Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=harborsolar.me
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 11, 2026
Valid Until
May 12, 2026
78 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C0:13:53:43:9F:FE:37:23:AC:A7:96:45:0E:F6:8D:82:6B:1F:5B:67:D0:48:DC:B6:D9:9F:9F:B4:A2:76:F1:27
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
ganbai.com
*.ganbai.com
*.ebay.ganbai.com
*.sitemaps.ganbai.com
*.wiki.ganbai.com
*.ww16.ganbai.com
*.ww17.ganbai.com
*.ww25.ganbai.com
*.ww38.ganbai.com
accommodationnambuccaheads.com.au
*.accommodationnambuccaheads.com.au
altaayers.homes
*.altaayers.homes
*.jamie.altaayers.homes
*.paige.altaayers.homes
*.trisha.altaayers.homes
autographs.uk
*.autographs.uk
*.demo.autographs.uk
*.old.pni.com.pl
pni.com.pl
*.pni.com.pl
*.test.pni.com.pl
emptyquartertours.com
*.emptyquartertours.com
*.mail1.emptyquartertours.com
*.mta.emptyquartertours.com
*.server1.emptyquartertours.com
*.ww38.emptyquartertours.com
harborsolar.me
*.harborsolar.me
*.office.harborsolar.me
*.v1.harborsolar.me
*.crm.julialane.com
*.git.julialane.com
*.hostmaster.julialane.com
julialane.com
*.julialane.com
*.mobile.julialane.com
*.sistema.julialane.com
*.support.julialane.com
*.72dde74d-b5f9-4746-8ef7-31d6e973b794.merpati.com
*.com.merpati.com
merpati.com
*.merpati.com
*.vpn.merpati.com
*.www.merpati.com
*.comune.monteviale.it
*.hostmaster.monteviale.it
monteviale.it
*.monteviale.it
newenglandairsoft.com
*.newenglandairsoft.com
*.ns.orftvthek.at
orftvthek.at
*.orftvthek.at
*.random.orftvthek.at
*.ww17.orftvthek.at
*.ww25.orftvthek.at
*.ww38.orftvthek.at
privatedelights.xyz
*.privatedelights.xyz
sabong78.bet
*.sabong78.bet
*.mail.siteware.com.au
*.mailer.siteware.com.au
*.prod.siteware.com.au
siteware.com.au
*.siteware.com.au
*.ww38.siteware.com.au
*.login.watchers.tv
*.sky.watchers.tv
*.usps.watchers.tv
watchers.tv
*.watchers.tv
*.alexa.wearelittlestar.com
*.dailystar.wearelittlestar.com
*.ipanema.wearelittlestar.com
*.random.wearelittlestar.com
wearelittlestar.com
*.wearelittlestar.com
*.com.xx1333.com
*.notexistsblog.xx1333.com
*.report.xx1333.com
*.server1.xx1333.com
*.summary.xx1333.com
*.superset.xx1333.com
*.www2s.xx1333.com
xx1333.com
*.xx1333.com
Other domains in certificate