Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=forlab.co
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 24, 2026
Valid Until
August 22, 2026
68 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E2:FD:D9:F0:C3:FA:E6:4D:D2:0B:6C:83:F6:C3:A5:7F:6C:47:BB:61:60:51:E4:64:95:52:4C:B3:B1:CD:33:E9
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
85 domains
weeklyminutes.com
*.weeklyminutes.com
forlab.co
*.forlab.co
gen77velocity.lol
*.gen77velocity.lol
gen77velocity.sbs
*.gen77velocity.sbs
*.3on.googleplaysinpeoria.com
googleplaysinpeoria.com
*.googleplaysinpeoria.com
gouwthailand.xyz
*.gouwthailand.xyz
h17.my
*.h17.my
innersoulpath.info
*.innersoulpath.info
mk571.xyz
*.mk571.xyz
nasp2021.com
*.nasp2021.com
neuraplumb.com
*.neuraplumb.com
newwave.dev
*.newwave.dev
onitsuka-tiger-hungary.com
*.onitsuka-tiger-hungary.com
panen99.company
*.panen99.company
pinaiq.com
*.pinaiq.com
s80joystk.lol
*.s80joystk.lol
sattaking-satta.in
*.sattaking-satta.in
scrumgenie.com
*.scrumgenie.com
spaceplay.tech
*.spaceplay.tech
speaker-br1.today
*.speaker-br1.today
svqb6l.cyou
*.svqb6l.cyou
swanseaenergy.com
*.swanseaenergy.com
tarnymus.club
*.tarnymus.club
telebotcare.com
*.telebotcare.com
thegreatlinkrace.com
*.thegreatlinkrace.com
theweddingprecision.beauty
*.theweddingprecision.beauty
thr77.blog
*.thr77.blog
tipsershub.com
*.tipsershub.com
tmxkn.biz
*.tmxkn.biz
tradingsi.com
*.tradingsi.com
tradisibet.monster
*.tradisibet.monster
trgoals1346.xyz
*.trgoals1346.xyz
tweakmytwitter.com
*.tweakmytwitter.com
userauth-bo2fa.com
*.userauth-bo2fa.com
v6v3919.xyz
*.v6v3919.xyz
vulkanpobeda-slot.com
*.vulkanpobeda-slot.com
w429jm.cyou
*.w429jm.cyou
w46m.cyou
*.w46m.cyou
x599.cn
*.x599.cn
xn--e-c49b.com
*.xn--e-c49b.com
yahh.com.au
*.yahh.com.au
yuntu.best
*.yuntu.best
Other domains in certificate