76/100 SECURITY SCORE

Certificate Information

Subject
CN=shotai.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 28, 2026
Valid Until
August 26, 2026 69 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E9:43:2A:9B:4E:16:1E:AD:12:00:E6:C0:48:8B:EE:FA:30:88:9E:94:B2:3E:7B:31:D3:92:FB:D7:76:78:52:FA
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
admins.page *.admins.page *.actio.admins.page *.agju.admins.page *.api.admins.page *.app.admins.page *.baigy.admins.page *.barde.admins.page *.coacheaps.admins.page *.dashboard.admins.page *.deicom.admins.page *.discte.admins.page *.hearze.admins.page *.m.admins.page *.mayge.admins.page *.nabgu.admins.page *.olbee.admins.page *.omven.admins.page *.prudup.admins.page *.router.admins.page *.speedin.admins.page *.test.admins.page *.uat.admins.page

Other domains in certificate

accare.co *.accare.co
agrocapital.co *.agrocapital.co *.sitemap.agrocapital.co
jobbs.co *.jobbs.co
loveco.co *.loveco.co *.mx.loveco.co
lunam.co *.lunam.co *.sitemaps.lunam.co
*.34445e9f-2933-44e1-86c3-842216a591d0.quiz30.biz *.551c5a93-c2a1-43fd-ab42-4abad93d43a1.quiz30.biz *.app.quiz30.biz *.backup.quiz30.biz *.gov.quiz30.biz *.k29gcz.quiz30.biz *.mail.quiz30.biz quiz30.biz *.quiz30.biz *.staging.quiz30.biz *.www.quiz30.biz
*.api.shotai.com *.ciscovpn.shotai.com *.cloud.shotai.com *.cpcontacts.shotai.com *.dev.shotai.com *.drvpn.shotai.com *.email.shotai.com *.exchange.shotai.com *.ftp.shotai.com *.gate.shotai.com *.gateway.shotai.com *.gp.shotai.com *.hostmaster.shotai.com *.imap.shotai.com *.m.shotai.com *.mail.shotai.com *.mvideo.shotai.com *.ravpn.shotai.com *.relay.shotai.com *.secure.shotai.com shotai.com *.shotai.com *.sitemap.shotai.com *.sitemaps.shotai.com *.smtp.shotai.com *.sslvpn.shotai.com *.test.shotai.com *.vpn.shotai.com *.webmail.shotai.com *.webvpn.shotai.com *.ww11.shotai.com *.ww25.shotai.com *.ww38.shotai.com
*.acesso.spygram.tech *.aplicativo.spygram.tech *.dev.spygram.tech *.enter.spygram.tech *.painel.spygram.tech spygram.tech *.spygram.tech *.tracking.spygram.tech *.web.spygram.tech *.ww38.spygram.tech