77/100 SECURITY SCORE

Certificate Information

Subject
CN=bazelet-group.highlander.cloud
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 15, 2025
Valid Until
February 13, 2026 89 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EF:45:1F:C6:48:AE:A4:AF:C9:52:5B:EA:5E:73:E5:1B:99:CE:3A:81:0C:BA:75:2F:46:16:53:4C:C7:BC:89:0E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
bazelet-group.highlander.cloud

Other domains in certificate

stg.act-app.com
www.actuz.com.br
www.agreenforest.org
ownflow.ai.kr
v13.angular.io
www.arvada.io
www.ashmd.biz
testflow.atomsai.net
gigboard.audioglobe.com
app.biblelite.com
staging.biket.fr
botterman.me
capa-aquascaping.fr
casadesaludfloresta.com
www.cetreal.com
christianmissionchurchsa.org
upload.chrm.fi
store.coconutwaiting.com
compramostuautocr.com
www.cortez-modell.com
www.cpost.io
qa.ctrise.org
www.danieleciceri.com
darzekielventures.com
srpl.decoderesolvency.com
cust-i.dev-ltl-xpo.com
resume.marcocosta.dev.br
fabric.divx.com
link.doublecheck.kr
dvibit.com
earbutarediocese.org
econutriconsultoria.com.br
elitefabriccare.in
www.fasta-46.com
www.fine-moves.com
app.greenkeeper.se
gsvrisk.info
howmanyisit.com
idea-association.com
www.immogay.fr
innovortex.in
isopnm.com
jaromirkalas.cz
jordanfamilyfarmsok.com
www.jpkrp.com
admin.kotaberbagi.com
kreationlab.net
www.lakahawaii.com
letsmeet.today
www.lilyhair2021.com
lojan.com.br
www.lynkestimating.com
lyomattomat.fi
dev.mangabox.ink
passwordmanager.marcello.dev
mariehamnsflygplats.fi
www.marually.com
maxhydraulics.com
inventory.meetjinn.com
www.midairtravel.com
mkchess.in
artsthread.monacofoundry.com
monkeysplash.com
b4u.mslogicbee.com
app.mydesk.chat
admin.neowshop.com
demo.nextgatetech.com
ecms-michael.nucor.report
www.oasishypnocoach.co.uk
www.oohvisionpro.com
www.palmtreeclub.finance
picme.am
piplosai.com
planningpokerpro.de
homapp.playdragx.com
plokie.com
assinar-hml.presencabank.com.br
ciberon.rebus.com.co
www.reconbuddy.com
webapp.requestorapp.co.za
revtheboutique.com
www.rootdigital.com.br
www.sapphire-cms.io
seacoast.partners
dev.sloteng.com
smart-trading-ai.com
specdrums-admin-staging.platform.sphero.com
www.app.stipendly.se
insurance.d1.stx.world
www.tappilyapp.com
tariqhammad.com
tatkhalsa.org
www.uniconnecthq.com
storewebdemo.ventagenie.com
app-sandbox.visitown.live
workflow.vsight.io
applink.woot.com
zinker.studio
student.dev.zlipp.in