78/100 SECURITY SCORE

Certificate Information

Subject
CN=okaryo.studio
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 11, 2025
Valid Until
March 11, 2026 76 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4B:E7:BB:4F:4A:47:5A:9E:73:6C:7D:A2:E7:D3:04:D8:E9:7B:57:33:7F:A0:06:81:7C:E2:2E:60:18:CB:9A:F1
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
require-trusted-types-for; report-uri; object-src; +3 more
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Significantly strengthen CSP directives
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
app.languakids.com

Other domains in certificate

dev.feasibility.metrofibre.28east.co.za
3boode75.uk
andrewkelly.xyz
www.arxis-ec.com
budget.baballou.com
auth.badmintonireland.com
www.bbi.id
beatthebeans.de
grizzlysgiesenvolley.deeplinks.bfansports.com
capital-iq.in
cardsly.be
sondage.ceim.org
www.cnergy-solutions.com
animeshmohanty.co.in bizzlab.co.in ff.thrivikram.co.in
www.codykit.dev
www.danielosetiawan.com
datamonastery.co.uk
www.deenshippingandmarine.com
www.definaut.xyz
dietetyklena.pl
doofenders.com
exif.dyno.design
e-tailer.co.uk
esploralibri.com
www.fallacy.io
festfrwrd.dev
stage.link.fmn.chat
taxi.gagantransport.com
daylight.gchouse.org
appjoven.saltillo.gob.mx
develop.gorbotics.com
www.greenhill.nl
www.dashboard.growupfund.com
www.halfbloodquince.com
ziele.impactwrap.com
ipdandp.com
www.jaqu.in
values.joinavenir.com
www.keepsafety.pl
marvel.kevcoder.co
www.laracunha.com.br
www.laughsavers.com
edge.librista.dev
www.liftandflow.co.uk
www.luxxymotors.co.uk
www.mariano-zorrilla.com
meedocument.in
www.memorable.kr
www.acessorios.meuplanoclaro.com.br
mgapsicologia.com
stockcal.minlabz.com
home.miwizz.com
mortensen.vc
mytargetbank.com
www.app.testnet.nerochain.io
info.new-mobil.de
app-link.nexopay.io
www.nointernetgames.net
ns-souken.com
nurtora.com
okaryo.studio
hub.test.orangeroofs.co.uk
www.pengelegen.no
crop-trade-sim.physictype.dev
web.pinaflare.com
www.pixie-embassy.xyz
www.primeautomotive.ca
sputnik.reachmedia.co.nz
www.rogercarter.co.uk
saravananns.com
dev-points.serban.pw
randompass.sid426.dev
singinglessonsdublin.com
olj.siwa.io
sandbox.snappers.tv
community-staging.synctalk.us
tanzraume.com
zebiestudios-pinata.teraception.com
www.thainesesolutions.com
evolutionary.theorygenerator.com
dev.thepocketdogtrainer.com
www.thomasdupre.fr
fire.tivvit.cz
mobiletrato.trato.io
node-hcqa.travizory.ch
www.triventcad.com
www.uebeleis.at
vegstreak.co.uk
test.visitame.pro
booking.visitnadabet.com
links.vocsong.com
links.well-beam.com
dashboard.wenergie.io
winkkee.fr
world-clock.com
zenovisuals.com
mdcall2020.zinglio.com