ms

SPF Analysis

SPF Record:
v=spf1 ip4:158.232.12.0/24 include:spf.protection.outlook.com include:_spfincludes.who.int -all

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The WHO website is built on a robust ASP.NET CMS platform (likely Sitefinity), leveraging modern JavaScript libraries such as FontAwesome and Kendo UI for UI components. It integrates analytics tools including Google Analytics and Microsoft Clarity, and uses Fundraise Up for online donations. The site is globally distributed via CDN, ensuring performance and availability. Mobile responsiveness and accessibility features are well implemented. The technical stack is mature and well-maintained, with opportunities to further modernize by adopting newer frontend frameworks or enhancing API-driven content delivery.
Analyze Another Website