76/100 SECURITY SCORE

Certificate Information

Subject
CN=olivergarden.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 22, 2026
Valid Until
August 20, 2026 76 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
75:DF:DB:97:25:16:A3:BF:0A:DE:8B:60:E2:29:CE:4A:27:04:9C:3F:E5:63:FB:51:F6:CA:0C:C0:1D:AD:2F:C2
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
iarunning.com *.iarunning.com *.api.iarunning.com *.assets.iarunning.com *.n9ki22.iarunning.com *.shop.iarunning.com

Other domains in certificate

axon.com.au *.axon.com.au *.georgeingham.axon.com.au *.gillsbreather.axon.com.au *.markwoolston.axon.com.au *.webmail.axon.com.au *.woodfired.axon.com.au
*.8b869251-848f-4b14-9365-722cf56999fe.designforminikind.com designforminikind.com *.designforminikind.com *.ftp.designforminikind.com *.m.designforminikind.com *.remote.designforminikind.com *.static.designforminikind.com *.webmail.designforminikind.com *.whm.designforminikind.com *.www.designforminikind.com
faveti.com *.faveti.com *.mail.faveti.com
funko-us.shop *.funko-us.shop *.ww38.funko-us.shop
*.6onqan.ghijjk.top *.87ab5.ghijjk.top *.cnfr9.ghijjk.top *.eu3rm.ghijjk.top ghijjk.top *.ghijjk.top *.kwid9.ghijjk.top *.nktjv.ghijjk.top *.nxc75.ghijjk.top *.qpuov.ghijjk.top *.rczhl.ghijjk.top *.vhakn.ghijjk.top
*.com.indiafirstjob.com indiafirstjob.com *.indiafirstjob.com
*.6e8d8684-bc69-4277-81b1-2b7237b823dd.mixi.in *.adult.mixi.in *.auth.mixi.in *.bhimqpopular.mixi.in *.campanha.mixi.in *.comms.mixi.in *.hostmaster.mixi.in *.m.mixi.in mixi.in *.mixi.in *.mta-sts.mixi.in *.popular.mixi.in *.sitemap.mixi.in *.sso.mixi.in
*.jobs.olivergarden.com olivergarden.com *.olivergarden.com *.random.olivergarden.com
parisbola99.loan *.parisbola99.loan
*.44businessca.pital.it *.email.pital.it *.firstwestca.pital.it *.mbca.pital.it *.mx.pital.it *.orldc.pital.it pital.it *.pital.it *.staging.pital.it
*.hostmaster.pug.asia pug.asia *.pug.asia *.www.pug.asia
thecaliforniasurflodge.com *.thecaliforniasurflodge.com
thecalvinator.com *.thecalvinator.com
wapdow.com *.wapdow.com
weebmaal.com *.weebmaal.com
*.5277.yingtao99.net *.av123.yingtao99.net *.cctv333.yingtao99.net yingtao99.net *.yingtao99.net