Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=wintertime.live
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 05, 2026
Valid Until
April 05, 2026
55 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DC:FC:61:B8:E3:C8:EB:3B:B7:D3:CD:ED:D4:06:BC:5A:32:96:A6:DA:53:CD:15:EE:4D:80:1C:A7:5B:31:D8:F0
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
77 domains
chri-eitor.studio
*.chri-eitor.studio
*.webmail.chri-eitor.studio
789club.cm
*.789club.cm
*.ww16.789club.cm
*.ww25.789club.cm
baghdadstylestreet.com
*.baghdadstylestreet.com
*.ww25.baghdadstylestreet.com
bnbscan.io
*.bnbscan.io
*.www.bnbscan.io
burtsnowshop.com
*.burtsnowshop.com
*.35009bb9-f0b2-4fc2-b5a8-eddeefa89f36.callsherni.xyz
*.autoconfig.callsherni.xyz
callsherni.xyz
*.callsherni.xyz
*.com.callsherni.xyz
cher.live
*.cher.live
*.does.cher.live
chillingoffers.click
*.chillingoffers.click
*.ww25.chillingoffers.click
*.ww38.chillingoffers.click
nem.com.pl
*.nem.com.pl
drivenowfl.net
*.drivenowfl.net
gba852.store
*.gba852.store
*.m.gba852.store
iinsha.xyz
*.iinsha.xyz
*.shop.iinsha.xyz
*.ww25.iinsha.xyz
kizi.cm
*.kizi.cm
ostreszachy.pl
*.ostreszachy.pl
paulhuntpornhouse.com
*.paulhuntpornhouse.com
*.ww38.paulhuntpornhouse.com
programfiles.ro
*.programfiles.ro
*.ww16.programfiles.ro
scooperdoop.io
*.scooperdoop.io
seaprovideremainrapid.click
*.seaprovideremainrapid.click
secrdexter1or.icu
*.secrdexter1or.icu
*.ww25.secrdexter1or.icu
*.cpanel.serenity4.click
serenity4.click
*.serenity4.click
*.sitemap.serenity4.click
*.123.sirene.store
sirene.store
*.sirene.store
*.1b.trt.guru
*.1n.trt.guru
trt.guru
*.trt.guru
unlochhere.com
*.unlochhere.com
*.story.viralvideosmms.online
viralvideosmms.online
*.viralvideosmms.online
visitoceansidelaw.com
*.visitoceansidelaw.com
wintertime.live
*.wintertime.live
zakariyaoukaka.site
*.zakariyaoukaka.site
Other domains in certificate