this is comical.
so a software security vendor needs to rely on people to tell them to follow modern encryption security practices?
They not alone in this problem.
e.g. software like avast and eset which have https scanning modules, will disable technologies such as OCSP and key pinning. Some version also have no tls 1.1/1.2 support.