76/100 SECURITY SCORE

Certificate Information

Subject
CN=aluminiumregal.de
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 15, 2026
Valid Until
August 13, 2026 74 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
30:3E:98:0B:C2:14:32:31:44:DC:AF:1D:FF:22:44:C4:5C:F5:3B:85:7C:18:37:D6:D1:B7:FB:B3:50:F3:8D:29
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
studiowebsitebuilder.com *.studiowebsitebuilder.com *.api.studiowebsitebuilder.com *.app.studiowebsitebuilder.com *.dev.studiowebsitebuilder.com *.docs.studiowebsitebuilder.com *.external.studiowebsitebuilder.com *.intranet.studiowebsitebuilder.com *.my.studiowebsitebuilder.com *.portal.studiowebsitebuilder.com *.share.studiowebsitebuilder.com *.sharepoint.studiowebsitebuilder.com

Other domains in certificate

*.1.1avlang.xyz 1avlang.xyz *.1avlang.xyz *.8.1avlang.xyz *.av.1avlang.xyz *.development.1avlang.xyz *.ht.1avlang.xyz *.jdkyl.1avlang.xyz *.preprod.1avlang.xyz *.superset.1avlang.xyz *.t.1avlang.xyz *.wt.1avlang.xyz *.ww.1avlang.xyz *.wwwt.1avlang.xyz
aluminiumregal.de *.aluminiumregal.de *.random.aluminiumregal.de
*.com.daversitycode.com daversitycode.com *.daversitycode.com *.org.daversitycode.com *.ww25.daversitycode.com
*.admin.enforcenoble.info *.app.enforcenoble.info *.dev.enforcenoble.info enforcenoble.info *.enforcenoble.info *.wnjltahcvqassets.enforcenoble.info
*.dgw.globallifeins.com *.dns.globallifeins.com globallifeins.com *.globallifeins.com *.hostmaster.globallifeins.com *.mx7.globallifeins.com *.ns1.globallifeins.com *.ns2.globallifeins.com
hmster.com *.hmster.com *.integration.hmster.com *.random.hmster.com *.sexgil.hmster.com *.superset.hmster.com *.ww25.hmster.com *.x.hmster.com *.xnx.hmster.com *.xnxx.hmster.com
*.cpanel.institutfrancaisfes.com *.hostmaster.institutfrancaisfes.com institutfrancaisfes.com *.institutfrancaisfes.com *.mail.institutfrancaisfes.com *.pop.institutfrancaisfes.com *.server.institutfrancaisfes.com *.webdisk.institutfrancaisfes.com *.webmail.institutfrancaisfes.com *.ww25.institutfrancaisfes.com *.www.institutfrancaisfes.com
multiagentbot.com *.multiagentbot.com *.staging.multiagentbot.com
*.admin.neuralinstinct.info *.api.neuralinstinct.info *.dashboard.neuralinstinct.info *.dev.neuralinstinct.info neuralinstinct.info *.neuralinstinct.info *.new.neuralinstinct.info *.staging.neuralinstinct.info *.web.neuralinstinct.info
*.2.strechinternet.com *.board.strechinternet.com *.php.strechinternet.com *.portal.strechinternet.com *.preview.strechinternet.com strechinternet.com *.strechinternet.com *.visualizations.strechinternet.com *.viz.strechinternet.com