76/100 SECURITY SCORE

Certificate Information

Subject
CN=cryptosavvysch.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 23, 2026
Valid Until
August 21, 2026 64 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
8D:40:E6:2B:7F:0A:26:FE:4C:07:C6:D5:DE:CA:44:0C:7A:86:20:D0:0B:68:DF:4F:0D:AE:7B:4B:AD:97:43:46
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
cryptosavvysch.com *.cryptosavvysch.com *.5dcc3e03-2fef-416c-9a1d-10a95be04e2a.cryptosavvysch.com *.66de5eb0-1664-4a97-b1c9-622f4318d59a.cryptosavvysch.com *.api.cryptosavvysch.com *.app.cryptosavvysch.com *.bot.cryptosavvysch.com *.dev.cryptosavvysch.com *.ebecb7b4-26f0-4e36-ba14-bbc106edd273.cryptosavvysch.com *.gitlab.cryptosavvysch.com *.m.cryptosavvysch.com *.mail.cryptosavvysch.com *.new.cryptosavvysch.com *.vpn.cryptosavvysch.com

Other domains in certificate

*.analytics.bigreader.net *.api.bigreader.net *.bi-preview.bigreader.net *.bi.bigreader.net bigreader.net *.bigreader.net *.dashboard.bigreader.net *.data.bigreader.net *.demo.bigreader.net *.dev.bigreader.net *.m.bigreader.net *.mail.bigreader.net *.members.bigreader.net *.notexistsapp.bigreader.net *.notexistsbackend.bigreader.net *.notexistsdemo.bigreader.net *.notexistsdev.bigreader.net *.notexistsstaging.bigreader.net *.reporting.bigreader.net *.research.bigreader.net *.staging.bigreader.net *.superset-sandbox.bigreader.net *.test.bigreader.net *.uperset.bigreader.net *.vpn.bigreader.net *.www.bigreader.net
bizfundexperts.com *.bizfundexperts.com *.mail.bizfundexperts.com
*.42a86f5b-e411-4fee-bfcb-c32d5dde1e0b.insinkeator.com *.69a15dcd-c401-4fec-a391-b1385b982f2f.insinkeator.com *.8d8c9d1a-52b2-4400-b23e-ddf2a94bf8de.insinkeator.com *.a0fd2b18-c513-4409-8a77-098d73dc2b3a.insinkeator.com *.admin.insinkeator.com *.api.insinkeator.com *.app.insinkeator.com *.b83667a7-3f6f-4217-a1e3-011b4952ef58.insinkeator.com *.c6b02469-30ba-42b7-bc1d-99c0f91bf229.insinkeator.com *.cloud.insinkeator.com *.cpanel.insinkeator.com *.cpdz4kojsi.insinkeator.com *.d6a58cc3-f850-4f3f-8779-177d41424984.insinkeator.com *.demo.insinkeator.com *.dev.insinkeator.com *.docs.insinkeator.com *.eeguhnyuqard.insinkeator.com *.explore.insinkeator.com *.external.insinkeator.com *.ftp.insinkeator.com insinkeator.com *.insinkeator.com *.intranet.insinkeator.com *.localhost.insinkeator.com *.my.insinkeator.com *.notexistsadmin.insinkeator.com *.perm.insinkeator.com *.portal.insinkeator.com *.public.insinkeator.com *.random.insinkeator.com *.rd.insinkeator.com *.rds.insinkeator.com *.rdweb.insinkeator.com *.register.insinkeator.com *.remote.insinkeator.com *.share.insinkeator.com *.sharepoint.insinkeator.com *.shop.insinkeator.com *.staging.insinkeator.com *.store.insinkeator.com *.tubmxrd.insinkeator.com *.vpn.insinkeator.com *.webdisk.insinkeator.com *.ww1.insinkeator.com
wjplus01.com *.wjplus01.com *.ww38.wjplus01.com