Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=1choice.construction
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 26, 2025
Valid Until
January 24, 2026 64 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7F:D1:A4:EF:60:60:15:27:AD:58:85:D8:85:AC:28:CD:21:7C:52:C0:4F:E1:64:F1:97:EC:5D:D3:CB:74:45:4D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
luca-ruf.de

Other domains in certificate

api.0xed.io
1choice.construction
5binvestments.in
adtriggers.net
aduanasanitaria.com
maraissa.agri40.ma
config.alusta.be
www.angulararchitecture.com
www.bayudewanto.com
fitbit.biotasense.dev
www.bortoni.net
portal.centrictech.net
staging.chatwithsteiner.de
cloudreports.ru
test.comnify.tech
beta.debtpanel.co.uk
alpha-trad.decaweb.fr
designist.co.uk
credits.digitalway.guru
myedinburghpark.equiem.mobi
qr.everest2003.cz
familyfresh.app
felipe.run
bonfire.firelink.info
www.flaner.com
flashcare.in
flintsol.trade
admin.flyingpigs.dev
monitoria.stag.gen-t.science
offers.getsway.com
gigigo.hu
app-temp.guestdash.com
www.horseriding.app
cse.hsyn.de
bethpage.impactwrap.com
its-mono.jp
a.bo.jug.im
justadmin.lol
www.justapplication.com
www.kcsam.net
www.kibervarnost.si
kol.ski
kourosh.de
www.kushpa.tel
universidadunirem.lapieza.io
dashboard.dev.lecto.ai
www.leinumber.uk
blog.lfabbro.com
loora.app
www.loyaltyautopilot.com
maanenergia.fi
lab.play.medeintegra.app
medicaresoutheast.com
cfunhotel.menuaddis.com
www.mykeyoffice.com
s.neuromagic.com
northfieldchoir.org
admin.staging.ohmymenu.com
page.ontic.ai
ottawa.profit.orderprinting.com
overengineered.ai
www.paytip.chat
terminal.pieterlinde.com
redirect.proposal.studio
ecard.prosenectute.ch
purim.app
www.recuropharma.com
reservadoapp.com
app.robertoesantos.com.br
roo-ogonek.ru
www.sarfaraztech.com
pincraft.saulnunez.com
seatmapgenerator.com
sebarosales.dev
sco-office.stg.shippio.jp
www.shivrajelectricals.com
signupclipboard.com
next.simplassur.app
www.skolekart.no
app.smoothielemammouth.com
solporno.com
www.sumnerdata.com
swiftfixservicesltd.com
www.techiepeppers.com
thebitcoinhole.com
www.therapeuticsupport.com.au
link.therich.io
www.thermodelchoc.com
dev1.trayectoriaseducativas.com.ar
www.tvgmm.com
unitedautosports.com
ununifi.org
utkalalumni.in
krest.vidocto.com
walmartmyhealthjourney.org
app.kiidc.webapiservices.in
www.younggrasshopper.co.za
erik.r.yverling.com
v3.zubtitle.com