77/100 SECURITY SCORE

Certificate Information

Subject
CN=crownaddons.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
September 26, 2025
Valid Until
December 25, 2025 39 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A1:8C:D6:34:7B:EC:44:B2:62:0E:D8:23:B9:99:90:8C:C3:C7:BD:5A:E5:9F:52:2B:03:EA:BA:23:11:A6:A0:E8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.novalogic.dev

Other domains in certificate

aarondetrick.com
pvp.acadarena.com
afrontare.com
memory.251019-restock.amnotify.com
areyouhouseready.com
assuredflow.com
ataraxiausa.com
york.bal.sg
www.bexarsoftware.com
lease-tracker.budgific.com
bunt.hr
carcamarchive.com
materials.chi46.com
static.cityuge.com
club-scene.co.za
crownaddons.com
www.d0rfforge.com
www.degreensustentable.com.ar
shplist-5.dev-ltl-xpo.com
www.devicefield.com
diaroogle.com
dijonexpress.com
dm7admin.dm7sistemas.com.br
elusivecar.com
ennellgroup.com
www.evidencehunt.app
www.falcon-ride.com
paul.fariza.nl
www.fire-dragon.net
www.frogpos.app
fromapot.com
www.galaxytale.de
help.hostmeapp-qa.dev
imperialinfosys.com
indiarolls.in
www.infobot.pl
inkuire.com
joycechild.com
www.joynetiks.com
www.judithmacdonald-lawson.co.uk
app.k1driven.com
query.kanakori.fi
demo.keynate.com
link.learningmattersinc.org
app.ledsc4.com
leoz.it
leveragegroup.it
listmint.io
lokassolutions.com
whitepaper.luciaprotocol.com
luckydust.app
www.virtualexpo.matsumototd.com
maxx.coffee
mealplanpilot.com
mehu.app
dev.mjvirtualevents.com
www.monoridge.co.jp
app.mpledesma.com
fortapp.naxelgames.com
ma.net3marketing.com
neuro-gymnastics.com
nikol.ai
www.novautilitymapping.com
opatry.net
abuseisnotlovequiz.phygitalxp.com.br
www.pintraveler.app
www.planebooker.app
plentyofpostcards.com
matei.popp.rocks
www.test.predplatenaelektrina.sk
www.prizm.pw
ptitcoinsavonnerie.fr
go.quranmajeed.com
links.racetrac.com
rauhut.no
reinscom.com.mx
rmembr.app
roflbook.com
sanchezryndwedding.com
skiplaces.app
softmakeia.com
spartapps.com
sportmeclub.com
sportsvision.co.za
steelersne.ws
stephenc.art
www.sticknodes.skin
stirium.com
studiodous.com.br
thalitalucarelli.com
thoughtalogue.com
www.tiedhearts.com
x.translateth.is
auth2.tsunagaru-online.jp
turisfreelance.com
android.vidyakul.com
presidente.votei.app
willowprescott.com
test.wordplay.dev