77/100 SECURITY SCORE

Certificate Information

Subject
CN=apps.hec133.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 12, 2025
Valid Until
March 12, 2026 81 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DB:D3:8F:D9:AD:E6:70:E6:B4:5E:1E:EA:EF:7E:51:03:1D:61:64:08:3F:97:A0:6E:CD:B1:3F:77:D6:24:B8:D5
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
develop.piletivahetus.ee

Other domains in certificate

mango.9lessons.info
track.aceunion.com
www.airsideconsult.com.br
alexandrugogan.com
mplayer.alterlatina.com
amal-hammoud.com
andregois.com
ocorrencias.app.br opsync.app.br
www.autotekvalenci.fi
www.bantachat.com
www.captain-retag.it
clarkmarkai.co.uk
haffner.clau.io
wap.clian.net
www.clotetnico.fr
www.co-herent.be
invite.iquest.com.ng
pronunciation.danmills.dev
grh-dopa.defense.bj
diamondheirsltd.ng
healthadm.portalcliente.divitech.com.br
emassie.dev
twinning.emsanakhchivan.org
enterdobrasil.com.br
www.exc.pt
farmthoughts.in
fetch.st
class.fitnesscamp.jp
www.flattlo.com
www.flirti.chat
gdl5.foodle.su
www.garciamonterde.com
session-test.gostudent.at
apps.hec133.com
hemanthpolu.store
valentyn-oksana.invito.link
www.italianwineeducator.com
www.jetstreaminnovations.com
ipm-dev1.joara.com
www.jwilbert.com
kapril.shop
keyshop.gr
displayer.kinderlabs.kr
krng.org
www.kurr.co
lachocolaterieduhautclocher.be
production.laurieanne.com
leerislekker.xyz
levelupmgmtconsult.services
www.lojix.com
dashboard.maka-bane.be
margaretbb.se
masterlimpezaehigienizacao.com.br
qa.doccsa.mayais.co.za
eli.api.mirageid.com
www.mirsall.com
play.moviola.io
firebase.myhers-market.com
www.mylogsec.com.au
app.myservicecity.com
www.newwavy.kr
www.opensource.dev
ortiagent.us
owlcavelabs.com
refund.parkyypass.com
www.partnerly.se
stage-pos.picks.com.br
purplebuilds.com
www.q-app.ch
www.qrservice.app
hunt.redsols.us
go.ridesoft.it
www.riedel.wtf
www.round1studio.com
rpghaven-app.com
safarisurfers.io
scottmaclennan.com
www.smartdevicesolutions.co.uk
smartdevpattaya.com
smartnexus.ma
moneymate.smuvix.com
alinks.speechblubs.com
demo1.stx.world
bodamejiacuellar.swanmoments.com
swellapp.co
synonym.studio
systeria.systems
client-app-stage.talent-alpha.com
heather.tallyfor.com
bubblecube.games.tetherstudios.com
www.tgrensgeval.be
www.tinyhare.com
www.tls.tools
dev.tuskr.app
volleywise.com
xconnect.xccelerata.com
www.yourai.app
candidaprofile-report.yourgutmap.co.uk