Open
Cached
·
just now
91/100
SECURITY SCORE
Certificate Information
Subject
CN=imperva.com
Issuer
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2025 Q4
Valid From
January 09, 2026
Valid Until
July 08, 2026
170 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
92:AA:D3:66:B2:56:BD:08:49:B9:F5:77:7F:9A:25:72:59:F4:3D:6E:60:D9:B4:A6:C2:76:10:FD:65:FA:E4:37
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000; includeSubdomains; preload
Content-Security-Policy
Basic
default-src; script-src; style-src; +10 more
default-src 'self' https://cdn.jsdelivr.net https://*.console.glassboxsaas.com https://*.report.gbss.io; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.appsflyer.com https://maps.googleapis.com https://places.googleapis.com https://cdn.segment.com https://ze.delivery https://repo.incognia.com https://*.google.com https://*.gstatic.com https://*.google.com.br https://*.google-analytics.com https://*.googletagmanager.com https://optanon.blob.core.windows.net https://connect.facebook.net https://code.jquery.com https://cdn.cookielaw.org https://analytics.tiktok.com https://*.hotjar.com https://*.tailtarget.com https://pixel.mathtag.com https://web-sdk-cdn.singular.net https://*.clearsale.com.br https://cdn.jsdelivr.net https://www.googleadservices.com https://*.clarity.ms https://*.ze.delivery https://www.google.com/ads/ga-audiences https://cdn.gbqofs.com https://*.console.glassboxsaas.com https://lantern.roeyecdn.com https://www.dwin1.com https://*.report.gbss.io https://*.awin1.com https://the.sciencebehindecommerce.com https://*.split.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://optanon.blob.core.windows.net https://www.googletagmanager.com https://cdn.cookielaw.org https://*.onetrust.com; img-src 'self' blob: data: https://*.bing.com courier-images-web.imgix.net courier-images-frontrelease.imgix.net courier-images-prod.imgix.net https://*.google-analytics.com https://*.googleapis.com https://ads.scorecardresearch.com https://eb2.3lift.com https://t.mookie1.com https://analytics.twitter.com https://us-u.openx.net https://id5-sync.com https://match.sharethrough.com https://analytics.twitter.com https://image2.pubmatic.com https://x.bidswitch.net https://odr.mookie1.com https://loadus.exelator.com https://contextual.media.net https://maps.googleapis.com https://places.googleapis.com https://www.facebook.com https://*.clearsale.com.br https://www.google.com https://www.google.com.br https://*.tailtarget.com https://*.singular.net https://*.hotjar.com https://*.incognia.com https://*.typeform.com https://*.doubleclick.net https://*.tiktok.com https://*.onetrust.com https://*.gstatic.com https://*.mathtag.com https://*.googleadservices.com https://*.facebook.net https://*.amazoncognito.com https://*.google.com https://*.ze.delivery https://img.saveur-biere.com https://content.hotjar.io https://translate.google.com https://adservice.google.com https://tags.w55c.net https://tags.bluekai.com https://dsum-sec.casalemedia.com https://idsync.rlcdn.com https://*.stickyadstv.com https://*.akgn.com https://www.googletagmanager.com https://ups.analytics.yahoo.com https://pixel.rubiconproject.com https://aa.agkn.com https://ce.lijit.com https://c.clarity.ms https://*.awin1.com https://www.awin1.com https://*.tapad.com; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self' https://www.facebook.com; frame-ancestors 'self' https://www.typeform.com; frame-src 'self' https://form.typeform.com https://*.doubleclick.net https://www.typeform.com https://*.google.com https://www.facebook.com https://www.googletagmanager.com https://zecompensa.ze.delivery https://*.awin1.com https://www.awin1.com https://zecompensa.ze.delivery; upgrade-insecure-requests ; connect-src 'self' https://api.pagar.me https://*.onelink.me https://*.google-analytics.com https://www.facebook.com https://*.google.com https://maps.googleapis.com https://places.googleapis.com https://*.clarity.ms https://*.split.io https://auth.split.io https://api.split.io https://*.ze.delivery https://api.club.zedelivery.in https://*.incognia.com https://*.icg-in.com wss://*.icg-in.com wss://*.incognia.com wss://ws.hotjar.com https://cdn.segment.com https://api.segment.io https://*.segment.com https://*.segment.io https://cdn.cookielaw.org https://*.onetrust.com https://analytics.google.com https://*.hotjar.com https://*.hotjar.io https://cognito-idp.us-west-2.amazonaws.com https://cdn.jsdelivr.net https://*.clearsale.com.br https://*.dynamsoft.com https://*.zedelivery.in https://*.gbqofs.io https://sdk-api-v1.singular.net https://*.gstatic.com https://ze-auth-service-consumer-prod.auth.us-west-2.amazoncognito.com https://ze-auth-service-consumer-frontrelease.auth.us-west-2.amazoncognito.com https://www.google.com/ads/ga-audiences https://*.console.glassboxsaas.com https://*.report.gbss.io https://*.googleadservices.com https://www.google.com.br https://www.dwin1.com https://www.awin1.com https://*.doubleclick.net https://*.appsflyer.com https://*.imgix.net https://*.googleapis.com https://*.tiktok.com;
