Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=avaliacao.truliv.com.br
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 30, 2025
Valid Until
December 29, 2025
46 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4A:94:35:80:3F:4D:BD:8B:FE:61:22:D1:6E:CD:2D:6D:BA:A0:91:63:59:98:73:C1:73:D5:E3:4F:67:DF:55:A9
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
brianjmillerjr.com
www.adventureteam.pl
ahamedenterprise.in
office.andresito.xyz
www.faq.anotemos.org
ashtindowler.com
businessriver.associationawards.ie
go.b-guest.com
bandmeet.org
www.baobyte.com
bestwander.com
blueskyamusement.com
borapraonde.com.br
brasilinovacoes.com.br
www.brickwise.org
brightideascorp.com
bunnacafe.me
callnightshift.com
www.cdmediase.pt
chachawarmi.com
chrzn.pl
servilo.co.il
platform.coffee-fellows.com
coreide.com
prayteam.creat1324.com
photocurves.curvednebula.com
cxloel.com
e.deva.sa
drinkstop.app
www.e-tag.pro
cxhub.ecosystem.life
backoffice.editoranapoleao.com.br
modulesurvey.lasalle.edu.sg
emerjmedia.com
ahc.play.emr.studio
globalrussia.eventtravel.app
ewhents.com
ezonetechnologyllc.com
fabriqon.com
farmmoja.org
app.fivokcs.com
funsport.dk
dashboard.geniusrepair.it
getthat.io
dev.gowithafr.com
graywavesolutions.com
gulmall.com
staging.halpfestival.sk
shortcuts.happergy.es
www.hello-world.ca
herramienta-financiera-rm.com
hippodex.com
api.hive.properties
homegame.uk
www.iffco.fr
astro.josiya.in
www.jueunedu.com
link.korma.nl
kvsbllp.com
tv.labyb.com
latifaktas.com
lutterlohwedding.com
spanish.luukjonko.nl
marmot.city
www.meadowlark-birding.com
demo.aslan.mojo-pay.com
musicalgameoflife.com
www.newagelidia.com
www.newvision-homeinspections.ca
www.novaagricola.pt
optimag.pl
pomoc-drogowa.ostrowiec.pl
loadsmithdev.parade.ai
patulandia.com
www.radon.ge
www.ramanouski.com
redzeplin.de
reprod-english.com
blog.revwiz.ai
riley.audio
roth.ooo
sach.co.za
sausank.no
secpassgen.com
ang1.shoghol.org
siete11spa.com
sieveanalysis.com
www.soi5barber.site
bodadanielayangel.swanmoments.net
www.symmetrics.app
tagtokn.com
corp.true-seekers.co.jp
avaliacao.truliv.com.br
petitions.tylerjon.es
blog.utkereses.hu
velograph.app
miatphotos.watchaturtle.com
retrospective.zendrop.com
www.zodyaki.com
zqtechlimited.site
Other domains in certificate