76/100 SECURITY SCORE

Certificate Information

Subject
CN=nvcasinouk.org
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 12, 2026
Valid Until
July 11, 2026 71 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
51:81:CE:91:22:DF:84:37:96:B3:3B:51:E5:66:0E:17:B0:9F:8D:43:A5:50:B6:EA:C1:F9:80:02:BA:FC:0E:65
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
crushfibromyalgia.com *.crushfibromyalgia.com *.pay.crushfibromyalgia.com

Other domains in certificate

amiral.it *.amiral.it *.api.amiral.it *.demo.amiral.it *.gestionepec.amiral.it *.hostmaster.amiral.it *.mx.amiral.it *.remote.amiral.it *.www.amiral.it
*.60e93b52-e152-4d0c-ae36-d71bd1e2eee2.bubet.one *.64696f36-03c4-40aa-ab3c-e0c0ec55c9e8.bubet.one *.656d56b3-69d6-403b-8707-54e12a20a798.bubet.one *.admin.bubet.one *.api.bubet.one *.app.bubet.one *.assets.bubet.one *.boutique.bubet.one bubet.one *.bubet.one *.demo.bubet.one *.dev.bubet.one *.hostmaster.bubet.one *.load.bubet.one *.nbngxassets.bubet.one *.otrsznbngxassets.bubet.one *.test.bubet.one
favono.co *.favono.co
*.admin.glamor.pro *.api.glamor.pro *.app.glamor.pro *.backend.glamor.pro *.bi.glamor.pro *.blog.glamor.pro *.cdn.glamor.pro *.chart.glamor.pro *.cicd.glamor.pro *.dash.glamor.pro *.dashs.glamor.pro *.demo.glamor.pro *.dev.glamor.pro glamor.pro *.glamor.pro *.home.glamor.pro *.hostmaster.glamor.pro *.loja.glamor.pro *.m.glamor.pro *.members.glamor.pro *.metrics.glamor.pro *.mobile.glamor.pro *.mpkflsqw.glamor.pro *.news.glamor.pro *.redash.glamor.pro *.remote.glamor.pro *.report.glamor.pro *.reporting.glamor.pro *.staging-pipeline.glamor.pro *.staging.glamor.pro *.superset.glamor.pro *.test.glamor.pro *.wap.glamor.pro *.web.glamor.pro *.wp.glamor.pro *.www.glamor.pro
*.api.mediablast.ai mediablast.ai *.mediablast.ai *.www.mediablast.ai
*.charisma.nursing.co.za nursing.co.za *.nursing.co.za *.unisa.nursing.co.za *.ww25.nursing.co.za
*.admin.nvcasinouk.org *.api.nvcasinouk.org nvcasinouk.org *.nvcasinouk.org *.root.nvcasinouk.org
*.argo.richiestefinanziamento.com *.demo.richiestefinanziamento.com richiestefinanziamento.com *.richiestefinanziamento.com *.staging.richiestefinanziamento.com *.workflow.richiestefinanziamento.com
*.hostmaster.volum.it volum.it *.volum.it