77/100 SECURITY SCORE

Certificate Information

Subject
CN=member-dev.oakmorehealth.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 29, 2025
Valid Until
January 27, 2026 74 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F3:71:71:54:09:17:C8:B9:28:BA:A4:4C:88:99:B2:6E:03:F1:6D:A2:EB:C0:0F:70:5E:C7:D9:E8:7A:94:3B:E9
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
whataremydevsdoing.com

Other domains in certificate

1erbalcon.fr
2nv2u.com
www.abhamarketing.com
www.aimresume.com
www.alasticit.com
conversion.ameneko.com
www.avicenni.com
app.base-chat.de
bcfmc.org
beforeidie.space
www.btoglise.no
app-02.dev.carto.com
www.cjcdevs.com
www.paydac.co.kr
communitylp.com
www.creationlife.study
www2.cwlau.com
www.dailyelvis.com
portal.danatbazar.com
www.davidefelline.it
stage.dd.digital
coinleague.dexkit.com
blog.documentnode.io
widget.e99x.com
api.earclubnft.com
elliss.xyz
www.enypages.com
evanwcrow.com
japanese.fengyi.rocks
finserveindia.com
sheets-preview.flechs.net
forddowner.com
friendtip.app
gearshiftfellowship.com
dev.auth.getliszt.com
vmp-qa.ics.gov.sc.govtas.com
help.gtohero.com
gundetection.io
hero-chart.kr
idolabs.de
www.infohk.net
inside.ingaia.com.br
staging.insurrectrebellion.com
www.ipscrcsaludytrabajo.com
aipna.jeffersonfreitas.dev
jenkodynamics.co.uk
jobspri.com
cece.kchopp.com
kkmsikichaimaiyam.com
ml2.klev.org
kobertin.net
kritish-softech.com
www.kydoscope.com
laovejatattoo.com
www.malory.co
www.mavely.life
movpark.com
mowzansi.com www.mowzansi.com
www.msp-navigator.com
osf.myvisit.guide
pic-tonybetes.mentor.neccton.com
www.neorred.com
www.nerdpol.ovh
www.nfbeats.io
api-docs.nupav.com
member-dev.oakmorehealth.com
www.app.oneclick.team
www.onlygangsters.com
patuncon.com
pianetawelfare.it
support.placeholder.co.jp
playbatre.com
ssd.poolsharking.com
zh.qm-games.com
reesheda50th.com
lab2mng.removis.jp
pos.qa1.restoplus.com
ext.sberdisk.ru
topdatatools.seanmlund.com
www.selmanates.com
corporate-lp.shokujii.jp
singhular.one
smartxelements.net
waypoint.stephaniecervi.design
strelets.work
teamsofthefuture.com
tebahchurch.org
thecflux.com
divine.timeglass.nl
www.timelogger.biz
www.triodesk.in
www.tylax.in
www.vaveda.games
vicenzaindonesia.com
www.vincentlau.rocks
demo.weckapp.com
kakera.yumenosora.net
zxgames.net