Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.hickmananalytics.co.uk
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 07, 2025
Valid Until
February 06, 2026
84 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
90:70:14:E4:08:71:A8:55:0C:D1:D0:C0:FF:21:47:9D:A4:82:F0:E2:C9:7C:6C:A1:98:D1:EB:D4:53:99:F0:F0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
fatex.io
www.98tank.com
truelogic-html-sanitizer.adelonzeta.com
aistandards.foundation
akarus.us
www.amanafund.org
s.ase.me
postofficescoin.af-south-1.aws.aurosoftware.net
pwa.azimutis.app
ireland.bacreate.eu
ekycstg.banexcoin.com
banhmibarhtx.com
wrft.static.barracks.gg
admin.beamian.com
bialgames.com
bookbrd.com
bunimarkets.com
www.castorena.com
chatfluenceapp.com
thechickensandwich.clau.io
closeclique.com
marketing-page-a.prod.cantaio.co.il
codesnip.xyz
www.connectedtribe.com
craftbyte.net
www.croyance.co.uk
development-app.cst-assistenten.dk
cms.cudidivn.com
applestore.dasistan.com
dubaiemploymenttips.com
eglow.pe
emoh.ru
policies.emptyseat.lk
evenschuilen.nl
www.expressdecision2.com
www.factorseis.com
familyday.org
www.giftcards.farmaciasgaleno.cl
support.filterize.net
account.fmawards.ie
firebase-auth-redirect.gaelg.im
admiral-kolo-srece.gd.si
gobigquery.cloud
registration.greenawards.ie
www.greycolorme.com
www.gulayozkececi.com
www.hag-haveagift.pt
halfmoonwaterskiteam.com
www.healthycontent.co.uk
www.hickmananalytics.co.uk
creative-demo4.hisy.in
hiteshnamrani.xyz
www.iamzakir.com
inmuuent.com
en.insibook.com
insibook.com
www.insibook.com
cochesegurounifinempleados.inter.mx
www.intothewhile.fr
isnap.info
www.jasonisapedophile.com
jeongmyung.com
security-app.kantsu.com
landdealer.net
lily-is.online
lonestarmasters.com
lyanan-cspintu.de
lyceum.so
marlim.co
mccarrendemo.garden
www.mppreadymix.co.za
netdreamsllc.com
neurosynclab.com
huntingtonbeach.opendata.report
www.huntingtonbeach.opendata.report
auth.ordering2online.co.uk
politecacrylicpaint.com
r-joi.com
www.rcloud.co.nz
rdtp.org
rentrediapp.com
operations-portal.qa.rocketkor-nonprod.net
salutesolutions.co.za
zsoiqdqztn7egnmtyirw.smartimob.io
socratech.it
www.socratech.it
splitx.in
mta-sts.t-flats.jp
tacklingthegap.be
tdmchamps.in
techcraft.digital
tiktokgraveyard.net
tryme.page
tuidziemy.pl
tweedehands.autos
tycoonautos.co.uk
webapp.venditoredigitale.it
via.vgbnd.co
vtes.global
calorieai.yantostore.com
Other domains in certificate