76/100 SECURITY SCORE

Certificate Information

Subject
CN=orcaai.com.br
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 07, 2026
Valid Until
September 05, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
43:85:78:73:CD:AC:D9:4F:8C:FA:2C:E0:59:02:77:8E:1A:99:C1:27:22:DF:8E:6D:9B:47:1A:A9:B1:92:FF:F1
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
shotofjaq.org *.shotofjaq.org *.random.shotofjaq.org *.ww25.shotofjaq.org

Other domains in certificate

123-movies.bet *.123-movies.bet *.kimo.123-movies.bet
17thstar.com *.17thstar.com *.cdn.17thstar.com *.ww25.17thstar.com
5a.studio *.5a.studio
airportlimos.au *.airportlimos.au
cabaredrinks.com *.cabaredrinks.com *.ww25.cabaredrinks.com
canvamod.pro *.canvamod.pro
cleangroup.it *.cleangroup.it
ducharmefox.com *.ducharmefox.com *.heart.ducharmefox.com *.ww25.ducharmefox.com *.www.ducharmefox.com *.ysxy.ducharmefox.com
gama567.io *.gama567.io
*.cpanel.globalconstructionmachineries.com globalconstructionmachineries.com *.globalconstructionmachineries.com
hopeandanchorflookburgh.co.uk *.hopeandanchorflookburgh.co.uk
hung.au *.hung.au
incaseofemergencyblog.co *.incaseofemergencyblog.co
jobform.io *.jobform.io
*.gplora.libcryptocoin.info libcryptocoin.info *.libcryptocoin.info *.sitemaps.libcryptocoin.info *.ww25.libcryptocoin.info
liberaria.life *.liberaria.life
*.admin786.muktisoftware.net muktisoftware.net *.muktisoftware.net
nnmclub.xyz *.nnmclub.xyz
opal1699.com *.opal1699.com
orcaai.com.br *.orcaai.com.br
panda-press.com *.panda-press.com *.tec.panda-press.com *.ww12.panda-press.com
photostreet.au *.photostreet.au
*.random.sassyprimitives.com sassyprimitives.com *.sassyprimitives.com
spyorg.com *.spyorg.com
strapsandbags.co.uk *.strapsandbags.co.uk
*.cdn-0.swabifirmware.online *.integration-pipeline.swabifirmware.online *.jenkins-test.swabifirmware.online swabifirmware.online *.swabifirmware.online *.uat-jenkins.swabifirmware.online *.ww25.swabifirmware.online
tosfedizmir.org *.tosfedizmir.org
tvelectro.pro *.tvelectro.pro *.www.tvelectro.pro
vulkan.bz *.vulkan.bz
*.m.xn--j6w82vqxfq21a.com *.rds.xn--j6w82vqxfq21a.com *.rdweb.xn--j6w82vqxfq21a.com *.sitemap.xn--j6w82vqxfq21a.com xn--j6w82vqxfq21a.com *.xn--j6w82vqxfq21a.com