Open
Cached
·
3h ago
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=bigcyprus.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 02, 2026
Valid Until
May 03, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:8D:90:9E:4F:BA:26:0F:ED:09:E0:36:31:79:DB:58:26:D5:01:B6:7B:8A:E2:7C:4D:2D:0D:10:41:0A:8B:23
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
bigcyprus.com
*.bigcyprus.com
*.classifieds.bigcyprus.com
*.mail.bigcyprus.com
*.yes5bl1rd3ni81c5.bigcyprus.com
autouploader.com
*.autouploader.com
*.dev.autouploader.com
*.sandbox.autouploader.com
*.store.autouploader.com
edisorder.com
*.edisorder.com
*.ww38.edisorder.com
invenditaonline.com
*.invenditaonline.com
jadiel.net
*.jadiel.net
jsxznb.net
*.jsxznb.net
jzds.org
*.jzds.org
*.api.kadunastate.com
kadunastate.com
*.kadunastate.com
kauaifsbo.com
*.kauaifsbo.com
kph22.top
*.kph22.top
labiale.com
*.labiale.com
lailj.net
*.lailj.net
lariana.com
*.lariana.com
leqojh.pro
*.leqojh.pro
mangiafuoco.com
*.mangiafuoco.com
marcolentini.com
*.marcolentini.com
marenza.it
*.marenza.it
marinaio.net
*.marinaio.net
minimercati.com
*.minimercati.com
monetalocale.com
*.monetalocale.com
montacarichidacantiere.com
*.montacarichidacantiere.com
*.blackboard.montrer.com
montrer.com
*.montrer.com
muscoloso.com
*.muscoloso.com
opada.com
*.opada.com
packing-company-jobs.click
*.packing-company-jobs.click
pettegolezzi.org
*.pettegolezzi.org
pezzispeciali.com
*.pezzispeciali.com
piantesecolari.com
*.piantesecolari.com
pop555.bet
*.pop555.bet
programmatoriweb.com
*.programmatoriweb.com
qpelx.net
*.qpelx.net
qrxdagb.top
*.qrxdagb.top
repercussively.com
*.repercussively.com
rifugialpini.com
*.rifugialpini.com
sajjada.store
*.sajjada.store
salutismo.com
*.salutismo.com
scalearredamento.com
*.scalearredamento.com
small-world.com
*.small-world.com
snobba.com
*.snobba.com
*.sitemap.thejumpfactory.com
thejumpfactory.com
*.thejumpfactory.com
Other domains in certificate