76/100 SECURITY SCORE

Certificate Information

Subject
CN=laksa.net
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026 84 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B1:19:D8:1B:84:A4:2B:32:81:40:65:C8:4D:58:E8:46:BD:7F:FC:C0:30:19:8B:7D:37:D3:F7:9A:58:83:E5:48
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
novamoda.com *.novamoda.com

Other domains in certificate

*.3n5isvd.advideo.xyz advideo.xyz *.advideo.xyz *.aol.advideo.xyz *.crawl.advideo.xyz *.damoh.advideo.xyz *.demo.advideo.xyz *.info.advideo.xyz *.mrs.advideo.xyz *.ms864cmgk.advideo.xyz *.ms9smfqqb.advideo.xyz *.msahlkpt.advideo.xyz *.msc67mat.advideo.xyz *.mscwix7ne.advideo.xyz *.mse9m40gq.advideo.xyz *.msi5sryeg.advideo.xyz *.msx648a8j.advideo.xyz *.mx.advideo.xyz *.privacy.advideo.xyz *.tw1.advideo.xyz *.ww5.advideo.xyz *.www.advideo.xyz *.z.advideo.xyz
*.aws.bmtour.com bmtour.com *.bmtour.com
laksa.net *.laksa.net *.ww5.laksa.net
*.api.lostboys.studio *.app.lostboys.studio *.demo.lostboys.studio *.dev.lostboys.studio lostboys.studio *.lostboys.studio *.www.lostboys.studio
manuscriptfelt.com *.manuscriptfelt.com *.nocrawl.manuscriptfelt.com
normativa.com *.normativa.com
onlinecalligraphy.com *.onlinecalligraphy.com
oremmortgage.com *.oremmortgage.com
osterhagen.com *.osterhagen.com
papandayan.com *.papandayan.com
parabebe.com *.parabebe.com
parkavenuebanquethall.com *.parkavenuebanquethall.com
passionatepatriot.com *.passionatepatriot.com
pathtogardenpeace.live *.pathtogardenpeace.live
pfaeffli.com *.pfaeffli.com
*.hostmaster.piastrine.com piastrine.com *.piastrine.com
plushboutique.com *.plushboutique.com
polster.com *.polster.com
posturologie.com *.posturologie.com
premierscale.com *.premierscale.com
prestamosfederales.com *.prestamosfederales.com
prouver.com *.prouver.com
proxydude.xyz *.proxydude.xyz
przekaz.com *.przekaz.com
pznn.com *.pznn.com
qb6by077.xyz *.qb6by077.xyz
*.amp.xhadult5.com *.test.xhadult5.com *.tr.xhadult5.com xhadult5.com *.xhadult5.com *.zh.xhadult5.com