Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=app.numoonprojects.co.za
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 13, 2025
Valid Until
March 13, 2026
52 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C7:C1:31:CB:32:9D:22:82:71:8B:99:1B:A2:5A:75:89:1D:61:24:C6:27:97:07:6A:14:A7:70:73:08:81:E9:A4
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
street-e.ch
dev.fredd.28east.co.za
www.activethings.io
aigerim.org
glossario.aleiros.com
alexdr.com
apertura.alfyinversiones.com.ar
ampubnight.org
www.andrewstone.dev
anthonykubeka.com
astrialp.com
hale.babsington.com
beaulink.ng
bienestarysaludnaturalimm.com
lab.bisteep.com
jayasakti.biz.id
bunkbread.com
app.bunnypark.co.za
everyday.bxt.org
test.portal.camino.solutions
www.centralmotorspatos.com.br
dashboard.combatgo.app
beta.couch.live
bookings-demo.daekon.io
www.davidcastro.com
despertame.org
pagelink.doctor.one
parking.dox.pub
eatwithjump.app
algoritmo.efetiva.dev
clasificados.elsoldehermosillo.com.mx
flexdev-solutions.com
www.fr-poppenhausen.de
www.fravinnu.is
shop.gemetis.com
mobile.godochurch.com
test-cancellation-origin.gohenry.com
ap.gramatikisht.al
hahanono.com
homele.jp
www.kble.co.uk
qa.konstantinedatunishvili.com
www.littlemillenniumnoidaextension.com
www.lsystem.md
lumofun.com
maginsights.in
tabor.malenovska.cz
www.masterschool.cloud
maurusfrei.app
measurementlab.org
omen.monsterbilligt.com
www.myconreg.xyz
avuu.nargil.net
www.nomid.tech
app.numoonprojects.co.za
www.o-code.io
omeryasiroguz.com
ekklesia-kristus.gkbi.or.id
ordonezart.com
www.pavelgolyshev.dev
actionbrowser.pixelsucht.net
planetmoji.com
app.podcastpage.xyz
www.protics.com.mx
task.pteno.com
dev.pttepworld.com
www.quantumfuzz.org
ralphiloutatoy.com
www.rodcero.com
3m.runi.in
saar-inc.co
www.sampledoom.site
www.shipticket.app
gifts.sjc.co.za
sodtf.com
midi.soho.lt
soik.me
spur.us
play.stackattack.app
app-beta.starsnoopy.de
strefa-fizjo.pl
surafel.com
tecxprt.com
tedxuoa.co.nz
www.tedxuoa.co.nz
the-ko.be
metadata.thetwentysix.io
transplease.fr
saidso-dev.tuan.contact
vehla.dev
www.vehla.dev
quiz.video-jockey.com
warungbersama.com
kvasir.westling.io
www.wiselysoftware.com
naspers.xhuma.io
writing.zafarali.me
zakwanashfaq.com
www.zatuai.com
zennetalers.be
Other domains in certificate