Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.leforestier-philippe.fr
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 22, 2025
Valid Until
January 20, 2026 48 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
11:1E:FD:4F:2C:DE:57:A7:81:31:A6:5F:00:D7:14:52:CC:FB:0F:C4:0B:5E:4B:6E:B6:21:11:7E:35:56:47:87
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
nedimhozic.com

Other domains in certificate

verify.acceede.com
bta-dev.affinity.do
www.agripuratchi.com
www.allinleak.com
www.ashfield-project-services.ltd
backchats.net
pre-prod.sso.baselane.com
www.bharathway.com
bigclock.party www.bigclock.party
teambonus.bondvet.com
www.bpm-buddy.com
apps.bythewake.com
calculosparaadvogados.com
portail.caprea.ca
tools.categoriacanal.com
api-docs.certane.com
m.charitybidder.com
app.cocoopter.com
teamplayer.com.gt
pmpro.com.pk
compete-game.com
dashboard.kiosk.cook.company
www.davidsz.com
carestreamdental-stage.dentalxr.ai
carla2018.deroberto.com
dominicanaava.com
dracofy.com
www.emotionally.app
endangeredclub.com
www.envolve.com
personal.epesipay.com
equilifeoffers.com
exogenlabs.com
www.ezfishbot.com
f-medapp.com
foodability.falkor.io
www.fritemos.com.co
console.fuseleadmarketing.com
stage.studente.futuri.education
www.getketoaf.com
ginecosr.com
www.givingishuman.com
landing.gourmai.co.uk
work.hi-fab.com
js-spm-78899.homsync.co
pos.ignitemenswear.com
www.imcool.do
inhr.dev
itchyfeet.com
www.jmpecharroman.com
bank.kahero.co
client.klipcard.app
kshanikstudios.com
kyawmoenaing.com
l-s-c.org
www.leforestier-philippe.fr
medulla.app
admin.memorize.ai
www.minecell.io
staging.motoverse.games
www.mylysoftware.com
onedollarwebsite.co.nz
kids.onmobile.com
oh.ourhello.com
app.paroty.me
baleus.pleasecuddle.me
proxymatch.io
www.qman.nl
qudak.se
qrdemo.resourcify.de
rewrittendesign.co
admin.rokam.co
static-page.salary-hero.com
consumer.sifted-demo.co
simoes.co
sjhc.in
softnixy.com
share.connect.somtoday.nl
www.sportshubegypt.com
sportsspeed.app
www.standbylimos.com
dashboard.stitchedbrand.com
www.streetmix3d.net
susarlabs.com
www.torihamilton.com
treepodia.com
www.tsunami.nz
ucls-artsfest.org
member.uhas.com
www.urlvayu.com
deeplink.staging.vendpark.io
help.voxelo.ai
walpurgis.fr
xtable.co
ticket.yuzuyou.com
travel.zenokoller.ch
menu.zyprun.com
nursery-qa.zz2.co.za