76/100 SECURITY SCORE

Certificate Information

Subject
CN=paintmaterials.click
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 16, 2026
Valid Until
August 14, 2026 73 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F9:2E:64:59:23:2B:3A:35:FA:A3:62:08:85:94:4C:D6:83:A7:37:9A:CF:99:72:38:36:8A:5F:61:B9:FD:B6:9D
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
paintmaterials.click *.paintmaterials.click *.128ihr.paintmaterials.click

Other domains in certificate

6122164pg.com *.6122164pg.com *.backup.6122164pg.com *.dev.6122164pg.com *.sitemaps.6122164pg.com
adonaisraingutters.de *.adonaisraingutters.de
apworld.life *.apworld.life *.comune.apworld.life
*.au.carcashexchange.com.au carcashexchange.com.au *.carcashexchange.com.au *.test.carcashexchange.com.au
chatincontri.org *.chatincontri.org *.demo-gate.chatincontri.org *.loveers.chatincontri.org *.ww12.chatincontri.org
flashscoreusa.us *.flashscoreusa.us *.ww25.flashscoreusa.us *.ww38.flashscoreusa.us
*.b.getaffair.com *.ftp.getaffair.com *.gallery.getaffair.com getaffair.com *.getaffair.com *.jobs.getaffair.com *.lvl2.getaffair.com *.mlm1.getaffair.com *.mlm16.getaffair.com *.mlm18.getaffair.com *.mlm26.getaffair.com *.mlm3.getaffair.com *.mx2.getaffair.com *.net.getaffair.com *.new.getaffair.com *.secure.getaffair.com *.sim.getaffair.com *.sms.getaffair.com *.srv1024.getaffair.com *.ww16.getaffair.com *.ww17.getaffair.com *.ww25.getaffair.com
historicwaterstreet.org *.historicwaterstreet.org *.mail.historicwaterstreet.org
*.hostmaster.imovies.tv imovies.tv *.imovies.tv *.m.imovies.tv *.www.imovies.tv
iptvmillenium.com *.iptvmillenium.com *.panel.iptvmillenium.com
moviecc.com *.moviecc.com *.ww38.moviecc.com
pajwu.com *.pajwu.com
putl.co.uk *.putl.co.uk
*.cp.salinastiresinwhittier.com *.crm.salinastiresinwhittier.com *.dev.salinastiresinwhittier.com *.dev2.salinastiresinwhittier.com *.noc.salinastiresinwhittier.com salinastiresinwhittier.com *.salinastiresinwhittier.com *.static.salinastiresinwhittier.com *.webmail.salinastiresinwhittier.com *.ww16.salinastiresinwhittier.com *.ww25.salinastiresinwhittier.com *.ww38.salinastiresinwhittier.com
*.api.sapminneapolis.com *.app.sapminneapolis.com *.dev.sapminneapolis.com sapminneapolis.com *.sapminneapolis.com
techyworld.co.in *.techyworld.co.in
vqtj.com *.vqtj.com
*.m.xuan633.top xuan633.top *.xuan633.top