Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=megamorano.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
May 31, 2026
Valid Until
August 29, 2026
88 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
10:3B:E7:74:71:53:DA:D6:DA:E6:FA:00:5B:54:0E:3C:2C:F6:E6:E5:0D:77:41:E3:02:CF:06:74:07:CD:F2:A9
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
62 domains
medicarepacificsource.com
*.medicarepacificsource.com
*.hostmaster.medicarepacificsource.com
*.random.medicarepacificsource.com
*.ww25.medicarepacificsource.com
*.ww31.medicarepacificsource.com
advertisehere.com.au
*.advertisehere.com.au
*.mx2.advertisehere.com.au
*.random.advertisehere.com.au
*.ww25.advertisehere.com.au
*.ww38.advertisehere.com.au
autismandbeyondapp.org
*.autismandbeyondapp.org
*.ww38.autismandbeyondapp.org
bridalgownhire.com.au
*.bridalgownhire.com.au
*.ww11.bridalgownhire.com.au
*.ww25.bridalgownhire.com.au
duoingo.com
*.duoingo.com
*.wildcard.duoingo.com
*.ww8.duoingo.com
eyebuydiret.com
*.eyebuydiret.com
*.hostmaster.eyebuydiret.com
*.ww25.eyebuydiret.com
goldankaufen.net
*.goldankaufen.net
*.ww25.goldankaufen.net
huynh.com.au
*.huynh.com.au
*.mail.huynh.com.au
*.java.lear.au
lear.au
*.lear.au
*.hostmaster.megamorano.com
*.mail.megamorano.com
megamorano.com
*.megamorano.com
*.ww16.megamorano.com
*.www.megamorano.com
randmvapestore.com
*.randmvapestore.com
*.ww25.randmvapestore.com
*.random.realrecovery.com.au
realrecovery.com.au
*.realrecovery.com.au
skatewearoutlet.com
*.skatewearoutlet.com
*.green.tittypix.com
tittypix.com
*.tittypix.com
*.wildcard.tittypix.com
*.ww25.tittypix.com
*.ww38.tittypix.com
unitarians.net
*.unitarians.net
*.ww25.unitarians.net
whichbike.com.au
*.whichbike.com.au
*.ww25.whichbike.com.au
Other domains in certificate