77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.fresh-value.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 15, 2025
Valid Until
January 13, 2026 53 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9F:62:5E:C2:A5:9A:C6:73:86:32:3E:5F:6F:BC:90:85:D1:F2:E6:67:9A:F7:32:03:3F:36:7D:91:14:50:50:B0
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
soundtext.kafeido.app

Other domains in certificate

100viral.com
www.1shipping.in
accha.nl
adamsware.org
advancedmetalshop.com
www.ajovuoro.fi
alexey.co.uk
base-webapp.applogsoft.net
steamedtreasures.appsaur.com
arequipekverde.com
www.asez.ai
dragos.bardac.net
app.sandbox.beegopp.com
www.benguelacollection.com
www.bluecheck.pl
bodyscale.co.jp
reservasbubaqia.bracelit.es
bsvscan.io
carveglobalstories.com
www.castlepurple.com
cinde.org
gasolineratotal.com.gt
sipkovo.copacodu.com
airporthours.devpro.gr
dinushasathyajith.lk
dynamicalbumproject.com
www.easy-order.online
www.edebost.com
www.colegiodrreichmann.edu.gt
joiner.efficientvineyard.com
go.emanageone.com
www.enotice.io
a.enpuri.jp
www.europakommunal.eu
test-link.experienz.co.uk
admin.fatimagomez.site
www.feriaempleouca.com
www.fresh-value.com
gofuckyourself.agency
www.greenslash.dev
gssnargames.com
homeherorealty.com
keio-attend-online-intg.iridgeapp.com
booking.jaroshund.no
jaymillerarnold.com
www.jsv-associates.com
www.krrajnish.com
localid.in
louhde.tech
smp.lovellebeautyacademy.com
www.matteoagosti.com
menamour.it
mewbyte.com
mezza.io
qr.mida.menu
www.mobileappslab.com
www.mrtstayr12.com
www.mundoquadri.com.br
analytics-dev2.mytechnis.com
nelloreciticabs.in
www.nomadictax.org
soroll.nubaltic.com
pathpal.org
pdcconsult.com
tempurasalou.pedidomovil.es
pepegram.io
app.quantumrfid.com
radekbaxa.cz
proposal.rcd.cool
app.roadmapper.fr
archives.royalcollege.lk
safehandsdiagnostics.in
www.sangiovannicostruzioni.it
www.scienceforruralindia.in
shanglongyeo.org
siriusconsulting.com
bubbakoossamco.sqwadhq.com furmansw.sqwadhq.com rufanhalloffameadmin.sqwadhq.com
person-note.starrycode.dev
www.stephenjelley.co.uk
staging.t-order.jp
tamkinexpress.com
es.teresabarrueco.com
tininfo.com
auth.toupain.fr
transworldiq.com
www.travelpud.com
app.triathlink.com
the.unconventional.company
unidator.com
www.upboards.net
cotador.vidasunidasbr.com.br
admin.vikrayashaala.com
articles.volvmedia.com
www.vrvenkatesh.com
waterpurifier-services.in www.waterpurifier-services.in
wolfsites.de