Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=hni.cc
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 01, 2026
Valid Until
May 02, 2026
79 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6D:99:8C:73:5B:9D:04:02:F7:A6:D4:63:B9:76:3A:49:86:B7:E0:B3:90:A9:00:BC:E6:A9:AC:40:27:F0:2C:86
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
rushseating.com
*.rushseating.com
aowleeftijd.eu
*.aowleeftijd.eu
*.x1335y22993.aowleeftijd.eu
bebis.com
*.bebis.com
*.connect.bebis.com
*.portal.bebis.com
*.ww16.bebis.com
cebufurniture.com
*.cebufurniture.com
*.ww1.cebufurniture.com
charol.com
*.charol.com
*.cloud.charol.com
*.cloudvpn.charol.com
*.owa.charol.com
*.ravpn.charol.com
*.vpn.charol.com
*.webvpn.charol.com
hangler.com
*.hangler.com
*.ww25.hangler.com
hni.cc
*.hni.cc
*.wildcard.hni.cc
*.aa.hotong.store
hotong.store
*.hotong.store
*.shop.hotong.store
ptikfq.pro
*.ptikfq.pro
puzpb.pro
*.puzpb.pro
revoletshipcycle.com
*.revoletshipcycle.com
sanskriticonventschool.in
*.sanskriticonventschool.in
sdnvjq.net
*.sdnvjq.net
*.com.shengchan.com
*.hjsp.shengchan.com
shengchan.com
*.shengchan.com
*.www.shengchan.com
shimato.net
*.shimato.net
sloansirvicing.com
*.sloansirvicing.com
sssgame.pro
*.sssgame.pro
thedefiacademy.com
*.thedefiacademy.com
theiconicbrandcompanies.com
*.theiconicbrandcompanies.com
tkefp.pro
*.tkefp.pro
truck-driving-jobs-us-au281065.icu
*.truck-driving-jobs-us-au281065.icu
ucmnt.pro
*.ucmnt.pro
ued055.com
*.ued055.com
ufa147g.live
*.ufa147g.live
unwin.pro
*.unwin.pro
vg88.info
*.vg88.info
vyz42.top
*.vyz42.top
website-erstellen-01.cfd
*.website-erstellen-01.cfd
winbr.love
*.winbr.love
workliferefinery.com
*.workliferefinery.com
xgkrmv.top
*.xgkrmv.top
yedusw.top
*.yedusw.top
yqg31.top
*.yqg31.top
zdqcw.net
*.zdqcw.net
zjfvd.academy
*.zjfvd.academy
zy635.top
*.zy635.top
Other domains in certificate