Open
Cached
·
just now
91/100
SECURITY SCORE
Certificate Information
Subject
C=CH, L=Zürich, O=ABB Asea Brown Boveri Ltd, CN=mobileappsourcecode.abb.com
Issuer
C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
Valid From
August 12, 2025
Valid Until
August 11, 2026
203 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A9:89:50:C8:BB:54:45:42:8F:E0:A9:8E:6E:30:1B:DA:F5:AD:0C:4E:62:C6:7C:97:B2:9F:28:ED:F7:B5:B7:95
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000; includeSubdomains
Content-Security-Policy
Basic
base-uri; child-src; connect-src; +12 more
base-uri 'self'; child-src https://www.google.com/recaptcha/ https://www.recaptcha.net/ https://www.googletagmanager.com/ns.html https://mobileappsourcecode.abb.com/admin/ https://mobileappsourcecode.abb.com/assets/ https://mobileappsourcecode.abb.com/-/speedscope/index.html https://mobileappsourcecode.abb.com/-/sandbox/ 'self' https://mobileappsourcecode.abb.com/assets/ blob: data:; connect-src 'self' wss://mobileappsourcecode.abb.com; default-src #<Module:0x00007f4463d29c50>; font-src 'self'; form-action 'self' https: http:; frame-ancestors 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/ https://www.googletagmanager.com/ns.html https://mobileappsourcecode.abb.com/admin/ https://mobileappsourcecode.abb.com/assets/ https://mobileappsourcecode.abb.com/-/speedscope/index.html https://mobileappsourcecode.abb.com/-/sandbox/; img-src 'self' data: blob: http: https:; manifest-src 'self'; media-src 'self' data: blob: http: https:; object-src 'none'; script-src 'strict-dynamic' 'self' 'unsafe-eval' https://www.google.com/recaptcha/ https://www.recaptcha.net 'nonce-pHj752MgSKES+O8oKKJ+1Q=='; style-src 'self' 'unsafe-inline'; worker-src 'self' https://mobileappsourcecode.abb.com/assets/ blob: data:
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
interest-cohort=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports