Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=app.strategytools.io
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 07, 2025
Valid Until
January 06, 2026 42 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
08:F5:DF:4E:32:EC:73:AE:84:90:BA:13:D1:D3:16:D8:04:08:17:D6:6D:A6:A9:EA:AB:70:F1:94:5A:A9:18:B4
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
foru.fan

Other domains in certificate

1001apps.tech
ray-sectional-config-cert.3dcloud.io
www.anielaolsztynek.pl
www.ar-infra.com
ascenders-partners.jp
www.assuranceski.com
bannds.com
bastienclement.ch
www.bezkomentare.com
bittokoinkajino.jp
www.carbondown.earth
kex.ceder.dev
dondaa.co.ke
www.coursemagnet.com
www.creativetechcoop.com
www.crush.me
madness.dangraphs.ca
test.decodedhealth.com
www.devintent.dev
qrcode.ecfone.com
app.ekselio.tech
invite.fintelli.app
www.followlives.com
admin.foodaciously.com
quiz.foxfox.io
fufu.be
www.geniosetraquinas.pt
gnadenweiler.de
www.golden-needle.dz
nazuna-kyoto-nijojo.b.hotekan.com
blockchain.humidefi.com
www.immersified.com
basqueueai.innrsys.com
jasmeenimmigration.ca
burger-builder.jimnguyen.dev
joeturner.me
www.jordanrhodes.dev
keglerouletten.dk
www.kitchenphysics.com
koi-lang.dev
message.lanissan.ca
kvakalmanak.livecasthq.com
lmd-solutions.fr
www.lmminspiredwords.com
www.luckango.com
restaurante.lupi.delivery
app.mixo.io
molzait.com
fukke.muchimuchi.dev
www.nerd.games
nicole-tsang.com
www.nikolaiarsentiev.com
dev-admin.novemapp.com
ollietroward.com
nbfsc.ondagoapp.com
applink.uat.opencheckout.org
www.orcamentospdf.com.br
admin.dev.orderease.com
www.parkyypass.com
www.partywave.io
www.prestaya-latam.com
proflead.ru
kraken.quebecorhub.com
qamuy-input-builder.qunasys.com
schedule.revas.org
www.robertadallavecchia.it
www.sagarpathare.com
satshealth.com
www.seasonleague.com
presale.secondworld.io
sim.see6.io
azan.shazvi.com
app.shoplitlive.com
www.sliceq.com
www.snipnshipja.com
app.solutionslv.fr
www.spankmonki.com
www.stellarscan.io
www.stoneybrookhollow.com
app.strategytools.io
sixways.swapp.work
photo-admin.thai.run
thecryptoknights.io
app.thefrozeneye.com
themathorigin.com
qa.tieple.com
triviafiesta.com
www.tutiqet.com
portfolio.vanblaricom.dev
visualcelebrities.com
wafflesworld.com
restoration.waterdamage1800.com
wavy.io
www.websupport-services.com
withvr.app
www.woodvalecounseling.com
www.x4prodchart.com
zhutadesign.com
zubairshehzad.com