Open
Cached
·
just now
89/100
SECURITY SCORE
Certificate Information
Subject
CN=mods.dev
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 21, 2025
Valid Until
February 19, 2026
40 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
95:17:39:0F:39:54:72:26:EB:41:75:6A:95:89:8C:B1:CD:42:38:7B:EB:3F:EE:56:19:C0:CF:2C:EA:36:0D:58
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Basic
connect-src; frame-src; img-src; +6 more
connect-src 'self' blob: data: https://swafp-swam.firebaseapp.com/api/v1/ firestore.googleapis.com us-central1-swafp-swam.cloudfunctions.net www.googleapis.com securetoken.googleapis.com apis.google.com swa-images.web.app swafp-swam.firebaseapp.com https://identitytoolkit.googleapis.com/v2/accounts/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.gstatic.com/recaptcha/releases/ 'sha384-b0a74d1a7afcd8ccf4206f6c46f5693f57fadcc9feb6b513777527ea7d63de81f6fe3ef9507dbcc384d25aaac08aff4a' 'sha384-VQkqyzWECBbjdnrmLsMeQdf0TTXr6rfxgJXnIIszVBecGcFa03Tl4VBO4n2inOOm' https://identitytoolkit.googleapis.com/v1/ https://openidconnect.googleapis.com/v1/userinfo https://firebasestorage.googleapis.com/v0/b/swafp-swam.appspot.com/ https://firebasestorage.googleapis.com/v0/b/swafp-swam.firebasestorage.com/ https://accounts.google.com/gsi/client https://content-firebaseappcheck.googleapis.com/v1/projects/swafp-swam/apps/ https://yodlee-1.hs.llnwd.net/v1/ https://cdn.yodlee.com/ https://cdn.yodlee.com/fastlink/v4/initialize.js https://maps.googleapis.com https://maps.gstatic.com; frame-src accounts.google.com swafp-swam.firebaseapp.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.gstatic.com/recaptcha/releases/ 'sha384-b0a74d1a7afcd8ccf4206f6c46f5693f57fadcc9feb6b513777527ea7d63de81f6fe3ef9507dbcc384d25aaac08aff4a' https://www.google.com/recaptcha/api.js 'sha384-P8pCcHmv6YuQzFS4CHCBH75RXE60mJL5a4xXH5SOKJXf73JeLMNzQcVajnZH59MQ' https://fl4.prod.yodlee.com.au/; img-src 'self' blob: data: swa-images.web.app www.google.com https://yodlee-1.hs.llnwd.net/v1/ https://cdn.yodlee.com/ https://maps.googleapis.com https://maps.gstatic.com; manifest-src 'self'; script-src-elem 'self' https://www.google.com/recaptcha/api.js 'sha384-P8pCcHmv6YuQzFS4CHCBH75RXE60mJL5a4xXH5SOKJXf73JeLMNzQcVajnZH59MQ' apis.google.com 'sha256-B5XDg6SX5QkSXo9nJFSSA4Uxy5VgX7WUxH73qbNa3f0=' https://www.gstatic.com/recaptcha/releases/ 'sha384-b0a74d1a7afcd8ccf4206f6c46f5693f57fadcc9feb6b513777527ea7d63de81f6fe3ef9507dbcc384d25aaac08aff4a' https://accounts.google.com/gsi/client https://cdn.yodlee.com/fastlink/v4/initialize.js https://maps.googleapis.com https://maps.gstatic.com; style-src-elem 'self' 'unsafe-inline'; worker-src 'self' swafp-swam.firebaseapp.com https://swafp-swam.firebaseapp.com/api/v1/; script-src 'self' apis.google.com 'sha256-B5XDg6SX5QkSXo9nJFSSA4Uxy5VgX7WUxH73qbNa3f0=' https://www.google.com/recaptcha/api.js 'sha384-P8pCcHmv6YuQzFS4CHCBH75RXE60mJL5a4xXH5SOKJXf73JeLMNzQcVajnZH59MQ' https://www.gstatic.com/recaptcha/releases/ 'sha384-b0a74d1a7afcd8ccf4206f6c46f5693f57fadcc9feb6b513777527ea7d63de81f6fe3ef9507dbcc384d25aaac08aff4a' https://cdn.yodlee.com/fastlink/v4/initialize.js; style-src 'self' 'unsafe-inline';
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer-when-downgrade
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
swafpapp.com
www.a1-industries.com
aetheriahome.shop
apisec.blog
t3.baduk.club
benjaminzahn.com
bhinmalutsav.com
app.biddad.com
binxhealth.net
opensource.brooboox.com
buildwithirine.dev
super.clau.io
www.cleanandcollect.com
dghs-cst-stage.cmedhealth.com
www.coachcheetah.com
www.crankedup.com
dainikschool.com
www.dainikschool.com
app.dpo365.com
drrevanthhairclinic.com
www.eastcoastaquascape.com
www.elsaluciaarango.com
www.emlkw.com
www.epic.band
www.ericodarmawan.com
www.exocortexapp.com
fanwgn.com
labdip.fashionsuite.com
forbusfarms.com
formatchannel.com
app.freemacrotracker.com
www.gavnest.com
staging-link.getonform.com
login.gosuperscript.com
hammondtruckingllc.com
munchies.heychao.com
app.heydayretirement.com
www.huseyinerenguler.com
www.ifnoyes.com
ihatexspaces.com
d.influ-api.com
inningeater.com
beta.intellocator.com
itsyourdayofficial.com
jaf.com.pe
jdsoltec.com
dansmalentille.jeanphilippebaillargeon.com
jjdvans.com
johnnytouch.com
www.jordyversmissen.nl
k1investments.com
www.kimandkeni.com
knockstoppers.com
lastfar.com
leandropimenta.com.br
rocnation.business.lifebrand.life
tsumugi.lilacwells.com
higginbotham.loadsure.net
lohitorq.com
maven.lolay.com
www.lorkin.cc
staging-admin.lovejunk.com
matthewli.com
www.mechanicsnow.com
meslameni.com
mods.dev
myeximbusiness.com
www.mywellbe.ing
noaperu.fr
lexisnexis.nxtinteractive.com
olik.is
onboarding-mate.com
www.opuscare.in
millionmileodometer.paperwebsite.com
admin.perfectzero168.com
www.probablyzen.com
printout.psalterapp.com
subamas-admin.pujasweb.co
www.quipsoteric.com
auth.rapcreate.com
share.realtimeaf.com
www.saborissa.com
sarafigphotography.com
scottsdaledancerlawsuit.com
shreeshyamevent.com
signitiva.com
siriniwasadesigners.com
www.sosclick.cl
chicagobearsreveal.sqwadhq.com
stylerpcweb.com
price-compare.suphakorn.com
tanquesparagas.com
tclee.dev
www.theinnovatio.com
link.togle.io
ztt.tryzapp.com
vigor-witaminy.com
wasl.ch
whitelabelnearshore.com
yigittuncel.com
Other domains in certificate