Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=client.leanlancer.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 30, 2025
Valid Until
February 28, 2026 57 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
AC:F0:D2:39:CC:EB:E6:AD:AA:AF:00:B0:F2:6B:4C:7E:FE:FC:66:54:A1:FE:9E:C7:92:28:FA:0B:C8:7A:38:BE
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
kralj.dev

Other domains in certificate

ftg-indoor-test.3dcloud.io
wru.addclarity.net
afeletricaemontagens.com.br
agent917.com
www.anhduongsmarthome.com
www.anineogkristoffergifterseg.no
www.ateamspot.com
ww.w.autobid.com
demoportal.bambumeta.software
license.briefcatch.com
casraf.dev
portal.cnsprojects.com
www.hongsin11.co.kr
greenrays.co.tz
calculator.coachingjd.com
deeplink.jobstick.com.my
viepet.contextaware.com.br
cqbinbinbin.xyz
diemcau.com
ndis.digitalsymphony.org
club.divetheplan.org
app.easzy.nl
cse.iem.edu.in
elemento.online
emineksi.com
erefy.dev
int.explorins.com
www.flamenco.study
payments.flux.chat
www.flyerx.app
jda-qa-ideacloud.forgedx.com
frasestodososdias.com.br
www.frontera-ics.com
hostdev.fwd10.com
game7.in
link.gardy.me
auth.ghanadatascience.com
intuicare.goact.com.au
admin.good-winds.com
gravitastec.com
partner.ideazmoney.com
www.inefablesjc.com.ar
ingogo-business-test1.ingogodev.net
www.intercreativo.com
finmate.io.vn
koseligerom.no
www.kryptonissen.no
lambdaton.de
client.leanlancer.com
larf-admin.liveb4buy.com
www.logixpie.com
mcaprintwala.com
meetappcards.com
melofizz.ca
www.mertsplayground.com
www.metavineproperties.com
www.michubet.com
app.hml.minharota.com.br
mountaintophvac.co
nicolasmv.cl
www.nile.ag
evouala.ondagoapp.com
apps.openmetal.io
opentodine.com
demo.os.city
oscarhelgesson.com
www.prontoux.com
praxis.psychomedica.de
app.reloov.com
www.responsibleaginkarstcountry.com
richardolujordan.com
rigakayaking.com
seanyoungstone.work
seminoleokdentistry.com
www.sequoiaconsultgroup.com
shaolin.dev
auth.smartlegaldoc.eu
www.sntminds.com
www.soltechcorp.com
sozy.tw
back-office-dev.stayopen.io
admin.superbullklse.com
www.timethings.xyz
www.totalgravura.md
tropezcapital.com
veiltornstudios.com
ml.veros.dev
spotify.viasacra.band
voicerepo.com
sms.wakeflow.io
www.webeese.com
www.webmuds.net
whatsmyscreensize.com
whichvpn.com
www.ybconsultingllc.com
shopping-list.yovstudio.com
yuenhomes.com
yureka.shop
www.zaczim.com