77/100 SECURITY SCORE

Certificate Information

Subject
CN=portfolio.alhajco.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 07, 2025
Valid Until
March 07, 2026 88 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B2:A4:C5:DD:97:5B:7E:C1:DC:D1:3B:49:01:CC:00:2A:F5:90:5D:63:21:F1:FC:36:07:4E:85:33:2E:D4:26:B8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
ntts.prodeo-live.com

Other domains in certificate

dashboard.233bite.com
cpb.3rm.fr
alcovex.studio
portfolio.alhajco.com
alifandallies.com
www.andreas-magg.de
testing-admin-panel.aokitech.com.ar
pedidodevendarifeiro.app.br
roombuilder.ashleyfurniture.com
attolis.jp
www.aureusventures.co.uk
axxstrategy.com
badbunnies.xyz
www.balintcsala.com
basemed.qa
2-24.battalion.org.au
stage.zordon.api.bento.ky
www.bexcare.club
www.bharatdigital.in
bleepbloop.app
www.briskrenewables.com
leroymerlin.buenatelier.com
dynamic-link-stage.captcares.com
cartmedia.io
malini.co.in
coinfactory.dk
onetest.oneclass.com.tw tgo.mabow.com.tw
sodalove-orders.crispnow.com
app-redirect.curelinktech.in
www.dimplefloor.com.au
dive.fund
www.dowinapp.es
dr-rashmee.com
institutohellis.drtis.com.br
saude.slmandic.edu.br
elsteradapters.com
enrichtrust.in
ourriverside.equiem.mobi
ethioivf.com
febrol.in
trender.fredrikpalm.com
egourmet.gabilheri.com
dev.geneowebapp.com
www.grablabs.com
www.haberajanda.com
samples.hamakar.com
www.hidevoicy.com
inewstamil.com
www.intervalo.de
www.jakesherwood.com
sales.karditor.com
dev.keystoneconfections.com
l2leiloes.com
legodlum.org
www.lendis.blog
linhtran.info
admin.loftyapps.com
minibar.dev
mobitaz.net
www.mybreathingpath.co.uk
biosani.nazaries.cloud
auth.dev.next-audit.de
nitrogenedit.com
parcel.events
parupati.com
pixl.garden
captainmorgan.poseparty.com
satisfactempire.reblochor.dev
repkingston.com
admin.qa5.restoplus.com
rosaapps.io
www.ruwaizhaja.com
www.sagamillhk.com
samsutton.dev
shanemion.me
www.simpsonwhitetails.com
fs8p4dzsquhtgwi9rjo6.smartimob.io
softruler.com
www.alvar.softspace.dev
encuesta-clima.spira.com.mx
tanzemy.com
taylored-therapies.com
www.terakoty.pl
eslip.thai.run
vne.tienphan.work
www.tinerovoyage.ro
www.trayn.com
webdev.udux.com
dobby-jokes.vatsalgp.com
www.vidirez.com
www.voicingvault.com
www.wake-up-voice.com
washmonkey.in
admin-station.wework.com.br
www.wingbot.app
homologacao.xptoconsig.com.br
ymx.me
youthcommissionudupi.in