76/100 SECURITY SCORE

Certificate Information

Subject
CN=anywherecompass.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 22, 2026
Valid Until
July 21, 2026 44 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
18:3A:F2:9A:94:30:A4:80:A1:C2:6A:53:5C:AB:28:23:D0:C6:74:F3:F6:82:36:D5:AD:6B:D3:D3:4B:EB:37:A8
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
touchstyle.it *.touchstyle.it *.backend.touchstyle.it *.redash.touchstyle.it

Other domains in certificate

1win-bk-web.top *.1win-bk-web.top *.blog.1win-bk-web.top *.d.1win-bk-web.top
amk9.bet *.amk9.bet *.dashboard.amk9.bet *.insight.amk9.bet
*.30f6a413-4c7c-42a0-8389-f7572207cb80.anywherecompass.com *.9dd54da8-3bca-4a4d-a27d-0e5d6bb7e058.anywherecompass.com anywherecompass.com *.anywherecompass.com *.api.anywherecompass.com *.app.anywherecompass.com *.cloud.anywherecompass.com *.docs.anywherecompass.com *.new.anywherecompass.com *.rd.anywherecompass.com *.rdweb.anywherecompass.com *.remote.anywherecompass.com
appscode.us *.appscode.us
birchtreepodiatry.com *.birchtreepodiatry.com *.bot.birchtreepodiatry.com *.dev.birchtreepodiatry.com *.smtp.birchtreepodiatry.com *.ww25.birchtreepodiatry.com *.www.birchtreepodiatry.com
blushy.pro *.blushy.pro
bosslot99b.site *.bosslot99b.site
drjavierbotia.co *.drjavierbotia.co *.ww25.drjavierbotia.co
*.admin.foodfighter.it *.api.foodfighter.it *.dashboard.foodfighter.it *.demo.foodfighter.it foodfighter.it *.foodfighter.it *.hostmaster.foodfighter.it *.staging.foodfighter.it
ibeiomz.site *.ibeiomz.site
lampshadesandtheaccessory.com *.lampshadesandtheaccessory.com *.ww38.lampshadesandtheaccessory.com
lastminuteflights.com.au *.lastminuteflights.com.au
megabook.com.au *.megabook.com.au
negotiation.com.au *.negotiation.com.au
passivebee.com *.passivebee.com *.www.passivebee.com
*.admin.readingfestival.it *.analytic.readingfestival.it *.backend.readingfestival.it *.dev.readingfestival.it readingfestival.it *.readingfestival.it *.superset.readingfestival.it
*.alpha.solopreneur.buzz *.insight-development.solopreneur.buzz *.insight-poc.solopreneur.buzz solopreneur.buzz *.solopreneur.buzz
spasser.com *.spasser.com
*.app.teamtrek.top *.sitemap.teamtrek.top teamtrek.top *.teamtrek.top
*.bgs.vik.au vik.au *.vik.au
*.random.wwwgeicoddc.com *.ww38.wwwgeicoddc.com wwwgeicoddc.com *.wwwgeicoddc.com
*.www.xzzybyq.com xzzybyq.com *.xzzybyq.com