Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=thornwoodneurology.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 04, 2026
Valid Until
April 04, 2026 41 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
55:1C:65:B3:AF:50:26:FB:38:6E:E6:EB:E5:AE:FB:FC:19:E3:F4:9A:4B:06:01:B9:0E:A1:C7:9F:24:DC:3E:66
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
hicoco.org *.hicoco.org

Other domains in certificate

allinphoto.com *.allinphoto.com *.allinwww.allinphoto.com
asurbot.xyz *.asurbot.xyz *.rustore.asurbot.xyz *.www.asurbot.xyz
balladheath.org *.balladheath.org *.mymail.balladheath.org
casinosite.live *.casinosite.live *.xo.casinosite.live
ecoledirecte.co *.ecoledirecte.co *.hostmaster.ecoledirecte.co *.ww38.ecoledirecte.co *.www.ecoledirecte.co
familyguyfunnymoments.com *.familyguyfunnymoments.com
gguljam.info *.gguljam.info
gmavto.net *.gmavto.net *.part.gmavto.net *.vpn.gmavto.net
*.ci.grand-bassam.info *.deli.grand-bassam.info grand-bassam.info *.grand-bassam.info
*.cpcontacts.hongkongfurzton.co.uk hongkongfurzton.co.uk *.hongkongfurzton.co.uk *.wvvjscpanel.hongkongfurzton.co.uk
leyaswarehouse.online *.leyaswarehouse.online *.ww38.leyaswarehouse.online
marine88.bet *.marine88.bet *.otc.marine88.bet *.play.marine88.bet *.ww25.marine88.bet *.ww38.marine88.bet
oneporcentbetter.com *.oneporcentbetter.com
*.ftp.onlinebaran.com onlinebaran.com *.onlinebaran.com
ototorpido.online *.ototorpido.online
scomputers.info *.scomputers.info
*.agent.selcuksportshd889.xyz selcuksportshd889.xyz *.selcuksportshd889.xyz *.www.selcuksportshd889.xyz
*.chat.soaicacomic.site *.cpanel.soaicacomic.site *.gitlab.soaicacomic.site *.m.soaicacomic.site *.mail.soaicacomic.site *.mx.soaicacomic.site soaicacomic.site *.soaicacomic.site *.test.soaicacomic.site *.webmail.soaicacomic.site *.zoom.soaicacomic.site
thornwoodneurology.com *.thornwoodneurology.com *.www.thornwoodneurology.com
torreto-barbershop.com *.torreto-barbershop.com
triptoglobal.com *.triptoglobal.com
*.analytics.xdeepfakes.com *.bqdxvmedias.xdeepfakes.com *.data.xdeepfakes.com *.medias.xdeepfakes.com *.medias20.xdeepfakes.com *.people.xdeepfakes.com *.ww25.xdeepfakes.com *.www.xdeepfakes.com xdeepfakes.com *.xdeepfakes.com
*.analytics1-static.zeed777plus.bio zeed777plus.bio *.zeed777plus.bio