Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=goodhotel.it
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 18, 2026
Valid Until
September 16, 2026 85 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B1:00:23:EC:A6:05:21:20:87:90:0A:E6:C2:E1:A7:76:63:DE:F4:AD:E4:4A:4A:16:F8:07:03:CF:0A:8C:57:A8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
goodhotel.it *.goodhotel.it *.admin.goodhotel.it *.api.goodhotel.it *.app.goodhotel.it *.bi.goodhotel.it *.dashboard.goodhotel.it *.demo.goodhotel.it *.dev.goodhotel.it *.superset.goodhotel.it

Other domains in certificate

3wx1.vip *.3wx1.vip *.beta.3wx1.vip *.blog108.3wx1.vip *.blog129.3wx1.vip *.careers.3wx1.vip *.cpcontacts.3wx1.vip *.dashboards.3wx1.vip *.external.3wx1.vip *.genealogycanada.3wx1.vip *.login.3wx1.vip *.mandycheung66.3wx1.vip *.mlbs.3wx1.vip *.portal.3wx1.vip *.sharepoint.3wx1.vip *.sitemap.3wx1.vip *.sitemaps.3wx1.vip *.vip.3wx1.vip *.visual.3wx1.vip *.www.3wx1.vip *.wwww.3wx1.vip
*.admin.bestloancalculate.com *.app.bestloancalculate.com bestloancalculate.com *.bestloancalculate.com
betterbusinessbeauro.com *.betterbusinessbeauro.com *.ww16.betterbusinessbeauro.com *.ww38.betterbusinessbeauro.com
clubplus.com.au *.clubplus.com.au *.random.clubplus.com.au *.ww25.clubplus.com.au
*.admin.decoraciones.it *.backend.decoraciones.it *.bi.decoraciones.it decoraciones.it *.decoraciones.it *.random.decoraciones.it
*.cloud-x-21-srb.jiraleto.xyz jiraleto.xyz *.jiraleto.xyz
kart.run *.kart.run *.shop.kart.run
*.bnozgapi.my-dc.com *.ipv6.my-dc.com my-dc.com *.my-dc.com *.sitemaps.my-dc.com
*.assets.noyontaraserials.info *.members.noyontaraserials.info noyontaraserials.info *.noyontaraserials.info *.shop.noyontaraserials.info *.www.noyontaraserials.info
paradiseawaits.com *.paradiseawaits.com
poweredbymesh.com *.poweredbymesh.com *.zz690t.poweredbymesh.com
*.aaccup.prisms.online *.basc.prisms.online *.bsu.prisms.online *.earist.prisms.online *.ironman.prisms.online *.marsu.prisms.online *.marsuu.prisms.online *.mobilr.prisms.online *.msc.prisms.online *.pmaps.prisms.online *.pmasbulsu.prisms.online prisms.online *.prisms.online *.random.prisms.online *.unp.prisms.online *.ww25.prisms.online
*.m.youngconductors.org youngconductors.org *.youngconductors.org