Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Google Trust Services, CN=WR1
Valid From
April 26, 2026
Valid Until
July 25, 2026
89 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7F:22:DF:7F:9A:F7:F6:E0:18:8D:14:69:5D:EF:8A:75:E1:46:11:D9:8B:B7:97:A1:E3:31:2B:C8:8F:BE:6E:97
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
51 domains
servicefox.com
www.servicefox.com
20somethingguru.com
www.ahonlaitaa.com
american-house.org
www.american-house.org
animation35.fr
www.animation35.fr
apostlepeterjones.com
www.astoundingaidservices.com
atrendymama.com
tls.automattic.com
belleswheels.com
www.belleswheels.com
bscdigitalmarketingsquared33.com
www.bscdigitalmarketingsquared33.com
chickflickspodcast.com
www.clarasatta.com
www.erdi-hse.com
gratzlwinkler.com
inquisitorvuln.com
www.inquisitorvuln.com
isabellechardavoyne.com
www.isabellechardavoyne.com
itwillbeok.blog
www.itwillbeok.blog
www.jarmopoukkula.com
jarrodrussell.com
jarynlyneahart.com
www.jarynlyneahart.com
jasmardis.com
www.jasmardis.com
www.lakeslandrfb.com
lonedevr.com
misshollywoodshow.com
mkbphotography.org
myyescapades.com
naturalmo.com
www.naturalmo.com
olab.blog
www.olab.blog
otherpeopleschildren.blog
overstreet.farm
psychologyhits.com
reispproductions.com
safari-eg.de
safy50.buzz
taxguru.com
thenomadicsaver.com
watanplusnews.com
www.watanplusnews.com
Other domains in certificate