77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.pbjapps.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 18, 2025
Valid Until
January 16, 2026 62 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
43:4A:36:58:4B:AC:F1:B3:16:70:2E:78:BA:08:0B:97:D8:A6:23:34:52:E7:69:8F:7D:2E:D0:4A:A2:9B:F9:CD
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
stbenedictknights.ca

Other domains in certificate

gage-admin.activ8games.com
honghock-admin.acuizen.com
agascba.com
alvenge.com
anatoliyruss.com
apexbodytuningmassage.com
app-yacht.com
quizapp.aronteh.com
arts-ts.com
www.astronav.app
beheren.com
fclausannesport.deeplinks.bfansports.com
biggerwebapp.com
blissfill.app
bowkr.com
bushrastudio.com
dev-signup.cbreenergy.com
app.cetiuc.com
christianlimas.com
cindyhu.dev
www.clitson.nl
maishamabatifactory.co.ke
computerenhance.com
www.convertmyclicks.com
copacaucachampions.com
cs-ops.xyz
deerdenradio.com
dimasfamily.com
dirzaaulia.com
dotachieve.com
dunati.com
duomessenger.com
architetti.duranteufficio.com
app.ecotank-pro.com
empyrealperfection.com
www.envizeconsultancy.in
explore-animals.com
fedjalusa.com
fishermanangles.com
foundry-ai.co
recaps.geovelo.app
gofastcargo.shop
admin.harghartiranga.com
www.hedgehogroast.com
hujihara-kanri.com
ihe.cl
q8-indexation-testing02.input4you.be
kapoker.app
sellgpt.letsaspiro.com
logicsyner.com
luckisses.com
luxurycarevent.com
mafiadealer.com
www.maisflex.com
matlab.lk
miguel-vargas.com
mmastats.ca
biz.momeant.app
myfinancialtool.com
night-watch.club
koss.nocorp.me
nota455.app
www.novacodellc.io
numerat.de
parents.patricks.app
www.pbjapps.com
pierrethary.com
pirr.app
puckconnections.com
quick-chat.ca
get.staging.quiltt.com
asset.rcloudsoft.app
retinedirecte.com
richmondfootandankle.ca
cellmachine.ricoapon.nl
saaketh.me
sainiproperties.com
sharemyroute.app
shipnexus.us
sistemarealidad.com.ar
me.spaki.io
www.studiojatayu.com
talentoso.cl
www.teamdivis.com
cdn.thecocooncollection.com
www.theeggwhite.com
web.time-wallet.app
todotijuana.com
tramites-sscqro-gob.mx
tfibengaluruchennaihyderabad.trustin.app tfidelhikolkata.trustin.app
vauxhealthcare.com
vinaydhomne.in
vipgsmstore.com
vitra.app
www.websitedocaralho.com.br
wedreel.in
whosu.co
staging-kitchen.yumitos.com