Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=flutterdemo2.miniorange.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 27, 2025
Valid Until
January 25, 2026
64 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
85:7F:85:2F:4C:31:C5:65:4D:96:1B:1C:CC:91:CF:1B:0F:ED:DF:91:CA:9E:EC:BE:0A:42:F3:1E:13:4A:ED:DB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
suez.dev
6horasmtb.com
tmp.akiicat.com
alpinjob.pl
preorder.atmotube.com
www.authrabbit.com
badal.io
bart.codes
beerbase.net
cookbook.bytelab.dev
link.c4j.jp
www.camberwelltech.co.uk
www.capitalprojectsportal.com
cardi.st
caribbeanlodge.org
www.cog-i.org
cbre.collaborative.fm
www.cyrilsaade.com
dashboard.deklussenapp.nl
www.designalley.in
www.digimedconsult.com
tictactoe.evelynbauer.ca
www.faisalbasheer.com
dev-tracking.farmartos.com
feedback.gifts
link.homolog.fieldpro.com.br
portal.firialabs.com
join.flashnprove.com
weekly.fleisure.com
flemingbuildingservices.com
www.flipface.io
garlawabogados.com
www.gasmexapp.com
admin.getml.com
svm-design.gospurr.com
grupocuidatemas.com
gyongyiras.hu
jumper.halfbrickplus.com
dental.hexas.co.uk
www.homefident.com
hooooooooo.com
dev-app.hostabee.com
nextshift.howtohockey.com
iamiyyappan.dev
app.imoveisvilela.com.br
instantapps.dev
instantxt.com
www.itzelyalejandro.com
demonstracao.portalcliente.izii.io
fb.jasonpitman.com
jerkeatsconcierge.com
jimotointl.com
linkstg.jinovel.com
portfolio.juulsgaard.io
demo.kesselring.nl
tirupati.kishoredroptaxi.com
litastacos.com
auth.lykdat.com
macwindle.com
la-nutrizionista.made-4-pets.com
evergreen.madhive.com
melinawedsjonathan.com
memoriasandresbello.com
flutterdemo2.miniorange.com
dev-app.minna-no-ginko.com
momotabs.com
www.mydebtfree.coach
nitink.com
notestring.com
uniloan.dev.ob-vious.com
www.onepicture.co.nz
app.ophelia.com
oysterassassins.com
bc.pep-rg.jp
www.carmelitaselda.plataformaelisea.com
playturnal.com
pocketstach.com
exams.qknowedtech.com
raynorlighting.com
www.realistichno.com
driver.roveapp.net
sadatahmed.com
app.sbilanciati.it
www.sibertakvim.com
slrewards.biz
maj.smanga.eu
www.smileypop.fun
fent.spwn.jp
www.techformalls.com
freecell.games.tetherstudios.com
tezel.dev
admin.thehusslasquad.com
thenineelements.com
flex.ton.surf
trainy.live
www.vineetkumarjain.com
preview3.fm.stage.voiapp.io
www.vvscode.net
waitwhile.com
xaydungtrongoithuanphat.com
Other domains in certificate