Open
Cached
·
just now
75/100
SECURITY SCORE
Certificate Information
Subject
C=US, ST=California, L=San Jose, O=Adobe Systems Incorporated, CN=secure4s.scene7.com
Issuer
C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
Valid From
September 26, 2025
Valid Until
September 25, 2026
250 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9C:6F:86:66:26:FE:C9:2A:E0:E0:62:82:C3:41:DA:DE:DC:45:45:63:0D:2F:08:EE:98:E9:B8:62:79:82:99:6C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
57 domains
images.vans.com
images.asics.com
assets.bajajbroking.in
images.baldwinhardware.com
image.benq.com
media.berghaus.com
images.birdfeeders.com
assets.centurylink.com
assets.christiandior.com
staging-assets.christiandior.com
images.coeur.de
pzimages.currentinc.com
media.deichmann.com
images.fcbayern.com
dyn.felissimo.co.jp
assets.footlocker.com
images.gallerycollection.com
images.campaign.hbonordic.com
images.heb.com
imgs7.hessnatur.com
dam.hublot.com
dmassets.hyundai.com
aem.johnnywas.com
images.kwikset.com
imageseu.lee.com
media-assets.lseg.com
image.lucrin.com
images.lumens.com
cdn-dynmedia-1.microsoft.com
media.napacanada.com
dynamicmedia.netjets.com
resources.nutanix.com
images.otto.nl
media.pentland.com
images.pfisterfaucets.com
product-images.pfisterfaucets.com
cdn.plansee-group.com
dynamicmedia.qspartners.com
assets.dm.rccl.com
media.restorationhardware.com
media.rhbabyandchild.com
media.rhmodern.com
media.rhteen.com
images.saferbrand.com
assets.santen.com
secure4s.scene7.com
bilder.servusmarktplatz.com
images.spectrumnews1.com
media.speedo.com
s7.spiritshop.com
media.tranetechnologies.com
assets.oneappcms.vodafone.com
assets.volkswagen.com
images.wegmans.com
images.withoutwalls.com
imageseu.wrangler.com
images.zarebasystems.com
Other domains in certificate