77/100 SECURITY SCORE

Certificate Information

Subject
CN=chroniker.co
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 27, 2025
Valid Until
January 25, 2026 59 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
17:02:EE:54:0F:B0:A7:2B:68:AB:D2:EA:AF:4B:CB:C2:19:D6:42:09:B3:CD:F6:ED:70:82:FA:23:74:F5:E6:52
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
rrhh.corposaludyaracuy.gob.ve

Other domains in certificate

tradelite.12traits.com
dev.demo.28east.co.za
www.acornsoft.uk
games.adiop.com
aghilmort.com
reto.alosuite.com
www.amanai.in
www.averto.app
axtellcommunitygrocery.com
www.beer-list.app
app-dev.benjiinvestments.com
www.berbernica-bickeji.rs
www.besttyreservices.com
blasterize.io
www.bythewake.com
www.capix.com.mx
www.cataria.games
chroniker.co
links.clbrk.com
egb.clevereducate.de
www.itdux.com.bo
mancala.share.coolplay.io
www.delightsystems.com
event.desnackcar.be
expenses.druhinh.com
econlinguistics.org
www.ekelz.com
endoclinic.pl
fezrestia.link
findmypath.org
www.firebirdmun.com
freoza.com
genevieveconnolly.com
hire.get-ikigai.com
app.getdevour.com
gmailbox.app
guestino.com
home-protector.jp
www.hristijanristeski.com
www.humancloudmanifesto.org
www.kai-lab.com
kripanaamkosh.sbs
lingobridge.app
lumi.page
maximemivilledeschenes.com
emsapanel.mds.sg
neurosight.mendi.io
mestredojo.net
www.minskblues.com
motostar.at
mukhtarzargar.com
muttleydoggydaycare.co.uk
hakim.my.id
test-admin.myhipai.com
docs.nannode.com
dashboard.docr.nd.gov
mtorchio.net.ar
dashboard-smnd.neurowaste.com
nomansskychef.com
www.ogh.am
oliblade.com
olmapp.xyz
sso-auth-stg.onum-labs.com
peak3.co
app.pizzerialapalmera.com
www.planwyze.com
www.playturnal.com
app.plusone.social
filedrop.premier-pump.app
m.prit.app
whois.publicissapient.fr
plus.qrq.app
app.rampstatus.com
resultcode.nl
www.retardcards.com
richardli.zone
www.autoparts.robertolegorreta.com
rooftoplabs.io
salihfsimsek.com
seanmena.com
staging.databeef.semex.com.br
verktyg.shadidomat.se
skylex.me
www.sreejaenterprises.com
staytruesurf.co
studiokad.fr
subreal.xyz
www.tagatakia.com
www.technoquest.co.uk
www.the-issues.jp
www.thedraw.co.nz
thestudyholics.com
timberhutpm.com
www.tonyvitro.com
staging-masoncounty.trueomni.com
lifestyle.ultrix.digital
www.uxcapital.asia
www.vladbasin.info
worldclockmeetingplanner.com