Open
Cached
·
just now
86/100
SECURITY SCORE
Certificate Information
Subject
CN=pivotcycles.com
Issuer
C=US, O=Google Trust Services, CN=WE1
Valid From
December 31, 2025
Valid Until
March 31, 2026
67 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA256
SHA-256 Fingerprint
39:8A:D3:9C:76:9F:04:F7:7B:DA:32:A4:9B:38:A0:A4:59:6A:7E:B4:A0:0F:2A:04:5A:04:DD:4C:20:C1:68:0C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
base-uri; default-src; frame-ancestors; +6 more
base-uri 'self'; default-src 'self' 'nonce-3a2e5c632996cb1abb0414bfe7a944c6' https://cdn.shopify.com https://shopify.com; frame-ancestors 'none'; style-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://use.typekit.net https://p.typekit.net https://*.livechatinc.com https://*.klarnacdn.net https://*.acsbapp.com https://*.hubspot.com https://*.hsappstatic.net https://cdn.cookie-script.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src pivotcyclescms.wpenginepowered.com https://cms.pivotcycles.com https://cdn.shopify.com https://unpkg.com https://cdn.jsdelivr.net https://*.affirm.com https://prodregistryv2.org:* https://featureassets.org:* https://*.locally.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.facebook.com https://connect.facebook.net https://*.clarity.ms https://api.livechatinc.com wss://lc.chat https://j.clarity.ms https://*.clarity.ms https://www.facebook.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://*.klarna.com https://*.klarnacdn.net https://*.klarnaservices.com https://*.klarnaevt.com https://acsbapp.com https://cdn.acsbapp.com https://*.acsbapp.com https://*.hubspot.com https://*.hubapi.com https://*.hsappstatic.net https://*.hscollectedforms.net https://*.hsforms.com https://js.hs-scripts.com https://js.usemessages.com https://d1jiq9n77635tp.cloudfront.net:* https://5raer21h.apicdn.sanity.io:* https://o4509125266702336.ingest.us.sentry.io:* https://www.googleapis.com:* https://ground-keeper-custom.myshopify.com:* https://ka8jjo2110.execute-api.us-east-1.amazonaws.com:* https://js.hs-banner.com https://*.hs-banner.com https://*.sentry.io https://*.ingest.sentry.io https://cdn.cookie-script.com https://report.cookie-script.com https://consent.cookie-script.com 'self' https://cdn.shopify.com/ https://monorail-edge.shopifysvc.com https://pivotcycles.myshopify.com https://pivotcycles.myshopify.com; script-src 'self' 'unsafe-eval' 'wasm-unsafe-eval' 'strict-dynamic' 'sha256-3bzWVxQE32IZQKH9eh8KzyHuhXOlMrboDVVBRd0fWTU=' https://cdn.shopify.com:* https://cdn1.affirm.com https://*.locally.com https://gkc-script-server.pages.dev https://ajax.cloudflare.com https://cloudflareinsights.com https://static.cloudflareinsights.com https://www.googletagmanager.com https://tagmanager.google.com https://cdn.livechatinc.com https://*.klarna.com https://*.klarnacdn.net https://acsbapp.com https://*.acsbapp.com https://*.hubspot.com https://*.hsforms.net https://*.hsappstatic.net https://js.usemessages.com https://js.hs-scripts.com https://js.hs-banner.com https://cdn.cookie-script.com https://report.cookie-script.com 'nonce-3a2e5c632996cb1abb0414bfe7a944c6'; frame-src *.youtube.com https://open.spotify.com https://cms.pivotcycles.com https://www.affirm.com https://*.locally.com https://gkc-script-server.pages.dev https://www.googletagmanager.com https://cdn.livechatinc.com https://secure.livechatinc.com https://*.livechatinc.com https://*.klarna.com https://*.klarnaservices.com https://www.facebook.com https://acsbapp.com https://*.acsbapp.com https://*.hubspot.com https://*.hsforms.com https://*.hsappstatic.net; img-src self *.pivotcycles.com vern.ngrok.app anthony.ngrok.app pivotcyclescms.wpenginepowered.com https://needed-absolute-mule.ngrok-free.app https://oyster-refined-rodent.ngrok-free.app https://pleasant-woodcock-upright.ngrok-free.app https://civil-redfish-real.ngrok-free.app https://anthony.pivotcycles.com https://anthony.ngrok.app http://localhost:3000 *.wpenginepowered.com cdn.shopify.com *.buzzsprout.com https://cdn-assets.affirm.com:* https://media2.locally.com picsum.photos *.picsum.photos blob: data: *.pivotcycles.com pivotcyclescms.wpenginepowered.com cdn.shopify.com *.buzzsprout.com https://res.cloudinary.com https://*.affirm.com https://*.locally.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://*.facebook.com https://connect.facebook.net https://*.clarity.ms https://c.bing.com:* https://*.livechatinc.com https://cdn.files-text.com https://*.klarna.com https://*.klarnacdn.net https://*.acsbapp.com https://*.hubspot.com https://*.hsforms.com https://*.hsappstatic.net https://*.hsforms.com https://d1jiq9n77635tp.cloudfront.net https://cdn.cookie-script.com; font-src 'self' data: https://cdn.shopify.com https://fonts.gstatic.com https://use.typekit.net https://p.typekit.net https://*.klarnacdn.net
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
ssl.com
comodoca.com
digicert.com
; cansignhttpexchanges=yes
godaddy.com
letsencrypt.org
pki.goog
; cansignhttpexchanges=yes
Wildcard CAs
comodoca.com
digicert.com
; cansignhttpexchanges=yes
letsencrypt.org
pki.goog
; cansignhttpexchanges=yes
ssl.com
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 6 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts