Open
Cached
·
just now
96/100
SECURITY SCORE
Certificate Information
Subject
CN=jerseyfinance.com
Issuer
C=US, O=Let's Encrypt, CN=E8
Valid From
December 06, 2025
Valid Until
March 06, 2026
42 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
0E:BC:8A:00:0E:55:48:E6:67:9F:3F:BD:93:B7:1F:FA:EF:0D:22:E1:81:15:35:58:F6:4A:58:8F:29:B0:0A:75
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Basic
default-src; script-src; style-src; +10 more
default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://portal.jerseyfinance.com https://*.gstatic.com https://*.google.com https://*.google.je https://*.google.co.uk https://*.googletagmanager.com https://*.analytics.google.com https://*.bing.com https://*.bing.net https://*.convertexperiments.com https://*.jsdelivr.net https://*.jerseyfinance.com https://*.unpkg.com https://*.doubleclick.net https://cdn.userway.org https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://*.wistia.com https://*.wistia.net https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://invt.io https://maps.googleapis.com https://player.vimeo.com https://sidebar.bugherd.com https://snap.licdn.com https://sst.jerseyfinance.com https://tags.srv.stackadapt.com https://www.bugherd.com https://www.buzzsprout.com https://www.clarity.ms https://scripts.clarity.ms https://*.staticflickr.com https://*.flickr.com https://ausi.github.io/respimagelint/collector.js https://*.zmags.com https://*.canva.com wasm-eval; style-src 'report-sample' 'self' 'unsafe-inline' https://portal.jerseyfinance.com https://*.google.com https://*.google.je https://*.google.co.uk https://*.googletagmanager.com https://*.analytics.google.com https://*.jsdelivr.net https://*.jerseyfinance.com https://*.unpkg.com https://*.doubleclick.net https://cdn.userway.org https://fonts.googleapis.com https://tags.srv.stackadapt.com https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://*.canva.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://portal.jerseyfinance.com https://ik.imagekit.io https://*.google.com https://*.google.je https://*.google.co.uk https://*.googletagmanager.com https://*.analytics.google.com https://*.googleadservices.com https://*.bing.com https://*.bing.net https://*.convertexperiments.com https://*.facebook.com https://*.clarity.ms https://notify.bugsnag.com https://cdn.userway.org https://*.litix.io https://*.wistia.com https://*.wistia.net https://adservice.google.com https://*.jsdelivr.net https://*.unpkg.com https://*.doubleclick.net https://*.jerseyfinance.com https://*.googlesyndication.com https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://sockjs.pusher.com https://api.sejda.com https://api.userway.org https://assets.jerseyfinance.com https://cdn77.api.userway.org https://consentcdn.cookiebot.com https://iihmbgdppz-dsn.algolia.net https://invt.io https://maps.googleapis.com https://portal.jerseyfinance.com https://px.ads.linkedin.com https://sessions.bugsnag.com https://sst.jerseyfinance.com https://tags.srv.stackadapt.com https://unpkg.com https://*.staticflickr.com https://*.flickr.com https://*.canva.com; font-src 'self' data: https://portal.jerseyfinance.com https://*.google.com https://*.google.je https://*.google.co.uk https://*.googletagmanager.com https://*.analytics.google.com https://cdn.userway.org https://algolia.net https://*.algolia.net https://fonts.gstatic.com https://*.wistia.com https://*.wistia.net https://*.canva.com; frame-src 'self' https://portal.jerseyfinance.com https://*.google.com https://*.google.je https://*.google.co.uk https://*.googletagmanager.com https://*.analytics.google.com https://cdn.userway.org https://*.userway.org https://*.litix.io https://*.wistia.com https://*.wistia.net cdn.userway.org https://*.youtube.com youtube.com https://*.doubleclick.net https://*.cookiebot.com https://*.vimeo.com https://vimeo.com https://*.bugherd.com https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://go.jerseyfinance.com https://sst.jerseyfinance.com https://www.buzzsprout.com https://www.googletagmanager.com https://ausi.github.io https://*.zmags.com https://*.canva.com https://players.brightcove.net; img-src 'self' blob: data: https://portal.jerseyfinance.com https://*.clarity.ms https://*.google.com https://*.google.je https://*.google.co.uk https://*.googletagmanager.com https://*.analytics.google.com https://*.bing.com https://*.bing.net https://*.vimeocdn.com https://sidebar.bugherd.com https://ik.imagekit.io https://*.youtube.com youtube.com https://adservice.google.com https://*.imagekit.io https://*.googlesyndication.com https://*.wistia.com https://*.wistia.net https://algolia.net https://*.algolia.net https://ad.doubleclick.net https://*.doubleclick.net https://assets.jerseyfinance.com https://sst.jerseyfinance.com https://cdn.userway.org https://d2iiunr5ws5ch1.cloudfront.net https://go.jerseyfinance.com https://imgsct.cookiebot.com https://maps.googleapis.com https://maps.gstatic.com https://px.ads.linkedin.com https://www.facebook.com https://*.staticflickr.com https://*.flickr.com https://*.zmags.com https://*.canva.com; manifest-src 'self'; media-src 'self' https://portal.jerseyfinance.com https://*.google.com https://*.google.je https://*.google.co.uk https://*.googletagmanager.com https://*.analytics.google.com https://*.userway.org https://*.litix.io https://*.wistia.com https://*.wistia.net https://player.vimeo.com https://*.vimeocdn.com https://*.doubleclick.net https://*.youtube.com youtube.com https://*.canva.com; worker-src 'self' blob:; form-action 'self' https://portal.jerseyfinance.com https://*.google.com https://*.google.je https://*.google.co.uk https://*.googletagmanager.com https://*.analytics.google.com https://*.userway.org https://*.bugherd.com https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://*.jerseyfinance.com https://go.jerseyfinance.com https://sst.jerseyfinance.com https://www.googletagmanager.com;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
ch-dpr=*, ch-width=*, ch-viewport-width=*
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Recommendations
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
- • Consider adding 'issuewild' records to control wildcard certificate issuance