Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=copthon.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
January 01, 2026
Valid Until
April 01, 2026
80 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
60:3E:94:57:55:12:03:5B:E8:88:7D:B7:EA:C9:18:A6:19:A5:BC:D3:74:8F:1C:00:7D:39:40:91:12:0C:62:DD
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
spotted.gi
kb.1337.life
feliz2026.3lastic.com
ep.tr.ac.th
www.afsfacilities.com
nexus.ailabmind.com
www.angg.io
www.atolyegencakademi.com
www.auto-go.cl
www.ayadischool.com
barbarinn.is
staging.beeswappy.com
www.bensailor.com
bluescope.bluewhale.kr
www.bohita.com
www.bptowing.co.nz
www.breadandbuttereatery.com
ui.bullwhip.io
californiawaves.studio
bbmanager.cbros.it
circuitcore.lk
sportter.cityx.hr
cloud-gem.be
singhvikas.co.in
www.suvidhamart.co.in
www.code-once.com
copthon.com
app-dev.curopeers.com
www.drone47.co.jp
www.eureciclo.eco.br
tools.f-fort.nl
www.fazlpublishing.com
www.funkyfata.ch
gmmtv.gachasta.com
blockhistory-winery.grapeweb.com.au
cumin-garnet.harecord-dev.com
hotube.hm-label.ru
admin.htccli.org
www.ingeservicios.com
dev.irace.club
isystim.nl
summer.itmizer.com.br
short-dev.itmr.dev
www.ivaigas.com.br
www.karolinakulis.com
knuri.kr
najp.kro.kr
zavalinka.kroneckera.com
lilyyang.work
majcreativity.com
makeevent.ru
www.manwomanandchild.com
link.martinozpizza.com
maxcalculo.com.br
librarian.mebooks.co
merlinglobalstudy.com
www.wooly-mammoth.michaelandersondev.au
mila.ec
www.moirarte.com.br
app.moonex.ltd
nickmarcionese.info
www.nnamo.co.uk
apps.nomowsoft.com
app.nudge.contact
app.oktomark.de
okyzo.ma
olickalgoldloan.in
store.ordo.is
paneladeferroivaipora.com.br
dev.pappstor.com
www.pensioenbijvebego.nl
admin.processdiy.com
www.puzzlesmastery.com
app.pwrpln.hu
aoasurvey.realtimeknowledge.com
feedback.realtimeknowledge.com
app-develop.reinaldoalguz.com.br
app.resumedart.in
rethinkreading.app
rms.roscompromotie.nl
rumbleonandridenow.com
saigonsoftware.solutions
www.sellerlab.shop
shanna.com.ar
shrimptech.vn
sm3rakennuspalvelut.fi
objectdoc.solvea.ch
dev.auth.app.theconvohub.com
www.thepositcollective.pl
app2.0.thesofttrainer.com
staging.thinkbudgetapp.com.au
www.tnylee.com
www.try-me.jp
www.vinalavite.com
www.vincentbarbosavaz.com
webkutuphane.com
whygames.top
wilfas.com
demo-forest-firefly.wiselysoftware.com
www.woxtr.com
Other domains in certificate