Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=cointer-pdvagro.com.br
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 24, 2026
Valid Until
May 25, 2026
49 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
3D:7E:BB:DE:9D:DF:BB:0F:0E:3F:EB:A1:AB:7C:B6:34:FF:51:6D:32:01:70:CC:DB:76:25:23:2A:31:0A:84:DB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
wasta.it
*.wasta.it
*.report.wasta.it
58287.net
*.58287.net
*.8vzjjk9.58287.net
*.beb4.58287.net
cargoweld.co
*.cargoweld.co
cointer-pdvagro.com.br
*.cointer-pdvagro.com.br
*.inscricao.cointer-pdvagro.com.br
*.4k.cricbozz.com
*.analytic.cricbozz.com
*.analytics.cricbozz.com
*.argo.cricbozz.com
*.bigdata.cricbozz.com
*.classifieds.cricbozz.com
*.corp-eur.cricbozz.com
*.cp.cricbozz.com
cricbozz.com
*.cricbozz.com
*.demo.cricbozz.com
*.dev.cricbozz.com
*.dhcp4.cricbozz.com
*.dt.cricbozz.com
*.events.cricbozz.com
*.fbx.cricbozz.com
*.gw2.cricbozz.com
*.lab.cricbozz.com
*.legacy.cricbozz.com
*.monitoring.cricbozz.com
*.mrtg.cricbozz.com
*.notexists4k.cricbozz.com
*.notexistsartemis.cricbozz.com
*.notexistsdt.cricbozz.com
*.notexistsww3.cricbozz.com
*.notexistsww6.cricbozz.com
*.orkflow.cricbozz.com
*.sip.cricbozz.com
*.superset.cricbozz.com
*.ww25.cricbozz.com
*.ww3.cricbozz.com
*.ww5.cricbozz.com
maioka.com
*.maioka.com
*.ww16.maioka.com
milionarios777.com
*.milionarios777.com
*.ww25.milionarios777.com
*.api.royolinvest.qpon
*.app.royolinvest.qpon
*.backend.royolinvest.qpon
*.backup.royolinvest.qpon
*.dashboard.royolinvest.qpon
*.dev.royolinvest.qpon
*.jjlrymwuzdassets.royolinvest.qpon
*.mail.royolinvest.qpon
*.marketing.royolinvest.qpon
*.qa.royolinvest.qpon
royolinvest.qpon
*.royolinvest.qpon
*.staging.royolinvest.qpon
*.stg.royolinvest.qpon
*.uat.royolinvest.qpon
*.v1.royolinvest.qpon
*.v2.royolinvest.qpon
*.web.royolinvest.qpon
*.wrbcqassets.royolinvest.qpon
*.cpcalendars.sikkiminsurance.in
*.m.sikkiminsurance.in
sikkiminsurance.in
*.sikkiminsurance.in
*.app.torchio.com
*.demo.torchio.com
*.dev.torchio.com
*.mail2.torchio.com
*.staging.torchio.com
*.supersets.torchio.com
torchio.com
*.torchio.com
tuxedorental.com.au
*.tuxedorental.com.au
*.sitemaps.velxara.com
velxara.com
*.velxara.com
*.www.velxara.com
*.hostmaster.virgia.com
virgia.com
*.virgia.com
Other domains in certificate