77/100 SECURITY SCORE

Certificate Information

Subject
CN=lacontenthouse.ca
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 23, 2025
Valid Until
December 22, 2025 36 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
AB:EF:E2:B4:93:65:2E:63:89:8C:D4:FC:AF:8E:F7:17:75:C0:C8:AD:15:69:1B:97:87:D0:E5:3D:2A:F9:3F:95
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
dev.drone-roofer.com

Other domains in certificate

jbmhrd.app.1on1navi.com
3regularguys.com
adeoedu.com
www.aetheresemporium.com
aicyellowjacketscamps.com
enterprise.ailumia.com
www.alburycleaningservices.com
www.alexherigon.com
www.anthonylallo.com
garrawayf.console.appabrik.jp
app.appotahome.com
voice.artobai.com
auth.ascendex.com
atiyax.com
atwspl.com
sizechart.apps.avada.io
bambanada.com
bottleneckexplode.com
www.bramhascientific.com
www.chirurgie-os-nador.com
elmin.com.tr
comproautoverona.com
www.constellation.xyz
www.creatio3d.com
cristinajuanpere.com
croissance.ng
cryptotea.fun
defensasonora.com
seminuevos.depfly.com
desorganizando.blog
www.downloadsaur.com
q2-pickup.dpdlocal.co.uk
eazyprop.com
dev.evryw.in
app.fan.ai
intranet.fibrastorage.com.mx
flixgateway.com
fractalmakers.com
www.gauranshsharma.com
geminiflow.io
studio.gruppo4d.com
gynmarketingdigitals2.com.br
app.harlan.fr
howtoquarantineathome.com
worc.hrestart.com.br
humanitydraw.com
ipatchpwa.xyz
iplog.fr
jobaustralia.com.au
dev.jonas-wanke.de
members.jrfd.ca
kadamclasses.com
www.koruq.com
lacontenthouse.ca
lerada.co
app.licitou.com.br
www.lilypianostudio.com
loahoctienganh.com
mobile.loveyourmother.beer
www.manvithapackersandmovers.com
marshallmutualinsurance.com
flywheel.merkleinc.com
vrp.midnight30studios.com
miriamly.co
nathaliesaab.com
dev-owner.nobunaga.life
www.noiselimited.com
join.nor.by
www.nrg-series.com
nzsapps.com
onezone.co
www.orddum.com
plaisance-records.com
my.beta.plantiga.io
www.poetryofthemachine.com
app.propely.no
prod.randivoo.ma
regexhost.com
resonanthypnosis.com
www.rundekultur.no
ryanhenneboehle.com
devfest.sanddollarapps.com
www.searchgita.com
sktravels.skybilling.app
sortear.click
soundsbutter.com
sherborne.sprxvr.com
www.srigowripackersandmovers.com
stedu.vn
syukyoma.com
todo.tap-software.com
www.planer.tbm-event.de
hr.texone.app
stories.thewholetruthfoods.com
memo.ugurdinc.ca
auth.app.undock.com
vb.vocalbrain.com
www.wasm.org
sms.xicall.com