Open
Cached
·
just now
93/100
SECURITY SCORE
Certificate Information
Subject
CN=seller.sanghinga.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 20, 2025
Valid Until
February 18, 2026
83 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
CE:CE:83:1A:7E:90:04:6F:CA:4D:A7:77:4F:79:D6:F9:4F:9F:11:36:6D:5B:7E:9B:1E:04:C5:F4:8D:BB:85:7C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=63072000; includeSubDomains; preload
Content-Security-Policy
Good
default-src; frame-src; connect-src; +7 more
default-src https:; frame-src https://*.firebaseapp.com; connect-src https://maxsold.blob.core.windows.net https://*.maxsold.com/ https://*.web.app https://*.cloudfunctions.net/ https://*.googleapis.com/ https://*.algolianet.com/ https://*.algolia.net/; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' https://*.algolianet.com https://*.algolia.com https://apis.google.com/ https://maps.googleapis.com/ https://*.maxsold.com/ https://*.web.app; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/ https://*.maxsold.com/ https://*.web.app https://maxst.icons8.com/; img-src * https://*.maxsold.com/ https://*.web.app; font-src * https://fonts.googleapis.com/; object-src 'none'; base-uri https://*.maxsold.com/ https://*.web.app
X-Frame-Options
Excellent
deny
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Missing
Not configured
Recommendations
- • Strengthen CSP by removing 'unsafe-eval'
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
sellerportal-admin-uat.maxsold.com
www.21-foundation.org
sftools.24na7.pl
go.adminedf.com
dev.ambersoftware.net
calivallebureau.appsiste.co
atlasone.co
www.availify.no
app.avec.ch
www.avoidendsnow.com
bestallen.com
admin-beta.bibicvendeghazak.hu
boabmaps.com
cafe.bio
cardscoring.com
dv.clamwave.com
clubify.it
classroom-growth.codingninjas.com
www.combat.school
zoom.commudle.com
who.wouldnt.click.such.a.convincing.link
links.crosschecksports.com
crral.com
datachester.com
dhaministudio.in
auth.djopa.fr
dmoori.com
www.docmaisdoc.com.br
pdr.vac.e-ceos.com.br
admns.enukso.com
eudania.com
ezkoray.com
www.filmararken.com
www.fingertips.in
a0fu.foodle.su
app.fractory.com
francesmorrison.com
geneanno.com
gestionaleventuribruno.it
goascendal.co
www.gora.hu
hannhwafabrics.com
haraldwenkassociates.com
harrow-education.com
hcmanifesto.com
helekgroup.com
vault-connect.hodllabs.io
www.ics-container.com
dev.indianpoliticstoday.com
w3schools.indyriot.com
jamesmayr.com
www.joose.ee
api.shorturl.jurivana.de
hn.k8jss.io
stg.awetism.katomaran.app
knockitout.app
www.kshortsleeve.art
hostel.lancehawks.com
www.lauradeus.com
letsplant.app
www.m-bk.com
www.manoamica.it
www.meadlight.it
www.medarov.app
pos.merapashu360.app
metheusstudio.com
app.global.minga.io
frfirebase.moboreader.com
mracul.fun
mypassioncoffee.com
nailbookingpro.ro
pay.nikol.ai
app-prod.obrinvest.com
perqt.com
pos-dev.phongvu.vn
www.platypuslabs.llc
psyjai-dashboard.com
web.push-knock.com
www.qadauto.com
rafasanjuan.com
recipebrigade.com
www.rukundotrans.com
seller.sanghinga.com
www.shredlevelone.com
skullapes.com
app-dev.snapmentor.no
sortyou.io
www.talentio.io
techmate.in
debug.the.app
hillsvet-stage.thepetdoor.eu
admin.topformaturas.com.br
trekk-sale.dk
muat.turnsignl.com
viusasa.com
staging.washere.app
wiforward.co.za
will-song.com
dashboard.winkyverse.io
zerahtech.com
Other domains in certificate