Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.unitysworkbench.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 21, 2025
Valid Until
March 21, 2026
68 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A2:84:04:05:3D:9D:D2:D2:DD:C8:18:CF:F5:66:09:CA:20:51:28:3B:B6:88:4E:6B:9A:80:DA:69:CB:7F:0E:81
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
merrycryptomas.com
testing.app.cupcake.29k.org
admin.testshopping.a-sta.com
ahaevent.org
www.anosales.net
www.aromaklinikken.com
balloonartist.in
biathlon.io
staging.karma.blackcurrantlabs.com
auth.bookup.online
breas.mx
brightuplabs.co.uk
bsidesbangalore.in
rtms.ccwc.io
cijferroyale.nl
classy.menu
tostadocafe.clau.io
cleverti.me
makeupmaster.co.in
gacha.conquestph.com
cytiva.mom
www.diomedica.com
app.disconnections.net
link.dkn.uz
docin.dev
customershipping-q1.dpduk.dev
gears.staging.drivetrainhub.com
www.easyscrum.eu
aritmakids.ekopujiyanto.page
etcgraphic.com
sandbox.everwritten.co
app.findz.app
auth.giftock.com
gocape.town
super.hanak.in
healthlk.com
www.hlavac.business
holod-baikala.ru
www.i550.com
app.indicors.com
www.ingeniousapps.tech
app.inovaed.com
istech.ro
jin-jin-jin.com
www.keindeya.com
kemecuador.com
share.kernet.co.za
modusdirect.madhive.com
www.maucobytes.com
maunayoga.org
www.metsatyopalvelu.fi
mindforge.in
books.internal.ml6.eu
mycity.mx
myjourney.icu
app.nexgami.com
notefuel.com
www.optiminy.com
barton-brook-green.ovh.org.uk
espace-accedant.partenordhabitat.fr
f.peoplehum.com
www.platic.es
www.pokerpuzzles.com
www.poweroptimus.com
puzzoola.com
jts.qati.me
qpes.co.za
bordiple.rafaelcamargo.com
dev.readingformeonline.com
docs.retium.org
rockstarlab.dev
try.rotapad.com
docs.scryr.io
www.segotravel.com
app-dev.shabu-yuzuan.jp
simplems.net
portal.skylarindia.com
soltroll.io
www.spsconvert.tech
www.standwithukraineapp.com
studybuddy.cz
dev.teacup.gg
invite-ping.telebu.com
shadeswood.terpity.com
themangalview.in
engineering.theorygenerator.com
toddler.training
trashbasher.fun
qt.turnosweb.app
auth.google.goplay.tv.br
ukuchile.com
www.unicoreproject.com
www.unitysworkbench.com
urbanodelivery.com.br
www.vieth-zahnaerzte.de
vk29.in
vyarth.com
www.vyarth.com
www.wifi-speedtest.com
worldwar3d.com
Other domains in certificate