Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=websim.co
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 03, 2026
Valid Until
September 01, 2026
77 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
90:EF:C9:64:D5:FB:9F:9B:B5:F8:B0:DA:CA:57:7B:4E:5F:D1:03:7A:D6:40:B0:AD:62:27:17:DC:6C:BA:CC:5D
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
galnet.org
*.galnet.org
*.arable.galnet.org
*.cesia-api.galnet.org
*.sitemap.galnet.org
*.spring.galnet.org
bit.directory
*.bit.directory
*.m.bit.directory
*.mail.bit.directory
*.random.bit.directory
bmy881.co
*.bmy881.co
built.bot
*.built.bot
*.www.built.bot
deepnudesart.com
*.deepnudesart.com
distractionden.com
*.distractionden.com
*.vpn.distractionden.com
jmmlapierre.com
*.jmmlapierre.com
jmple.com
*.jmple.com
*.ekf.jpds8.world
jpds8.world
*.jpds8.world
*.vng.jpds8.world
*.xre.jpds8.world
*.panel.puppydroid.io
puppydroid.io
*.puppydroid.io
*.archive.rh-dev.com
*.m.rh-dev.com
rh-dev.com
*.rh-dev.com
*.api.scfsupplies.co.uk
scfsupplies.co.uk
*.scfsupplies.co.uk
*.free.servicesbd.xyz
*.gov.servicesbd.xyz
*.nid.servicesbd.xyz
servicesbd.xyz
*.servicesbd.xyz
tarisite.com
*.tarisite.com
*.m.tokuteiginou.blog
tokuteiginou.blog
*.tokuteiginou.blog
*.www.tokuteiginou.blog
*.demo.trendzeye.com
*.desktop.trendzeye.com
*.dev.trendzeye.com
*.gateway.trendzeye.com
*.gp.trendzeye.com
*.m.trendzeye.com
*.ra.trendzeye.com
*.rd.trendzeye.com
*.rdp.trendzeye.com
*.remoto.trendzeye.com
*.secure.trendzeye.com
*.test.trendzeye.com
trendzeye.com
*.trendzeye.com
*.vdi.trendzeye.com
*.vpnssl.trendzeye.com
*.admin.videowall.live
*.api.videowall.live
*.app.videowall.live
*.backend.videowall.live
*.dev.videowall.live
*.hostmaster.videowall.live
*.jenkins.videowall.live
*.lshlyhostmaster.videowall.live
*.m.videowall.live
*.notexistsadmin.videowall.live
*.notexistsbackend.videowall.live
*.random.videowall.live
*.server.videowall.live
*.sitemaps.videowall.live
videowall.live
*.videowall.live
*.www.videowall.live
wanwang2.com
*.wanwang2.com
*.on.websim.co
*.steampunk-catalog.websim.co
websim.co
*.websim.co
Other domains in certificate