76/100 SECURITY SCORE

Certificate Information

Subject
CN=boitedecaramels.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 10, 2026
Valid Until
September 08, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E7:30:73:34:73:19:38:DA:27:FE:BA:8A:71:8C:A7:25:B2:09:18:78:3D:8E:44:78:ED:2C:67:06:7B:09:EF:A7
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
fantasydevelopers.com *.fantasydevelopers.com *.m.fantasydevelopers.com

Other domains in certificate

boitedecaramels.com *.boitedecaramels.com *.members.boitedecaramels.com
builthq.com.au *.builthq.com.au *.shop.builthq.com.au *.staging1.builthq.com.au *.ww38.builthq.com.au
cakeologist.com *.cakeologist.com *.www.cakeologist.com
*.cloud.davegarfield.com davegarfield.com *.davegarfield.com *.webmail.davegarfield.com
gainminer.xyz *.gainminer.xyz *.igqlc.gainminer.xyz
gavinsworld.com *.gavinsworld.com
*.app.gcbin.co gcbin.co *.gcbin.co
*.dev.groomingstyles.info groomingstyles.info *.groomingstyles.info
*.blog.guadianlife.com guadianlife.com *.guadianlife.com *.signin.guadianlife.com *.uat.guadianlife.com *.ww.guadianlife.com
hot9.me *.hot9.me *.sitemaps.hot9.me *.ww01.hot9.me
icloudremoval.us *.icloudremoval.us *.integration.icloudremoval.us *.random.icloudremoval.us *.ruwww.icloudremoval.us *.ww.icloudremoval.us *.ww16.icloudremoval.us *.ww25.icloudremoval.us *.wwe.icloudremoval.us *.www.icloudremoval.us *.wwww.icloudremoval.us
jiali03.top *.jiali03.top *.xn--b9-fk7ca.jiali03.top *.xn--d7-fk7ca.jiali03.top
kartelsoft.com *.kartelsoft.com *.ww25.kartelsoft.com
metrolink.au *.metrolink.au *.ww25.metrolink.au *.ww38.metrolink.au
montanarv.net *.montanarv.net *.ww25.montanarv.net
*.m.openroles.ai openroles.ai *.openroles.ai
*.cisk.psprintportal.xyz *.new.psprintportal.xyz psprintportal.xyz *.psprintportal.xyz *.ww25.psprintportal.xyz
*.api.quieroapuntes.com *.ns1.quieroapuntes.com *.owa.quieroapuntes.com quieroapuntes.com *.quieroapuntes.com *.remote.quieroapuntes.com
*.auth.theneighborlyapp.com *.blog.theneighborlyapp.com theneighborlyapp.com *.theneighborlyapp.com *.ww25.theneighborlyapp.com
uria.it.com *.uria.it.com *.www.uria.it.com
*.barclays.vrai.in *.godaddy.vrai.in vrai.in *.vrai.in