An expired or mismatched certificate is the most visible security failure a website can have. Browsers replace your page with a full-screen warning, most visitors leave, and anything that calls your API — mobile apps, integrations, webhooks — simply fails. Certificates are usually renewed automatically, which is exactly why this breaks without anyone noticing: the renewal job stops working and nobody finds out until the day the certificate lapses. A warning at 30 and 15 days turns that outage into a routine ticket.
TLS 1.0 and 1.1 are retired protocol versions. Modern browsers no longer use them, so leaving them switched on gains you nothing, while it lets an older or misconfigured client connect with weaker cryptography. Security questionnaires and auditors ask about this directly, and “we still accept TLS 1.0” is an answer that creates follow-up questions.
Many sites sit behind a CDN or load balancer, and the TLS settings your visitors meet belong to that edge, not to your application. That is easy to overlook: we found TLS 1.0 and 1.1 still accepted on two of our own domains. The check reports what is actually answering for your hostname, so you know where the setting needs to change.