HTTPS Readiness test

Input

Check here if your site complies with the HTTPS best practices

Domain analysis: quebechot.com

  • No redirect to https - Best practice is to use HTTPS always/everywhere
  • IP addresses: 188.114.97.3, 188.114.96.3
  • Certificate details

  • This SSL Certificate was created for sni.cloudflaressl.com but is also valid for quebechot.com
  • Certificate issued by Cloudflare, Inc., of type Cloudflare Inc ECC CA-3
  • Certificate start date: Jul 17 00:00:00 2021 GMT
  • Certificate expiration: Jul 16 23:59:59 2022 GMT (in 60 days)
  • Certificate validity period: 1 year(s) => commercial (paid) certificate
  • Encryption algorithm: TLSv1.3 / TLS_AES_256_GCM_SHA384
  • More certificate details?
  • SSL Labs: get more detailed HTTPS report
  • Mozilla Observatory: get more detailed HTTPS report
  • HTTPS Headers

  • Missing HTTP header x-xss-protection - should be 1; mode=block
  • Missing HTTP header x-frame-options - should be SAMEORIGIN
  • Missing HTTP header content-security-policy - create at least a minimal one
  • Missing HTTP header strict-transport-security (HSTS)
  • For a GDPR-focused review of your domain, use Churlie GDPR Checkup
  • Content details

  • Mixed content: this page uses insecure content from ad2globe.com, www.quebechot.com, www.annoncexxx.com, www.appartqc.ca, www.maximumxxx.ca, www.info.golf, www.fantasmexxx.ca, www.sitedrole.com, www.plaisiradeux.ca, www.libidoduquebec.com, www.modelesduquebec.com, www.maison-chalet-online.com, www.maladiesmentales.org, quebecbabes.xxxlog.co, www.billets-canadiens.com, www.maison-condo-a-vendre.com, www.motels-montreal.com, www.motels-quebec.com, www.celibataire-rencontre.net, www.toutalouer.ca, www.pegasproductions.com, www.lesentreprisescdc.com, www.sondageremunere.com, lameilleureprime.ca, ottawagatineau.wordpress.com, francois101.blogspot.com
  • How to get https for your site

  • Let’s Encrypt is a free, automated, and open Certificate Authority.
    Example: cloudfleet.io, scotthelme.co.uk
  • Cloudflare One-Click SSL (also on the Free Plan)
    Example: toolstud.io
  • Paid certificates: Verisign, GeoTrust, Comodo, DigiCert, Thawte, Globalsign
    Example: www.amazon.com, www.mozilla.org, twitter.com
  • References