Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=static.onebadapplenow.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 17, 2025
Valid Until
March 17, 2026
46 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A1:CA:24:6A:23:88:A6:3E:91:63:11:FB:F9:9B:DC:CA:E7:AF:D9:07:38:E2:C5:5E:38:22:A3:EF:9E:6D:6E:C0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
darrelllove.com
app.1gravity.com
abogadomacarena.cl
acee.cat
www.acuronai.com
www.affordableappliance.net
meli.alejandrotiria.com
alquilerlabarrosa.es
www.anandmaurya.in
aphroditeproject.co
auranalabs.com
app-staging.be-hookd.com
bloopfishfarm.com
blumelabs.in
breakcoregivesmewood.org
issuer.brex.vc
cardapiocloud.com
www.cardosmedia.com
casagris.dev
app.crossconnectedapp.com
www.curtisgoud.com
links.dicomlab.com
drifting-ai.com
empatheticbyte.com
bc.ereo-creatives.com
exitz.app
www.expensifire.com
explorehc.com
freehold-realestate.com
www.freehold-realestate.com
www.getgameplan.com
getitcodified.com
www.growtech-in.com
growurmedia.com
test.sonon.healcerion.com
hexill.com
www.uat.howlingwolfe.com
complement.iamdeveloper.es
elitepf.impactwrap.com
tmn.it.com
mobile.hyper.itmsgh.com
jesuscmx.dev
status.jungroup.com
junkbot.dev
kavalastays.com
keraa.co
kopano.ai
kreatedeck.com
zero.dev.kubershmuber.com
bedu.lapieza.io
www.larmcr.com
app.loqly.dev
www.macacomaya.com
markatlarge.com
masalskis.io
navotkarshaitsolutions.com
newthetaxihouse.com
demand.noneho.com
novasnatch.com
srsorders.nybgf.com
static.onebadapplenow.com
oraxai.com
www.osrsrecords.com
sandbox.paincareoregon.com
paul-koehler.dev
www.playmobility.com
pluzloyalty.com
babylullaby.portalgroove.com
ramonenses.com.mx
wholesale.redskydesigns.com
rainbow.redsoftware.in
talentex-thaiteam.reflect.page
richvisionacademy.com
www.richvisionacademy.com
overlays.rtirl.com
vtc7.simpliroute.com
www.snippbits.com
softfortoday.com
soluweb.com.ar
nxo-telecom-app.speakylink.com
nxo-telecom.speakylink.com
spectrum20kw.com
wmubasketballsw.sqwadhq.com
staige.ch
taleturns.com
tecky.be
the-hidden-chapter.com
www.thebrainshapers.com
www.theworldsbiggestchatroom.com
www.tiendadeturismo.com
app.timesofisrael.com
tirelesstrader.com
zeatunaessence-referral.tspacedata.com
underpressure-app.com
www.voisincapital.com
wfares.com
criczone.xtraclasses.com
yalphenix.com
yunyounglee.com
www.yutakaintertrade.com
Other domains in certificate