Open
Cached
·
just now
89/100
SECURITY SCORE
Certificate Information
Subject
CN=readme.com
Issuer
C=US, O=Google Trust Services, CN=WE1
Valid From
October 05, 2025
Valid Until
January 03, 2026
40 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA256
SHA-256 Fingerprint
8C:C5:3D:91:B1:78:17:4E:DF:A5:7B:24:F3:65:38:E3:EA:E6:7A:1C:F2:93:3D:4B:BA:53:99:DF:BC:8C:1F:21
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=604800; includeSubDomains; preload
Content-Security-Policy
Basic
script-src; style-src; img-src; +6 more
script-src 'self' 'unsafe-eval' 'unsafe-inline' data: http://s.adroll.com https://connect.facebook.net https://d.adroll.com https://fast.wistia.com https://googleads.g.doubleclick.net https://ipv4.d.adroll.com https://js.driftt.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-scripts.com https://js.hsadspixel.net https://js.hscollectedforms.net https://js.hsforms.net https://js.hubspot.com https://js.intercomcdn.com https://readme.com https://s.adroll.com https://snap.licdn.com https://track.hubspot.com https://widget.intercom.io https://www.google-analytics.com https://www.googletagmanager.com https://www.youtube.com; style-src 'self' 'unsafe-inline' https://cdn.icomoon.io https://fonts.googleapis.com https://ka-p.fontawesome.com https://kit.fontawesome.com https://readme.com; img-src 'self' * data:; font-src 'self' data: https://cdn.icomoon.io https://fonts.gstatic.com https://fonts.intercomcdn.com https://ka-p.fontawesome.com https://readme.com; worker-src 'self' blob:; connect-src 'self' https://analytics.google.com https://api-iam.intercom.io https://api.airtable.com https://api.hsforms.com https://api.hsforms.net https://api.hubapi.com https://api.lu.ma https://api.mapbox.com https://connect.facebook.net https://cta-service-cms2.hubspot.com https://dash.readme.com https://forms.hscollectedforms.net https://forms.hsforms.com https://google.com https://googleads.g.doubleclick.net https://hubspot-forms-static-embed.s3.amazonaws.com https://px.ads.linkedin.com https://sentry.io https://stats.g.doubleclick.net https://www.buzzsprout.com https://www.google-analytics.com https://www.google.com wss://nexus-websocket-a.intercom.io; frame-ancestors 'self'; object-src 'none'; base-uri 'self';
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
comodoca.com
digicert.com
; cansignhttpexchanges=yes
letsencrypt.org
pki.goog
; cansignhttpexchanges=yes
ssl.com
Wildcard CAs
comodoca.com
digicert.com
; cansignhttpexchanges=yes
letsencrypt.org
pki.goog
; cansignhttpexchanges=yes
ssl.com
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • You have authorized 5 CAs - consider limiting to only the CAs you actively use
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts