Open
Cached
·
just now
93/100
SECURITY SCORE
Certificate Information
Subject
CN=eu.phrase.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 01, 2025
Valid Until
March 01, 2026
62 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6A:49:C1:39:BA:4B:88:6B:4A:C1:C3:78:3B:CD:2D:4C:6E:D3:04:0A:3B:7B:61:37:B6:3F:FC:19:FD:F1:94:CA
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
base-uri; font-src; form-action; +12 more
base-uri 'none'; font-src 'self' https://fonts.gstatic.com/s/inter/ https://*.gstatic.com data:; form-action 'self' https://*.phrase.com https://*.zendesk.com; frame-ancestors 'none'; img-src data: blob: 'self' https://gravatar.com/avatar/ https://*.userpilot.io *; object-src 'none'; script-src-attr 'none'; style-src 'self' https://fonts.googleapis.com/ https://*.userpilot.io https://fonts.gstatic.com https://fonts.googleapis.com https://*.birdie.so 'unsafe-inline' https://js.chargebee.com https://undefined.chargebee.com/assets/hp_v3/iframe_views/; script-src 'self' 'unsafe-eval' https://*.userpilot.io https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ http://js.userpilot.io/sdk/latest.js https://*.google.com https://*.googleadservices.com https://*.googletagmanager.com https://*.googleanalytics.com https://*.google-analytics.com https://cookie-cdn.cookiepro.com https://widget.intercom.io/ https://client.prod.mplat-ppcprotect.com https://js.zi-scripts.com/ https://googleads.g.doubleclick.net https://js.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://*.hscollectedforms.net https://*.hubspot.com https://*.forethought.ai https://phrase.com https://*.licdn.com https://*.bing.com https://*.ads-twitter.com https://*.facebook.net https://*.albacross.com https://*.birdie.so 'unsafe-inline' https://js.chargebee.com https://js.chargebee.com/v2/chargebee.js; upgrade-insecure-requests; default-src 'self' 'unsafe-inline' 'unsafe-eval'; child-src 'self' *; frame-src https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://undefined.chargebee.com/ 'self' *; worker-src 'self' blob:; connect-src 'self' https://*.userpilot.io wss://*.userpilot.io https://cookie-cdn.cookiepro.com https://js.chargebee.com https://js.hs-scripts.com https://widget.intercom.io https://snap.licdn.com https://bat.bing.com https://connect.facebook.net https://*.hscollectedforms.net https://privacyportal.cookiepro.com/request/v1/consentreceipts https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location https://region1.google-analytics.com https://www.google-analytics.com https://www.google.com https://*.hubspot.com https://*.birdie.so wss://sock.birdie.so https://googleads.g.doubleclick.net ws:;
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports