Open
Cached
·
just now
79/100
SECURITY SCORE
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
December 03, 2025
Valid Until
March 03, 2026
68 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
B4:DE:C0:34:C7:C9:E3:2B:5A:FD:D5:49:DE:D2:D2:A6:D6:85:09:9C:75:13:27:F2:DB:93:61:25:A6:67:F5:29
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
51 domains
glosku.com
www.glosku.com
www.8bit-chimp.com
abcinnovacion.com
www.abcinnovacion.com
annaisa.moda
www.annaisa.moda
tls.automattic.com
chesleysoftware.com
www.chesleysoftware.com
mujerplena.family.blog
freelancemarketingsource.com
www.freelancemarketingsource.com
line11financial.com
playmoviestv.movie.blog
educacionayboxeo.music.blog
et-ut-nobis-idblog.music.blog
eum-distinctio-eaque-tempore-autblog.music.blog
fashionstylist.music.blog
hic-voluptatum-porroblog.music.blog
houdinisocialclub.music.blog
howtoplayguitar.music.blog
impedit-quis-consequatur-laborum-possimusblog.music.blog
itaque-nulla-repudiandae-undeblog.music.blog
justmymind.music.blog
music-is-my-life-3.music.blog
nemo-itaque-nesciuntblog.music.blog
oldisgold.music.blog
rockcity.music.blog
rockexperience.music.blog
songshelby.music.blog
turbulence.music.blog
vale.music.blog
www.asperiores-culpa-velit-voluptas-etblog.music.blog
www.cats.music.blog
www.computerscience.music.blog
www.corporis-quis-dolorum-odioblog.music.blog
www.empoweringwomen.music.blog
www.krishna.music.blog
www.laborum-libero-impeditblog.music.blog
www.militia.music.blog
www.moviegame.music.blog
www.qui-blanditiis-etblog.music.blog
www.singsfromishka.music.blog
www.skyiscalling.music.blog
www.snoky.music.blog
www.superhit.music.blog
www.supermarvel.music.blog
www.unlimtedgmail.music.blog
www.vip.music.blog
www.3421523.music.blog
Other domains in certificate