77/100 SECURITY SCORE

Certificate Information

Subject
CN=todos.rohanj.dev
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
October 05, 2025
Valid Until
January 03, 2026 48 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E3:6E:92:0C:E3:8B:03:7F:5B:6E:AB:3B:A5:5E:33:A9:76:4B:BB:63:0E:CE:AC:7F:F7:8A:3B:0C:FA:5A:79:0B
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.sentiententities.com

Other domains in certificate

mkt.abovemakeup.com.br
docs.intranet.airborne-support.com
ramanathapuram.anbudroptaxi.com
appy.backslashdemo.com
www.betweight.in
www.butterflyconstructions.com
www.capitaldiag.com
www.cheapshot.co
gp.construwell.com
app.copyflow.io
cpbindia.org
crystalchiang.space
m.cyb-org.com
www.disruptorrecords.com
www.dluxury.at
www.donromaniello.com
voucher.drchob.com
link.dreamchildparenting.com
qutentrepreneursurvey.eante.com.au
empruntemonstock.com
fidtech.net
authentication.floweradvisor.co.uk
www.gagansinghart.com
www.glamboxbrasil.com
www.globalitc.org
staging.gradrx.com
www.greenlandblue.com
tracker.hattieanddella.com
api.hero24.com
hidalgosebastian.com
histovery.com
app-links.hyperjar.com
www.infinitecinematics.com
link.intrior.com
invernodasortehyundai.com.br
mozaikplay-advisors-stage-5.ischoolconnect.com
www.johanneshearts.com
staging.kanoa.com.br
virtual.lanzaroteartgallery.com
apps.lazzybee.com
leonbioingenieria.online
ligalivechat.de
lojica.dev
bau.lottosocial.com
apptest.lovingloyalty.com
luriko.com
www.marketdirecto.co
memberhub.de
metadoc.dev
www.mrandmrsnuzzo.com
murrcap.com
dashboard-retail-integration.mytechnis.com
dashboard.mytrellis.com
www.neokcs.com
nutriologataniaflores.com
signal.odiho.com
www.ofirnadav.com
ohyureka.com
admin.onestopbizfiling.com
admin.onitkorea.com
broker.opesjet.com
linksotwu.oysho.com
pairentapp.com
patronus.cloud
i.piggyth.com
www.productioncliq.com
qa-fundep.prompt-pitang.com
app.quicksnap.ai
plantis.randyzhu.com
www.rasmus.productions
rdcarq.com
recoverunited.com
clientes-telemedicina2.redsalud.cl
devportal.reitcircles.com
auth.remente.com
app.ca.revolutiones.com
todos.rohanj.dev
app.sandtape.com
www.santafecap.com
screensetapp.com
www.serhatakkurt.com
sheets-enhancer.org
api.skillp.dev
beta.skullz.city
www.smart-prof.com
socialteacherstg.com
israel.solomonschariot.com
www.starcodegalaxy.com
link.swiiprx.com
www.t369token.com
staging-auth.tabnine.com
www.tech-sulting.com
ambrosiana.thetislive.com
app.thewodgenerator.com
women.thisissoon.com
admin.transitoonline.com.br
typingbro.com
black.viabilizandosuaconstrucao.com.br
www.canadaapp.wefix.co.uk