Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.tomato.ai
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 25, 2025
Valid Until
February 23, 2026
84 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
72:94:6D:0B:41:EC:11:F9:86:47:F9:24:BA:39:E0:21:22:6B:6E:40:95:48:02:E3:81:58:F8:CD:7A:68:74:15
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
au2.resbutler.com
dev.feasibility.clearaccess.28east.co.za
soc.akibaa.com
trailspot.albertodelahoz.com
aybkk.moscow
www.bazaaroapp.com
www.birthdaybox.io
bmjfit.fr
consumerapp.boomtownroi.com
staging.cardsly.be
www.cedeppe.global
cmc-development.work
carta.coleccionistacoffee.com
armoire.com.uy
www.dataliberationfront.org
www.dataslots.org
money.desdea.com
www.di-dy.com
scanfood.durban.cat
avoimetovet.edukamu.fi
bankinter.engage360.es
cn.listwithus.favstay.com
registro.g2canal.com.br
app.dev.getsystem2.com
worker.link.gigsmart.soy
glorious-shallow.com
addon.goooled.com
physician.greenlightbalance.com
charles.gregoireweber.io
honey-comb.fi
i-remember.co.uk
fw.imamie.fr
api.immodigi.app
www.in.mk
vdfin-bailiff-dev.input4you.be
link.inquize.net
intidinamis.com
link.it-pass.jp
iyadaboudargham.com
comp3120-2023-c03.jayenashar.org
readr.klg.bz
leszczynski.me
ques-prod.da.letsdive.io
trasas-staging.logivan.com
www.lucaklingler.com
laboris.luxater.com
menui.at
www.mifillosophy.com
app-stg.mmseas.com
mohyaghoub.com
movielist.info
nayagadget.shop
book.norsegaming.no
nususc.com
onefacture.mx
pagapr.com
www.paraclinics.cl
www.patentepratica.it
home.phillipwildhirt.com
placemakinginstitute.org
vodafoneitaly.staging.platformkids.com
playpromptly.com
presidido.com
www.qadusers.com
www.quikpago.com
www.rehov.net
new.robynjwall.com
rodneyshafar.com
rok.digital
www.saijyothospital.com
savely-editor.com
toggenburgshop.scango.ch
www.sharedonfarms.com
docs.sheesh.vc
www.siderealtimepiece.com
platform.siphonapp.io
certificates-staging.plugins.skore.io
www.slye.dog
www.softjads.com.br
checkout.somethingsimple.me
uchigeki.spwn.jp
strategicclaimsdirection.com
app.studio-ask.com
www.sualoto.com.br
my.talir.pro
join.team.repair
www.tglawgroup.com
live.time-drops.com
www.tomato.ai
beta.traleemasjidkicc.ie
quiz.vino.blog
www.vokablo.com
www.wakapapa.dk
wabprogram.websiteservice.co.za
westigate.com
www.wolfland.games
devmulti01.wowdesk.jp
links.wrestle-universe.com
yasamnedir.com
zakisessence.pk
Other domains in certificate