Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.lengoland.co.uk
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 20, 2025
Valid Until
January 18, 2026
57 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D9:5C:EE:9A:2F:AF:C7:81:04:FF:9B:52:41:7D:AE:D4:A2:B6:FF:4D:7D:21:DD:69:06:04:FE:96:B5:26:7D:8E
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
hoardle.app
invite.oozi.aimpact.ai
www.anomalousauditoryresearch.com
ansasolutions.tech
armchairsoftware.com
bangalore.arnidroptaxi.in
99veiculos.autoshoppingimigrantes.com.br
b2b-sales-accelerator.de
www.booze-feed.com
www.brianalanhager.com
www.carlosalejano.app
cennet.ai
www.chaincard.co
chewkokshin.online
www.claritale.com
dl.clicnpark.com
resty.co.il
resumeapp.com.pk
devexp.co.uk
devfestsgf.com
bmx-robotics.dstteam.com
downloads.eceos.com.br
calculator.ejincollective.com
dashboard.entrust-assessment.org
ethancota.dev
fewo-maedchen.de
www.freshhaber-24.com
gt-shpe.com
dev-api.hooolders.com
www.i-chi-li.info
ich-hasse-geschenke.de
nguyenhuyhoang744453.id.vn
ifixattics.com
innovativeperfection.com
iophysics.net
links.jaguarnac.com
www.jewishwedding.info
kalkanpad.com
kintedu.in
kunzacademy.com
www.commande-mobile.lecentral.ca
www.leeker.io
www.lengoland.co.uk
localbites.kitchen
app.mdc.com.br
meloveiculospatos.com.br
www.meylertech.com
www.monika-trans.eu
mustafademirtas.me
mybusinessapp.co.za
www.mythreadtracker.com
newleafproservices.com
nidhikachhadiya.com
noofangled.com
www.noticefly.com
open-nutri.com
parisiannailsalon-westcobb.com
petroexplore.com
www.app.ph2.io
podscribe.app
www.portugol.dev
qa.procpro.com
profile.12.jwc.in.th
puzzlelab.top
www.quieromifarma.com
radimare.com
rajneethi.org
book2021.reapra.com
www.recargas24hrs.com
riftscheduling.com
www.ringfencing.fun
www.routeseven.io
rspasientes.com
rtxmidias.com.br
sc.technology
schramkowski.com
seodaemun-kimchi.com
siddhantlodha.com
www.simple-business-by-oa.com
wongpanit-book-store.siwawesw.space
skilldetektor.de
worktime.soprasteria.com
sweetspotfarms.com
takeoffspeeds.com
unisync.theroomieapp.com
thingsbecoming.food
www.toroalgo.com
tremain.xyz
bot.new.dev.ucall.asia
ultim.pro
smiles.insights.umanni.com.br
business.universalcuisines.com
www.vehicleshippinggroup.com
victorioussoft.in
videoleap.store
visuallogics.in
app.windsapp.com
ydiva.com
yockyard.com
www.zingsoft.com
Other domains in certificate