Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=patient.albert.health
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 09, 2025
Valid Until
March 09, 2026
88 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E2:D6:F2:6B:AA:5F:A3:F7:CA:EA:D6:05:58:6F:86:AB:82:FB:4B:77:A7:B1:57:6A:4B:91:79:AB:BA:53:BA:1A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
cruzhacks.com
3attar.art
aasalem.com
ai-society-su.com
patient.albert.health
architectelevator.com
bithermit.com
enterprise.bizreview.ai
brandsnezt.com
brodiecarlisle.com
bigwin-backoffice.cbdata.cz
firebase.ccfit.app
cemsina.com
www.pianogogo.co.kr
line.karaskin.co.th
licence.consteelsoftware.com
www.corememoryrentals.com
nodeferret.archive.devget.net
www.dontforget.in
easybase64.com
twitter.edlin.app
app.efficientem.com
equinoxsolutionsmy.com
filinapps.com
www.flt.guru
admin.fornaxdiamonds.com
info.fortum.com
fusemedia.online
lensinfo.grandvision.com
home.grips.dev
halifaxweb.dev
www.htmlzero.com
www.inkomenslastentoets.nl
polisa-id.input4you.be
web.moonlander.ip-ddns.com
ipsoftware.ru
auth.itspinv.com
jeffandcaseytime.com
www.jumpstarthealthymeals.org
makers.kawatta.com
kmiteservices.com
ktkathirvel.com
asm.kwiqsol.com
app.legalbaaj.com
linkitoapp.com
www.linkmalloc.com
rader.livecasthq.com
localizapp.com
majrmech.com
covid19.supportnavi.mamafre.jp
www.maryliang.com
www.mattcrookshank.com
www.meowhalo.com
mindandcode.com
mirkaimmonen.com
www.mister-tee.net
help.moneyrebase.com
moretweet.info
morse-codle.com
nahomalem.com
nanopro.fi
on-generalservices.com
onlinediyetisyensistemi.com
www.pincer.io
www.poker-toolkit.com
app.portaria.org
poupatempoprofessor.com.br
www.poziv.co
www.promatrixinc.com
robedsc.com
staging.app.safesitecheckin.com
samclearman.com
sangeethasringeri.com
www.sanveegroup.com
www.sarinali.me
app.sharedraw.cc
www.smarterlabs.tech
console.snaprefund.io
www.spencerricks.com
steelwindows.ie
www.vorschau.strassenlotse.hamburg
www.summitcoop.com
www.swafpapp.com.au
admin.teddmegadd.hu
teohc.xyz
tinhngaydusinh.click
totat.nl
app.tradeup.ai
www.tributememorials.com
post-generator.tuntoon.com
poseidon.turnosweb.app
ultrafluid.in
exhibition.unshackled.net.au
vidyabharatonline.com
links.vooy.app
www.webinaduler.com
member.wfc-club.com
yaskravi.com
assinatura.yourder.com.br
zionsphere.com
Other domains in certificate