Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=lightpro.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
March 19, 2026
Valid Until
June 17, 2026
65 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
25:54:48:FE:14:FE:C9:92:47:DB:62:83:B5:5D:13:DD:1B:F7:D4:62:36:7F:DF:F8:56:98:12:85:59:00:53:44
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
kibrom.com
*.kibrom.com
*.anyconnect.kibrom.com
*.billing.kibrom.com
*.blog.kibrom.com
*.cat.kibrom.com
*.forum.kibrom.com
*.ildcard.kibrom.com
*.images.kibrom.com
*.it.kibrom.com
*.mail1.kibrom.com
*.server2.kibrom.com
*.test.kibrom.com
*.users.kibrom.com
*.vpn1.kibrom.com
*.ww25.kibrom.com
canadalfe.com
*.canadalfe.com
*.cas.canadalfe.com
*.eas.canadalfe.com
*.owa.canadalfe.com
*.random.canadalfe.com
*.webmail.canadalfe.com
*.cipok.dendi.com
dendi.com
*.dendi.com
*.1.drv.ms
drv.ms
*.drv.ms
*.random.drv.ms
*.ww25.drv.ms
*.ww38.drv.ms
junger.it
*.junger.it
*.webmail.junger.it
lightpro.it
*.lightpro.it
*.supersets.lightpro.it
*.comune.milliondollarrustic.com
*.cpanel.milliondollarrustic.com
*.dzjt.milliondollarrustic.com
*.mail.milliondollarrustic.com
milliondollarrustic.com
*.milliondollarrustic.com
*.random.milliondollarrustic.com
*.rusticheritagefurniture.milliondollarrustic.com
*.sso.milliondollarrustic.com
*.webdisk.milliondollarrustic.com
*.webmail.milliondollarrustic.com
*.ww25.milliondollarrustic.com
*.www.milliondollarrustic.com
palmettostatesrmory.com
*.palmettostatesrmory.com
*.travel.palmettostatesrmory.com
*.users.palmettostatesrmory.com
*.xxx.palmettostatesrmory.com
podcaststudiotop.com
*.podcaststudiotop.com
*.yandex-staff.podcaststudiotop.com
*.api.screensavergratis.it
screensavergratis.it
*.screensavergratis.it
scrocco.com
*.scrocco.com
*.ww20.scrocco.com
*.seed.solidrockfaith.com
solidrockfaith.com
*.solidrockfaith.com
*.ww16.solidrockfaith.com
*.api.spyros.it
*.backend.spyros.it
*.dev.spyros.it
spyros.it
*.spyros.it
*.superset.spyros.it
texasdps.org
*.texasdps.org
*.ww25.texasdps.org
*.random.umstands-mode.de
umstands-mode.de
*.umstands-mode.de
*.a.wherearejohnandtodd.com
*.c.wherearejohnandtodd.com
*.d.wherearejohnandtodd.com
*.e.wherearejohnandtodd.com
*.f.wherearejohnandtodd.com
*.i.wherearejohnandtodd.com
*.m.wherearejohnandtodd.com
wherearejohnandtodd.com
*.wherearejohnandtodd.com
Other domains in certificate