Open
Cached
·
1m ago
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.servicescaler.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 20, 2025
Valid Until
December 19, 2025
37 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3B:AF:CC:82:1A:77:9C:D1:DA:DD:4A:BC:6F:A8:80:97:51:9C:1C:67:AB:4F:9E:14:9F:F0:39:C6:96:64:69:C0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
sforzato.xyz
anunciavi.com
conecta.uaisat.app.br
quizarchive.appsbychristian.de
asiaadams.org
bluejayengineering.co.za
www.bonneink.com
brimwylm.com
devis.bude-brus.be
www.buildingapprovalspecialists.com.au
ftest.cankaya.io
hi.cashx.lk
try.clips.fit
collegetown.ai
nimeshthapa.com.np
staging.commissionvision.io
discord.deshpande.page
rm.edsys.com.br
dev.mis.foresthillschool.edu.kh
egitek.com.br
fabianrapp.de
auth.fdrive.cz
neurad.ferbotz.com
www.finding.email
gedu.it
sua.glambox.com.br
media.gouldcs.com
harvprinted.com.au
forums.healthtree.org
auth.hopmate.com.au
preorder.hotwax.io
app.hyped.com
loitran123.id.vn
ilb.io
old.inavinfotech.in
innov-tech.org
advent-of-code.inova.si
www.jabezsamson.in
jornalbhs.fun
www.joshuabennett.dev
www.jourfixed.com
www.kangoo-trekka-club.org
www.kartonagen-weber.at
kontaktkampen.kontaktdagarna.se
kroatie.pro
links.kuaay.com
www.lalomadelosreyes.com
www.lwaziapp.co.za
mesbro-religion.mesbro.in
momot-consulting.de
www.momoteescucha.org
demo-agents.mpower.africa
mvishal.in
fire-v1.mydnspanel.com
www.nazdigital.com
www.oeura.com
admin2.ooca.dev
www.pangea-technology.com
www.par-t-cart.com
peakit.io
www.platformcontent.net
pott.dev
powerbitraining.ie
app.printdash.io
roster.professionail.co.nz
www.progressivetooling.com
rakhimova.pro
rkstudio.net
www.rustythecat.com
climb3rs.schmittsfn.com
www.scool.town
www.sebastianmoreno.se
www.servicescaler.com
api.crew.sgospel.no
www.shaneneeley.com
www.slicemap.com
chargein.spirii-apps.com
www.sthreekendra.com
www.marketplacebooth.swapaholic.com
links.telescopenet.com
app.thaihomes.in
theanthropocenereviewedreviewed.com
thelandrecords.in
thelivingarchive.org
themappingservice.com
thepakora.com
tokyointernationalacademy.com
admin.traeguate.gt
www.trickfilm.com
pidefacil.turbopizza.mx
www.tylerlasicki.com
upperrange.com
vantagetools.com
www.vincenzoberretti.it
wear24rom.com
www.westyellowstoneskijoring.com
hub.wmonline.co.nz
referral.staging.woo.org
worldisonefamily.com
app.zuboq.com
Other domains in certificate