Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=app.beaherotoday.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 01, 2025
Valid Until
March 01, 2026
89 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
83:7F:C0:45:6A:B2:04:AB:E3:8A:83:3C:DF:31:66:1F:67:C4:0C:73:F5:3D:5B:23:6C:4A:73:E4:FA:46:E6:1F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
material.coachreferee.com
admin.passcard.psu.ac.th
compass-staging.acelr8.com
albatross-bets.com
alisagames.com
antillect.org
www.arquivo.app
avasync.apps.avada.io
www.axonapps.net
barsosteria.it
molkky.bayly.eu
app.beaherotoday.com
www.becketto.dev
www.betrustworthy.ca
betteragenttools.com
member.bodymechanicshealthandfitness.ie
app.bydesign.io
ceylonese-travel.com
chingaderas.studio
chop-me.com
jsmartapp.co.il
cobycolson.com
cochranglobal.com
www.correlate.me
western.cxipl.com
damith.me
datasensum.com
digifybd.com
doubleu-adv.com
myproductbook.dpdlocal.co.uk
app.elinkfinance.com.au
adminwebtest.equipmyschool.com
finopsy.info
fittl.app
www.footprint-ai.com
freshfarmfoods.co.za
getchristian.app
gigfuel.app
www.haketech.com
staging.hazira.com
hyperpolybook.app
impfdashboard.de
www.infinityinvest.in
developer.iprogrammer.com.au
eurovision.jkstudios.be
jolias-sanchez.com.ar
babydash.jonchiam.com
www.teamradar.katalysatorduravermeer.nl
links.klips.me
legaless.fr
www.lindener.it
www.liquidgov.org
connect.locus.sh
www.lucabosch.com
luxurysocks.in
www.mairini.com
www.ai-english.manlai.app
marjukcreates.org
farmlands.market2x.app
www.medeberya.app
www.melissamolina.dev
dealify.mobappcreator.com
moments.ooo
api.muhoov.eu
www.netwhere.online
notii.app
odysseyskinandhealth.com
ollis.app
www.ollygraham.uk
omentum.app
argonassault.otherg.com
www.outfitz.app
www.popkode.fr
www.pramukhmoneytransfer.in
projectmeet.app
analytics.qa100-raksul.me
value.qu3ry.net
www.rainwords.fun
ref.cards
restart-creations.com
brb-erp.rosoftsavvy.app
savannaoils.com
poc.sgmobileuniverse.com
app-link-dev.shabu-yuzuan.jp
shidory.com
shiksha.studio
sides-ways.com
www.smallmiraclesedu.info
open.staging.snapscan.io
toolbox.solsyn.dev
dev.sportscards.io
app.super-tenant.com
www.synallagma.gr
tapall.nl
auth.taxscouts.es
novel-studio.teller.jp
console.carrot.ultraimpression.jp
www.waifu.digital
wearltc.com
alpha.wearsafe.com
Other domains in certificate