Open
Cached
·
just now
80/100
SECURITY SCORE
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
December 06, 2025
Valid Until
March 06, 2026
64 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
C1:70:A3:E2:0F:84:53:4B:78:51:46:C7:CA:B5:B9:33:D2:75:A2:70:66:0D:FF:0F:56:A0:31:A3:32:A9:EB:23
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Wildcard CAs
Incident Reporting
mailto:[email protected]
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 6 CAs - consider limiting to only the CAs you actively use
Subject Alternative Names
49 domains
coolfirecore.io
www.coolfirecore.io
abbotslangleynursery.co.uk
alan-may.com
atomicmommy.com
www.atomicmommy.com
tls.automattic.com
banyubirukonfeksi.car.blog
www.banyubirukonfeksi.car.blog
choi.org
svosmorazliciti.code.blog
everylanguagelearner.co.uk
www.everylanguagelearner.co.uk
freedomsocial.family.blog
www.freedomsocial.family.blog
farpish.org
www.bohemianstyle.fashion.blog
riski.finance.blog
www.riski.finance.blog
gunturtimur.com
www.jasminesblog.health.blog
ignite-your-growth.com
www.ignite-your-growth.com
www.kraeuterkuesstwein.com
lineofdefensetraining.com
www.marathacycle.com
www.massagejunkees.com
myswissledger.com
www.myswissledger.com
odetocarthage.com
www.piecedbacktogetherx2.com
ryanlabegabryan.com
www.ryanlabegabryan.com
bread.ryelle.blog
salondesassociations-agora.com
www.salondesassociations-agora.com
www.silviapolesello.com
www.biggamesapp.sport.blog
talkradioproject.com
www.talkradioproject.com
www.tanyalolonis.com
fuzzyminds.tech.blog
mytechsolution.tech.blog
prashant.tech.blog
wardrobe.tech.blog
www.gadgethigh.tech.blog
www.mytechsolution.tech.blog
www.prashant.tech.blog
theitalianloop.com
Other domains in certificate