83/100 SECURITY SCORE

Certificate Information

Subject
CN=www.buncheedev.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 09, 2025
Valid Until
March 09, 2026 55 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
52:29:F0:02:F4:77:CB:CB:33:57:9D:9D:B9:5D:C6:1D:62:4A:C4:04:13:CB:71:3A:E3:D6:56:B4:04:27:86:9C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Good
default-src
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Strengthen CSP by removing 'unsafe-eval'
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
dev-api.careerfairplus.com

Other domains in certificate

aagenciafixe.com
go.oozi.aimpact.ai
www.alsakerhytte.no
andreealipan.com
ankitranjan.dev
ashtoncharters.co.uk
www.assignmenthelpbuddy.com
www.berkstech.club
www.blomma.dev
borintechs.com
www.buncheedev.com
cayden.games
www.cboonnag.com
mental.chronogears.net
app.tzav-rishon.co.il
www.atifelectrician.co.in
jb.codingbychad.com
www.cofemacaqueta.com.co
app.coincu.com
c.kimacloud.com.cn
phieubengoan.hinhanh.com.vn
concisegpts.com
www.cradle.dev
www.craft-itech.co
oneday.digitalgdi.com
app.dimecuba.com
www.dreamjotapp.com
crazyflie-app.droneblocks.io
www.eco7solar.com
static.ensembl.app
www.expresobollatti.com
savills.fastvalue.vn
fayzkamera.uz
www.fish2shark.com
www.forgex.forgeacademy.co.za
www.gabrielpablobarragan.com
gbbapp.com
udem-dev.gestion-traiteur.shop
auth.gotokens.io
dev.hawsinc.com
heavybagapp.com
dev.igloopos.com
alpha.impactwrap.com
interreader.com
apps.intrinsic.ventures
ivan-ally.invito.link
www.ithyx.dev
sync-spotify.jasonpoindexter.io
jimhateswork.com
kevvlar.com
zurich.kriplaney.com
www.linarit.com
pau-admin.m1studio.co
stockwatch.marketwatchapp.com
www.matthiasappelmans.be
checkout.mattildapayments.com
mii-no-hitorigoto.com
www.morima.co.jp
mrtstayr13.com
dashboard.msoftware.pk
ndogga.com
app.neurozone.com
niiodenkey.com
nomz.us
horry-dev.onelink.tw
pathadvice-stage.pathadvice.ai
www.patosaur.com
performsport.com
beautycity.piticommerce.com
poll.ly
www.repetitionlearn.com
cbr.rflex.io
www.rheagoswami.com
quiz.rionegrobar.com
billing-studyabroad.seamlessvisa.com www.billing-studyabroad.seamlessvisa.com
www.skandhaagro.com
dentibot.soklan.com
www.spindrops.org
genevieve.sprow.info
www.stunning.studio
l.sumup.com
partner-app-prod.talent-alpha.com
www.talevana.com
cd.taqui.online
www.testescolare.ro
thebananostand.com
thefour.au
theotherjacobbailey.com
theugagolf.com
tommyfan.me
on.tyme.today
gateway.umpay.io
uzbekdance.org
voto.vcoop.net
washit.com.au
www.wolphtype.com
referral.staging.woox.io
xcloc.com