Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.monach.horseriding.app
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 29, 2025
Valid Until
January 27, 2026
66 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9C:67:3A:F3:71:6A:25:B5:24:BE:09:A5:1B:76:68:CB:9A:76:41:D8:D4:46:73:B7:70:99:4A:31:EB:1F:7E:52
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
coplur.com
join.2l-lab.com
app.abhishekc.design
wavelengthtraining.ardent-training.com
staging-mcp.armor1.ai
join.audry.io
auryonlabs.com
aviatoracademy.net
premiacoesagt.beflyconecta.com.br
blackmammoth.ph
chelseabenson.com
app.civi.fit
www.app.civi.fit
www.civi.fit
climaki.com
clinicaneuromuscularcr.com
ourfundi.co.ke
halitbaykan.com.tr
smartlogic.com.ua
www.conviviodining.co.uk
salone.davidecampello.app
www.dispatchy.io
drfiruzaparikhathnreliance.in
www.eaglixconnectivity.com
editor.ecombuddha.ai
app.engage-iq.io
join.erioon.net
fancore.app
farmaciadeguardia.app
forecash.io
www.friendlycompetition.com.au
www.garrettquintplastery.com
glowbyanelisa.co.za
gokulkamali.life
www.graphidas.com
www.hairbazaarstudio.pl
profile.harshaljoshi.in
www.monach.horseriding.app
www.hqdigital.store
www.infinela.sk
www.infolineemat.it
itmizer.com.br
kamakshielectronics.com
www.kamzinternational.com
keraai.in
www.kreamining.cl
games.kreo-tech.com
kurosaba.fun
www.lepsidom.at
www.lovelymedia.co.uk
luichigo15.app
sobremesa.manjarliterario.com.ar
metabolife.health
mype.co.uk
myviscer.co
www.transconvida.org.br
www.ortalum.com
www.ourwalletsourpower.org
ownerisgodpay.net
pakavaka.ru
sparky-framework.cdn.fed.apps.paloaltonetworks.us
www.pecuschain.com
bestellen.pizzalaluna-moers.de
company.ploou.com
primeaudittools.com
pumpclick.io
qlabstech.io
racefin.co
checkout.rapidpay.pk
ogcbrowser.rauhala.app
sas.reimscoworking.fr
resumeofjoshlee.com
shop.sandunsiwantha.com
lexiconquest.schoolbase.org
secretlife.in
sellstr.ca
serprogas.com.mx
seshavidyashramcbse.com
app.slim-with-me.com
smartwaydesign.hr
www.smartwaydesign.hr
srikanthcars.com
stalkersfilmsim.com
www.stalkersfilmsim.com
superfive.io
eclass.synth365.com
sorting-speed.szabonorbert.me
toptechauto.net
trackcourierstracking.in
tryultra.app
twigl.app
app.ucast.com.au
www.vaagaichikitsalaya.com
vacationconnects.com
www.vacationconnects.com
vanqueo.com
app.speeltuin.watdrinkje.be
presenca.wdsolucoes.com.br
charts.winy.ai
xpenzora.com
Other domains in certificate