76/100 SECURITY SCORE

Certificate Information

Subject
CN=pureflix.co
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 09, 2026
Valid Until
May 10, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
09:73:B8:D5:59:17:94:A8:DB:8A:65:33:55:44:D6:1C:BB:FE:4F:40:31:4A:21:97:E4:2C:99:44:EA:C8:3C:DB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
girlsaway.com *.girlsaway.com *.admin.girlsaway.com *.api.girlsaway.com *.app.girlsaway.com *.backup.girlsaway.com *.beta.girlsaway.com *.blog.girlsaway.com *.crm.girlsaway.com *.demo.girlsaway.com *.dev.girlsaway.com *.forum.girlsaway.com *.forums.girlsaway.com *.help.girlsaway.com *.home.girlsaway.com *.hostmaster.girlsaway.com *.m.girlsaway.com *.mail.girlsaway.com *.mobile.girlsaway.com *.new.girlsaway.com *.news.girlsaway.com *.old.girlsaway.com *.remote.girlsaway.com *.shop.girlsaway.com *.sitemap.girlsaway.com *.sitemaps.girlsaway.com *.staging.girlsaway.com *.store.girlsaway.com *.temp.girlsaway.com *.test.girlsaway.com *.vpn.girlsaway.com *.wap.girlsaway.com *.web.girlsaway.com *.wiki.girlsaway.com *.www.girlsaway.com

Other domains in certificate

aapf-resources.com *.aapf-resources.com *.beacon.aapf-resources.com *.benefits.aapf-resources.com
*.1hp4ixudnf.abogadoenhouston.com abogadoenhouston.com *.abogadoenhouston.com *.admin.abogadoenhouston.com *.api.abogadoenhouston.com *.assets.abogadoenhouston.com *.demo.abogadoenhouston.com *.m.abogadoenhouston.com *.member.abogadoenhouston.com *.members.abogadoenhouston.com *.nisdxsitemaps.abogadoenhouston.com *.sitemap.abogadoenhouston.com *.sitemaps.abogadoenhouston.com *.test.abogadoenhouston.com *.ww1.abogadoenhouston.com *.ww16.abogadoenhouston.com *.ww17.abogadoenhouston.com
alfajormaradona.com *.alfajormaradona.com *.ww25.alfajormaradona.com
bomgosto.com.br *.bomgosto.com.br *.brww25.bomgosto.com.br *.ww38.bomgosto.com.br
flui.it *.flui.it
*.exchangecorp.genesissytems.com genesissytems.com *.genesissytems.com *.monitoring.genesissytems.com *.rds.genesissytems.com *.reporting.genesissytems.com *.sitemap.genesissytems.com *.sitemaps.genesissytems.com *.stats.genesissytems.com *.visual.genesissytems.com
*.every.moment.be moment.be *.moment.be
onlinefraudpreventionteam.com *.onlinefraudpreventionteam.com
*.hostmaster.pureflix.co pureflix.co *.pureflix.co
*.cpanel.ringtonedl.net *.mail.ringtonedl.net *.new.ringtonedl.net ringtonedl.net *.ringtonedl.net *.rock.ringtonedl.net *.us.ringtonedl.net