Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=cannastars.org
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 18, 2026
Valid Until
August 16, 2026 83 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EF:BE:53:B0:98:8E:CD:D1:D1:FC:9C:78:FC:F4:4B:86:DF:46:C1:0D:40:35:B5:98:16:42:EA:B8:19:3B:38:F6
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
alterbus.com *.alterbus.com *.wlamazcsrv1.alterbus.com *.ww16.alterbus.com *.ww25.alterbus.com

Other domains in certificate

27305357.vip *.27305357.vip
amsterdamfinedining.com *.amsterdamfinedining.com *.cz3duw.amsterdamfinedining.com *.hostmaster.amsterdamfinedining.com
arbitrix-new.com *.arbitrix-new.com *.dev.arbitrix-new.com *.vpn.arbitrix-new.com
balancerobotic.com *.balancerobotic.com *.gitlab.balancerobotic.com *.new.balancerobotic.com *.vpn.balancerobotic.com
ballon.blog *.ballon.blog *.tyqhjassets.ballon.blog
*.app.betssports.net betssports.net *.betssports.net *.cpanel.betssports.net
*.187f18c3-2971-4069-98e3-a6dae5c51040.bymayvenstudios.com *.6b92ab1c-225f-42ed-9bb5-c176526ef0cc.bymayvenstudios.com *.723d7716-c250-42f9-9c4e-b4f1b8f7c373.bymayvenstudios.com *.9daa3fae-a881-4d82-b59b-8513afa5ac12.bymayvenstudios.com *.app.bymayvenstudios.com bymayvenstudios.com *.bymayvenstudios.com *.cloud.bymayvenstudios.com *.d3f2b264-c6c0-4fbe-9c39-b3e4c9548986.bymayvenstudios.com *.demo.bymayvenstudios.com *.f5d40004-944f-4003-a870-026a6da68a26.bymayvenstudios.com *.rd.bymayvenstudios.com *.rds.bymayvenstudios.com *.rdweb.bymayvenstudios.com *.remote.bymayvenstudios.com *.vpn.bymayvenstudios.com
cannastars.org *.cannastars.org *.www.cannastars.org
*.api.dewakoin-rtp.click *.app.dewakoin-rtp.click dewakoin-rtp.click *.dewakoin-rtp.click
*.dc-819d9ed1109b.edcstudios.live edcstudios.live *.edcstudios.live *.ww38.edcstudios.live *.www.edcstudios.live
growlife.org *.growlife.org *.hostmaster.growlife.org *.sitemaps.growlife.org
*.a.hospiceincare.info *.api.hospiceincare.info *.app.hospiceincare.info *.dev.hospiceincare.info hospiceincare.info *.hospiceincare.info *.orrat7.hospiceincare.info *.www.hospiceincare.info
*.bsnho.izzpa.com *.hostmaster.izzpa.com izzpa.com *.izzpa.com *.tttnen.izzpa.com
*.admin.seelenwachsuptum.com *.app.seelenwachsuptum.com *.gbogti.seelenwachsuptum.com seelenwachsuptum.com *.seelenwachsuptum.com
spitfirehotsauce.com *.spitfirehotsauce.com *.tvr9vl.spitfirehotsauce.com
*.random.tcsportscards.com tcsportscards.com *.tcsportscards.com *.workspace2.tcsportscards.com *.ww38.tcsportscards.com
typemailist.com *.typemailist.com *.vkfxcpay.typemailist.com *.web.typemailist.com