Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=beta.fundwave.app
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 23, 2025
Valid Until
December 22, 2025 32 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
31:63:78:AA:C3:BA:44:96:A1:26:D5:75:88:28:C8:B8:78:5D:E1:89:93:5D:13:01:D8:B2:AA:2D:F2:B4:2E:D6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
wtpa.club

Other domains in certificate

www.0xf2.com
3weekwanderlust.com
pipeline.8bitpictures.com
www.8lueberry.com
blog.alexalves.design
dev.patient.ambii.com
arepschool.com
link.artsplit.com
www.ataralondon.com
signup.staging.athenago.com
avictimof.com
online.ayyappadevasthanambowenpally.com
glenaan.ballycastle-accommodation.com
benedekszabolcs.com
up.bergmann.tech
biba-bop.fr
bigcodegen.com
brasumadre.com
auth.bukytalk.com
buysiderealtor.com
www.chessonlinegame.com
chickenbot.com
chrisport.com
amantraders.com.pk
dailycreative.com.tw
consolidinc.com
salary.dailyuxwriting.com
danfarisato.com
dangolban.com
datedojo.com
davidvest.dev
www.debabydoctors.nl
dena-bc.com
discoverycancun.com
briefingtool.easybranding.be
cef-info.easysignage.app
emeraldicons.com
legacy.ethertulips.com
fatcatcoffee.com
fekvefogyasgyor.hu
fishtank.cloud
offline.parcs.dev.flashparking.com
admin.tst.frissegedachtes.nl
frolikov.com
fswm.de
beta.fundwave.app
www.gigajot.com
grok.grokdox.com
hipona.pl
hippona.org
hitthebox.com
coldmoor.hububz.com
imrenkasap.com
www.it-e.se
joelweb.ch
mobile.kaliteh.com
kiwifinance.com.au
docs.komp.ai
eva.lernit.app
links.lifereminders.eu
limweien.com
mabucket.com
www.manindra.com.au
miguelmosca.com
www.moffitt.app
www.opx.net.br
www.nik-sytnik.com
api.nopwd.io
mobile.odss.jp
app.oneweekleap.com
my.onework.co
paulastonecounselling.co.uk
app-dev.pocketjaunts.com
www.preptaxcorp.ca
proangular.com
q8tn.io
espace.qr-up.fr
app2.quicktype.io
www.restocleandashboard.com
www.rikukallio.fi
www.salarysurvey.in
www.shadowsinthemirrorfilm.com
www.yakoovrotman.shopix.me
staging.signalflare.app
www.soujanya.dev
strongwallet.co
cdnstatic.studio-mason.it
bodacarlosyraquel.swanmoments.lat
taniepodroze.com
samiexperimentation.tech4work.fr
tecoolremovals.co.uk
textabledev.textable.app
theguiltfreepledge.com
villajaidee.com
www.virtualavionics.com.br
wakka.com.br
quiz.whiskay.dev
www.whoma.co.uk
app.zawadi.africa