Open
Cached
·
just now
84/100
SECURITY SCORE
Certificate Information
Subject
CN=imperva.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2025 Q3
Valid From
August 06, 2025
Valid Until
February 02, 2026
14 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
36:45:88:A5:7E:62:0D:42:BF:B2:45:0B:A3:1F:30:70:1E:A2:9F:22:DE:1A:13:EC:9C:0A:B8:89:9A:D3:5E:8F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
upgrade-insecure-requests; base-uri; default-src; +9 more
upgrade-insecure-requests; base-uri 'self'; default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.zywave.com https://cdn.jsdelivr.net https://cdn.heapanalytics.com https://heapanalytics.com https://unpkg.com https://identity.netlify.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://heapanalytics.com; img-src 'self' https://heapanalytics.com https://avatars.githubusercontent.com; object-src 'self'; connect-src 'self' https://heapanalytics.com https://*.algolia.net https://*.algolianet.com https://*.algolia.io data: https://api.github.com; worker-src 'none'; child-src 'self'; frame-ancestors 'none'; font-src 'self' https://heapanalytics.com;
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
accelerometer=(), autoplay=(), browsing-topics=(), camera=(), display-capture=(), document-domain=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(self), usb=(), web-share=(), xr-spatial-tracking=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
68 domains
*.zywave.com
*.onzywave.com
*.portal.zywave.com
accountportal.net
*.accountportal.net
accuagency.com
*.accuagency.com
advisen.com
*.advisen.com
*.agencymatrix.com
brokeragebuilder.com
*.brokeragebuilder.com
clientportalonline.com
*.clientportalonline.com
codesixfour.com
*.codesixfour.com
dmwarehouse.com
*.dmwarehouse.com
*.getitc.com
hr360.com
*.hr360.com
hrbasicsonline.com
*.hrbasicsonline.com
hrconnection.com
*.hrconnection.com
imperva.com
inscontact.com
*.inscontact.com
*.insurancewebsitebuilder.com
itccarrierrates.com
*.itccarrierrates.com
itcdataservices.com
*.itcdataservices.com
itcratingservices.com
*.itcratingservices.com
iwantinsurance.com
*.iwantinsurance.com
*.quotes.iwantinsurance.com
miedge.biz
*.miedge.biz
miedge.net
*.miedge.net
modmaster.com
*.modmaster.com
myinsportal.com
*.myinsportal.com
mywaveelements.com
*.mywaveelements.com
*.onzywave.co.uk
partnerxe.com
*.partnerxe.com
*.portal.partnerxe.com
*.sisportal-dev.partnerxe.com
*.sisportal-prod.partnerxe.com
*.sisportal-qa.partnerxe.com
planadvisor.com
*.planadvisor.com
plandocbuilder.com
*.plandocbuilder.com
*.proposal.insure
ratefactory.com
*.ratefactory.com
secureclient.net
*.secureclient.net
turborater.com
*.turborater.com
*.wrap360.com
*.zywave.co.uk
Other domains in certificate