Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=oneclickshoppingpk.online
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 26, 2026
Valid Until
April 26, 2026
62 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:DD:15:C6:0C:EE:89:A4:B2:B8:13:42:0D:69:2A:08:48:E1:3C:80:41:99:08:4A:32:E3:06:B4:7C:08:17:5A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
84 domains
markwtwatch.com
*.markwtwatch.com
*.beta.markwtwatch.com
*.ci.markwtwatch.com
*.cicd.markwtwatch.com
*.jenkins.markwtwatch.com
aestpe.com
*.aestpe.com
blackhillsengery.com
*.blackhillsengery.com
*.ci.blackhillsengery.com
*.cicd.blackhillsengery.com
*.it.blackhillsengery.com
*.jenkins.blackhillsengery.com
*.production.blackhillsengery.com
bodylotion.com.au
*.bodylotion.com.au
camiyui.co.uk
*.camiyui.co.uk
*.ww38.camiyui.co.uk
chedrawi.com
*.chedrawi.com
*.co.chedrawi.com
*.users.chedrawi.com
*.youtube.chedrawi.com
*.beta.reliacegeneral.co.in
reliacegeneral.co.in
*.reliacegeneral.co.in
coloradocitycreamery.com
*.coloradocitycreamery.com
*.email.coloradocitycreamery.com
*.random.coloradocitycreamery.com
creamdip.com
*.creamdip.com
*.forum.creamdip.com
*.pipeline.creamdip.com
*.test.creamdip.com
*.control.enaymotors.com
enaymotors.com
*.enaymotors.com
*.ww11.enaymotors.com
fatherscry.com
*.fatherscry.com
*.video.fatherscry.com
*.autodiscover.icuod.com
icuod.com
*.icuod.com
*.hostmaster.imgadvisor.com
imgadvisor.com
*.imgadvisor.com
instagrahm.com
*.instagrahm.com
*.staging.instagrahm.com
itchenaid.com
*.itchenaid.com
*.ww25.itchenaid.com
*.german.matrixita.com
matrixita.com
*.matrixita.com
mrricela.com
*.mrricela.com
*.www.mrricela.com
*.blog.needmoreweapons.com
*.book.needmoreweapons.com
*.c.needmoreweapons.com
*.forum.needmoreweapons.com
*.gallery.needmoreweapons.com
*.games.needmoreweapons.com
needmoreweapons.com
*.needmoreweapons.com
*.users.needmoreweapons.com
oneclickshoppingpk.online
*.oneclickshoppingpk.online
orpheus-selfcare.com
*.orpheus-selfcare.com
*.ww16.orpheus-selfcare.com
rbklegalconsulting.online
*.rbklegalconsulting.online
*.cpcalendars.stagsheadhotel.com.au
stagsheadhotel.com.au
*.stagsheadhotel.com.au
*.ww38.stagsheadhotel.com.au
vashlimitzaim.online
*.vashlimitzaim.online
Other domains in certificate