Open
Cached
·
just now
79/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=croissancetop.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 05, 2026
Valid Until
May 06, 2026
69 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
82:EF:CC:39:54:85:54:C4:7E:F5:5B:19:39:BA:7F:3E:04:3F:E9:CD:AD:49:9F:DD:37:67:41:DC:73:29:03:39
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
archeagent.com
*.archeagent.com
932158.cc
*.932158.cc
934rpt301.top
*.934rpt301.top
95646.loan
*.95646.loan
970210.com
*.970210.com
99007.pro
*.99007.pro
9xav18.xyz
*.9xav18.xyz
a002jys.top
*.a002jys.top
adfinwrk.click
*.adfinwrk.click
adsgencylabs.com
*.adsgencylabs.com
aitopupex.com
*.aitopupex.com
alhrpmlgyvmwimxjuhkg.com
*.alhrpmlgyvmwimxjuhkg.com
anlyrapp.click
*.anlyrapp.click
anlytool.click
*.anlytool.click
appuifeu.com
*.appuifeu.com
ariatsaleus.com
*.ariatsaleus.com
artshop.top
*.artshop.top
asosfc.org
*.asosfc.org
assisted-living-for-seniors-11.click
*.assisted-living-for-seniors-11.click
bachelorofnursing.com
*.bachelorofnursing.com
barren.us
*.barren.us
bavaroy.com
*.bavaroy.com
bayar77ind.cfd
*.bayar77ind.cfd
beautyfinde.com
*.beautyfinde.com
bixamo.com
*.bixamo.com
bouchikha.com
*.bouchikha.com
bravefendora.com
*.bravefendora.com
brservices-003.click
*.brservices-003.click
byroll.com
*.byroll.com
careergrowthhub.site
*.careergrowthhub.site
chinesename.one
*.chinesename.one
coat.one
*.coat.one
creactivecareers.com
*.creactivecareers.com
croissancetop.com
*.croissancetop.com
ctusi.info
*.ctusi.info
czgwjq.me
*.czgwjq.me
d67kb9.shop
*.d67kb9.shop
dailyfooddelights.food
*.dailyfooddelights.food
dailymz.com
*.dailymz.com
dating-sites-nlyy.click
*.dating-sites-nlyy.click
delikabeads.com
*.delikabeads.com
derinyansima.org
*.derinyansima.org
digaccess.com
*.digaccess.com
digitalmagazines.net
*.digitalmagazines.net
diospiro.com
*.diospiro.com
Other domains in certificate