76/100 SECURITY SCORE

Certificate Information

Subject
CN=lottatori.com
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
May 28, 2026
Valid Until
August 26, 2026 73 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
18:D0:7B:C2:00:36:F3:BF:FF:05:A9:92:DD:59:D5:A8:C8:6D:DD:2C:B7:61:3A:0F:67:7F:A7:1A:7C:76:98:C3
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
mevsimsiz.com *.mevsimsiz.com *.random.mevsimsiz.com *.sitemaps.mevsimsiz.com *.vdi.mevsimsiz.com

Other domains in certificate

*.8mfyuw57qh46wuj4.centralpixelvibe.com *.admin.centralpixelvibe.com *.api.centralpixelvibe.com centralpixelvibe.com *.centralpixelvibe.com *.dev.centralpixelvibe.com *.hostmaster.centralpixelvibe.com *.mail.centralpixelvibe.com *.panel.centralpixelvibe.com *.sitemap.centralpixelvibe.com *.sitemaps.centralpixelvibe.com *.vpn.centralpixelvibe.com *.webmail.centralpixelvibe.com *.ww1.centralpixelvibe.com *.ww12.centralpixelvibe.com *.ww99.centralpixelvibe.com *.www.centralpixelvibe.com
*.bhttwww.fasdefense.fr *.f.fasdefense.fr fasdefense.fr *.fasdefense.fr *.m.fasdefense.fr *.ww1.fasdefense.fr *.ww130.fasdefense.fr *.ww131.fasdefense.fr *.ww133.fasdefense.fr *.ww135.fasdefense.fr *.ww137.fasdefense.fr *.ww138.fasdefense.fr *.ww139.fasdefense.fr *.ww140.fasdefense.fr *.ww141.fasdefense.fr *.ww142.fasdefense.fr *.ww145.fasdefense.fr *.ww146.fasdefense.fr *.ww38.fasdefense.fr *.wwv.fasdefense.fr
fitnessventurepro.run *.fitnessventurepro.run
fumedo.pro *.fumedo.pro
genuineglobetravel.xyz *.genuineglobetravel.xyz
*.app.howtobuygoldcoins.com howtobuygoldcoins.com *.howtobuygoldcoins.com *.staging.howtobuygoldcoins.com
lottatori.com *.lottatori.com
*.admin.namenickels.com *.d603c764-2f69-4b69-a590-6acae593916b.namenickels.com *.ekb.namenickels.com *.hostmaster.namenickels.com namenickels.com *.namenickels.com
onlycash.co *.onlycash.co
*.a.pdfhub.info *.app.pdfhub.info *.bxswgefp.pdfhub.info *.dev.pdfhub.info pdfhub.info *.pdfhub.info
projectgo.co *.projectgo.co *.sitemaps.projectgo.co
savorsatch.com *.savorsatch.com *.www.savorsatch.com
*.api.stardacasino-vsem1.top *.m.stardacasino-vsem1.top stardacasino-vsem1.top *.stardacasino-vsem1.top
*.login.trade-vedex2.com trade-vedex2.com *.trade-vedex2.com
tradiesm8.com.au *.tradiesm8.com.au *.webdisk.tradiesm8.com.au
vapezone.co *.vapezone.co *.www.vapezone.co
*.4k7.xiaohaitun.net.cn xiaohaitun.net.cn *.xiaohaitun.net.cn