Comparison Overview

Sherwood Lumber

VS

Travis Perkins plc

Sherwood Lumber

225 Broadhollow Dr Suite 310W Melville, NY 11757, US
Last Update: 2025-05-03 (UTC)

Strong

Sherwood Lumber is a wholesaler of building materials. We provide customers with value added services, including just- in-time truckloads, mill direct shipment, forward pricing, risk management, technical support and superior handling from company operated facilities. Sherwood Lumber Corporation's family of associates are committed to being the company you prefer to do business with. Our commitment of superior service and quality with the utmost of integrity will gain the trust that is essential to a quality business relationship. We will achieve our goals through our continued appreciation and loyalty of our valued customers, suppliers, community and Sherwood Lumber associates. Our goal is to earn customer relationships by providing outstanding service and superior quality products. Sherwood Lumber only aligns itself with top quality, dependable producers. Our employees are committed, as a team, to exceeding customer expectations. We are committed, as individuals, to being respectful and protective of one another. All Sherwood Lumber associates offer suggestions, seek solutions and are quick to adapt to the ever changing business climate. We are responsive to the demands of our customers and strive to gain a solid understanding of their unique challenges. Sherwood Lumber will continue to meet and exceed the needs of our customers.

NAICS: 4233
NAICS Definition: Lumber and Other Construction Materials Merchant Wholesalers
Employees: 51-200
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Travis Perkins plc

Lodge Way House, Lodge Way, Northampton, Northamptonshire, NN5 7UG, GB
Last Update: 2025-03-05 (UTC)

Excellent

As a leading partner to the construction industry, weโ€™re here to help build better communities and enrich lives and support our customers to build, repair and maintain the many places, buildings and infrastructure that touch all of our lives every day. We have over 20,000 colleagues in the UK and also in France, Belgium and the Netherlands through Toolstation, and we are proud to have helped to build Britain for over 200 years; whether thatโ€™s by building new, or transforming our existing homes into places that people love, and helping to create the infrastructure, schools, hospitals and businesses that everyone deserves. The Group includes some of the leading businesses in the industry, with almost 1,300 locations nationwide, including; Travis Perkins, Toolstation, BSS, Keyline Civils Specialist and CCF. To find out more about working for Travis Perkins plc and to see our latest opportunities visit: www.tpplccareers.co.uk

NAICS: 4233
NAICS Definition: Lumber and Other Construction Materials Merchant Wholesalers
Employees: 12,403
Subsidiaries: 4
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/sherwood-lumber-corp.jpeg
Sherwood Lumber
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/travis-perkins.jpeg
Travis Perkins plc
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
Compliance Summary
Sherwood Lumber
100%
Compliance Rate
0/4 Standards Verified
Travis Perkins plc
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Wholesale Building Materials Industry Average (This Year)

No incidents recorded for Sherwood Lumber in 2025.

Incidents vs Wholesale Building Materials Industry Average (This Year)

No incidents recorded for Travis Perkins plc in 2025.

Incident History โ€” Sherwood Lumber (X = Date, Y = Severity)

Sherwood Lumber cyber incidents detection timeline including parent company and subsidiaries

Incident History โ€” Travis Perkins plc (X = Date, Y = Severity)

Travis Perkins plc cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/sherwood-lumber-corp.jpeg
Sherwood Lumber
Incidents

No Incident

https://images.rankiteo.com/companyimages/travis-perkins.jpeg
Travis Perkins plc
Incidents

No Incident

FAQ

Travis Perkins plc company company demonstrates a stronger AI risk posture compared to Sherwood Lumber company company, reflecting its advanced AI governance and monitoring frameworks.

Historically, Travis Perkins plc company has disclosed a higher number of cyber incidents compared to Sherwood Lumber company.

In the current year, Travis Perkins plc company and Sherwood Lumber company have not reported any cyber incidents.

Neither Travis Perkins plc company nor Sherwood Lumber company has reported experiencing a ransomware attack publicly.

Neither Travis Perkins plc company nor Sherwood Lumber company has reported experiencing a data breach publicly.

Neither Travis Perkins plc company nor Sherwood Lumber company has reported experiencing targeted cyberattacks publicly.

Neither Sherwood Lumber company nor Travis Perkins plc company has reported experiencing or disclosing vulnerabilities publicly.

Travis Perkins plc company has more subsidiaries worldwide compared to Sherwood Lumber company.

Travis Perkins plc company employs more people globally than Sherwood Lumber company, reflecting its scale as a Wholesale Building Materials.

Latest Global CVEs (Not Company-Specific)

Description

Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying their signatures. Both the email verification token login path and the password reset server action use the same validator, which does not check the tokenโ€™s signature, expiration, issuer, or audience. If an attacker learns the victimโ€™s actual user.id, they can craft an arbitrary JWT with an alg: "none" header and use it to authenticate and reset the victimโ€™s password. This issue has been patched in version 4.0.1.

Risk Information
cvss3
Base: 9.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Description

Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events. A malicious website can send forged messages to the embedding page, causing the victimโ€™s browser to execute arbitrary GraphQL queries or mutations against their GraphQL server while authenticated with the victimโ€™s cookies. This issue has been patched in Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3.

Risk Information
cvss3
Base: 8.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Description

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /consulta-dispensas. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of the argument aluno_id causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. It is advisable to upgrade the affected component. The vendor responds: "We have confirmed that the issue mentioned in the report does not exist in the latest releases".

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X