76/100 SECURITY SCORE

Certificate Information

Subject
CN=hottestwomaninthegalaxy.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 04, 2026
Valid Until
September 02, 2026 84 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
25:E4:D0:F6:C2:DD:66:18:B6:44:16:26:88:00:51:57:C8:CD:FC:3B:66:2B:79:35:DF:9A:75:E3:31:D2:23:32
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
debavent.com *.debavent.com *.account.debavent.com *.admin.debavent.com *.administration.debavent.com *.api.debavent.com *.app.debavent.com *.assets.debavent.com *.auth.debavent.com *.backup.debavent.com *.blog.debavent.com *.client.debavent.com *.cloud.debavent.com *.dashboard.debavent.com *.dev.debavent.com *.fevnsjor.debavent.com *.fwubvspx.debavent.com *.home.debavent.com *.hostmaster.debavent.com *.jenkins.debavent.com *.llm.debavent.com *.m.debavent.com *.mail.debavent.com *.mailer.debavent.com *.marketing.debavent.com *.new.debavent.com *.news.debavent.com *.partner.debavent.com *.pipelines.debavent.com *.portal.debavent.com *.prod.debavent.com *.qa.debavent.com *.rd.debavent.com *.rds.debavent.com *.remote.debavent.com *.remoto.debavent.com *.stats.debavent.com *.stg.debavent.com *.test.debavent.com *.tickets.debavent.com *.trend.debavent.com *.uat.debavent.com *.unix.debavent.com *.user.debavent.com *.v1.debavent.com *.vdzpirds.debavent.com *.vpn.debavent.com *.wap.debavent.com *.web.debavent.com *.yzbkdgms.debavent.com

Other domains in certificate

*.api.hottestwomaninthegalaxy.com *.app.hottestwomaninthegalaxy.com *.cpmzhtgs.hottestwomaninthegalaxy.com *.dashboard.hottestwomaninthegalaxy.com *.dev.hottestwomaninthegalaxy.com hottestwomaninthegalaxy.com *.hottestwomaninthegalaxy.com *.mail.hottestwomaninthegalaxy.com *.mailer.hottestwomaninthegalaxy.com *.marketing.hottestwomaninthegalaxy.com *.members.hottestwomaninthegalaxy.com *.secure.hottestwomaninthegalaxy.com *.test.hottestwomaninthegalaxy.com *.ujomerfk.hottestwomaninthegalaxy.com *.v1.hottestwomaninthegalaxy.com *.v2.hottestwomaninthegalaxy.com *.web.hottestwomaninthegalaxy.com *.xlqzrapi.hottestwomaninthegalaxy.com
*.admin.portalfhd.com *.api.portalfhd.com *.app.portalfhd.com *.assets.portalfhd.com *.backup.portalfhd.com *.dashboard.portalfhd.com *.demo.portalfhd.com *.dev.portalfhd.com *.ktwqhavz.portalfhd.com *.mail.portalfhd.com *.mailer.portalfhd.com *.marketing.portalfhd.com *.members.portalfhd.com *.ojrpndemo.portalfhd.com portalfhd.com *.portalfhd.com *.staging.portalfhd.com *.txctrapi.portalfhd.com *.uat.portalfhd.com *.v1.portalfhd.com *.v2.portalfhd.com *.web.portalfhd.com