76/100 SECURITY SCORE

Certificate Information

Subject
CN=neonime.org
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 31, 2026
Valid Until
May 01, 2026 79 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
48:DA:FA:BE:B2:21:FC:2C:ED:5A:2B:58:D5:49:E2:DE:B9:BE:96:8E:32:31:B8:A8:08:60:B5:C5:6C:78:C9:B3
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
royalkosher.com *.royalkosher.com *.access.royalkosher.com *.ww38.royalkosher.com

Other domains in certificate

*.album.boypedia.xyz boypedia.xyz *.boypedia.xyz *.coffeshop.boypedia.xyz *.control.boypedia.xyz *.cpcalendars.boypedia.xyz *.dash.boypedia.xyz *.ipv6.boypedia.xyz *.node.boypedia.xyz *.panel.boypedia.xyz *.server.boypedia.xyz *.smm.boypedia.xyz *.whm.boypedia.xyz
*.30dam.celeb-trending.com *.64bvl.celeb-trending.com *.8od10.celeb-trending.com *.amndc.celeb-trending.com *.baytc.celeb-trending.com *.bcisd.celeb-trending.com *.bsoau.celeb-trending.com celeb-trending.com *.celeb-trending.com *.ddptj.celeb-trending.com *.dmwkk.celeb-trending.com *.dnrec.celeb-trending.com *.dqhrk.celeb-trending.com *.duydr.celeb-trending.com *.eaait.celeb-trending.com *.edpdr.celeb-trending.com *.ejxde.celeb-trending.com *.etsps.celeb-trending.com *.eumd2.celeb-trending.com *.exeu1.celeb-trending.com *.h5cbn.celeb-trending.com *.hcp70.celeb-trending.com *.hcpnm.celeb-trending.com *.inhau.celeb-trending.com *.jenxy.celeb-trending.com *.k8top.celeb-trending.com *.kanro.celeb-trending.com *.kjura.celeb-trending.com *.ktnbi.celeb-trending.com *.mmc21.celeb-trending.com *.moxa5.celeb-trending.com *.neoff.celeb-trending.com *.ongky.celeb-trending.com *.orkfa.celeb-trending.com *.qekxy.celeb-trending.com *.qsrul.celeb-trending.com *.rfomv.celeb-trending.com *.ribjp.celeb-trending.com *.royal.celeb-trending.com *.sbubg.celeb-trending.com *.tkmtd.celeb-trending.com *.tocpk.celeb-trending.com *.tqmaq.celeb-trending.com *.trkfr.celeb-trending.com *.udkom.celeb-trending.com *.vfsle.celeb-trending.com *.vmimk.celeb-trending.com *.voeht.celeb-trending.com *.wavoh.celeb-trending.com *.wildcard.celeb-trending.com *.xnoua.celeb-trending.com *.zfyxy.celeb-trending.com
*.client.kredytowy.com kredytowy.com *.kredytowy.com *.ssl.kredytowy.com
neonime.org *.neonime.org *.ww25.neonime.org
*.random.sikel.com sikel.com *.sikel.com
*.dravagyogyszertar.uzlet.com uzlet.com *.uzlet.com *.vacziarpad-ugyved.uzlet.com
*.ceo.weolsfargo.com *.evetest.weolsfargo.com *.staging.weolsfargo.com *.vpn.weolsfargo.com weolsfargo.com *.weolsfargo.com