This report summarizes how well saintisidore.org is configured for secure web delivery. It covers HTTPS availability, HTTP→HTTPS redirects, TLS/SSL certificate validity, security headers, HTTP/2 and HTTP/3 support, and mixed content. Use it to quickly spot configuration gaps and improve your site's security and trust.
Enabled
No
F · 1.2, 1.3
3/6
The site is reachable over HTTPS.
Why it matters: HTTPS encrypts traffic and protects user data.
No redirect from HTTP to HTTPS was detected.
How to fix: Configure your server (Nginx, Apache, or host) to 301/302 redirect http:// to https://.
| Valid | No |
| Issuer | C=GB, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA |
| Expires | 2022-09-12 |
| Days until expiry | -1426 days |
Why it matters: A valid, non-expired certificate ensures encryption is trusted by browsers.
To improve your grade
Monitor this domain
We'll check SSL grade, HTTPS, redirects, and security headers automatically. Email only when something changes.
Free: 1 domain, weekly. Plans from €7/mo — daily checks, up to 50 domains, history & white-label PDF.
Requires 4 of 6 headers and Content-Security-Policy (CSP).
To improve your grade
Score: 3 of 6 headers effective. For the grade factor (5 pts), 4+ headers and Content-Security-Policy (CSP) are both required. We count a header only when its value actually provides the protection, so a header sent with a weak value counts as “sent, but weak” rather than present. Scanners that count a header as present regardless of its value will report a higher number here.
Why it matters: HSTS tells browsers to use only HTTPS for this site. Preload allows inclusion in browsers’ built-in HSTS lists.
We check Chromium’s built-in list. hstspreload.org checks eligibility for submission (HSTS header, redirect chain). Results may differ for domains that are preloaded but no longer meet current eligibility rules.
Not advertised
The server does not advertise HTTP/3 (QUIC) via the Alt-Svc header.
No HTTPS record. Browsers discover protocols via connection — an HTTPS record speeds this up. Learn more →
No CAA records. Any CA can issue certificates. Consider adding CAA to restrict issuance.
When you visit the site over HTTP, the server may send you through one or more redirects until you land on the final HTTPS URL. Shorter chains are faster and better for SEO.
Based on this scan, here are the 5 next steps that would most improve security and SEO for saintisidore.org.
saintisidore.org does not redirect plain HTTP requests to HTTPS. Visitors (and search engines) landing on the HTTP version get an insecure page, and you may be splitting SEO signals between two versions of the site. A single 301 redirect fixes both.
The certificate for saintisidore.org is expired. Browsers show a full-page warning for invalid certificates, which drives most visitors away immediately.
saintisidore.org sends 3 of 6 recommended security headers — missing: CSP, Referrer-Policy, Permissions-Policy. Most take one line of server config and protect against clickjacking, MIME sniffing and data leaks.
saintisidore.org supports HTTP/2 but does not advertise HTTP/3 (QUIC). HTTP/3 improves performance on lossy mobile networks. If you are behind Cloudflare or a modern CDN it is usually a toggle.
saintisidore.org has no CAA record, so any certificate authority can issue certificates for it. A CAA record limits issuance to the CAs you actually use — a cheap defense against mis-issuance.
Let your visitors know your SSL setup is verified. The badge always shows your current grade and links to this report. Paste the snippet into your site footer:
<a href="https://httpsornot.com/report/saintisidore.org?utm_source=badge" target="_blank" rel="noopener"> <img src="https://httpsornot.com/badge/saintisidore.org.svg" alt="SSL grade for saintisidore.org — checked by HTTPS Checker" height="20" loading="lazy" /> </a>
Domain owner? If you want this report removed or made private, contact us.