76/100 SECURITY SCORE

Certificate Information

Subject
CN=weretherefirst.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 13, 2026
Valid Until
August 11, 2026 82 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
78:31:E8:44:71:E3:83:6C:E0:1E:BF:32:A9:A2:72:A8:07:AC:73:55:B0:C8:A6:BB:64:7C:FF:28:DB:66:C8:E7
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
daqingzhan.com *.daqingzhan.com *.api.daqingzhan.com *.app.daqingzhan.com *.ci.daqingzhan.com *.crm.daqingzhan.com *.elearning.daqingzhan.com *.fcca5428-c93e-43f6-90d1-35722c576a0a.daqingzhan.com *.home.daqingzhan.com *.hostmaster.daqingzhan.com *.rd.daqingzhan.com *.rdweb.daqingzhan.com *.ssp.daqingzhan.com *.staging.daqingzhan.com *.uat.daqingzhan.com *.www.daqingzhan.com

Other domains in certificate

65362.my *.65362.my
68277.me *.68277.me
acquisitionbond.com *.acquisitionbond.com *.agent.acquisitionbond.com *.m.acquisitionbond.com *.www.acquisitionbond.com
actuemosya.org *.actuemosya.org
appliances-flower-707.sbs *.appliances-flower-707.sbs
b67u.cyou *.b67u.cyou
bee85.icu *.bee85.icu
claritas.it *.claritas.it
dental-impl-dorosh.click *.dental-impl-dorosh.click
derby.vc *.derby.vc
dhhph505pm.xyz *.dhhph505pm.xyz
digitalsignageserver.com *.digitalsignageserver.com
divadrrepair.com *.divadrrepair.com
ecohelpers.world *.ecohelpers.world
growthsystemsnetwork.co *.growthsystemsnetwork.co *.www.growthsystemsnetwork.co
*.32.latchkey.life latchkey.life *.latchkey.life
*.nktjv.nzgze78k3u.xyz nzgze78k3u.xyz *.nzgze78k3u.xyz
*.cn.sportmedicine.cn sportmedicine.cn *.sportmedicine.cn
*.ns1.tray.com.au tray.com.au *.tray.com.au *.ww25.tray.com.au
vbknusp448.vip *.vbknusp448.vip
vehuz.com *.vehuz.com
veksus.com *.veksus.com
vlucky7.biz *.vlucky7.biz
weretherefirst.com *.weretherefirst.com
wlykbj.work *.wlykbj.work
womenliterature.click *.womenliterature.click
*.autodiscover.wxpay.co *.hostmaster.wxpay.co *.webmail.wxpay.co wxpay.co *.wxpay.co
youflow.co *.youflow.co
zamowienie-alm44xqv2dlf0znb86ryp1.onl *.zamowienie-alm44xqv2dlf0znb86ryp1.onl
*.0l5lrh.zz7878.vip zz7878.vip *.zz7878.vip