Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=anasaviajes.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 25, 2025
Valid Until
February 23, 2026
85 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
31:6A:D4:10:7B:CF:77:5F:72:CB:2F:D9:0B:F1:C7:3B:38:26:61:3D:DA:3B:F3:4A:20:4B:6D:3F:BB:52:52:8D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
ashfordapp.cleantie.com
app.activeviewer.it
link.cards.activout.app
agoraosint.com
allealex.it
www.allealex.it
www.ammelt.com
anasaviajes.com
autocallrec.app
azulgoldenfinanciamentos.com.br
blackroguecoffee.com
www.bramtrabaho.com
cellebrity.bio
celonmetrics.com
chalc.app
bartender-staging.checkson.me
dl.checkuphealth.co.uk
www.christophgajda.com
license.cinedeck.app
training.te.claridash.com
flexcredit.admin.staging.codewell.ai
crossingvoidhq.com
dallascustoms.com
dashboard.davidborge.com
quote.ddbox.com.au
dianafarhat.com
staff.douvk.co.uk
dtplus.com.br
catalog.egsey.com
redeem.ekwe.app
climalaboral.elhadigital.com
beta.enezatelecom.com
enormousmachines.com
eshaanchaudhari.com
www.espireads.com
etiquetaqr.online
eudial.com
exec.dev.evertransit.com
iot.exflair.com
faiyazsundrani.com
falardepolitica.com.br
family-spots.com
feedflex.app
bartelsdatastore.felixxgroep.nl
webapp.flaner.com
a0ca.foodle.su
testing.foodworks.online
fratellipizza.com.br
freemoviesus.com
geniushomecare.com
getelleratlet.se
goalogic.pro
www.golfsolitaire-online.com
energie-check-plus.gridty.com
devcard13579.healcard.com
hibrid.app
doctors.hippocrades.com
www.hmtechconsulting.com
ghidiem.hocchoi.com
www.ianskillersudoku.app
www.icivilsa.com
widget.input4you.be
joaoclaudio.dev
joeraver.com
admin.lightboxglobal.com
www.lyricalgame.com
www.malyctenar.cz
www.marche-design.com
ministeriofamiliasdt.com.br
calendars.mira-one.com
mokin.nl
eduloan-apply.money-phone.com
moneysweet.app
muhmundr.com
firebase.nieve.id
db.omelett.co
openvox.io
platinum.orhanarslan.com
profesyonel.orhanarslan.com
join.pascal-kasbeitzer.dev
pokedex.pascal-kasbeitzer.dev
sharkie.pascal-kasbeitzer.dev
phms.com.br
mooncake.prl.one
boat.prodiversapp.com
boatapp.prodiversapp.com
www.programavimo-paslaugos.lt
www.proyectomenosesmas.com.ar
mobileapi.radiotoolkit.com
www.samrcujpacer.co.za
www.scorebug.online
shopavize.app
sobrmate.app
www.sobrmate.app
triu.ch
www.twisleton.net
usmonumentalchoir.org
resume.zaryab.dev
zchess.xyz
cosmoseye.zense.online
Other domains in certificate