Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=davidpellegrini.ca
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 04, 2025
Valid Until
March 04, 2026
69 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C0:CE:31:D3:0C:17:D9:86:A4:BA:19:C7:17:63:E8:9C:61:4C:E1:B1:BE:09:66:0E:FF:D9:89:51:57:B0:68:C3
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
durandenterprises.com
scp-product-config.3dcloud.io
go.3harmfulfoods.com
3th.biz
akerboom.family
www.akvotech.com
www.apphause.co.uk
architecturewithnico.com
armyleadersbook.app
www.artbyval.ca
www.austinandlajos.com
billetera.bestcard.com.ar
bill-masters.com
bryankenneth.com
dev-connect.capturs.com
clubberpeople.com
www.codeblenders.com
anfora.com.gt
apps.denn.com.my
cortellum.com
www.covid19-line.com
www.creatingyourbestself.com.au
www.davidcobbina.com
davidpellegrini.ca
dcprincipal.com
www.doctorbrett.com
booking.drmaurya.org
wordcounter.easyling.com
dev.app.eggbun.net
www.elotracker.app
www.essence-lai.com
signup.evertransit.com
gamerstudios.dev
www.getbap.com
b4063-cycleway-have-your-say.gloucestershire.gov.uk
www.goldcleats.ai
golearningsource.com
share.gostore.app
www.gscmaintenancecmms.app
salescope.hiddenslate.net
hyperparameter.co
idleht.ee
binance.pay.imem.app
iqchat.app
itcg.life
karthikdattu.com
app.keeptheearthfresh.org
www.kevinmoy.org
knolm.de
kronno.com
admin.latestphones.in
lucapalanga.de
links.lucrasports.com
lumadimaderas.com.ar
marissamsinc.com
marketingcontactcenteraxalta.com
time.mcmullin.app
mountelizabeth-hospital.app
go.mulhak.com
www.nasirshotdog.com
guesstheflag.nikhilmetrani.com
corpo.noticia.ca
www.nroadcorp.com
dev.beta.numerous.cloud
deepdive.oceansai.tech
candidate-mvp-redux.offerdox.com
opticred.optagestion.cl
preplyft.com
accounting.ptlumbung.com
qdonomy.com
clock.rapidapi.cloud
campaigns.rate-rise.com
redact.at
reformasbogota.com
www.repeatparty.com
residence11.com
treaty.prod.resre.bm
www.rikeshzaveri.com
www.robertoo.st
www.rovash.eu
russiananabolicspharma.com
seen.link
senesan-tech.com
posters.shawalmbalire.com
pulstraning.sisuidrottsbocker.se
www.smart-cities.nrw
dl.spiconn.com
policy.spsoft.sk
mauricio.stockers.app
str-it.de
suchinth.com
audio.syncro.space
www.taki.club
taxisbarquisimeto.com
qa-bizworks.gov.taxscribe.app
terryhoangnguyen.com
tucanjuguetes.com.ar
unibit.ai
app.viralata.do
waraiapp.com
Other domains in certificate