Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=chinofeliz.pedidomovil.es
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 22, 2025
Valid Until
January 20, 2026
45 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
66:15:B9:43:3D:6B:82:BF:9B:43:45:5B:72:F6:FD:95:CD:22:76:A0:14:CE:63:63:06:2A:E2:6F:76:AC:6F:E9
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
openplastic.app
1ft.shop
adirmachadoadvogados.com.br
after-scool.com
agnexim.com
www.aigotthis.com
sintry.aimcomely.com
www.akarapon.com
www.alfasoft.be
api.amzretificadores.com.br
anitakitchen.com
www.appliedlabs.net
www.arkham-starter.com
arqui1.com.br
www.ashutec.com
betmoneymaker.com
bigbundesign.com
www.capitalcutz.com
app.carteiraholder.com.br
hive.catamac.com.au
christianacceleration.org
www.la-luna.co.il
iaol.co.in
www.muratbobinaj.com.tr
www.constructionmlsr.ca
correaflooring.com
cspot.tv
cybarites.com
esg.data-insight.biz
www.dercampus.ch
www.devdez.com
dtiserv.com
account.educationawards.ie
elclubdelinversor.es
www.elwalidkadura.com
assets.equix.app
etdesign.co
etitango.com.ar
www.eyedoc.me
www.flappycopter.com
vrznaccounts-qa-ideacloud.forgedx.com
www.glauciagregoryadvogada.com
heroes.goodhood.sg
grenxapp.com
www.grocerieslist.app
gssinternational.us
admin.hagakuresushi.it
clinident-app.howob.com
immervoll.app
businessriver.irishcma.ie
jjean.io
getafterit.jordantippetts.com
www.laadi.co.uk
app.lareco-bornem.be
latonyawhite.com
bots.lenarge.com.br
xmas.littlerobots.nl
dapp.lode.one
beta.m.works
marcanandpartners.com
www.metagram.uk
mobify.live
rn-md-favorite-places-privacy-policy.mohammed-najib.me
www.mountcontrolsystems.com
moz.ninja
cats.nizhgorodov.ru
www.noelrecords.com
novaracing.ie
app.ownible.co
www.paloorkottapark.com
chinofeliz.pedidomovil.es
garages.personalarch.com
plan-to-succeed.com
pldna.de
siseveeb.pohjala.ee
kyber-js.reason.consulting
regfynder.in
iws-applink.rlgapps.com
it.roti.io
www.rpwhiz.com
pos-dev-pro.sahlhub.com
www.sanchitburkule.dev
skills4.org
bluesense.skyzh.dev
link-particuliers.par.societegenerale.fr
app.sprouthub.com
mastodon.stillfollowers.app
www.superplumber.app
tansy.app
www.timonriemslagh.be
staging-poconos.trueomni.com
www.turbocrash.com
vinceruiz.com
l.voxabular.com
link.voxabular.com
tsuburaya.app.wakuas.com
dwisnu.web.id
wontgivup.com
usercenter.woolili.com
www.workandrise.com
Other domains in certificate