Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=ccfh.partner.felporgetve.hu
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 07, 2025
Valid Until
January 05, 2026
55 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8F:66:0A:D4:22:3A:C4:52:24:C5:BB:AE:80:B4:AB:2F:CB:3D:64:56:4D:5E:83:95:BA:C6:58:B5:72:E3:5B:6F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
themonkeyspaw.app
www.aagate.net
portal.oe.jcfl.ac.jp
accordle.uk
addisonkreed.com
todo.ahjim.com
www.appac.us
www.ballerinas.nl
psb.ballesta.com.ar
www.beti.ch
app.bluebase.io
www.buildingblocksfinancial.com
help.calvarycampo.com.br
clydellmfactory.com
mmapp.mobile-money.com.my
monocar.com.ua
www.customcloud365.com
dash.datapacific.com
doddie.it
eventtrinket.com
ccfh.partner.felporgetve.hu
www.flutterdevelopersatl.com
admin.fotografijesaraftinga.com
kaleidoscope.frinjz.com
crm-dev.fwd.tw
gamesmystery.com
app.halodao.com
www.heartbeat.clinic
stage.hellostrata.com
www.imjustwaiting.net
ecommerce-admin.inchargeof.com
app-prod.investmarkets.com
johannfeser.de
jowall.kr
sport-en-fete.sj.k12.tr
karbotronics.com
weekly.khan.kr
staging-link.kollectin.me
www.kreatific.com
ucg.lapieza.io
www.leemartinclarke.com
www.legalraksha.com
letmai.com
nakaishoko.lfv.jp
buildabook.littlehibba.com
update.lotteries.bz
image.m1studio.co
machdaslebenan.de
www.mainzlbrass.live
loudnoises.mattdonnelly.com.au
travel.mbmint.com
store.mobilexpressrx.com
mojaid.com
mughalmasalas.com
security.multplx.com
www.murilolanches.com.br
www.mx-tickets.com
www.necoeducation.com
neuqa.com
www.ochterbeck.de
app.odiylekesfediyorum.com
www.ollari.info
oneoceanseafood.com
static.prolocksmithsorlando.com
hn.promo-tigo.com
www.ptg-in-a-box.com
qthevote.com
readgator.com
www.remi-escamilla.com
parakeet.retro-ink.com
dlh-hayati-kotim.rinjani-parahita.com
www.sbjedu.com
sbscleaning.us
scratch2screen.com
slamfriend.de
reg.smartsoft.in
teslapulse.solonevich.com
spaayurvedaninarangel.com
www.streamevents.co.za
www.stresslimitdesign.com
studigpt.com
paradiselounge.studiossolution.com
sturgeonmanager.com
systentando.com
app.dev.tara.ai
taylorrr.com
www.tegshjargal.com
thepadonwheels.com
theretirementtracker.com
www.ecom.tintoc.vn
tomke-nils.de
www.totat.nl
trainrexofficial.com
cafeathomeemenu.triggersplus.com
mars.troov.io
serpandemie.vasypaulette.com
www.vschemp.com
www.wat.by
www.wecutlb.com
www.yasu26.tech
Other domains in certificate