Cached · just now
85/100 SECURITY SCORE

Detected Technologies

Certificate Information

Subject
CN=savvas.com
Issuer
C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV R36
Valid From
November 03, 2025
Valid Until
December 04, 2026 211 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
0F:01:A6:98:D5:81:9C:BB:9A:E7:E3:F6:C9:53:6C:72:0B:B6:28:D7:F0:00:0C:5B:67:BF:8D:B8:F6:65:DE:10
Alternative Names

Security Configuration

TLS Protocols
TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

71 domains
savvas.com apsi.savvas.com blog.savvas.com cm.savvas.com homeschool.savvas.com international.savvas.com mysavvasorders.savvas.com parents.savvas.com privateschools.savvas.com prod1.savvas.com publicassets.savvas.com review.savvas.com savvas-sc-assets.savvas.com savvas-sc-content-hub.savvas.com siop.savvas.com teachingedge.savvas.com www.savvas.com cd-stage.prod1.savvas.com cm-stage.prod1.savvas.com cm.apsi.savvas.com cm.blog.savvas.com cm.homeschool.savvas.com cm.international.savvas.com cm.parents.savvas.com cm.prod1.savvas.com cm.publicassets.savvas.com cm.review.savvas.com cm.teachingedge.savvas.com ctxproc.review.savvas.com ctxrep.review.savvas.com maops.review.savvas.com marep.review.savvas.com prc.review.savvas.com prod1.apsi.savvas.com prod1.blog.savvas.com prod1.homeschool.savvas.com prod1.international.savvas.com prod1.parents.savvas.com prod1.privateschools.savvas.com prod1.publicassets.savvas.com prod1.teachingedge.savvas.com si.prod1.savvas.com si.review.savvas.com www.cm.savvas.com www.ctxproc.savvas.com www.ctxrep.savvas.com www.maops.savvas.com www.marep.savvas.com www.prc.savvas.com www.prod1.savvas.com www.publicassets.savvas.com www.review.savvas.com www.si.savvas.com www.teachingedge.savvas.com www.xcollect.savvas.com www.xrefdata.savvas.com www.xsearch.savvas.com xcollect.review.savvas.com xrefdata.review.savvas.com xsearch.review.savvas.com cm.prod1.apsi.savvas.com cm.prod1.blog.savvas.com cm.prod1.homeschool.savvas.com cm.prod1.international.savvas.com cm.prod1.parents.savvas.com cm.prod1.privateschools.savvas.com cm.prod1.publicassets.savvas.com cm.prod1.siop.savvas.com cm.prod1.teachingedge.savvas.com www.cm.prod1.savvas.com www.cm.review.savvas.com