75/100 SECURITY SCORE

Certificate Information

Subject
C=US, ST=Arkansas, L=Bentonville, O=Walmart Inc., CN=ak-prod5.walmart.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018
Valid From
March 13, 2025
Valid Until
April 14, 2026 135 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6D:01:5F:2B:5E:4A:A4:2B:6C:3F:4C:B9:3F:14:A8:5C:98:E3:11:0D:B4:B6:F1:DC:40:18:81:2C:0A:49:6C:C8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

72 domains
ak-prod5.walmart.com chat.walmart.com cp.walmart.com ewaltex.walmart.com gscope.walmart.com jira.walmart.com mfaas-static.walmart.com onesource-gateway.walmart.com onesource.walmart.com opinion.walmart.com reels.walmart.com swift.walmart.com visit-api.walmart.com visit.walmart.com wm12.walmart.com wm13.walmart.com wm14.walmart.com wm15.walmart.com wm16.walmart.com wm17.walmart.com wm19.walmart.com wm3.walmart.com wm5.walmart.com wm7.walmart.com wrd.walmart.com affil.www.walmart.com collect.defenderx.walmart.com enforce.defenderx.walmart.com links.em.walmart.com preorder.wireless.walmart.com reservations.wireless.walmart.com rider.wireless.walmart.com ulearn-int.prod.walmart.com www.wm12.walmart.com www.wm13.walmart.com developer.api.ca.walmart.com developer.api.cl.walmart.com people.api.prod.walmart.com

Other domains in certificate

opinion.asda.com
bestprice-registration.com
bestprice.in
communication.ddiwork.com documentapi.ddiwork.com instantpay.ddiwork.com kyc.ddiwork.com weeklypay.ddiwork.com
b.apps.lider.cl super.lider.cl
creator.samsclub.com opinion.samsclub.com
clicks.scintilla.com scintilla.com www.scintilla.com
scintilla.mx www.scintilla.mx
scintillacanada.com www.scintillacanada.com
iptsupplier-gw.wal-mart.com mfa.wal-mart.com qtririgacl.wal-mart.com spec-ext.wal-mart.com
opinion.walmart.ca portal.walmart.ca wallet.walmart.ca wallet.www.walmart.ca
walmart.io www.walmart.io
sandbox.walmartapis.com
api.walmartdataventures.ca
learn.walmartdataventures.com
api.walmartdataventures.mx learn.walmartdataventures.mx