Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=facturacionrecepcion.primeraplus.com.mx
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 09, 2025
Valid Until
January 07, 2026
56 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
35:BE:79:98:58:E6:3F:54:13:F0:69:12:D8:A4:D1:5B:3C:9D:3C:49:B9:9C:5F:37:B2:0C:4B:D6:36:43:88:B2
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
app.brinkanalytics.com
jointhefun.1agbn.org
pokemoncardshipping.alexisgommet.com
alfredo.run
truth.or.dare.dirty.androbrain.com
www.ansync.com
oticasdinizb2b.appshare.com.br
atorsy.jp
ngspeamchikanadmin.auxswot.com
www.axisroot.info
app.bookaclub.com
www.bootspruefung.info
admin.cargamos.com
www.celebratingjulia.com
centrorivadavia.com.ar
www.clovis-sanceo.com
vrotech.co.in
comado.app
link.conexaopolitica.com.br
confiction.org
www.coview.com
crescentflare.com
www.danielbreault.com
www.dataharbour.com.au
www.dclix.tn
dhh.co.jp
digitalservo.jp
dash.ambulance.dma.works
time.staging.dspdesign.pro
dev.elearncert.com
www.familydsoftware.com
hammer.partner.felporgetve.hu
fixily.net
www.fodmapchecker.com
funner.com
geodistance.com
app.getcarbon.ai
docs.enterprise-wallet.ginco.co.jp
cms.globalcyd.com
goondae.com
www.gorillasports.ae
admin.hamptoncollege.cl
hananba.jp
www.hansoopad.com
cdn.haulex.com
hello-pizza.ma
matkhau.hocchoi.com
stage.iact.com
canvas.inspirnathan.com
institutosetas.com
www.iprslab.it
react1.joetlobb.com
josepcisneros.com
app.kiwi-bop.com
kingyoku2020.kojo-shin.com
ladynade.co.uk
dev.mca.leanera.work
listaapp.net
simulator.lukascech.cz
marquest.io
martinschafer.com
www.maydaybt.com
www.meetwithpuffin.com
www.micondocr.com
www.mondebiz.com
cp.nofilterstream.com
datawrap-platform.nue.com.mx
pacient.nuuphealth.com
omcdev.com
cp5754926648000512.order.place
redirect.oryal.pl
app.outroeubrasil.com.br
links.office.planeat.eco
facturacionrecepcion.primeraplus.com.mx
www.pvkmladostbjelovar.hr
mail.rocketjets.com
saboop.com
www.salenyvychodnar.sk
schaererinno.com
schnapp.app
robin.silentbyte.com
sixpackbyjune.com
nipoapp.sndbox.jp
planner.snedsted-turistbusser.dk
stithiansscouts.org.uk
storylabslanguage.com
surfingtracker.com
swagbox.in
www.todayescape.com
www.toy-pro.net
invite.tweeq.me
uranites.in
sandbox.vctech.io
www.viddi.is
vizcaya.pro
www.wargdrones.com
asg.webtabel.ru
wott.in
wwronka.com
reservas.xschooldev.eu
Other domains in certificate