Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=developers.malin1.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 30, 2025
Valid Until
March 30, 2026
83 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4D:45:CB:87:AE:4F:22:DF:5D:BB:99:09:85:7D:23:60:1D:15:E9:6B:F6:0B:BC:BE:D5:95:C3:47:12:9B:38:98
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
ourcountrykitchen.com
www.acpropertysourcing.co.uk
www.addisonredmond.com
short.advyzen.fr
www.akemenid.com
admin-staging.analyticindex.com
anjeza.architects-and-architects.com
www.areadingwithpenelope.com
sgc.atepja.com.br
softball.athleteera.app
mp3player.apps.babaaman.com
baseline.care
www.billboardfarsi.com
binarycube.in
app.bnhl.in
opportal.brsth.com
christopher.house
www.codeofeverything.com.au
auth.zenminder.cognuscraft.com
link.zdrop.com.bd
cupol.jp
coincraft.detroitlabs.com
tariff-mgmt-s.dev-ltl-xpo.com
doomhowl-interactive.com
drdadds.com
demo.earlymarkers.com
enypages.com
exovian.dev
www.exx.dk
eyeinthesky.photos
www.fchapel.com
fontspalace.net
frankfauci.com
www.georgiacaregiving.org
goojin.de
backend.greenhillcapital.be
edenred.hai.bo
entry.hakudenkai.games
helvetia-prive.ch
himitsulab.com
www.huygensoft.com
phamducdung-20215265.id.vn
ssih-sormland.infosynk.se
indra.portalcliente.izii.io
app.jareads.com
leads.jatinderkaur.in
www.jriimala.com
justinmaynard.me
www.kantindeyiz.net
kulezic.com
language-rooms.com
www.language-rooms.com
stg.leafb.one
locusapp.in
m2rc.net
developers.malin1.com
www.maxautosale.com
mcelogistics.com
musicreadingtrainer.melihhakanpektas.com
milenasilva.com.br
mluqmanmoon.com
www.moveandfitness.app
www.mudrvyrostkova.sk
nacremusic.com
nakta.me
napelembalaton.hu
pf.nekobooks.com
api.nichemat.es
b2b.nocnoc-internal.com
ogmentorbt.com
www.oliveexports.in
www.outjet.com
app.peeceeliquor.com
dev.prodolzenie.ru
atenea.proyectosuperarse.com.ar
queerstuff.org
reputelo.com
resume4all.com
shiftlive.jp
sistemacontrolasistencias.space
staging.tv.smashpark.com
api.spried.com
ssrgroup.net.au
moj.studenac.hr
syskim.com
preview.talea.de
www.taxhead.de
occ.teenycoders.com
therapiy.com
ecom-demo.thesashka.com
thevortyx.com
api-training.tradedash.com
trianglepartyandcrafts.shop
tokyowangan.uechiryu.okinawa
ospe.upolicy.ca
app.veero.ai
vitasync.nl
wakecountymutualaid.org
www.welshwellbeing.co.uk
worlddomination.group
Other domains in certificate