76/100 SECURITY SCORE

Certificate Information

Subject
CN=thorplay.net
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 14, 2026
Valid Until
August 12, 2026 63 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
01:05:B9:AC:A2:E1:B0:85:77:45:A3:CD:60:FC:7F:2D:58:3B:17:57:3E:65:C7:7B:19:61:A5:65:38:EF:24:03
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
ninfea.it *.ninfea.it *.analytic.ninfea.it *.dashboard.ninfea.it *.dashs.ninfea.it *.db.ninfea.it *.development.ninfea.it *.ex02.ninfea.it *.exchange.ninfea.it *.hostmaster.ninfea.it *.mail3.ninfea.it *.mobileconnect.ninfea.it *.notexistsadmin.ninfea.it *.notexistsrd.ninfea.it *.owa.ninfea.it *.phpmyadmin.ninfea.it *.rd.ninfea.it *.rds.ninfea.it *.remote.ninfea.it *.reporting.ninfea.it *.superset.ninfea.it *.visual.ninfea.it

Other domains in certificate

8am.it *.8am.it *.hostmaster.8am.it *.peter.8am.it
amato.live *.amato.live
cable2095.cc *.cable2095.cc *.ww25.cable2095.cc
chestercodepromo.online *.chestercodepromo.online *.www.chestercodepromo.online
clientesyox.com *.clientesyox.com *.download.clientesyox.com *.hijodemo.clientesyox.com *.mail.clientesyox.com *.upick.clientesyox.com *.upickfund.clientesyox.com
cliphot18.net *.cliphot18.net *.sitemap.cliphot18.net *.www.cliphot18.net
*.dashboard.declutr.xyz declutr.xyz *.declutr.xyz *.ndwdadashboard.declutr.xyz *.ww38.declutr.xyz
*.32.elektricienvlaanderen.com elektricienvlaanderen.com *.elektricienvlaanderen.com
engagefurnishedfasten.com *.engagefurnishedfasten.com
*.fixed.kpn.life kpn.life *.kpn.life
pwerleads.com *.pwerleads.com
rabeaalkhaleej.com *.rabeaalkhaleej.com
*.comune.retrobarkz.com retrobarkz.com *.retrobarkz.com *.ww38.retrobarkz.com
savvy.onl *.savvy.onl *.sslvpn.savvy.onl
theolaybook.bet *.theolaybook.bet *.ww25.theolaybook.bet *.ww38.theolaybook.bet
thorplay.net *.thorplay.net *.ww25.thorplay.net *.www.thorplay.net
*.analytics.troppotardi.it *.app.troppotardi.it *.backend.troppotardi.it *.dashboards.troppotardi.it *.demo.troppotardi.it *.dev.troppotardi.it *.hostmaster.troppotardi.it *.metrics.troppotardi.it *.superset.troppotardi.it troppotardi.it *.troppotardi.it
wirefly.com.au *.wirefly.com.au