Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=freeloaderapp.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
February 01, 2026
Valid Until
May 02, 2026 82 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
01:B2:C4:97:1C:3A:58:06:8E:AD:BC:20:42:96:8D:8E:DD:E8:CB:C2:6D:A6:24:FD:B4:50:F5:8F:92:03:C0:13
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
perk.bluvern.com

Other domains in certificate

ph.1800flynow.com
www.aanksolutions.in
abextransport.com
students.academix.dev
www.aerostar.app
atoptengame.aiman.space
www.ainexas.com
emr.alleviationtherapeutics.com
admin.apifaker.dev
ashwik.com
www.autodrop.app
badetemp.io
pro.bilo.ba
staging-survey.binds.co
ussd.bluerobot.com
truco.app.blyts.com
staging-disputes.buslane.com
www.caseyenglishstory.com
chamoliphysio.com
easyhospitality.clau.io
www.closeones.app
rupak-thapa.com.np
couplet.love
smartsite.dataauchan.fr
detainrelease.com
discovergis.com
www.eclipseguild.com
elsaluciaarango.com
app.emotely.de
esn-tumi.de
f1wm.pl
fayd.app
admin.flamabirrayburgers.com.ar
florentpetit.info
www.flycheapalways.com
foodhero.in
auth.foodrank.app
fortitudewomensgym.com.au
freeloaderapp.com
dynamic-firebase.geoza.dev
app.healthassuranceplan.com
pro.inspireinsight.com
www.jasondamour.com
www.jfconstructora.cl
kfo-am-kaiserplatz.de
covid.kurzdigital.com
page.linky.app
llynxmtl.com
logitrix.net
link.lowchart.com
pur.ltl-xpo.com
l.markspolakovs.me
play.matt54633.com
mattmoody.dev
easy.mbility.app
docs.moviecolab.com
mrtstayo11.com
mubashirirfan.dev
www.myhairnote.com
mymercato.online
parampara-utsav.namastey.co
www.neilcurry.com
newlybride.app
www.ninekd.co.uk
nubifica.co
app.nursehealthservice.com
app.oaleadsprofit.com
operationathena.com
pacta-cloud.app
suporte.pegueleve.com
polarion.app
orgauth.possobuild.ai
rdkr.dev
readword.net
relicensemble.org
righardbrink.com
vilje.shed.no
www.sjftrading.com
vonxnbteuyp18kvlwyh3.smartimob.io
sparemic.app
spearhead.me
stella-och-ginas-jul.se
www.sukolabo.net
dashboard.talentafricagroup.com
fire.sandbox.tapico.cloud
teamcubicle.com
teammzr.com
www.tellimused.ee
thelaxminarayan.com
www.theloophobart.com.au
test.todamoon.live
app.touchdown.aero
truckherd.com
tylermccarley.me
sol.under25universe.com
vendwish.com
www.wiefel.dev
masjidprayertimes.xalting.com
www.zenlotusnosh.com