Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=lab.motekawa.photo
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 08, 2025
Valid Until
January 06, 2026
52 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
84:84:11:08:98:F7:D8:3F:AF:38:0D:A1:78:B3:69:23:5C:D1:B1:50:91:B8:22:B8:34:40:7A:92:C5:54:2C:EB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
www.danielhess.me
11520895.stratics.io
ondemand.adinfluence.cl
africa-risk-consulting.africa
www.agileccpm.com
amarabrands.co
cliente.navalha.app.br
commonconnect-links.appcom.ca
apphour.com
www.artistconnect.de
www.asianassignmenthelp.com
awsankara.com
beta.b2b4-check.com
www.basavagroup.in
www.bmeguard.com
botan-w2a.com
bottirecoverytrucks.com
brezel.app
bryanle.co
buc1.com
captionpal.org
dtpm.cityred.cl
consumewise.in
public.csrcloud.app
www.datalogic.be
rigel.delisles.com
desconfieja.com.br
open.dindinn.com
www.dix-mille.com
dragongalaxygames.com
www.drnidhijain.in
www.eckastudio.com
www.ecofriendlyeve.com
ionic5fullapp.enappd.com
enumat.com
xmas.escthegame.com
is.fancrew.jp
admin.film-point.com
five5.au
top-up.fonbnk.com
www.fusionbrow.co
liconnect.getdex.com
configurator.getmystripes.com
uat-x1.golfpass.app
www.gravity-ops.com
patient.gtsvirtualhealth.net
staging.healthread.com
www.huggableheart.com
www.ipect.app
live.ishitohoshi.com
www.jdsosa.com
whatsthat4.jonas-wanke.com
joshblitstein.dev
joshualim.me
kredittium.no
universidadindoamerica.lapieza.io
little-mastermind.com
balancedunderwriting.loadsure.net
www.lockkeygames.com
lyta-sante.fr
www.mghealth.solutions
lab.motekawa.photo
nockdeighton.demo.movello.se
app.myattachment.ai
myst.my
www.nicholastobiasart.com
omsomnicanal.offcorss.com
organiser.hypenation.optimasysdev.com
pieterseassociates.com
app.plate.click
www.pltfrm.dev
docs-staging.privacyai.com
promarinernic.com
alpha.psalterapp.com
psychologue-traeger.com
clock.rangercoder.space
razorsedgeboxingclub.com
redshipping.co
www.reynanda.ca
assinatura.robsonmatos.com.br
app.s81.eu
servisuladm.com
shannonhspence.com
sharedassets.app
demonstracao.lab.sistemasnemesis.com.br
www.sloandavis.com
www.snowjoe.com
solinkp.com
olo.spoton.link
staffway.com.br
superboy.dev
www.superspesaonline.it
tarydium.com
thepour.club
toduel.app
trekontech.in
extensions.distribution.upnext.in
xbrestaurante.com
portfolio.xi-or.com
www.youlearntube.com
Other domains in certificate