77/100 SECURITY SCORE

Certificate Information

Subject
CN=money.xhuma.io
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
May 30, 2026
Valid Until
August 28, 2026 88 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DD:ED:8E:0F:FC:29:1E:B6:E6:46:BA:9E:DB:89:A6:B1:48:92:BA:72:B8:7D:1E:4B:CA:14:8C:7F:26:D0:35:01
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
ding-dong-digital.com

Other domains in certificate

yasser.abdechafik.me
adworkshop.com
homeshare.afanasev.net
akshayaheals.com
school.alexsquibbs.com
resetpwd.alosuite.com
altepeter.net
amnydn.dev
www.angulartraining.ie
www.awarenessindev.de
admin.beenfo.com
bespokesystems.net
www.bluebowfashion.com
www.brsrolloff.com
cellartech.net
cherrypick.com.br
www.cleo-childminding.co.uk
order.compass-group.no
www.cosmolith.tech
demexperts.com
derech.co.il
www.dinereel.com
www.doccib.com
cdn.earningsahead.com
www.eastrotary.org
emilypancake.com
emmanueldgz.com
galva.energia.app.br
web.goalie.enkeldigital.com
hom.crfbuilder.ephealth.com.br
weihnachtsspiel.etavis.ch
etell.me
www.eugen-i.dev
fnbce.falkor.io
farmerdash.online
wahlkabine.firlefleisch.at
fishermans-flavours.com
www.flex4sex.co.za
exp-qa-ideacloud.forgedx.com
www.h-cap.fr
hangsav.hu
harteliebe.de
admin.hataluck.jp
www.hiloshilazas.com
www.hotelgarden.pl
company-uat.hotwax.io
jayhotechenterprises.com
jsonviewer.tech
kaaralar.com
www.koroglusoft.net
cowin.kwiqsol.com
www.kyuen.co.uk
letsreviewit.co.uk
www.libcyberarm.online
chennai.loyaldroptaxi.com dindigul.loyaldroptaxi.com erode.loyaldroptaxi.com nilgiris.loyaldroptaxi.com pondicherry.loyaldroptaxi.com
maceioparaeventos.com.br
www.matchhai.com
mathuoso.com
measures.me
mesconges.info
mintmoves.life
painel.mobilizei.com.br
hello-firebase.moukaeritai.work
myworkbox.link
niklas-noise.space
sports.nirvana-groups.com
www.orthodoxcoins.com
www.pathtofit.me
link.peppy.health
pumptrack.pl
www.robotplaytime.com
gmtv.rugvedkoshiya.in
sandbox.demo.members.sargon.com
server.sarmad.xyz
satyapara.com
www.shoppinglive.fr
seller.shopsogood.live
www.skyemotors.com
skylintechnology.com
smarterlabs.tech
test.nft.thecoin.io
www.thedreamlife260.org
thenowtimes.com
thequickcalc.com
theweddingwhites.com
console.dev.thingware.net
www.thomascowder.com
dl.ulesson.com
auth.unthread.io
vida-launchpad-stg.vdms-remote.com
wiseacre.app
www.worlddomination.group
www.writer.solutions
wukoin.wukongproject.com
money.xhuma.io