Open
Cached
·
just now
88/100
SECURITY SCORE
Certificate Information
Subject
CN=imperva.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2025 Q4
Valid From
November 26, 2025
Valid Until
May 25, 2026
132 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
49:5C:B0:A6:B6:B1:CC:8C:77:D5:47:B5:BA:13:95:EF:A8:44:C9:9E:52:8E:DB:C8:AF:CB:18:7E:DA:04:F0:09
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
script-src; script-src-elem; frame-ancestors; +2 more
script-src 'self' 'nonce-815a327e00434e84058d3d2572f8ff86' 'strict-dynamic' 'sha256-3Q7Fer8VTVLBYfrpLbYBTwQkF9lmBnkJeuVShwQexS4=' 'sha256-Y5IFCmhYJPeYnnxHExQbP71aYPdfo8QhW52lqZ3+e8s=' 'sha256-pEbW1vfmjdEXxHaLC2MsW7FC79gH/35q+LEsXPH5vpM=' 'sha256-cH01299cZjq8b/f0ckDCzJP0qmI7L42T6JQdKnaW17g=' 'sha256-PeCBPuhqzZB21Syy61T2kFckbFtt7p1Op6K4ir2SoP4=' 'sha256-7ZLbZOp/U87ra/W1xjXAbujkCGRI0H0ouZM3uQiMoXg=' 'sha256-K1EvWOm2FWNOEX1/1prAtZhEFqHPu5J3bnu5uZ9vGAQ=' 'sha256-euuuZNr+eaDixtsO5Zp6wEpaN1qB33RCkHW55SNE78c=' 'sha256-taDM5hlEU3GKhB8zqkqzmJ/2GyuX88T+Vaa3jRyD9Uo=' 'sha256-Y5IFCmhYJPeYnnxHExQbP71aYPdfo8QhW52lqZ3+e8s=' 'sha256-PeCBPuhqzZB21Syy61T2kFckbFtt7p1Op6K4ir2SoP4=' 'sha256-7ZLbZOp/U87ra/W1xjXAbujkCGRI0H0ouZM3uQiMoXg=' 'sha256-K1EvWOm2FWNOEX1/1prAtZhEFqHPu5J3bnu5uZ9vGAQ=' 'sha256-euuuZNr+eaDixtsO5Zp6wEpaN1qB33RCkHW55SNE78c=' 'sha256-ZdDTEfl8xrGn7iZ/2mMDizDIe6JRmep2vz9STHJi4Zs=' 'sha256-taDM5hlEU3GKhB8zqkqzmJ/2GyuX88T+Vaa3jRyD9Uo=' 'sha256-s1/jMWC705QbAX8+P4Ty1Ce8EMOeuAGqI+hJ+pyK+gM=' 'sha256-PRMWS4ECvr6YujA6g9ufhzIjsfD/0/Mj0MvHIZXk+5U=' 'sha256-u4lsTgfOCZMrfyPr+Rbh0h5gStzCz8oAcS9duESdRUM=' 'sha256-1rWysHw8RNR5A5g0ClWRDZknrWAfmV2OzlI6EaIj6kA=' 'sha256-M7AuWmSvpzFQm4SS8EePwuJNQCgMLFr52oz6le6TEsg=' 'sha256-oWdPUohf0zSZdOunpZD2EKpOeXpV5XsHveey7nijmlE=' 'sha256-/08+/pOIbP2O/MDoeI7B0Gmc9Dw7xUk7errprXPtcn4=' 'sha256-rm73FNM100MK8Q7OQA44UblVHfjVjGe1R2RLLrbf9yw=' 'sha256-iYoImlxV+SuExv63r0FRgV8nLxEedfFtm4p2f0U04Pk=' 'sha256-Uz0yn00PqpvyPuK+MptaAirzRCPwuCU4Vhj/iAbfJxk=' 'sha256-pSKoa5DbpWOyKoO3mAdwvShgFxkhqYpdHZrzhWY+/IA=' 'sha256-l9qCt/biX7q1hPnjVaa6uFB/ZE6J6DL1zE8jcp+ymG8=' 'sha256-PRMWS4ECvr6YujA6g9ufhzIjsfD/0/Mj0MvHIZXk+5U=' 'sha256-bcB+2Flb43KiqxHny+wUQIAHKW9WtTOot4cLUfJckWQ=' 'sha256-Ns8iiUSFKbT1I3cdYhn5yrR2ZDy0arXwT3iT4yM2D1g=' 'sha256-Sp6ckhRSfiqC2HJ9pQZzWyOqePJvlA9avbxyvurnCQY=' www.google.com www.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net tpc.googlesyndication.com www.youtube.com consent.cookiebot.com consentcdn.cookiebot.com libraries.creatio.com marketplace.creatio.com d3a7ykdi65m4cy.cloudfront.net maps.googleapis.com www.influ2.com js.intercomcdn.com widget.intercom.io bat.bing.com connect.facebook.net s.yimg.com a.quora.com sc.lfeeder.com ws.zoominfo.com a.plerdy.com cdn.jsdelivr.net cdnjs.cloudflare.com polyfill-fastly.io unpkg.com webtracking-v01.creatio.com mdbootstrap.com ct.capterra.com www.getapp.com js.stripe.com devakatalk.com