76/100 SECURITY SCORE

Certificate Information

Subject
CN=freevouchercode.org
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 05, 2026
Valid Until
August 03, 2026 59 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3D:86:14:8B:F0:3F:FA:FA:30:A0:6C:15:F3:00:76:64:94:05:72:37:38:81:58:3A:7D:C7:81:2A:FE:55:7D:66
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
freevouchercode.org *.freevouchercode.org *.a.freevouchercode.org *.cf.freevouchercode.org *.downloads.freevouchercode.org *.gpt.freevouchercode.org *.i.freevouchercode.org *.library.freevouchercode.org *.m.freevouchercode.org *.magento.freevouchercode.org *.mkt.freevouchercode.org *.ww38.freevouchercode.org

Other domains in certificate

5050.bio *.5050.bio *.controller.5050.bio *.random.5050.bio
561xxs.shop *.561xxs.shop *.ww38.561xxs.shop
aviatorslotmachinebonus.xyz *.aviatorslotmachinebonus.xyz *.ww25.aviatorslotmachinebonus.xyz *.ww38.aviatorslotmachinebonus.xyz
*.analitik.ekkennels.com ekkennels.com *.ekkennels.com *.vis.ekkennels.com *.ww38.ekkennels.com
elearningwithguru.com *.elearningwithguru.com *.ww38.elearningwithguru.com
*.ftp.govtjobalertwala.com govtjobalertwala.com *.govtjobalertwala.com
*.comune.jam4d.info *.email.jam4d.info jam4d.info *.jam4d.info *.new.jam4d.info
*.1f56a483-3654-4d2f-b5ee-dce0e82a0f37.km13.pro km13.pro *.km13.pro *.sitemap.km13.pro *.ww38.km13.pro
*.demo.oky.bet oky.bet *.oky.bet *.yen.oky.bet
*.gtjjui.peczuwjs.com *.gtvvowu.peczuwjs.com *.gtvvvi.peczuwjs.com *.htijin.peczuwjs.com peczuwjs.com *.peczuwjs.com *.tysys.peczuwjs.com
*.app.sorairo.xyz *.cpanel.sorairo.xyz *.demo.sorairo.xyz *.ftp.sorairo.xyz *.mail.sorairo.xyz sorairo.xyz *.sorairo.xyz *.webmail.sorairo.xyz *.ww25.sorairo.xyz
templomasonico.info *.templomasonico.info *.ww38.templomasonico.info
thefappening.bet *.thefappening.bet *.ww38.thefappening.bet
*.com.vaidvan.com vaidvan.com *.vaidvan.com *.ww38.vaidvan.com
*.files.wordunlimited.org wordunlimited.org *.wordunlimited.org *.ww25.wordunlimited.org
*.analytics.ycmcard.com *.by.ycmcard.com *.cdn.ycmcard.com *.dev2.ycmcard.com *.old.ycmcard.com *.ru.ycmcard.com *.static.ycmcard.com *.users.ycmcard.com *.ww38.ycmcard.com ycmcard.com *.ycmcard.com