Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=filla.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 13, 2026
Valid Until
August 11, 2026
50 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BF:8B:54:49:6B:0C:4B:51:A8:1C:F7:6C:B7:01:97:85:02:EF:49:74:90:2C:2B:8C:7A:E3:92:66:F5:B2:53:F8
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
therap.it
*.therap.it
*.admin.therap.it
*.analytics.therap.it
*.api.therap.it
*.backend.therap.it
*.bi.therap.it
*.chart.therap.it
*.ci.therap.it
*.dash.therap.it
*.dashs.therap.it
*.demo.therap.it
*.dev.therap.it
*.redash.therap.it
*.reporting.therap.it
*.staging.therap.it
*.test.therap.it
*.60t9v.7d77ylxx.top
7d77ylxx.top
*.7d77ylxx.top
*.dwij7.7d77ylxx.top
*.he00g.7d77ylxx.top
*.kac0t.7d77ylxx.top
*.l2aa8.7d77ylxx.top
*.00584a31-aae8-409f-9855-115e5642de7c.cimetidine.net
*.7a443622-9708-452b-8522-67f39c4e4525.cimetidine.net
*.app.cimetidine.net
*.backup.cimetidine.net
cimetidine.net
*.cimetidine.net
*.cpcontacts.cimetidine.net
*.dashboard.cimetidine.net
*.git.cimetidine.net
*.m.cimetidine.net
*.rd.cimetidine.net
*.rds.cimetidine.net
*.rdweb.cimetidine.net
*.remote.cimetidine.net
*.secure.cimetidine.net
*.stg.cimetidine.net
*.v1.cimetidine.net
*.v2.cimetidine.net
*.web.cimetidine.net
*.www.cimetidine.net
filla.it
*.filla.it
*.hostmaster.filla.it
*.mail3.filla.it
financemyvehicle.com
*.financemyvehicle.com
*.www.financemyvehicle.com
*.admin.lefantasie.it
*.app.lefantasie.it
*.backend.lefantasie.it
*.bi.lefantasie.it
*.ci.lefantasie.it
*.dashboard.lefantasie.it
*.demo.lefantasie.it
*.dev.lefantasie.it
lefantasie.it
*.lefantasie.it
*.metrics.lefantasie.it
*.remote.lefantasie.it
*.supersets.lefantasie.it
northindia.in
*.northindia.in
*.www.northindia.in
oldlots.com
*.oldlots.com
*.www.oldlots.com
olivehillssalon.de
*.olivehillssalon.de
*.76kdpel143.vanity-press.co.uk
*.analytic-hotfix.vanity-press.co.uk
*.beta-pipeline.vanity-press.co.uk
*.cicd-dev.vanity-press.co.uk
*.comune.vanity-press.co.uk
*.demo-visualize.vanity-press.co.uk
*.dev.vanity-press.co.uk
*.flowise.vanity-press.co.uk
*.insights-production.vanity-press.co.uk
*.jenkins.vanity-press.co.uk
*.random.vanity-press.co.uk
*.trail.vanity-press.co.uk
vanity-press.co.uk
*.vanity-press.co.uk
*.oinszr.xrappai.com
*.xmtcvula.xrappai.com
xrappai.com
*.xrappai.com
Other domains in certificate