Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=hermossa.co.uk
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
December 19, 2025
Valid Until
March 19, 2026 34 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
79:78:0E:F4:D1:03:88:DD:04:14:A1:9D:51:2A:21:8C:7C:D1:A8:51:2D:70:17:88:24:25:B3:30:DD:0C:80:3E
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
nimas.com *.nimas.com *.com.nimas.com *.der.nimas.com *.facebook.nimas.com *.ftp.nimas.com *.gis.nimas.com *.isblaiv.nimas.com *.isblaivi.nimas.com *.random.nimas.com *.search.nimas.com *.site.nimas.com *.test.nimas.com *.users.nimas.com

Other domains in certificate

carptacklepoundshop.co.uk *.carptacklepoundshop.co.uk *.staging.carptacklepoundshop.co.uk *.staging1.carptacklepoundshop.co.uk *.staging5.carptacklepoundshop.co.uk
designasign.co.uk *.designasign.co.uk *.ebay.designasign.co.uk *.euro.designasign.co.uk *.random.designasign.co.uk *.staging.designasign.co.uk *.staging1.designasign.co.uk *.staging2.designasign.co.uk *.staging4.designasign.co.uk *.staging5.designasign.co.uk
englisch.de *.englisch.de *.grundschulmagazin.englisch.de *.lernt.englisch.de *.m.englisch.de
*.e.fordpro.co fordpro.co *.fordpro.co
*.cf.harrisoneyeclinic.co.uk harrisoneyeclinic.co.uk *.harrisoneyeclinic.co.uk *.staging.harrisoneyeclinic.co.uk *.staging1.harrisoneyeclinic.co.uk *.staging5.harrisoneyeclinic.co.uk
hermossa.co.uk *.hermossa.co.uk *.staging.hermossa.co.uk *.staging2.hermossa.co.uk *.staging3.hermossa.co.uk *.staging4.hermossa.co.uk *.staging6.hermossa.co.uk
poascotland.co.uk *.poascotland.co.uk *.poascotland.poascotland.co.uk *.staging.poascotland.co.uk *.staging1.poascotland.co.uk *.staging2.poascotland.co.uk *.staging4.poascotland.co.uk
*.dev.ppsnusa-link.com *.mail.ppsnusa-link.com ppsnusa-link.com *.ppsnusa-link.com *.qa.ppsnusa-link.com *.vpn.ppsnusa-link.com
*.credit-union.san-jose.tv *.radio.san-jose.tv *.random.san-jose.tv san-jose.tv *.san-jose.tv *.staging.san-jose.tv *.staging2.san-jose.tv *.ww25.san-jose.tv
tgtuve.com *.tgtuve.com *.ww25.tgtuve.com
*.sub.winx.bet winx.bet *.winx.bet *.www.winx.bet
*.byrd-name.wwwjj.com *.cloud.wwwjj.com *.com444hhh.wwwjj.com *.random.wwwjj.com *.ww.wwwjj.com wwwjj.com *.wwwjj.com
*.v3.zhongtong.sbs *.v5.zhongtong.sbs *.www.zhongtong.sbs zhongtong.sbs *.zhongtong.sbs