76/100 SECURITY SCORE

Certificate Information

Subject
CN=videoandmusic.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 11, 2026
Valid Until
May 12, 2026 86 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E6:FF:2C:3B:24:71:9F:E3:D0:BD:63:5E:5B:6A:1D:80:45:69:1D:F5:FE:2A:76:A0:A0:BA:44:82:D0:BC:E9:12
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
hepperle.com *.hepperle.com *.hostmaster.hepperle.com *.sitemap.hepperle.com

Other domains in certificate

100caloriediet.com *.100caloriediet.com *.api.100caloriediet.com *.backup.100caloriediet.com *.dev.100caloriediet.com *.hostmaster.100caloriediet.com *.sitemaps.100caloriediet.com *.ww1.100caloriediet.com
*.5.anakib.net *.admin.anakib.net anakib.net *.anakib.net *.api.anakib.net *.app.anakib.net *.backend.anakib.net *.bi.anakib.net *.chart.anakib.net *.dashboard.anakib.net *.dashboards.anakib.net *.dev.anakib.net *.insight.anakib.net *.m.anakib.net *.mail.anakib.net *.metric.anakib.net *.metrics.anakib.net *.notexistsww1.anakib.net *.notexistsww5.anakib.net *.notexistsww6.anakib.net *.o.anakib.net *.remote.anakib.net *.report.anakib.net *.reporting.anakib.net *.reports.anakib.net *.staging.anakib.net *.superset.anakib.net *.supersets.anakib.net *.visual.anakib.net *.ww1.anakib.net *.ww3.anakib.net *.ww5.anakib.net *.www.anakib.net
brooklyndentists.com *.brooklyndentists.com *.sitemaps.brooklyndentists.com
*.beta.cornerstonemetals.com cornerstonemetals.com *.cornerstonemetals.com
gardenia888.co *.gardenia888.co
hdfull.icu *.hdfull.icu *.mobileconnect.hdfull.icu *.online.hdfull.icu
iv88.love *.iv88.love *.m.iv88.love
*.analyze.liverpo.com liverpo.com *.liverpo.com
pamwolf.com *.pamwolf.com *.sitemap.pamwolf.com *.ww16.pamwolf.com
*.comune.sexualinsight.com sexualinsight.com *.sexualinsight.com
*.ftp.thoughtdelimited.org thoughtdelimited.org *.thoughtdelimited.org
*.mail.videoandmusic.it *.remote.videoandmusic.it videoandmusic.it *.videoandmusic.it
*.asapo.webuntis.co *.avs-itzehoe.webuntis.co *.borys.webuntis.co *.erich-brost-bk-essen.webuntis.co *.hepta.webuntis.co *.igs-querum.webuntis.co *.kadmos.webuntis.co *.kephiso.webuntis.co *.kos.webuntis.co *.random.webuntis.co *.tom.webuntis.co webuntis.co *.webuntis.co