76/100 SECURITY SCORE

Certificate Information

Subject
CN=chot.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 17, 2026
Valid Until
July 16, 2026 56 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DD:06:48:05:B8:37:A8:6F:04:43:C7:5B:20:E2:A6:C6:AA:30:A1:5B:9C:40:8F:9E:08:70:8B:F1:21:09:66:86
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
chot.it *.chot.it *.analytics.chot.it *.bi.chot.it *.chart.chot.it *.dashboard.chot.it *.database.chot.it *.hostmaster.chot.it *.irc.chot.it *.reports.chot.it *.research.chot.it *.stats.chot.it *.superset.chot.it *.visual.chot.it *.xmpp.chot.it

Other domains in certificate

annen.it *.annen.it *.demo.annen.it *.staging.annen.it
*.app.bungalowdorf-zadelsdorf.de *.blog.bungalowdorf-zadelsdorf.de bungalowdorf-zadelsdorf.de *.bungalowdorf-zadelsdorf.de *.kundenportal.bungalowdorf-zadelsdorf.de *.sitemaps.bungalowdorf-zadelsdorf.de *.vpn.bungalowdorf-zadelsdorf.de *.ww25.bungalowdorf-zadelsdorf.de
buycryptobitcoins.com *.buycryptobitcoins.com *.m.buycryptobitcoins.com *.mtwodmembers.buycryptobitcoins.com *.prod.buycryptobitcoins.com *.shop.buycryptobitcoins.com *.staging.buycryptobitcoins.com *.user.buycryptobitcoins.com *.vps.buycryptobitcoins.com *.web.buycryptobitcoins.com *.zkbckmtwodmembers.buycryptobitcoins.com *.zoom.buycryptobitcoins.com
deutschland-rechtsschutz.de *.deutschland-rechtsschutz.de *.service.deutschland-rechtsschutz.de
*.app.exosia.org *.dashboard.exosia.org *.dashboards.exosia.org *.demo.exosia.org *.dev.exosia.org exosia.org *.exosia.org *.metrics.exosia.org *.reporting.exosia.org *.stats.exosia.org *.superset.exosia.org *.supersets.exosia.org *.ww16.exosia.org
financialnavigationllc.com *.financialnavigationllc.com *.ww25.financialnavigationllc.com
injectors.ca *.injectors.ca *.m.injectors.ca
*.hostmaster.passamano.com passamano.com *.passamano.com *.ww42.passamano.com
simplebest.club *.simplebest.club *.webdisk.simplebest.club
torrentsee149.com *.torrentsee149.com *.ww25.torrentsee149.com
*.edu.uaccm.com *.helpdesk.uaccm.com uaccm.com *.uaccm.com *.ww38.uaccm.com
*.access.waiwen.com *.sitemaps.waiwen.com *.ts.waiwen.com waiwen.com *.waiwen.com *.ww25.waiwen.com *.ww38.waiwen.com *.www.waiwen.com
*.514d1110-59b9-4e3e-920f-0bf6844c0d92.xsmbchunhat.com *.a.xsmbchunhat.com *.api.xsmbchunhat.com *.shop.xsmbchunhat.com xsmbchunhat.com *.xsmbchunhat.com