Open
Cached
·
just now
83/100
SECURITY SCORE
Certificate Information
Subject
CN=skyble.ae
Issuer
C=US, O=Google Trust Services, CN=WE1
Valid From
December 11, 2025
Valid Until
March 11, 2026
58 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA256
SHA-256 Fingerprint
C2:D0:DC:88:4F:6A:20:88:25:A1:2F:D2:18:1F:43:92:0E:87:8D:9A:DD:54:26:66:56:D0:90:63:8A:4A:BA:23
Alternative Names
Security Configuration
TLS Protocols
TLS 1.0
TLS 1.1
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
Warnings
- • TLS 1.1 is deprecated and should be disabled
- • TLS 1.0 is deprecated and should be disabled
HTTP Security Headers
Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Basic
default-src; script-src; style-src; +8 more
default-src 'self' data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' embed.figma.com figma.com https://*.superopsmsp.com https://*.superops.ai blob:; script-src 'self' data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' https://*.getbeamer.com https://*.google.com https://*.superops.com https://*.superops.ai https://*.mysuperops.com https://www.gstatic.com assets.superopsmsp.com https://*.chameleon.io https://*.commandbar.com https://embed.figma.com https://*.figma.com https://unpkg.com cdn.mxpnl.com fast.appcues.com js.chargebee.com *.jsdelivr.net js.stripe.com widget.intercom.io canny.io js.intercomcdn.com blob:; style-src 'self' data: 'unsafe-inline' 'unsafe-hashes' https://*.getbeamer.com https://*.commandbar.com https://embed.figma.com https://api.fontshare.com https://*.figma.com https://*.superops.ai https://*.superops.com js.chargebee.com *.jsdelivr.net fonts.googleapis.com fast.appcues.com; img-src * 'self' data: https://*.superops.ai https://*.chameleon.io https://embed.figma.com https://*.figma.com https://*.superopsmsp.com https://*.commandbar.com https://*.googleusercontent.com https://galaxy-attachments-prod.s3.us-east-2.amazonaws.com https://eu-galaxy-attachments-prod.s3.eu-central-1.amazonaws.com https://downloads.intercomcdn.com https://js.intercomcdn.com https://static.intercomassets.com https://i.ytimg.com galaxy-attachments-prestage.s3.us-east-2.amazonaws.com galaxy-attachments-stage.s3.us-east-2.amazonaws.com galaxy-attachments-dev.s3.us-east-2.amazonaws.com galaxy-attachments-prod.s3.us-east-2.amazonaws.com https://www.gstatic.com blob:; font-src 'self' data: https://*.superops.ai https://*.chameleon.io https://*.figma.com https://js.intercomcdn.com https://fonts.intercomcdn.com https://fonts.gstatic.com https://www.gstatic.com https://cdn.fontshare.com js.stripe.com; connect-src 'self' ws: wss: api.appcues.net https://*.superops.ai https://*.superops.com https://*.mysuperops.com https://api.ipstack.com https://*.getbeamer.com https://cdn.fontshare.com https://*.chameleon.io https://*.figma.com https://unpkg.com https://*.superopsmsp.com https://*.commandbar.com https://public-api.freshstatus.io https://session-replay.browser-intake-datadoghq.com https://rum.browser-intake-datadoghq.com https://rum.browser-intake-us5-datadoghq.com/ https://api-js.mixpanel.com https://uploads.intercomcdn.com/ fast.appcues.com galaxy-attachments-prestage.s3.us-east-2.amazonaws.com events.launchdarkly.com clientstream.launchdarkly.com api-iam.intercom.io app.launchdarkly.com appcues.com https://*.bettermode.com https://ingress.us1.rum-ingress-coralogix.com https://ingress.eu2.rum-ingress-coralogix.com https://*.intercom-messenger.com wss://*.intercom-messenger.com; media-src 'self' https://*.superops.ai https://*.superops.com https://embed.figma.com https://*.figma.com https://*.commandbar.com https://js.intercomcdn.com; object-src 'self'; prefetch-src 'self'; frame-ancestors 'self' https://*.superops.ai http://wails.localhost wails://wails https://wails.localhost; frame-src 'self' https://*.getbeamer.com https://play.google.com https://*.superops.ai https://*.superops.com https://*.mysuperops.com https://*.chameleon.io https://www.gstatic.com https://www.google.com https://embed.figma.com https://*.figma.com https://*.commandbar.com https://widget.dromo.io https://superops.chargebee.com js.chargebee.com https://intercom-sheets.com https://www.youtube.com https://www.youtube-nocookie.com fast.appcues.com js.stripe.com
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Present
geolocation=(),microphone=(),camera=()
Recommendations
- • Consider adding 'preload' to HSTS for maximum security
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports