Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=mammactive.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 28, 2025
Valid Until
February 26, 2026
87 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D6:2E:4A:68:B3:CD:16:2C:18:97:5B:AA:02:61:78:0C:3D:70:B8:B6:54:6E:19:45:8F:CC:85:95:30:F0:AD:B5
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
signactive.com
2024.gdgindia.dev
andychill.art
biriyani-recipe.arundhatidas.com
atise.com.br
ngsprekanchanhadmin.auxswot.com
beringmaritime.com
boxscorefitness.com
uhcole-usability.bswing.com
buddym.co.uk
cosplayerfest.seller.tst.acceso.com.bo
cradle-app.net
demucs.danielfrg.com
dexhash.com
dk-meter.com
admin.doesoh.com
deeplink.dragoappli.com
www.dynasoft.co.uk
digitalview.easysignage.app
eatingdisordersandveganism.com
demo.edsys.com.br
eintracht-auerbach-singt.de
onboarding.equix.app
back1.eventnative.com
service.fazendacoffee.com
fidtech.ar
magic.fluenn.com
fullautokeywords.com
www.gdogmate.com
getdailyscore.com
admin.gethommey.com
kimonodvie.giorgettivalentin.fr
www.giostech.com
community.glissandoo.com
www.goprestigepower.com
grantharris.dev
hack-track.com
admin-accounts.homenetmentoronto.com
isabellaeichleronus.com
kconwe.com
kmcsociety.com
korbo.fr
www.lexflowapp.com
www.linkmetool.com
locha.lv
madeleine-dove.com
mammactive.com
mattsolano.com
meenahandicrafts.com
www.minorhacks.dev
www.munchkinnotes.com
newlifeaparelhosauditivos.com.br
link.noonnownow.com
www.oelenberg-apps.de
www.parfait.cafe
parquetarahuin.cl
www.pixapuzzle.app
www.primeconsultingsweden.com
admin.proforextrades.app
qreed.com
auth.dashboard.qualdesk.io
radhasoami.ca
www.radsconsult.com
rajmistry.ca
www.rehanhajee.com
reportinsight.info
www.rrurgentcare.com
saykudos.co
seanderham.com
serverobotic.com
servicios-sauce.com
shieldautostore.com
aolmigration.shuttlecloud.com
www.sidd.fyi
simplelm.com
www.skywardsafariadventures.com
beta-dynamic-links.somosmoneda.com
predictivpro.speakylink.com
spotpack.com
squatchnosh.com
pet.subtlemedical.com
t3los.com
app.tapitsolutions.com
techcraftpanda.com
www.teunkelting.com
www.thenineelements.com
thesantacruz.app
order.theserum.co
tippko.de
typingwarrior.com
ugatta-llc.com
page.until.blog
connect.vaihde.io
demo3.velocitytalent.com
verdiapp.com
videoconverterdownloadermp3.com
www.whendoibreakeven.com
dyn-v1.whichone.in
manager.woonig.app
web.wrench.ai
Other domains in certificate