76/100 SECURITY SCORE

Certificate Information

Subject
CN=ufey.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 10, 2026
Valid Until
May 11, 2026 80 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
D2:28:3A:F4:70:3B:BF:58:80:B4:3E:C8:22:83:7C:F8:08:2F:E1:52:48:7A:81:EA:CB:73:16:8D:03:7D:CD:94
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
hernutrition.com *.hernutrition.com *.cdn.hernutrition.com *.demo.hernutrition.com *.help.hernutrition.com *.hostmaster.hernutrition.com *.sitemaps.hernutrition.com *.ww17.hernutrition.com *.ww25.hernutrition.com *.ww38.hernutrition.com *.www.hernutrition.com *.xh.hernutrition.com

Other domains in certificate

*.admin.aoweii.com aoweii.com *.aoweii.com *.app.aoweii.com *.auth.aoweii.com *.confluence.aoweii.com *.email.aoweii.com *.producer.aoweii.com *.rd.aoweii.com *.rds.aoweii.com *.remote.aoweii.com *.shhagrd.aoweii.com *.site.aoweii.com *.smtp.aoweii.com *.vnluclsmxiadmin.aoweii.com *.wildcard.aoweii.com
boshcarservice.be *.boshcarservice.be
caplus-web.com *.caplus-web.com
electrifiedwallet.com *.electrifiedwallet.com *.m.electrifiedwallet.com
*.docs.gasps.lol gasps.lol *.gasps.lol
*.d1c65.jr-finance.com jr-finance.com *.jr-finance.com *.mail.jr-finance.com *.ql7be.jr-finance.com *.rdo5q.jr-finance.com *.u2d8g.jr-finance.com *.vpn.jr-finance.com *.vw5r7.jr-finance.com *.vx0t3.jr-finance.com *.wdaqj.jr-finance.com *.wildcard.jr-finance.com *.ww12.jr-finance.com
*.adidas.mx42.club *.ads.mx42.club *.csg.mx42.club *.email.mx42.club *.hjnetwtr1099.mx42.club *.i2.mx42.club *.lineage2.mx42.club *.members.mx42.club *.membership.mx42.club *.music.mx42.club mx42.club *.mx42.club *.net.mx42.club *.pan.mx42.club *.roslin.mx42.club *.santander.mx42.club *.sasg.mx42.club *.shca.mx42.club *.staffmail.mx42.club *.staging.mx42.club *.teeth.mx42.club *.toyota.mx42.club *.users.mx42.club *.ww2.mx42.club *.wwwprod.mx42.club
*.bi.tevila.com *.charts.tevila.com *.superset.tevila.com *.template-insights.tevila.com tevila.com *.tevila.com *.ww1.tevila.com
trufflespastryshoppe.com *.trufflespastryshoppe.com
*.mm.ufey.com *.owa.ufey.com ufey.com *.ufey.com *.ww25.ufey.com