76/100 SECURITY SCORE

Certificate Information

Subject
CN=growshop.cc
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 30, 2026
Valid Until
July 29, 2026 47 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
67:9E:4B:C3:26:F9:CE:B1:33:50:EA:43:CF:5B:02:1F:D5:AA:08:E8:14:D6:21:25:47:39:34:E7:DA:95:94:49
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
chefstech.co *.chefstech.co *.adminer.chefstech.co *.login.chefstech.co *.private.chefstech.co *.springboot.chefstech.co *.sso.chefstech.co

Other domains in certificate

50919.loan *.50919.loan
50975.my *.50975.my
5099sv10.cc *.5099sv10.cc
79896.cc *.79896.cc *.www.79896.cc
brillancupeautos.com *.brillancupeautos.com
d83c.run *.d83c.run
d863jwd97c.world *.d863jwd97c.world
dcsrf630.com *.dcsrf630.com
dental-marketing-7878.click *.dental-marketing-7878.click
*.30sjourney.dizim.ai *.app.dizim.ai *.cuonggaugau.dizim.ai *.demobarcelo.dizim.ai dizim.ai *.dizim.ai *.easy.dizim.ai *.hustson.dizim.ai *.ove.dizim.ai *.support.dizim.ai *.thegioidocongnghetienich.dizim.ai *.tranlinh.dizim.ai *.vpb.dizim.ai *.ww38.dizim.ai
*.9fgn52.gold-dragon.bet gold-dragon.bet *.gold-dragon.bet
*.admin.growshop.cc *.app.growshop.cc *.dev.growshop.cc growshop.cc *.growshop.cc *.sitemaps.growshop.cc *.test.growshop.cc
karrierekupompas.com *.karrierekupompas.com
king4tv.net *.king4tv.net
nortongratis.com *.nortongratis.com *.ww12.nortongratis.com *.ww38.nortongratis.com
personal-loans-pl0430.top *.personal-loans-pl0430.top
plancraft.net *.plancraft.net
qrislnpay.com *.qrislnpay.com
redbull789.bio *.redbull789.bio
secfk.cc *.secfk.cc
sobatkaltim.com *.sobatkaltim.com
style-shoes.com *.style-shoes.com *.ww38.style-shoes.com *.www.style-shoes.com
tango77bray.xyz *.tango77bray.xyz
thenorthfacevest.com *.thenorthfacevest.com
theunionpost.com *.theunionpost.com
*.a.worldashome.com *.admin.worldashome.com *.demo.worldashome.com *.dev.worldashome.com *.klkhma.worldashome.com worldashome.com *.worldashome.com
xgambet.me *.xgambet.me