80/100 SECURITY SCORE

Certificate Information

Subject
CN=www.mypassioncoffee.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 21, 2025
Valid Until
February 19, 2026 89 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FE:50:6C:15:77:02:8E:74:60:70:0D:68:E5:36:0E:F7:41:49:3F:00:9C:4A:C2:3D:DD:7D:29:4E:09:64:6F:EB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Basic
script-src
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Improve CSP by adding more specific directives and removing 'unsafe-inline'
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
emocije-istrazivanje.com

Other domains in certificate

65bunjitsu.xyz
abeni.net
app.act-node.com
www.alpafyonluoglu.com
www.amezexpress.com
goodwood.andrew512.com
asf-terrassement.fr
bam.assettwin.nl
schwarzweierfurt.deeplinks.bfansports.com
web.boyztown.app
www.brainbrawl.app
www.bsr-rv.com
buntroots.com
chartwell.ai
roberto.clau.io
short.clever.ps
shatzki.co.il
srcrackers.co.in webadmin.srcrackers.co.in
docs.codethebox.dev
www.codingmystery.com
swipe.coitor.com
app-lpg.commo.dev
condopal.it
rudasburgers.corntech.com.mx
voice-app.creativevirtual.com
sugarrushsweets-orders.crispnow.com
ctsynergy-ph.com
internet-obscura.develu.io
dhgeoconsultancy.com
digitowl.dev
www.electedtechnologies.co.uk
www.emilianogreco.me
link.emplivecloud.com
faawud.com
findlayoilerscamps.com
www.flagshippage.com
dev.fleetsafe.io
staging.flowai.be
flybrewing.net
monitor.prod.fynchmobility.net
fyreflysystems.com
gamesrushti.com
globalbjt.com
link.gotap.com.br
guilhermo.nl
www.gyik.app
hangar55peruibe.com.br
hefeapp.com
www.hypeitorhateit.com
iantsai.com
tempcover.ics-digital.com
inferlay.com
ire-view.com
advisors-demo.ischoolconnect.com
krishnaapp.com
uuplanner.kudlacep.dev
miatyche.com
mintmini.online
mymart.market
www.mypassioncoffee.com
newcode.pe
novelution.net
nydeckyrevival.cz
ovenbits.com
backstage.parallel.live
bpnext.paycloudafrica.com
imaj.qfix.ai
replatformday.com
rumanscaffolding.in
www.runeslice.com
sewaora.com
sipfeed.com
partners.slim-subway.com
stakeholdertakeover.com
bodamirandajuarez.swanmoments.lat
takedahachio.net
app.taskio.online
www.theblackbox.app
thesense.cloud www.thesense.cloud
tiengtrungbotui.com
www.toolminder.co.uk
torascience.jp
trappedjpegs.art
agafaremenu.triggersplus.com
ci-dev.trinitybrands.co.za
triptempo.app www.triptempo.app
www.tsotechnology.com.br
vallartaexcursions.net
www.vexasystem.com
data.watchlist101.com
widget.websolar.cloud
whalespodbiz.com
www.whatif.app
www.wheelofnames.app
yoonseo.shop
zaliczajznami.pl