Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=link.bioscopelive.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 26, 2025
Valid Until
January 24, 2026
76 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A7:DE:D7:62:17:79:4D:70:2B:9B:A6:90:58:40:17:CD:29:E1:0A:7E:BE:B7:05:BB:EF:A8:E3:F9:2E:31:5C:E5
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
fishfacts.com
digifull.cms.2na8.com
www.akiinoue.com
www.alanchang.co
alectoai.com
alhadiahmed.com
www.anuonewaydroptaxi.com
www.apeiron-vr.com
arkagamestudios.com
asa-sanpo.com
asleslie.com
avogato.co
betondx.com
link.bioscopelive.com
bittersourcomics.com
www.bluve.com.br
bytesfantastic.com
cablemagico.ec
dtltest.calloflove.org
canyouflow.com
carbsonplate.com
carrozzeriacupparo.it
admin.cdcare.ng
www.chantobox.com
circlekcomm.com
testing.coastertokyo.com
onetest-dev.oneclass.com.tw
www.crajit.com
deanweaver.com.au
depotriplek.id
www.die-telefonistinnen.de
www.dmximobiliaria.com.br
www.edpic.app
elnaprat.com
beta.emceapp.link
enoughgiving.com
familykonnect.app
www.feedback.place
partner.fidelizzare.app
flatmindgames.com
flokventures.com
gdjo.foodle.su
www.gdgbolivia.com
hdbdata.com
coupletherapy.healthbj-uk.org
duck.helpinghands.community
fbtest.houseofjones.com
icstanisonuc.com
inmobiliariacampanillas.com
my.primary.health.irugyou.com
jbestcosmetics.com
johnbase.io
resume.kampkode.tech
kimmccaskill.com
www.kleis.ch
kreativepeeps.com
www.kylerichards.tech
www.leninfeebb.it
erp.luqra.com
moviestarplanet.maxkandersen.dk
gtp.mbility.app
medianochelabs.com
www.mikada.co
www.myheadhurts.app
admin.mysmartcoke.com
app-dev.nannyadvisor.it
neespa.ca
nestorfock.app
neuraldreams.art
auth.babor.next-audit.de
ninhcorp.com
content.orwi.app
link.paymii.io
pdtechnology.co
www.plamob.com
webhooks.pollination.cloud
home-dev.publicissapient.fr
app.qrcodepreferido.com
questionable.io
io.raceme.io
admin.railtasker.com
app.rflex.dev
support.roadbotics.com
www.sattaliveresults.com
scotton.co.za
app.socialdisplay.io
voda.softet.cz
go.sosafe.app
www.stockmoves.io
storyofpainting.com
student.stutor.com
www.surpriseculture.in
teacup.gg
thebeaconoc.org
admin.dev.thetoucan.app
www.thomasrossetti.com
cem.turnosweb.app
urjinee.ai
prep.portal.internal.viana.ai
cdn.de.voxelmax.com
Other domains in certificate