pixel.byspotify.com snap.licdn.com tag.demandbase.com script.hotjar.com static.ada.support ddwl4m2hdecbv.cloudfront.net scripts.clarity.ms dev.visualwebsiteoptimizer.com; script-src-elem 'self' 'nonce-815a327e00434e84058d3d2572f8ff86' 'sha256-3Q7Fer8VTVLBYfrpLbYBTwQkF9lmBnkJeuVShwQexS4=' 'sha256-Y5IFCmhYJPeYnnxHExQbP71aYPdfo8QhW52lqZ3+e8s=' 'sha256-pEbW1vfmjdEXxHaLC2MsW7FC79gH/35q+LEsXPH5vpM=' 'sha256-cH01299cZjq8b/f0ckDCzJP0qmI7L42T6JQdKnaW17g=' 'sha256-PeCBPuhqzZB21Syy61T2kFckbFtt7p1Op6K4ir2SoP4=' 'sha256-7ZLbZOp/U87ra/W1xjXAbujkCGRI0H0ouZM3uQiMoXg=' 'sha256-K1EvWOm2FWNOEX1/1prAtZhEFqHPu5J3bnu5uZ9vGAQ=' 'sha256-euuuZNr+eaDixtsO5Zp6wEpaN1qB33RCkHW55SNE78c=' 'sha256-taDM5hlEU3GKhB8zqkqzmJ/2GyuX88T+Vaa3jRyD9Uo=' 'sha256-Y5IFCmhYJPeYnnxHExQbP71aYPdfo8QhW52lqZ3+e8s=' 'sha256-PeCBPuhqzZB21Syy61T2kFckbFtt7p1Op6K4ir2SoP4=' 'sha256-7ZLbZOp/U87ra/W1xjXAbujkCGRI0H0ouZM3uQiMoXg=' 'sha256-K1EvWOm2FWNOEX1/1prAtZhEFqHPu5J3bnu5uZ9vGAQ=' 'sha256-euuuZNr+eaDixtsO5Zp6wEpaN1qB33RCkHW55SNE78c=' 'sha256-ZdDTEfl8xrGn7iZ/2mMDizDIe6JRmep2vz9STHJi4Zs=' 'sha256-taDM5hlEU3GKhB8zqkqzmJ/2GyuX88T+Vaa3jRyD9Uo=' 'sha256-s1/jMWC705QbAX8+P4Ty1Ce8EMOeuAGqI+hJ+pyK+gM=' 'sha256-PRMWS4ECvr6YujA6g9ufhzIjsfD/0/Mj0MvHIZXk+5U=' 'sha256-u4lsTgfOCZMrfyPr+Rbh0h5gStzCz8oAcS9duESdRUM=' 'sha256-1rWysHw8RNR5A5g0ClWRDZknrWAfmV2OzlI6EaIj6kA=' 'sha256-M7AuWmSvpzFQm4SS8EePwuJNQCgMLFr52oz6le6TEsg=' 'sha256-oWdPUohf0zSZdOunpZD2EKpOeXpV5XsHveey7nijmlE=' 'sha256-/08+/pOIbP2O/MDoeI7B0Gmc9Dw7xUk7errprXPtcn4=' 'sha256-rm73FNM100MK8Q7OQA44UblVHfjVjGe1R2RLLrbf9yw=' 'sha256-iYoImlxV+SuExv63r0FRgV8nLxEedfFtm4p2f0U04Pk=' 'sha256-Uz0yn00PqpvyPuK+MptaAirzRCPwuCU4Vhj/iAbfJxk=' 'sha256-pSKoa5DbpWOyKoO3mAdwvShgFxkhqYpdHZrzhWY+/IA=' 'sha256-l9qCt/biX7q1hPnjVaa6uFB/ZE6J6DL1zE8jcp+ymG8=' 'sha256-PRMWS4ECvr6YujA6g9ufhzIjsfD/0/Mj0MvHIZXk+5U=' 'sha256-bcB+2Flb43KiqxHny+wUQIAHKW9WtTOot4cLUfJckWQ=' 'sha256-Ns8iiUSFKbT1I3cdYhn5yrR2ZDy0arXwT3iT4yM2D1g=' 'sha256-Sp6ckhRSfiqC2HJ9pQZzWyOqePJvlA9avbxyvurnCQY=' www.google.com www.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net tpc.googlesyndication.com www.youtube.com consent.cookiebot.com consentcdn.cookiebot.com libraries.creatio.com marketplace.creatio.com d3a7ykdi65m4cy.cloudfront.net maps.googleapis.com www.influ2.com js.intercomcdn.com widget.intercom.io bat.bing.com connect.facebook.net s.yimg.com a.quora.com sc.lfeeder.com ws.zoominfo.com a.plerdy.com cdn.jsdelivr.net cdnjs.cloudflare.com polyfill-fastly.io unpkg.com webtracking-v01.creatio.com mdbootstrap.com ct.capterra.com www.getapp.com js.stripe.com devakatalk.com pixel.byspotify.com snap.licdn.com tag.demandbase.com script.hotjar.com static.ada.support ddwl4m2hdecbv.cloudfront.net scripts.clarity.ms dev.visualwebsiteoptimizer.com; frame-ancestors 'self' *.creatio.com; object-src 'none'; base-uri 'none'
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports