Open
Cached
·
just now
91/100
SECURITY SCORE
Certificate Information
Subject
CN=jdeckman.com
Issuer
C=US, O=Google Trust Services, CN=WE1
Valid From
November 25, 2025
Valid Until
February 23, 2026
35 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA256
SHA-256 Fingerprint
29:AA:45:03:70:2A:48:05:26:B6:52:CB:72:FA:68:F1:F5:92:9E:50:82:57:15:94:7F:47:5F:FA:DB:84:51:EF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000;preload
Content-Security-Policy
Basic
img-src; default-src; script-src; +10 more
img-src 'self' data: https://wp.jdeckman.com https://maps.googleapis.com https://www.google.com https://www.googletagmanager.com https://www.google-analytics.com https://demo-content.kaliumtheme.com https://img.youtube.com https://www.jdeckman.com https://i.ytimg.com https://translate.google.com https://fonts.gstatic.com https://cdn.honey.io https://plugins.svn.wordpress.org https://repository.kreaturamedia.com blob: https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.youtube.com https://connect.facebook.net https://www.google.com https://www.jdeckman.com https://www.gstatic.com data: https://get663.com https://sc-static.net https://ajax.googleapis.com https://platform.twitter.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.youtube.com https://connect.facebook.net https://www.google.com https://www.jdeckman.com https://www.gstatic.com data: https://get663.com https://sc-static.net https://ajax.googleapis.com https://platform.twitter.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.jdeckman.com https://www.gstatic.com data: https://cdn.honey.io ; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.jdeckman.com https://www.gstatic.com data: https://cdn.honey.io ; font-src 'self' https://fonts.gstatic.com https://static.zip.co https://www.jdeckman.com https://svcs.tql.com https://cdn.blerp.com data:; frame-src 'self' https://www.youtube-nocookie.com https://www.google.com https://www.facebook.com https://www.googletagmanager.com https://mozbar.moz.com blob:; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://translate.googleapis.com https://get663.com https://translate-pa.googleapis.com; media-src 'self' data:; worker-src 'self' blob:; frame-ancestors ; upgrade-insecure-requests;
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports