76/100 SECURITY SCORE

Certificate Information

Subject
CN=thecraftyspark.co.uk
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 04, 2026
Valid Until
September 02, 2026 87 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
C4:45:07:67:25:33:55:1A:DD:77:53:EE:EA:9A:28:99:DF:DC:71:B5:1C:03:3B:52:C0:C9:DD:DB:C0:92:86:46
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
flashtapes.com *.flashtapes.com *.9978d1b4-e5fa-4d1e-b255-594a62ea4334.flashtapes.com *.admin.flashtapes.com *.api.flashtapes.com *.app.flashtapes.com *.assets.flashtapes.com *.cloud.flashtapes.com *.demo.flashtapes.com *.hostmaster.flashtapes.com *.rd.flashtapes.com *.rds.flashtapes.com *.rdweb.flashtapes.com *.remote.flashtapes.com *.test.flashtapes.com *.vpn.flashtapes.com

Other domains in certificate

*.admin.eoiyouth.org *.api.eoiyouth.org *.app.eoiyouth.org *.autodiscover.eoiyouth.org *.cpanel.eoiyouth.org *.cpcontacts.eoiyouth.org *.dev.eoiyouth.org *.docs.eoiyouth.org eoiyouth.org *.eoiyouth.org *.external.eoiyouth.org *.hostmaster.eoiyouth.org *.intranet.eoiyouth.org *.m.eoiyouth.org *.mail.eoiyouth.org *.mta-sts.eoiyouth.org *.webdisk.eoiyouth.org *.webmail.eoiyouth.org
*.ahdwui.msmgrare.diamonds *.api.msmgrare.diamonds *.app.msmgrare.diamonds *.backoffice.msmgrare.diamonds *.cabinet.msmgrare.diamonds msmgrare.diamonds *.msmgrare.diamonds *.vygkrapp.msmgrare.diamonds
*.api.pi.luxury *.app.pi.luxury *.autodiscover.pi.luxury *.cadastro.pi.luxury *.dashboard.pi.luxury *.dev.pi.luxury *.landing.pi.luxury *.mailer.pi.luxury *.marketing.pi.luxury *.members.pi.luxury pi.luxury *.pi.luxury *.sbzrustaging.pi.luxury *.ssl.pi.luxury *.staging.pi.luxury *.test.pi.luxury *.uat.pi.luxury *.ud8m7x.pi.luxury *.v1.pi.luxury *.web.pi.luxury
thecraftyspark.co.uk *.thecraftyspark.co.uk
*.api.thrillwallet.com *.app.thrillwallet.com *.assets.thrillwallet.com *.beta.thrillwallet.com *.blog.thrillwallet.com *.bvwfcqid.thrillwallet.com *.dev.thrillwallet.com *.git.thrillwallet.com *.gitlab.thrillwallet.com *.hostmaster.thrillwallet.com *.internal.thrillwallet.com *.mail.thrillwallet.com *.panel.thrillwallet.com *.portal.thrillwallet.com *.prod.thrillwallet.com *.qfnxwstaging2.thrillwallet.com *.secure.thrillwallet.com *.shop.thrillwallet.com *.staging2.thrillwallet.com *.store.thrillwallet.com *.support.thrillwallet.com *.test.thrillwallet.com thrillwallet.com *.thrillwallet.com *.trftbmx.thrillwallet.com *.web.thrillwallet.com