Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Google Trust Services, CN=WR1
Valid From
April 18, 2026
Valid Until
July 17, 2026
75 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6B:52:88:89:05:41:7E:90:AE:E6:8D:8C:9B:97:AE:C8:F8:FF:21:77:F3:6A:DD:90:21:AA:54:31:C3:30:C1:FD
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
46 domains
brain-drops.com
www.brain-drops.com
tls.automattic.com
bluefinfishprocessing.com
www.bluefinfishprocessing.com
bostonumc.com
www.bostonumc.com
boyandhorse.com
bragrejer.org
www.bragrejer.org
brahmason.com
www.brahmason.com
braidsnbonnets.com
www.braidsnbonnets.com
brain-wreck.com
www.brain-wreck.com
brainbodybuzz.com
www.brainbodybuzz.com
brainder.com
www.brainder.com
brainder.org
braindrainpain.com
www.braindrainpain.com
braindrainunclogged.com
www.braindrainunclogged.com
brainerdmasonic.org
www.brainerdmasonic.org
brainerdwallpaper.com
www.brainerdwallpaper.com
cenitratec.com
www.cenitratec.com
www.continentalgrass.com
designsignshop.com
www.designsignshop.com
may60.com
www.may60.com
oxide-mapping.com
www.oxide-mapping.com
www.rebeccakeltie.com
tendesignstudio.com
www.thecounter.press
therevivemd.education
tokendesignworks.com
www.tokendesignworks.com
toldoshl.com
www.tonguetied.uk
Other domains in certificate