Open
Cached
·
just now
83/100
SECURITY SCORE
Certificate Information
Subject
CN=doublerootcoffee.ng
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
October 28, 2025
Valid Until
January 26, 2026
43 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5E:04:F4:FD:1F:39:A2:29:6D:E6:2C:42:59:16:A9:FD:2D:74:A3:9C:80:0F:4F:FA:86:97:D1:83:C6:41:91:76
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=15552000; preload
Content-Security-Policy
Weak
frame-ancestors
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
accelerometer=(), attribution-reporting=(self), autoplay=(), bluetooth=(), browsing-topics=(self), camera=(self "https://www.fbsbx.com"), ch-device-memory=(), ch-downlink=(), ch-dpr=(), ch-ect=(), ch-rtt=(), ch-save-data=(), ch-ua-arch=(), ch-ua-bitness=(), ch-viewport-height=(), ch-viewport-width=(), ch-width=(), clipboard-read=(self), clipboard-write=(self), compute-pressure=(), display-capture=(self), encrypted-media=(self), fullscreen=(self), gamepad=*, geolocation=(self), gyroscope=(), hid=(), idle-detection=(), interest-cohort=(self), keyboard-map=(), local-fonts=(), magnetometer=(), microphone=(self), midi=(), otp-credentials=(), payment=(), picture-in-picture=(self), private-state-token-issuance=(), publickey-credentials-get=(self), screen-wake-lock=(), serial=(), shared-storage=(), shared-storage-select-url=(), private-state-token-redemption=(), usb=(), unload=(self), window-management=(), xr-spatial-tracking=(self);report-to="permissions_policy"
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Significantly strengthen CSP directives
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
placedealers.com
*.placedealers.com
1602wrld.com
abnass.com
alislam.ng
alp.ng
*.alp.ng
amana.ng
*.amana.ng
amanamarket.org
*.amanamarket.org
amber.ng
aridunu.com
astrics.ng
babarice.com
barnex.ng
baseus.ng
besttopup.ng
blissville.ng
*.blissville.ng
bmwclub.ng
bpsany.ng
brisk.ng
carpapers.ng
cicenugualumni.ng
*.cicenugualumni.ng
cieeen.org
coamana.ng
*.coamana.ng
coamanamarket.com
*.coamanamarket.com
coamanamarket.ng
*.coamanamarket.ng
coamanamarket.org
comeinn.ng
doublerootcoffee.ng
drugstorenigeria.com
dwellora.ng
educlimax.ng
*.educlimax.ng
emmanuelmbaka.net
emmanuelmbakafoundation.com
emmanuelmbakafoundation.org
emmanuelmbakaofafrica.com
emmanuelndubuisimbaka.com
fastlane.ng
fedoz.ng
*.fedoz.ng
fedoz.org
mail.fedoz.org
www.fedoz.org
fordax.ng
fthlab.com
*.fthlab.com
fthlab.net
fthlab.ng
groceries.ng
havanzer.ng
hniprime.com
ibatea.com
kajurulga.ng
kinisoo.com
*.kinisoo.com
kleanas.com
koropey.ng
landwey.ng
mauwizo.com
maxima.ng
millandhotel.ng
*.millandhotel.ng
muryarhausa24.com
nahbpon.ng
mail.noipolls.com
noipolls.com
www.noipolls.com
northino.ng
onile.ng
passage.ng
payinto.ng
pcnihouston.org
www.pcnihouston.org
peoplesclubofnigeriahouston.com
peoplesclubofnigeriahouston.org
plugs.ng
rimsltd.com
ritelink.ng
rivetsoftware.org
swh.ng
tabithacumifoundation.org
valueanalyticsolutions.net
valueanalyticsolutions.org
vetarent.ng
mail.whispa.ng
whispa.ng
www.whispa.ng
whisper.ng
*.whisper.ng
zaihar.com
zaihar.ng
zannoza.net
Other domains in certificate