Cached · just now
78/100 SECURITY SCORE

Certificate Information

Subject
CN=andrewjamesbaker.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
January 08, 2026
Valid Until
April 08, 2026 85 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8D:0D:B0:A0:A3:3F:E4:61:FC:A9:19:3E:7D:C7:01:69:36:8C:39:45:0A:0B:E5:31:7F:62:BC:0C:16:ED:C7:6D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
require-trusted-types-for; report-uri; object-src; +3 more
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Significantly strengthen CSP directives
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
app.dailyshot.co

Other domains in certificate

abafacil.app
emoji-quiz.acatango.com
acslc.com
www.agromultiservicios.com
aivanlife.com
aixgencore.com
pepstery.anceu.com
andrewjamesbaker.com
appveg.com
aromejardin.com
azimonti.com
app.ba-living.com
bandmatic.app
i-got-this.barin.app
cabaretflamenco.com
www.calisome.com
www.savitricommunication.co.in
dermaiapp.com
diahk.cz
ecohousesrls.cloud
www.editorialhonduras.com
dev-link.ehubstar.com
charging-console.electriphi.io
eticketrepubliquedominicaine.com
www.fishbookpro.com
friendscard.co
fuelplan.hu
goyongnuri.com
auth.gridbox.io
www.gyaanai.ai
harmonyosteocare.com
paystack.helot.co
www.hengstenberg.biz
www.hindsite2020.ca
hotelgrandheritagedaman.com
certificado.icnr.com.br
auth.jointalentscout.com
www.karan-cf.fr
www.kebrown.dev
www.kfz-wieczorek.de
mtr.kihoon.dev
dashboard.laurandrion.com
link.leaframe.com
learnhahu.com
legacyflow.org
dev.lge-tns.com st.lge-tns.com
marisamioto.com.br www.marisamioto.com.br
masternmasters.com
morphurl.com
mundomontessori.cl
myaibuilder.com
naikideal.com
admin.od24.in app.od24.in
akillitahtayonetim.ogretimsayfam.com
www.pairato.com
patchmeifyuoucan.com
www.pickaticket.app
pit90.com
zunseinsein.piticommerce.com
www.planelogiq.app
prahitaengineers.com
auth.priceotus.com
promededucation.com
puremediasa.com
admin.rcircular.cl
recheio.pt
www.rehabtherapypartners-hi.com
www.revelto.app
roromasalonart.com
ryanlimyihng.com
admin.secumax.in
sedasa.co.za
seropda.com
sharp9architecture.com
shivaprintaid.com
sidewalkpdx.com
app.skicomltd.com
www.smartscouting.app
sngg315.com
solvea.ch
stocklink.app
sukatabjj.com
jsonviewer.sweetsalmonmedia.com
taouti.cc
www.taskzilla.app
techsynergyhq.com
affinity.tectes.com
tiendaecovibes.cl
timetone.app
trumnu.com
admin.vailo.ai
vireum.fi
watchmoney.ca
xaviersalcedo.es
openlivelifelocal.yodelit.co
ztudio.app