Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=nugget.cfd
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 22, 2026
Valid Until
May 23, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F7:46:AC:70:20:E7:75:48:E5:07:E7:6B:DE:49:33:46:36:46:F6:AA:DC:06:75:4F:72:76:AD:9B:6D:77:F5:31
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
nugget.cfd *.nugget.cfd

Other domains in certificate

bdnice24.com *.bdnice24.com *.calculator.bdnice24.com *.client.bdnice24.com *.consulting.bdnice24.com *.demo.bdnice24.com *.edu.bdnice24.com *.lms.bdnice24.com *.m.bdnice24.com *.news.bdnice24.com *.remote.bdnice24.com *.shop.bdnice24.com *.slippa.bdnice24.com *.tube.bdnice24.com *.wp.bdnice24.com *.writer.bdnice24.com *.ww12.bdnice24.com
*.admin.buildmuscle.in *.analytics.buildmuscle.in *.bi.buildmuscle.in buildmuscle.in *.buildmuscle.in *.chart.buildmuscle.in *.dashboards.buildmuscle.in *.dev.buildmuscle.in *.m.buildmuscle.in *.mail.buildmuscle.in *.metric.buildmuscle.in *.metrics.buildmuscle.in *.notexistsdev.buildmuscle.in *.notexistsremote.buildmuscle.in *.old.buildmuscle.in *.remote.buildmuscle.in *.reports.buildmuscle.in *.stats.buildmuscle.in *.superset.buildmuscle.in *.supersets.buildmuscle.in *.visual.buildmuscle.in *.ww25.buildmuscle.in *.www.buildmuscle.in
*.admin.halfpricelandscaping.com *.api.halfpricelandscaping.com *.app.halfpricelandscaping.com *.assets.halfpricelandscaping.com *.cloud.halfpricelandscaping.com *.demo.halfpricelandscaping.com *.dev.halfpricelandscaping.com halfpricelandscaping.com *.halfpricelandscaping.com *.hostmaster.halfpricelandscaping.com *.hpxatywb.halfpricelandscaping.com *.mail.halfpricelandscaping.com *.members.halfpricelandscaping.com *.rd.halfpricelandscaping.com *.rds.halfpricelandscaping.com *.rdweb.halfpricelandscaping.com *.test.halfpricelandscaping.com *.vpn.halfpricelandscaping.com *.www.halfpricelandscaping.com
*.app.holmbyhills.com *.crm.holmbyhills.com *.forums.holmbyhills.com holmbyhills.com *.holmbyhills.com *.home.holmbyhills.com *.m.holmbyhills.com *.mail.holmbyhills.com *.mobile.holmbyhills.com *.new.holmbyhills.com *.news.holmbyhills.com *.qa.holmbyhills.com *.shop.holmbyhills.com *.store.holmbyhills.com *.v1.holmbyhills.com *.wap.holmbyhills.com *.www.holmbyhills.com
*.crm.liquidram.com *.hostmaster.liquidram.com liquidram.com *.liquidram.com *.mail.liquidram.com *.store.liquidram.com *.tentatore.liquidram.com
*.kuveyt.turk.bio *.sitemaps.turk.bio turk.bio *.turk.bio *.www.turk.bio