Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=nicesecurite.fr
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 28, 2025
Valid Until
January 26, 2026
71 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3B:EC:0E:FA:E3:6B:A8:01:11:9A:24:51:67:D7:69:4B:B1:D2:41:B7:0D:A9:57:C5:20:25:E6:AB:83:A6:F9:7F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
gwappadmin.procurementmonitor.org
tools.4run.fit
www.aceintegrate.com
ackwalk.com
acptech.cl
vts.adroitiot.in
ahmds.de
alastaircox.com
autocallbox.com
www.ayos.me
below-msrp.com
benjaminali.com
bidonad.com
qr.blgfx.com
comunicats.capleshortes.cat
www.cenkayyigit.com
profile.chippit.co
cmstern.com
my-stage.empire.co.at
www.mydegree.co.il
www.harikesh.co.in
yazhdroptaxi.co.in
www.voismoi.com.tr
cooiny.com
www.danpride.com
devory.com.co
widgets.dixper.gg
doxifly.com
develop.feedback.ecoe.vn
entrenarte-estudio.com.ar
escueladeliderazgoprimerospasos.com.ar
eten-corp.com
a0ak.foodle.su
www.fotoceramicabidese.com
www.gonetwork.co
qc.hbmediacloud.tv
www.hbs.pl
hellofish.net
auth.homelandy.vn
felag.hsf.fo
auth.impossible.parts
kallakurichi.jiotaxi.in
nagapattinam.jiotaxi.in
pondicherry.jiotaxi.in
johnshortland.com
julianpropst.com
www.julianpropst.com
k0c.org
questworlds.karmitsa.fi
tool.klimaatgerust.nl
app.koicontrol.com
spark-stage.leapindia.org
www.legionarchitects.com
livekoora.vip
dev.localadmanager.de
lunei.se
magicalblooms.sg
mandeepdhillon.in
www.massage-angels.net
maxbusinesssoulutions.com
aditya.mitraadi.com
prakritikendra.mitraadi.com
skillvento.mitraadi.com
montericovip.online
stg.nakipower.com
neba.cafe
ngonge.com
nicesecurite.fr
www.ongevalrisico.nl
eustis.opendata.report
order.ows.fi
parama.in
www.parama.in
phdreamhome.com
www.planera.org
polyax.com
mobile.posify.in
app.preanestia.com.br
reilation.com
www.relaxes.me
auth.relaydesk.trade
agent.safeinvestmax.com
sepiapotato.nl
serene.is
serviaire.net
sitiocasadepedra.com.br
teamup.stofberg.dev
virtual-alt.surveillant.tech
www.thefishingway.com
www.themanorbelek.com
app.tradely.io
treealphabet.co.uk
www.trulinote.com
usereye.de
vcu.network
www.wanderindia.blog
www.weightlosstrackingbuddy.com
www.wisetro.com
www.smaregi-booster.work.gd
www.zowal.de
Other domains in certificate