77/100 SECURITY SCORE

Certificate Information

Subject
CN=ppociitk.in
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 02, 2025
Valid Until
March 02, 2026 89 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
01:A3:F0:2D:84:C0:82:1B:82:23:9E:2C:E3:A1:3F:75:9B:CE:9B:D9:85:A9:BF:DB:9C:F1:90:66:0A:92:E8:4F
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
onboarding.locallypay.com

Other domains in certificate

demo.11yearsafter11.nl
emma-demo.adalab.es
stg-360.sellerhub.ailumia.com
www.albashatechnic.com
www.azooro.xyz
www.becreative.hu
connect.beekeepr.app
rurineko-virtualshop.bestat-data.com
acceso.bibliotecaescolardigital.com
recetas.caracasdevelopment.com
dev.codebotlabs.com
admin-staging.coverr.co
bot.craftycram.net
danielpifer.com
www.datagee.com
datasenseanalytics.com
dmj.page
app.doid.dev
link.dovewallet.com
www.dximagenvet.com
elisabethunger.com
www.fishcat.org
admin.flipperz.co
sintpauluscollege.flockim.com
www.flow-flow-flow.com
app.flygaggle.com
demo2.portal.formfabric.com
futuralabs.co
www.getbraintrust.co
pdf.gosunergy.com
www.greencarwash.it
guokai.dev
my-dev.hipaamate.com
www.histoire-du-polar.com
www.ibustcargoturquie.com
www.ikwiljeietsvertellen.nl
www.jimmyandlaura.com
jkbc.dev www.jkbc.dev
klatkikadry.pl
knsn.cc
www.kohei.com
clinician.kyndwellness.com
lentilscorp.com
etags.lmes-phygital-pre.lmes.cloud
stage.machdaslebenan.de
mealcodes.com
michaelpeterhartmann.net
minidot.be
start.mojarib.io
monkeybrix.com
mosammoscomltd.com
musiclessonhub.com
funnel.my-muse.ai
console.mycure.md
www.mylandlordis.com
www.nzctd.co.nz
www.omikuji.app
www.ordo.net
app.partou.nl
pavelowbrewing.com
perle.me
photos.lol
mhwenge.piticommerce.com
internship.pixiv.co.jp
test.positive-places.com
app.powtain.com
ppociitk.in
console.primaryaccount.com
passwords.publicinterestnetwork.org
putervision.com
www.raremetalgames.com
auth.registelecom.com.br
app.reoffice.io
app.reveel.id
rzbbaseball.com
saivinayakinternationalschool.com
sakshamsevatn.org
www.setup-simracing.com
shiatsu-sumiyo-annecy.com
www.simonaertsportfolio.com
simonschlecker.de
singinglessonsoxford.com
blog.skillsleague.ninja
strim.in
subastalocal.com
systb.io
tezjs.io
theivyroombooking.com
www.time-drops.com
tremenz.com
portal.truviewnw.com
auth-neues.umishun.com
vlkn.io
url.webnhe.com
wirepledge.com
www.xlending.cc
yomando.co
goto.zoralab.com