Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=vina58okvip.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 26, 2026
Valid Until
August 24, 2026 72 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
AE:2D:B3:4A:71:F9:4E:2C:05:ED:DE:25:DD:B0:52:23:EB:46:80:2F:3E:9D:3D:C8:0B:F5:72:D9:CC:27:6F:0F
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
winbd.bz *.winbd.bz *.api.winbd.bz *.app.winbd.bz *.assets.winbd.bz *.dev.winbd.bz *.test.winbd.bz *.www.winbd.bz

Other domains in certificate

*.22e8a20c-b476-404a-9e07-2bb3aaee6303.corpotracker.com *.admin.corpotracker.com *.api.corpotracker.com *.app.corpotracker.com *.assets.corpotracker.com corpotracker.com *.corpotracker.com *.demo.corpotracker.com *.dev.corpotracker.com *.remote.corpotracker.com *.test.corpotracker.com *.vpn.corpotracker.com *.wwljgdev.corpotracker.com *.xibqfwwljgdev.corpotracker.com
coyot-e.com *.coyot-e.com *.dashboard.coyot-e.com *.qa.coyot-e.com *.stg.coyot-e.com
expediaaarp.org *.expediaaarp.org *.stage.expediaaarp.org
*.autoconfig.mymathplan.com *.boutique.mymathplan.com *.cloud.mymathplan.com *.ecfjhvpn.mymathplan.com *.ftp.mymathplan.com *.gitlab.mymathplan.com *.hostmaster.mymathplan.com *.ioymuecfjhvpn.mymathplan.com mymathplan.com *.mymathplan.com *.rds.mymathplan.com *.remote.mymathplan.com *.sitemap.mymathplan.com *.test.mymathplan.com *.vpn.mymathplan.com *.yfbvjftp.mymathplan.com
ondadate.com *.ondadate.com *.qoxz.ondadate.com
pilatesboston.com *.pilatesboston.com *.prod.pilatesboston.com
vina58okvip.com *.vina58okvip.com *.vpn.vina58okvip.com
*.access.visualtour.net *.analytics.visualtour.net *.anyconnect.visualtour.net *.api.visualtour.net *.app.visualtour.net *.apps.visualtour.net *.bi.visualtour.net *.connect.visualtour.net *.dashboard.visualtour.net *.demo.visualtour.net *.desktop.visualtour.net *.intelligence.visualtour.net *.login.visualtour.net *.metrics.visualtour.net *.owa.visualtour.net *.rd.visualtour.net *.remote.visualtour.net *.report.visualtour.net *.reports.visualtour.net *.secureaccess.visualtour.net *.ssl.visualtour.net *.staging.visualtour.net *.superset.visualtour.net *.supersets.visualtour.net visualtour.net *.visualtour.net *.vpn.visualtour.net *.web.visualtour.net *.webconnect.visualtour.net *.webvpn.visualtour.net *.www.visualtour.net
*.dev.winrealcashonlinecasino.top winrealcashonlinecasino.top *.winrealcashonlinecasino.top