Open
Cached
·
just now
86/100
SECURITY SCORE
Certificate Information
Subject
CN=www.initcorp.co.kr
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
January 16, 2026
Valid Until
April 16, 2026
86 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
37:75:D0:73:86:A6:9B:95:A0:49:6C:02:90:B2:AB:67:53:8D:AC:91:1D:E5:3E:29:33:D0:E6:21:64:4E:E4:62
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=63072000; preload
Content-Security-Policy
Basic
frame-ancestors; worker-src; script-src
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
lyricstudio.net
afrojastyle.com
www.anneshoe.com
share.apie.app
app.autourdesparents.fr
pc.bangdiem.vn
benatoms.com
www.benatoms.com
apply.berlinartprize.com
beyondvibecoding.com
m.bongdatm.com
transferf.calabresi.com.br
aspect-ratio.at.calculatorhub.app
calimaru.com
links.catapoke.com
catholicretreats.net
chats-club.com
www.clinicaciudad.com.ar
www.aipr.co.kr
www.initcorp.co.kr
bla.coachpipe.com
www.colorpageforkids.com
www.ctforwarding.com.my
cdmedia-staging.contentcard.com
ctmp.corsecontrol.com
crackmock.com
the.curbd.app
www.dailynotes.cc
dailyuxwriting.com
www.dictation.io
www.diyonwaterpets.com
admin.dmsounds.nl
www.elranchowine.com
eyephone.wtf
docs.floatvalue.com
rates.fundwave.app
app.glassfrogg.com
www.grandheroes.org
www.hadessaveeditor.app
houseofzyora.com
iatlas.app
lab.ibhava.com
qlongg.id.vn
imaharah.com
elitefitness.impactwrap.com
www.ire-view.com
www.jandomtl.com
jinjatechhub.com
jm-swimming.academy
mkp.kioscodeseguros.com
kprinfotechsolutions.com
word-streams-dev.letsdive.io
letshike.co
www.levelwork.io
www.littlecitytreat.com
www.littlely.nl
lumafi.ai
maisonmayaki.tg
mathaminfotech.com
www.mixalo.eu
test-popup.mobilitymojo.com
support.mrblocks.nl
onboarding.muslim.events
privacy-qa.myvaillant.com
www.colmena.net.co
norahs.world
ntuna.com
oquecomer.net
app-admin.fcp.org.ar
events.pesepay.com
playset.app
www.qpos.me
app.qualiitrak.com
plataforma.rastrotec.com.br
rdadvisors.co
www.reclameaquii.com.br
redoui.com
www.reseye.app
gitfinder.richardsonke.com
www.rzz.me
sauronseyes.com
www.security-center.net
sitemax.showitbig.com
shriramschoolpataudi.com
shwetsatya.com
www.softcactusstudio.com
www.spookydooky.net
stissingtheatreguild.org
www.swagdecorative.com
www.swisssetter.com
staging.onthi.tabbook.vn
www.tailorno1.in
trackvest.xyz
friendlychat.tugan.app
www.u-d.co.jp
www.umland.berlin
www.upperpneus.com.br
insights-dev.labs.valorep.com
verbia.systems
www.writeit.ai
Other domains in certificate