Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=founders.shokko.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
January 15, 2026
Valid Until
April 15, 2026
85 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6A:01:25:0F:B2:C5:3E:E1:46:0F:B7:77:E4:B1:27:17:39:65:0A:8A:D4:F0:F6:8A:B1:82:0F:8C:08:50:60:E6
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
ccsh.com.br
sandbox.command.adionatech.com
affilliatenetwork.com
www.alexrbeltran.com
alizikry.com
rov-configurator.anekonnect.io
www.arts-ts.com
blog.audiobiography.com
www.authentication-china.com
romleborg.axellundh.se
bebop.cash
www.bebop.cash
app.bltn.io
ai.brainz.fit
legacy.citadel.tools
www.cncice.in
morocco.aid-air.co.il
hpvaway.com.tw
www.creamai.com
cremedelameowmeow.com
dev.crosskudi.com
dev2.d-brief.me
dal-texenterprises.com
appredirect.dalmiadelight.com
desolvers.org
app.digame.top
atualizacao.digitalaligner.com.br
forms.dragon.co
franck.dujoux.fr
eae-app.com
erbax.edsys.com.br
felipepmdias.com.br
financanapratica7.com.br
career-pathways.fire-up.net
app7.firstchoicepos.com
www.fitcoder.in
flexcinema.eu
app.foreceipt.com
www.frankthegamer.com
frenchngo.com
fruitbythebay.com
gempdf.xyz
gigfire.com
ginger-restaurant.restaurant
lea.gkhneisser.com
new-portal-workdotlife-staging.goodylabs.com
gostryder.me
haisoft.com.mx
activitytracker.hashxpert.com
media.hausvalet.ca
hiryuutechnologies.com
stg-console.i-grove.com
iloverex.com
booking-iframe.zurich.impacthub.ch
inabtech.com
xilef.is-a.dev
jessicakhope.com
jimsgroceryanddeli.com
pay.roster-dev.kenoviiva.com
keypulse.ru
kiewic.com
la-savore.de
www.locacommuity.com
marketmaking.co
test.mdp.click
minitoolbar.com
moeshekhi.me
widget.nervous.net
next-ai-horizon.xyz
stagingapp.nextblock.sg
blog.ostraca.fr
pokero.xyz
cloud1.popit.io
businessriver.privatehealthcareawards.ie
holymelt.order.pulp.eu
re.cards
www.rushsocial.in
auth.saudeker.com
founders.shokko.com
shokko.com
sports-fem.solva.ar
adnetwork-adserviceadpage.spaceeight.net
media.strans.ua
www.tax4u.tax
cepc.techkey.pro
thejunglehues.com
auth.trackmax.ca
tradeadmin.pro
shop.tungnv.com
uaupizzaa.com.br
www.uown.in
vektornode.ch
www.velo-x.com
www.vhn.vin
boligvelger.visterhemsedal.no
watradingcc.com
www.watradingcc.com
s.dev.watt.tv
epistura.web.id
niina.yamagata.jp
Other domains in certificate