Open
Cached
·
just now
92/100
SECURITY SCORE
Certificate Information
Subject
CN=static.alledotech.in
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 19, 2025
Valid Until
February 17, 2026
85 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FA:27:AA:18:0A:E8:07:C5:E2:15:78:06:1C:A5:B1:BF:54:5F:9F:E2:5F:21:01:04:B3:76:BC:88:1A:29:EC:51
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Good
default-src; connect-src; script-src; +10 more
default-src 'none'; connect-src 'self' https:; script-src 'strict-dynamic' 'sha256-ErSGQ5RkfdaGFyDT7yi/vnakQoxNloHzsJR8SRc4ISE=' 'sha256-OCIXGGEs6GGJrkZ3DhTMqIm277qA8+G6HZuJoB9i23g=' 'sha256-58sds9O7fxu83qHKg3dpDUACqVL3gbpuiDHIBn7eyOA=' 'sha256-DHJs+kXwtZMstB3VdRI/M0GJcMPj7BOOElIZHVH/9k8=' https: 'unsafe-inline'; img-src 'self' https: data: blob:; style-src 'self' 'unsafe-inline' fonts.googleapis.com; font-src 'self' fonts.gstatic.com; object-src 'none'; base-uri 'self'; frame-src https://syqlo-nava-dev.firebaseapp.com/ https://nava-staging.firebaseapp.com/ https://mm-nava-prod.firebaseapp.com/; frame-ancestors 'self'; form-action 'self'; trusted-types angular dompurify google-maps-api-loader google-maps-api#html goog#html gapi#gapi lit-html default; require-trusted-types-for 'script';
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
accelerometer=(), camera=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Strengthen CSP by removing 'unsafe-eval'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
nava-dev.syqlo.com
104.tw
2022.kspaze1.art
untifo.253below.com
4bytes.in
www.activemetrics.com
prerelease-dashboard.addble.com
www.agamworks.com
agnostech.in
static.alledotech.in
chat.astropedia.fr
atsru.ro
member.aumhum.com
www.bagarinho.pt
baya-relocation.fr
ubbrugby.deeplinks.bfansports.com
csm.bitkey.site
roadmap.bonobo-project.org
bpurplehq.org
bridge2things.com
www.bytecodev.com
candiceai.co.za
links.celebchamp.com
www.cfo.chat
rook.chektdev.com
ref.chientran.com
admin.ciye.co
www.codingarena.io
www.creatillo.com
auth.cyberwingman.ai
decisionlab.com.br
www.digioindia.com
disimprove.com
duliptech.com
dveri-renessans.ru
develop1.manaport.seto-solan.ed.jp
pcgddaknong.esoft.edu.vn
www.invitados.eduardoynely.com
eng-ai.com
links.engineeruniv.com
fatbrother.net
fireenjin.com
invite.fitbeat.com
m.four-site.com
www.ghostcoinhq.com
googleformstemplate.com
firebase.gregmoy.com
www.hairbymoosh.com
idea-association.nl
app.integrity1auto.com
admin.iplatform.it
advisor-dashboard-demo.ischoolconnect.com
billing.jack.joynson.software
admin.kegtracker.co.za
laptoptassen.nl
lennonkatsumata.work
lexeducation.in
www.lmcalc.com
mam-enterprise.com
electromenager.marmelade.io
matrioskas.es
www.maxhairdiffusion.it
en-qa.memberhub.de
merchbytes.com
meroedu.com
www.miaoo.io
www.minigolflive.com
minimousemacro.online
motivizatehoy.com
neilpathare.com
niftybounty.com
niklaspirnay.com
client3.onlinetestyap.com
orcacode.com
www.overyonderonthecape.com
dashboard.parfums-asie.fr
pixlk.com
podium-link.com
radfi.network
www.re-ynd.com
www.retokena.com
qa.riffbox.app
runsak.com
sikkimhighvisionrealestate.in
www.soleadoj.com
recette-auth.speakylink.com
stevenayerscarter.com
survlee.com
tempbutton.com
theblb.in
www.theshdp.org
tivra-ai.com
field.tomson.xyz
villamerica.hu
www.svarka.vn.ua
vny.dk
volleymusic.com
admin.wrdz.app
yamamap.com
zylitics.io
Other domains in certificate