Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=avr-gadgets4.xyz
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
January 08, 2026
Valid Until
April 08, 2026
45 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
BE:32:91:F7:68:32:6D:03:4B:79:6B:90:21:E4:BE:B4:2F:93:03:4D:C8:59:5A:0C:79:70:68:7A:0B:07:53:F2
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
auth.name
*.auth.name
*.auth.auth.name
*.csd.auth.name
*.data.auth.name
*.elig3.auth.name
*.props.auth.name
*.server.auth.name
*.soap.auth.name
*.sysauth.auth.name
accu-tech.pro
*.accu-tech.pro
avr-gadgets4.xyz
*.avr-gadgets4.xyz
boobiepass.com
*.boobiepass.com
*.members.boobiepass.com
*.mhg.boobiepass.com
*.register.boobiepass.com
*.secure.boobiepass.com
*.ww38.boobiepass.com
*.www.boobiepass.com
*.acpe.edp.au
*.beautyedu.edp.au
edp.au
*.edp.au
*.ep.edp.au
*.gateways.edp.au
*.harvest.edp.au
*.alpha.humgay.us
*.ci.humgay.us
*.cpanel.humgay.us
*.hostmaster.humgay.us
humgay.us
*.humgay.us
*.mail.humgay.us
*.prod.humgay.us
*.report.humgay.us
*.sandbox.humgay.us
*.staging.humgay.us
*.superset.humgay.us
*.viz.humgay.us
*.wildcard.humgay.us
*.ww25.humgay.us
*.www.humgay.us
jesselle.au
*.jesselle.au
*.ww38.jesselle.au
*.mail.maximumsafety.com.au
maximumsafety.com.au
*.maximumsafety.com.au
*.ww38.maximumsafety.com.au
*.admin.mayalike.com
*.api.mayalike.com
*.app.mayalike.com
*.bbs.mayalike.com
*.demo.mayalike.com
*.dev.mayalike.com
*.git.mayalike.com
*.lwww.mayalike.com
*.mail.mayalike.com
mayalike.com
*.mayalike.com
*.repo.mayalike.com
*.rustore.mayalike.com
*.sitemap.mayalike.com
*.sitemaps.mayalike.com
*.staging.mayalike.com
*.vpn.mayalike.com
*.ww1.mayalike.com
*.ww12.mayalike.com
*.ww25.mayalike.com
*.ww38.mayalike.com
*.ww7.mayalike.com
*.ww99.mayalike.com
*.api.ooze.world
*.backend.ooze.world
ooze.world
*.ooze.world
*.sitemaps.ooze.world
primefloors.com.au
*.primefloors.com.au
*.ww25.primefloors.com.au
*.ww38.primefloors.com.au
slimstar.com
*.slimstar.com
weareeverise.co
*.weareeverise.co
*.ww25.weareeverise.co
*.ww38.weareeverise.co
Other domains in certificate