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
ch-ua-model=("https://sdk-api-v1.singular.net"), ch-ua-platform-version=("https://sdk-api-v1.singular.net"), ch-ua-full-version-list=("https://sdk-api-v1.singular.net"), attribution-reporting=(), browsing-topics=(), otp-credentials=(), accelerometer=(self "https://zecompensa.ze.delivery"),attribution-reporting=(self "https://zecompensa.ze.delivery"),autoplay=(self "https://zecompensa.ze.delivery"),bluetooth=(self "https://zecompensa.ze.delivery"),browsing-topics=(self "https://zecompensa.ze.delivery"),camera=(self "https://zecompensa.ze.delivery"),compute-pressure=(self "https://zecompensa.ze.delivery"),display-capture=(self "https://zecompensa.ze.delivery"),encrypted-media=(self "https://zecompensa.ze.delivery"),fullscreen=(self "https://zecompensa.ze.delivery"),gamepad=(self "https://zecompensa.ze.delivery"),geolocation=(self "https://zecompensa.ze.delivery"),gyroscope=(self "https://zecompensa.ze.delivery"),hid=(self "https://zecompensa.ze.delivery"),identity-credentials-get=(self "https://zecompensa.ze.delivery"),idle-detection=(self "https://zecompensa.ze.delivery"),local-fonts=(self "https://zecompensa.ze.delivery"),magnetometer=(self "https://zecompensa.ze.delivery"),microphone=(self "https://zecompensa.ze.delivery"),midi=(self "https://zecompensa.ze.delivery"),otp-credentials=(self "https://zecompensa.ze.delivery"),payment=(self "https://zecompensa.ze.delivery"),picture-in-picture=(self "https://zecompensa.ze.delivery"),publickey-credentials-create=(self "https://zecompensa.ze.delivery"),publickey-credentials-get=(self "https://zecompensa.ze.delivery"),screen-wake-lock=(self "https://zecompensa.ze.delivery"),serial=(self "https://zecompensa.ze.delivery"),storage-access=(self "https://zecompensa.ze.delivery"),usb=(self "https://zecompensa.ze.delivery"),web-share=(self "https://zecompensa.ze.delivery"),window-management=(self "https://zecompensa.ze.delivery"),xr-spatial-tracking=(self "https://zecompensa.ze.delivery")
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
135 domains
ze.delivery
*.ze.delivery
ab-inbev-switzerland.ch
*.ab-inbev-switzerland.ch
ab-inbev.at
*.ab-inbev.at
*.ab-inbev.com
bookmydesk.ab-inbev.com
*.brewdat.ab-inbev.com
*.dev.ab-inbev.com
*.global-le.ab-inbev.com
*.opr.ab-inbev.com
*.rewards.ab-inbev.com
*.ab-inbev.de
abi.tools
*.abi.tools
abrecycling.com
*.abrecycling.com
abtaproom.com
*.abtaproom.com
ambevon.com.br
*.ambevon.com.br
ambevtech.com.br
*.ambevtech.com.br
*.huehub.anheuser-busch.com
*.abwp.beertech.com
*.beertech.com
*.otel.naz.beertech.com
*.survey-assets.beertech.com
*.survey.beertech.com
*.bees-internal.com
*.bees-platform.com
*.sit.bees-platform.dev
besucherzentrum.online
*.besucherzentrum.online
birradelborgo.it
*.birradelborgo.it
bosteelsbrewery.com
*.bosteelsbrewery.com
budnet.com
*.budnet.com
budweiser.com.mx
*.budweiser.com.mx
*.budweiser.ie
*.budweiser.kr
cerveceria-nacional.com
*.cerveceria-nacional.com
cervezabalboa.pa
*.cervezabalboa.pa
cervezacorona.pa
*.cervezacorona.pa
*.chrexpert.fr
cass.co.kr
*.cass.co.kr
*.hanmac.ob.co.kr
*.hoegaarden.co.kr
michelobultra.co.kr
*.michelobultra.co.kr
*.ob.co.kr
*.stellaartois.co.kr
tadadelivery.com.bo
*.tadadelivery.com.bo
tadadelivery.com.do
*.tadadelivery.com.do
cervezacorona.com.ec
*.cervezacorona.com.ec
clubtada.com.ec
*.clubtada.com.ec
tadadelivery.com.ec
*.tadadelivery.com.ec
tadadelivery.com.pa
*.tadadelivery.com.pa
michelobultra.com.py
*.michelobultra.com.py
*.corona-extra.it
coronaextra.ie
*.coronaextra.ie
coronaextra.nl
*.coronaextra.nl
coronahn.com
*.coronahn.com
coronasv.com
*.coronasv.com
culturaavl.com
www.culturaavl.com
cutwater.ca
*.cutwater.ca
eklos.com.ar
*.eklos.com.ar
ezyenergy.eu
*.ezyenergy.eu
horecasupport.be
*.horecasupport.be
*.horecasupport.nl
imperva.com
labattmeilleursensemble.ca
www.labattmeilleursensemble.ca
michelobultragt.com
*.michelobultragt.com
*.fintech.mybees-platform.com
*.dtc.uat.mybees-platform.dev
*.eu.uat.restricted.mybees-platform.dev
*.fintech.dev.mybees-platform.dev
*.gds1.uat.mybees-platform.dev
*.martech.uat.mybees-platform.dev
*.mybees.co.za
*.us.mybees.com
*.mybees.com.co
mybenefitschoices.com
*.mybenefitschoices.com
olandbrewery.ca
www.olandbrewery.ca
pepsimusictour.com.ar
*.pepsimusictour.com.ar
powerupnaz.com
*.powerupnaz.com
qrcode.beer
*.qrcode.beer
sitebees.games
*.sitebees.games
spo-online.be
www.spo-online.be
spo-online.de
www.spo-online.de
spo-online.es
www.spo-online.es
spo-online.it
www.spo-online.it
rimborso.tennentssuper.it
*.rimborso.tennentssuper.it
tueventobees.com
*.tueventobees.com
winwithbud.ie
*.winwithbud.ie
*.club.dev.zedelivery.in
Other domains in certificate