80/100 SECURITY SCORE

Certificate Information

Subject
CN=www.tomato.ai
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 26, 2025
Valid Until
December 25, 2025 34 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4B:B7:D9:D9:D3:2D:2A:E9:50:31:9C:02:A5:7D:32:42:1C:A6:93:6F:17:0D:A3:A1:CF:E7:85:45:0F:E3:20:24
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Configured (Restricts certificate issuance)
Current Issuer
Authorized (Matches CAA policy)
Recommendations
  • Consider using critical flag (flags=128) for stricter CAA enforcement
  • You have authorized 6 CAs - consider limiting to only the CAs you actively use
  • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts

Subject Alternative Names

100 domains
littleairavatpreschool.in

Other domains in certificate

10kadds.com
www.accusim.com
beta.adiutor.co links.adiutor.co
aire.pw
soc.akibaa.com
trailspot.albertodelahoz.com
app.alphamoonbase.de
andemta-exhibitions.com
material.angularjs.org
assetbuddy.in
assl.io
admin.barmapper.co.uk
bdnk.design
www.bisoul.es
s.canadiary.com
www.careduct.com
fipstum.chriswijnia.com
codegennials.com
deepakkumarshah12.com.np
liana.lia.com.sg
www.coopeviajes.com
www.dancesquare.be
www.danier.dev
www.data-type.com
www.dishan.de
easypinger.com
kiosk.ehryourway.com
stage.dogfood.elli.eco
www.endo-pc.com
share.farhat.ly
cn.listwithus.favstay.com
firepeak.tech
www.app.focusokr.com
social.foundationlocal.com
app.dev.getsystem2.com
glorious-shallow.com
goodgamesguide.com
www.gotthereceipts.app
questions.grinboss.com
hawaiican.org
hdcorp.in
hmins.net
shepherd.loadtest.hrbrain.dev
www.itcnologia.com
iyadaboudargham.com
www.j3s.dev
www.jacobrturner.com
content.janamx.com
kaiohsawa.com
readability-checker.khufrudamonotes.com
kidsupsoroban.vn
readr.klg.bz
calendar.legalis.pl
app.louisstones.com
lucamorrow.com
lucky-skin.com
laboris.luxater.com
matchelly.com
www.merabtene.me
app-stg.mmseas.com
mohyaghoub.com
nikolousis.gr
nususc.com
offgen.net
pagapr.com
www.philoshea.com
playpromptly.com
presidido.com
cms.primpo.app
r6skins.cc
redbeacon.cl
www.reeffunctionhub.org
pk.reliablepunching.com
rodneyshafar.com
rowans.page
www.rssistemas-itu.com.br
sadaiv.com
savely-editor.com
www.servielec.cl
click.setu.in
strategicapp.shoshkey.com
www.skallafantur.com
console.dev.smartcloud.smartsys.io
app.spbeu.ru
artist.stillac.com
supporttrust.org
link.syncmd.com
tanglehub.org
links.tellapp.com
admindev.thepearls.com
live.time-drops.com
www.tomato.ai
ffc.tshembo.com
portal.staging.vendpark.io
www.videogameon.com
volter.energy
dev.willo.app
workhard.store