77/100 SECURITY SCORE

Certificate Information

Subject
CN=dev.eggkat.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 31, 2025
Valid Until
March 31, 2026 82 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
29:71:30:BA:0A:C0:5E:C0:02:C2:7D:6A:5B:81:DA:12:6F:9B:3D:7C:B9:E2:D2:EA:8C:54:57:59:20:5B:72:FE
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
wardrobe.fascwear.com

Other domains in certificate

docu.11yearsafter11.nl
www.9tube.org
www.adbzz.com
votex.adminone.co
v10.material.angular.dev
bucket-combine-test.bce.dev
staging.backoffice.beepforhelp.nl
branched.group
www.calcolo-settimana-gravidanza.it
www.carlosmendoza.tech
www.cdopeople.com
clover.cafe
app.clup.com.br
co-financing.ru
reimagine.co.kr www.3hsolutions.co.kr
forward.com.do
costruzionidigisrl.it
rilevanps.deanchen.dev
dragonmetrics.cn
crm-staging.ed360.in
dev.eggkat.com
link.fitillion.com
fnax.co.uk
www.gametaper.com
test.gepete.com.br
app.getrentline.com
gigiboudreauxcpa.com
staging-games.granatalabs.com
www.horsesdeveloper.com
www.imageai.app
sewa.inrisk.insure
www.investaflow.com
j316.kr
staging.jodacare.com
static.jossgitlin.com
kinklyapp.com
fim-chatbot.kitchen-smart.com
klugtechnologies.com
sdk.klyoaso.com
hr.koelfresh.in
admin.lambda-math.com
lanobleza.com
delega.legalesolutions.com
letterbomb.io
letzplay.com
libozeng.com
staging-admin.lutzlotte.de
maison-regneugneux.fr
www.mazdasthyacinthe.com
megaleep.com
www.meili-story.ch
www.mensajeriabts.com
www.miguel-ceja.com
www.modernsmartspaces.com
portfolio.mouad.co
exclusives.mygate.com
www.nathanhigh.com
share.notestech.co.za
install.novonav.com
www.oldfashiontaranto.com
digitalaward.tpa.or.th
aidanfieldpreschool.org.nz
builder.paulhalleux.be
www.payboard.com
www.petrolprices.co.za
www.playtoki.com
plutonium.id
polca.pro
www.prepareyou.app
prescriptionpeptides.com
qwyk.io
frontend.hunedoara.rambit.ro
randall.vg
rfcao.com
rjsendai.com
demo.saltycareers.com
samametalltechnik.com
santaritajacutinga.app
www.serviciotecnico.ar
app-qa.setkeeper.com
shevchenkors.com
www.shsreport.com
www.signacare.co.uk
snowypotato.com
oasi-planet.soluzione-digitale.com
www.state-of-the-world.org
hymnbook.surocreators.com
www.swifthood.cz
terovest.com
tokyotoushihigai.net
app.tyme.rocks
office2-dev.typex.kr
unidasapp.com
travel.simulator.unipla.app
wanderoo.it
waybetternow.com
joinnow.winfinith.com
colecciones.zrapata.com