77/100 SECURITY SCORE

Certificate Information

Subject
CN=necsquare.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 09, 2025
Valid Until
January 07, 2026 44 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EA:07:B2:93:FA:BB:9F:85:14:F9:6B:58:9E:01:C1:74:71:59:AA:BB:EA:EF:00:81:C0:33:5A:08:5A:98:5A:F6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.brokenheartstables.com

Other domains in certificate

20225218.id.vn
23rg.fr
diklat.adinkes.org
www.akathian.com
anse.ro
www.anthonyelele.com
auth.awwwe.co
api.becketto.dev
www.benharvey.dev
www.bigsoftstudios.com
bluebowfashion.com
www.bmb-portfolio.dev
www.busybit.io
test.canilottie.com
ceyay.com
chateron.am
kansascity.column.us
corncob.top
p37-dev.credeo.io
dazl.studio
www.dehesa-partenon.es
www.downloadpayback.com
customeraddressbook-d1.dpduk.dev
romind.api.edwinsecure.com
mapex.exploredata.app
display-dev.ezturns.com
www.ezxapp.com
qa.face2faceweb.com
www.fagerlund.fi
product-autopilot.fashiondata.io
business.fewlsy.com
www.flexibleforms.net
godspeedmagazine.online
builder.gofoto.io
groupock.com
www.gustavbylund.com
hannamassage.pl
links.hashtime.io
www.hfrisiko.no
igu-landscape.org
www.institutosetas.com
students.ischoolconnect.com
www.israelmeirfoundation.org
www.jackmanmusician.com
pokemon.jansen.co
kaptain.art
account.karasu256.com app.karasu256.com
zecalc.katalysatorduravermeer.nl
support.like-a-rainbow.com
dev.livemedia.space
api-test.locationinventory.info
www.magen.online
mathirekha.com
mcivermotorsport.com
mesaspace.org
moneyquiz.app
auth.stage.mybacchus.net
nanolens.ro
necsquare.com
www.talleratres.net.ar
www.onkey.press
dev.pbj.live
primal-lang.org
crispysoul.order.pulp.eu
www.ratch.it
www.rsvp.express
scla.com.br
bootleggers.secretcityadventures.com
prod.signatrue.app
dispatch.sjcapl.com
staging-assets.sowork.com
sportrate.me
romebravesrace.sqwadhq.com
beta.streetcar.live
www.structuralzone.com
www.studio-dmla.ca
www.studioflo.in
synxite.org
tamayodevelop.com
www.tchalupnik.cz
www.techzodigital.com
portal.teheca.com
admin.beta.thegiftery.nz
legacy.thepcrtest.com
surveys.thesimplevue.com
links-staging.trybench.com
app.umiiiku.com
host.unipos-stg.me
upcode.ro
www.uru-rugby.com
viewdigicard.com
www.vtcbarcelona.com
wadahan.com
wajahatkarim.com
developer.web.support
app.weddlist.com
haaste.wiljam.fi
www.willowacre.com