76/100 SECURITY SCORE

Certificate Information

Subject
CN=laspisa.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 19, 2026
Valid Until
May 20, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1A:FF:49:43:29:89:0E:1D:75:09:BC:B1:64:D3:32:0B:F2:F4:9D:A0:ED:31:9B:58:7A:09:1B:47:DA:27:3F:00
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
loanholder.com *.loanholder.com *.admin.loanholder.com *.api.loanholder.com *.app.loanholder.com *.assets.loanholder.com *.backup.loanholder.com *.dashboard.loanholder.com *.demo.loanholder.com *.dev.loanholder.com *.ftp.loanholder.com *.hostmaster.loanholder.com *.m.loanholder.com *.mail.loanholder.com *.mailer.loanholder.com *.marketing.loanholder.com *.qa.loanholder.com *.secure.loanholder.com *.sitemaps.loanholder.com *.staging.loanholder.com *.stg.loanholder.com *.test.loanholder.com *.uat.loanholder.com *.v1.loanholder.com *.v2.loanholder.com *.web.loanholder.com *.ww17.loanholder.com *.ww25.loanholder.com *.ww41.loanholder.com

Other domains in certificate

*.admin.cinturon.com *.api.cinturon.com *.app.cinturon.com *.aumkacom.cinturon.com *.backup.cinturon.com *.blog.cinturon.com cinturon.com *.cinturon.com *.cloudvpn.cinturon.com *.com.cinturon.com *.dashboard.cinturon.com *.dev.cinturon.com *.hostmaster.cinturon.com *.mailer.cinturon.com *.marketing.cinturon.com *.qa.cinturon.com *.shop.cinturon.com *.sitemaps.cinturon.com *.staging.cinturon.com *.v1.cinturon.com *.web.cinturon.com *.ww11.cinturon.com *.ww16.cinturon.com *.ww38.cinturon.com
*.bk.excitinggardeningprojects.live excitinggardeningprojects.live *.excitinggardeningprojects.live
*.admin.laspisa.com *.api.laspisa.com *.app.laspisa.com *.demo.laspisa.com *.dev.laspisa.com *.hostmaster.laspisa.com laspisa.com *.laspisa.com *.shop.laspisa.com *.ww11.laspisa.com *.ww17.laspisa.com *.ww38.laspisa.com
*.ciscoasa.tupone.com *.email.tupone.com *.exchange.tupone.com *.hostmaster.tupone.com *.imap-mail.tupone.com *.imap.tupone.com *.imaps.tupone.com *.inbound.tupone.com *.m.tupone.com *.mail.tupone.com *.mx.tupone.com *.securemail.tupone.com tupone.com *.tupone.com *.ww1.tupone.com *.ww11.tupone.com *.ww16.tupone.com *.ww17.tupone.com *.ww25.tupone.com *.ww38.tupone.com *.ww5.tupone.com *.www.tupone.com