77/100 SECURITY SCORE

Certificate Information

Subject
CN=tree-of-remembrance.hwa.org.nz
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 21, 2025
Valid Until
February 19, 2026 89 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
42:D1:69:CA:BA:2D:C2:12:C2:0B:AB:02:30:9E:73:4E:03:A5:32:53:C8:13:E2:26:65:E2:88:EC:55:09:6A:8E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
macusegwin.sqwadhq.com

Other domains in certificate

freedom.5f.app
www.971tutors.com
www.aldealafuente.eu
www.anamedeiros.net
cao-textiel.appdashboard.nl
www.calluson.com
app.camzify.com
chatsupo.com
www.cleanmycrate.com
me.cmelon.top
collegebar.co.il
www.irasolution.co.in
www.codingexpress.ca
gsoc.cormas.org
dm.crosscorners.cloud
www.davidjohn.pro
dibbery.co.uk
eatrics.be
edensitko.com
www.educationaz.com
eduteeb.com
admin-int.eeule.de
admin.eezycoach.com
epzira.com
yt.evanzap.com
fastandlow.app
web4.fidisys.com
dvabeautique.freshlygroundapps.com
lencoispaulista.g2canal.com.br
gpogrtech.com
harem-law-firm.com
tatangga.hendywijaya.com
dev.herdscope.com
hillsdalechargerscamps.com
www.hora-ev.eu
bookings.ihe-oman.com
ihelevate.com
kcfs.imanage.services
mobile.innovint.us
jaylinbowers.com
kingsoffadesalon.co.za
lifeofobjects.co.uk
www.lucasoconnell.net
guarantymedia.madhive.com
www.matchmagik.com
metroartweho.com
soycandidato.co.moons.rocks
app.morningattire.com
nabo.demo.movello.se
mriverius.com
dashboard.mytelescope.io
dev.twinkle.nandenjin.com
nascarlawsuittracker.site
www.nextops.au
nftytoolkit.com
noelwhitaker.com
nordicoscardapio.com.br
www.nuvocentrix.com
www.okven.com
app.onpointify.com
tree-of-remembrance.hwa.org.nz
para-nerede.com
www.paven.io
bt.sample.pe.kr
www.physiolife.center
www.proto.software
www.rahuldey.dev
www.re.cards
www.my.reflection.app
www.rgvstorage.net
rodolfoborja.com
rodrigorosario.es
rrguntaka.com
ruckcloud.com
sb2hspse.bj
senselabs.ai
canarana.bioponto.sistemasnemesis.com.br
share.dev.smarty-app.com
solpiccoinmuebles.com.ar
ember-utils-react-staging.staffshift.com
en.stenograf.io
streamzy.io
dev.swoof.me
taginsight.com
www.takalavouna.gr
takeoutme.jp
www.thestartravellers.com
tidyfork.com
games.together.science
www.trayi.org
www.tuinakinaterapi.se
admin-salud-autenticostigres.uanl.mx
www.universoenergia.com.br
www.verzekeringenvdb.be
gallery.victorvdb.be
www.x-syst.com
yarnea.com
www.yozeinc.com
ytlhomes.co.nz