77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.leo-ricci.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 27, 2025
Valid Until
December 26, 2025 50 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DC:B6:99:00:80:64:1C:C8:6A:1E:55:EB:C1:4C:82:68:93:F0:23:CD:0B:50:0A:EB:1A:1E:A9:FE:61:F5:B8:D6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
expo.cofaral.com.ar

Other domains in certificate

epidemie.abradatas.cz
adiop.com
www.aihero.studio
ajaydharamsingh.com
www.almdata.com
mb.almeraim.com
www.alokit.in
resume.anirudhgiran.com
annabeljefferies.com
www.anonymous-videochat.com
dashboard.atlasdot.co.za
axiomconsulting.ca
bartexx.com
benvass.cv
app.bine.world
www.bkhydraulicsindia.com
www.bluuweb.dev
api.buscuu.com
casadascoxinhasecia.com.br
www.charlottepradel.de
chillcheck.org
www.cirus.mx
prod.clevernet.app
clerk.cloud-terminals.com
cats.cmrl.in
columbiariverpainting.com
login.conneqtid.com
consultasn.com
www.corequ.com
na.cradle.work
auth.dms-nr5.com
www.dominicanuniversitycamps.com
hanged.ebombo.io
editshub.co
elenabyalaya.com
emojiappiconmaker.com
www.encord.com
jpf.envisageworldwide.com
ezspeek.com
fairviewfellowshiphome.com
a061.foodle.su
foodscape.blog
dev.frieppy.com frieppy.com
rustilida.fulfiledu.uz
myvaultspa.gen11project.com
gifygram.com
sandbox-app.glomopay.com
goagile.co.nz
imac.cc
indemnitevelo.fr
intel-i-park.com
mta-sts.jimw.ca
kamasutra-app.com
www.keeperflow.com
www.leo-ricci.com
www.liziasmr.com
lugarrico.ng
bookings.manzana.media
mazzeo.io
michaelmaryanoff.com
www.mz-bazaar.com
oms-center.nextlogix.vn
nickbrennancartoonist.co.uk
cdc2.order.place
www.schmidt.pension-luckau.de
claroclub.pentcloud.com
philbaylog.com
covid-screening.quadprep.org
safepass.rajrajhans.com
admin.residentex.com
rikhavshishodia.com
www.sanajingsanathambal.com
www.sanawa.co
www.savoirvivrecosmetics.com
www.saylah.sg
www.scs-rybnik.pl
www.shamudeen.ca
console.smartrails.ch
stumblingswingout.com
maymarswedding.swanmoments.lat
x--dev.tayl.app
www.thalystory.com
links.dementia-dev.theprojectfactory.com
www.therealnews.in
auth.thicc18.com
tjexp.co
assets.tresastronautas.com
ubitlogger.com
gfh-mobile-app-privacy-policy.upgraide.ai
staff-test-mig.uptrust.co
testing.valliento.tech
vishalchhatwani.com
app.engage.demo2.voyagernetz.us
vscanimaging.com
www.walljam.app
wardrobeway.app
bsbpay.xptoconsig.com.br
dev.yourappstudio.com