Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=fitguy-upscales.site
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 13, 2026
Valid Until
April 13, 2026
48 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FF:46:F8:DB:67:22:6A:E3:97:3C:3F:91:E1:43:AF:6F:6F:F9:BE:5B:90:E3:77:56:69:B1:7F:CE:2E:D7:E4:DC
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
cloudfly.me
*.cloudfly.me
*.bank.cloudfly.me
*.blog.cloudfly.me
*.api.bootesphotography.com
bootesphotography.com
*.bootesphotography.com
*.webmail.bootesphotography.com
*.ww25.bootesphotography.com
darawoodgroup.com
*.darawoodgroup.com
*.ww25.darawoodgroup.com
fitguy-upscales.site
*.fitguy-upscales.site
*.ww25.fitguy-upscales.site
hunters.studio
*.hunters.studio
*.pay.hunters.studio
*.ww25.hunters.studio
m88online.bet
*.m88online.bet
*.mail.m88online.bet
moto88.bet
*.moto88.bet
*.ww25.moto88.bet
*.ww38.moto88.bet
*.afyf.mp3-converter.xyz
*.av.mp3-converter.xyz
*.bhthp.mp3-converter.xyz
*.bhuns.mp3-converter.xyz
*.btppf.mp3-converter.xyz
*.chr.mp3-converter.xyz
*.cpcalendars.mp3-converter.xyz
*.ddx.mp3-converter.xyz
*.ekp.mp3-converter.xyz
*.fnsd.mp3-converter.xyz
*.ft.mp3-converter.xyz
*.gcu.mp3-converter.xyz
*.hlx.mp3-converter.xyz
*.irx.mp3-converter.xyz
*.khd.mp3-converter.xyz
*.lk.mp3-converter.xyz
*.llthl.mp3-converter.xyz
*.lmov.mp3-converter.xyz
mp3-converter.xyz
*.mp3-converter.xyz
*.mszwh.mp3-converter.xyz
*.mzm.mp3-converter.xyz
*.ndd.mp3-converter.xyz
*.nfggr.mp3-converter.xyz
*.ninoi.mp3-converter.xyz
*.okc.mp3-converter.xyz
*.oyq.mp3-converter.xyz
*.pmzfw.mp3-converter.xyz
*.ptl.mp3-converter.xyz
*.pwq.mp3-converter.xyz
*.qak.mp3-converter.xyz
*.qbzne.mp3-converter.xyz
*.qytgc.mp3-converter.xyz
*.rhul.mp3-converter.xyz
*.rvklx.mp3-converter.xyz
*.saaf.mp3-converter.xyz
*.tq.mp3-converter.xyz
*.unovp.mp3-converter.xyz
*.unugo.mp3-converter.xyz
*.uyvd.mp3-converter.xyz
*.verm.mp3-converter.xyz
*.vik.mp3-converter.xyz
*.wmpya.mp3-converter.xyz
*.ww25.mp3-converter.xyz
*.wyuty.mp3-converter.xyz
*.xdsou.mp3-converter.xyz
*.xgf.mp3-converter.xyz
*.xqyk.mp3-converter.xyz
*.zsnzg.mp3-converter.xyz
musicfree.io
*.musicfree.io
*.random.musicfree.io
*.ww25.musicfree.io
nordland.group
*.nordland.group
*.ww25.nordland.group
shababna-by2ra.info
*.shababna-by2ra.info
*.ww25.shababna-by2ra.info
sovegastro.com
*.sovegastro.com
*.wildcard.sovegastro.com
*.ww11.sovegastro.com
*.ww25.sovegastro.com
Other domains in certificate