Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=auth.nativescript.org
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 24, 2025
Valid Until
February 22, 2026
88 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
43:D2:96:D3:69:02:E1:7A:09:95:83:E0:44:DA:C5:F4:46:9A:06:C7:54:FC:C4:37:9C:FD:D6:8D:3F:A6:5C:6F
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
wafka.com
116os.de
www.agrgtr.xyz
agrihard.com
panel.airtraningcenter.com
www.alacart.shop
www.askyesman.com
www.autowash.online
www.batymultimedia.co.za
bestemoji.online
bezosolana.xyz
botev-ardea.com
fallabilbao.bracelit.es
www.brightestbio.com
wallet.byteblockchain.org
www.cahane.co.uk
carequarium.com
dl.chorusclass.com
www.globaltoursandtravels.co.in
www.vigneshfireworksagencies.co.in
coffoundation.org
confera.me
www.criticalpathsolutions.com.au
alpha.admin.cureboon.com
d17o.com
destrywright.com
www.disrupttechlabs.com
example.spp-prod.domainsfordays.net
echowear.org
app.effizient.ca
goodbye2021.enigmahouse.jp
www.ethanlouie.com
laundry.freshclothes.app
georgesavvas.co.uk
shop.gls-spain.es
gyrosbbq.com
cliente.henriquesetecordas.com.br
www.hfhsociety.com
iambluewonk.com
iamhernan.com
editor-steamhub.idealabkids.com
adlac.immodigi.app
indefinible.live
careerlearning.indiandevelopers.org
www.iplan.to
jesusyalicia.com
jichao.li
india.jugaddeals.com
pm.jvapps.in
otamas.kreisen.org
events.laughlounge.ca
feedback.limacharlie.io
www.locknotes.app
lootlot.com
www.luizmoura.me
lupovidal.com
www.madisonworld.in
makapartners.com
matsuepiano.com
mattymcfatty.com
partners.medics.academy
dev.minsparta.ru
bank.moneylover.me
www.mrerogers.com
musicfm.jp
auth.nativescript.org
naturheilpraxis-daube.de
www.nazohiroba.com
devinsight.onboardrs.com
www.oneminutefor.com
pantrywizard.io
7star.piticommerce.com
iptv.playflix.fun
portoaquitemsus.com.br
www.puntolabs.com
web.recibofacil.app
rijschoolnickan.nl
rileqe.com
jsonninja.risubramonian.com
ryanleichliter.com
www.dnd.samsite.io
shmuelberman.com
track.simplytech.mx
www.sparsecreations.com
ssorenson.com
sviamiprimonraj.in
tools.thecodingco.in
www.thinkzambia.org
www.topgeneralautoglass.com
www.tourmaline.nyc
tradonics.in
noodplan-bv-test.trustedaccountant.nl
vhill.com.mx
www.vincentogloblinsky.com
plugplayscore.vz-experiences.com
www.welldhan.com
wingtracer.com
yeahunter.hu
zoltragroup.com
zoologicapps.com
Other domains in certificate