76/100 SECURITY SCORE

Certificate Information

Subject
CN=kitchenmorocco.com
Issuer
C=US, O=Let's Encrypt, CN=YR2
Valid From
May 30, 2026
Valid Until
August 28, 2026 62 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
1F:9E:F0:D1:43:62:B1:05:E4:2B:C1:45:92:A1:68:3A:8A:F9:CC:89:FB:46:D4:BF:76:5C:F5:F1:6E:50:86:12
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

88 domains
kitchenmorocco.com *.kitchenmorocco.com *.app.kitchenmorocco.com *.dev.kitchenmorocco.com

Other domains in certificate

*.account.tvorf.at *.analytic.tvorf.at *.api.tvorf.at *.app.tvorf.at *.assets.tvorf.at *.b53f7e61-9baa-4950-80a1-bf2f2d29ac3b.tvorf.at *.bi-poc.tvorf.at *.bi-production.tvorf.at *.bi-staging.tvorf.at *.blog.tvorf.at *.boyfriend.tvorf.at *.ci-insight.tvorf.at *.client.tvorf.at *.cloud.tvorf.at *.customer.tvorf.at *.dashboard.tvorf.at *.dev.tvorf.at *.development-dash.tvorf.at *.development.tvorf.at *.emv1.tvorf.at *.explorer.tvorf.at *.goldgay.tvorf.at *.home.tvorf.at *.hotfix.tvorf.at *.hqugcstore.tvorf.at *.intranet.tvorf.at *.kianvanalytics-test.tvorf.at *.kunden.tvorf.at *.m.tvorf.at *.news.tvorf.at *.notexistswew.tvorf.at *.partner.tvorf.at *.pkkkdtrend.tvorf.at *.portal.tvorf.at *.preprod-superset.tvorf.at *.production-data.tvorf.at *.production.tvorf.at *.random.tvorf.at *.rd.tvorf.at *.rds.tvorf.at *.rdweb.tvorf.at *.remote.tvorf.at *.sandbox.tvorf.at *.service.tvorf.at *.servus.tvorf.at *.shop.tvorf.at *.ss.tvorf.at *.staging-data.tvorf.at *.staging.tvorf.at *.store.tvorf.at *.trend.tvorf.at tvorf.at *.tvorf.at *.uat.tvorf.at *.users.tvorf.at *.wap.tvorf.at *.web.tvorf.at *.webdisk.tvorf.at *.wew.tvorf.at *.www.tvorf.at
usdpi.org *.usdpi.org
*.a.verila.info *.admin.verila.info *.api.verila.info *.aplxra.verila.info *.assets.verila.info *.dashboard.verila.info *.demo.verila.info *.dev.verila.info *.gefdbhcm.verila.info *.mail.verila.info *.mailer.verila.info *.marketing.verila.info *.qkllbsecure.verila.info *.secure.verila.info *.stage.verila.info *.staging.verila.info *.stg.verila.info *.uptzpaplxra.verila.info *.v1.verila.info *.v2.verila.info verila.info *.verila.info