76/100 SECURITY SCORE

Certificate Information

Subject
CN=splendidgardenpath.live
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 11, 2026
Valid Until
May 12, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
39:62:DA:1B:C6:7D:CA:1C:0D:7B:1A:F1:6E:12:E9:70:4D:30:7E:1B:C7:8D:1F:36:FD:2D:8B:F1:27:9A:FF:4A
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
gonflable.com *.gonflable.com *.api.gonflable.com *.cairn.gonflable.com *.dev.gonflable.com *.mail.gonflable.com *.test.gonflable.com

Other domains in certificate

*.1j.9yo.co 9yo.co *.9yo.co
*.aptest.chicagotemple.com *.backup.chicagotemple.com chicagotemple.com *.chicagotemple.com *.forum.chicagotemple.com *.hostmaster.chicagotemple.com *.impsat.chicagotemple.com *.pay.chicagotemple.com *.sharepoint.chicagotemple.com *.telefonia.chicagotemple.com *.wildcard.chicagotemple.com *.ww43.chicagotemple.com
distribute.au *.distribute.au
*.api.gptpublishers.com gptpublishers.com *.gptpublishers.com *.staging.gptpublishers.com
*.ai.hostinggratisbrasil.com *.anxiety.hostinggratisbrasil.com *.dev.hostinggratisbrasil.com *.flowise.hostinggratisbrasil.com *.goodcat.hostinggratisbrasil.com hostinggratisbrasil.com *.hostinggratisbrasil.com *.kookser.hostinggratisbrasil.com *.kwowukxa.hostinggratisbrasil.com *.pipeline.hostinggratisbrasil.com *.tdtuamo.hostinggratisbrasil.com *.tibuogoz.hostinggratisbrasil.com *.womamalimi.hostinggratisbrasil.com *.zzizlita.hostinggratisbrasil.com
mymetriclaim.com *.mymetriclaim.com
perfumetics.com *.perfumetics.com
propel.au *.propel.au
*.63a80507-6bef-4404-af2a-12011d60d220.puregrowthproject.com *.backup.puregrowthproject.com *.beta.puregrowthproject.com *.bgptools-wildcard-confirmed.puregrowthproject.com *.cpanel.puregrowthproject.com *.dashboard.puregrowthproject.com *.m.puregrowthproject.com *.members.puregrowthproject.com *.mta-sts.puregrowthproject.com *.old.puregrowthproject.com *.pnhumfirewall.puregrowthproject.com puregrowthproject.com *.puregrowthproject.com *.share.puregrowthproject.com *.staging.puregrowthproject.com *.test.puregrowthproject.com *.web.puregrowthproject.com *.webdisk.puregrowthproject.com *.webmail.puregrowthproject.com *.ww1.puregrowthproject.com
sadovodstvo.pro *.sadovodstvo.pro
schatzenfrequenz.at *.schatzenfrequenz.at
*.98120589-d297-4e59-99f5-07c8ddf2557c.sfbayviews.com *.portal.sfbayviews.com *.qa.sfbayviews.com *.sber.sfbayviews.com *.secure1.sfbayviews.com sfbayviews.com *.sfbayviews.com *.staging.sfbayviews.com *.webmail3.sfbayviews.com *.webstore.sfbayviews.com *.wildcard.sfbayviews.com
*.portal.splendidgardenpath.live splendidgardenpath.live *.splendidgardenpath.live
*.admin.xtgpay.cc *.api.xtgpay.cc xtgpay.cc *.xtgpay.cc