Open
Cached
·
just now
92/100
SECURITY SCORE
Certificate Information
Subject
CN=www.beulahsewerproject.org
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 29, 2025
Valid Until
February 27, 2026
47 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
06:33:38:11:87:6C:C6:92:97:85:15:B9:1E:AA:B3:3C:FE:8D:C8:3E:65:10:6C:0B:44:F9:BF:94:1F:8F:A3:C3
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; script-src; style-src; +11 more
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' js.stripe.com *.paypal.com *.paypalobjects.com *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com *.contentsquare.net *.google-analytics.com *.googletagmanager.com *.sentry.io *.paddle.com blob:; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.paddle.com; img-src 'self' data: blob: *.stripe.com *.paypal.com *.paypalobjects.com *.googleapis.com *.gstatic.com *.google.com *.googleusercontent.com *.contentsquare.net *.paddle.com *.googletagmanager.com *.google-analytics.com; font-src 'self' data: fonts.gstatic.com; connect-src 'self' api.listingupgrade.com *.googleapis.com *.google.com *.gstatic.com *.firebaseio.com wss://*.firebaseio.com *.sentry.io *.stripe.com *.paypal.com *.google-analytics.com *.googletagmanager.com *.contentsquare.net *.contentsquare.com *.paddle.com data: blob:; frame-src 'self' js.stripe.com *.stripe.com *.paypal.com *.google.com *.firebaseapp.com *.paddle.com; frame-ancestors 'none'; form-action 'self'; base-uri 'self'; object-src 'none'; worker-src 'self' blob:; upgrade-insecure-requests; report-to csp-endpoint
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=*, picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
listingupgrade.com
www.1-for-1.org
adapstract.be
www.alsalaam.com.au
dev.anomalilab.com
applyandgo.eu
www.atlantaloverseas.com
www.azmartialarts.com
bagbahceyatirim.com
testa.beamian.com
www.beulahsewerproject.org
att.beyondzetta.com
biggame.one
butterflyconstructions.com
www.calculatorwidget.pro
share.app.cambri.ai
cebirsu.com
grandresidency.co.in
cursosinformaticos.online
www.devbug.dev
www.devpatch.com
easy-inc.jp
mailchimp.eldiario.es
shi.equiem.mobi
harley.evbatteryreturns.com
selfcheckout.farmatodo.com
fast-project.co
www.firewoodarmy.com
firstglobal-consulting.org
sales.gagamenu.com
getliszt.com
gurten-taxi.ch
hcm.com.ar
www.hoianmotor.com
ibakurov.com
managers-alpha.idu-identification.com
s3ms8.poda.incentable.com
mozaikplay-advisors-stage-7.ischoolconnect.com
www.ishanikadevelopers.in
www.itsagro.com
ivycoder.com
www.jbkrol.com
wedding.jeffreychan.xyz
auth.joinpeekaboo.com
joshuacaddy.com
www.kirubaioffsetprinters.com
kreatifbangsa.com
leotourstravels.com
lin-m.com
gamut.madhive.com
malcolmsturgis.com
marktplatz-wallerstein-ev.de
mdc.com.br
medionclick.com
mir-khan.com
mmibroadcasting.com
en.moke.tw
mooninblack.org
web.stg.mt-analysis-tool.com
mzansiemporium.com
boostbranding.neoufitness.com
staging.nerri.ca
ngx.tools
nitro.lol
njpremiumconstruction.com
nkyo-uruma.com
noboundfx.io
adminpanel.novellic.com
app.orelo.audio
othmanadi.com
peskyreminders.com
pizzeriacapra.com
prodevkit.com
project-april.com
qadlean.com
www.quarzomohedano.com
www.reax.com
www.redaustraldereiki.com.ar
consultancy.redsector.nl
link.regolith.pro
ritualspacalendar.com
telepharm.roboflow.ai
www.royalsummit.org
salgadosveganosmanaus.com.br
takasuki.siju.it
insights.soundalerts.com
sutharworks.com
tangram.nz
www.teomantuncer.com
explore.terratrekapp.com
the-ai-security-guy.com
www.tiffanymcnerlin.com
tombee.io
unidotaciones.com
unoindustry.it
audition.v-llage.com
www.valerioterebinto.com
viagemaolugardainfancia.com
xcessivemedsolutions.com
yogagoof.com
Other domains in certificate