Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=18244.my
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 31, 2026
Valid Until
August 29, 2026
71 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C3:97:1C:68:4A:A9:F2:25:BE:D4:7F:0E:81:2E:DB:F8:15:54:ED:48:E9:93:33:7D:D3:DC:84:CF:11:CA:24:12
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
chromewater.com
*.chromewater.com
18244.my
*.18244.my
201815.qpon
*.201815.qpon
2ks0rev1sp.top
*.2ks0rev1sp.top
57635.my
*.57635.my
b4r.cc
*.b4r.cc
blinkymoon.com
*.blinkymoon.com
caakp.my
*.caakp.my
chelseafootballkit.com
*.chelseafootballkit.com
chongzhiyouhui.com
*.chongzhiyouhui.com
commama09.com
*.commama09.com
drwayashop.com
*.drwayashop.com
ecovillababilonia.co
*.ecovillababilonia.co
*.25.kihachijo.com
kihachijo.com
*.kihachijo.com
mooncatsale.com
*.mooncatsale.com
moshawquit.com
*.moshawquit.com
moviegsc.info
*.moviegsc.info
mytrendbest.online
*.mytrendbest.online
nwzur.my
*.nwzur.my
pilot.im
*.pilot.im
procraftingdiy.live
*.procraftingdiy.live
proyek88-main.monster
*.proyek88-main.monster
rollstorm.xyz
*.rollstorm.xyz
rtpbanteng69jp.sbs
*.rtpbanteng69jp.sbs
safehavenhorti.xyz
*.safehavenhorti.xyz
stwxadxw.click
*.stwxadxw.click
taiuk88.vip
*.taiuk88.vip
terapagogo.info
*.terapagogo.info
toptiervacations.xyz
*.toptiervacations.xyz
trypackagefinder.com
*.trypackagefinder.com
u-rwa.com
*.u-rwa.com
uqa117k.top
*.uqa117k.top
wosteel.cn
*.wosteel.cn
woxnd.cc
*.woxnd.cc
wwhanswers.com
*.wwhanswers.com
xdoraejk9x.top
*.xdoraejk9x.top
xeaat.my
*.xeaat.my
xebs26n.top
*.xebs26n.top
xenoexecuto.com
*.xenoexecuto.com
xez43i.cyou
*.xez43i.cyou
xgdiy.my
*.xgdiy.my
xhhvr.sbs
*.xhhvr.sbs
xn--v6clunjci2dza4fwbv0g4a8dwcyee.com
*.xn--v6clunjci2dza4fwbv0g4a8dwcyee.com
yvdigoobthggisbextde.com
*.yvdigoobthggisbextde.com
Other domains in certificate