Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=breakthroughchapel.co.ke
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 20, 2025
Valid Until
March 20, 2026 66 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C6:1F:E1:D7:87:5C:9B:A8:30:CA:65:BB:F8:0D:A2:7F:64:E4:15:E4:12:95:D8:5E:B8:44:8D:92:94:8B:C9:40
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
ignat.dev

Other domains in certificate

lamarca.cms.2na8.dev
aamirmadari.com
gage.activ8games.com
thus.aeat.us
agentesai.mx
aisonoassistant.com
www.ajmalpkc.me
allethiopianews.com
www.andamanvpn.com
andrewscherkus.com
retro-dev.appsatease.com
pgx.arielmedicine.com
www.arisecorpn.com
arsjp.com
autonum.app
mcg.banpunext.dev
beach.beaches.app
follow.beet.live
calebbesser.quest
iot.canalgestionlanzarote.com
setup-feature-prod.captego.com
members.careerbase.co
www.cargopacker.co
chasealbright.com
clubhousecasuals.com
breakthroughchapel.co.ke
referrals.popmeals.co.th
www.codegen.ninja
68transport.waysoft.com.my
auth.7oy.cyberhaven.io
cycleit.co
danlowe.dev
daytonabeachfrontcondo.com
personal.dcmapps.com
www.designbysphiria.com
lp.digskill.net
dorellana.eboe62.com
www.freelancercostarica.com
links-debug.fyfly.de
gabri-e-ale.it
getpraxis.app
goopay.app
gruposeara.com
www.gymtrackpro.com
www.haidarzxc.com
headbanger.ai
dev.honeycome.jp
hostguide.ai
www.housingmobile.app
immoteam-bergstrasse.de
mealsspotlight.imsonu.in
sspraveen.indiandevelopers.org
www.ingridisidro.es
flotillascoppel-qa.inter.mx
www.jasonhay.dev
www.joyhealthcare.org
www.juttame.ch
kahilkubilay.dev
lorolabs.com
minucs.com
monsterroom.app
mxchange.io
trade.occasionbeaucage.com
onetreelabs.com
www.paidifitz.com
palladium-bachata.de
www.paraelisa.org
parkur.finance
persistnow.app
provisioning.pienissimo.com
www.pratiksinghal.com
www.prowashlaundry.com
www.qr0.co
rebeccakennet.com
reef.ree-jp.net
dp.replied.ai
www.rethinkreading.dev
roldonbrown.com
portal.rootedelementsmedia.com
shengweizhu.com
www.shortform.co
www.siliconally.org
sfcvote.sqwadhq.com
anime.stackdeveloper.in
www.thoughtexhaust.com
www.tomgreenaway.com
www.toytrainsfortherestofus.com
www.tripsides.com
tuancuong.dev
www.turnitinaidetector.com
unio-stone.de
uniquehomecareinstallationsllc.com
cocoona.vidocto.com
api3.vinota.com
www.war-game.io
www.wordsagainsttheclock.com
yourvisionbooster.com
www.zagnetic.com
zohargoichberg.com