75/100 SECURITY SCORE

Certificate Information

Subject
C=US, ST=Arkansas, L=Bentonville, O=Walmart Inc., CN=ak-prod2.walmart.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018
Valid From
March 13, 2025
Valid Until
April 14, 2026 131 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CE:94:BF:64:6F:33:E0:42:61:BD:49:0D:F1:3B:F7:B1:07:A5:F7:05:89:A4:5B:95:16:8B:48:55:F7:57:B5:0F
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

77 domains
academy.walmart.com advertising.walmart.com ak-prod2.walmart.com atps.walmart.com brandportal.walmart.com bulkgiftcards.walmart.com cc.walmart.com chat.walmart.com confluence.walmart.com delivery.walmart.com deliverytracking.walmart.com donations.walmart.com ds-prod.walmart.com eclosingcloud.walmart.com flowplan-api.walmart.com flowplan.walmart.com gscope.walmart.com healthscreening.walmart.com identity-teflon.walmart.com identity.walmart.com jobs.walmart.com notification-pref.walmart.com ota.walmart.com screening-service.walmart.com texttoshop.walmart.com tracking.walmart.com transition.walmart.com vrm.walmart.com wallet.walmart.com wap.walmart.com wireless.walmart.com wmtmanagedb2c-identity.walmart.com wrd.walmart.com www-ak.walmart.com api.cc.walmart.com api.notification-pref.walmart.com api.one.walmart.com api.smartreorder.walmart.com appointments.wireless.walmart.com developer.us.walmart.com dv.ptt.walmart.com preorder.wireless.walmart.com reservations.wireless.walmart.com rider.wireless.walmart.com ulearn-int.prod.walmart.com developer.api.us2.walmart.com external.etc.bopgta.us.walmart.com

Other domains in certificate

www.cmiw.com
app.joyrun.com joyrun.com orders.joyrun.com portal.joyrun.com www.joyrun.com
appointments.wireless.samsclub.com preorder.wireless.samsclub.com wireless.samsclub.com
abss.supplier.wal-mart.com api.eclosing2.wal-mart.com comms.feedback.prod.wal-mart.com documentwm-ui.prod.wal-mart.com eclosing2.wal-mart.com eclosingcloud.wal-mart.com gsmglobal.wal-mart.com gssrecovery.wal-mart.com logistics-scheduler-www9.wal-mart.com plum-child-ext.wal-mart.com plum-ext.wal-mart.com portalfirmadigital.wal-mart.com preventit.wal-mart.com spec-ext.wal-mart.com welcomecenter.wal-mart.com
portal.walmart.ca www.portal.walmart.ca
www.walmartclaimsservices.com
walmartconnect.com www.walmartconnect.com
walmartluminate.com