76/100 SECURITY SCORE

Certificate Information

Subject
CN=autodealers.it
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 03, 2026
Valid Until
September 01, 2026 69 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5B:3D:B8:DA:00:1C:9D:EC:39:C6:FD:7B:72:F2:70:F4:F6:AE:D0:0A:9D:53:64:A7:AE:CE:01:F4:BF:AC:4D:A3
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
ripacandida.com *.ripacandida.com *.giankishow.ripacandida.com *.hostmaster.ripacandida.com *.iotgateway.ripacandida.com *.mail.ripacandida.com

Other domains in certificate

*.app.autodealers.it autodealers.it *.autodealers.it *.backend.autodealers.it *.staging.autodealers.it
*.blog.cased.it cased.it *.cased.it *.k.cased.it
d10d.shop *.d10d.shop *.dev.d10d.shop *.members.d10d.shop *.test.d10d.shop
display.wtf *.display.wtf *.public.display.wtf
*.e6e.haimaijx.cn haimaijx.cn *.haimaijx.cn
*.api.htm945j-aa.com htm945j-aa.com *.htm945j-aa.com *.tb7d83.htm945j-aa.com
*.jelena.magisplus.com magisplus.com *.magisplus.com
mekitsi.com *.mekitsi.com *.portal.mekitsi.com
movingplaces.com.au *.movingplaces.com.au
mycases.co *.mycases.co *.ww1.mycases.co *.ww16.mycases.co *.www.mycases.co
*.comune.nafdqualifications.org.uk nafdqualifications.org.uk *.nafdqualifications.org.uk
*.67253f4a-37f9-4a96-8bd0-949737cf276b.onionplay.my onionplay.my *.onionplay.my
pablo88.top *.pablo88.top *.wap.pablo88.top
*.0bilktqoke.singularityzeitgeist.com singularityzeitgeist.com *.singularityzeitgeist.com
*.lctkjgoe.tari.wtf *.qa.tari.wtf tari.wtf *.tari.wtf *.vfifqassets.tari.wtf
tazeakil.info *.tazeakil.info *.testing.tazeakil.info *.tf2ns9.tazeakil.info
*.app.terreniedificabili.com *.backend.terreniedificabili.com *.mail.terreniedificabili.com *.mail2.terreniedificabili.com terreniedificabili.com *.terreniedificabili.com
thegardenvenue915.com *.thegardenvenue915.com *.www.thegardenvenue915.com
truthfullspeed.uk *.truthfullspeed.uk *.ww25.truthfullspeed.uk *.ww38.truthfullspeed.uk
*.au.unicus.com.au *.cpanel.unicus.com.au *.tomdeane.unicus.com.au unicus.com.au *.unicus.com.au *.ww25.unicus.com.au
*.t098v.usdj.net usdj.net *.usdj.net
*.m.zhaoshaobi11.com *.weiyun.zhaoshaobi11.com zhaoshaobi11.com *.zhaoshaobi11.com