Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=nwjc.xyz
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
January 07, 2026
Valid Until
April 07, 2026
50 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
72:9A:DC:24:89:83:11:B7:90:03:58:E4:96:08:A2:0A:48:88:F1:5D:A8:10:9E:93:33:92:46:C6:2E:3C:39:DD
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
toxwap.com
*.toxwap.com
25abhishekgupta.com
*.25abhishekgupta.com
beginnerstocktrades560512.icu
*.beginnerstocktrades560512.icu
carlinkitlife.com
*.carlinkitlife.com
*.ww38.carlinkitlife.com
coursi.io
*.coursi.io
*.tracking.coursi.io
*.ww25.coursi.io
*.ww38.coursi.io
*.30b1fad59688.easymoney.life
*.beta.easymoney.life
*.blog.easymoney.life
easymoney.life
*.easymoney.life
*.magento.easymoney.life
*.sitemap.easymoney.life
*.ww25.easymoney.life
*.ww38.easymoney.life
gobarbatti.com
*.gobarbatti.com
*.afiliados.ilha.bet
ilha.bet
*.ilha.bet
invisalignquote634312.icu
*.invisalignquote634312.icu
lightyear.store
*.lightyear.store
*.ww38.lightyear.store
*.www.lightyear.store
marsaic.com
*.marsaic.com
*.oliz.marsaic.com
*.es.natal.studio
natal.studio
*.natal.studio
neckpain373680.icu
*.neckpain373680.icu
*.authors.nwjc.xyz
nwjc.xyz
*.nwjc.xyz
*.www.nwjc.xyz
pelipedia.com
*.pelipedia.com
*.ww17.pelipedia.com
*.citrix.sexphoto.me
*.forum.sexphoto.me
*.mail.sexphoto.me
*.me.sexphoto.me
*.mx.sexphoto.me
*.root.sexphoto.me
sexphoto.me
*.sexphoto.me
stillwatersgardens.com
*.stillwatersgardens.com
swiftexpressdeliverypro.live
*.swiftexpressdeliverypro.live
*.ahufykanezi.vintagebooth.me
*.ajubinuniv.vintagebooth.me
*.amewiji.vintagebooth.me
*.azehofod.vintagebooth.me
*.ebury.vintagebooth.me
*.ifaxogenyzyj.vintagebooth.me
*.ipohezuc58.vintagebooth.me
*.ivisum.vintagebooth.me
*.iwakulagu76.vintagebooth.me
*.mewww.vintagebooth.me
*.okoceho.vintagebooth.me
*.orijelacovi.vintagebooth.me
*.orygove11.vintagebooth.me
*.upexof.vintagebooth.me
vintagebooth.me
*.vintagebooth.me
*.ww25.vintagebooth.me
*.www.vintagebooth.me
*.ydibybec.vintagebooth.me
*.yjinowahe77.vintagebooth.me
*.ynativi29.vintagebooth.me
*.ysavivezil42.vintagebooth.me
*.cache.webanalytic.online
webanalytic.online
*.webanalytic.online
westsidedentalcare.com.au
*.westsidedentalcare.com.au
*.ww38.westsidedentalcare.com.au
*.www.westsidedentalcare.com.au
Other domains in certificate