Open
Cached
·
just now
77/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tls.automattic.com
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
February 11, 2026
Valid Until
May 12, 2026
87 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
53:27:8B:7E:07:EF:93:48:0D:BE:B7:65:59:6F:EE:E5:9F:92:64:72:1E:9B:D3:23:2D:A3:C0:EA:17:5F:E4:FF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
50 domains
zen-k9.com
argengen.com
www.argengen.com
tls.automattic.com
coppervalleyclosings.com
www.coppervalleyclosings.com
dailyglobalstories.blog
www.dailyglobalstories.blog
blog.diami-mx.com
fatedwisdom.com
inventive9c0d8fa611.life
www.inventive9c0d8fa611.life
judesartisticimpression.blog
www.judesartisticimpression.blog
martingrose.blog
www.martingrose.blog
mrmorningsun.com
www.mrmorningsun.com
www.reviewandrecommend.com
www.roxanabyrde.com
www.sospaconsulting.com
www.spincastmedia.com
steveandemmawedding.com
www.steveandemmawedding.com
stockmarket-fire.com
www.stockmarket-fire.com
www.storyedits.com
straysheeps.jp
www.straysheeps.jp
sundrasam.com
www.sundrasam.com
sunrisewonders.com
www.sunrisewonders.com
www.t-jdistributing.com
theunmaker.com
www.theunmaker.com
thinklikeascientist.org
www.thinklikeascientist.org
www.tysonellert.com
upwardtips.com
vius.co
wmcmh.org
www.wmcmh.org
zamzamblogs.com
zauberfestival.life
www.zeidconsultant.com
zelena-art.com
www.zerodot.agency
zerodot.agency
www.zumir.jetzt
Other domains in certificate