Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=shop.finewinelibrary.nl
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 09, 2025
Valid Until
January 07, 2026
40 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
51:D0:3C:4E:40:E7:EC:F4:E8:2E:15:06:7E:E1:98:8A:FC:CB:88:59:C8:7B:2E:48:E7:42:A5:01:AB:44:17:66
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
hnzkstudio.com
pulsar.12rw.io
novella.bard.aabass.net
www.airflyff.fr
alboradadeunpueblo.com.ar
dev-portal.appzi.io
www.arlawaustin.com
arrivebio.com
asmi.app
www.barrett-consulting.co.uk
beauandbadger.co.uk
hive.bee-fulfilment.nl
profiler.bennybutton.com
www.bluedotecommerce.org
www.bravespine.com
aprop.cargobici.com
carlosgzz.com.mx
cherrydarlingsbakehouse.com
dev.chi-value.net
help.clouddaddy.com
www.colectspot.com
covid19outcomes.connexia.com
cookmesh.com
pickmeupdrinks-orders.crispnow.com
derfurth.com
www.designmindsboutique.com
oasis.digitizeme.com
dinostoff.se
doodlepartygame.com
earlylogic.org
eden6.com
corporate-demo.edlin.app
el-divan.com
www.elibailey.org
www.erayyapimarket.com
dash.espireads.com
faangx.com
fastlogisticsng.com
shop.finewinelibrary.nl
firstfan.com
fitclip.jp
www.fullyone.com
leads.futura.healthcare
garage-door-us-co.com
www.getsuresure.com
join.givently.com
goazcart.com
crm.gocheap.vn
www.goldenapp.it
heliahaghighi.com
verify.hereyougo.com
hiretlnt.com
host.i-sis.net
grsti.inf.br
website.int3grity.com
jamesdavidpresents.com
snaker.jkierem.com
psandbox.jorigine.fr
gallery.josnsof.com
3d.juanguarin.com
wallet-dev.kryptogo.app
about.leftfieldlabs.com
grupomarroquin.lernit.app
www.lightofaya.com
www.maharajasweets.org
martinwong.net
pe.mayamd.ai
mcghee.me
shares.mettasocial.com
www.mezcal.studio
www.miloogymaker.net
www.lesonline.my.id
app.studybuddy.mypabox.com
www.nedevelopers.in
link2.onigo.club
osteorelief.ca
gamedevjourney.paperwebsite.com
www.pawsforabeer.com
dev.portfo.me
www.pronajdi.com
questionsforu.com
ruse.recursyve.dev
app.relearn.fyi
tickets.resoluteai.in
rvisi.ca
www.showrd.com
sinocrack.in
csa.streetbrewers.be
swansburg.ca
www.the-fish-house.co.uk
koru.thegreentable.it
apidev.trincico.net
greensight.turfcloud.com
www.u-trainer-fitness.de
vtcvalencia.com
waafi.ca
waterfilmtechnology.com
www.whooming.com
www.wzvpn.io
ymmv.flights
Other domains in certificate