Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=homeradar.co.uk
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 28, 2025
Valid Until
December 28, 2025
45 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3C:F4:EF:74:73:34:8D:1E:74:04:FC:4C:9D:E6:05:6B:2C:A2:9A:9E:DE:AF:BC:E1:78:57:0F:8F:B7:A7:38:A9
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
www.imprimatur.de
0971519452.sodientu.com
tickets.aftermoodla.com
www.agrobarnsley.com
auth.aiheadshots.us
www.ak-hpk.cz
preview.ameroexteriors.com
website.anagraph.io
baileyhulsey.com
bassetti-ites.in
www.boeconsulting.no
cashengbung.org
app.cannactive.co.il
www.codimatica.com
tv.coibong30.app
compliment-cloud.com
muvstok.consultafatura.com.br
www.jjvv.corcolen.cl
ea.cryptoethic.com
cuis.app
cyberdad.io
define.ag
www.dobra-nabidka.cz
debugtoken.dockerify.dev
ecoabc.com.mx
dev-links.ecredits.com
agents.erosmoney.in
www.fastor.in
app.floment.ai
forcey.net
www.francisgallardo.com
www.gavlansgame.com
admin.harzaan.com
firebase.st-sc-yard-management.gcp.homedepot.com
homeradar.co.uk
www.hudsonrha.com
inquiry.online
nik.is-a.dev
ivan.digital
www.jamesjwarren.com
jordy-hertogs.nl
www.kids360.in
kiismet.sg
knowtion.ca
www.knowvic.in
clientes.lifesource.es
hidrocaldas.linvixapp.com.br
loli.tokyo
lqmedia.vn
lxbrown.dev
makemywindoor.com
marcellaza.com
www.mistyburrow.com
ttrebates.mssdev.works
app.mycraftnote.de
banepa.nepaldrivinglicense.site
biratnagar.nepaldrivinglicense.site
www.nonlinear-vegan.io
app.novem.education
oben.global
www.orakalabs.com
www.pagosescuinapa.com.mx
www.sushikoasturias.pedidomovil.es
www.priorityautoescuela.es
redirect.rccsonline.com
reachsummit.app
www.revampcrew.com
www.reyescybersolutions.com
rodrigogarcia.me
api.roxabo.com
www.sandhedstabel.dk
stg.register.satella.shop
www.serverge.io
www.shubhambutle.com
app.smsenabled.com
relatorio.softenge.com.br
console.spacemarklabs.com
spreadthevote.net
admin.storevan.vlaanderen
www.strangevibrations.com
www.su-pay.jp
taxirent.sk
multido.temibox.tech
theaterhoogeveen.nl
dip.thelexusaddict.com
link.tmint.dev
beta.tripkindle.com
beta.veviam.com
www.vovapy.com
bestel.speeltuin.watdrinkje.be
www.weathertolaunch.com
wekeep.app
www.wework.cr
webplayer-stage.wexer.com
go.wing.co
fun.winticket.jp
tenant.woonig.app
app.woowbe.com
portfolio.yoojongwoo.com
www.yssolutions.org
Other domains in certificate