Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=cleanbend.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
June 20, 2026
Valid Until
September 18, 2026 88 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
33:35:CC:44:34:52:E2:EE:A6:F7:74:B1:7B:FA:1F:67:9E:C8:63:E6:1D:51:C5:ED:AD:27:2C:F3:8A:F2:30:3C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
allevon.com *.allevon.com *.admin.allevon.com *.api.allevon.com *.hostmaster.allevon.com *.member.allevon.com *.test.allevon.com

Other domains in certificate

*.access.bihba.com *.admin.bihba.com *.anyconnect.bihba.com *.api.bihba.com *.apps.bihba.com bihba.com *.bihba.com *.dev.bihba.com *.gitlab.bihba.com *.mail.bihba.com *.o.bihba.com *.rdp.bihba.com *.remote.bihba.com *.rh.bihba.com *.shop.bihba.com *.test.bihba.com *.vpn.bihba.com *.webmail.bihba.com *.webvpn.bihba.com
*.backend.chickenwingsrecipesinfo-us.site chickenwingsrecipesinfo-us.site *.chickenwingsrecipesinfo-us.site *.cicd.chickenwingsrecipesinfo-us.site *.mail.chickenwingsrecipesinfo-us.site *.uccmrdev.chickenwingsrecipesinfo-us.site *.ww38.chickenwingsrecipesinfo-us.site
*.access.cleanbend.com *.accounts.cleanbend.com *.activesync.cleanbend.com *.admin.cleanbend.com *.anyconnect.cleanbend.com *.checkpoint.cleanbend.com cleanbend.com *.cleanbend.com *.fortivpn.cleanbend.com *.gateway.cleanbend.com *.outlook.cleanbend.com *.proxy.cleanbend.com
*.admin.coachspherebrand.com *.app.coachspherebrand.com *.blog.coachspherebrand.com coachspherebrand.com *.coachspherebrand.com
*.account.lieyong.com *.admin.lieyong.com *.api.lieyong.com *.auth.lieyong.com *.backup.lieyong.com *.beta.lieyong.com *.blog.lieyong.com *.cloud.lieyong.com *.crm.lieyong.com *.demo.lieyong.com *.forum.lieyong.com *.forums.lieyong.com *.help.lieyong.com *.intranet.lieyong.com lieyong.com *.lieyong.com *.m.lieyong.com *.new.lieyong.com *.old.lieyong.com *.owhmsforum.lieyong.com *.racypowhmsforum.lieyong.com *.rd.lieyong.com *.rds.lieyong.com *.rdweb.lieyong.com *.remote.lieyong.com *.shop.lieyong.com *.sso.lieyong.com *.staging.lieyong.com *.store.lieyong.com *.temp.lieyong.com *.uyqhlforum.lieyong.com *.vpn.lieyong.com *.wiki.lieyong.com
*.cpcalendars.nursehub.org nursehub.org *.nursehub.org
*.blog.xiansb.com *.mail.xiansb.com xiansb.com *.xiansb.com