85/100 SECURITY SCORE

Certificate Information

Subject
CN=thought-bubbles.blessingbox-ai.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 18, 2025
Valid Until
March 18, 2026 78 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
60:E8:DD:E8:5B:83:10:CC:30:D9:42:CB:20:E9:7F:28:91:F9:00:06:6D:FA:90:2E:EC:75:DA:34:F8:19:B9:B1
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=300
Content-Security-Policy
Weak
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Significantly strengthen CSP directives
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
dev.smartsite.dataauchan.fr

Other domains in certificate

agenciaportodg.com.br
www.agileo.pl
next.airlec.jp
dev.alanian.com
amry.dev
analyzee.io
andygrace.dev
www.ato-gear.com
audazcreativeagency.com
publishers.axon.es
www.badasing.com
bcgcrypto.com
benjibooks.ch
blackflux.in
thought-bubbles.blessingbox-ai.com
app.bnbflow.ai
boccuti.dev
www.brickcityhoops.com
www.casas-app.com
app.cashkaka.com
jobs.citytour1.com
climateactiontruro.org
collaborx.org
auth.compensate.com
ros1.configuradordeco.com
www.coppincamps.com
crm.datavalue.ar
digitaleburnoutapp.be
www.donteatglue.com
dourous.net
api.dynamicloyalty.ai
eficiente.co
eduplus.esparkconsultants.com
www.eth.cafe
fashionly.store
freshlinen.in
fujimaki-semi.com
www.gamemic.com
glucosa-active.com
goodonesolutions.in
journals.gpsresearchpublishers.com
sophie.hr-campus.ch
hrr.center
www.innocol.com.co
acceptance-de-ag.input4you.be
webchat.it-xp.ru
lp.itatorders.in
nutres.itera.es
jungleart.co.za
kanguru.mx
vp.katytech.com.br
www.kopsitsolutions.com
leboss.ch
www.lexer.dev
link.livingprint.com
lonelydogrecords.com
dashboard-chinmoy.magnusmonitors.com
team.mtv-gifhorn-ski.de
processor.myya.com
nemuichat.com
www.nerri.ca
fundrock.nextgatetech.com
www.optpax.com.br
www.ownliga.com
idnotes.peterjanak.dev
portal.pixietag.me
backoffice.plconnect.com.br
www.plenty.dev
porn-finder.com
www.prattmic.com
www.quantikmind.com
rashchupkin.com
manual.retailrocket.net
roastme.fun
app.saraga.id
geo.sec.live
urgentcare.sevaro.com
sharedchart.care
www.skrub.dev
www.spacetrip.agency
www.taitarestaurante.com
talentbrick.com
doctest.techilatechnologies.com
www.technossion.com
teoanastasiadis.com
teresabarrueco.com
v.thevandeheys.com
tianyichen.one
tjudd.dev
cloud.tracplus.com
agent.ufalove.com
uidesignlog.com
www.ultimateforce.com.br
lender.valos.ai
www.vendee-lavage.com
app.vilago.com
firebase.xoss.co
bel.youtabox.com
zipcomparetool.com