91/100 SECURITY SCORE

Certificate Information

Subject
CN=storylabs.app
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 14, 2025
Valid Until
January 12, 2026 49 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8D:EC:25:44:A2:B2:62:90:2B:74:A4:EE:D9:CD:62:19:1A:3B:A0:7F:99:C1:44:ED:94:C7:30:55:34:A6:3A:E1
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=15552000; includeSubDomains
Content-Security-Policy
Good
default-src; base-uri; block-all-mixed-content; +8 more
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Strengthen CSP by removing 'unsafe-eval'
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
dev.api.zipeli.com

Other domains in certificate

headucation.1000heads.com
www.adometa.com
alexindojayaamerta.com
anthonyharm.com
www.arnozwaag.nl
iot.baliniot.in
betbabaia.com
stage.biobarica.com
bnovalab.com
www.cantemosbingo.com
care-keepers.com
admin.qa-prod.cargamos.com
casph-royal.com
mfe.staging.castingapp.com
www.centralgovtjobs.com
app.checklist.info
www.chikach.net
metaspaceinteriors.co.in www.keeper.co.in
en.ktevotech.co.th
code-gym.de
portal.coderivy.net
c.colmi.info
pagos.corntech.com.mx
curseofeternity.com
daniel.systems
try.deskbooking.app
app.duna.games
www.elizabethkiselev.com
emojinfo.com
www.eventosr2.com.br
www.facadecalculator.com
frosttelehealth.com
app.fumumu.net
korea.furikuri.net
yais-ci.gda.sa
diest.gemeenteraad.live
beta.gokind.app
gsquid.xyz
v2.hutupia.com
dioovhv.id.vn toanvu7204.id.vn
imdadshafi.com
ambulans-sahlgrenska.infosynk.se
interactiveoasis.com
www.kbkouc.sk
king.dev
kiplog.be
app.kit.fit
www.limitless.ninja
niigata.linx.live tokushima.linx.live
www.lorinallred.com
marcioautomoveisptc.com.br
www.mayacatering.nl
www.dashboard.oaimstudio.com
opdig.com
upversion.opteksolutions.com
oravskedomacecestoviny.sk
ordertoeat.ca
ascor.partnerhub.co.za
pavlinafuchsova.cz
psclient11169.philanthrosphere.com
www.pinstopconcierge.com
www.policoders.com
www.produvar.nl
www.qleanlabs.ru
barracaeuropa.queliga.com
red-pinks.net
www.square.frontend-challenge.ronne.dev
www.rutlandplastering.co.uk
www.samslogix.com
sarvasolar.in
sunnybrook.scheduleteam.com
powerhour.schism.co
www.serviwindow.com
home.shinnova.io
www.shobhitsharma.com
chat.siwoo.xyz
slyn.asia
j146mp0czgicnj1pqf37.smartimob.io
specifiq.ch
www.srtdbrasil.com.br
portal.alertaclaro.stefaniniinspiring.com.br
storylabs.app
tecgos.com
colours.terpity.com
www.tharkuritech.com
achija.thediners.in
www.timesmeter.com
dev.karaoke.topia.tv
send.toshimomo.net
tsjat.com
www.vanramsey.com
gestiones.watsy.io
wealthspaces.co.za
www.wgcouch.de
auth.wittopkoning.nl
www.worldsystech.com