SSL Verification Bypassed
The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.
Reason:
Hostname Mismatch - certificate is issued for *.ezit.hu, not for ezit.hu
Open
Cached
·
just now
92/100
SECURITY SCORE
Certificate Information
Subject
CN=*.ezit.hu
Issuer
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1
Valid From
October 06, 2025
Valid Until
October 05, 2026
300 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C6:25:5D:3F:A3:D0:86:F7:52:CA:DA:F4:4D:49:03:4E:63:17:39:55:CB:99:D9:5B:1F:0F:AC:F0:74:DA:B9:DF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
default-src; script-src; style-src; +8 more
default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' *.gstatic.com *.google.com *.acsbapp.com mhosting.hu *.mhosting.hu *.iubenda.com cookiebot.com *.cookiebot.com googleapis.com *.googleapis.com trustpilot.com *.trustpilot.com googletagmanager.com *.googletagmanager.com googleads.g.doubleclick.net analytics.tiktok.com connect.facebook.net snap.licdn.com bat.bing.com *.ads-twitter.com c.seznam.cz *.hotjar.com *.ladesk.com srv.isy-teamblue.services srv.motu-teamblue.services *.adform.net www.youtube.com *.clarity.ms; style-src 'self' 'report-sample' 'unsafe-inline' cdn.jsdelivr.net *.mhosting.hu cdn.iubenda.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.acsbapp.com *.doubleclick.net *.facebook.com *.mhosting.hu *.clarity.ms *.iubenda.com googleapis.com *.googleapis.com *.google.com pagead2.googlesyndication.com px.ads.linkedin.com analytics.tiktok.com bat.bing.com *.google-analytics.com *.motu-teamblue.services; font-src 'self' pw.w.org cdn.jsdelivr.net; frame-src 'self' *.google.com *.mhosting.hu *.apps.ladesk.com *.iubenda.com td.doubleclick.net webonic.ladesk.com www.googletagmanager.com; img-src 'self' data: *.facebook.net srv.motu-teamblue.services *.google.com *.doubleclick.net pw.w.org ps.w.org *.googletagmanager.com *.bing.com *.mhosting.hu *.clarity.ms www.facebook.com www.google.com www.google.hu; manifest-src 'self'; media-src 'self';
X-Frame-Options
Good
sameorigin
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Wildcard CAs
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts