76/100 SECURITY SCORE

Certificate Information

Subject
CN=cafebonappetite.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 03, 2026
Valid Until
September 01, 2026 82 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
17:4D:69:B6:BF:78:9B:4E:83:C9:31:A1:35:57:10:57:81:67:72:69:43:C2:BB:C1:A3:2C:5E:24:C0:F3:FA:DB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

87 domains
trainrobotics.info *.trainrobotics.info *.11dfdc32-1736-4f0d-ae9d-f81d80eeff06.trainrobotics.info *.49eaaa88-8d57-4b6f-aad1-d05726184dec.trainrobotics.info *.a.trainrobotics.info *.admin.trainrobotics.info *.akf628.trainrobotics.info *.api.trainrobotics.info *.assets.trainrobotics.info *.bjkkromfqcakf628.trainrobotics.info *.dev.trainrobotics.info *.m.trainrobotics.info *.members.trainrobotics.info *.staging.trainrobotics.info *.test.trainrobotics.info *.www.trainrobotics.info

Other domains in certificate

598ii.com *.598ii.com *.ww17.598ii.com
*.board.cafebonappetite.com *.butler.cafebonappetite.com cafebonappetite.com *.cafebonappetite.com *.case.cafebonappetite.com *.cd.cafebonappetite.com *.dev.cafebonappetite.com *.kaiser.cafebonappetite.com *.mayoclinicphoenix.cafebonappetite.com *.openai.cafebonappetite.com *.payless.cafebonappetite.com *.prod.cafebonappetite.com *.recursion.cafebonappetite.com *.reed.cafebonappetite.com *.rz.cafebonappetite.com *.westminster.cafebonappetite.com *.ww1.cafebonappetite.com
*.andy.citiecards.com citiecards.com *.citiecards.com *.random.citiecards.com
*.admin.cleardcore.com *.apps.cleardcore.com cleardcore.com *.cleardcore.com *.login.cleardcore.com *.m.cleardcore.com *.vpn.cleardcore.com *.www.cleardcore.com
ecstudyabroad.net *.ecstudyabroad.net *.www.ecstudyabroad.net
fbstream.com *.fbstream.com *.random.fbstream.com
*.api.hyaal.com *.apps.hyaal.com *.cloud.hyaal.com *.f.hyaal.com hyaal.com *.hyaal.com *.mail.hyaal.com *.rdp.hyaal.com *.rds1.hyaal.com *.rdweb.hyaal.com *.remote.hyaal.com *.sslvpn.hyaal.com *.ts.hyaal.com *.vpn.hyaal.com *.webvpn.hyaal.com *.xhcm.hyaal.com
kidsrockintreehouse.com *.kidsrockintreehouse.com *.test.kidsrockintreehouse.com
nhla.nl *.nhla.nl
*.dashboard.november.com.au *.mail.november.com.au november.com.au *.november.com.au *.smtpauth.november.com.au
*.cloud.startkitai.com *.demo.startkitai.com startkitai.com *.startkitai.com
*.ww38.yeomans-nissan.co.uk yeomans-nissan.co.uk *.yeomans-nissan.co.uk