76/100 SECURITY SCORE

Certificate Information

Subject
CN=bestwestern.au
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 12, 2026
Valid Until
July 11, 2026 50 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
00:17:B7:46:03:25:46:1C:87:35:E2:BD:D5:D3:F9:28:B3:C2:19:16:C9:66:3F:F7:B2:80:D9:1A:7E:E4:D7:EC
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
vanguardglassblock.com *.vanguardglassblock.com *.integration.vanguardglassblock.com *.preview.vanguardglassblock.com *.superset.vanguardglassblock.com *.tech.vanguardglassblock.com *.test.vanguardglassblock.com

Other domains in certificate

acll.org *.acll.org *.ftp.acll.org *.ns1.acll.org *.ww1.acll.org
balandros.com *.balandros.com *.hostmaster.balandros.com *.ww25.balandros.com
bestwestern.au *.bestwestern.au *.ww25.bestwestern.au
braghini.com *.braghini.com *.juli.braghini.com
*.bi.checkcredit.com.au checkcredit.com.au *.checkcredit.com.au *.demo.checkcredit.com.au *.production.checkcredit.com.au *.ww1.checkcredit.com.au *.ww25.checkcredit.com.au *.ww38.checkcredit.com.au
*.com.cometschoolsupplies.com cometschoolsupplies.com *.cometschoolsupplies.com *.ww16.cometschoolsupplies.com *.ww17.cometschoolsupplies.com *.ww25.cometschoolsupplies.com *.ww38.cometschoolsupplies.com
fasthouse.co *.fasthouse.co *.mx.fasthouse.co *.www.fasthouse.co
*.app.homesolarpanels.it *.demo.homesolarpanels.it homesolarpanels.it *.homesolarpanels.it *.staging.homesolarpanels.it *.webmail.homesolarpanels.it
*.cpanel.miamiredcross.org *.dqxy.miamiredcross.org *.hostmaster.miamiredcross.org miamiredcross.org *.miamiredcross.org *.random.miamiredcross.org *.reply.miamiredcross.org *.ww25.miamiredcross.org
puja24.in *.puja24.in *.uqeeipost.puja24.in
*.random.s6x3.mom s6x3.mom *.s6x3.mom
*.dev.selltraffic.uk selltraffic.uk *.selltraffic.uk *.shop.selltraffic.uk *.v2.selltraffic.uk
*.pay.sherrimorgan.com sherrimorgan.com *.sherrimorgan.com
*.dns.tennesseetitansjersey.us tennesseetitansjersey.us *.tennesseetitansjersey.us
*.hrka1.wanderlusttravelguides.xyz *.kwid9.wanderlusttravelguides.xyz *.ndifg.wanderlusttravelguides.xyz *.nktjv.wanderlusttravelguides.xyz *.vizaseq.wanderlusttravelguides.xyz wanderlusttravelguides.xyz *.wanderlusttravelguides.xyz *.wfo557lgte8h9jde32a5i16i.wanderlusttravelguides.xyz *.wfsab865ajvcdnde3suvno2u.wanderlusttravelguides.xyz *.y9zz2.wanderlusttravelguides.xyz
*.e5261e9b-5da9-4a42-bba5-03e78d0c889a.xn--d1aiaemzn.com *.hostmaster.xn--d1aiaemzn.com *.m.xn--d1aiaemzn.com *.mail.xn--d1aiaemzn.com *.omsk.xn--d1aiaemzn.com xn--d1aiaemzn.com *.xn--d1aiaemzn.com