Open
Cached
·
just now
95/100
SECURITY SCORE
Certificate Information
Subject
CN=contra.com
Issuer
C=US, O=Let's Encrypt, CN=E8
Valid From
December 23, 2025
Valid Until
March 23, 2026
88 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
6C:4E:C2:C0:57:F4:E5:81:B6:10:75:06:6B:B7:AC:52:DC:D7:DB:8B:2F:6B:FD:8E:74:2D:B6:9B:26:70:7E:78
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Good
default-src; script-src; style-src; +9 more
default-src 'self'; script-src 'self' 'unsafe-inline' https://*.contra.com https://contra.com https://*.ads.linkedin.com https://snap.licdn.com https://connect.facebook.net https://www.facebook.com https://beehiiv-adnetwork-production.s3.amazonaws.com https://www.tiktok.com/embed.js https://www.instagram.com/embed.js https://www.youtube.com https://*.tiktokcdn-us.com https://gist.github.com https://platform.twitter.com https://challenges.cloudflare.com https://accounts.google.com https://apis.google.com https://googletagmanager.com https://www.googletagmanager.com https://*.doubleclick.net https://*.posthog.com https://app.intercom.io https://js.intercomcdn.com https://widget.intercom.io https://*.stripe.com https://*.airwallex.com https://static.hsappstatic.net/MeetingsEmbed/ex/MeetingsEmbedCode.js https://js.hscta.net https://*.hubspot.com https://*.hsleadflows.net https://*.hsforms.net https://*.hsforms.com; style-src 'self' 'unsafe-inline' https://builds.contra.com https://github.githubassets.com; img-src 'self' data: blob: https://*.contra.com https://*.ads.linkedin.com https://*.linkedin.com https://www.facebook.com https://storage.googleapis.com https://cdn.loom.com https://*.googleusercontent.com https://www.googletagmanager.com https://www.google.com https://*.intercom-attachments-1.com https://*.intercom-attachments-2.com https://*.intercom-attachments-3.com https://*.intercom-attachments-4.com https://*.intercom-attachments-5.com https://*.intercom-attachments-6.com https://*.intercom-attachments-7.com https://*.intercom-attachments-8.com https://*.intercom-attachments-9.com https://*.intercom-attachments.eu https://*.intercom.io https://*.intercomassets.com https://*.intercomassets.eu https://*.intercomcdn.com https://*.intercomcdn.eu https://*.intercomusercontent.com https://*.stripe.com https://*.stream-io-cdn.com https://no-cache.hubspot.com https://*.hubspot.com https://*.hsforms.net https://*.hsforms.com https://api.producthunt.com; font-src 'self' data: https://builds.contra.com https://fonts.gstatic.com https://*.intercomcdn.com; connect-src 'self' https://*.contra.com https://contra.api-fast.cloudinary.com https://*.ads.linkedin.com https://connect.facebook.net https://www.facebook.com https://ingestion.apiary.beehiiv.net blob: https://www.loom.com https://prod.spline.design https://storage.googleapis.com https://*.ingest.sentry.io https://*.google-analytics.com https://www.google.com https://*.posthog.com https://*.intercom.io https://*.intercomcdn.com https://*.intercomcdn.eu https://*.intercomusercontent.com wss://*.intercom.io https://*.stripe.com https://chat.stream-io-api.com wss://chat.stream-io-api.com https://*.airwallex.com https://*.hubspot.com https://*.hubapi.com; frame-src 'self' https://embed-v2.testimonial.to/ https://www.facebook.com/ https://instagram.com https://m.youtube.com https://platform.twitter.com https://player.vimeo.com https://rive.app https://www.instagram.com https://www.tiktok.com https://www.youtube.com https://www.loom.com https://www.behance.net https://www.canva.com https://codepen.io https://codesandbox.io https://share.descript.com https://www.figma.com https://embed.figma.com https://gist.github.com https://www.linkedin.com https://assets.pinterest.com https://replit.com https://w.soundcloud.com https://my.spline.design https://prod.spline.design https://open.spotify.com https://stackblitz.com https://docs.google.com https://inquiry.withpersona.com https://storage.googleapis.com https://challenges.cloudflare.com https://content.googleapis.com https://accounts.google.com https://content-people.googleapis.com https://www.googletagmanager.com https://*.doubleclick.net https://intercom-sheets.com https://*.stripe.com https://*.airwallex.com https://*.hubspot.com https://*.hs-sites.com https://*.hsforms.net https://*.hsforms.com https://*.figma.site https://*.bolt.host https://*.dreamflow.app https://*.netlify.app https://*.lovable.app https://*.figma.site https://*.replit.app https://*.vercel.app; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; media-src 'self' data: blob: https://media.contra.com https://builds.contra.com https://*.intercomcdn.com https://*.intercomcdn.eu https://*.stream-io-cdn.com; report-uri https://o382696.ingest.us.sentry.io/api/5302437/security/?sentry_key=3545da037ee749aa92a658508243b17d;
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
camera=(self "https://*.withpersona.com/"), display-capture=("https://us.i.posthog.com/"), fullscreen=(self "https://*.figma.com"), geolocation=(), microphone=(), publickey-credentials-get=(), screen-wake-lock=(), web-share=()
Recommendations
- • Strengthen CSP by removing 'unsafe-eval'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
comodoca.com
digicert.com
; cansignhttpexchanges=yes
letsencrypt.org
pki.goog
; cansignhttpexchanges=yes
ssl.com
Wildcard CAs
ssl.com
comodoca.com
digicert.com
; cansignhttpexchanges=yes
letsencrypt.org
pki.goog
; cansignhttpexchanges=yes
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 5 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts