Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=speechtotext.oppa.app
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 01, 2025
Valid Until
January 30, 2026 81 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F4:37:16:07:5C:AC:66:42:8A:A5:67:97:3D:4E:24:1A:FC:F3:2D:25:1F:65:C9:88:02:4D:C8:82:13:5B:60:F4
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
brettfene.com

Other domains in certificate

4seasonshomestay.com
www.agenciamicrosaas.com
baby-dev.ai-saloon.com
www.amazingbrushes.com
api.appres.org
hire-staging.auzmor.com
www.axerapy.com
hello-world.barky.com
girondins.bfsp.app
biancarosa.com.br
bierbord.nl
bridge2things.at
canberkelmal.dev
compasswallet.io
cornerstonehca.com
www.cybernetex.org
deanwagner.info
www.deepura.com
domdaria.com
fish-bowl2.droov.io
dsat16.com
selfserve.duttongarage.com
earg.org
eddiefls.store
requestl.ertech.com.co
estacionapro.com
eternaspace.com
eusouinocente.com
dashboard-training.fhinck.com
test.authentication.fullmarks.io
funteractive.app
futpolemica.com
gensocial.ai
georgprassl.at
www.guitarlessonssunderland.com
www.harmonyplume.fr
www.huahlabs.com
admin.inteliped.online
journeyproductions.org
imefu.lapieza.io
www.ibu.learningsuite.at
talentohema.lernit.app
mavisacademy.com
eterna.miapppro.com
mistability.com
morgan-photography.fr
morpheus-tech.io
musicevent.app
nadjaundloris.ch
display.nebraskafll.org
pic-spreadbetting.mentor.neccton.com
www.nikitalama.com
aheadgdpr.novavista.cloud
flutterpainter.omarhurani.me
speechtotext.oppa.app
ordenanow.com
lyfja-onfleet.pan.is
patchi.dev
pedidomovil.es
hotrods.philanthrosphere.com
link.philsebastian.app
pierreschutz.com
ops.takanome.pirika.org
pizzapluscompany.com
www.play24.stream
profiserban.ro
forum.questgames.net
api.quickswap.exchange
nctc.reachplatform.com
reqasong.com
rewanow.com
sebi.rezervari.app
rocnescribner.com
www.safecircle.africa
saidthat.app
shubhamarya.com
skiclick.com
smart-scan.app
soilsolution.com
sorentodaily.com
www.sprel.fr
sribank.lk
app.ssam.net.au
client-dev.talent-alpha.com
phoenix-api.talentlytica.com
www.techveda.ca
tgif.my
thaack.com
www.tixora.co
trumankautzman.com
auth.upnext.in
uqfintech.org
viserstudio.com
mmlive-staging.viuing.io
historico.votei.app
www.wordsandpictures.app
www.xcolons.com
sociobridge.yourfirstad.com
www.yunusemreozturk.me