SSL Verification Bypassed

The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.

Reason:

Expired Certificate - the server's certificate has expired

62/100 SECURITY SCORE

Certificate Information

Subject
CN=newswell.co
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
May 15, 2025
Valid Until
August 13, 2025 Expired
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
91:4A:D7:12:C8:DD:BA:8B:C2:72:41:52:EF:01:B8:44:76:C4:EB:FA:D3:46:EC:5A:05:FE:3D:CD:25:BC:58:AE
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.staging.dashboard.perigigi.com

Other domains in certificate

ioslink.25h.app
thats-vapore-corporate.5loyalty.com
a.488777.xyz
dash.adamhawa.app
agrogps.tech
ahatovaraida-biologiya.com
ai-official.live
anael-magicien.com
blog.andybrown.dev
appzotech.in
www.arturba.pl
consumer.atoa.me
avanpore.com
bbtools.bbapps.it
bigartwall.com
www.biodiversidadyculturaambiental.org
download.breathonics.com
cabaprojects.com
it.caldera.is
www.capp.solutions
plan.cascade.app
dev.checkestate.app
chrisgio.dev
www.cifunsa.com
link.coltondogportraits.com
limmogo.standy.com.tr
www.connectingthedots.ca
doc-internal.dalek.rs
tomorrowtec-staging.devmagic.com.br
www.dozingcatsoftware.com
advent-of-guyguy.ealionel.me
egybto.com
www.eidson.com.br
dev.eventor.app
www.exalt.ps
app.fanchat.jp dev-app.fanchat.jp
firesite.io
2players.games235.com
garigliano.com
geonsi.com
giuliadirocca.com
www.globalonetrading.in
globetecher.de
haustic.com
huidental.com
icon.inohom.link
www.jarsty.com
www.jessicashao.com
kaamka.com
kampar-refill.com
www.knowbaguio.com
koalition.se
www.kroatie.pro
legalsystembr.com
leija.se
letsscoutabout.com
local718petanque.com
www.loyalbook.net
www.luichigo15.app
www.mdigman.com
pdca.miidas.com.br
misracharityfoundation.org
www.mithibaicultural.in
muja.dev
dl.muuv.fit
admin.myeximbusiness.com
www.mykitchenkart.com
mytaible.com
newswell.co
auth.omara.es
ostelios.com
kaaassambly-app.oz-tms.com kaaassambly.oz-tms.com
download2.paradisefoods.com
www.dev.api.payos.app
www.phillyup.online
projspot.com
ihlas.qfix.ai
dev.ctvm.qitech.app
rabik.dev
resinates.art
www.restonpeace.org
b.xi.run.place
www.salesdelight.ai
slopebear.com
smartnook.cl
demo-pay.tesel.tech
tukkafy.com
www.ufacasino-24.com
unspoylt.com
solar-calculator.valleysunsolarco.com
venevakuutus.com
stage-backoffice.vipscasino.com
vkxtutors.com
wamaformining.com
warroomelite.com
zeneffi.co.jp
jovicbiralo.ziontechug.com