76/100 SECURITY SCORE

Certificate Information

Subject
CN=tampahomehealthai.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 02, 2026
Valid Until
August 31, 2026 74 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
08:F0:1E:05:E8:22:2B:E5:D4:E8:28:80:E8:DA:EF:C4:9D:E8:1A:B4:52:DD:0E:5D:D8:33:6B:FD:3F:FB:C5:FC
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
franki-group.com *.franki-group.com *.0433fdd0-a045-4617-9bb4-0cb323e2757f.franki-group.com *.6tp0shvgsbnho2zuk92e0uo3r.franki-group.com *.admin.franki-group.com *.af290dff-c1a7-4910-9e9f-88a3a7f0dd0d.franki-group.com *.api.franki-group.com *.app.franki-group.com *.apps.franki-group.com *.assets.franki-group.com *.book.franki-group.com *.c33f17c2-3a80-4344-8199-43bd7ebbc9ef.franki-group.com *.chat.franki-group.com *.ckmprchat.franki-group.com *.cloud.franki-group.com *.cpanel.franki-group.com *.cpcontacts.franki-group.com *.crm.franki-group.com *.de.franki-group.com *.debisgcr.franki-group.com *.demo.franki-group.com *.dev.franki-group.com *.fr.franki-group.com *.home.franki-group.com *.hsbrlmxt.franki-group.com *.info.franki-group.com *.log.franki-group.com *.m.franki-group.com *.mta-sts.franki-group.com *.ns.franki-group.com *.old.franki-group.com *.pop.franki-group.com *.secure.franki-group.com *.staging.franki-group.com *.test.franki-group.com *.vpn.franki-group.com *.vpnsgyaj.franki-group.com *.webdisk.franki-group.com *.whm.franki-group.com *.wss.franki-group.com *.ww12.franki-group.com *.ww17.franki-group.com *.ww6.franki-group.com

Other domains in certificate

*.axyxvaging.hrwizard.tech hrwizard.tech *.hrwizard.tech *.test.hrwizard.tech
*.dev.lysti.io lysti.io *.lysti.io *.test.lysti.io
*.2298e1bc-f0d3-429e-be86-2a0a5dc75442.shuller.es *.a54a5e25-a9ed-41d4-af1f-6864f09fc10d.shuller.es *.admin.shuller.es *.dev.shuller.es *.intranet.shuller.es *.owa.shuller.es *.panel.shuller.es *.pop.shuller.es *.portal.shuller.es *.shop.shuller.es shuller.es *.shuller.es *.smtp.shuller.es *.store.shuller.es *.uaclxwtb.shuller.es *.webmail.shuller.es *.whm.shuller.es
*.admin.strangefish.art *.api.strangefish.art *.app.strangefish.art *.backend.strangefish.art *.d7crzm8vkpm9sof0.strangefish.art *.demo.strangefish.art *.dev.strangefish.art *.home.strangefish.art *.intranet.strangefish.art *.m.strangefish.art *.news.strangefish.art *.shop.strangefish.art strangefish.art *.strangefish.art *.wap.strangefish.art *.www.strangefish.art
tampahomehealthai.com *.tampahomehealthai.com
*.wildcard.xn--vox31bq54f.com *.www1.xn--vox31bq54f.com xn--vox31bq54f.com *.xn--vox31bq54f.com