Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=ecologycourse.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 04, 2026
Valid Until
September 02, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
62:13:D4:2C:F3:FB:22:0B:55:0F:04:06:62:E4:C3:34:94:56:AE:2E:CB:BC:06:9F:86:8B:7E:38:B5:68:3E:0B
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
ecologycourse.com *.ecologycourse.com *.api.ecologycourse.com *.app.ecologycourse.com *.assets.ecologycourse.com *.backend.ecologycourse.com *.backup.ecologycourse.com *.blog.ecologycourse.com *.demo.ecologycourse.com *.dumvranp.ecologycourse.com *.hostmaster.ecologycourse.com *.kmz.ecologycourse.com *.mail.ecologycourse.com *.mailer.ecologycourse.com *.qa.ecologycourse.com *.remote.ecologycourse.com *.shop.ecologycourse.com *.sitemaps.ecologycourse.com *.staging.ecologycourse.com *.stg.ecologycourse.com *.test.ecologycourse.com *.twbejm.ecologycourse.com *.uat.ecologycourse.com *.v1.ecologycourse.com *.v2.ecologycourse.com *.vmbxgauk.ecologycourse.com *.web.ecologycourse.com *.www.ecologycourse.com

Other domains in certificate

*.1d817.an99.cfd *.3ugcn.an99.cfd *.4yj7f.an99.cfd *.5qutp.an99.cfd *.6cd9j.an99.cfd *.87ab5.an99.cfd *.8r9pg.an99.cfd *.95lw2.an99.cfd *.admin.an99.cfd *.ahomwnan1j.an99.cfd an99.cfd *.an99.cfd *.aowpq.an99.cfd *.api.an99.cfd *.app.an99.cfd *.assets.an99.cfd *.auth.an99.cfd *.ayfpk.an99.cfd *.blog.an99.cfd *.bujvnww16.an99.cfd *.civoh.an99.cfd *.demo.an99.cfd *.dev.an99.cfd *.dn930.an99.cfd *.fu1fc.an99.cfd *.g89kw.an99.cfd *.game.an99.cfd *.ghtlpuwopxapp.an99.cfd *.home.an99.cfd *.i51qg.an99.cfd *.iovou.an99.cfd *.jmgeih.an99.cfd *.m.an99.cfd *.mail3.an99.cfd *.mailin.an99.cfd *.ms.an99.cfd *.my.an99.cfd *.nan1j.an99.cfd *.ndifg.an99.cfd *.nemln.an99.cfd *.new.an99.cfd *.nfszsahomwnan1j.an99.cfd *.qk6fu.an99.cfd *.rnyzj.an99.cfd *.rustore.an99.cfd *.s5kjz.an99.cfd *.shop.an99.cfd *.test.an99.cfd *.tpxa3.an99.cfd *.uhrnfrnyzj.an99.cfd *.uw9i.an99.cfd *.uwopxapp.an99.cfd *.vpn.an99.cfd *.webmail.an99.cfd *.ww1.an99.cfd *.ww16.an99.cfd *.ww6.an99.cfd *.z4gbs.an99.cfd *.zimbra.an99.cfd *.zruod.an99.cfd