76/100 SECURITY SCORE

Certificate Information

Subject
CN=crib.wtf
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 28, 2026
Valid Until
August 26, 2026 69 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
69:93:58:80:1A:1D:F7:B8:8A:99:4A:9C:ED:F5:55:A0:39:BD:96:5B:3F:39:6C:8E:4E:50:64:FB:BF:9B:F3:E4
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
improbabili.com *.improbabili.com *.admin.improbabili.com *.analytics.improbabili.com *.api.improbabili.com *.argo.improbabili.com *.backend.improbabili.com *.dashboard.improbabili.com *.data.improbabili.com *.demo.improbabili.com *.dev.improbabili.com *.intelligence.improbabili.com *.report.improbabili.com *.staging.improbabili.com *.superset.improbabili.com *.workflow.improbabili.com *.www.improbabili.com

Other domains in certificate

*.admin.buysale.net *.api.buysale.net *.app.buysale.net *.assets.buysale.net *.backend.buysale.net *.bbs.buysale.net buysale.net *.buysale.net *.chat.buysale.net *.docs.buysale.net *.external.buysale.net *.hostmaster.buysale.net *.intranet.buysale.net *.m.buysale.net *.mail.buysale.net *.ms1.buysale.net *.mx01.buysale.net *.mx7.buysale.net *.notexistsadmin.buysale.net *.notexistsapi.buysale.net *.notexistsbackend.buysale.net *.owa.buysale.net *.portal.buysale.net *.public.buysale.net *.random.buysale.net *.remote.buysale.net *.share.buysale.net *.sharepoint.buysale.net *.smtp.buysale.net *.vpn.buysale.net *.webmail.buysale.net *.www.buysale.net
crib.wtf *.crib.wtf *.members.crib.wtf
faresnipers.com *.faresnipers.com *.oqbmsschool.faresnipers.com
flinkee.com *.flinkee.com *.optube.flinkee.com
*.backup.maskedmaids.com *.hostmaster.maskedmaids.com *.intranet.maskedmaids.com maskedmaids.com *.maskedmaids.com *.share.maskedmaids.com *.uat.maskedmaids.com
*.api.nftworldgame.com nftworldgame.com *.nftworldgame.com *.portal.nftworldgame.com *.rdweb.nftworldgame.com *.remoto.nftworldgame.com *.test.nftworldgame.com *.ts.nftworldgame.com *.webvpn.nftworldgame.com
*.api.sditfatahillah-kebagusan.org *.app.sditfatahillah-kebagusan.org *.backup.sditfatahillah-kebagusan.org *.dev.sditfatahillah-kebagusan.org *.docs.sditfatahillah-kebagusan.org *.external.sditfatahillah-kebagusan.org *.intranet.sditfatahillah-kebagusan.org *.my.sditfatahillah-kebagusan.org *.portal.sditfatahillah-kebagusan.org sditfatahillah-kebagusan.org *.sditfatahillah-kebagusan.org *.share.sditfatahillah-kebagusan.org *.sharepoint.sditfatahillah-kebagusan.org *.staging.sditfatahillah-kebagusan.org *.uat.sditfatahillah-kebagusan.org