Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=aspectsofmana.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 24, 2025
Valid Until
February 22, 2026
87 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
88:FA:2B:16:2C:B3:E2:77:E5:2A:26:1B:A1:BE:5E:BF:4D:B6:88:58:FD:1E:F7:1A:A8:E0:55:20:3B:20:89:42
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
primefitphysio.com
demo4.app2.1on1navi.com
www.agrogova.com
www.alle-tech.it
dev-ui-v2.applogie.com
cheatsforwhatsbehind.apptget.com
aspectsofmana.com
www.astronautslab.com
event.bezla.com
www.blizzard.dev
briannestande.com
www.carspricess.com
www.closedcaptionunity.com
underwriter.bewell.co.ke
www.coconut-studio.com
www.anfora.com.gt
salecar.com.ua
start.com.vn
auth.compscilib.com
www.confetticaddy.com
hr.cookapps.com
criminal-makers.com
shopping.crosswirl.com
portfolio.cschaepper.ch
cyclerovers.com
dev-auth.deaftawk.com
dynfix.com
cma.edu.sv
www.erdoganoptikgroup.com
essayconfidential.com
f2bportfolio.com
fanaro.app
stg-salon.favsalon.com
www.finansap.com
links.freeya.com
freshnailsspalasvegas.com
www.gamepleasethanks.com
genworx.ai
admin.getfriday.ai
gkhneisser.com
www.glamisrecoveryinc.com
www.greaves-travel.com
guitarlessonsbelfast.co.uk
helloshirt.app
www.help4up.com
www.howtorememberdreams.com
qa.huddlearea.com
links.ignatiusdeveloper.com
blackboard.immsane.com
www.infosimples.com
islamicstickerstore.com
app.ivyukraine.com
elite-boat-detailing.jakesinson.com
www.joncarlost.dev
jppaintservices.com
demo.juke.band
justiciafinanciera.com
kamality.com
kliqr.knesis.com
next.koobiq.io
app.loomer.se
lopatnov.com
test.maderr.com
melihhakanpektas.com
www.melihhakanpektas.com
www.microvisionembedded.com
mimicando.com
miyamorigame.com
link.test.myshop.mobi
privacy.myvaillant.com
www.notforme.org
auth.perimeter.ai
pestoperators.com
playnonsense.com
crediagora.homologacao.quitaboletos.com
notifications.radiumtecnologia.com.br
stg.rising-ent.jp
ritaesmatyi.hu
www.ryanrubush.com
sicerdikiot.sicerdik.com
sixteenapp.com
www.solarprotect.dz
www.stateless.money
sudheeksha.co
sunupcollection.com
resume.takasqr.dev
tarsalkodo.hu
app.tharprocess.com
themozine.com
www.theremont.com
www.btcconference.thndr.gg
tickyplayer.com
auth.todayshoroscope.co
www.trample.me
branch.treelog.io
urbanfix.dk
wagmi.kitchen
webcomponentessentials.com
weddygram.com
yogaposhana.com
Other domains in certificate