77/100 SECURITY SCORE

Certificate Information

Subject
CN=afroeducadora.com.br
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 27, 2025
Valid Until
March 27, 2026 74 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
07:3F:0F:8F:01:AF:40:36:A1:DA:9E:15:D4:6F:93:B6:3F:48:D5:54:78:D6:B8:3E:37:E2:22:75:0A:24:E0:05
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
asc.habitfivepercent.com

Other domains in certificate

1specialsecuritybattalion.co.za
panel.abgmedia.pl www.abgmedia.pl
abhiragroup.com www.abhiragroup.com
afroeducadora.com.br
b-g-s.agtdijital.com
www.alexdev.se
apexcartia.com
www.astragrandhall.com
www.astronjson.com
app-staging.autoolic.com app-test.autoolic.com
www.aymen-developer.site
baadesaba.org www.baadesaba.org
backbenchstories.com
prostata.boostedchat.com
www.hackerhostel.com.jm
eedgesolutions.com.ng
conferences-nerhadou.com
cdmedia-montenegro-staging.contentcard.com cdmedia-montenegro.contentcard.com
coreconsultingit.com
crownofashes.app
daotaolaixengocduc.com
degemsclub.com
dosingcharts.app
auth.drawjo.ai
tct.libot.stedu.edu.vn
solkraft.edvardsson.eu
entrig.com
fee.epackvn.com
fencinghub.net.au
byre-dev.fieldmargin.com
www.financiawise.blog
firmfoundation.academy
flarenetcompany.in
grailverse.com
club.hagakuresushi.it
halalpitch.com www.halalpitch.com
beta.hbariot.com dev.hbariot.com hbariot.com
bi.i-o.digital
seminariodeiluminacion.iesmexico.org
investwise-inc.com
istiqdam.xyz
jaspreetnp.com
www.jerry-agboola.ch
www.knowyourciti.com
krustyburger.com.ar
laxminarayan.org www.laxminarayan.org
leal.systems
lifetimeqrcodes.com
arpa.linaxbd.com
loveconnectplus.fr
lucky-playground.com www.lucky-playground.com
mh-optimizer.com
openwaters.monacofoundry.com
mselatechnology.co.za
www.myculinarycollective.org
mylawadvisors.com
ndemenu.com
notanovice.com
peeledupmarket.com
rasoia.com
www.reformedchristian.org
authv4.reidmediaplus.com.au
reg2mng.removis.jp
reskillmax.ai
reskillmax.app
erp.ryan-info.com
s-dentalclinic.site
erp.samacharlookout.com
www.sasolburgboulevard.co.za
sbscgroup.com
www.selflearnlangs.com
market.yorwor.siraphop.me
www.sland.xyz
www.smartxelements.net
solartime.com.br
studio.thedotlines.com
www.app.tontaube.ai
ocpp.tramev.vn
design.trustyourngos.com
trymgmt.co.jp
tyreditorial.com
docs.valmius.io
www.vayuform.in
auth.viralclipai.io
visaworld.online
www.vitaransvar.com
webfly.site
werkgroeplhee.nl
yasirsoleja.co.uk