Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=stoneybrookschool.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
May 05, 2026
Valid Until
August 03, 2026
86 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
52:82:CB:EB:75:FA:F2:DA:A2:D9:E8:9F:7C:EE:C5:37:C1:0C:02:73:A0:4D:91:1A:F0:AC:58:56:78:16:0F:74
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
auth.harusplit.com
abdulrahmanprojects.com
acol-boarding.com
adnex.shop
www.akshagna.com
www.algoninjas.com
apexjunkremovalservices.com
dev.beehus.controladoria.beehus.com.br
bizzwords.app
blue-cristal.ch
boomhaus.design
www.cad3d.com.au
candorsoftwaresolutions.com
www.candorsoftwaresolutions.com
medinet.cirmena.com
www.cityspot.ro
codysmobilemechanic.com
www.crabe.art
dataforme.fr
dubairro.app
www.e-gathitulegal.com
egy-coal.com
escalanacional.com
www.feniks.ca
fladmin.app
docs.flex-testing.com
hase.fundman.ai
gjfinancialsolutions.com
hawkwood.dev
portal.hmmediaorlando.com
holoart.com.tr
www.hostalroma.com
cms.hugs4bugs.me
www.hurip.com
cic.isamtool.com
itcyberworks.com
jaguarema.org.br
jasoncornish.dev
www.joywallet.com.tr
www.kaitlyngreenvb.com
karaokesocial.app
www.kiwicode.net.nz
laslucas.com
lexsigma.co
developers.litta.co
localtradechecks.co.uk
manaroystudio.com
marvelinstitutions.in
tnc.max-index.com
www.mondadoritrento.it
indeje.muhanji.co.ke
www.muslimunitedvoice.nz
www.myguardianninja.com
neolexical.com
pos.nomimicafe.com
odiasocietyrva.org
www.oneup4real.com
openfeed.co.za
otgruzchiki.kz
pandemicbrewing.com
www.pandemicbrewing.com
phammduy.id.vn
piklab.ai
playamericaner.com
app.promesha.com
pudustudio.dev
www.pudustudio.dev
homeweather.qkuronekop.dev
quytrungnguyen.id.vn
aether.refactory.co.za
www.regusprint.com
residenzamarconi.it
www.rocliterary.com
comunicacao-develop.rogeriossantos.com.br
rooseveltpark.dev
saldoofin.com.br
samudraaqua.com
secondstoryhousing.com
wadidemo.sinankm.com
singletonsoftware.co.uk
slowtourcilento.it
www.slowtourcilento.it
stoneybrookschool.com
studioforged.com
www.systemis.dev
tajskyviewresidences.co.in
www.tangzhou.rest
telepatiq.com
trade-r.com
tsr-trenchless.com
www.vakilhai.in
vorticemusical.com
www.wanabee-score.com
werewolfsden.com
www.werewolfsden.com
williamjewellcamps.com
wonderus.app
prep.worlddebatecollective.org
yavar.io
yetanotherapp.dev
Other domains in certificate