Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=health-care-cost.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 11, 2026
Valid Until
August 09, 2026
74 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
73:BC:BF:58:6D:89:B1:39:04:3B:7C:10:0F:7D:70:2E:85:67:9D:76:6B:10:E9:33:C4:F7:CF:A3:A7:09:B1:52
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
82 domains
yasuj.com
*.yasuj.com
*.static.yasuj.com
131076.com
*.131076.com
*.random.131076.com
3feel.com
*.3feel.com
*.ww25.3feel.com
brasserielecercle.com
*.brasserielecercle.com
*.ww25.brasserielecercle.com
commercialpilot.com.au
*.commercialpilot.com.au
electrolysisbyrosemarie.com
*.electrolysisbyrosemarie.com
fixer-net.com
*.fixer-net.com
hdyuhhgdgshha1217.top
*.hdyuhhgdgshha1217.top
*.dev.health-care-cost.com
*.explore.health-care-cost.com
*.forum.health-care-cost.com
health-care-cost.com
*.health-care-cost.com
*.intelligence.health-care-cost.com
*.m.health-care-cost.com
*.new.health-care-cost.com
*.random.health-care-cost.com
*.shop.health-care-cost.com
*.test.health-care-cost.com
healthywatersheds.org
*.healthywatersheds.org
heating-system-q6u6x.click
*.heating-system-q6u6x.click
hedge-fund-investment.click
*.hedge-fund-investment.click
hfk66.icu
*.hfk66.icu
hmj.com.au
*.hmj.com.au
hoktoto.vip
*.hoktoto.vip
icklicker.com
*.icklicker.com
*.join.icklicker.com
*.ww38.icklicker.com
kingsdaughter.org
*.kingsdaughter.org
konnichiwa9.click
*.konnichiwa9.click
*.kubeflow-pipeline.konnichiwa9.click
*.learn.konnichiwa9.click
lenakedlunch.com
*.lenakedlunch.com
*.ww38.lenakedlunch.com
mercurylegal.com.au
*.mercurylegal.com.au
minnetonkawhec67.org
*.minnetonkawhec67.org
nighclub.eu
*.nighclub.eu
nilayashokshah.com
*.nilayashokshah.com
*.www.nilayashokshah.com
*.academy.purpletree.life
*.m.purpletree.life
*.mail.purpletree.life
purpletree.life
*.purpletree.life
redpanda.au
*.redpanda.au
sigtrak.net
*.sigtrak.net
theysayitsrare.com
*.theysayitsrare.com
workerhealth.com.au
*.workerhealth.com.au
xn--q3cropc2fyf.com
*.xn--q3cropc2fyf.com
yummyy.cc
*.yummyy.cc
Other domains in certificate