76/100 SECURITY SCORE

Certificate Information

Subject
CN=goldenstarsintls.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 25, 2026
Valid Until
May 26, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E1:DD:57:29:A7:FC:E4:24:F1:7A:AD:66:C1:89:4C:BF:D7:0A:97:E1:72:91:25:D8:CB:CA:7E:A4:FB:31:CD:AE
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
collegebroad.org *.collegebroad.org *.app.collegebroad.org *.idp.collegebroad.org *.mypractice.collegebroad.org *.mysat.collegebroad.org *.plet.collegebroad.org *.practice.collegebroad.org

Other domains in certificate

auri.space *.auri.space *.remote.auri.space
avventuraalptop.com *.avventuraalptop.com *.webdisk.avventuraalptop.com
awardwinninghomeimprovements.com.au *.awardwinninghomeimprovements.com.au
cooptin.com *.cooptin.com *.hostmaster.cooptin.com *.ww1.cooptin.com
*.api.cryptopowered.club *.axe.cryptopowered.club *.bizjenkins.cryptopowered.club *.comaxe.cryptopowered.club *.compool2.cryptopowered.club cryptopowered.club *.cryptopowered.club *.dashboard.cryptopowered.club *.equihash.cryptopowered.club *.pool.cryptopowered.club *.pool2.cryptopowered.club *.prowww.cryptopowered.club *.ptpool.cryptopowered.club *.reporting.cryptopowered.club *.ruaxeninja.cryptopowered.club *.terminal.cryptopowered.club *.visualize.cryptopowered.club *.ww25.cryptopowered.club
*.crm.goldenstarsintls.com goldenstarsintls.com *.goldenstarsintls.com
*.hostmaster.jilo.in jilo.in *.jilo.in *.m.jilo.in *.mx.jilo.in *.old.jilo.in *.remote.jilo.in *.vpn.jilo.in *.wildcard.jilo.in
kazanmemory.club *.kazanmemory.club
*.jenkins.khohs.com khohs.com *.khohs.com *.ww.khohs.com
lasercuttingwelding304532.icu *.lasercuttingwelding304532.icu
loulcy.club *.loulcy.club
pagamentto-segurro.shop *.pagamentto-segurro.shop *.ww25.pagamentto-segurro.shop
pollination.com.au *.pollination.com.au
roxcasino-24club7.club *.roxcasino-24club7.club
*.jobui.sibai.net *.m.sibai.net sibai.net *.sibai.net
sultanhobbies.com.au *.sultanhobbies.com.au
*.development.thepointcaferestaurant.com.au *.mail.thepointcaferestaurant.com.au thepointcaferestaurant.com.au *.thepointcaferestaurant.com.au *.ww16.thepointcaferestaurant.com.au *.ww25.thepointcaferestaurant.com.au *.ww38.thepointcaferestaurant.com.au
*.bedg.xci.co.uk xci.co.uk *.xci.co.uk
*.mo.xinguan.com *.ww01.xinguan.com xinguan.com *.xinguan.com
zhiyun.com.au *.zhiyun.com.au