Open
Cached
·
just now
90/100
SECURITY SCORE
Certificate Information
Subject
CN=babydroptaxi.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 08, 2025
Valid Until
January 06, 2026
46 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
95:14:FB:81:7E:3C:AE:C3:84:5A:58:51:24:E7:AB:68:3D:BE:18:46:82:69:22:E4:83:1B:40:23:AB:E5:E3:ED
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; preload; includeSubDomains
Content-Security-Policy
Basic
default-src; script-src; style-src; +10 more
default-src *.facebook.com *.fbcdn.net *.instagram.com blob:;script-src *.instagram.com static.cdninstagram.com *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* 'nonce-yRJigUct' blob: 'self' 'unsafe-eval' https://*.google-analytics.com https://translate.google.com https://apis.google.com https://accounts.google.com;style-src *.instagram.com static.cdninstagram.com data: blob: 'unsafe-inline' *.fbcdn.net *.facebook.com;connect-src *.instagram.com wss://edge-chat.instagram.com connect.facebook.net *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* ws://localhost:* blob: *.cdninstagram.com wss://*.instagram.com:* 'self' https://meta.privacy-gateway.cloudflare.com/relay;font-src *.instagram.com static.cdninstagram.com data: *.fbcdn.net *.intern.facebook.com *.facebook.com https://fonts.gstatic.com;img-src *.instagram.com *.facebook.com *.fbcdn.net data: *.cdninstagram.com *.whatsapp.net blob: *.fbsbx.com android-webview-video-poster: *.oculuscdn.com *.giphy.com *.tenor.co *.tenor.com www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk https://www.gstatic.com https://*.google-analytics.com;media-src *.facebook.com *.fbcdn.net *.instagram.com *.cdninstagram.com cdn.fbsbx.com lookaside.fbsbx.com data: blob: https://*.giphy.com *.tenor.co *.tenor.com;child-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;frame-src *.instagram.com *.facebook.com *.fbsbx.com fbsbx.com data: www.googleadservices.com *.doubleclick.net *.google.com *.google.co.uk;manifest-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;object-src *.facebook.com *.fbcdn.net *.instagram.com data: blob:;block-all-mixed-content;upgrade-insecure-requests;
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
accelerometer=(self), attribution-reporting=(), autoplay=(), bluetooth=(), camera=(self), ch-device-memory=(), ch-downlink=(), ch-dpr=(), ch-ect=(), ch-rtt=(), ch-save-data=(), ch-ua-arch=(), ch-ua-bitness=(), ch-viewport-height=(), ch-viewport-width=(), ch-width=(), clipboard-read=(), clipboard-write=(self), compute-pressure=(), display-capture=(self), encrypted-media=(), fullscreen=(self), gamepad=(), geolocation=(self), gyroscope=(self), hid=(), idle-detection=(), interest-cohort=(), keyboard-map=(), local-fonts=(), magnetometer=(), microphone=(self), midi=(), otp-credentials=(self), payment=(), picture-in-picture=(self), private-state-token-issuance=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), shared-storage=(), shared-storage-select-url=(), private-state-token-redemption=(), usb=(), unload=(self), window-management=(), xr-spatial-tracking=();report-to="permissions_policy"
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
famees.com
logic.a4apps.com
www.agenciaforfan.com.br
www.asnfbikeparts.com
www.atmaspace.ru
aujude.com.br
axzy.co.uk
babydroptaxi.com
www.badetemp.io
www.baraoke.app
www.batuhanhidiroglu.com
bavat.at
photonlens-competition.be-hookd.com
wallet.budgific.com
vendor-app.bvaah.com
campingmontacabana.com
cangrejord.net
canilottie.com
certifiedoa.com
cfrioux.com
www.chefs.tv
www.crissknotcottage.com
www.cybearjinni.com
nibako-mng.daihatsu.co.jp
deedpile.mortgage
www.devsenpai.com
deyandobrev.com
digilabs.media
www.divinemarriagecenter.com
beehive.dpduk.dev
url.e04.dev
life.ecflow.app
dev.echo.lu
ganhemais.emccamp.com.br
portal.emission-framework.org
www.fahrschule-kressbronn.de
gestionclientes.fain.es
www.falconexport.com.au
www.foodiespointbhopal.com
app.freterra.com
www.genosyn.com
geospencer.dev
www.getmajorna.com
goodpointsglobal.com
tickets-demo.goruckit.com
www.hometownhiring.com
pyramids.hrtech.com.br
nguyenvanminhhong20224856.id.vn
roman-karina.invito.link
janathperera.com
janetbrunowedding.com
squash.kevinschweikert.de
www.kidshealthportal.com.au
www.kittilanlentoasema.fi
www.kityazilim.com
laperladepalamos.com
www.megaslice.uk
www.mondosposaitalia.it
cms.motiv-app.com
mountaineersfvg.it
auth.notepan.com
www.office-sagawa.com
oymakinsaat.com
stpeters.patrickrumble.com
console.peazi.eu
ponlaya.com
portefoliogeoffrey.com
app.staging.psychofacile.com
www.punkpixel.io
www.qman.io
radiokasoot.com
icabs-staging.rentokil-initial.com
rosemaryconover.com
sewelljohnathan.com
www.sfduel-wiki.com
shotpe.com
www.singinglessonsportsmouth.com
link.sketchpay.io
www.smartfixcare.com
admin.somenu.digital
sondlyn.com
www.sounddrop.io
stayroi.it
link.stockl.io
sucreebakehouse.com
invitation-service-en.test.tada.dev
takecareof.se
cointerm.tanutapi.dev
app.teampurpose.de
tickalist.com
static.traceit.info
www.traveldestinationfinder.com
tryfootprynt.com
links.gakugei.school.services.int.unpaidworks.com
t.vorapp.net
my.wcbc.edu
portfolio.xoogler.de
yt5s-fr.com
est.zdserver.com
www.est.zdserver.com
Other domains in certificate