Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=nuggetfinder.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026
84 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
5F:E0:1B:0D:4F:1C:2E:23:27:0C:81:09:FC:B3:2A:37:34:FE:87:43:61:E9:43:11:AF:AE:C5:28:44:98:5C:10
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
defrise.com
*.defrise.com
*.crm.defrise.com
*.ww17.defrise.com
3trees.live
*.3trees.live
*.admin.3trees.live
*.aws.3trees.live
*.laravel.3trees.live
*.pay.3trees.live
casalasagna.com
*.casalasagna.com
*.store.casalasagna.com
*.ww38.casalasagna.com
diaprojektor.de
*.diaprojektor.de
*.admin.elpicante.com
elpicante.com
*.elpicante.com
*.rustore.elpicante.com
*.shop.elpicante.com
*.ww1.elpicante.com
*.a.ferrari-owners.club
*.apps.ferrari-owners.club
*.assets.ferrari-owners.club
*.book.ferrari-owners.club
*.de.ferrari-owners.club
*.es.ferrari-owners.club
ferrari-owners.club
*.ferrari-owners.club
*.forum.ferrari-owners.club
*.fr.ferrari-owners.club
*.gitlab.ferrari-owners.club
*.info.ferrari-owners.club
*.mail1.ferrari-owners.club
*.mobile.ferrari-owners.club
*.mx.ferrari-owners.club
*.office.ferrari-owners.club
*.vpn.ferrari-owners.club
*.wss.ferrari-owners.club
*.ww38.ferrari-owners.club
gxiz.com
*.gxiz.com
*.jri.gxiz.com
*.blog.jus4fun.xyz
jus4fun.xyz
*.jus4fun.xyz
*.ww25.jus4fun.xyz
*.1d817.labaa.xyz
*.1yme1.labaa.xyz
*.a2d26cb3-b095-43aa-9b74-8a5fcc33ead8.labaa.xyz
labaa.xyz
*.labaa.xyz
*.z3dl1.labaa.xyz
*.cpcontacts.laowanghfw744.us
laowanghfw744.us
*.laowanghfw744.us
*.random.laowanghfw744.us
*.hermes.mwl.cn
*.idci.mwl.cn
*.mh.mwl.cn
mwl.cn
*.mwl.cn
*.random.mwl.cn
*.sltj.mwl.cn
mymusicclass.com
*.mymusicclass.com
nautico.net
*.nautico.net
nhypost.com
*.nhypost.com
nuggetfinder.com
*.nuggetfinder.com
nutkhut.com
*.nutkhut.com
oesscoreboards.com
*.oesscoreboards.com
olivenza.com
*.olivenza.com
*.help.perfectpay.solutions
perfectpay.solutions
*.perfectpay.solutions
polinesio.com
*.polinesio.com
schminkkurse.de
*.schminkkurse.de
sweetifox.com
*.sweetifox.com
xn--frettchenkfige-fib.de
*.xn--frettchenkfige-fib.de
Other domains in certificate