Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.codeauditor.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 25, 2025
Valid Until
January 24, 2026
73 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
50:2A:B4:CC:1C:A9:5F:A0:13:0D:5B:23:01:28:1B:FF:F4:BB:EC:B5:BB:A7:CE:64:39:B0:3B:CC:D7:40:99:0A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
windsocq.ch
squad.agriboss.com
truecanada.aiempower.ca
app.ar-route.com
accounts.assemblrworld.com
app.bienautravail.io
biererieshelton.com
loans.buja101.com
www.burmsverzekeringen.be
cascadiacarbon.com
www.cavemanbarber.cz
www.cbofc.com
app.centelhr.com
kaya.chi46.com
billing.unitedventures.co.in
www.codeauditor.com
acea.kvs.controltag.it
workinslovakia.copacodu.com
mobile.coteparents.com
curso-angular-recipes-app.davidborge.com
admin.digitalguest.eu
d1-international.dpd.co.uk
www.e4iu.pt
account.earthimpact.com
sandbox.cloud.edierre.net
cms.staging.elkaso.app
eon-games.com
www.eplata.com.br
links.eqicorretora.com
fdssisb.com
www.fenomenos.org
api.fina.cash
plan.footballcoachs.com
admin.gakal.au
events.generals.io
authpartners.getlavado.com
www.goalcupapp.com
www.golftracker.ie
www.hanekhx.app
hariomjangra.tech
number-api.harshpatel.info
applications.hummingbirdtech.com
www.hydro.tv
www.hyperglass.com.au
ighsaansadienattorneys.co.za
www.imagebellissimo.in
bo-dev.ywc.in.th
ids.indu40.com
www.inteliped.online
jazaninv.sa
www.blog.jubitz.ch
app.kenesty.online
dlink.kougekisya.jp
krokis.org
lukecutting.com
mainmosaic.com
materiahunter.com
angular.matthiasmatz.ch
www.mdaware.io
dev.monax.dk
www.mozzom.io
app.nomadhideout.com
onboarding.plus
www.packedge.de
swarm.phospec.io
dsa.pokehub.de
app.professionisanitarie.com
ios.push7.jp
weathermap.qap.red
realindrit.xyz
analytics-viewer.robotical.io
www.semeree.com
admin.sendgate.net
www.shopifydataconverter.com
app.skedit.io
adet.slared.cl
medlem.snart.nu
sodybalabunavoje.lt
swafpapp.com.au
www.szabobeata.hu
www.taichi.lv
www.thehappyarc.com
app-sandbox.theoceanleads.ai
hillsvet-dev.thepetdoor.eu
thoughtscape.app
ana-paton-pilates-center.timp.io
tomasjezowicz.cz
tsebo.app
unyfox.com
epu.vz-experiences.com
app.wangll.co
www.webassembly.tech
producthunt.weekday.works
wfm-consulting.dk
williamott.net
yamboo.app
nurselink.ygit.tech
www.shiftly.ygit.tech
www.zigali.fr
auth.testenv.zizr.id
Other domains in certificate