Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=firstsafety.co.bw
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
April 15, 2026
Valid Until
July 14, 2026 62 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
14:26:CD:95:2C:87:2C:00:A6:56:B3:29:1C:16:12:F2:D1:3B:BE:14:54:38:DA:3C:50:A1:B0:75:A5:53:13:A5
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
tinyepoch.com

Other domains in certificate

dirtybit.12traits.com
404-labor.de
a24payroll.a24group.com
pudukkottai.akdroptaxi.com tirunelveli.akdroptaxi.com
akira.run
cv.alirezad.ir
angular2bes.org.uk
www.astrodynamic.co.uk
events.automatfoto.se
app.bash.social
benjaminlopez.me
rec-cda-admin.bens-groupe.com
bluberypancakes.com
apps.booklazy.org
budgetgearfinds.org
bx2group.com
www.catalina-wine-mixer.com
www.commonloyalty.com
app.contract-dewatering.com
corepox.net
deepshikhagirlsintercolleges.com
developerweekend.org trv.developerweekend.org
applinks.dhan.co
dwhtest.com
poker.dwsaas.co.uk
www.eugenectang.com
staging-superadmin.evfy.sg
ezard.io
firstsafety.co.bw
a06y.foodle.su
poms-app.frt.vn
cdn.ga-group.it
stage.apa.gaviti.com
app.getlovebug.com
gototopay.com
beta.greenqms.com
www.gsfm-platform.com
feedback.healthpointe.team
verizon-staging.ideacloud.com
idleht.ru
iiotronics.com
inrelease.nl
www.investinyou.ai
ivanzim.com
app.iworkie.com
jefferyhatch.com
jointometer.app
jundyservices.com
demo.kathaa.lk
kerlonkerlon.com
jyvasparkki-dev.kesselrun.dev
www.lealeandra1001.art
www.levelplastering.co.uk
app.linqir.com
portal.logichat.io
makeyourmenu.de
app.maxima.lv
meowspace.app
www.mshatry.me
www.nachtaktiv-emm.de
nguyenkevin.com
painel.okajimadistribuidora.com.br
app.ownhome.com
www.paliersv.com
pdaus.org
pechi-bani-spb.store
www.plotartisan.com
es.nightly.owner.pocketpost.life
votebedrock.pokefind.co
www.queerstuff.org
re-ynd.com
www.rectify.me
rl2.co.uk
launchpad.savilabs.org
schutz-wolf.de
sergiorollan.com
simuladoresstein.com
smaccoun.com
snappexfulfilment.nl
socialhi5.com
solidtech.es
www.solihull-25-plus.co.uk
beta.stepfood.com
bibleforall.sterin.dev
sc2.supercolliderportal.org
www.tanaka-architect-inc.com
thomtran.id.vn
thoughtsapp.xyz
tia-therapie.com
tryrebellion.com
policy.tvis.in.th
usual.io
vitalizebeautyco.com
login.wazistore.com
weedram.whiskyvultures.com
www.wieo.se
www.workinaz.com