Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=lacittadellarte.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 03, 2026
Valid Until
May 04, 2026
67 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
A0:66:C6:4E:2A:BE:96:FA:7E:0D:67:88:A5:15:60:CC:58:EA:D8:76:14:E6:A4:B8:3E:F4:43:5A:C7:DC:0E:7E
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
paypak.it
*.paypak.it
lacittadellarte.it
*.lacittadellarte.it
lanchgood.com
*.lanchgood.com
laughter.it
*.laughter.it
lilioulii555.xyz
*.lilioulii555.xyz
*.git.mentorecarrtop.com
mentorecarrtop.com
*.mentorecarrtop.com
mqriy.top
*.mqriy.top
mustlove.it
*.mustlove.it
myfirstjob.it
*.myfirstjob.it
myxreality.com
*.myxreality.com
nbfd.org
*.nbfd.org
needforgreen.it
*.needforgreen.it
static-vsnl.net.in
*.static-vsnl.net.in
nhacai11bet.casino
*.nhacai11bet.casino
nicco.it
*.nicco.it
nicole-banana.com
*.nicole-banana.com
nodig.it
*.nodig.it
nonvedenti.it
*.nonvedenti.it
offertedioggi.it
*.offertedioggi.it
onthenet.it
*.onthenet.it
owqdjpwma.cn
*.owqdjpwma.cn
parinaya.in
*.parinaya.in
petro.it
*.petro.it
physiques.it
*.physiques.it
play-amber-stronghold.xyz
*.play-amber-stronghold.xyz
psa-software-15.cfd
*.psa-software-15.cfd
qux.it
*.qux.it
rcu60.top
*.rcu60.top
religiose.it
*.religiose.it
rtpsiap-mantap3.sbs
*.rtpsiap-mantap3.sbs
sattakingwin.com
*.sattakingwin.com
search-apartmentin-il.click
*.search-apartmentin-il.click
seo-fundamentals.com
*.seo-fundamentals.com
serenebridejubilee.beauty
*.serenebridejubilee.beauty
seturoncrew.com
*.seturoncrew.com
soshanews.com
*.soshanews.com
sportactivezone.cfd
*.sportactivezone.cfd
storyqualityexcitement.college
*.storyqualityexcitement.college
strategicclientmanager.com
*.strategicclientmanager.com
zcp13.top
*.zcp13.top
zhkjg.com
*.zhkjg.com
znyczw.pro
*.znyczw.pro
zulut.pro
*.zulut.pro
zvkvi.bid
*.zvkvi.bid
Other domains in certificate