Open
Cached
·
just now
93/100
SECURITY SCORE
Certificate Information
Subject
CN=verso.de
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
November 19, 2025
Valid Until
February 17, 2026
49 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
90:60:B9:1A:92:4A:07:82:B4:B7:08:70:D5:62:8C:4F:C4:11:F3:C6:6D:B0:5A:A0:0E:B3:46:15:7E:F8:27:30
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
Content-Security-Policy
Basic
frame-ancestors; frame-src; default-src; +10 more
frame-ancestors 'self'; frame-src 'self' blob: data: https://wp-rocket.me/ https://youtube.com https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com *.verso.de *.hsforms.net *.hubspot.com *.hs-sites.com *.hubspot.net play.hubspotvideo.com *.hsforms.com https://bid.g.doubleclick.net https://td.doubleclick.net https://www.googletagmanager.com https://googletagmanager.com; default-src 'none'; script-src 'self' *.verso.de *.wpenginepowered.com https://*.outbrain.com https://amplify.outbrain.com *.hsforms.net *.hubspot.com *.hsadspixel.net *.hs-analytics.net js.hscta.net static.hsappstatic.net *.usemessages.com *.hs-banner.com *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hsforms.com *.hs-scripts.com *.hubspotfeedback.com feedback.hubapi.com data: 'unsafe-eval' 'unsafe-inline' https://googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://dntfctn.com https://cdn.mxpnl.com https://snap.licdn.com https://yoast.com https://ams.wpml.org https://*.mixpanel.com https://api-js.mixpanel.com; connect-src 'self' *.verso.de *.wpenginepowered.com https://*.outbrain.com https://stats.g.doubleclick.net https://px.ads.linkedin.com *.dntfctn.com https://dntfctn.com https://*.dntfctn.com *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net *.hsforms.com https://googleads.g.doubleclick.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://www.google.com https://yoast.com https://my.yoast.com https://ams.wpml.org https://*.mixpanel.com https://api-js.mixpanel.com https://*.hsappstatic.net; img-src 'self' blob: data: https: *.gravatar.com *.hsforms.net js.hscta.net no-cache.hubspot.com *.hubspot.com *.hubspot.net cdn2.hubspot.net *.hsforms.com www.googletagmanager.com https://googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com https://google.com; style-src 'self' 'unsafe-inline' cdn2.hubspot.net *.verso.de https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com https://ams.wpml.org; font-src 'self' https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self'; form-action 'self' https://forms.hsforms.com; media-src 'self'; child-src 'self' blob: *.hsforms.com *.verso.de https://verso.de;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
no-referrer
Permissions-Policy
Present
accelerometer=(), autoplay=(self), camera=(), encrypted-media=(), fullscreen=(), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(self), usb=()
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports