76/100 SECURITY SCORE

Certificate Information

Subject
CN=weldraum.de
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 19, 2026
Valid Until
May 20, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
71:6D:C9:1E:86:5B:A6:66:C3:60:0C:87:D8:8C:A9:49:8D:1A:D0:35:9A:0C:5B:FF:2C:7B:84:08:B2:3F:23:A4
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

68 domains
supplement.net *.supplement.net *.activity.supplement.net *.algorand.supplement.net *.anti.supplement.net *.automated.supplement.net *.avalanche.supplement.net *.blockchain.supplement.net *.cardano.supplement.net *.cex.supplement.net *.cft.supplement.net *.chainlink.supplement.net *.cold.supplement.net *.computation.supplement.net *.corda.supplement.net *.cosmos.supplement.net *.ctr.supplement.net *.currency.supplement.net *.distributed.supplement.net *.dlt.supplement.net *.ethereum.supplement.net *.farming.supplement.net *.financing.supplement.net *.finastra.supplement.net *.fis.supplement.net *.fiserv.supplement.net *.fix.supplement.net *.fpml.supplement.net *.hardware.supplement.net *.hashgraph.supplement.net *.hedera.supplement.net *.hot.supplement.net *.hsm.supplement.net *.hyperledger.supplement.net *.iso20022.supplement.net *.jack-henry.supplement.net *.laundering.supplement.net *.liquidity.supplement.net *.mastercard.supplement.net *.module.supplement.net *.monitoring.supplement.net *.mpc.supplement.net *.multiparty.supplement.net *.near.supplement.net *.ofac.supplement.net *.polkadot.supplement.net *.polygon.supplement.net *.quorum.supplement.net *.ripple.supplement.net *.sanctions.supplement.net *.sap-banking.supplement.net *.sar.supplement.net *.screening.supplement.net *.sepa.supplement.net *.software.supplement.net *.stellar.supplement.net *.terrorism.supplement.net *.visa.supplement.net *.yield.supplement.net *.your.supplement.net

Other domains in certificate

aiserver.co.uk *.aiserver.co.uk
belnzt.be *.belnzt.be
weldraum.de *.weldraum.de
xn--wrmemenge-v2a.de *.xn--wrmemenge-v2a.de