76/100 SECURITY SCORE

Certificate Information

Subject
CN=pridefilmfestival.org
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 16, 2026
Valid Until
May 17, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
EA:89:52:2B:34:F0:BB:8D:86:D2:74:82:2A:30:EB:2E:CD:88:FF:8B:57:D7:83:AC:B8:BD:77:67:91:AA:DD:42
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
grumpygrouper.com *.grumpygrouper.com *.access.grumpygrouper.com *.anyconnect.grumpygrouper.com *.app.grumpygrouper.com *.apps.grumpygrouper.com *.auth.grumpygrouper.com *.autoconfig.grumpygrouper.com *.autodiscover.grumpygrouper.com *.calendar.grumpygrouper.com *.cisco.grumpygrouper.com *.ciscovpn.grumpygrouper.com *.citrix.grumpygrouper.com *.cloud.grumpygrouper.com *.cpanel.grumpygrouper.com *.drvpn.grumpygrouper.com *.email.grumpygrouper.com *.fax.grumpygrouper.com *.gateway.grumpygrouper.com *.globalprotect.grumpygrouper.com *.gp.grumpygrouper.com *.imap.grumpygrouper.com *.intra.grumpygrouper.com *.labvirtual.grumpygrouper.com *.m.grumpygrouper.com *.mail.grumpygrouper.com *.online.grumpygrouper.com *.portal.grumpygrouper.com *.prelogon.grumpygrouper.com *.ra.grumpygrouper.com *.ravpn.grumpygrouper.com *.rd.grumpygrouper.com *.rdp.grumpygrouper.com *.receiver.grumpygrouper.com *.remoteapp.grumpygrouper.com *.secureaccess.grumpygrouper.com *.smtp.grumpygrouper.com *.ssl.grumpygrouper.com *.sslvpn.grumpygrouper.com *.vdi.grumpygrouper.com *.virtualapps.grumpygrouper.com *.vpn.grumpygrouper.com *.vpnssl.grumpygrouper.com *.webdisk.grumpygrouper.com *.webmail.grumpygrouper.com *.workspace.grumpygrouper.com *.www.grumpygrouper.com

Other domains in certificate

1548-gg123.cfd *.1548-gg123.cfd *.29494.1548-gg123.cfd *.60130.1548-gg123.cfd *.88363.1548-gg123.cfd *.92231.1548-gg123.cfd
88goals.info *.88goals.info *.hilo.88goals.info *.hokm-ws.88goals.info *.hokm.88goals.info *.inbetapi.88goals.info *.penality.88goals.info *.poker-web.88goals.info *.predictor.88goals.info *.redgreen.88goals.info *.rgs-livedealerwebsocket.88goals.info *.warriors.88goals.info
*.admin.pridefilmfestival.org *.api.pridefilmfestival.org *.assets.pridefilmfestival.org *.autodiscover.pridefilmfestival.org *.e75d1aa4-185c-457e-81d8-b63ccf4a4613.pridefilmfestival.org *.ftp.pridefilmfestival.org *.lnyhins1.pridefilmfestival.org *.mail2.pridefilmfestival.org *.members.pridefilmfestival.org *.ns2.pridefilmfestival.org pridefilmfestival.org *.pridefilmfestival.org *.stg.pridefilmfestival.org *.tdacnowa.pridefilmfestival.org *.v1.pridefilmfestival.org *.webmail.pridefilmfestival.org *.wildcard.pridefilmfestival.org
*.dev.sulake.it *.helpdesk.sulake.it *.staging.sulake.it *.stats.sulake.it *.status.sulake.it sulake.it *.sulake.it