Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=scm.piticommerce.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 07, 2025
Valid Until
January 05, 2026
40 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FD:C1:2B:C7:E8:1F:A7:3E:38:8D:F7:DB:73:AD:C7:67:19:8E:3E:07:44:2D:89:DA:F8:ED:7D:6D:78:CA:F5:81
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
mantarstudios.com
link.123mobileapps.com
1shipping.in
activitiesmatter.app
www.alanayoub.dev
nws.almeraim.com
gnk-staging.anyware.software
bq.axel-karcher.dev
bhoominursery.in
dev-portal.blazebite.com
www.bootstrapping.tools
bustedmag.net
vificapital.co.in
privacidad.cochabamba.bo
comvc.app
www.app.staging.coupocket.com
communitree.crosscorners.cloud
cycler.io
www.dahmerconsorcios.com.br
dev.authentication.dataiads.io
www.designbiofilico.com.br
digi-shark.de
webapp.dimenzio-kft.hu
accesscode.divethru.com
djandyjuice.com
admin.easytaxconsultancy.com
www.explorerclaims.co.za
finance.feijo.dev
login.feldfuehler.app
flyerx.app
link.foundry45.com
www.fouroaksconsulting.com
www.ganandgarage.com
dev.getmade.co
links.grata.life
www.hard2say.com
phoenix-dev.hi.fi
hoardle.net
punchkingvietnam.impactwrap.com
talentacademy.indiandevelopers.org
www.investabloom.com
weatherly.jkierem.com
app.leedus.io
maler-durdu.de
www.muuttokuopio.fi
myexclusive.ge
maptest.mysticetus.com
qr.namsutech.vn
nickipedia.dev
omshakthiproperties.com
oneglobb.com
open-science.xyz
www.pharmacist.dev
dev3.pitchxo.com
pitcraft.io
pitirestaurant.piticommerce.com
scm.piticommerce.com
www.problemdaily.com
tiny.puddy.club
www.punfoods.com
employee-health.quantactions.com
interna-ee.queliga.com
app.ipbso.portal.quietpathtech.com
raskmote.com
stg.nik.re2fe.com
www.rebeccapacht.com
efsolare.rgateway.it
rizwanmustafa.com
www.samisafadi.org
app.sampledecks.com
santafd.app
admin.shaale.com
shashandkat.com
auth.qa.somostera.com
sougile.com
www.splendo.health
statusbeacon.com
link.steaker.com
firebase.strainprint.ca
relevance.demo.styloml.com
wuxing2048.sumlook.com
syscontrolar.com
trip-service-en.tadatada.com
takeyourpillsapp.com
textmarley.com
www.thelittlesafari.com
thetalesitell.com
burg18.score.to-on.com
trainee.dev
link-qa.trytrue.com
link.trytrue.com
tv-nfts.com
www.ukrainify.com
unipathapp.com
testnet.vaultrio.com
app.int-live.vibepay.com
volontairesmontagne.ch
app.witful.dev
wrapigo.com
zeltlager-wilhelmsburg.de
Other domains in certificate