77/100 SECURITY SCORE

Certificate Information

Subject
CN=llip.io
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 19, 2025
Valid Until
January 17, 2026 64 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F1:2D:17:45:88:1A:50:6B:10:6C:04:BC:34:7D:05:1A:E4:7C:02:80:50:43:68:2F:53:9C:83:5E:77:19:5E:48
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.clocktowercompanion.com

Other domains in certificate

1stmarinecorp.com
app.dev.affilimate.com
jlsyachts.ardent-training.com
www.armadaops.com
azuik.com
badassnegroni.com
bamiri.dev
mturk02.bcause.app
app.blocktickets.io
www.bnbtokens.com
sto.cadsoft.com
www.careconnectau.org
chauffeur.cityxerpa.com
go.claim-your-benefits.com
www.codingketchup.com
kiranuprety.com.np
www.deepfakex.ai
apple.degencoinflip.com
www.dg-clips.com
dieneuezimmerei.de
staging.divii.ca
dogyi.group
earningcardano.com
www.energytechnics.be
go.equippedproperty.com
www.escolafiore.com.br
mortgageapp.etiennetheodore.com
faisalakhtar.co.uk
admin.falconconsulting.fr
www.formfabric.nl
funcionalmind.com
gerrywebertoronto.com
gowithme.app
www.guildpactapp.com
mobile.hapoweb.com
www.hvormyetjener.no
idi-research.com
jackkirkham.com
jazzspot.jp
www.jibhuionline.com
jmlasalle.com
kniched.com
kou2kkkt.dev
lajoyapark.com
laylaf.com
app.lexr.ch
jp.litsly.org
llip.io
demo.lnbb.nl
www.lordanco.uk
watch.lovieawards.com
dashboard.marco-parco.com
www.mazdadegranby.com
www.medbook-ph.com
www.mipslip.com
www.morsemangini.com
backend.mortgagebuyersinc.com
chat.muytico.com
myfairybook.com
mystique.com
nearplate.com
engineer-app.nibc.co.uk
nicholashucal.ca
nisargshah.dev
omarcarrizales.com
www.onewaytaximamalla.com
blog.onkeypress.io
photographbyjohn.com
review.pitzaslice.com
odu.playfuturetraders.com
pos.point4more.com
www.projectecho.online
psirwithaires.com
admin.rategalaxy.ca
rentalplicity.com
resource.reoapp.com
www.revendedoresbrasil.com.br
robbiebooth.com
pranali.rotaract3142.org
sanjeevagrawal.com
sloandavis.com
smartcart-tech.com
smashthewalls.com
thescrutinizer.snapmentor.no
stateless.nl
tracker.stoddartlabs.com
www.suggestify.app
admin.tandemstudio.fr
auth.themonkmoney.com
meet.tknomisa.com
link.toneitup.com
tpusoft.com
amanda.turborad.com
unyoron.com
www.ushanktech.com
cuisine.valentin-maerten.fr
account.varzea.co
vcslacker.rocks
install.zerobase.io