76/100 SECURITY SCORE

Certificate Information

Subject
CN=booksarena.tech
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 19, 2025
Valid Until
March 19, 2026 32 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
19:AE:35:B2:9D:37:86:49:98:4F:4A:FC:E3:45:42:09:C5:D4:B6:48:D6:CA:34:34:49:EC:E5:8B:8E:6F:AE:E6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
samsoju.org *.samsoju.org *.agent.samsoju.org *.azurefd.samsoju.org *.preview.samsoju.org *.test.samsoju.org

Other domains in certificate

booksarena.tech *.booksarena.tech *.ww25.booksarena.tech
cascina.com *.cascina.com *.coaching.cascina.com *.email.cascina.com *.mobile.cascina.com *.movie.cascina.com *.mx.cascina.com *.openvpn.cascina.com *.users.cascina.com *.ww16.cascina.com *.ww17.cascina.com *.ww25.cascina.com *.ww38.cascina.com
ceklomazovia.pl *.ceklomazovia.pl *.ww25.ceklomazovia.pl
*.bike.faithway.info *.car.faithway.info *.credit.faithway.info faithway.info *.faithway.info *.game.faithway.info *.software.faithway.info
largeboobspictures.com *.largeboobspictures.com
morgenmantel.de *.morgenmantel.de
*.dev.mypepsico.co *.etoolspmf.mypepsico.co *.ite.mypepsico.co mypepsico.co *.mypepsico.co *.pfnaweb.mypepsico.co *.preprod.mypepsico.co *.ps.mypepsico.co *.qa.mypepsico.co *.random.mypepsico.co *.smiles.mypepsico.co *.web.mypepsico.co *.ww38.mypepsico.co
*.birth.panfind.info *.com.panfind.info panfind.info *.panfind.info *.pg.panfind.info *.print.panfind.info
*.cem.qamar.in qamar.in *.qamar.in
*.beta.ripaimcsgo.xyz *.demo.ripaimcsgo.xyz *.g5v.ripaimcsgo.xyz *.rank.ripaimcsgo.xyz ripaimcsgo.xyz *.ripaimcsgo.xyz *.test.ripaimcsgo.xyz *.thdtx-cfs.ripaimcsgo.xyz *.vip.ripaimcsgo.xyz
rjwebdesign.com.au *.rjwebdesign.com.au
rohhitsharrmaaitodaynews.xyz *.rohhitsharrmaaitodaynews.xyz
streamed.si *.streamed.si
*.c.te.net.au *.ipywpidx.te.net.au te.net.au *.te.net.au
*.random.turnitinggpt.com turnitinggpt.com *.turnitinggpt.com *.ww16.turnitinggpt.com *.ww25.turnitinggpt.com *.ww38.turnitinggpt.com *.www2.turnitinggpt.com
*.api.wwwpurina.com *.ww25.wwwpurina.com wwwpurina.com *.wwwpurina.com