Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=unionstudio.co
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 01, 2026
Valid Until
August 30, 2026
70 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C5:55:B5:71:64:7E:04:65:B6:39:04:5C:24:23:0D:AF:A7:27:2E:6F:5B:44:F9:16:B5:6E:00:35:96:E1:02:A7
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
04465.my
*.04465.my
03995.co
*.03995.co
1198yyq301.top
*.1198yyq301.top
27ee20250227.live
*.27ee20250227.live
3pyramidsofgold.com
*.3pyramidsofgold.com
4y591b.cyou
*.4y591b.cyou
59686ag.vip
*.59686ag.vip
65810.vip
*.65810.vip
6figureformula.net
*.6figureformula.net
ara085p.top
*.ara085p.top
assuredvoyageline.live
*.assuredvoyageline.live
blockblast-online.me
*.blockblast-online.me
craftpieplatform.info
*.craftpieplatform.info
dewajitumaxwin.com
*.dewajitumaxwin.com
dewajp.hair
*.dewajp.hair
dewan69.com
*.dewan69.com
dewi1001.dev
*.dewi1001.dev
e1blue.net
*.e1blue.net
gardenportfolio.xyz
*.gardenportfolio.xyz
gzwrv.qpon
*.gzwrv.qpon
hyperstaking-echo.xyz
*.hyperstaking-echo.xyz
iiiyayi.com
*.iiiyayi.com
itrans.net
*.itrans.net
jdsjs26.lol
*.jdsjs26.lol
jhfd4056-4051ef-805465e1f.com
*.jhfd4056-4051ef-805465e1f.com
jxx8680s.cc
*.jxx8680s.cc
nyvozyy8.click
*.nyvozyy8.click
onlineclasses.io
*.onlineclasses.io
pol1on-chg8sha-bn.xyz
*.pol1on-chg8sha-bn.xyz
polawin.xyz
*.polawin.xyz
polo77ters.autos
*.polo77ters.autos
pornmovies.asia
*.pornmovies.asia
quasimark.com
*.quasimark.com
rollvault.xyz
*.rollvault.xyz
rtpbosbobetreal.com
*.rtpbosbobetreal.com
rummy-meet.com
*.rummy-meet.com
sex192.com
*.sex192.com
tryaxelliantlabs.com
*.tryaxelliantlabs.com
unionstudio.co
*.unionstudio.co
vapemr.com
*.vapemr.com
weightsmt.com
*.weightsmt.com
xn--lhrva.com
*.xn--lhrva.com
xnturniej.info
*.xnturniej.info
xtok.charity
*.xtok.charity
yoyo33way.xyz
*.yoyo33way.xyz
Other domains in certificate