Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=cheap-flights.top
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 20, 2026
Valid Until
August 18, 2026
82 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
2A:04:C0:AE:DC:84:96:26:9B:C9:41:AD:9E:7E:19:21:6B:F5:70:56:E9:7F:84:B2:AA:81:15:67:F4:DA:3F:AD
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
perspicacious.net
*.perspicacious.net
28916.one
*.28916.one
31600.one
*.31600.one
34291.my
*.34291.my
4yyz7jd2qc.cc
*.4yyz7jd2qc.cc
9215.my
*.9215.my
ancy.org
*.ancy.org
*.backend.cheap-flights.top
*.bi.cheap-flights.top
cheap-flights.top
*.cheap-flights.top
*.hostmaster.cheap-flights.top
*.kwhotadmin.cheap-flights.top
*.mx3.cheap-flights.top
*.pipeline.cheap-flights.top
*.production.cheap-flights.top
*.rxjkpipqsikfdicg.cheap-flights.top
*.staging-cicd.cheap-flights.top
*.streaming.cheap-flights.top
*.test-pipeline.cheap-flights.top
*.videos-cdn.cheap-flights.top
cpuuu.loan
*.cpuuu.loan
czpcz.loan
*.czpcz.loan
e29rmp.cyou
*.e29rmp.cyou
ethiosparkel.com
*.ethiosparkel.com
evictioncentral.com
*.evictioncentral.com
evolutionaryleadership.org
*.evolutionaryleadership.org
impression.it.com
*.impression.it.com
itsfunny.org
*.itsfunny.org
*.ww16.itsfunny.org
*.ww38.itsfunny.org
kbkoreanlanguage.com
*.kbkoreanlanguage.com
kht111.com
*.kht111.com
lajollafriendsoftheseals.org
*.lajollafriendsoftheseals.org
lgueh.one
*.lgueh.one
*.22.mab-contractor.com
mab-contractor.com
*.mab-contractor.com
*.vpn.mab-contractor.com
*.box.nhelp.com
*.comune.nhelp.com
*.domee.nhelp.com
*.mail.nhelp.com
*.mx.nhelp.com
nhelp.com
*.nhelp.com
*.orenciaca.nhelp.com
*.relaxatio.nhelp.com
*.server1.nhelp.com
*.sp.nhelp.com
*.www.nhelp.com
*.zp.nhelp.com
nobleza.co
*.nobleza.co
novamaster389.top
*.novamaster389.top
pf3xnq.cyou
*.pf3xnq.cyou
quantumoffshore.com
*.quantumoffshore.com
*.admin.xn--szyzkleri-07a2eb.com
*.app.xn--szyzkleri-07a2eb.com
*.backend.xn--szyzkleri-07a2eb.com
*.ci.xn--szyzkleri-07a2eb.com
*.dev.xn--szyzkleri-07a2eb.com
*.mta-sts.xn--szyzkleri-07a2eb.com
*.staging.xn--szyzkleri-07a2eb.com
*.superset.xn--szyzkleri-07a2eb.com
*.testing.xn--szyzkleri-07a2eb.com
xn--szyzkleri-07a2eb.com
*.xn--szyzkleri-07a2eb.com
Other domains in certificate