Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=alanmachado.com.br
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 27, 2025
Valid Until
December 26, 2025
45 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:1E:C9:E8:B0:4F:4D:A2:DB:B4:4E:57:94:75:67:50:D7:E4:F9:5C:BF:A0:B2:E3:4E:98:EA:DE:3F:7E:F1:86
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
admin.truthtotable.com
102306479.com
3kyu.net
vania-run-thru.aisessment.com
alamedaprovence.com
alanmachado.com.br
alexandregerez.com
anjb.pt
avplumbingandgas.com
www.bakemyapps.com
jacob.beckstead.net
www.dashboard.benchmarkprotocol.finance
stronger.song.benhaim.app
app.bintech.in
www.bobertquail.com
bolt-auto.com
mcs.my.brinno.com
francesco.brozzu.xyz
report.uprightpose.bycopilot.com
city-ol.ch
virtuousvision.co.in
codereis.com
teamtalk.communitas.app
bio.danikarine.com
deltacalendar.com
demsvote.us
www.diceeestudio.com
dieselgrid.com
dreamlightguide.app
www.echovalleyevents.com
egedenfoods.com
ellataxi.site
envivo.space
geobuitrago.dev
app-test.getrecustom.com
glassapp.us
goodvibes-studio.com.au
hcadvisors.com.au
www.innung.app
www.jitendra-kumar.com
app.joesandcos.com
www.jomotransportation.com
www.kkarchdes.com
kpatravels.in
www.kpatravels.in
docs.launchpad.games
v1.llamafood.com
mascara.m1studio.co
www.magicmotionmedia.in
www.mateosma.com
mellowcards.com
miracl.org
www.mjusmanict.com
backend.mkbl.dk
myfamilyboard.com
chat2023.niceinfos.com
novaagricola.pt
www.novacodellc.com
www.obkoni.com
auth.oddstrader.com
api.onroad.app
orobinario.com
www.owenpropertyholdings.co.uk
park-street-manor-apartments.com
www.photoshade.app
consumer.pinhome.id
www.piscatorlab.com
privacyguard.cc
www.pulcer.net
react-native.shop
www.rhimtec.com
rugbyexplained.co.uk
www.rvspotminder.com
saar.date
races.sampsoid.com
sarosmgmt.com
www.shortercut.app
www.simplementeyoga.org
www.softfortoday.com
www.spacedev.cc
spaceimagined.com
statelineinsurance.net
surtiplataformas.com
tanktactics.net
dev-admin.tecnoaircoldcr.com
tgitconsulting.com.au
quickreco.thepetdoor.net.au
thnkzy.me
tke.us
www.travisyatsko.com
troop30lr.org
www.tubeflix.com
console.tucar.dev
murph.turnosweb.app
share.uaeproleague.ae
unitoro.tech
verificaenmorelos.mx
watafan.com
webknot.in
ekyc.yourcanvas.co
Other domains in certificate