Cached · just now
89/100 SECURITY SCORE

Certificate Information

Subject
CN=app.hdione.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 30, 2025
Valid Until
March 30, 2026 71 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
92:A5:97:67:AB:A6:39:03:D1:29:B8:93:9B:AE:41:AA:C6:7E:A7:82:46:85:1F:DF:4B:67:5B:87:13:2C:90:E6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=1000
Content-Security-Policy
Weak
upgrade-insecure-requests; style-src
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Significantly strengthen CSP directives

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
app.hdione.com

Other domains in certificate

restaurant.alifhalalmeat.ca
www.andychill.art
arrowords.com
www.awaelalnoor.com
berkeleytransport.org
bikingbeyond.de
www.sonepar.bluevis.io
fitness.bobbysciacchitano.com
bokhari.de
www.bottlecaptech.in
brandscentral.net
budgetnuts.com
www.christianscreen.com
www.clikclak.com
planettravel.com.sg
kingstore.com.ua
compresso.pics
plantaflag.dalta.app
datalayer.ca
www.datepainter.com
www.daypaint.app
denzildoyle.me
deshop.my
links.dogorama.app
we.domobile.com
dpportotextil.com.br
www.dublostudios.com
eccentriclogistics.com
lumadistribuidora.edsys.com.br
www.edu-design.ca
www.educrestpreschool.com
erp-works.com
clima-dev.farmacare.dev
finalversion2.com
super-cab-hub-staging.us1.fleet-dev.com
fleximama.shop
focus.fulcher.io
fyleprep.com
gigops.app
glintventures.com
www.gonzalocuartichi.com
pergolacalc.hollander.tech
hml-www.inoa.com.br
acceptance-widgets.input4you.be
instacnc.com
itay.uk
foodlist.jacobklaren.com
junglefruit.net
kaido-mobility.fr
killnoi.se
www.kitanga.dev
www.kutayacar.com
livability.org
pt.luis.zip
demo.marschalllabs.com
www.mbuzi24.com
campaign.memtell.com
static.mimicle.com
monarkhq.com
dashboard.mould-web.at
myipantry.com
namerecs.com
dev.nannyme.love
www.dreamcode.net.br
www.oceanwise.dev
www.ojasrohatgi.com
openspur.com
admin.orangefigs.com
app.orcadigital.com.br
app.paystro.ke
persistentecho.com
share.picklepoll.com
www.plmserve.com
www.plokie.com
qualifast.bg
sync.sakida-dev.com
www.sbscr.com
ticket.scj.io
screenart.in
admin.securedai.co
beta.sellez.store
paul-mitchell.showroom.app
www.siamdoduang.com
simongarton.net
sincerelyist.com
www.socialpreneurinc.com
www.srbatterysalesandservice.in
www.suchaktea.com
syazy.com
auth.teabee.org
nikunj.theariesa.in
speak.tosatur.com
www.two-cents.app
docs.useswyft.com
vitted.hu
finder.vrijraj.xyz
www.webdoko.com
yonosoychef.co
www.zuva.ai