77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.playtrainmotiv.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 27, 2025
Valid Until
January 25, 2026 65 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5A:7F:95:15:ED:D2:40:48:4E:CE:9F:17:1D:4D:37:12:76:09:88:EB:BA:BD:29:31:CE:52:F6:2A:CC:93:7D:15
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
lowes-kitchens-cert-b.3dcloud.io

Other domains in certificate

astroteaser2.32studio.org
download.aadee.app
www.acczyoutsourcing.com
www.ai-jihye.com
all-players-tool-lab.com
v2.angular.io
www.anse.ro
unisobrasil.appshare.com.br
asani.in
contact.atakanyigit.com
survy.binds.co
care.blufiori.co
booza.app
www.cargopro.ai
client21.citadel.tools
simplysoy.co.in www.xpulse-uat.co.in
www.codebaes.org
condoalert.ca
ford-app.ctrl.co.za
doomagency.co
usados.dycar.com.ar
www.entourageuae.com
www.erpack.dev
control.eventools.ru
www.farwise.com
portfolio.federicoduret.net
corporate.dev.first-iraqi-bank.co
souscription-dev.flitter.fr
fractalflux.com
getroadie.app
dev-jornada.paciente.gohealth.tech
www.gomchik.com
gomesse.fr
granomio.com.br
site.halucuraft.dev
admin.heavyagger.dk
portal.ifeelfood.co
bizgeek.infocityhosting.in
themarsvoyage.interzonas.info
jsanchez.is-a.dev
invest.jantbeatsfestival.com
link-choi-wan.jec-digital.com
kenjeborsten.nl
kingdomhall.info
fitd.konahart.com
www.ksslc.co.uk
www.kurrent.studio
kuto.app
catalogo.lememilitar.com.br
mascotia.co
www.mealstogether.org
mes-rendements.fr
www.mikaelstrid.se
www.norbert.page
numismat.app
www.nyevo.no
www.occasionpark.com
oga.co.jp
sandbox.oh-ship.co.za
fightech.oz-tms.com
pulse.panavizo.com
www.playtrainmotiv.com
www.pms-eg.com
l.prezage.fr
privacyvip.com
dev.mission-control.pwapilipinas.org
dev.riders-coffee.com
module.roccai.com
samstrucking.app
therailpark.dashi.sasaki.com
new-testlink.sbulltech.com
www.securentis.com
www.seotaiwanseo.com
www.sepran.id
app.sigma3b.com.br
www.sigmapiuw.com
vtc3.simpliroute.com
simplseat.com
www.singinglessonscoventry.com
strawhatinnovativesolutions.in
subnet.techlanda.com
www.tenderbox.my
thinklink365.com
www.manager.tipthebandapp.com
toddyflores.live
trendzvornik.com
app.trustfinta.com
feriadigitalov.uanl.mx
static.unicornboost.app
app.vervewater.co.za
app.vigourise.com
vishnupe.com
vizure.net
wakamemt.com
app-dev.wearefairgame.com
wimble.cards
emojibar.wurkspaces.dev
xenon.engineering