77/100 SECURITY SCORE

Certificate Information

Subject
CN=inmobiliariamunio.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 08, 2025
Valid Until
March 08, 2026 87 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C4:38:2D:D1:20:69:0F:47:AF:04:B1:CC:8B:B3:67:AF:79:8E:86:F4:65:88:36:7C:B7:AF:F8:46:14:34:80:BB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
ar-vr.ihub-drishti.ai

Other domains in certificate

7ok.in
links-swiftcut.acty.com
dev.myadblock.licensing.adblockplus.dev
aestribra.net
menu.agoramenu.com.br
v2.alanho.work
angular.kr
antiprocrastinationlist.fr
member.appji.org
aranissa.com
arteyalmaproducciones.com
artofpilgrim.xyz
www.atomservice.co.uk
bethgallagher.com
bonychops.com
bouncehousedude.com
caex.fr
cartraxx.com
www.chatmvp.org
www.chefqibraheem.com
chocobitstudio.com
jfl-track.roadcast.co.in somu.co.in
portafolio.condor-soft.com
www.cosseno.com.br
app.curelands.com
dsh.fyi
pdv.e-ceos.com.br
xhunol.easyapp.co xvvejs.easyapp.co
enfo.ai
chronova.escobedev.com
esytaxgroup.com
exempla.io
test-site-results.farmgateauctions.com.au
asap.forsvaret.no
content.getnuma.com
ghostgame.io
glamboxbrasil.com
dev.h-p.io
hollerdate.com
links.hypno.com
inmobiliariamunio.com
itsprobablyababy.com
staging.justiceapp.com
portal.khoahuyhoang.com
alpha.kipinto.ch
fertisa.lernit.app
www.sellgpt.letsaspiro.com
lfabbro.com
liquordaddy.in
app.lobibox.com
lvliverealestate.com
grobbee.nutt.test.m4m.io
knitting.matthewbickell.co.uk
idp.mercari-shops.com
app.meulanchinho.com.br
www.mindfulmission.earth
jagholm.demo.movello.se
www.mowbraydachshunds.co.uk
website.mpn.rip
sby.mtnpy.id
www.mypagex.com
namibiareads.com
collision.nissanusa.com
thiruvarur.onewaydroptaxie.com
osparis.fr
host.pebbletheapp.com
chihiro.pedidomovil.es
admin-dev.peppy.health
www.placemakinginstitute.org
www.primelankatravels.com
app.quadri.com.ar
rabool.com
www.saifaldin.ca
app.sentrum7.com
shenkconsulting.com
skiatech.com
www.smartbusinessforce.com
share.qa.soniccloud.com
splusgroup.net
uhmsweeps1.sqwadhq.com
srisudahandcraft.com
www.stockrepublic.se
www.televisionreligion.com
tellstories.xyz
telth.com
www.testfcplcrm.com
www.teup.mx
links.staging.thefreshgrocer.com
tooljet.io
admin-test.tredplus.com
vararuchiartgallery.com
viggu.me
visa4all.eu
registro.wapchita.com
careflow.wholisticservicesinc.com
link.zeenshopapp.com
help.zerothreat.dev