Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=gdgcraiova.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 05, 2025
Valid Until
January 03, 2026
43 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
37:4C:08:0E:86:9A:BF:DE:75:1C:3B:22:7A:0F:42:E0:15:60:8C:20:E3:3F:E7:23:03:6B:1B:C6:76:EF:E8:10
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
inteliped.online
app.ace-up.com
next.agua3.com
admin-test.ailahealth.net
www.bookstack.co
app.campbot.com.au
chasingeinsteinmovie.com
stage.cirqit.app
rean.co.in
sharing.medistream.co.kr
app.imepay.com.np
khanalrajan.com.np
tracker.ddongbbang.com
designmonkeys.in
digitaljourney.it
earlypath.org
insta.eceinel.dev
edftw.com
tugsdelgerekh.edu.mn
www.esportsbonusoffers.com
www.foirfesolutions.com
showcase.ftelocations.com
gdgcraiova.com
apps.geoarabic.com
gerardtolan.com
api.getflowly.com
staging.groovechat.fm
www.gulsahbayazit.com
hhuynhtechlead.com
www.homedr-admin.com
inwine.com
isitwrong.net
www.jeffpolakiewicz.com
www.join.cards
kainwalker.com
www.kawatta.com
www.lafinyhealth.com
laksitha.dev
www.lalapak.com
www.laurent-wattieaux.com
lawfully.dev
www.livingmeaningfully.ca
log-point.jp
marcosolfrini.it
www.mentorific.org
xtechsignin.mingalartech.com
mksoft.tech
mondays.business
dlink.mumara.com
app.muzzle.run
meet.mv-gechingen.de
jack.mvogelgesang.com
www.mylife-timeline.com
p.o2o.vn
dev.oldasdirt.com.au
otravida-tattoo.de
www.p-systems.io
staging.paradigma.education
wallets.paystitch.com
portal.payxps.com
www.philanthrosphereloop.com
phonobox.mx
lig-demo.picol.app
playwrds.com
presspledge.com
horne-fl-qa.psg-labs.com
deeplink.rapidbooksapp.com
rbasouth.com
auth.redskymarkets.com
rekat.in
resm.me
www.ruytingen.be
samcopharmaceuticals.com
newcastle.scouthub.app
shrusoft.com
siasharemarket.in
sieciitm.com
smart-inventory.app
smscapa.com
snowmedia.ca
spaily.com
stacysinclair.com
www.stakesignal.app
www.pet-monster.studiocloud.dev
www.supermax168.com
savethedaterosaleslopez.swanmoments.com
taustrat.com
gelardini.thetislive.com
www.thoughtcrafters.com
www.tlcdental.mx
transporttrackerai.com
gamenight.trevorwithdata.com
trueahead.no
turiconnect.com
twentyei.com
my.updateeveryone.com
redirect.usp.center
admin.vette.io
registration.vida.id
consent.staging.your.vet
Other domains in certificate