Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Google Trust Services, CN=WR1
Valid From
April 21, 2026
Valid Until
July 20, 2026
73 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C8:74:8D:27:B5:BE:29:0B:F7:04:DA:D1:12:D1:AB:6A:5E:39:EB:86:86:03:A6:41:D9:F1:50:33:4A:35:0D:D8
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
50 domains
djrioblog.com
accessoiresdemode.blog
www.accessoiresdemode.blog
www.aficariskmappingatlas.com
architecturalfinishingsystems.com
tls.automattic.com
www.benedictseggs.com
bigarmsbigissues.blog
www.bigarmsbigissues.blog
courtneyrokerlaga.com
www.courtneyrokerlaga.com
djtroyatlanta.com
dk-app-s.com
dkarchives.com
www.dkarchives.com
dkatiepowellart.me
www.dkatiepowellart.me
driftwoodspaandsalon.com
www.driveaxle.com
englishwithmissduma.com
www.englishwithmissduma.com
atomiclol.fancytest.site
www.atomiclol.fancytest.site
gharabeeb.com
www.gharabeeb.com
hadleywojtkiw.com
www.hadleywojtkiw.com
krypttza.com
www.krypttza.com
lutonlass.com
www.lutonlass.com
m3thod.agency
www.m3thod.agency
minuteexplorations.com
www.minuteexplorations.com
mionicostruzioni.it
www.mionicostruzioni.it
mirandavaughanjones.com
www.mirandavaughanjones.com
www.miscellenea.com
www.mjoelle-eschmann.ch
mleducation.org
www.mleducation.org
mmackinnonwriter.com
www.mmackinnonwriter.com
moonrisetherapeutics.org
www.moonrisetherapeutics.org
moranoeldance.com
www.moranoeldance.com
teakdropleaffoldingtables.com
Other domains in certificate