Open
Cached
·
just now
95/100
SECURITY SCORE
Certificate Information
Subject
CN=www.alex-rubio.dev
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 15, 2025
Valid Until
February 14, 2026
79 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
40:19:76:7E:D9:43:38:F9:49:39:DB:E0:33:9B:35:34:EA:3B:4D:0A:A8:4D:60:44:FF:7E:17:BE:6C:3A:9B:D3
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Good
frame-src; frame-ancestors; default-src; +5 more
frame-src https://admin.stage.doorjames.com/ https://www.google.com/; frame-ancestors https://teams.microsoft.com/ https://teams.microsoft.com/ https://skype.com/ https://admin.stage.doorjames.com/; default-src 'self' 'unsafe-inline' https://js.stripe.com/ https://www.google.com/ https://cdnjs.cloudflare.com/ajax/libs/font-awesome/; img-src 'self' blob: data: https://doorjames.releasenotes.io https://s3.amazonaws.com/release-assets/production/team-3224/ https://stage.spacestation.lb.alias.infra.doorjames.app https://stage.ionosfrankfurt.satellite.alias.infra.doorjames.app https://stage.spacestation.lb.infra.doorjames.com https://stage.ionosfrankfurt.satellite.infra.doorjames.com; script-src 'self' 'unsafe-inline' https://js.stripe.com/v3 https://s3.amazonaws.com/cdn.releasenotes.io/ https://cdn.releasenotes.io/ blob: data: ; style-src-elem 'self' 'unsafe-inline' https://cdnjs.cloudflare.com/; connect-src 'self' https://stage.spacestation.lb.alias.infra.doorjames.app https://stage.ionosfrankfurt.satellite.alias.infra.doorjames.app https://statics.infra.doorjames.com/ https://widget.releasenotes.io/doorjames.releasenotes.io/; font-src 'self' https://cdnjs.cloudflare.com/ajax/libs/font-awesome/
X-Frame-Options
Present
ALLOW-FROM https://teams.microsoft.com/
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Present
same-origin
Permissions-Policy
Present
vibrate=(self 'https://stage.doorjames.app'), sync-xhr=(self 'https://stage.doorjames.app')
Recommendations
- • Strengthen CSP by removing 'unsafe-eval'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
stage.doorjames.app
6bees.co
adame-techs-tv.com
agswift360.com
www.alex-rubio.dev
alkhandaqpadelacademy.com
anifestmalaysia.asia
pba-banus.ardent-training.com
verify.auditshortcut.at
authorhanalee.com
avanibnl.com
axend.co
www.barryplumbinginc.com
berimbaula.com
buildsohar.com
www.camtekuae.com
teamgmc.cargoerp.com
casaalizee.com
www.ceylonalproducts.com
armenia.aid-air.co.il
collab-merch.com
complical.fr
www.compucon.ca
hamsafar.contributenow.in
seethihaji.contributenow.in
coursademia.com
www.cryptovers.site
danielautry.com
www.daruzo.com
desilogo.com
www.desorganizando.blog
dragonsfireforge.com
ekps.in
www.fabianperez.cl
www.faviconforge.com
fitspecs.net
hkxfamilytree.com
android.infiposs.in
jagarld.me
lekarz.jedrzej-lewandowski.pl
www.jflorchi.ca
junkie-tattoos.com
karpathy.ai
keaty.co
lauren-ipsum.com
www.lava-azores.com
lectricsengineering.in
leiastream.com
lemanee.app
clientapp.lokapala.games
lomobox-nude.art
crm.lyhoursbiinsurance.com
test.magicexhibits.com
markuspoutanen.com
mathematicalinc.com
www.mellylue.cv
metaversies.com
app-link.moov.cc
orange360.agency
app.packandtrackcouriers.com
website-studio.parallelstudios.co
www.dash.pedidorapido.app
rc-connect.petleo.app
www.pizzaindustrymontalbert.com.au
prabhoo.in
webapi.proglesson.com
radianttechnosft.in
links.portal.testing.ridealto.app
rishikr.com
public2.roboflow.ai
app-news-hub-legacy.robotical.io
samuelholyhead.com
js.selimsql.com
www.seuretgranitellc.com
shieldmaze.com
shift07.ai
shiningsmile-reservation.com
www.shinkanote.com
app.shipwithnj.com
app.shipwithphe.com
app.shipwithswoosh.com
smartspacenaija.com
smtechmartllc.com
app.snapshipja.com
sometimesigethigh.com
sori-games.com
dev.sport-smash.com
os.sreerams.in
www.swapyfin.com
syslaconnect.com
www.trustcheck365.com
tusprompts.es
tvdooh.com.br
functions.uniserse.com
www.vivekabir.com
app.voox.me
wealthmanagementexperience.com
wheresmyshiny.com
x20tech.com
xoxo-original.com
Other domains in certificate