Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=nycstudio.neoufitness.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 17, 2025
Valid Until
January 15, 2026 60 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:2A:0F:B0:00:37:52:3A:C8:2E:99:A7:60:5F:B9:6C:4F:26:C3:A4:28:D4:D8:2E:F7:95:A3:5D:96:5D:82:C1
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
bussiness.page

Other domains in certificate

6campos.com.br
aacad.cymru
agrevolution.in
www.aksharenterprise.com
resume.andrei.cc
artmvstd.com
asianamericanedu.org
dynamic.avid.health
www.auth.qa.bbh.li
benmiz.com
qr-api.blindsqua.re
website-demo.boothtransport.com
c3rescue.com
app.staging.campushub.io
dev.cleanover.com
coinfrs.com
www.companytracker.co.uk
conexionaltura.net
crea-terre-et-feu.com
cryptotraderbase.com
www.dagpenger.no
me.danielle.ai
diemoond.com
censo.ditosas.com
ranipet.eacabs.com
feriauniversidades.uepac.edu.ec
test.essensi.se
fantasticaiconsulting.com
stacked.filledstacks.com
www.flexfincare.com
targerests.fsbd.ai
fussballranked.no
galbumreviews.com
engine.getafeel.com
app.getdevwin.com
dpm.giorgio-dots.com
auth-dev.gluegroups.com
devs.healthid.ai
herwigserpieters.be
admin.hoblen.com
www.homezz.vn
www.intelligrow.com.br
link-choi-ming.jec-digital.com
alps.jtsiskin.com
kennyb.dev
kokon.app
ce.ldsmex.org
llamas.cloud
www.magictradingpost.com
demo1.menusdigitalesmty.com
mkhemel.com
demo-dashboard.mpower.africa
mybms.io
auth.mybodyecology.com
natemoo.re
score.nathantate.io
nycstudio.neoufitness.com
docs.nerochain.io
www.networkmedikal.com
payroom.nodev.com.ar
paletteeny.nofowl.dev
old-dev.noknokgroceries.com
ohentgroup.com
openstageamsterdam.nl
www.orderr.in
pacto.dev
www.papuga-app-lab.com
www.papuga-app-lab.net
plan24.io
rasa-co.com
painel.redetn.com
rosemountlandscaping.com
ryserecovery.org
www.sandramarichal.com
sarthakcab.com
shapesie.com
sneakercoder.com
www.sochneaankha.com
componentes.solucionesvaltech.com
raidersfordtailgateadmin.sqwadhq.com
stevenmu.dev
sts.suppy.app
bodaalexaydiego.swanmoments.net bodaserpasperez.swanmoments.net xvsarasdiscoparty.swanmoments.net
games.tashtaree.in
dev.tenet.aw
app.tept.in
link.the007percent.com
test.themyst.com
thinkgeoai.com
timestrail.com
twizzytalk.com
www.valentinotekel.com
valeriaintini.com
vishwasp.dev
books.withyour.coffee
yoyalty.com
app.zappaimoveis.com