80/100 SECURITY SCORE

Certificate Information

Subject
CN=www.niranjanux.in
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 09, 2025
Valid Until
January 07, 2026 53 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EA:EA:18:14:27:A8:7F:B7:04:B2:BF:03:26:C3:13:B7:A7:2B:11:81:C7:FF:8B:16:FC:03:F4:8E:87:35:32:49
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Configured (Restricts certificate issuance)
Current Issuer
Authorized (Matches CAA policy)
Authorized CAs
pki.goog letsencrypt.org digicert.com ; account=d55e1707fe59cbbcecc371e9b7ddadbdaf2e3ccbb4bac1f5ae6a686a8e26f25f
Incident Reporting
Recommendations
  • Consider using critical flag (flags=128) for stricter CAA enforcement
  • Consider adding 'issuewild' records to control wildcard certificate issuance

Subject Alternative Names

100 domains
ext-web-admin.ltl-xpo.com lnh-5.dev-ltl-xpo.com

Other domains in certificate

1milepass.nuclep.1mile.com.br
www.alisarfaresboulos.com
alnaqdan.com
andrewsk.com
annete.cl
antipodes.dev
argha.ai
exercise.astige.com
attentivemembers.com
axisdentaltx.com
classic.bagmask.com
v1.bernatowicz.dev
blirebonk.nu
estimator.branchtwist.com
destineye.brokengravity.com
go.buyer.black
www.calistrovieyra.com
ctrldeacceso.cascadacon.com
links.cervonwong.com
app.cine-match.com
www.clicktofeelgood.com
mgt.nairathrift.com.ng
app.conectasuite.com
maaling.coreculture.dk
cwra.africa
dqx.d-navi.net
www.dataliberationfront.com
crash-testing.degencoinflip.com
app.dentalbillingin.com
mweb.desofy.app
www.discordclique.com
auth.drivinginstructorlady.co.uk
docs.dronemqtt.com
victory.ucu.edu.ua
empezarrybelsus.com
portal.engym.com
www.fcnoaber.com
www.fima.ai
www.flipbundle.com
flipn.co
www.funcreaenaccion.com
www.student.getyasa.com
gicocep.com
www.goascendal.com
uat-blog-origin.gohenry.com
happyanniversaryxinwei.com
hdgethitched4321.com
howtaxworks.co.za
iohn.se
iqms.iqhive.com
short.izymoov.com
jacevedo.cl
jeffrey-hicks.com
www.jeffreyaboh.co.uk
ksx.fi
cait.kuwaitbinary.com
links.lafraise.app
welldex.lernit.app
manugoel.com
martnmall.com
svm.mayamd.ai
rtff.mjbdevs.co.uk
montpellier-techhub.org
moviesearch.ca
mth-search.com
nakedkitties.club
paste.ngobach.com
www.niranjanux.in
nirfeinste.in
www.ohlovetime.com
www.orderbell.app
osopandagrantarajal.com
www.paraglide.app
beta.support.parkchamp.ca
ecg.paynowafrica.com
login.penmateapp.com
penpalconnect.com
www.piadero.com
pockt.com.au
postfy.co
projectstanley.com
psirudahximenes.com
clients.quickpic-app.com
app.riddl.ca
dance.salem.edu
www.snailbytegames.com
app.splitex.com
thingswithyou.app
ucca.com.au
smoothie.upmedia.dk
agent.videolink.app
virthis.com
signintest.staging.wecommend.app
gerry.wedocontracting.ca
www.whoof.ph
www.yebalespices.com
yetanothertask.com
zayntek.com