Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=stagegearstore.co.uk
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
December 22, 2025
Valid Until
March 22, 2026
40 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
9E:6B:27:C4:99:E9:30:03:2F:48:C9:FD:56:58:2F:45:BB:0F:4E:47:38:64:71:B6:CF:B3:93:88:36:13:84:13
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
71 domains
sidelegendotel.com
*.sidelegendotel.com
*.72373b1a1b43.sidelegendotel.com
*.cpcalendars.sidelegendotel.com
*.webdisk.sidelegendotel.com
anabelentome.co
*.anabelentome.co
auto01.co
*.auto01.co
bangflipchart.us
*.bangflipchart.us
bodyinmotionwigan.co.uk
*.bodyinmotionwigan.co.uk
fkk.de
*.fkk.de
*.limit.fkk.de
*.sakura.fkk.de
*.teesn.fkk.de
*.web.fkk.de
ied.au
*.ied.au
*.vi.ied.au
javsubindo.net
*.javsubindo.net
*.juavsubindo.javsubindo.net
*.random.javsubindo.net
*.tv.javsubindo.net
jessyalves.online
*.jessyalves.online
lo7tak.com
*.lo7tak.com
*.ww25.lo7tak.com
netflixmirrir.com
*.netflixmirrir.com
*.ww25.netflixmirrir.com
*.ww38.netflixmirrir.com
*.media.raptorfind.com
*.pool.raptorfind.com
raptorfind.com
*.raptorfind.com
*.acceptatie.secretinternetsys.com
*.cloud.secretinternetsys.com
*.oud.secretinternetsys.com
*.rd.secretinternetsys.com
*.rds.secretinternetsys.com
*.remote.secretinternetsys.com
secretinternetsys.com
*.secretinternetsys.com
*.sitemaps.secretinternetsys.com
*.mail.stagegearstore.co.uk
*.mrcaudio.stagegearstore.co.uk
stagegearstore.co.uk
*.stagegearstore.co.uk
*.random.totallib.com
totallib.com
*.totallib.com
turismoseguro.com
*.turismoseguro.com
*.atwww.v3instruments.com
*.comwww.v3instruments.com
*.new.v3instruments.com
*.qwertypanda.v3instruments.com
*.random.v3instruments.com
*.sounderveethreewww.v3instruments.com
*.usawww.v3instruments.com
v3instruments.com
*.v3instruments.com
*.veethreewww.v3instruments.com
*.w.v3instruments.com
*.ww.v3instruments.com
*.ww25.v3instruments.com
Other domains in certificate