Open
Cached
·
just now
86/100
SECURITY SCORE
Certificate Information
Subject
CN=pivotcycles.com
Issuer
C=US, O=Google Trust Services, CN=WE1
Valid From
January 23, 2026
Valid Until
April 23, 2026
82 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA256
SHA-256 Fingerprint
F2:16:85:6E:8D:54:76:F6:32:DF:5B:61:B5:6F:24:D6:77:03:A2:74:B7:FE:73:97:21:DA:D7:E7:14:67:20:A8
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
base-uri; default-src; frame-ancestors; +6 more
base-uri 'self'; default-src 'self' 'nonce-1cefec042fce4c652f9a6fe15f123439' https://cdn.shopify.com https://shopify.com; frame-ancestors 'none'; style-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://use.typekit.net https://p.typekit.net https://*.livechatinc.com https://*.klarnacdn.net https://*.acsbapp.com https://*.hubspot.com https://*.hsappstatic.net https://cdn.cookie-script.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src pivotcyclescms.wpenginepowered.com https://cms.pivotcycles.com https://cdn.shopify.com https://unpkg.com https://cdn.jsdelivr.net https://*.affirm.com https://prodregistryv2.org:* https://featureassets.org:* https://*.locally.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.facebook.com https://connect.facebook.net https://*.clarity.ms https://api.livechatinc.com wss://lc.chat https://j.clarity.ms https://*.clarity.ms https://www.facebook.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://*.klarna.com https://*.klarnacdn.net https://*.klarnaservices.com https://*.klarnaevt.com https://acsbapp.com https://cdn.acsbapp.com https://*.acsbapp.com https://*.hubspot.com https://*.hubapi.com https://*.hsappstatic.net https://*.hscollectedforms.net https://*.hsforms.com https://js.hs-scripts.com https://js.usemessages.com https://d1jiq9n77635tp.cloudfront.net:* https://5raer21h.apicdn.sanity.io:* https://o4509125266702336.ingest.us.sentry.io:* https://www.googleapis.com:* https://ground-keeper-custom.myshopify.com:* https://ka8jjo2110.execute-api.us-east-1.amazonaws.com:* https://js.hs-banner.com https://*.hs-banner.com https://*.sentry.io https://*.ingest.sentry.io https://cdn.cookie-script.com https://report.cookie-script.com https://consent.cookie-script.com 'self' https://cdn.shopify.com/ https://monorail-edge.shopifysvc.com https://pivotcycles.myshopify.com https://pivotcycles.myshopify.com; script-src 'self' 'unsafe-eval' 'wasm-unsafe-eval' 'strict-dynamic' 'sha256-3bzWVxQE32IZQKH9eh8KzyHuhXOlMrboDVVBRd0fWTU=' https://cdn.shopify.com:* https://cdn1.affirm.com https://*.locally.com https://gkc-script-server.pages.dev https://ajax.cloudflare.com https://cloudflareinsights.com https://static.cloudflareinsights.com https://www.googletagmanager.com https://tagmanager.google.com https://cdn.livechatinc.com https://*.klarna.com https://*.klarnacdn.net https://acsbapp.com https://*.acsbapp.com https://*.hubspot.com https://*.hsforms.net https://*.hsappstatic.net https://js.usemessages.com https://js.hs-scripts.com https://js.hs-banner.com https://cdn.cookie-script.com https://report.cookie-script.com 'nonce-1cefec042fce4c652f9a6fe15f123439'; frame-src *.youtube.com https://open.spotify.com https://cms.pivotcycles.com https://www.affirm.com https://*.locally.com https://gkc-script-server.pages.dev https://www.googletagmanager.com https://cdn.livechatinc.com https://secure.livechatinc.com https://*.livechatinc.com https://*.klarna.com https://*.klarnaservices.com https://www.facebook.com https://acsbapp.com https://*.acsbapp.com https://*.hubspot.com https://*.hsforms.com https://*.hsappstatic.net; img-src self *.pivotcycles.com vern.ngrok.app anthony.ngrok.app pivotcyclescms.wpenginepowered.com https://needed-absolute-mule.ngrok-free.app https://oyster-refined-rodent.ngrok-free.app https://pleasant-woodcock-upright.ngrok-free.app https://civil-redfish-real.ngrok-free.app https://anthony.pivotcycles.com https://anthony.ngrok.app http://localhost:3000 *.wpenginepowered.com cdn.shopify.com *.buzzsprout.com https://cdn-assets.affirm.com:* https://media2.locally.com picsum.photos *.picsum.photos blob: data: *.pivotcycles.com pivotcyclescms.wpenginepowered.com cdn.shopify.com *.buzzsprout.com https://res.cloudinary.com https://*.affirm.com https://*.locally.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://*.facebook.com https://connect.facebook.net https://*.clarity.ms https://c.bing.com:* https://*.livechatinc.com https://cdn.files-text.com https://*.klarna.com https://*.klarnacdn.net https://*.acsbapp.com https://*.hubspot.com https://*.hsforms.com https://*.hsappstatic.net https://*.hsforms.com https://d1jiq9n77635tp.cloudfront.net https://cdn.cookie-script.com; font-src 'self' data: https://cdn.shopify.com https://fonts.gstatic.com https://use.typekit.net https://p.typekit.net https://*.klarnacdn.net
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 5 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
- • Consider adding 'issuewild' records to control wildcard certificate issuance