Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=bako.co
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 22, 2025
Valid Until
January 20, 2026 58 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CD:02:65:E1:CF:35:A8:C6:DB:E3:21:EE:64:2D:DA:75:C2:D2:2B:FD:A6:14:D6:DF:4A:35:9C:CC:BC:A5:69:19
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
matan-dayan.com

Other domains in certificate

www.abrcomputers.com
abrionfreight.com
configurator.accessiway.com
www.agorify.com
app.alpho.com
alzahrahajj.com
business.stage.amplifylife.com
www.angelimittal.com
hello.anisehealth.co
hu.artboxy.com
www.autogoldmine.com
www.azadf.com
www.bakeaholicks.com
bako.co
balcancrossover.com
bizbit.bitfixsystems.com
machiavelli.bjorge.com
hub.bytecolony.com
byyiro.dev
cberner.com
centerthediv.com
www.cesar-acosta.com
www.cipherarmor.com
www.clinicasaludintegral.co
signup.cloudasta.com
codminers.com
dev.colerobertfisher.com
www.ajls.com.np
completecircuitelectricllc.com
svkaxis2.configurableart.com
mail.costumesbycrystal.com
cryptoornotcrypto.com
czepbuilds.com
www.dailyuxwriting.com
danielmingey.com
danpavlov.com
www.decorumapp.com
defirm.ai
gamesmod.drapalamathieu.pro
dylanjmcdonald.com
bniroyals.dynamicliquids.com
app.dynamicroadmap.com
eagleridgestays.com
eokul.dev
fincaponce.com
foursalesgroup.com
team-it.gbirdtech.com
dev.myadblock.licensing.getadblock.com
restream.gostream.vn
grove-app.com
gsaero.com.au
habitition.com
d.heiminspektor.com
app.honeydew.cloud
www.invrdao.com
www.jayandlark.com
jlcontovasilis.com
www.jonathan-dennis.co.uk
app-dev.justonechesed.org
kikbak-app.com
klara-scheduling.klara-team5-staging.com
www.ktwapps.com
my.kyndwellness.com
www.lifequeststudios.com
mailrhunt.com
mobilemistingaz.com
hn.mumk.dev
dashboard.nefacabs.com
neuromorphiccloud.com
business-dev.ngdel.com
link-automatize.nibo.com.br
nissansthyacinthe.com
nolatreatmap.com
test.notch-health.app
oneclub.backstage.oneclass.vn
oppsett.no
www.optimaldigitalgrowth.com
parkdellen.pdr.cloud
peacefumediation.co.uk
www.peterperezjr.com
dev.dynamic.pindaz.com
project9brewing.com
rightcareerpoint.com
rollmydices.com
salamfoon.fi
sallys-tiertraining.de
www.samuioffplan.com
shalomrentacar.com
solutionservicesgroup.com
soruyabak.com
www.stecorretoradeseguros.com.br
tapotap.com
protenis.toplay.app
tvapi.cn
www.twinsimo.com
www.vitskuliiga.fi
m.wickedcampers.co.nz
configurator.endor.integ.y1.de
zachariahwatson.com