Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=app.gaminggoat.io
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 23, 2025
Valid Until
February 21, 2026
86 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
06:87:87:56:F1:A0:A3:D2:15:99:16:34:69:5E:EC:CA:7C:1C:E3:21:2F:BA:D7:BE:C3:43:47:14:96:FC:B0:2B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
demo.platea.info
alphabio-digital.net
www.amplifynature1.com
www.bigquery-json-schema-generator.com
tools.bluetreelab.net
falcon-admin.bluewhale.kr
boogaloo.io
www.carpincho.es
www.cashpay.healthcare
cauto.in
www.chd.su
ciastomaniak.pl
backoffice.citypop.app
phuthogroup.com.vn
stories-dev.comobi.io
apoderados.contigojuegoyaprendo.cl
dl.cormeumapp.com
www.dikshaiet.com
docs.divconcontrols.com
donate613.com
embedmaker.com
eumepego.com
excel-arete.com
glosolan.review.fao.org
www.fncapital.ca
upload.frastas.com
app.gaminggoat.io
app.genit.ma
collateral.gokyolabs.com
www.grouple.app
data.honikan.pl
ajgav.ind.in
fuelamerica.inseat.menu
www.itcginc.com
id.janitza.de
weather.jeffreylobato.com
kooiman.dev
www.kooiman.dev
www.lanubo.net
preprod-studio.lesvieillessouches.fr
lightonkundaliniyoga.com
vdi.loap-software.com
lol-roulette.es
dashboard.lovemob.io
cn.marsgranite.net
martincai.com
mbility.eu
kiosk.prod.medeintegra.app
mesh-hq.com
eleevateoverseas-mba.metis.club
medopen.mka-karate.org
app.moon.ac
msbri.me
devfest2019.mscc.mu
mura-wallet.io
www.neurolify.com
www.nicathletics.ca
nuestrasalud.info
portal.oomphwellness.org
www.oraichainlabs.org
admin-dev.origamiwash.com
merillife.iotbit.otobit.com
www.pearlescentsounds.com
violeta.pedidomovil.es
www.phuketfete.com
www.pixelentertainment.de
sso.stg.postprime.dev
www.rhodium-iv.com
riskeeper.global
www.riskprofiler.co.za
characters.rpg.solutions
www.sam-techs.com
www.setting4u.com
www.smallbands.be
www.so-vera.com
www.socialteetime.com
sonaksdp.com
www.spaceduck.io
www.spacewarriors-club.com
www.spicexchangeindia.com
triviadecredito.sqwadhq.com
starkit.es
quran.suhaib.in
www.en.tenczyninfo.com
buyingmgmt.texone.app
app.theliben.com
lp.thrill-in-love.games
tobiak.com
www.tradebycode.com
angular.uchisen.com
wallet.walletpayment.net
warlock.games
weekme.app
weight-tracker.app
www.money.wesselbuchling.com
login.wetrans.in
www.whyaftab.com
www.wunderklub.com
wzhang-sampling.page
www.covid19.zoiclabs.net
Other domains in certificate