76/100 SECURITY SCORE

Certificate Information

Subject
CN=repo.bio
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 13, 2026
Valid Until
September 11, 2026 76 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
7D:9E:FF:47:B5:94:31:DE:E7:8D:70:13:01:38:31:B9:27:63:18:17:A3:EF:AC:83:35:AF:97:29:BB:D0:6C:E1
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
justifymedia.com *.justifymedia.com *.api.justifymedia.com *.ebay.justifymedia.com *.hostmaster.justifymedia.com *.m.justifymedia.com *.mywebmail.justifymedia.com

Other domains in certificate

61706.ad *.61706.ad
cromoluce.it *.cromoluce.it
*.admin.finweaver.com *.app.finweaver.com *.demo.finweaver.com finweaver.com *.finweaver.com *.m.finweaver.com
*.cpanel.freechristians.org freechristians.org *.freechristians.org *.hostmaster.freechristians.org *.m.freechristians.org *.mail.freechristians.org *.server1.freechristians.org
*.4no68r.gossipdeck.live gossipdeck.live *.gossipdeck.live
*.demo.heripass.com heripass.com *.heripass.com *.vpn.heripass.com
*.admin.kapten62.org *.api.kapten62.org *.app.kapten62.org *.assets.kapten62.org *.backup.kapten62.org *.dashboard.kapten62.org *.demo.kapten62.org *.go.kapten62.org *.hcogwmail.kapten62.org kapten62.org *.kapten62.org *.mail.kapten62.org *.mailer.kapten62.org *.marketing.kapten62.org *.media.kapten62.org *.qa.kapten62.org *.secure.kapten62.org *.seguro.kapten62.org *.staging.kapten62.org *.static.kapten62.org *.status.kapten62.org *.stg.kapten62.org *.test.kapten62.org *.uat.kapten62.org *.v1.kapten62.org *.vip.kapten62.org *.web.kapten62.org *.webdav.kapten62.org *.www.kapten62.org
*.api.kitchenmorocco.com *.app.kitchenmorocco.com *.dev.kitchenmorocco.com *.jliopkkztuo.kitchenmorocco.com kitchenmorocco.com *.kitchenmorocco.com *.kkztuo.kitchenmorocco.com *.test.kitchenmorocco.com *.vpn.kitchenmorocco.com
*.m.rebatebeast.com rebatebeast.com *.rebatebeast.com
*.m.repo.bio repo.bio *.repo.bio *.sitemap.repo.bio
*.m.seaclub.net seaclub.net *.seaclub.net
securityalert.com.au *.securityalert.com.au
*.lms.unipathdiagnosticcenter.com *.qr.unipathdiagnosticcenter.com unipathdiagnosticcenter.com *.unipathdiagnosticcenter.com
*.hostmaster.wefocusonyou.com *.m.wefocusonyou.com *.sitemap.wefocusonyou.com wefocusonyou.com *.wefocusonyou.com