77/100 SECURITY SCORE

Certificate Information

Subject
CN=engage.planfuly.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 18, 2025
Valid Until
February 16, 2026 81 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B6:60:CC:76:3C:76:D0:9A:3B:90:1B:33:DA:0D:D3:15:75:44:72:C7:34:8A:9D:E7:1E:80:59:C0:59:4F:89:B5
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.craft2gether.com

Other domains in certificate

3amwave.tech
bdr-test.3dcloud.io
alinasokolova.ru
antoinetteastro.fr
arenaesportetotal.com.br
astrolix.no
www.bableai.com
biodiversidadyculturaambiental.org
campushire.me
chatelo.net
ingrid.co.in www.tutorbee.co.in
www.codeblueapp.com
dailywriting.app
dashboard.tmb.dol.it
drtitikshagoyal.in
e-umbricht.com
eeepmanoelmano.com.br
energysource.com.br
exoai.pro
www.feastfinder.com
auth.fevir.net
app.fortworthpickleball.org
playground.functionamsterdam.com
crf.futureway.in
pindorama.g2canal.com.br
www.gdgdoha.com
getgrants.in www.getgrants.in
getonboard.work
wiki.graid.io
coinflip.hopcroft.dev www.hopcroft.dev
checkout.hosting.com
huesofhills.com
hyfcompany.com
ihac-app.site
ikebukurofighters.pl
www.infocontrataciones.com
www.irisertc.org
irishmancreek.com
www.ittae.com
jeromedsoucy.com
kalyanibhagat.com
karmadise.link
kartorama.com.br
www.kiozko.com
kitzo.in
app.komododecks.com
j.kscore.com
www.lakshaykautish.com
www.liath-laverne-hawke.com
www.lilaraum.com
app.lobahn.com
manuelaraujo.com
minhngocsv.com
nazarov.dev
www.nikplace.com
odontostark.com
www.overtureatributetorush.com
engage.planfuly.com
www.pleaseintroduceyourself.xyz
projectionlab.io
www.qrcurbs.com
eldo.ratality.com
www.renatachaves.com.br
clinicaalemanaosorno.rflex.io
www.rigakayaking.com
rockyouraccountability.com
www.rupeoinrc.com
saranovellopinto.com
firebase.sdrnco.net
www.seinfeldjunkie.com
www.selvainfotech.com
dev-v2.sipldev.com
slyusarev.ru
qcshowdownwin.sqwadhq.com
srilakshmidevihomecare.com
blog.svip.dev
tanis-ska.pl
tetra.games
stage.admin.teuestoque.com.br
townlb.com
usamafarhat.com
utopia-hongkong.io
vaastu.life www.vaastu.life
vaibhavsatish.dev
link-px.dev.vetster.com
www.vfinstudio.com
www.app.vippax.com.br
directed-attested-weblib.live.websheet.io directed-attested-webui.live.websheet.io unicurl-v2.live.websheet.io
wern.space
mint.wizardcreatures.com
wsolucaoweb.com.br
www.xir0.dev
zalvax.com