77/100 SECURITY SCORE

Certificate Information

Subject
CN=easyworkout.app
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 31, 2025
Valid Until
January 29, 2026 79 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3A:58:04:D8:FC:4F:AA:56:AB:F3:FC:8E:A0:1B:0C:25:B4:85:3A:26:8E:A9:2A:29:7B:D2:3A:0A:14:56:03:25
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
incandescentdigital.com www.incandescentdigital.com

Other domains in certificate

www.1th.uk
app.cupcake.29k.org
cardsharks.agntfor.com
ahn1967.com
amarouter.org
andrewbruner.dev
andrewsneed.io
android-worldwide.com
awwuk.co.uk
www.baraban.art
www.bespokesystems.net
bibletrivia.io
www.bx2group.com
www.cactourz.com
cdtechaz.com
dev.chronostimetracking.com
www.edihovalot.co.il
coshel.co.in
examine.comepass.co.kr
coachfoster.org
westminsterwindow.column.us
www.comteharebourg.com
account.conecta4edu.com
joinbridge.cosmitude.com
nightly.sfa.e-bukken.app
easyworkout.app
tvsmotor.uat.eisqr.com
equation.space
www.firebase.tools
www.flscarend.nl
cms.fuse-on.co
www.dev.plataforma.gestio.school
link.infi.us
inviteee.to
3j72iqha1x4vybya.staging.no.isnot.info
www.johnmit.com
www.kalinakraleva.com
kinsey.info
krka.works
leley.online
auth.londonbuspal.co.uk
www.lumityot.fi
staging.makegoodapp.com
malisatracking.com
mark6.app
mesbro.in
mikec.org
mtmlogistics.com.au
multiforce.org
mumoin.com
bio.muralikannan.com
murderinparis.com
billing.bayamproduction.my.id
narita.link
www.neolexical.com
www.neonpopsicle.com
iccproject-app.oz-tms.com
pavelbinar.cz
round.playonigo.com
rabbat.app
backoffice.rateballplus.com
re.tn
auth.refocusai.com
npcadmin.rewiretech.com
rezar.com
models.staging.roboflow.com
www.rustixmanor.com
link.rydercup.com
celebrity-demo.ui.sceenic.co
club.scorelit.com
securitydogsni.co.uk
admin.seekpeace.io
makanai.sg-apps.com
www.simonaustin.net
simonpiggott.co.uk
www.so-digital.at
www.soga-permanentie.be
dev.auth.sokuyaku.jp
www.sreef.in
stonehousegroup.co.za
link.streets-stg.jp
sultanconstruction.co.uk
bodaguillenzambrano.swanmoments.com
tapwill.com
taxilink.no
www.tiliportaalioy.fi
www.tlz.me
www.tradingif.com
www.traveldestinationservices.com
truehealth.app
saleschat.truenorthitg.com
dashboard.trybe.fit
tulukaalmagro.turnosweb.app
valeriandelphin.eu
routingbe.viveit.cl
voxregi.org
app-uat.wknpa.hk
weight-calculations.youssefhigazy.com