SSL Security Test of
srf-sport-app.firebaseio.com

Test the SSL/TLS stack of your web or email server for security, cryptographic flaws and misconfigurations, and compliance with NIST & HIPAA
Free online tool with PDF report
  • Web Server SSL/TLS Security
  • Post-Quantum Cryptography (PQC) Readiness
  • Email Server SSL/TLS Security
  • PCI DSS, GDPR, HIPAA & NIST Compliance
  • SSL Certificate Validity
  • Best-Practices Compliance
Free online tool with PDF report
186,709,771 tests performed
Provided "as is" without any warranty of any kind
159
tests
running
135,899
tests
in 24 hours
Tests in 24 Hours
Share this report:

Summary of srf-sport-app.firebaseio.com:443 (HTTPS) SSL Security Test

Provided "as is" without any warranty of any kind.
This test was made 176 days ago and may be outdated
Refresh Test
Date/Time:Mar 28th, 2026 07:49 GMT+0
Source IP/Port:35.190.39.113:443
Protocol:HTTPS
Location:Mount Hope, United StatesUnited States
Your final score:
  • A
  • B
  • C
  • F
A-
The server has TLS 1.0 enabled. It is non-compliant with NIST since SP 800-52 REV. 2 and non-compliant with PCI DSS since the 30th of June 2018.
Non-compliant with PCI DSS and NIST
The server has TLS 1.1 enabled. It is non-compliant with NIST since SP 800-52 REV. 2 and non-compliant with PCI DSS since the 31st of March 2025.
Non-compliant with PCI DSS and NIST
The server supports the most recent and secure TLS protocol version of TLS 1.3.
Good configuration

Test Results Summary for srf-sport-app.firebaseio.com

  • Post-Quantum Cryptography (PQC) Readiness Test
    The server on the tested port is currently not prepared for post-quantum key exchange. The server’s certificate chain relies entirely on classical signature algorithms without post-quantum support. Show details.
  • SSL/TLS Certificate Analysis
    1 SSL/TLS end-entity certificate detected: the first certificate is a trusted RSA 2048 bits certificate with issuer WR1 valid until June 6, 2026. 1 certificate chain detected. Show details.
  • PCI DSS Compliance Test
    5 of 11 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with PCI DSS: P-256, P-384 and X25519. There is 1 more issue which makes the server non-compliant with PCI DSS: potential Marvin Attack. Show details.
  • NIST and HIPAA Compliance Test
    6 of 11 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with HIPAA: P-256, P-384 and X25519. There is 1 more issue which makes the server non-compliant with HIPAA: server does not support OCSP stapling. Show details.
  • Industry Best Practices Test
    No issues related to industry best practices were identified. Show details.

Compliance Summary for srf-sport-app.firebaseio.com

  • PCI DSS Compliance Failed: 5 of 11 supported cipher suites are not compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with PCI DSS: P-256, P-384 and X25519. There is 1 more issue which makes the server non-compliant with PCI DSS: potential Marvin Attack.
  • HIPAA Compliance Failed: 6 of 11 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with HIPAA: P-256, P-384 and X25519. There is 1 more issue which makes the server non-compliant with HIPAA: server does not support OCSP stapling.
  • GDPR Compliance Failed: 5 of 11 supported cipher suites are not compliant with GDPR. The server supports GDPR compliant protocols (TLSv1.2 and TLSv1.3) as well as non-compliant protocols (TLSv1.0 and TLSv1.1). All supported elliptic curves are compliant with GDPR: P-256, P-384 and X25519. There is 1 more issue which makes the server non-compliant with GDPR: potential Marvin Attack.

PDF Certificate and Badge

Please wait. Data is loading...
Share this report: