76/100 SECURITY SCORE

Certificate Information

Subject
CN=xsaudio.pro
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 10, 2026
Valid Until
August 08, 2026 81 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
4B:59:C7:28:F9:62:6E:9A:8C:82:24:EF:1A:FF:B3:F2:67:B5:AD:4F:BF:08:7A:F4:37:7A:AC:C2:F7:9B:85:B3
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
fluxus.studio *.fluxus.studio *.alpha.fluxus.studio *.api-test.fluxus.studio *.chat.fluxus.studio

Other domains in certificate

7776pg.bet *.7776pg.bet *.comune.7776pg.bet
angkanet.group *.angkanet.group *.control.angkanet.group *.link.angkanet.group *.www.angkanet.group
bagyplus.xyz *.bagyplus.xyz *.cpanel.bagyplus.xyz *.cpcalendars.bagyplus.xyz *.jenkins.bagyplus.xyz *.pipeline.bagyplus.xyz
btcash.club *.btcash.club *.dev.btcash.club *.partner.btcash.club *.personal-area.btcash.club *.ww25.btcash.club
*.32.compraze.store compraze.store *.compraze.store *.ww25.compraze.store
*.comune.funy.live funy.live *.funy.live
growww.org *.growww.org
*.admin-api.indiangirl.pro *.back.indiangirl.pro indiangirl.pro *.indiangirl.pro *.omada.indiangirl.pro *.services.indiangirl.pro *.staging.indiangirl.pro *.www.indiangirl.pro
*.32.jkdecor.vip jkdecor.vip *.jkdecor.vip *.ww38.jkdecor.vip
keyprince.net *.keyprince.net *.ww38.keyprince.net
*.analytic.kingcheats.xyz *.analyze.kingcheats.xyz *.api.kingcheats.xyz *.dashs.kingcheats.xyz *.internal.kingcheats.xyz kingcheats.xyz *.kingcheats.xyz *.notexistsadmin.kingcheats.xyz *.report.kingcheats.xyz *.stats.kingcheats.xyz *.tftuhoytwuaspdisummary.kingcheats.xyz *.visual.kingcheats.xyz
*.32.openpg.vip openpg.vip *.openpg.vip *.ww25.openpg.vip
score808tv.pro *.score808tv.pro
spoon.live *.spoon.live *.ww38.spoon.live
*.cpcalendars.strodel.info *.cram.strodel.info *.dia.strodel.info *.gfap.strodel.info *.location.strodel.info *.m.strodel.info *.nathan.strodel.info *.notes.strodel.info strodel.info *.strodel.info *.widget.strodel.info *.www.strodel.info
*.32.xsaudio.pro *.www.xsaudio.pro xsaudio.pro *.xsaudio.pro
*.32.zenithapp.io *.m.zenithapp.io zenithapp.io *.zenithapp.io