Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=topotech.org
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 04, 2025
Valid Until
January 02, 2026 45 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1C:6A:2D:FA:D8:E9:72:B0:38:82:8F:1F:33:84:2E:E4:CD:B0:95:62:9D:13:DD:FD:B6:70:9E:C2:27:95:A5:00
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
horizonlabs.tech

Other domains in certificate

1nv1n.com
22okt2016.de
adadigiverse.com
aganhealthcare.com
analfabeeld.nl
www.astrolyra.com
web.autoforwardtelegram.com
azersoft.nc
bananabits.com
broker.bankari.sk
portal.bathnroom.com
bedibug.com
www.berkayworks.com
abstimmungen.bernerzeitung.ch
www.bitsqueak.net
dash.brain-vita.com
brokertg.com
app.bubsjournal.com
buttoned-up-service.com
cajandj.com
cakesbydia.com
canpanionnft.com
castillonabogados.com
www.chaseholdren.com
sushiexpress.clau.io
www.dev.crewchiefga.com
danwilkerson.com
client.app.dev-platforma.one
www.diabrisk.com
people.dijiti.com
duiardal.se
auth.edvoy.com
eldonchew.com
emulator.evolvequickly.com
staging.f.chat
yolo.fiopl.com
indicaai.focoengenharia.com
groups.forbidden-sheets.com
www.foristudio.com
www.fornaxdiamonds.com
foxyjot.com
fronteradevs.com
www.fujiba.net
gamecraftersguild.com
ct-staging.gestion-traiteur.app
deeplink.goodpairdays.com
henri.live
holt-and-catch-fire.com
interbee.io
www.j5kmusic.com
kalmarunionen.no
kozelkaelectric.com
app.labrador.ai
www.lvlogistica.com.ar
deep.mai.menu
www.meistergerhards.de
play.microservicios.co
mpoqq.net
www.mvibn.com
maxidecesare.net.ar
new-self.org
nitra.ai
www.pebble.solutions
hyundai.pecas2b.com.br
www.pithandpally.com
pivotium.co.uk
qalp.ar
realtysynch.co.za
reclip.pro
sanawa.co
shop.sandrasoft.app
panel.screenz.live
www.servicefolder.com
www.spent.club
spiritbearkaratekobudo.ca
prod.sportyapp.com
squarehoot.com
stonesoupcoop.org
www.sttcabs.in
jacto.teuestoque.com.br volks.teuestoque.com.br
pedidos.thechiefbbq.com
opensource.theyakka.com
www.tigerlilystudio.in
stage.timeto.work
todayilearned.app
topotech.org
parkspass.utah.gov
vagamist.in
valur.com.br
vectotech.in
vedix.link
www.washitworkshop.club
partner.lab.watdrinkje.be
whizzyle.com
willntrix.com
writ.solutions
yourchoicetravels.com
health3.zrenix.com