78/100 SECURITY SCORE

Certificate Information

Subject
CN=app.nearcast.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 22, 2025
Valid Until
February 20, 2026 87 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EB:6D:43:18:20:6E:52:6C:8B:EA:7A:25:B5:38:1D:68:D6:8E:81:5A:D7:88:58:6C:F0:09:E3:6A:49:EC:40:3C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Weak
require-trusted-types-for; report-uri; object-src; +3 more
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Significantly strengthen CSP directives
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
dlinks.meetlete.com

Other domains in certificate

edg.12traits.com
www.adecrown.com
www.agroinnovagh.com
anandvanbeachresort.com
armstrongcleaning.co
azcuit.com
bebesleep.com
bestftso.xyz
www.bills.cool
brewbeer.ca
cems.app
chorisaga.com
foodie.clau.io
www.cloudbinder.app
www.coven.games
www.csncommunity.au
www.dawlabs.com
dazole.com
www.debtortoinvestor.com
admin.deductify.com
www.deepshotai.com
safe-hands-staging.devbeebit.com
www.diymechaniclog.com
www.dokidoki.studio
fb.dambrete-test.draxogames.com
www.dsapptech.com
demo.eatlink.co
www.entity.uz
www.erhardbrand.com
www.evolvengin.com
face-card.app
fluttery.co
stage-admin.ghuddy.com
www.gl-ph.com
haman.ca
go.haru2036.com
magic.henrydierks.com
cla.hexhoot.com
links.hometurfapp.com
dev.invessed.com
kashchawla.com
aiep-pretest.klarway.com
konfiso.com
www.ktty.nl
app.lettuscamp.com
www.lfnandoc.net
linva.net
www.lostbikes.se
web.ltl-xpo.com
www.lukul.ca
maisiesmelody.com
masayaholding.com
pcr.midiagnostico.cl
app.miradsilvalalor.ai
www.mulyam.in
muratkaymaz.com
app.nearcast.com
newsco.jp
oe18.nicoalbers.de
privacy.noiclub.net
nothingapp.app
tabsekki.notsobad.jp
nvasolar.app
octopusbrowser.com
pbh.onelastglance.com
deeplink.overtune-api.com
portal.paxi.co.za
pedrodev.net
auth.pocketrn.dev
www.precium.in
covid-19.preversalud.com
www.radiium.com
www.roaakdm.com
ronnyerkens.de
www.s2pedutech.com
scholfestival.be
www.sinocrack.in
sjfurniturerepair.com
sparkhousedevo.com
sudburypetition.uk
tlink.svasthiya.in
tbcceramics.com
help.teleboing.com
teplyakov.me
www.timporter.tech
stg.t-port-uchiiwai.tmls.jp
ugofy.com
www.viiital.com
farefirst.visa2fly.com
www.vivekmadathil.com
vppbb1.com
vuestripe.com
weddingwish.id
www.weightlines.com
staging-studio.yepic.ai
yunjeong.net
appdev.zeekdoc.com
www.ziptrax.in
namecard.zychin.com