Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.pitchfork.dev
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 30, 2025
Valid Until
February 28, 2026
89 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8D:1E:4E:FD:CE:E0:1C:E9:D7:1B:F7:06:50:69:73:7C:4D:AD:18:D1:D7:85:48:4B:E9:B1:6D:AB:15:6C:65:18
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
hub-stg.staza.io
abidereading.com
absurdd.com
eccc.adrianleung.dev
ajyadcosmetics.com
www.albioninnovation.com
aminquran.com
appyukt.com
www.appyukt.com
arterio-belgium.com
astralnetwork.in
ayamishunka.com
bennettsbridge.ie
www.brass-hotelsuites.nl
userguide.broot.ai
buyinstant.online
careergpt.in
onling-status.cbdata.cz
chiefsravenna.com
www.chiefsravenna.com
coqueiroteam.com.br
crescentpoolsupply3.com
genoma.danimoya.es
datecaterers.com
dentalcemanager.com
happy-birthday-suchi.divyanshusaraswat.in
www.dowlinglife.com
easylaundry.ch
ecommerceweb.ca
www.edwardaddley.co.uk
docs.efficientix.com
elliotthm.com
www.enterseg.com.br
omnicdp.evision.com.br
www.excimlaser.mx
www.fkworkout.de
www.fluencytrainer.in
www.focustudio.ai
franchisee.foxcity.space
operation.foxcity.space
franz.cx
freemindbr.com
gettonote.com
www.gettwine.app
gotyou.click
helpr.pk
caregiver-preprod.hercare.se
admin.tecnovale.ind.br
internationalaudience.com
www.iot-mty.mx
jacksonschuler.ca
jeiprofessional.com.br
szakimobil.joszaki.hu
karijerkast.com
d2l-dev.klarway.com
koensulting.co.za
www.koensulting.co.za
kolonba.com
leu-intranet.dev.lake-dynamics.com
lazzuly.com
www.lazzuly.com
www.lextax.com.br
puzzle-kit.logicpuzzle.app
auth.dashboard-staging.marblefashions.co.uk
careers.matchfin.ar
mathodical.com
mavinsandeep.xyz
mountainriver.ca
mwchats.com
www.mwchats.com
mithunraj.myhivespace.in
links.klaabu.namesong.com
nangosha.com
neoland-edu.com
orbis-markets.com
dash.pagerules.io
pateladvertising.com
pictle.net
www.pitchfork.dev
profit-pulse.top
www.profit-pulse.top
questoes.propofando.com.br
registrotrapmania.com
www.retailerhub.eu
adm.rsegmonitoramento.com.br
schoolwork.guru
schriftbot.com
schriftbot.de
shashankjaysurya.com
www.sinhax.com
www.sisnordbau.de
stanningleybowlsclub.co.uk
dj.tabl.page
www.thefroyo.com
tugraecem.blog
app.ura.tj
www.vwynco.com
www.wecyberit.com
www.yasasinhamileyim.com
bestellen.zaids-pizza.de
Other domains in certificate