Open
Cached
·
just now
91/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=finio.co
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 13, 2026
Valid Until
July 12, 2026
67 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
14:70:76:0F:2A:31:27:C5:0D:B9:18:61:7D:4A:E3:BC:53:57:69:8A:51:8D:A3:FD:3D:D9:03:F0:90:8E:31:4B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000; includeSubDomains; preload
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin
Permissions-Policy
Present
geolocation=(), midi=(), sync-xhr=(); +6 more
Recommendations
- • Add Content-Security-Policy header to prevent XSS attacks
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
ethwmine.com
*.ethwmine.com
*.iceberg.ethwmine.com
*.next.ethwmine.com
*.admin.afriherbalcosmetics.com
afriherbalcosmetics.com
*.afriherbalcosmetics.com
*.cpcalendars.afriherbalcosmetics.com
*.ww25.afriherbalcosmetics.com
*.ww38.afriherbalcosmetics.com
*.www.afriherbalcosmetics.com
*.api.ettaro.it
ettaro.it
*.ettaro.it
*.hostmaster.ettaro.it
*.losco.ettaro.it
*.loscop.ettaro.it
*.staging.ettaro.it
*.admin.finio.co
finio.co
*.finio.co
*.www.finio.co
floristeriabogota.online
*.floristeriabogota.online
live-sport-streams.com
*.live-sport-streams.com
*.mail.live-sport-streams.com
*.avito.lrev.dev
lrev.dev
*.lrev.dev
*.prod.lrev.dev
*.rustore.lrev.dev
*.fr.manatoki305.net
manatoki305.net
*.manatoki305.net
*.office.manatoki305.net
*.vpn.manatoki305.net
pbaiaiyu.xyz
*.pbaiaiyu.xyz
*.wildcard.pbaiaiyu.xyz
*.ww25.pbaiaiyu.xyz
*.ww38.pbaiaiyu.xyz
premyur.click
*.premyur.click
*.app.puertasdeseguridad.net
*.checkout.puertasdeseguridad.net
*.cpcalendars.puertasdeseguridad.net
*.cpcontacts.puertasdeseguridad.net
puertasdeseguridad.net
*.puertasdeseguridad.net
*.sitemap.puertasdeseguridad.net
*.sitemaps.puertasdeseguridad.net
*.support.puertasdeseguridad.net
*.webdisk.puertasdeseguridad.net
*.www.puertasdeseguridad.net
*.mail.restituire.it
restituire.it
*.restituire.it
*.a.tapcheckhr.com
*.admin.tapcheckhr.com
*.app.tapcheckhr.com
*.dan.tapcheckhr.com
*.demo.tapcheckhr.com
*.git.tapcheckhr.com
*.mrcxscloud.tapcheckhr.com
*.mymail.tapcheckhr.com
*.remote.tapcheckhr.com
*.sip.tapcheckhr.com
*.sitemaps.tapcheckhr.com
tapcheckhr.com
*.tapcheckhr.com
*.wcfwzrds.tapcheckhr.com
*.www.tapcheckhr.com
*.ovbniwjqhlfzsn.tjaplt.cn
tjaplt.cn
*.tjaplt.cn
*.wlay.tjaplt.cn
*.xy87.tjaplt.cn
turbosalesforce.co
*.turbosalesforce.co
*.aaa.vmedicalsupply.com
*.analytic.vmedicalsupply.com
*.phpmyadmin.vmedicalsupply.com
*.pma.vmedicalsupply.com
*.shop.vmedicalsupply.com
vmedicalsupply.com
*.vmedicalsupply.com
vpdgjm.net
*.vpdgjm.net
Other domains in certificate