Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.menuplace.gr
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 23, 2025
Valid Until
January 22, 2026
76 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
70:9E:F1:A6:F6:34:C4:49:62:FD:A4:5A:34:35:93:DC:64:BD:1F:12:A8:69:97:3F:A3:26:11:44:53:BB:DB:E0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
citycenter-dental.com
test.adambridges.ca
afyrat.se
blog.almeraim.com
altriconsultancy.com
app.articleninja.ai
www.assertionaccounting.com
www.birwi.net
bleaneclothes.shop
bookmypharmacy.com
app-staging.brnkl.io
www.certifiedtrue.co
www.chennaicalltaxi.in
app.chewins.nl
www.chrysalyst.com
studiorami.co.il
www.roservicecare.co.in
iwo-ote.excelcomms.com.my
admin.dev.connectsx.com
indiquepride.construtorapride.com.br
dailydentist.ca
dive.bio
donaldposkitt.com
admin-staging.driverguide.is
online.egovconference.ee
130lc.equiem.mobi
dashboard.estatesync.com
eterkit.com
exp-ai.com
demolink.fastesthealth.in
www.ferdowsi.de
flutterdude.com
login.forbes.com
beta.foundershield.com
sdk-wuolah.froged.com
gelaterianuvola.com
m.giddy.co
series.gmph.co
group-reading.com
gunespeksen.com
app.guri-tech.net
havasuoffer.com
www.hochziit-bero.ch
howfastdoitype.com
hushhushgali.com
ihome-rf.ru
dev.integradehub.org
calculator.khinfosoft.com
koomzo.com
lanha.space
agri.limandrew.org
notification.linkx.global
lk.sv
www.logopaedie-lohhof.de
www.macroswiththemicklos.com
mariatech.io
app.marimole.com
massiva.sk
matiasklemola.com
mech-key.com
mediafinanciers.com
www.menuplace.gr
www.mindtrail.in
miraimusubi.jp
teams.mymoodbit.com
www.nakurz.cz
i.am.nasz.my
njtravel.nl
dealer.on2off.it
e.ozakglobal.com
old.pack744.com
pamoteam.com
www.stepstone.parkey.io
partiallyrekt.com
bestellen.piazza-bielefeld.de
stage-picks-control.picks.com.br
booking.plus3trainings.eu
www.pokerclassrooms.com
www.pomodifferent.com
www.portail-restaurer.ca
hotelsavoy.ratality.com
sahilhpatel.com
dl.sasanm.ir
admin.saverpe.com
savvysale.ca
www.scim.tech
sheqprac.com
test-santacloud.stnikolaus-wohlen.ch
dev.swapptechs.com
testingyvr.ca
admin-dev.marathon.thai.run
www.theaihive.xyz
theweekendwarriors.com
tikgen.fr
tomasmier.xyz
www.truerconsulting.com
ucca.edu.au
dev.widget.vestico.co
www.wedevelopsmartapps.com
www.zpikonline.com
Other domains in certificate