95/100 SECURITY SCORE

Certificate Information

Subject
CN=invites.dev.payd.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 31, 2025
Valid Until
January 29, 2026 59 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E9:DA:86:F8:71:23:B6:11:72:F9:68:DB:A9:61:80:52:FB:A0:C2:C4:E2:80:48:9A:1F:6C:00:4A:EA:2C:1B:10
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
Content-Security-Policy
Good
default-src; script-src; style-src; +15 more
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
geolocation 'none'; camera 'none'; speaker 'none'; vibrate 'none'; microphone=(self 'https://isc-chat-stage.web.app'); fullscreen=(self); payment 'none'; sync-xhr 'none'
Recommendations
  • Strengthen CSP by removing 'unsafe-eval'

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
mozaikplay-advisors-stage-1.ischoolconnect.com

Other domains in certificate

iia.agency.in
dashboard.altamarcm.com
www.amrzedan.com
anaz.ae
birnsaquamate.anekonnect.io oceanscan.anekonnect.io
anishchouhan.com
deposit.apigamewallet.com
araiinfotech.com
artistekbuilders.com
koyi.atakaice.com
auroraguides.site
www.auzzierunfamily.com
biazo5.com
dev.bigdreamboard.com
portal-qa.bitsonic.ai
borreliachecken.se
app.breezeai.com
cantstoplearning.help
corp.cdc-jp.com
app.centrumszkolenmorskich.pl
tnorth.co.in
trailpass.contextfound.com
www.cruisecalls.app
dartopen.com
test.esri.on.decisionrules.io
puzzles.hirata.dev.br
soclover.drpjl.com
www.ecommercefusion.co.uk
edhc-bio-labo.com
budgify.elfinancialista.com
live.farmgateauctions.com.au
fix-wagen.com
litera.flavioosh.com
app.foodlee.io
taskmap.g2solutions.io
www.gemahernan.com
explore-test.gemini.edu
www.hoewerktduurzaam.nl
iglivestreams.com
emoji-codebreakers.immersescape.games
indiatribaltours.com
www.inovhy.com.br
app.test.inrelation.io
jjhstore-ltd.com
jouwboodschappenbuddy.nl
juliolenis.com
kaseemstephenson.com
kasiawozniak.photo
kmgtechsolutions.com
www.kyleweintraub.com
www.lapiazzagenk.be
levizumi.com
www.lewiscountymutual.com
www.lexicount.in
www.mashaimmigration.com
manager.milktech.io
monkey02.com
mountd.com
www.msbauheld.de
muttch.com
nagashima.dev
www.laufmit.nataliepawlik.de
cof2.neoufitness.com
orb.wada.net.br
dekksok.nodelab.no
erd.oneselect.global
overlock.cloud
owendavisbower.com
paganeto.store
invites.dev.payd.com
stage-signup.peakflo.co
driver.pksoslo.com
helfin.portfoliolink.co.za
dev.quakermaps.com
restaurantnapoli.nl
robertreppel.com
hotels.roomcheck.co
runningman.io
driver.dev.safetyinminutes.ca
salarytt.com
samgetlan.com
sisselfood.se
skipt.app
l.dev.clue.spinlow.co
app.starlinklab.in
www.tcgnotify.net
www.textilsanramon.com.pe
beta.timeboss.app
timesoftware.llc
arcadisenergie.tqwi.nl
tsvtek.com
www.underscore.co.jp
www.vastuviterp.com
vectizo.com
kop.venuetax.com
app.woodstock.club
www.yourtech.co
zero1code.info