Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=winerycave.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 15, 2026
Valid Until
August 13, 2026
70 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5F:11:AB:D1:B9:39:36:A1:92:07:F7:C6:52:DC:85:C5:36:80:72:17:2A:99:F9:1B:D2:72:34:A7:3B:94:82:56
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
buganda.coffee
*.buganda.coffee
*.dev.buganda.coffee
*.exypys.buganda.coffee
1771.info
*.1771.info
1800primespace.com
*.1800primespace.com
483572.top
*.483572.top
4c6b40jtjs.sbs
*.4c6b40jtjs.sbs
540588.cc
*.540588.cc
577504.xyz
*.577504.xyz
58353.my
*.58353.my
605322.club
*.605322.club
768892.vip
*.768892.vip
7xoc.cc
*.7xoc.cc
98383.loan
*.98383.loan
9p2cgm6q78.world
*.9p2cgm6q78.world
9ty.top
*.9ty.top
a48609599.top
*.a48609599.top
fusionsbook.com
*.fusionsbook.com
*.gitlab.fusionsbook.com
newsolar.io
*.newsolar.io
newwavehealing.com
*.newwavehealing.com
nocaus.com
*.nocaus.com
oneidacounty.info
*.oneidacounty.info
pcjxgj.com
*.pcjxgj.com
qjagcs.store
*.qjagcs.store
qkckltwlzh.cc
*.qkckltwlzh.cc
rocboard.store
*.rocboard.store
saxendapen.com
*.saxendapen.com
sculptes.store
*.sculptes.store
sendmyeliquid.com
*.sendmyeliquid.com
sonbisey.com
*.sonbisey.com
td30591.cc
*.td30591.cc
thelooneyfarm.store
*.thelooneyfarm.store
uyhedg.site
*.uyhedg.site
vleedesigntheory.site
*.vleedesigntheory.site
vyacheslavkalinin.com
*.vyacheslavkalinin.com
vyyqzz.site
*.vyyqzz.site
w25tygj8ycpr0y9.cc
*.w25tygj8ycpr0y9.cc
*.1e-aa94593e5c5f.watalentspecialist.info
*.api.watalentspecialist.info
*.eywlhtest.watalentspecialist.info
watalentspecialist.info
*.watalentspecialist.info
whooly.store
*.whooly.store
winerycave.com
*.winerycave.com
www76s2.com
*.www76s2.com
y3-18589539.xyz
*.y3-18589539.xyz
zwistonia.com
*.zwistonia.com
zytorio.com
*.zytorio.com
Other domains in certificate