76/100 SECURITY SCORE

Certificate Information

Subject
CN=bodylove.store
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 05, 2026
Valid Until
May 06, 2026 76 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
2C:4A:2B:94:D9:9A:9F:96:58:46:21:80:0C:10:9F:D8:6A:7E:71:5F:DA:61:CF:0E:1F:47:35:3E:0B:37:22:29
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
guatematica.com *.guatematica.com *.crm.guatematica.com

Other domains in certificate

5movierulzs.io *.5movierulzs.io *.7.5movierulzs.io *.m.5movierulzs.io *.wildcard.5movierulzs.io
*.37495f46-3a56-4204-9ad8-5853fb391b25.beachcities.tv beachcities.tv *.beachcities.tv *.bot-development.beachcities.tv *.random.beachcities.tv *.staging.beachcities.tv *.store.beachcities.tv
bodylove.store *.bodylove.store
camaradecomerciodelalba.com *.camaradecomerciodelalba.com
ccsid.biz *.ccsid.biz
cldprivatearchives.com *.cldprivatearchives.com *.random.cldprivatearchives.com
dragonflyy.co *.dragonflyy.co
fastwinmodapk.online *.fastwinmodapk.online
filmy-hit.cfd *.filmy-hit.cfd
fit-perfect.de *.fit-perfect.de
fortinet.store *.fortinet.store
gingerhotel.store *.gingerhotel.store
hundkatzefisch.de *.hundkatzefisch.de
*.ansueo6gfb.o3member.club o3member.club *.o3member.club
*.common.osakametro.co *.dantaiken.osakametro.co *.emetro-app-dev.osakametro.co *.emetro-dispatchtab-dev.osakametro.co *.emetro-dispatchtab.osakametro.co *.emetro-ondemandbus-dev.osakametro.co *.fms-stg.osakametro.co *.id-stg.osakametro.co *.metruck-ft-mgt-dev.osakametro.co *.metruck-stg.osakametro.co osakametro.co *.osakametro.co *.pffr-dev.osakametro.co *.pfid-stg.osakametro.co *.pointope-dev.osakametro.co *.random.osakametro.co *.subway.osakametro.co
prevenlifenutricionfuncional.com *.prevenlifenutricionfuncional.com
prospect360global.com *.prospect360global.com
seanhlewis.me *.seanhlewis.me
*.25.teamgeneration.online *.ap.teamgeneration.online *.dev.teamgeneration.online *.eb.teamgeneration.online *.home.teamgeneration.online *.m.teamgeneration.online *.mobile.teamgeneration.online *.news.teamgeneration.online *.sitemap.teamgeneration.online *.sitemaps.teamgeneration.online teamgeneration.online *.teamgeneration.online *.vpn.teamgeneration.online *.wap.teamgeneration.online *.web.teamgeneration.online *.ww25.teamgeneration.online
*.azure.ucecorp.com *.barracuda.ucecorp.com *.bb.ucecorp.com *.blog.ucecorp.com *.blogs.ucecorp.com *.qa.ucecorp.com ucecorp.com *.ucecorp.com *.vpn.ucecorp.com