Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=ondrejbures.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 13, 2025
Valid Until
January 11, 2026 56 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
28:98:73:83:34:0B:DC:40:B2:A2:17:3D:71:05:CB:F9:7B:C6:27:B1:5F:CB:76:00:B3:95:7B:1E:83:51:45:08
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
thekamalatoe.com

Other domains in certificate

123meet.com.br
wickes-cert.3dcloud.io
academiafabrica.com.br
www.albassel-logistic.de
www.aperclasssettlement.com
atess.dev
magda3.brinias.eu
bwfieldapp.com
td.camiapp.net
cat-guardians.com
www.cleversale.com.br
radio.intechsoft.co.kr
med.com.vc
crosstalk.lol
www.daisyinsight.ca
dctechcommunitychampions.org
denbaba.be
dexba.de
www.dezinersoftware.com
thiruvarur.eacabs.com
escueladeyachting.com
wes.exverge.com
earthday.fairchain.org
www.fertilab-bo.com
dev-app.frisbee.today
gardez-votre-permis.fr
gjorchestra.it
www.globalonewaycabs.com
gods11forecast.in
gofranch.com
gurukripaphysiotherapy.in
harmansingh.me
www.hitbytes.com
homeneedscatalog.com
www.hoppaardjehop.com
www.hostyourfrontseat.in
i2rps.com
icicle.exchange
indiskportal.se
www.insanecrew.net
www.isrndt.com
www.nimmm.it.com
jam.jamables.com
pwa-inss.kardbank.com.br
admin.khetipoint.com
paydev.lipalater.com
app.logishotels.com
marcoscazaux.com
www.mobredical.com
auth.dev.nekonone.jp
envestnet.advisor.netlaw.com
admin.nevermealwayswe.com
nihalbabu.in
app.notaryaudio.com
www.nunar.es
ondrejbures.com
oneinamillion.today
www.opsambala.com
festival.osim.at
palmayasociados.com
u.paw-swing.com
vodafoneitaly.platformkids.com
player2productions.com
admin.plodovi.hr
premtisk.com
www.profumeriarizzato.it
www.rajbedagphotography.com
raymond-price.com
link.recrewt.de
wax-center.redreamer.io
www.redswansoft.com
www.rement.io
saatvikheal.com
inspiringtoumorrow.sanofievents.in
short-video.jp
dev.skorapp.id
www.smartelectriccorp.net
vilnius-airport-parking.snabb.lt
mtsusweeps.sqwadhq.com
sreegokulevents.com
stevenpopovich.me
docs.sucm.org
bodacastillopalmar.swanmoments.com
client.synergy-app.net
dev.taponces.com
transervicecanada.tcontur.pe
www.thefreshdairy.com
stage.thejaredwilliams.com
user.dev.topia.tv
www.traveldia.in
tupgrade.com
univerdis.media
admin.urbancitytravel.com
www.viphotels.lk
policy.voa.delivery
weluz.com
www.whizzbusinesssolutions.com
www.xamarketsinvestment.com
beta.yac.com