Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=club.agroskills.com.br
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 26, 2025
Valid Until
February 24, 2026
87 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9C:76:2D:A9:4A:5A:F3:E2:63:B1:B7:E1:40:99:A6:34:4C:D9:10:B5:39:C8:82:E2:E3:2C:F0:6F:1F:4E:CB:F1
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
dashboard-stage.propeller.ba
sb.7tam.net
share.90s90s.de
club.agroskills.com.br
www.aldrenet.com
www.alfaradi.com
stg-app.anytag.jp
www.apitests.dev
satisfactory.appelent.nl
www.apron.cloud
askjoe.site
auroravision.nz
focusmodus.biem-gaming.com
www.bongda.eu
www.carevalet.com
cinarlaw.com
www.clashbasepedia.com
coderexploder.com
events.coditas.com
text.coffeeandmotivation.com
saibou.cpn-othellonia.com
ledovaplocha.ddmpraha.app
mikulas.ddmpraha.app
www.defensiqtech.com
deshna.life
www.drtriumph.com
www.ecbase.io
edujobs.uk
verify.enabledb.com
www.ericdetjen.com
staging.evfy.sg
exciterfashion.com
www.fabricaderedacaoonline.com.br
www.fingermanga.com
fitnesspilatesmullingar.ie
kubeit.flairtechno.com
fronterasky.com
www.fungamestoplayathome.com
ganapp.gana.com.co
www.garuzo.com
www.glowupmyresume.com
greenenergycorp.net
hannythecore.ch
auh-dev.havemony.com
hcesonepat.org
www.healthlynx.co
internal.healthplexfitness.com
www.highwaydroptaxi.com
www.igotcho.com
iipvapi.com
queue-coworker-prod.digitalse.ikea.com
rater.integralagility.net
itnecommerce.com
video.jemedia.org
jfortunatojr.com
backoffice-test.ka-ching.dk
beta.labddb.site
lapengtutors.com
likeacoffee.com
gis.lingmaps.com
www.localiq.app
novaxia.louveinvest.com
www.lowkey.dk
miksing.com
my.mindsum.app
mindyourtax.in
app.navneets.com
ourshoppinglist.nilsallmeroth.de
npcgym.se
www.octopusbrowser.com
omerfaruk.dev
pasapass.com
www.plenty-of-pooches.org
test.prematax.com
mentor.productmarketingalliance.com
remoteos.io
staging.revenue.resbutler.com
sanatmente.com.co
admin.seanpautzbio.co.za
seegull.org
mailer.sevseux.me
www.shepherdathleticcamps.com
shopjob.uk
facedev.spiolabs.com
sports-safety.com
devplay.taptapwin.com
techwithaoun.com
tenteams.co.uk
thumble.it
tickets-onchain.com
unitysworkbench.com
uo-dok.com
usskimya.com
link.dev.vetster.com
www.vianiassicura.it
vimigaa.com
app.vurbis.market
www.yakkstones.com
moments.ylsideas.co
staging-social.yumitos.com
Other domains in certificate