77/100 SECURITY SCORE

Certificate Information

Subject
CN=www.cristodesanagustin.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 04, 2025
Valid Until
March 04, 2026 86 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
40:CC:B6:BA:B6:56:9F:E3:38:FD:12:DA:D6:C1:98:C5:AC:BD:1E:11:EF:EC:84:C0:D5:4E:22:F1:FF:5F:EB:A2
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.carwaffle.app

Other domains in certificate

creator.6cuts.com
admin.shopping.a-sta.com
qr.absaco.com
www.accnorthphoenix.org
africasunrise.com
agsproconsulting.com
www.aliran.com.mx
andrewta.ca
menasha.appfactoryuwp.com
aprenderedivertido.com.br
krivora.aryansoni.fr
axecut.com
www.bakesbytash.com
www.basicdisarm.com
www.bitloops.com
www.catastrophicinjury.org
giganet.ceosconnect.com.br
www.chaseschweitzer.me
global-construction.com.ua
www.compliantpdf.com
www.cristodesanagustin.com
cuboapp.cl
datbikers.vn
www.debtkarma.io
app.deskbird.com
imaging.dicomlab.com
admin.donorconnection.org
easy-web-tools.net
qa.libot.stedu.edu.vn
www.emartapp.com
ercancoruh.com
www.examora.in
familyratedboardgames.com
www.finsightsfx.com
www.flowsportclub.com.br
freetools-pro.com
gugoc.com
gvsistemas.com.ar
www.hamrohelp.com
mestrado.henriquemiossi.com
heptasecurity.com
hpflexipack.com
portal.wetterdaten.hr.de
auth.hrestart.com.br
flashcards.izzet.tech www.flashcards.izzet.tech
kailaasarp.in
staging.kheli.co
www.kmfire.cz
leandroap.com
leasemojo.com
amano-reha.lfv.jp
luxevitaglazing.com
manageeverything.app
medzperfect.com
app.mentalizze.dev mentalizze.dev
mesalocahtx.com
mistergreen.es
auth.mkmfloor.com
mkthiagoshot.com.br
mohammadalijarjoumah.com
public.mooney.agency
www.nexmoby.com.br
www.niallbeard.co.uk
www.obidoner.com
www.ongakuconnection.com
parlacen.int
resume.petemdev.com
event.pixeen.com.br
playnice.games
plotlin.com
pre.quiquepintor.es
merchant.reserver.in
riadattou.com
rondarastreadores.com.br
www.rustcursus.nl
scan-master.ch
screencandy.tv
confresa.bioponto.sistemasnemesis.com.br
godstowe.sparxvr.com
stellawire.com
aida.d1.stx.world
stzengenring.com
techmedicsa.com
teutondev.com
www.thevirtualoperator.com
secure-staging.tranzfar.com
www.trompe.fr
social.v4.company
vishnuprasadkp.xyz
entrena.voicetest.org
www.webhost.com.au
weekend-editions.com
wetters-lieve.info
apps.wittysparks.com
www.workoutmuscle.com
yoninshogi.com
znamtypa.pl