76/100 SECURITY SCORE

Certificate Information

Subject
CN=cpjc88.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 16, 2026
Valid Until
July 15, 2026 32 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D6:64:E6:CD:2A:A0:BA:C6:7A:32:42:08:5F:E6:73:55:41:ED:E6:11:00:96:0D:87:39:6C:2F:E1:69:5E:90:ED
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
aeroscraper.io *.aeroscraper.io *.api.aeroscraper.io *.arch.aeroscraper.io *.archway-dev.aeroscraper.io *.avax.aeroscraper.io *.gwt.aeroscraper.io *.indexerv2.aeroscraper.io *.indexerxion.aeroscraper.io *.inj.aeroscraper.io *.injective.aeroscraper.io *.manta.aeroscraper.io *.xion.aeroscraper.io

Other domains in certificate

*.0870com.80870.ca 80870.ca *.80870.ca *.ca.80870.ca *.com.80870.ca *.games.80870.ca
americasjobsexchange.com *.americasjobsexchange.com *.ww38.americasjobsexchange.com
aneursma.de *.aneursma.de
answerable.it *.answerable.it
aramex.live *.aramex.live *.dev.aramex.live *.imap.aramex.live *.mobile.aramex.live *.webmail.aramex.live *.ww25.aramex.live *.ww38.aramex.live
cpjc88.com *.cpjc88.com
free-nefl.com *.free-nefl.com *.ww38.free-nefl.com
gameaft.com *.gameaft.com *.hostmaster.gameaft.com
gfx-verge.de *.gfx-verge.de *.hostmaster.gfx-verge.de
*.4c0524bf-718a-4b02-a462-af3e9cb55eed.hotfile.org *.5605462b-1ead-4fe9-811d-6025eae4281b.hotfile.org hotfile.org *.hotfile.org *.random.hotfile.org *.remoteaccess.hotfile.org
i33.studio *.i33.studio
lookovie2.to *.lookovie2.to *.ww25.lookovie2.to *.ww38.lookovie2.to
*.a.mittelstandsversorgung.info *.dev.mittelstandsversorgung.info *.mailer.mittelstandsversorgung.info *.marketing.mittelstandsversorgung.info *.members.mittelstandsversorgung.info mittelstandsversorgung.info *.mittelstandsversorgung.info
*.autodiscover.opensex.it *.cpanel.opensex.it *.dev.opensex.it opensex.it *.opensex.it
plabis-md.de *.plabis-md.de
*.pay.ppp-appraisals.com ppp-appraisals.com *.ppp-appraisals.com
retinalsurgery.com *.retinalsurgery.com *.sitemap.retinalsurgery.com *.superset.retinalsurgery.com *.victory.retinalsurgery.com *.vmncdwap.retinalsurgery.com
*.hostmaster.schue24.de schue24.de *.schue24.de
*.hostmaster.spz.com.au *.random.spz.com.au spz.com.au *.spz.com.au
tabletsevent.com *.tabletsevent.com *.webdisk.tabletsevent.com