77/100 SECURITY SCORE

Certificate Information

Subject
CN=app.coefficiency.net
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
April 20, 2026
Valid Until
July 19, 2026 82 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E9:66:DA:11:4D:8F:7D:65:21:45:22:36:39:F1:9B:9D:B4:60:1B:6B:06:AF:1A:FE:B6:BB:36:40:CE:59:52:34
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
auth.spotquik.com

Other domains in certificate

www.1force.be
576201.com
www.aaautoinsurancecfl.com
www.aasthikbuilders.com
www.acomaj.cz
akimsepeti.com
aloriente.cl
alta-velocidad.com
altagracia360.com
altamarresidencial.com.mx
www.andreae.ca
autoselmolino.com
azylusgraphics.co.za
bakuguard.com www.bakuguard.com
berbergo.com.tr
staging.bhdaon.co.kr
app.biejanssen.nl
d.bitaksi.com
cauveryelectricals.in
ishan.chandrakar.dev
app.coefficiency.net
projects.crossight.com
cypaps.com.ar
www.dacosta-renov.fr
defedesvin.com
dentistamooca.com.br
ezdata.devcoreapps.com
dinomonz.com
www.docode.se
emmyvasse.com
www.espaciolorca.org
fairylullaby.com
www.finalversion2.com
findmyfavourites.com
fre-studios.com
genaiworldassociation.com
ghostpadapp.com
pay.andy-testing-013.gr4vy.app pay.sandbox.andy-testing-013.gr4vy.app
gr6systems.com
app.grew.eco
guitarlessonsswansea.com
www.gvav-utilities.com
gws1.cc
admin.gyfbox.com
haoxuechinese.com www.haoxuechinese.com
inexarum.in
www.instafuture.in
johannarode.com
juras-crew-services.lv
kalamautomationgps.com
autolive.awheels.kitloongholdings.com
knvas.dev
kultexplorer.kultunaut.dk
www.linus-teklenburg.de
www.novios.misterboda.es
tracker-preview.mobilitymojo.com
morzetech.com
mobile-apps.mycarly.com
juggl.myceliumllc.dev
myels.space
www.nexoracoliving.co.in
nfltable.com
link-jbl.nibo.com.br
nikola-kovacevic.ch
em.numerous.cloud
auth.openloomstudio.com
www.pharrellphone.com
resume.pixeldocs.in
www.pixsoulweb.in
quantum-it.uk
rbdgswg.me
rekanaiti.com
www.reprar.in
revan.it
schocke.ch
selonhippocrate.ch
api-clientes.servicesdtk2.cl
list.shiftinc.jp
essentials.simplewealthdad.com threadsempire.simplewealthdad.com
sncloudtech.com
wealthcoach.sohamvaluecreation.com
sharedev.sparrowconnected.com
stagplanr.co.uk
stayleafhotel.com
strivepay.online
synergyauto.com
www.techarchgrid.com
tenntenn.dev
theclinivolve.com
stage-admin.traderinmaking.in stage.traderinmaking.in
www.urbangroup.ie
williambanquier.ca
dev.woo.network
yokicode.com