77/100 SECURITY SCORE

Certificate Information

Subject
CN=app.oction.de
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 15, 2025
Valid Until
February 13, 2026 89 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
40:1D:54:2C:B6:71:CA:C5:8F:BC:2B:93:8E:24:4A:1F:A2:74:A3:93:D9:46:2E:FE:44:B1:C1:DA:DE:77:07:D2
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.thousandreams.it

Other domains in certificate

demo.sp.bettersure.4-sure.net
africangiant.shop
console.afrienmastermind.org
gp-demo.agbsul.com.br
bizstack.ajstacks.com
andronio.me
sfusd.backpackfordrive.app
bitsimply.com.au
bizz.place
payments.blackpugstudio.com
health.blueberryx.com
bobclerx.nl
bricksandmint.com
www.buro.lv
bytecodex.co.uk
admin.calchez.com
admin.chatterslaundry.co.nz
www.cornerfoods.ng
painel.correcaodesolo.com.br
business.dinatus.com
www.dobedosoft.com
eerielabs.app
elettricista-treviso.it
launcher.ericnahon.net
backoffice.eurogold.sk
flutterconflatam.dev
dockr.flytebit.com
www.fukuoka-important-guard.com
simulators.braille.hadleyhelps.org
admin.dev.hairtect.jp
dev.control.hark.eco
heed.icu
www.hexadan.com
print.housekinoa.me
www.humaka.ro
nguyenduckhai202400049.id.vn nkd.id.vn
jobs.immigo.io
www.joseguerrero.me
www.joshuamanning.com
saintjerome-admin.kards.fr
kblawoffice.me
qs.kumunua.kr
lantechcom.io
m-acre.ca
www.madeinwestgermany.com
store.medionclick.com
www.mobifrota.pt
www.monodance.com
demo.montessoriconnect.global
www.montrealwebstop.com
mooth.co.jp
www.myanmar2d.com
myflag.co.za
app.linkface.net.br
www.nettle.ai
www.noxahayari.com
app.oction.de
recipify.okaryo.io
qr.oloround.com
onlinehalli.com
epasti.pasdidik.com esmiti.pasdidik.com esmitihq.pasdidik.com esritihq.pasdidik.com hq.pasdidik.com school.pasdidik.com
paymentinapp.com
petmarked.com
phoeshons.com
app.pod.io
printloveart.com.br
qadprecision.com
ranking-ubezpieczen.com
rapid-prompt.de
tutorial.raxanexpress.com
buffycrucible.rossmack.com
www.sagarmistry.net
embed.sceneopsis.com
search-my-devices.com
shreyasprasad.dev
hraguaboa.bioponto.sistemasnemesis.com.br
www.softytravel.com
auth.sosaudavel.com.br
starlingburgers.fr
switchonstudio.com
teamdominion.jp
auth.thecreators.io
therainteligencia.com.br
pilates-santander-center.timp.io
brinksbdc.turbosbir.com
www.tyombo.com
dev.urlxm.com
verifier.one
www.vidrioslacosta.com
viniiride.com
www.vitaosuspensoes.com.br
www.w-putki.fi
workfromcafe.app