76/100 SECURITY SCORE

Certificate Information

Subject
CN=apexadventuretravel.xyz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 04, 2026
Valid Until
August 02, 2026 78 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
82:DE:0B:B0:67:97:1B:97:00:7C:B8:80:4E:D7:3F:36:8D:8E:D2:60:48:71:1A:45:EC:C8:20:19:67:0A:2D:BB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
imobiliarias.it *.imobiliarias.it *.api.imobiliarias.it *.backend.imobiliarias.it *.demo.imobiliarias.it *.dev.imobiliarias.it *.staging.imobiliarias.it

Other domains in certificate

77betcom.bet *.77betcom.bet *.ww38.77betcom.bet
*.0cf4f8a6-d53f-4d7c-b9fe-80727b6b70a1.apexadventuretravel.xyz *.1846m.apexadventuretravel.xyz *.60t9v.apexadventuretravel.xyz *.6cd9j.apexadventuretravel.xyz *.97e4155f-39d0-4923-ac13-7ad287f7c884.apexadventuretravel.xyz *.ahepckac0t.apexadventuretravel.xyz apexadventuretravel.xyz *.apexadventuretravel.xyz *.aqzmk.apexadventuretravel.xyz *.cc2mm.apexadventuretravel.xyz *.dashboard.apexadventuretravel.xyz *.jeikocc2mm.apexadventuretravel.xyz *.ndifg.apexadventuretravel.xyz *.nemln.apexadventuretravel.xyz *.ootbp.apexadventuretravel.xyz *.osc36.apexadventuretravel.xyz *.q2s8t.apexadventuretravel.xyz *.secure.apexadventuretravel.xyz *.snx68.apexadventuretravel.xyz *.stg.apexadventuretravel.xyz *.tpxa3.apexadventuretravel.xyz *.uat.apexadventuretravel.xyz *.v3ywp.apexadventuretravel.xyz *.wakkl.apexadventuretravel.xyz
brendhina.live *.brendhina.live
*.admin.egisp.com egisp.com *.egisp.com *.mail.egisp.com *.ns1.egisp.com *.ns2.egisp.com *.srv.egisp.com *.wp.egisp.com *.www.egisp.com
*.ar.flagofnepal.com *.blog.flagofnepal.com *.chat.flagofnepal.com *.demo.flagofnepal.com flagofnepal.com *.flagofnepal.com *.help.flagofnepal.com *.mobile.flagofnepal.com *.movies.flagofnepal.com *.news.flagofnepal.com *.office.flagofnepal.com *.origin.flagofnepal.com *.portfolio.flagofnepal.com *.rss.flagofnepal.com *.ru.flagofnepal.com *.sandbox.flagofnepal.com *.se.flagofnepal.com *.sms.flagofnepal.com *.spb.flagofnepal.com *.tampa.flagofnepal.com *.update.flagofnepal.com
punnoboti.com *.punnoboti.com *.ww25.punnoboti.com
*.3d4b449a-6f01-47ba-b6bd-040828f10d1d.qwikqwot.com *.a4c478e9-f790-4f14-8c37-855f0d6e38b1.qwikqwot.com *.admin.qwikqwot.com *.api.qwikqwot.com *.app.qwikqwot.com *.assets.qwikqwot.com *.auth.qwikqwot.com *.cloud.qwikqwot.com *.demo.qwikqwot.com *.dev.qwikqwot.com qwikqwot.com *.qwikqwot.com *.rd.qwikqwot.com *.remote.qwikqwot.com *.testing.qwikqwot.com *.www.qwikqwot.com
*.checkout.wapo.it *.owa.wapo.it wapo.it *.wapo.it *.www.wapo.it