SSL Verification Bypassed
The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.
Reason:
Expired Certificate - the server's certificate has expired
Open
Cached
·
just now
62/100
SECURITY SCORE
Certificate Information
Subject
CN=dev2.goldenplateform.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
March 11, 2025
Valid Until
June 09, 2025
Expired
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B0:CB:93:FD:D8:C4:68:08:00:A1:2E:1C:5A:6A:E9:EF:73:28:C4:F6:1A:37:42:20:8E:A3:01:2B:A7:C7:78:49
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
dashmeshminerals.com
www.5f.app
oodev.abacus.co
www.aiblocks.in
anyface.ai
www.avefin.com
baroneg.com
www.bodybysatinva.pl
brendering.com
tirupathur.yazhdroptaxi.co.in
futureform.co.th
www.containcorpgame.com
cosap.bio
danno.nz
www.del-rosal.com
console.oruyo.doikougei.com
www.duckpond.app
app.eardleyco.com
test.earnin.link
widget.echo.lu
evota.uniajc.edu.co
app-eng.eintrade.eu
schuhdb.eloxo.de
fanfaars.com
www.findremotecareers.today
fusspflege-eliane.de
dev2.goldenplateform.com
www.granitebug.com
halalmerchant.com
saigonsportsclubhrm1.impactwrap.com
www.portal.jaib.live
johannarode.com
dev.justjestb.com
admin.khetose.com
korean-typing.com
kossanlund.se
registration.lifesciencesawards.ie
link.linkclassroom.com
www.luissantosdev.com
chat.luukjonko.nl
www.manuel-schmidt.biz
www.marcel.xyz
millionways.me
paopao.moderntea.ch
ctime.monoful.jp
moyaproductions.us
moonspay.mymoons.cl
nandavaram.com
nathankrebs.app
dev.next-audit.de
noisy.zone
audits-dev1.nucor.report
officeprintersbytechknowledgeyinc.com
fb.okinari.com
uniguairaca.orbiedtech.app
www.panoramapp.cl
dashboard.parkingplus.id
personalchauffeur.pl
www.playtrimmingsails.com
poodoku.app
pornstar.university
bridgespay.quitapay.com
www.raheelfarouk.com
www.realcodecity.com
stage-forms.remoteinspection.no
www.riparimeelektroshtepiake.com
rishabnt.com
www.rokinapp.com
www.rooferintel.com
app.satisplan.com
schocke.ch
admin.segurdiez.com
admin.selenity-job-evaluator.com
www.sendgate.net
signal-ri.org
skolo.dev
socialdayfest.com
www.softinmedia.com
tabify.soundworks-ai.com
telsi-admin.speakylink.com
emailbot.sprinklr.com
www.ssddroptaxi.com
www.stevenhollander.com
studiobreezy.com
www.swcollection2187.com
testmydoc.com
www.thebbfafrica.co.za
bitcoinbay.thndr.games
www.triangula.com
truehealth.truedigital.com
uckers.app
radsizer.ukradiators.com
way2lab.com
www.welldonepapers.com
www2.wickedgardengnomes.com
hideaway.willowprescott.com
app.world50.com
planner.wpooley.com
xplorepod.com
app-link-dev.yakiniku-king.jp
Other domains in certificate