Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=bigfactsnocap.co
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
December 03, 2025
Valid Until
March 03, 2026
85 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
53:72:2D:27:26:F5:C9:61:FC:FD:28:E2:43:33:19:AB:EE:12:F7:36:A7:FA:95:EC:57:45:BD:76:50:69:C6:F7
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
zarnice-rona.si
1163.pontuax.com.br
voodoo.12traits.com
www.aafundrinks.com
aaronmoloney.com
www.ailabmartech.com
auinsights.algodriven.app
alphaxds.com
amigocao.pet
www.andrerobertlee.com
apiprivacy.com
www.atlantisthief.de
postofficescoin.eu-north-1.aws.aurosoftware.net
babybingo.app
admin.backbeaver.com
www.immaculate-team.baseball-connections.com
www.bayoujunkies.com
linkpre.beady.fun
bigfactsnocap.co
bluebirds.dev
calegram.app
www.calvinln.com
www.carbondashboard.ch
thebluefam.checkconnection.net
chilemat.cl
mobile.bwinners.co.zw
service.alko-garden.com.ua
commu-hub.com
dashboard.compcodes.com
go.cpl.cloud
darumapagos.com.ar
admin.deep-sea-marine.com
docsandhya.com
www.domainecappa.corsica
xkhgpn1.easyapp.co
easyfinancialcharts.com
admin.takepart.staging.egg.srl
sommelier.etoh.app
demo.fleaflet.dev
pbw2023.foodstarter.io
getmytata.app
www.curlcupid.glimmer.info
ticket.cambodiatechex.gov.kh
hajarkids.com
dev.i.hxmspace.io
hya.app
www.inkoplist.app
dashboard.dev.inkryptus.com
volodymyr-anhelina.invito.link
griddle.jevans.uk
www.karatewaremmegeer.be
knees.gg
kurianrenovations.ca
www.lamparinadesign.com.br
messenger.leftbrain.it
app.leisurekart.com
lilypads.cc
backoffice.local-elves.com
www.macankumbang.ch
www.marounabdelnour.com
metrolabs.ai
www.murikarox.com
linked.mutual.app
www.nickbellisario.com
njeri.codes
dev.nutshell-studios.com
www.onda100.com
pay.onedaybridal.com.au
demo-cms.orryworx.com
oscarzapata.dev
www.paintbox.pro
pluvial.dev
psychologonline.be
punchin.com.br
raw.pwcc.app
dev-app.reliantrecovery.co.za
reverbeat.pro
guides.rockgarden.io
www.s2ndev.com
schonwetter.ca
ads.shopsavvy.com
www.solocochelectrico.es
m.spacemonk.io
www.stakehex.today
www.talktobuddhaai.com
taocode.com
textandpictures.com
color.vixi-dev.thefamousgroup.com
www.thijsnijman.com
www.three14.llc
apps.timbra.online
edu.toshimomo.net
www.trackforest.net
trackt.ca
verification-helper.review.trustdock.io
vizzua.com.br
www.wireit.pl
fanaticape.games.woolili.com
eid.yazeed.xyz
www.zanmy.com
Other domains in certificate