77/100 SECURITY SCORE

Certificate Information

Subject
CN=alanmachado.com.br
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 27, 2025
Valid Until
December 26, 2025 45 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:1E:C9:E8:B0:4F:4D:A2:DB:B4:4E:57:94:75:67:50:D7:E4:F9:5C:BF:A0:B2:E3:4E:98:EA:DE:3F:7E:F1:86
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
admin.truthtotable.com

Other domains in certificate

102306479.com
3kyu.net
vania-run-thru.aisessment.com
alamedaprovence.com
alanmachado.com.br
alexandregerez.com
anjb.pt
avplumbingandgas.com
www.bakemyapps.com
jacob.beckstead.net
www.dashboard.benchmarkprotocol.finance
stronger.song.benhaim.app
app.bintech.in
www.bobertquail.com
bolt-auto.com
mcs.my.brinno.com
francesco.brozzu.xyz
report.uprightpose.bycopilot.com
city-ol.ch
virtuousvision.co.in
codereis.com
teamtalk.communitas.app
bio.danikarine.com
deltacalendar.com
demsvote.us
www.diceeestudio.com
dieselgrid.com
dreamlightguide.app
www.echovalleyevents.com
egedenfoods.com
ellataxi.site
envivo.space
geobuitrago.dev
app-test.getrecustom.com
glassapp.us
goodvibes-studio.com.au
hcadvisors.com.au
www.innung.app
www.jitendra-kumar.com
app.joesandcos.com
www.jomotransportation.com
www.kkarchdes.com
kpatravels.in www.kpatravels.in
docs.launchpad.games
v1.llamafood.com
mascara.m1studio.co
www.magicmotionmedia.in
www.mateosma.com
mellowcards.com
miracl.org
www.mjusmanict.com
backend.mkbl.dk
myfamilyboard.com
chat2023.niceinfos.com
novaagricola.pt
www.novacodellc.com
www.obkoni.com
auth.oddstrader.com
api.onroad.app
orobinario.com
www.owenpropertyholdings.co.uk
park-street-manor-apartments.com
www.photoshade.app
consumer.pinhome.id
www.piscatorlab.com
privacyguard.cc
www.pulcer.net
react-native.shop
www.rhimtec.com
rugbyexplained.co.uk
www.rvspotminder.com
saar.date
races.sampsoid.com
sarosmgmt.com
www.shortercut.app
www.simplementeyoga.org
www.softfortoday.com
www.spacedev.cc
spaceimagined.com
statelineinsurance.net
surtiplataformas.com
tanktactics.net
dev-admin.tecnoaircoldcr.com
tgitconsulting.com.au
quickreco.thepetdoor.net.au
thnkzy.me
tke.us
www.travisyatsko.com
troop30lr.org
www.tubeflix.com
console.tucar.dev
murph.turnosweb.app
share.uaeproleague.ae
unitoro.tech
verificaenmorelos.mx
watafan.com
webknot.in
ekyc.yourcanvas.co