76/100 SECURITY SCORE

Certificate Information

Subject
CN=crop.wtf
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 04, 2026
Valid Until
September 02, 2026 81 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
86:97:6E:8F:CB:ED:91:90:54:F9:52:01:76:B6:13:D3:6E:A4:52:70:AB:9B:D2:AA:85:66:F9:FF:7B:E5:76:30
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
crushedring.com *.crushedring.com *.admin.crushedring.com *.api.crushedring.com *.app.crushedring.com *.assets.crushedring.com *.demo.crushedring.com *.dev.crushedring.com *.test.crushedring.com *.vpn.crushedring.com

Other domains in certificate

*.apply.ceocfoinfobiz.com *.aws.ceocfoinfobiz.com *.backend.ceocfoinfobiz.com *.business.ceocfoinfobiz.com ceocfoinfobiz.com *.ceocfoinfobiz.com *.chat.ceocfoinfobiz.com *.checkout.ceocfoinfobiz.com *.cloud.ceocfoinfobiz.com *.console.ceocfoinfobiz.com *.cpcalendars.ceocfoinfobiz.com *.cpcontacts.ceocfoinfobiz.com *.ecommerce.ceocfoinfobiz.com *.game.ceocfoinfobiz.com *.lms.ceocfoinfobiz.com *.local.ceocfoinfobiz.com *.play.ceocfoinfobiz.com *.prod.ceocfoinfobiz.com *.projects.ceocfoinfobiz.com *.school.ceocfoinfobiz.com *.secure.ceocfoinfobiz.com *.test.ceocfoinfobiz.com *.webdisk.ceocfoinfobiz.com
*.backup.crop.wtf crop.wtf *.crop.wtf *.demo.crop.wtf *.dev.crop.wtf *.dtvbkyni.crop.wtf *.mail.crop.wtf *.marketing.crop.wtf *.new.crop.wtf *.nvplrapp.crop.wtf *.qa.crop.wtf *.rigetchcqfuat.crop.wtf *.secure.crop.wtf *.staging.crop.wtf *.stg.crop.wtf *.test.crop.wtf *.uat.crop.wtf *.v1.crop.wtf *.web.crop.wtf
*.00131a19-ff78-488e-80d5-87e50e5a2882.seoboost.digital *.1.seoboost.digital *.admin.seoboost.digital *.alemtat.seoboost.digital *.animals-travel.seoboost.digital *.api.seoboost.digital *.app.seoboost.digital *.arca.seoboost.digital *.aviasales.seoboost.digital *.backup.seoboost.digital *.blog.seoboost.digital *.bts.seoboost.digital *.demirbank.seoboost.digital *.demo.seoboost.digital *.dostavka.seoboost.digital *.events.seoboost.digital *.forum.seoboost.digital *.kaspi.seoboost.digital *.mailex.seoboost.digital *.members.seoboost.digital *.ostrovok.seoboost.digital *.ozon.seoboost.digital *.partners.seoboost.digital *.personal.seoboost.digital seoboost.digital *.seoboost.digital *.server.seoboost.digital *.smtp.seoboost.digital *.staging.seoboost.digital *.stats.seoboost.digital *.tbank.seoboost.digital *.test.seoboost.digital *.uat.seoboost.digital *.upload.seoboost.digital *.vps.seoboost.digital *.webmail.seoboost.digital *.ww.seoboost.digital *.www.seoboost.digital