76/100 SECURITY SCORE

Certificate Information

Subject
CN=theknowledgehut.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 05, 2026
Valid Until
May 06, 2026 79 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
22:35:CA:2D:FF:B9:C4:52:16:BF:9E:0A:74:4B:77:AF:FB:E6:3C:A0:77:F2:59:B3:2D:EA:87:77:25:05:4C:69
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
vandoni.com *.vandoni.com *.app.vandoni.com *.assets.vandoni.com *.gateway.vandoni.com *.marketing.vandoni.com *.rdp.vandoni.com *.ts.vandoni.com

Other domains in certificate

*.aididmuaddib.donateillinois.com *.amwekdev.donateillinois.com *.app.donateillinois.com *.arrumadissimoecia.donateillinois.com *.asbyte.donateillinois.com *.brl-cyber.donateillinois.com *.centerville.donateillinois.com *.coldfusion.donateillinois.com *.conte.donateillinois.com donateillinois.com *.donateillinois.com *.heisenberg.donateillinois.com *.terpss.donateillinois.com *.topgans.donateillinois.com
*.a2.geving.com *.a4.geving.com *.desktop.geving.com geving.com *.geving.com *.pro.geving.com *.ww38.geving.com
*.api.senarath.com *.app.senarath.com *.du.senarath.com senarath.com *.senarath.com *.support.senarath.com
*.archive.theknowledgehut.com *.nwkmcnptghlegnearchive.theknowledgehut.com *.rpmsrstaging.theknowledgehut.com theknowledgehut.com *.theknowledgehut.com
*.app.thomsongrassvalley.com *.collaborate.thomsongrassvalley.com *.desktop.thomsongrassvalley.com thomsongrassvalley.com *.thomsongrassvalley.com *.ww.thomsongrassvalley.com
*.analytic.weedtexas.shop *.asdfd.weedtexas.shop *.aua.weedtexas.shop *.bbx.weedtexas.shop *.cabak.weedtexas.shop *.cpcalendars.weedtexas.shop *.dah.weedtexas.shop *.fhkkf.weedtexas.shop *.godhy.weedtexas.shop *.iam.weedtexas.shop *.lzil.weedtexas.shop *.mcnvc.weedtexas.shop *.notexistswak.weedtexas.shop *.nrjme.weedtexas.shop *.nwivg.weedtexas.shop *.olnu.weedtexas.shop *.qjnk.weedtexas.shop *.superset.weedtexas.shop *.tpid.weedtexas.shop *.ufhbff.weedtexas.shop *.usnskk.weedtexas.shop weedtexas.shop *.weedtexas.shop *.wvjial.weedtexas.shop
*.m1.wgqqcru.com *.m10.wgqqcru.com *.m11.wgqqcru.com *.m15.wgqqcru.com *.m16.wgqqcru.com *.m20.wgqqcru.com *.m23.wgqqcru.com *.m24.wgqqcru.com *.m31.wgqqcru.com *.m33.wgqqcru.com *.m34.wgqqcru.com *.m36.wgqqcru.com *.m37.wgqqcru.com *.m38.wgqqcru.com *.m42.wgqqcru.com *.m5.wgqqcru.com *.m6.wgqqcru.com *.m7.wgqqcru.com wgqqcru.com *.wgqqcru.com