Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.privogram.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 09, 2025
Valid Until
February 07, 2026
78 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7D:AA:9F:DB:CD:49:B3:8F:8B:53:36:39:84:B1:12:DF:ED:CD:26:CC:60:9A:F4:19:1E:FE:70:16:0C:D4:AC:FB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
dinatus.com
booking.alquarto.it
altimaconseil.com
www.ancimed.com
www.aphasiarehabtherapy.com
robattle.apm2.studio
auth.stage.assetron.dev
astlax.com
auralogiclabs.com
babycools.be
bandmatic.app
i-got-this.barin.app
beruehrungs-punkt.org
shree-shyaam-printing-press.bidonad.com
bigodigital.nl
www.bjb26.at
recoveryapp.bounce.bike
demo.onboarding.camiapp.net
ssl2.ship.chowari.jp
print4me.thearchitect.co.in
crm.ulusalyesilenerji.com.tr
cqcontrolcenter.id
datameans.com.br
www.drfixy.ai
elizaryan.com
staging.enklakassan.nu
new.exptrax.top
user.figosaude.com.br
futuredroptaxi.in
ticksy.futurense.com
www.gaetanoracioppa.it
order.goshweet.com
gratutitycalculator-uae.ae
greenworkstrees.com
www.greenworkstrees.com
gurukulamhostels.in
paysli-dev.handclap.jp
dxt701.id.vn
agendamentos.microsys.inf.br
institutoterapeuticoloto.org
www.isidoorhemiksem.be
jahajwala.com
www.joincrossd.com
kaiscabin.com
krantisetu.in
www.krantisetu.in
krearthmoverscoimbatore.in
www.krearthmoverscoimbatore.in
www.lesstrace.com
tattoos.likeahe.ro
www.lwbb.cz
manhwa-tracker.mahifaiyaz.ca
market760.com
www.michaelandmacie.com
mlegis.it
altairglobal.demo.movello.se
real3.kitaro.my.id
mentor-dev.neccton.com
mentor-stage.neccton.com
nexara-ls.com
www.nexara-ls.com
auth.omara.at
flightfolio.oracleaviation.co.za
www.oxygentech.com.au
pathifyai.me
www.pcbcorex.com
app.peztime.com
polarisai.dev
www.privogram.com
qryonix.com
www.qryonix.com
quibal.com
relaydesk.trade
www.reuseprimeapp.com
www.revelto.app
sergemilien.be
www.shoplite.rw
harveys-group.shotextract.com
www.slopebear.com
www.sockeep.com
school.subashreepublishers.com
staging.surescoops.com
test.surescoops.com
internal.tak-tech.com
taxiadministration.se
techspicyx.com
affinity.tectes.com
thedivineshealth.com
www.thejasdental.com
www.themandies.com
toroconsorcios.com.br
tortly.ro
masterkey.id-dev-tbzg3.tumbleweed.jp
twotreesapps.com
banshee-dev.universalvoice.nl
villagemarketfairfield.com
webtoolgames.com
wiscostumps.com
www.wiscostumps.com
www.workflowdigital.ro
Other domains in certificate