Open
Cached
·
just now
77/100
SECURITY SCORE
Certificate Information
Subject
CN=www.nourishthesaints.com
Issuer
C=US, O=Google Trust Services, CN=WR3
Valid From
November 20, 2025
Valid Until
February 18, 2026
86 days
Public Key
RSA
2048 bit
Adequate
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
65:D4:5E:76:50:06:AF:E7:75:A7:D9:5B:DE:3B:41:33:25:E3:53:65:2D:0B:CB:70:41:89:D5:F3:9C:5E:51:EF
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31556926
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
100 domains
zonactivakids.com
www.ai-shala.com
hicharging.aihitech.com
dashanan.aimcomely.com
www.andynserveri.fi
animate.me
www.dash.anovanet.com
crm.ansaricapital.com
prospeccion.aprovimed.com
www.better-soft.de
link.bfirstauto.vip
customer.staging.bharatsey.com
widget-stage.billmybank.com
demo.mouse.bizoo.cloud
app.bmsclothingbrand.com
breefer.io
caarya.me
www.care724.com
warehouse.catkodagu.com
staging.ceq.de
clip-maker.chino.cafe
www.choquel-marketing.com
my.cloudhealth.co.za
www.codetool.dev
www.councilofandrews.com
portfolio.danielherzog.es
dataelevate.ai
app.disctopia.com
objetivos.eduka.tech
www.elytrarobotics.com
snapfinance.f2bportfolio.com
fasttrackcanadaservices.ca
app.fteyewear.in
lahan.transmigrasi.go.id
login-staging.goodhuman.me
hagchat.ca
studio.hass.ai
nazuna-kyoto-tsubaki-st.b.hotekan.com
wise.jordan.ieee.org
app.imve.pt
imve.pt
app.incision.care
www.tiacheck.innrsys.com
minside.iris-salten.no
www.jalaw.fi
kobilev.ru
www.kri-and.fi
santeacrm.lexcellence-grp.com
greenlight.loopthrough.ch
ev.lsceco.cloud
masnibennett.com
mastri-barbieri.it
integrations.metsights.com
moonapp.me
www.nourishthesaints.com
apptool-test.nucor.report
www.nydeckyrevival.cz
mfa.ooca.dev
www.ossamenta.com
owenjamesvincent.co.uk
ozzydt.com.au
admin.patchpocketapp.com
pcmcrunners.in
www.plug.io
powerview.lat
primascuola.app
www.radiantfzco.com
www.rameal-nabeeh.com
readb.co
redpath.dev
www.staging.requestiq.com
www.reshailawan.com
rocox.co
auth.roothq.africa
ryeol.io
www.shootzup.com
app.showandco.it
www.siriusconsulting.com
soohwanjiyeon0906.world
sphoorti.com
fleepsolar.srv.br
demo2.ssipl.lk
st-art.me
residencia.studus.com.br
www.synecode.com
www.taxitribe.com
technomore.ae
www.tosup.kr
chronicle.trexlin.net
booking.tutorlynow.eu
veertig.dev
www.visgis.com
wankyo.jp
www.waxngo.be
www.wherearemydigs.at
portal.wurlio.com
yayayoga.ca
yildirim.me
www.zhuodonghuang.com
www.zsebtanar.hu
Other domains in certificate