Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=effico.co
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 17, 2025
Valid Until
March 17, 2026
82 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0B:29:A6:9F:12:48:77:C3:18:4F:5F:30:E8:EF:E7:1D:F6:1B:FF:B0:65:EB:A4:26:B4:8F:A3:C2:BC:A8:26:47
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
itdux.app
lowes-kitchen-hub-cert.3dcloud.io
accessibilityanalytics.com
airsoftmarket.es
dbus.aspevo.com
dnb.atomslearning.com
console.staging.gaia.auchan.fr
ayrtonapps.com
snake.babaaman.com
www.beltri.com
benashton.dev
connect.beyondboundaries.app
usap.deeplinks.bfansports.com
bigoltiddies.com
www.billy-and-spencer.monster
binariusconsulting.ca
bloemekets.be
track-uat.bouncelogistics.com
stephanie.choriatis.com
classasker.com
oxeye.co.in
www.amst.co.in
function.control-j.com
www.d7taxi.fr
dendrotreecare.com
wame.leu.dev.br
www.digineeru-lsoa.in
echofive.app
ecrime-gcnp.com
stage.edzag.com
effico.co
notify.equihealth.be
www.esmenava.com
explorearabiaonline.com
corporate.stage.first-iraqi-bank.co
gangudupalli.in
fresh.garageproject.co.nz
getplans.app
www.getvfeed.com
gluekode.com
www.groziopulsas.eu
www.horizondrift.com
hotplateapp.com
www.jaisakthipapers.com
wordle.jpcreekmore.com
moyolvera.kenailabs.com
auth.kinetictechnique.com
www.kmcleanandshine.com
ladvik.eu
larunfla.com
ltw-dev.da.letsdive.io
e-supplement.littlesyntax.app
app.luwx.dev
massagelk.com
laboratory.offsite.medisureonline.com
memoriesofmaya.com
mikerosellini.com
moroccancrypto.com
www.mustafagartenbau-gmbh.ch
n-m4.in
refraction.ncc.la
cdn.neman.hr
staging.nlalarm.app
noiseboyz.com
npmresearch.com
app-dev.okonomiyaki-honpo.jp
www.oneclickinterviews.com
othercooked.com
www.petelepage.com
lendistry.pirm.io
pixelshard.com
www.qualifast.bg
stage.auth.relish.com
invest.republic.co
docs.resultam.com
links.reworld.io
dev.rivermeadlodge.org.uk
samabox.com
schubert-schwall.com
assinatura.selffi.com.br
shusteripartnery.com
rechtwijzer.slachtofferhulp.nl
soquasi.com
vinhchau.ebot.stedu.vn
tictactoe.techvigorous.com
theoceanleads.ai
employee-sls.tio.works
triibo-api-gateway-hml.triibo.com.br
www.tryginger.app
urbantz.io
vegre.no
video-of-the-day.de
vilton.tech
walocha.me
www.walocha.me
flutter.wonkytech.net
www.xpinpoint.com
www.yeditepe.work
zarges.cloud
www.zionmjh.com
Other domains in certificate