Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=4pk1.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 03, 2026
Valid Until
May 04, 2026
77 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
DA:78:5D:95:70:4E:94:9F:E5:5F:94:A6:8C:94:37:69:6F:E2:48:9F:8C:47:F8:4F:07:9D:BE:3C:62:E9:E5:1B
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
mercadodeauto.com
*.mercadodeauto.com
4pk1.com
*.4pk1.com
*.wap.4pk1.com
*.ww38.4pk1.com
asiania.com
*.asiania.com
*.mx4.asiania.com
*.random.asiania.com
*.644a2c0c-bc7b-4af0-a39a-53c1996ceb1b.garbagemaga.org
garbagemaga.org
*.garbagemaga.org
mallusex.com
*.mallusex.com
*.ravpn.mallusex.com
marulanda.com
*.marulanda.com
maruo.com
*.maruo.com
massbach.com
*.massbach.com
matrix-ace.xyz
*.matrix-ace.xyz
*.rnyzj.matrix-ace.xyz
medyumlar.com
*.medyumlar.com
menopaluu.net
*.menopaluu.net
miney.com
*.miney.com
minshew.com
*.minshew.com
modelingsite.com
*.modelingsite.com
mortgageandfinancial.com
*.mortgageandfinancial.com
muhittin.com
*.muhittin.com
mullady.com
*.mullady.com
multiproprieta.com
*.multiproprieta.com
musab.com
*.musab.com
myasylegal.xyz
*.myasylegal.xyz
myconquest.com
*.myconquest.com
*.dev-dev.nuwork.de
*.dev-e2e.nuwork.de
*.dev-hotfix.nuwork.de
*.dev-ib.nuwork.de
*.dev-stage.nuwork.de
*.dev-tg.nuwork.de
*.dev-tp.nuwork.de
*.dev-tt.nuwork.de
*.dev-tw.nuwork.de
*.dev.nuwork.de
*.infra.nuwork.de
nuwork.de
*.nuwork.de
*.tools.nuwork.de
vn88.luxe
*.vn88.luxe
*.www.vn88.luxe
*.cnuemj.wsofi.com
*.d821215f-d6bc-4f50-9660-60aaa426de39.wsofi.com
*.email.wsofi.com
*.hostmaster.wsofi.com
*.login.wsofi.com
*.m.wsofi.com
*.mvideo.wsofi.com
*.mx.wsofi.com
*.oma.wsofi.com
*.ppc.wsofi.com
*.rds1.wsofi.com
*.si.wsofi.com
*.smtp01.wsofi.com
*.task.wsofi.com
*.verespnenvivo.wsofi.com
wsofi.com
*.wsofi.com
*.ww25.wsofi.com
*.ww38.wsofi.com
*.ww43.wsofi.com
*.www.wsofi.com
*.www.zucmg.net
zucmg.net
*.zucmg.net
Other domains in certificate