Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=bripaxspa.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 04, 2025
Valid Until
January 03, 2026
49 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0E:77:FE:B6:7A:C0:80:A4:44:EF:B1:9C:4A:79:54:6A:25:DC:B7:D9:4C:D9:CC:6A:4F:3F:C1:7B:9C:F1:81:11
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
uccloud.com.tw
204.play.online.zupeegame.in
roomscanner.3dcloud.io
studio.adventify.com
ai-threads.shop
www.aicasindia.in
surgicaltray.akdndhrc.org
alexandrapopescu.com
www.alexvriezen.nl
andrewrotert.com
properties.anhnguyenre.com
cms.appcharlie.com
atelierdoodle.net
auxilia.cloud
uxtools.behaviolabs.com
build.bespoken.io
bln.city
tools.block-flow.com
bripaxspa.com
butgodbook.co
www.christinazhang.me
groceries.cjennings.dev
www.clinkee.com
portal.cloudhexa.com.au
uatgalderma.weget.co.th
demo.ips.bluepin.com.hk
pinkninja.fizen.com.pl
ne.com.tr
aiurg.cosyandsafe.com
app.development.coupocket.com
portal.databackup.com.br
dibyanshupandey.com
www.dothingsapp.com
d1-my.dpd.co.uk
blog.dropin.place
duix.co.uk
www.earlyedqualitycheck.org.au
dev.checkin.northlineschool.edu.kh
www.esbspeed.ca
gromit.fairycat.biz
www.familiabet.com.br
salon.favsalon.com
www.flexpdf.com
flowindi.com
getup.ai
v2.gpsfleet.my
grimerian.com
hahn.graphics
hdcode.dev
wiki.hexchain.org
app.holy-quran.site
staging-hub.hoxby.com
nguyenminhhieu20224983.id.vn
www.improvementafosas.com
stg.auth.parents.inexus-co.com
app.informationhub.io
interviewcarousel.com
irontech.cl
javierfullstack.es
auth.k-9apps.com
www.kypa.com.co
www.lemetrika.org
lifebitsapp.com
beta.loyal.guru
windigital.madhive.com
hub.malmeidadev.com
www.mbo.me
doorlock.mhmranch.com
milumino.app
admin.monstersportsinsurance.co.uk
dashboard-retail-beta.mytechnis.com
dashboard.neuralsoftsystems.com
nextapple-external-login.nextapple.com
www.nexusrealm.io
producer.nrtya.com
crm.dasta.or.th
pmot.com.br
www.politiks.us
staging.p.pukket.co.uk
www.reten.ai
www.rivierachalet.ae
ppe.teacher.roingapp.com
safejourney.app
taaluma.sayuriai.co.za
www.skinseed.io
dior.sky-boy.com
sneed.io
www.gestion.sportclub.com.ar
hangman.szabonorbert.me
td7.cc
perfil.truco.online
tullamarineairporttransfers.com.au
backend.uugot.it
www.verbouwingen-verschatse-bv.be
victorjouin.com
www.vintagepro.app
vizboard.vizlab.cc
vssnagpur.com
dashboard.williecubed.me
goodlifec.wowdesk.jp
Other domains in certificate