Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=spotloan.co
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 16, 2026
Valid Until
July 15, 2026
39 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
84:52:11:70:9B:16:F5:CC:63:53:85:90:19:54:1A:A6:F6:E4:4D:29:87:24:DD:A0:46:59:C1:1A:9C:E6:A6:7E
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
florana.it
*.florana.it
*.admin.florana.it
*.app.florana.it
*.backend.florana.it
*.dash.florana.it
*.dashboards.florana.it
*.dashs.florana.it
*.demo.florana.it
*.dev.florana.it
*.prod.florana.it
*.redash.florana.it
*.staging.florana.it
*.summary.florana.it
*.superset.florana.it
268537.top
*.268537.top
*.caixa.digitalinfo.fun
digitalinfo.fun
*.digitalinfo.fun
*.fun.digitalinfo.fun
eden-enchanted.com
*.eden-enchanted.com
*.api.flatirron.com
*.assets.flatirron.com
*.cloud.flatirron.com
*.demo.flatirron.com
*.dev.flatirron.com
flatirron.com
*.flatirron.com
*.rds.flatirron.com
*.rdweb.flatirron.com
*.remote.flatirron.com
*.shop.flatirron.com
*.test.flatirron.com
homero.me
*.homero.me
ipiuamati.com
*.ipiuamati.com
jccmdi226.asia
*.jccmdi226.asia
*.sitemap.jccmdi226.asia
*.bbs.kuvaz.com
kuvaz.com
*.kuvaz.com
*.ww38.kuvaz.com
*.55750a89-f75c-4352-a7ea-4d881fb0ee15.skypey.quest
*.admin.skypey.quest
*.app.skypey.quest
*.assets.skypey.quest
*.c224e305-f132-43ce-b590-5cd1c1e19084.skypey.quest
*.demo.skypey.quest
*.dev.skypey.quest
*.finance.skypey.quest
*.hostmaster.skypey.quest
*.rustore.skypey.quest
skypey.quest
*.skypey.quest
*.test.skypey.quest
*.7a6b7aa0-a0e4-4988-aad2-70a9313e75c8.spotloan.co
*.8a716461-9508-44d7-a430-231f5d4136dc.spotloan.co
*.a115244c-61fb-47ff-b9ef-d905a3504646.spotloan.co
*.apply.spotloan.co
*.autodiscover.spotloan.co
*.backup.spotloan.co
*.beta.spotloan.co
*.blog.spotloan.co
*.crm.spotloan.co
*.demo.spotloan.co
*.e193e2cc-9f99-4c5d-9c86-d216badfc97e.spotloan.co
*.emv1.spotloan.co
*.forum.spotloan.co
*.forums.spotloan.co
*.help.spotloan.co
*.m.spotloan.co
*.mail.spotloan.co
*.new.spotloan.co
*.old.spotloan.co
*.payment.spotloan.co
*.remote.spotloan.co
*.shop.spotloan.co
spotloan.co
*.spotloan.co
*.store.spotloan.co
*.temp.spotloan.co
*.test.spotloan.co
*.wiki.spotloan.co
*.wmihxjlp.spotloan.co
*.www.spotloan.co
Other domains in certificate