Open
Cached
·
just now
89/100
SECURITY SCORE
Certificate Information
Subject
CN=nexant.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
December 10, 2025
Valid Until
March 10, 2026
71 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
32:2D:FC:2E:B7:5D:87:09:95:26:CA:4C:DE:A9:4D:88:49:33:A6:2E:49:98:30:7B:D5:E8:99:E5:A5:EA:C5:56
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
default-src; script-src; base-uri; +5 more
default-src 'self' https://app.cookieyes.com https://log.cookieyes.com/ https://cdn-cookieyes.com/ https://www.google-analytics.com/ https://pagead2.googlesyndication.com/ https://www.google.com/ https://www.googletagmanager.com/ https://directory.cookieyes.com/; script-src 'unsafe-eval' https://www.googletagmanager.com/ https://pi.pardot.com/ https://cdn-cookieyes.com/ https://log.cookieyes.com/ https://app.cookieyes.com/ https://cdnjs.cloudflare.com/ https://www2.resource-innovations.com/ https://recruitingbypaycor.com/ 'nonce-dGtycmhodnBsYXp6empybXZxbW5ya2xjd3JrcW5obmd3Z2dq' 'nonce-ampxeGh5eWxzdm11bnl3amZqcmhtdmRueHNhd2psenRkZGpo' 'nonce-YXF5bWhlcndnc3pxb2t0ZHpvZ3ZnbGp6dHdnZ2htbWt6bHlp' 'nonce-aWdpbmNlcWZ5amlxa3NtaXl4amplZXFscHB6ZW5vemVvY2J3' 'nonce-ZXlqbHZteXJ1ZXh4ZGdobXhxbndrYmthemxycGx4amhqeWhq' 'nonce-ZWJhemtmZW1keWJobWRyc2todHB0a3VxaWJ3dW9ob2ptZHN6' 'self' 'nonce-4dbe9a1bd9416d9469f24261a517a0701915e020d772'; base-uri 'self'; frame-src https://www2.resource-innovations.com/ https://clerk.chat/ https://www.resource-innovations.com/ https://resource-innovations-production.cl-us-east-5.servd.dev/ https://www.googletagmanager.com/ https://www.youtube.com/ https://recruitingbypaycor.com/; font-src 'self'; img-src 'self' https://www.googletagmanager.com/ https://optimise2.assets-servd.host/ https://cdn2.assets-servd.host/ https://www.resource-innovations.com/ https://resource-innovations-production.cl-us-east-5.servd.dev/ https://cdn-cookieyes.com/; manifest-src 'self'; style-src 'self' 'unsafe-inline';
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports