76/100 SECURITY SCORE

Certificate Information

Subject
CN=ilturista.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 11, 2026
Valid Until
August 09, 2026 68 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
87:6A:7C:B4:83:2B:3A:6C:5A:E0:0D:ED:3D:55:8D:C3:88:27:4D:A2:3D:F9:7B:E5:3C:A3:00:B8:D7:21:55:35
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

87 domains
planscell.com *.planscell.com *.77166426-3fd0-439a-a5cc-b01810a6ff7b.planscell.com *.admin.planscell.com *.api.planscell.com *.app.planscell.com *.codedeploy.planscell.com *.dashboard.planscell.com *.dbzkeofx.planscell.com *.demo.planscell.com *.dev.planscell.com *.hostmaster.planscell.com *.ic5klq.planscell.com *.kxisclssnbapi.planscell.com *.mailer.planscell.com *.v2.planscell.com *.web.planscell.com *.www.planscell.com

Other domains in certificate

1148yhj301.top *.1148yhj301.top *.7c1a0a83a6.1148yhj301.top *.a2bf9f944d.1148yhj301.top
backbaywellness.com *.backbaywellness.com *.dev.backbaywellness.com
backyard.cfd *.backyard.cfd
badyk.club *.badyk.club
callingallcharities.com *.callingallcharities.com *.sitemap.callingallcharities.com
*.bot.dir.bz *.cpanel.dir.bz dir.bz *.dir.bz
*.cpanel.dungeondefense.online *.cpcontacts.dungeondefense.online dungeondefense.online *.dungeondefense.online
ilturista.it *.ilturista.it *.www.ilturista.it
independentmusic.it *.independentmusic.it
loganthan.site *.loganthan.site
lojavinhosvalduga.site *.lojavinhosvalduga.site
*.first.love.mom *.i.love.mom *.loads.love.mom love.mom *.love.mom *.my.love.mom
molly.cfd *.molly.cfd
momentum.cfd *.momentum.cfd
myoptiumserve.com *.myoptiumserve.com
paintvisionary.digital *.paintvisionary.digital
*.cpcalendars.pluck.info pluck.info *.pluck.info
*.atsscwww.putlockers2.site putlockers2.site *.putlockers2.site
rationalthinkingnetwork.sbs *.rationalthinkingnetwork.sbs
satta-super-fast.com *.satta-super-fast.com
supertruckscards.net *.supertruckscards.net
sweetbeorganics.com *.sweetbeorganics.com
towerfreeze.com *.towerfreeze.com
*.bolcanie.vote4amare.com vote4amare.com *.vote4amare.com
wedding-dresses-business.site *.wedding-dresses-business.site
*.demo.xdesignui.online xdesignui.online *.xdesignui.online