75/100 SECURITY SCORE

Certificate Information

Subject
C=US, ST=Arkansas, L=Bentonville, O=Walmart Inc., CN=cf-prod.walmart.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018
Valid From
February 25, 2025
Valid Until
March 29, 2026 120 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1B:4B:6A:DA:14:7C:EB:1B:1B:B5:15:22:A8:C8:5A:10:0F:D8:C9:A1:42:24:B5:88:58:73:E2:AB:41:5C:19:73
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

101 domains
academy.walmart.com advertising.walmart.com associateonboarding.walmart.com atps.walmart.com billboard.walmart.com brandportal.walmart.com cc.walmart.com centroamerica.walmart.com cf-prod.walmart.com chat.walmart.com confluence.walmart.com cougar.walmart.com cpa-api.walmart.com cpa-ui.walmart.com customersparkcommunity.walmart.com daastipping.walmart.com delivery.walmart.com deliverytracking.walmart.com donations.walmart.com ds-prod.walmart.com eclosingcloud.walmart.com ecm-web-prod.walmart.com feedbackally.walmart.com flowplan-api.walmart.com flowplan.walmart.com fonts.walmart.com git-ext.walmart.com gscope.walmart.com guide-api.walmart.com guide-identity.walmart.com health.walmart.com healthscreening.walmart.com helicarrier.walmart.com help.walmart.com idcapps.walmart.com jobs.walmart.com lotus.walmart.com merlin-marketplace.walmart.com mytech.walmart.com notification-pref.walmart.com ota.walmart.com rptrcks.walmart.com screening-service.walmart.com solutions.walmart.com sparknotifications.walmart.com sspr.walmart.com status.walmart.com surveysays.walmart.com svipreg.walmart.com swift.walmart.com texttoshop.walmart.com tracking.walmart.com visit-api.walmart.com visit.walmart.com vrm.walmart.com wally-ga.walmart.com wap.walmart.com wellness.walmart.com wireless.walmart.com wmgate-hro.walmart.com wmgate.walmart.com wmtmanagedb2c-identity.walmart.com wrd.walmart.com yopico.walmart.com analytics.mobile.walmart.com api.affil.walmart.com api.cc.walmart.com api.feedbackally.walmart.com api.health.walmart.com api.mytech.walmart.com api.notification-pref.walmart.com api.smartreorder.walmart.com api.sparknotifications.walmart.com api.surveysays.walmart.com appointments.wireless.walmart.com bixby.prod.walmart.com console.polymorph.walmart.com dv.ptt.walmart.com e.polymorph.walmart.com incident.uno.walmart.com intltracker.prod.walmart.com links.em.walmart.com livebundle.storage.walmart.com ntransit.transportation.walmart.com p.polymorph.walmart.com preorder.wireless.walmart.com prod.tailfin-mobile-view.walmart.com reservations.wireless.walmart.com rider.wireless.walmart.com static.sparknotifications.walmart.com teflon.deliverytracking.walmart.com ulearn-int.prod.walmart.com walmartsustainabilityhub.emissionscalculators.walmart.com walmartsustainabilityhub.joingigaton.walmart.com walmartsustainabilityhub.sustainabilityportal.walmart.com t.us-east4.polymorph.walmart.com t.us-west1.polymorph.walmart.com external.etc.bopgta.us.walmart.com hp-oe.prod.seiyuapis.cloud.walmart.com rakuten-oe.prod.seiyuapis.cloud.walmart.com sng-oe.prod.seiyuapis.cloud.walmart.com