Open
Cached
·
just now
78/100
SECURITY SCORE
Certificate Information
Subject
CN=featherco.de
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 30, 2025
Valid Until
February 28, 2026
87 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
48:5A:48:7C:C0:8F:C6:DD:F2:61:D5:9B:43:68:52:2A:3A:01:E5:C6:D6:4B:62:F7:83:1D:33:11:EF:57:AE:19
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
require-trusted-types-for; report-uri; object-src; +3 more
require-trusted-types-for 'script';report-uri /_/DurableDeepLinkUi/cspreport,script-src 'report-sample' 'nonce-0JnwfKcrDVuIqr7WdDaCeg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DurableDeepLinkUi/cspreport;worker-src 'self'
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Significantly strengthen CSP directives
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
devapp.1timesports.com
geiger-modular-test.3dcloud.io
json-translator.404-labor.de
www.aarootshi.com
www.adambathie.com
adamliu.page
alpenfruechte.de
andrewjdillon.com
joke-teller.anusha.dev
rentmates.appstruct.in
www.arete.li
aadmin.aspirantsprep.com
austincumberlander.com
www.autx.net
auvaan.com
www.baltcoda.com
www.uniform-numbers-mlb.baseball-connections.com
kurancili.bel.tr
app.berkeliumlabs.com
bhidiroglu.com
admin.bidmii.com
bigda.me
birkman-beratung.de
bluejay.dance
codenames.braican.com
brians4paws.com
budubana.com
c2view.cloud
carlisleselfstoragellc.com
app.chatsooner.com
external-components-dev.codedesign.ai
simrikasubedi.com.np
www.kentakademi.com.tr
www.console.communitilocal.com.au
log-inspecciones.cydocs.cl
dannyglavan.com
auth-dev.deedz.net
devoltech.com
demo.dielink.ca
eh-widget-dev.ellipsishealth.net
www.elsa.id
www.evernest.io
exaltrates.trade
www.fcortesnila.com
featherco.de
fotoenblan.co
tools.goudsteen.nl
honeycomb.chat
development.app.hoofbid.com
admin.hvakr.com
auth.test.immo-data.fr
auth.intechopen.com
jangid.co.uk
scottrv14.jaredsolomon.net
www.julebobler.no
juniorhr.com
backpack.k12ahisd.net
kahitoz.com
kegeltrainer.app
khitma.net
lauragarciahernandez.me
www.lecoursville.com
www.lime-tracker.com
www.linuxgames.com
auth.lorii.ai
www.map-x.jp
ppe.moteev.store
station-app.mylock.es
thefibsbycharlesai.ninfa.io
beta.nurseid.io
openintervue.com
ottoschool.org
pay.pfstaging.xyz
stage.triunfo.photofied.tech
promilapratap.com.au
dev.pymes.cloud
refwell.net
punchbeta.sahlhub.com
samaitests.scontinent.com
securetix.net
matrimony.sheikhsoft.com
sis-bau.info
www.sis-sanierung.info
sophoselectronics.net
souqtajer.ma
spaziovettoriale.it
www.spaziovettoriale.it
vendedores.srconstruccion.com
www.symphonist.net
www.synworks.jp
www.tabrezdal.com
lista.templat.dev
tools.tnshipping.us
www.ulog.ai
www.unrealcoach.com
dev-cms.urcupcafe.com
staging-cms.urcupcafe.net
vignesh.tech
workhonesty.com
app.zero1-mtl.com
Other domains in certificate