Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Google Trust Services, CN=WR1
Valid From
April 20, 2026
Valid Until
July 19, 2026
65 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
59:52:FF:CB:87:07:4D:7D:A0:E9:A3:DC:F7:80:47:37:45:21:52:9C:22:E5:CB:4A:13:EF:92:EB:61:58:69:D0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
44 domains
vtguy65.link
www.vtguy65.link
tls.automattic.com
devi-x.fr
www.devi-x.fr
www.mach5data.com
qvago.services
www.qvago.services
stefanocarbone.net
www.stefanocarbone.net
thesongwarden.com
www.thesongwarden.com
www.thewoodencrown.com
tkdunning.com
www.tkdunning.com
tondutonini.com
www.tondutonini.com
www.topnotchstumpgrinding.com
torontoreads.com
totalpipelinecleaning.com
www.totalpipelinecleaning.com
transintranslation.com
www.transintranslation.com
transportperspectives.com
uniwash.se
www.uniwash.se
untilyoudrop.shop
usjcalc.org
www.usjcalc.org
utahblockchain.org
www.utahblockchain.org
www.victoriasartcorner.com
www.victoriascott.ca
vmesni-svetovi.blog
www.vmesni-svetovi.blog
www.watersportsandiego.com
wdittmann.com
www.weareequal.art
www.whats-in-the-box.uk
whenallelsefailseatcake.com
www.whenallelsefailseatcake.com
whereintheworldismilzy.com
whistlerborn.com
whiteseacapital.com
Other domains in certificate