Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.poachedfilm.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 05, 2025
Valid Until
January 03, 2026
38 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
30:F4:07:41:64:BD:E6:1E:8C:90:9A:53:4B:7A:6F:48:14:AB:18:1A:CC:E7:8D:61:7F:81:76:23:BD:B7:DB:5D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
fungaiaziendagricola.com
firebase.agora-ed.app
agrid.io
ahmedworks.com
alliancesoccer.club
my.anyplans.app
appcompadre.com
www.appcompadre.com
landing.appgua.com.mx
ashhadwaquas.me
bark-at-the-park.com
brasafgcu.com
buildingcats.co.uk
www.buildingcats.co.uk
adsnetwork.campusjeunes.net
castleplayer.com
cemjsolucoes.com.br
www.chriswolfdesign.com
www.ciudadaniadepolonia.pl
www.cloudwday.com
jcedu.co.in
demo.coachway.app
dev.coachway.app
staging.coachway.app
admin.ehs.conny.tech
www.covertek.fi
bulten.darussafaka.org
dco.uz
www.deinsssol.mx
store2.dercocenterx.cl
www.dharmadreams.app
digitaldivesolutions.com.ar
line.djjam.app
hrconclave.uem.edu.in
www.entityx.io
dev.ewaves.com
www.exspressocafe.com
floriculturacriative.com.br
fomo-no-no.co.uk
fotocoke.com
www.fxgrid.zone
demo.g-trac.net
www.seychelles.govtas.com
judge.greenawards.ie
dev-bechozap.gupshup.io
gurpstools.com
haasjennsen.ee
hoeveherlaerbosch.nl
www.hty-code.com
igorgo.nl
petar.impactwrap.dev
prsa.impactwrap.dev
jaeminy.love
kalisi.dev
kaminoplay.com
www.kawcode.com
www.kinderpsychotherapie-kaiserslautern.de
laocjoshua.com
leobulhoes.com
www.mundimarcos.art
diagnostico.mymoons.mx
www.neighborgood.info
www.portal.nextlevelfitnessgl.co.uk
fireadmin.oco.sg
www.pingo.one
pintify.app
www.planner.live
www.poachedfilm.com
poke-do.com
www.pushkarguesthouse.com
identity-staging.recruiting-solutions.org
attorneyhamilton.redacted.ai
robology.ai
auth.dev.sayhello.cash
sayi.do
app.shearai.com
sitesdigitais.com.br
stormbase.co
storyglow.online
community.synctalk.us
www.tela-hq.com
thepetdoor.net.au
beta.timyst.com
tinysparks.guru
www.trevsbargainemporium.com.au
userlm.ai
veloxsim.com
dynamiclinks.vgfit.com
app.viaggiarerent.com
metis.virevol.com
vividclm.app
backoffice.vois.io
wellbie.co
wibce.eu
xerp.app
xhaka.tech
shipping-webhook.yiswaapp.com
link.yonple.com
www.wordle.yousefbahar.com
zeus247.ng
Other domains in certificate