Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
March 05, 2026
Valid Until
June 03, 2026
34 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
71:0C:12:68:90:24:D0:AE:23:52:22:76:79:F7:12:AB:E2:91:51:7B:2C:7E:59:95:AF:CC:EA:0E:1D:DE:8D:96
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
49 domains
entertablement.com
12stonesfarmhouse.com
www.12stonesfarmhouse.com
aaliyaheportfolio.com
www.aaliyaheportfolio.com
aceorgo.com
www.aceorgo.com
agencemel.com
www.agencemel.com
art-book.blog
www.art-book.blog
aufildesmots.blog
www.aufildesmots.blog
tls.automattic.com
avantelaw.co
www.avantelaw.co
bemybabyfilms.net
www.bemybabyfilms.net
bonitobean.com
www.bonitobean.com
chaletbruno.ch
cornwallphotographs.com
www.cornwallphotographs.com
dieselcentrum.com.pl
www.dieselcentrum.com.pl
dmergent.blog
dontdonothing.com
www.dontdonothing.com
fantasypredictionforfree.com
www.fantasypredictionforfree.com
felixyoungman.de
www.felixyoungman.de
www.foulreport.blog
fourthandgoalfitness.com
www.fourthandgoalfitness.com
healingallhearts.org
www.healingallhearts.org
www.kono-kokusai.jp
mz-photography.com
www.mz-photography.com
nsmgroup10.link
old-fart-young-heart.com
www.old-fart-young-heart.com
www.perdidaperoconwifi.blog
theofficialwhistle.blog
www.theofficialwhistle.blog
thewanderingchaos.life
www.thewanderingchaos.life
fontaneroenmislata.tufontaneria.com
Other domains in certificate