77/100 SECURITY SCORE

Certificate Information

Subject
CN=tools.eldiario.es
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 30, 2025
Valid Until
December 29, 2025 37 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4C:EB:6B:4B:15:BF:13:A6:00:E0:DC:A1:F6:F4:0F:23:A4:93:1A:46:7F:BC:6F:80:2F:D7:95:8D:0B:E9:63:D6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
hero-routes-globalsolution.devbeebit.com

Other domains in certificate

staging.1bio.me
www.1f8.co.jp
alcanzandoobjetivos.com
www.allotmentbook.app
argue.win
arpiza.me
ops.asslpl.com
www.bestchoicetravelconsult.com
brianjohnston.ca
www.calvinyhu.com
centum.pe
monitoring-s1.chekt.com
chrisharper.dev
cleude.com
asinteriorandaluminium.co.in
personalitytest.co.kr
mta-sts.gensoft.co.th
developer.conomy.app
www.cookcook.it
dgsbbb.com
doublecheckdrugs.com
e-libertasufpel.com.br
tools.eldiario.es
iolaregister.enotice.io
ethiopiabible.org
eyraverse.com
www.facilbula.com.br
fausz.dev
d4c-links.feedbackstr.com
www.fineandfurious.com
corporate.fitlego.com
www.flordeldia.com
teamdemo.fomerly.com
frigateaboutitcharters.com
solutions.galial.com www.solutions.galial.com
gbonita.com
order.getblood.com
auth.gocollab.cc
app.gopetplan.com
www.haywirefilms.com
imo83.me
script-api-tmp.impactproduct.com
investleilaoimoveis.com.br
www.isitstillafreecountry.com
jointaction.cloud
kavincab.in
auth.kitabisa.com
knownot.ai
kodistic.com
kuiperdev.com
www.lahainadojo.com
chaotic-inventor.latific.click
lepka-tela.com
lidtest.de
lionster.tech
www.manugoel.in
mediaonelive.co
app.meloads.io
metavis.app
metromedidas.com
meyvn.io
mueblesx.com
test.mynextderma.com
admin.mypoke.ru
myvoltera.io
apps.no1.mobi
firebase.nuestrashojasamarillas.com
shoes.nupeacock.com
ozonetabletennisclub.com
www.promotapas.com.ar
www.rahulrahate.com
rajdeepchauhan.blog
dashboard.recover-hub.com
rolazarcoding.com
www.sandrios.com
manager-staging.screenlime.app
secc-intl.com
sergiosapps.com
beta.socialcurator.com
check-list.spnc.jp
spokanerace.sqwadhq.com
swiftnotes.in
admin.takochart.com
onboarding.teamtelefoon.nl
www.otello.staging.tekfluent-softwares.com
www.thomas-levendig.nl
mes-pilates.timp.io
timschier.com
tixora.net
t-port.tmls.jp
tulukalaplata13.turnosweb.app
ukri.info
www.vanielson.com
lists.vern.dk
micro.volvmedia.com
weaverlabs.ca
app.zyhap.com
dev.labcare.zym365.com