76/100 SECURITY SCORE

Certificate Information

Subject
CN=medicalrehabilitation.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 20, 2026
Valid Until
August 18, 2026 72 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C3:B5:1B:C2:11:B1:DC:DA:33:92:EA:C5:B1:43:CA:CF:3A:38:DF:0E:76:E2:AC:8C:7E:53:A7:B4:83:89:AB:3D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
ciids.org *.ciids.org *.admin.ciids.org *.api.ciids.org *.demo.ciids.org *.dev.ciids.org *.hostmaster.ciids.org *.insta.ciids.org

Other domains in certificate

44vc6xaaue.com *.44vc6xaaue.com *.lwesoes.44vc6xaaue.com
*.admin.bes911.net *.api.bes911.net *.backend.bes911.net bes911.net *.bes911.net *.checkout.bes911.net *.demo.bes911.net *.sitemaps.bes911.net *.webmail.bes911.net *.ww1.bes911.net *.ww25.bes911.net *.www.bes911.net
*.7228e67f-6d31-4e76-9cac-0750abda56a6.betnbetci.com betnbetci.com *.betnbetci.com *.rd.betnbetci.com *.rdweb.betnbetci.com *.wap.betnbetci.com *.www.betnbetci.com
catemark.com *.catemark.com *.ww25.catemark.com
digicollege.com *.digicollege.com *.report.digicollege.com *.ww17.digicollege.com *.ww25.digicollege.com
*.525v4.gamer-dubaispin168.cfd *.bnbod.gamer-dubaispin168.cfd *.fdy0p.gamer-dubaispin168.cfd gamer-dubaispin168.cfd *.gamer-dubaispin168.cfd *.lkzdx.gamer-dubaispin168.cfd *.swx9yz.gamer-dubaispin168.cfd *.v6j6e.gamer-dubaispin168.cfd *.z4r76.gamer-dubaispin168.cfd
mariobluegloves.info *.mariobluegloves.info
medicalrehabilitation.it *.medicalrehabilitation.it *.www.medicalrehabilitation.it
rumeurlingeriesandiego.de *.rumeurlingeriesandiego.de
servicekinggaragedoorsstlouis.de *.servicekinggaragedoorsstlouis.de
shoppatiopatch.de *.shoppatiopatch.de
skelbiu.it *.skelbiu.it
solecaremobilepodiatry.de *.solecaremobilepodiatry.de
*.mail.spinningwheeldiner.com spinningwheeldiner.com *.spinningwheeldiner.com
tektk77toto.vip *.tektk77toto.vip *.webmail.tektk77toto.vip
waka.au *.waka.au *.ww25.waka.au *.ww38.waka.au
wavecam.com.au *.wavecam.com.au *.ww25.wavecam.com.au
*.dev.xveido.com *.flowise.xveido.com *.jenkins.xveido.com *.pipeline.xveido.com *.ww31.xveido.com *.wwe.xveido.com xveido.com *.xveido.com *.xxx.xveido.com
*.random.z4x.co.uk z4x.co.uk *.z4x.co.uk
zan62.xyz *.zan62.xyz