Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
April 08, 2026
Valid Until
July 07, 2026
55 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
5F:8D:FB:DF:DE:81:BE:AE:6D:29:78:22:34:54:1D:F8:1B:F2:ED:D5:B0:52:09:8A:C4:55:85:6A:FD:FF:91:E0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
51 domains
www.integralcomms.com
www.abctest00001.com
adoredsalon.com
www.adoredsalon.com
www.agility1cx.com
allhose-inc.com
www.allhose-inc.com
andersonappraisalca.com
www.andersonappraisalca.com
tls.automattic.com
director.bcicny.com
carfcuracao.com
www.carfcuracao.com
dearcolton.com
degennaro.law
www.degennaro.law
denveroms.com
detoxforu.com
www.detoxforu.com
drpipefabplus.com
www.drpipefabplus.com
duanewells.com
www.duanewells.com
elisabethrapportcomm.com
www.elisabethrapportcomm.com
emptypictures.net
www.emptypictures.net
espridalivecontrol.com
www.espridalivecontrol.com
community-development.extension.org
copdei.extension.org
grapes.extension.org
healthy-food-choices-in-schools.extension.org
gormc.org
jejsd.com
www.kidsofincarceratedparents.org
kmg-import.com
www.kmg-import.com
lfl.kcr.mybluehost.me
xtj.zct.mybluehost.me
novelinvestor.com
www.novelinvestor.com
okair.ca
www.okair.ca
orolawfirm.com
www.orolawfirm.com
blog.pledgeme.co.nz
www.rasmachinetool.com
www.somodernlife.com
springboardccia.com
booking.stewartcp.ca
Other domains in certificate