76/100 SECURITY SCORE

Certificate Information

Subject
CN=kumo-ai.tech
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 02, 2026
Valid Until
July 31, 2026 58 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C1:E5:80:A7:63:58:C8:4D:C3:27:93:19:E5:9B:92:CA:26:0F:82:B8:41:6A:30:D3:8D:05:F6:F3:04:40:CF:E4
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
lunchbrook.info *.lunchbrook.info *.api.lunchbrook.info *.app.lunchbrook.info *.backoffice.lunchbrook.info *.dev.lunchbrook.info *.portal.lunchbrook.info *.www.lunchbrook.info

Other domains in certificate

*.15129bf4-b60c-4123-8331-08070dd68ec4.acsmallcos.info *.81662.acsmallcos.info acsmallcos.info *.acsmallcos.info *.admin.acsmallcos.info *.app.acsmallcos.info *.s81662.acsmallcos.info *.staging.acsmallcos.info *.testing.acsmallcos.info *.www.acsmallcos.info
auroraruggieri.eu *.auroraruggieri.eu *.ktj.auroraruggieri.eu *.nhqzdri.auroraruggieri.eu *.wercmv.auroraruggieri.eu *.zabjhpr.auroraruggieri.eu
jointgennesis.us *.jointgennesis.us
*.docs.kumo-ai.tech *.guitar-chords-search-svelte-kit.kumo-ai.tech kumo-ai.tech *.kumo-ai.tech *.songs-search.kumo-ai.tech
*.hostmaster.lowered.it lowered.it *.lowered.it
mcpforce.com *.mcpforce.com
*.backend.mp3yt.tech mp3yt.tech *.mp3yt.tech *.ww38.mp3yt.tech
*.m.myclosetme.com *.mail.myclosetme.com myclosetme.com *.myclosetme.com *.random.myclosetme.com *.richhausm.myclosetme.com *.scbe.myclosetme.com *.staging.myclosetme.com *.t.myclosetme.com *.uwww.myclosetme.com *.website.myclosetme.com *.ww.myclosetme.com *.ww25.myclosetme.com *.ww38.myclosetme.com *.wwww.myclosetme.com *.xn--1260www-1o3f.myclosetme.com
*.cpanel.nikoniko.asia nikoniko.asia *.nikoniko.asia *.random.nikoniko.asia *.ww25.nikoniko.asia
noticiaes.online *.noticiaes.online
*.admin.occhialiallamoda.com *.api.occhialiallamoda.com *.app.occhialiallamoda.com *.bi.occhialiallamoda.com *.chart.occhialiallamoda.com *.dashboard.occhialiallamoda.com *.dashboards.occhialiallamoda.com *.demo.occhialiallamoda.com *.dev.occhialiallamoda.com *.metric.occhialiallamoda.com occhialiallamoda.com *.occhialiallamoda.com *.redash.occhialiallamoda.com *.reporting.occhialiallamoda.com *.stats.occhialiallamoda.com *.superset.occhialiallamoda.com *.visual.occhialiallamoda.com *.workflow.occhialiallamoda.com
*.kkompressor.supersale1000.website *.kompression.supersale1000.website *.myorte.supersale1000.website *.random.supersale1000.website *.sticks.supersale1000.website supersale1000.website *.supersale1000.website
vip-iptv.club *.vip-iptv.club