76/100 SECURITY SCORE

Certificate Information

Subject
CN=criticize.in
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 20, 2026
Valid Until
August 18, 2026 83 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C8:C6:9F:13:FC:A9:A7:A2:30:4D:EE:D5:EC:49:6B:1E:0E:43:0C:46:94:36:27:38:ED:58:C0:AC:EB:EE:D0:62
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
aimentioned.com *.aimentioned.com *.admin.aimentioned.com *.api.aimentioned.com *.app.aimentioned.com *.dev.aimentioned.com *.m.aimentioned.com *.pacqndev.aimentioned.com *.rustore.aimentioned.com *.www.aimentioned.com

Other domains in certificate

criticize.in *.criticize.in *.hostmaster.criticize.in *.m.criticize.in *.www.criticize.in
*.admin.findwherefouradvertising.co *.api.findwherefouradvertising.co *.app.findwherefouradvertising.co *.assets.findwherefouradvertising.co *.blog.findwherefouradvertising.co *.bmaczshop.findwherefouradvertising.co *.demo.findwherefouradvertising.co *.dev.findwherefouradvertising.co findwherefouradvertising.co *.findwherefouradvertising.co *.shop.findwherefouradvertising.co *.tpyundev.findwherefouradvertising.co *.www.findwherefouradvertising.co
*.access.life.fm *.account.life.fm *.admin.life.fm *.adore.life.fm *.aivczsecureaccess.life.fm *.anyconnect.life.fm *.app.life.fm *.asa.life.fm *.autodiscover.life.fm *.backend.life.fm *.canliradyodinle.life.fm *.cisco.life.fm *.comune.life.fm *.connect.life.fm *.cpanel.life.fm *.cpcalendars.life.fm *.cpcontacts.life.fm *.deepthought.life.fm *.dev.life.fm *.email.life.fm *.fortinet.life.fm *.fortivpn.life.fm *.gateway.life.fm *.globalprotect.life.fm *.gp.life.fm *.his.life.fm *.hostmaster.life.fm *.in.life.fm *.liderstvo.life.fm life.fm *.life.fm *.m.life.fm *.mail.life.fm *.notexistscanliradyodinle.life.fm *.notexistsdeepthought.life.fm *.notexistspt.life.fm *.office.life.fm *.on.life.fm *.owa.life.fm *.perm.life.fm *.pop.life.fm *.portal.life.fm *.prelogon.life.fm *.pt.life.fm *.ra.life.fm *.remote.life.fm *.sagicor.life.fm *.sbbbtautodiscover.life.fm *.secure.life.fm *.secureaccess.life.fm *.shop.life.fm *.ssl.life.fm *.staging.life.fm *.ugueyshop.life.fm *.vpn.life.fm *.vpnssl.life.fm *.wildcard.life.fm *.ww.life.fm *.www.life.fm *.wxycorih.life.fm