Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=tugbaonline.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 19, 2026
Valid Until
June 17, 2026
39 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
31:CA:35:0C:09:93:D5:BA:B4:66:EC:29:E9:39:8B:12:3A:A5:5D:DA:B1:E5:B3:CB:F5:92:46:A3:EF:9C:5D:B1
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
wegotkidz.com
*.wegotkidz.com
*.curlz.wegotkidz.com
*.kidzwithcurlz.wegotkidz.com
*.random.wegotkidz.com
*.server.wegotkidz.com
50thcelebrationsweepstakes.com
*.50thcelebrationsweepstakes.com
*.ww25.50thcelebrationsweepstakes.com
beaconpulse.com
*.beaconpulse.com
*.samza.beaconpulse.com
*.users.beaconpulse.com
*.v28.beaconpulse.com
digitconsult.it
*.digitconsult.it
*.email.digitconsult.it
*.imap.digitconsult.it
*.mail.digitconsult.it
*.mx.digitconsult.it
*.pop.digitconsult.it
*.pop3.digitconsult.it
*.rds.digitconsult.it
*.smtp-in.digitconsult.it
*.access.dpf.it
*.demo.dpf.it
dpf.it
*.dpf.it
*.notexistsbackend.dpf.it
*.zs.dpf.it
fandomcasting.com
*.fandomcasting.com
*.hostmaster.fandomcasting.com
*.ww25.fandomcasting.com
*.www.fandomcasting.com
*.dlkrwi.gp-magma.net
gp-magma.net
*.gp-magma.net
*.id.gp-magma.net
*.ww38.gp-magma.net
*.zteywu.gp-magma.net
*.flowise.hardrockcafetampa.com
*.flowiseai.hardrockcafetampa.com
hardrockcafetampa.com
*.hardrockcafetampa.com
*.ns1.hardrockcafetampa.com
*.ns2.hardrockcafetampa.com
*.search.hardrockcafetampa.com
*.tour.hardrockcafetampa.com
*.ww16.hardrockcafetampa.com
*.ww25.hardrockcafetampa.com
icland.com
*.icland.com
*.mail.icland.com
*.ww25.icland.com
*.5crr2.njy.de
njy.de
*.njy.de
*.lfi.noe.bet
*.lk.noe.bet
noe.bet
*.noe.bet
*.seminarbaeuerinnen.noe.bet
*.admin.obeline.it
*.backend.obeline.it
*.dev.obeline.it
obeline.it
*.obeline.it
*.remote.obeline.it
pansudopokervip.bet
*.pansudopokervip.bet
*.cdn.tugbaonline.com
*.e.tugbaonline.com
tugbaonline.com
*.tugbaonline.com
*.ww25.tugbaonline.com
*.ww38.tugbaonline.com
*.www.tugbaonline.com
uptvotom.com
*.uptvotom.com
urgse.co
*.urgse.co
usa-en-moringamagic.com
*.usa-en-moringamagic.com
*.ww25.wwwcvscaremark.com
*.ww38.wwwcvscaremark.com
wwwcvscaremark.com
*.wwwcvscaremark.com
zuwal.com
*.zuwal.com
Other domains in certificate