Open Cached · just now
77/100 SECURITY SCORE

Certificate Information

Subject
CN=umx.helight.dev
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 03, 2025
Valid Until
March 03, 2026 87 days
Public Key
RSA 2048 bit Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1B:36:16:0F:BD:AB:5E:A2:F1:DD:01:AC:A3:01:D0:74:5F:7C:D3:F9:6B:05:28:33:6C:AB:54:94:D3:44:81:13
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

100 domains
www.uneau.com

Other domains in certificate

ajmalpkc.me
foodics.anyware.software
centrodeeventos.appsiste.co
crm.binarysystem.eu
app.bitstack.fr
www.booleanstate.com
www.bubble-buy.com
byallrights.net
www.chochewees.com
frozen.clau.io
subscriptions.cloutlayer.com
www.pluginsoft.co.kr
plus.colavo.kr
app.daataar.in
www.daneplusplus.com
duermevela.shop
img.dummyapi.io
chat.etherity.org
stage-wrh-admin.exitest.com
test.portal.farmote.com
invoices.fatorak.com
api.staging.fitbykaty.com
flockletter.com
fp.link
stg.frica.info
www.gellit.net
ml.gpeasynet.co
grimaldiengineering.co.uk
bk.harmonicmarkets.com
umx.helight.dev
www.horyca.com
i2cweb.com
ianlabs.net
intellicubix.com
ithubkhammam.com
jefafa.com
beta.jointherefolution.com
ketketi.com
kevinbuhmann.dev
kibom.se
kitme.co.nz
klok.online
kul.cloud
experienciadisney.leafb.one
leaflet.so
life-work.info
www.littlefallslocal.com
loscortes.mx
admin.loxamformation.com
managekaro.org
blinq.mastrowi.cz
cms.mathu.co.za
mind-engage.mcntech.com
dev.app.mindysimagination.com
blog.motobase.jp
portal.mtrfreight.com
watch.informacion.my.id
www.mztech.us
www.neoncomet.com
niconico.llc
ommbe.com
www.onalapartmani.com
neo-dev.onderwijsonline.nl
docs.owlly.ch
paulrichter.org
www.peter-grafiek.nl
www.piren.org
lok-jagaran-abhiyan.pmprant.in
dashboard.pradco.in
www.pshields.net
www.rentalaires.com
links.integration.ridealto.app
samrothfarb.com
sayonara-monotone.info
kitchen.scenariocaffe.com
www.schneideradapters.com
app.selectfood.com.ar
www.shamanland.com
shambhugyawali.com
www.signalfa.com
sim-teach.net
www.smartlitic.com
panel-staging.spotbyspot.pl
link.stadiumliveapp.com
app.sugahara-community.com
admin.supplyspace.in
theartificialmind.co.uk
third-ray.com
sbp.tripwardrobe.com
developer.troves.gg
www.unbrandedcattle.com
weightsprint.underlama.com
uniquekaranjit.com
www.veviam.com
www.visuallabs.net
www.voraces.es
voxzogo-friends.jp
www.vrmmo.games
yashanand.dev