Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=api.dev.upnext.in
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 11, 2025
Valid Until
March 11, 2026
87 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
75:AA:AD:42:3F:CF:01:5A:84:E3:37:6A:8E:AC:0E:2D:60:AA:DE:8A:C7:C9:68:CE:F3:A6:64:25:90:B0:FF:DA
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
aimemestore.com
1scor.com
crm.airlift.app
www.anismarian.com
www.arredamentivalgandino.it
s.autoverify.ca
links.blendnow.com
entrerios.bracelit.es
brisstudio.no
burningidealabs.com
chaseschweitzer.me
cimrdr.com
www.cleir.app
cobinno.com
kahut.coders-x.com
colemancodes.com
consultorplansaude.com.br
www.contra.chat
www.copy.pics
daiylu.com
www.dandelichalet.com
web-sporter-frontend.staging.rug.delcom.nl
projects.developersden.in
devy.ch
play.dkatta.com
q1-international.dpd.co.uk
www.ecoluxclean.in
eflatunyazilim.com
elite-vtc.fr
www.espertoo.com
fastprosbayarea.com
www.firststreet.io
gorillasports.kr
www.gorillasports.kr
clicks.grevling.dev
app.guardian-agents.com
app-dev.hellodibsly.com
innovakemet.com
www.intervalrecognition.com
ipatlantawest.org
chefsguide.irinoxprofessional.com
itclic.de
ivapp.co
joppy.me
jtburgess.com
kada.live
kenailabs.com
kindredhug.com
www.kindredhug.com
kinkychicks69.com
kiotobcn.com
app-contabilidad.ledmon.com
www.leecon.de
llmac.co
i.m69r.com
magneinvestments.ch
maisguyana.com
marcossperoni.com
marcossperoni.tech
www.midlandautosales.co.uk
mtg-tradingpost.com
myrcolcleaning.ca
naoken-naiso.com
nofinancial.com.au
www.nothingserious.au
nuwana.ai
www.ok-noted.com
our-deployment.com
www.palladiumbau.com
www.poolpep.net
pooping.co
admin-panel-dev13.qlub.cloud
vendor-dev13.qlub.cloud
aprovei.quitaboletos.com.br
staging-student.rlabsu.org
ruanthai.fr
app.scanafy.de
www.schmetterlingschule.de
platform.segna.io
www.kanbanfire.segnet.us
siraaj.uk
studio.soulcode.com
sportstracker.app
www.caballito.sushi2x1.com.ar
www.swapple.gg
tastethemetawurst.xyz
blog.tbun.dev
www.theessenceworld.com
www.thehappytherapist.com.au
www.ticketlink.com.br
estabelecimentos.togoweb.com.br
www.tridenthse.co.uk
sumup.tuteeapp.com
api.dev.upnext.in
vdmdd.com
virtual.versemedia.io
www.webdevelopland.com
www.xvend.au
www.yashashomestay.com
admin.ytsv.vn
Other domains in certificate