Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=demo.plugandhealth.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 19, 2025
Valid Until
March 19, 2026
65 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
61:F8:E5:3C:9D:E3:04:B4:1F:07:3E:46:53:43:2D:46:E8:BC:1B:66:0A:54:1D:12:6B:29:71:17:75:72:E1:F9
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
pack-party.com
www.actiontranslate.dev
aghansteen.no
admin.alineadoresaroalign.com
alist.to
portal.anvilproject.org
tryme.apostleconnect.com
appquant.app
baby-navi.com
app.baldassari.co
bamboozoology.org
bhumanch.com
bluthumb.io
rafstage.bmhost.net
cercacars.in
cjterminal.net
www.closr.io
fanusisi.com.tr
dashboard.prod.crilabs.net
databin.com.br
catherine.davit.fr
www.daysgoby.io
dinate.in
suite.dlt360.io
www.eatwelltobewell.ca
effectpro.mk
www.elminmehdili.com
etraining-aquacycle.eu
evelight.in
evernis.fr
a0bg.foodle.su
concierge.freespadelifestyle.com
www.frhoneyedbee.com
www.gurudada.com
hushcode.dev
web.infidreams.com
jeromecastillo.net
app.kansasgolfscores.com
kiespace.in
www.klikkie.de
rhythm-uat.lassio.io
reports.layer.team
cms.leaguelife.com
www.leboncode.be
help.leezair.com
malosvicios.net
membership.ir
preprod2.merval.fr
qb.mk.ua
dashboard-admin-integration.mytechnis.com
ngen6and6.com
nrss.co.za
nununugames.com
onlinequrancenter.net
opus.studio
gestao.gopi.org.br
pallagialla.com
pixelplex.io
demo.plugandhealth.com
www.poodleform.com
www.portfolioaudrey.com
www.prakharrathi.com
demo.account.prestoexpress.co.uk
share.preventchildabuse.org
www.prioritizeapp.com
prop-edge.org
stg.victon-album.re2fe.com
operator.rebus.com.co
backoffice-frontend-rp24.rechtsportal24.de
rohan-mistry.com
rwandaelectronics.com
beaconpark.dashi.sasaki.com
save-rank.com
www.sekaimura.net
admin.shoppedmw.com
sofamad.com
complete-ira.solerabank.com
mali.solomonschariot.com
app-support.sqwadhq.com
starlessrealms.com
starseedgames.com
app.studymizer.com
graduacionflorencealfaro.swanmoments.com
auth.teknoir.info
promotor-sem.tenebit.co
themythosengine.com
www.tigerlaunch.com
tmj-pain.com
www.torontozenmusic.com
micross.tresch.me
uknow.global
open.unepstrata.org
www.vasudharaautomations.com
vikrambahl.com
test.woorihero.com
xwarddigital.io
yujetbrasil.com.br
t.yumip.com
zebardast.com
zlegit.com
Other domains in certificate