76/100 SECURITY SCORE

Certificate Information

Subject
CN=burgerday.us
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 19, 2026
Valid Until
September 17, 2026 83 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
75:C9:42:6D:B8:86:05:1F:1F:E7:E4:E4:53:37:BC:0F:B9:B3:93:E3:3A:A8:30:B6:6E:C2:EE:24:A8:A4:22:48
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
addcoupons.com *.addcoupons.com *.ftp.addcoupons.com *.localhost.addcoupons.com *.ssh.addcoupons.com

Other domains in certificate

al-leone.info *.al-leone.info *.correo.al-leone.info
assamtourism.com *.assamtourism.com *.random.assamtourism.com *.ww16.assamtourism.com
burgerday.us *.burgerday.us *.cicd.burgerday.us *.community.burgerday.us *.hostmaster.burgerday.us *.mobile.burgerday.us *.shop.burgerday.us *.whm.burgerday.us *.www.burgerday.us
dingdong77hoki.com *.dingdong77hoki.com *.sitemap.dingdong77hoki.com *.vpn.dingdong77hoki.com *.ww12.dingdong77hoki.com *.ww99.dingdong77hoki.com *.www.dingdong77hoki.com
*.app.dropabet.com *.arquivos.dropabet.com *.dan.dropabet.com *.demo.dropabet.com dropabet.com *.dropabet.com *.m.dropabet.com
*.dash.globalportal48h.com globalportal48h.com *.globalportal48h.com *.staging.globalportal48h.com
*.admin.ilginecologo.it ilginecologo.it *.ilginecologo.it
impression.it.com *.impression.it.com *.tss.impression.it.com
*.cpcalendars.internationallanguages.it *.cpcontacts.internationallanguages.it internationallanguages.it *.internationallanguages.it
*.g.mkiju.my mkiju.my *.mkiju.my
*.lp.ncncu.xyz ncncu.xyz *.ncncu.xyz *.poc.ncncu.xyz *.ww38.ncncu.xyz
*.m.paralegal.asia paralegal.asia *.paralegal.asia
*.dev.syktyvkar.org syktyvkar.org *.syktyvkar.org *.web.syktyvkar.org *.wildcard.syktyvkar.org
topnewoffers.shop *.topnewoffers.shop
tqshoes.shop *.tqshoes.shop
*.admin.ukproperty.it *.api.ukproperty.it *.app.ukproperty.it *.backend.ukproperty.it *.bi.ukproperty.it *.dashboards.ukproperty.it *.demo.ukproperty.it *.dev.ukproperty.it *.intelligence.ukproperty.it *.metric.ukproperty.it *.metrics.ukproperty.it *.superset.ukproperty.it ukproperty.it *.ukproperty.it *.www.ukproperty.it
*.32.utmr.studio *.comune.utmr.studio *.jp.utmr.studio utmr.studio *.utmr.studio