Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=matrixphysiotherapy.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 09, 2026
Valid Until
April 09, 2026 56 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5F:50:34:AB:2A:DC:E3:16:CA:AB:B5:BE:11:68:F6:A4:2C:BD:43:F6:D0:8F:07:51:81:29:51:3E:F0:46:2E:CF
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
cornholeshop.com *.cornholeshop.com *.old.cornholeshop.com *.ww17.cornholeshop.com *.ww38.cornholeshop.com

Other domains in certificate

9zh658w3.online *.9zh658w3.online *.random.9zh658w3.online *.ww.9zh658w3.online *.ww38.9zh658w3.online
*.acculance.afandi.store afandi.store *.afandi.store *.odoo.afandi.store *.zaid.afandi.store
*.hostmaster.iglesialamonserrate.org iglesialamonserrate.org *.iglesialamonserrate.org *.mail.iglesialamonserrate.org *.www.iglesialamonserrate.org
insuranceforsemitruck610467.icu *.insuranceforsemitruck610467.icu
*.auv.ironbomb.pl *.hwt.ironbomb.pl *.imnop.ironbomb.pl ironbomb.pl *.ironbomb.pl *.mgzqp.ironbomb.pl
*.indo-china.malaya.au malaya.au *.malaya.au *.mchaw.malaya.au *.mimi.malaya.au *.mimini.malaya.au *.mm.malaya.au *.umenionamm.malaya.au
*.cpcontacts.matrixphysiotherapy.com *.ftp.matrixphysiotherapy.com matrixphysiotherapy.com *.matrixphysiotherapy.com
nrtv.live *.nrtv.live *.www.nrtv.live
pettydom.store *.pettydom.store *.ww38.pettydom.store
pfbrduwa.website *.pfbrduwa.website *.random.pfbrduwa.website *.ww25.pfbrduwa.website
prostatetreatment474235.icu *.prostatetreatment474235.icu *.ww25.prostatetreatment474235.icu
*.admin.skinceutical.online *.alpha.skinceutical.online *.api.skinceutical.online *.cicd.skinceutical.online *.demo.skinceutical.online *.dev.skinceutical.online *.n0rm6k5ymwdprg3h.skinceutical.online *.pipeline.skinceutical.online *.production.skinceutical.online skinceutical.online *.skinceutical.online *.staging.skinceutical.online *.test-ci.skinceutical.online *.test-cicd.skinceutical.online *.test.skinceutical.online *.www.skinceutical.online
*.comune.therunningworks.net *.hub.therunningworks.net *.m2.therunningworks.net *.mx.therunningworks.net *.staging.therunningworks.net therunningworks.net *.therunningworks.net *.ww38.therunningworks.net
*.random.warungwifi.net *.server.warungwifi.net *.srv1.warungwifi.net *.srv2.warungwifi.net *.twospace.warungwifi.net warungwifi.net *.warungwifi.net
*.mailserver.zona.au *.random.zona.au *.ww25.zona.au zona.au *.zona.au