Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=energia-secreta.site
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 06, 2026
Valid Until
April 06, 2026
62 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
19:E1:CD:8F:F5:D9:19:90:9F:CA:EF:E4:8B:CB:E1:94:95:02:9A:12:B1:83:2B:7F:A5:81:A6:63:E8:18:F5:09
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
63 domains
fb2.online
*.fb2.online
*.agent.fb2.online
*.bi.fb2.online
*.k.fb2.online
*.lib.fb2.online
clicktivism.org
*.clicktivism.org
constructorconference.org
*.constructorconference.org
dpmanual24.xyz
*.dpmanual24.xyz
*.ww25.dpmanual24.xyz
dramawebseries.com
*.dramawebseries.com
energia-secreta.site
*.energia-secreta.site
*.pixel.energia-secreta.site
*.sitemap.energia-secreta.site
*.www.energia-secreta.site
eurostreaming.vip
*.eurostreaming.vip
*.ww25.eurostreaming.vip
funtik.space
*.funtik.space
innoxbio.com
*.innoxbio.com
jageedsual.com
*.jageedsual.com
justlooking.fyi
*.justlooking.fyi
light-room.pro
*.light-room.pro
*.ww38.light-room.pro
melsgotit.fyi
*.melsgotit.fyi
*.m23.onzldbt.com
*.m3.onzldbt.com
*.m31.onzldbt.com
*.m32.onzldbt.com
*.m8.onzldbt.com
onzldbt.com
*.onzldbt.com
oscartunjo.co
*.oscartunjo.co
planetromeo.au
*.planetromeo.au
*.ww16.planetromeo.au
*.ww38.planetromeo.au
stephendoe.xyz
*.stephendoe.xyz
trendingscript.com
*.trendingscript.com
vinhome.group
*.vinhome.group
*.ww25.vinhome.group
*.dashboard.wahanatoto2.cyou
wahanatoto2.cyou
*.wahanatoto2.cyou
wantit.fyi
*.wantit.fyi
xwyjrakzyaql.com
*.xwyjrakzyaql.com
Other domains in certificate