Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=franckcolonna.fr
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 06, 2025
Valid Until
January 04, 2026
45 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3F:86:60:54:E8:43:D3:76:62:FA:8C:50:82:E8:4F:2B:BB:4E:27:3E:DD:84:81:4E:FC:CB:2F:BF:0A:37:6D:12
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
financieramifortaleza.com
aecore-solutions.com
algebraistdates.com
passwords.anb.codes
apprve.de
enrollment.artschoolsfbay.com
avatar-me.ai
dev.bidlogiq.app
bitpups.com
blkk.tech
qm.docs.bondvet.com
one.braid.health
app.brandedposts.com
brettwilliams.dev
concreterush.com
datagrid.cl
dbfiddle.dev
www.deanwagner.info
developsolutions.in
guesser.dijiti.com
video.discoverglimpse.com
dluxury.at
www.donkey.fans
www.echitect.com
platforms.elevationai.com
elisabethhreflexoreiki.ca
enclaveinteractive.in
eprvmnt.com
www.esense-eegenius.com
eshi.io
evalli.fr
fanza-man.com
www.fieldfactsbaseball.com
app.finpic.com
franckcolonna.fr
applink.gamership.app
geogardenclub.app
sources.getarmada.app
gravityforcetech.com
greatcallcoach.app
app.helperplace.com
www.hersenwerkpropsy.cz
hotelberhamporelodge.com
instalp.co
www.jainsavar.com
one-account.jkierem.com
www.johannfeser.dev
www.jugasalfutbol.com.ar
www.juristapaligs.lv
beta.kampoy.com
buzz-recruit.kayac.com
manager.staging.klarcommunity.com
lightglo.ca
www.lolita.fashion
lyta-sante.com
phasesofthemoon.m2catalyst.com
www.maestro4edu.com
maidslips.co.za
www.manacon.fi
auth.martinmorris.ar
kf-integration-test.marxent.cloud
mentarimedia.com
www.beta.miveratech.com
www.mrlokimonster.com
myreme.pl
hlasovani.naschomutov.cz
www.nhp.digital
ofoz.org
thoothukkudi.onewaytravels.in
www.paranormax.be
parkyypass.com
www.pegasustransport.com.au
pgjazzz.win
preview.poconorestorations.com
www.prescast.com
mult.quitapay.com
www.rchen.ca
www.richardbound.com
www.rotamda.com
www.samajsebi.com
omar-altaha.sharp-devs.com
www.shii.fi
sign.mt
auth.sixelf.com
dev.smartviewmd.com
www.staffinghrm.com
help.tablechamp.at
app.teachmehipaa.com
www.tekacs.com
app.theroxfox.com
thesofttrainer.com
todaytomorrowyesterday.app
tubidy.re
dev.unifize.com
valentinasparty.com
vastumitraa.com
uat-admin.verscan.com
www.webdevadmin.com
www.wehappy.se
www.yumzzmenu.com
Other domains in certificate