76/100 SECURITY SCORE

Certificate Information

Subject
CN=kidscandance.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 19, 2026
Valid Until
June 17, 2026 35 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3A:0F:FC:87:86:63:74:44:D5:9D:5F:7C:4C:5C:1C:70:2C:D4:55:48:FC:3A:E5:BE:F5:8B:B3:83:D5:4D:69:1D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
amaeicanexpress.com *.amaeicanexpress.com *.admin.amaeicanexpress.com *.ca.amaeicanexpress.com *.eng.amaeicanexpress.com *.ww25.amaeicanexpress.com *.ww38.amaeicanexpress.com

Other domains in certificate

afrec.org *.afrec.org *.au.afrec.org
artbrush.it *.artbrush.it *.webmail.artbrush.it
berlinficktalles.de *.berlinficktalles.de
*.api.cbgsdgsd.cc cbgsdgsd.cc *.cbgsdgsd.cc *.d3z8x.cbgsdgsd.cc
chasenank.com *.chasenank.com
chihulygardenglass.com *.chihulygardenglass.com
*.cicd.dallorgeneral.com dallorgeneral.com *.dallorgeneral.com
erwinmeller.de *.erwinmeller.de
ferienhaus-daenemark-hvide-sande.de *.ferienhaus-daenemark-hvide-sande.de
*.com.freemail.com.au freemail.com.au *.freemail.com.au *.nospam.freemail.com.au
gameloft.au *.gameloft.au *.neworleans.gameloft.au *.ww38.gameloft.au
grammaerly.com *.grammaerly.com
intexcorps.com *.intexcorps.com *.ww25.intexcorps.com
*.glance.inutuit.com *.gopayment.inutuit.com inutuit.com *.inutuit.com *.quickbooks.inutuit.com *.tsheets.inutuit.com *.ww38.inutuit.com
jtqb.com *.jtqb.com *.ww25.jtqb.com
*.classifieds.kidscandance.com kidscandance.com *.kidscandance.com
*.email.mediasmartec.com mediasmartec.com *.mediasmartec.com *.random.mediasmartec.com
multilinks.it *.multilinks.it
osdeconnect.com *.osdeconnect.com *.random.osdeconnect.com *.ww25.osdeconnect.com
roomdivider.com.au *.roomdivider.com.au *.ww25.roomdivider.com.au
*.random.scorpionmotorsport.com.au scorpionmotorsport.com.au *.scorpionmotorsport.com.au
techdirect.net.au *.techdirect.net.au
thestreameast.ps *.thestreameast.ps *.ww25.thestreameast.ps *.ww38.thestreameast.ps
*.activate.tjreward.com tjreward.com *.tjreward.com *.ww25.tjreward.com
treansfermarkt.de *.treansfermarkt.de
webstraunstore.com *.webstraunstore.com *.ww38.webstraunstore.com
*.ww25.wwwvast.com wwwvast.com *.wwwvast.com