76/100 SECURITY SCORE

Certificate Information

Subject
CN=filhotescaesbh.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 13, 2026
Valid Until
May 14, 2026 89 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
29:36:34:56:1A:6E:0A:E3:56:98:09:7C:35:B2:D8:CD:57:DF:65:44:1B:31:0A:BF:4A:53:B0:E6:91:EB:CF:A3
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
concordwatch.com *.concordwatch.com *.andromeda.concordwatch.com *.ar.concordwatch.com *.its.concordwatch.com *.msk.concordwatch.com *.portainer.concordwatch.com *.static.concordwatch.com

Other domains in certificate

av-actressstar.com *.av-actressstar.com *.ww12.av-actressstar.com
*.ask.espinar.com *.edge.espinar.com espinar.com *.espinar.com *.m.espinar.com *.postmaster.espinar.com *.www.espinar.com
espnwwwos.com *.espnwwwos.com *.ww12.espnwwwos.com
filhotescaesbh.com *.filhotescaesbh.com *.ww1.filhotescaesbh.com
hicandaroniiosdalctrl.cyou *.hicandaroniiosdalctrl.cyou *.smtp.hicandaroniiosdalctrl.cyou
*.app.min88mega.monster *.backup.min88mega.monster *.eqajnuat.min88mega.monster *.evolution.min88mega.monster *.hostmaster.min88mega.monster *.kavdiejg.min88mega.monster *.marketing.min88mega.monster min88mega.monster *.min88mega.monster *.qa.min88mega.monster *.web.min88mega.monster
pebshampharmacy.co.uk *.pebshampharmacy.co.uk
*.coffey.smarvault.com smarvault.com *.smarvault.com
su04rt.top *.su04rt.top
sun777.love *.sun777.love
*.sitemap.sweeptracker.com *.store.sweeptracker.com sweeptracker.com *.sweeptracker.com
*.hostmaster.trovazienda.it trovazienda.it *.trovazienda.it
uogzwp.top *.uogzwp.top
*.access.weddingchick.com *.admin.weddingchick.com *.api.weddingchick.com *.app.weddingchick.com *.apps.weddingchick.com *.assets.weddingchick.com *.cloud.weddingchick.com *.demo.weddingchick.com *.dev.weddingchick.com *.glutaapi.weddingchick.com *.hostmaster.weddingchick.com *.m.weddingchick.com *.mail.weddingchick.com *.members.weddingchick.com *.rdp.weddingchick.com *.rds1.weddingchick.com *.rdweb.weddingchick.com *.remote.weddingchick.com *.sitemap.weddingchick.com *.sitemaps.weddingchick.com *.staging.weddingchick.com *.test.weddingchick.com *.ts.weddingchick.com *.vpn.weddingchick.com weddingchick.com *.weddingchick.com *.ww1.weddingchick.com *.ww11.weddingchick.com *.ww16.weddingchick.com *.ww25.weddingchick.com
y8games.my *.y8games.my
yassistants.com *.yassistants.com