79/100 SECURITY SCORE

Certificate Information

Subject
CN=panteon.io
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 31, 2026
Valid Until
May 01, 2026 80 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
FE:62:0E:3E:5E:8D:83:82:5B:C2:B8:81:F1:AA:98:08:4F:05:1F:00:B8:B1:70:6D:7F:FD:C9:2B:97:83:2D:EB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

87 domains
oxygenvision.com *.oxygenvision.com *.lab.oxygenvision.com

Other domains in certificate

arabianborka.com *.arabianborka.com *.mail.arabianborka.com
betsilin754.com *.betsilin754.com *.m.betsilin754.com
*.a4n56o3fir6h.cdn-jupiter.com cdn-jupiter.com *.cdn-jupiter.com *.d7izxzkm5jvh.cdn-jupiter.com *.i2qq0vb1aul7.cdn-jupiter.com *.qbyrpo83t7d3.cdn-jupiter.com *.qfdjvs9xshtqmeip.cdn-jupiter.com *.tfaullundco4.cdn-jupiter.com *.ww25.cdn-jupiter.com
*.admin.innovation-develop.com *.api.innovation-develop.com *.apiauth.innovation-develop.com *.apipost.innovation-develop.com *.apipremiere.innovation-develop.com *.apivuejsdemo.innovation-develop.com *.ar2.innovation-develop.com *.ar3.innovation-develop.com *.ar5.innovation-develop.com *.course.innovation-develop.com *.courseapi.innovation-develop.com *.demo1.innovation-develop.com *.demo10.innovation-develop.com *.demo11.innovation-develop.com *.demo12.innovation-develop.com *.demo2.innovation-develop.com *.demo3.innovation-develop.com *.demo4.innovation-develop.com *.demo5.innovation-develop.com *.demo6.innovation-develop.com *.demo7.innovation-develop.com *.demo8.innovation-develop.com *.demo9.innovation-develop.com *.front.innovation-develop.com *.game.innovation-develop.com innovation-develop.com *.innovation-develop.com *.national.innovation-develop.com *.nationalv2.innovation-develop.com *.nuxt.innovation-develop.com *.post.innovation-develop.com *.premiere.innovation-develop.com *.school.innovation-develop.com *.school1.innovation-develop.com *.school2.innovation-develop.com *.school3.innovation-develop.com *.school5.innovation-develop.com *.school5v2.innovation-develop.com *.school6.innovation-develop.com *.school7.innovation-develop.com *.shop.innovation-develop.com *.vueauth.innovation-develop.com *.vuejsdemo.innovation-develop.com
istanajayamakmur.site *.istanajayamakmur.site *.members.istanajayamakmur.site
*.archive.laoxizi.com laoxizi.com *.laoxizi.com
*.bar.nearme.direct *.beach.nearme.direct *.breakfast.nearme.direct *.chinese.nearme.direct *.coffee.nearme.direct *.food.nearme.direct *.liquor-store.nearme.direct *.mall.nearme.direct nearme.direct *.nearme.direct *.park.nearme.direct *.pizza.nearme.direct *.store.nearme.direct
*.masfreelancer.panteon.io panteon.io *.panteon.io *.ww25.panteon.io
*.rds1.vcdaddy.com vcdaddy.com *.vcdaddy.com