Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Google Trust Services, CN=WR1
Valid From
May 01, 2026
Valid Until
July 30, 2026
80 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
41:7E:C5:D6:70:7B:E6:9E:85:07:BF:F5:B9:4D:3F:11:48:61:BE:10:94:7E:AF:56:47:B6:C0:ED:E5:AE:5C:15
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=86400
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
49 domains
mangled-rc.com
akronboudoirphotographer.com
www.akronboudoirphotographer.com
tls.automattic.com
belgiumimagyarok.link
www.belgiumimagyarok.link
dxthive.com
foxart.uk
jlburkholder.com
jorgemartretblog.com
www.jorgemartretblog.com
leschroniquesdafifa.com
www.leschroniquesdafifa.com
lovespiceandeverythingnice.com
www.lovespiceandeverythingnice.com
manardiesel.com
www.mandolinenorchester-bischofsheim.org
www.mandycollie.com
mandyevebarnett.com
mandysavesmoments.com
manglermixer.com
mangoesworld.com
mangosandmonkeys.com
www.mangosandmonkeys.com
mangoseedsandpintobeans.com
mangroveecology.com
www.mangroveecology.com
mangrovescience.org
www.manickmanda.com
manovrage.online
www.mercycenter.ee
www.mfbarrettlaw.com
www.mintstringquartet.com
www.novascotiaartisticswimming.ca
ohio-boudoir-photographer.com
www.ohio-boudoir-photographer.com
oneoak.capital
www.oneoak.capital
oodlesexotics.com
www.oodlesexotics.com
ourvineyardcreek.com
pipe-tahoo.com
ramzibenzina.pro
www.ramzibenzina.pro
revitivinfusions.com
www.revitivinfusions.com
russischraclette.blog
shustruck.com
thesparklygiraffe.com
Other domains in certificate