76/100 SECURITY SCORE

Certificate Information

Subject
CN=lightsound.co
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 25, 2026
Valid Until
August 23, 2026 65 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A9:7A:22:63:E1:72:0E:B7:42:60:B9:72:F5:BE:51:65:39:6B:28:4F:1E:D1:1F:35:59:9E:E8:0C:75:E1:E7:CC
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
lightsound.co *.lightsound.co *.beta.lightsound.co *.blog.lightsound.co *.demo.lightsound.co *.extranet.lightsound.co *.public.lightsound.co *.sitemaps.lightsound.co *.wiki.lightsound.co

Other domains in certificate

*.api.bennettvalley.net *.app.bennettvalley.net bennettvalley.net *.bennettvalley.net *.lms.bennettvalley.net *.m.bennettvalley.net *.remote.bennettvalley.net *.sitemap.bennettvalley.net *.sitemaps.bennettvalley.net *.staging.bennettvalley.net *.webmail.bennettvalley.net
*.apps.devlights.in *.cfed1e6c-71f2-40e8-86d1-a720a42984bb.devlights.in devlights.in *.devlights.in
ebv53.icu *.ebv53.icu
eyes.ad *.eyes.ad *.lvzodw2juuln.eyes.ad
furfreeminneapolis.org *.furfreeminneapolis.org *.m.furfreeminneapolis.org *.www.furfreeminneapolis.org
hellyvalentine.net *.hellyvalentine.net *.m.hellyvalentine.net *.sitemaps.hellyvalentine.net *.vpn.hellyvalentine.net *.webdisk.hellyvalentine.net *.www.hellyvalentine.net
hummusway.co *.hummusway.co *.ww38.hummusway.co
*.com.masterplay99amp.xyz *.joker-mainsite.masterplay99amp.xyz masterplay99amp.xyz *.masterplay99amp.xyz
neuneon.co *.neuneon.co *.ww38.neuneon.co
*.6b1bsf.rtpbatik77-jostop1.shop rtpbatik77-jostop1.shop *.rtpbatik77-jostop1.shop
selektr.club *.selektr.club
*.4fyevs.sherpastrategicfund.biz *.api.sherpastrategicfund.biz *.app.sherpastrategicfund.biz *.mail.sherpastrategicfund.biz *.mnxxqy.sherpastrategicfund.biz sherpastrategicfund.biz *.sherpastrategicfund.biz *.sk10om.sherpastrategicfund.biz *.staging.sherpastrategicfund.biz *.support.sherpastrategicfund.biz
*.random.thatsgreece.com thatsgreece.com *.thatsgreece.com *.ww25.thatsgreece.com
*.branches.thedolphinilfracombe.co.uk *.cloud.thedolphinilfracombe.co.uk *.finance.thedolphinilfracombe.co.uk *.locations.thedolphinilfracombe.co.uk *.mail10.thedolphinilfracombe.co.uk *.staging2.thedolphinilfracombe.co.uk *.stores.thedolphinilfracombe.co.uk thedolphinilfracombe.co.uk *.thedolphinilfracombe.co.uk *.ww01.thedolphinilfracombe.co.uk
*.mail.uplimova.com uplimova.com *.uplimova.com
v8bet.pro *.v8bet.pro
*.ww38.xoscan.io xoscan.io *.xoscan.io
*.proww38.zeropack.pro zeropack.pro *.zeropack.pro