76/100 SECURITY SCORE

Certificate Information

Subject
CN=portalfinance.co
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 19, 2026
Valid Until
May 20, 2026 82 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FA:50:F0:11:34:2A:BB:81:00:7D:7B:A0:11:75:07:02:88:81:52:6A:8A:0B:27:C9:EB:19:18:01:EC:C8:DD:E4
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
loanholder.com *.loanholder.com *.admin.loanholder.com *.api.loanholder.com *.app.loanholder.com *.assets.loanholder.com *.backup.loanholder.com *.dashboard.loanholder.com *.demo.loanholder.com *.dev.loanholder.com *.ftp.loanholder.com *.hostmaster.loanholder.com *.m.loanholder.com *.mail.loanholder.com *.mailer.loanholder.com *.marketing.loanholder.com *.qa.loanholder.com *.secure.loanholder.com *.sitemaps.loanholder.com *.staging.loanholder.com *.stg.loanholder.com *.test.loanholder.com *.uat.loanholder.com *.v1.loanholder.com *.v2.loanholder.com *.web.loanholder.com *.ww16.loanholder.com *.ww17.loanholder.com *.ww25.loanholder.com *.ww41.loanholder.com

Other domains in certificate

*.api.deposer.com deposer.com *.deposer.com *.dev.deposer.com *.hostmaster.deposer.com *.mail.deposer.com *.ww1.deposer.com *.ww16.deposer.com *.ww17.deposer.com *.ww25.deposer.com
*.access.portalfinance.co *.app.portalfinance.co *.gaspbqfl.portalfinance.co *.insights.portalfinance.co portalfinance.co *.portalfinance.co *.qa.portalfinance.co *.staging-aggregation.portalfinance.co *.staging-carola.portalfinance.co *.ww25.portalfinance.co *.xhtjikong-prod-blue-api.portalfinance.co
*.hostmaster.taillet.com *.parked.taillet.com *.rdp.taillet.com *.sitemaps.taillet.com *.sslvpn.taillet.com taillet.com *.taillet.com *.vpn.taillet.com *.ww1.taillet.com *.ww16.taillet.com *.ww25.taillet.com *.ww38.taillet.com *.www.taillet.com
*.8geotjcw8x.thegarrisons.com *.api.thegarrisons.com *.cpanel.thegarrisons.com *.dashboard.thegarrisons.com *.dev.thegarrisons.com *.hostmaster.thegarrisons.com *.m.thegarrisons.com *.mail.thegarrisons.com *.mailer.thegarrisons.com *.marketing.thegarrisons.com *.stat.thegarrisons.com *.stg.thegarrisons.com *.storage.thegarrisons.com thegarrisons.com *.thegarrisons.com *.v1.thegarrisons.com *.v2.thegarrisons.com *.web.thegarrisons.com *.webmail.thegarrisons.com *.whm.thegarrisons.com *.ww16.thegarrisons.com *.ww17.thegarrisons.com *.ww25.thegarrisons.com *.ww38.thegarrisons.com *.xazbsxna5e.thegarrisons.com