Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.mantzarisfisheries.com.au
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 17, 2025
Valid Until
March 17, 2026
65 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7B:44:71:33:FB:69:25:0C:75:A6:80:D1:56:C3:D7:36:CD:AE:55:7C:05:85:D5:85:6D:9A:B6:D4:F6:2F:CA:D0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
aayushsoft.com
2twt2.com.mx
links-dev.3dmeet.com
3oh6.com
aaronbell.co.uk
abadi-motor.com
www.abusrestaurant.co.uk
agamaengenharia.com.br
www.aiyushjain.ca
www.aktekniikka.fi
cms.al-kaser.com
ferraduraturismo.appshare.com.br
www.attainr.com
devglomocontinuity.bbva.com.ar
www.beutelracker.de
www.buycasino.net
resident.buysell-technologies.com
byobutler.com
www.cavallaro.rsvp
custom.clevateam.io
arena.code101.in
share.coolplay.io
staging.share.food.cururucu.jp
www.cyborg-it.de
www.damatoelectricidad.com
www.darklingq8.com
delvalscottishdance.org
diety.de
digiweaver.co.uk
dlombasegglvodralb.de
double5th.com
duizendstra.com
ecopay.ecosystem.co.uk
www.eith.cz
pre-backoffice.eldiarioar.com
www.eleentech.ly
www.rocket.eurodycar.com.ar
pptool.exagensolutions.com
exalt-tech.com
jdpb.exodusadmin.work
ezgiler.net
www.fairylullaby.com.au
fastlinecomputers.com
feedok.com
www.fitmas.mx
topup-wallet-test.flexm.com
www.forsvarer.no
gwiztreasurehunts.co.uk
controls.hitechfreak.com
portfolio.httky.com
imagiantionapps.xyz
influenker.online
iomicsanalysis.com
www.ishaper.surf
test.jacksonic.net
old.kitadake.net
www.kristoflemp.de
ladypower.online
lifebuckets.ca
www.mantzarisfisheries.com.au
microcashpay.in
link.miloto.com
app.mindbites.io
moongoldprod.com
vc-coverages.mrvillage.dev
social.myentourages.com
myfirstmillion.quest
admin.mytownrocks.co.uk
reo-museum.oshio.co
osulhf.org
www.outlooknews.org
app-cos.overview.one
www.ozcelikgeridonusum.com
app.dev.panda-cloud.co.uk
www.app.parkcenterlounge.com
performartech.com.br
marketing.primehealth.one
prochac.cz
rocketpen.site
app.rootid.io
connect-ng-asset-management.rxoconnectuat.rxo.com
hub-staging.s6.io
wellness.saayahealther.com
chat.secretcode.kr
auth.google.servcomplay.com.br
app.singjamei360.com
sintheta.in
central.speedycon.com
www.sphverse.org
www.tasitdefteri.com
testndev.com
www.texaskidsnutrition.org
thewatotoacademy.org
www.tlaciva-online.sk
www.vahebi.se
veganbuddy.site
meu.vendergas.com.br
pharm.vicharas.net
www.you2you.co
youhelpme.fr
Other domains in certificate