Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=97160.app
Issuer
C=US, O=Let's Encrypt, CN=YR1
Valid From
June 01, 2026
Valid Until
August 30, 2026
69 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
70:BC:50:98:C3:3A:93:15:B9:1B:E6:F2:1B:91:D5:6E:67:E8:64:CA:0D:3A:64:23:30:71:BF:3C:92:EF:A6:EA
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
undervaluednfts.com
*.undervaluednfts.com
014979.cn
*.014979.cn
0606000.com
*.0606000.com
117848.my
*.117848.my
1688388tips.shop
*.1688388tips.shop
202ddd425.top
*.202ddd425.top
206230.loan
*.206230.loan
22134.app
*.22134.app
301358.cc
*.301358.cc
953528.cc
*.953528.cc
97160.app
*.97160.app
991111.top
*.991111.top
99132.locker
*.99132.locker
9dlsq9.top
*.9dlsq9.top
9nmqug.top
*.9nmqug.top
a41.my
*.a41.my
agjdjh39.com
*.agjdjh39.com
an99aa.club
*.an99aa.club
baoxin-ttr.com
*.baoxin-ttr.com
c304d23d9b926b61.com
*.c304d23d9b926b61.com
cjbfn.work
*.cjbfn.work
clnsh.love
*.clnsh.love
copenhagen-oslo-coach-tour-dk.sbs
*.copenhagen-oslo-coach-tour-dk.sbs
differentcoffee.com
*.differentcoffee.com
redeemdaily.com
*.redeemdaily.com
rjbq.shop
*.rjbq.shop
rkscn.my
*.rkscn.my
rllg8b.cc
*.rllg8b.cc
s54b.icu
*.s54b.icu
slotgacorpastiwd.com
*.slotgacorpastiwd.com
speedgacor89.monster
*.speedgacor89.monster
thabeting.com
*.thabeting.com
thetown-2025.site
*.thetown-2025.site
trytelvanateam.com
*.trytelvanateam.com
tushijiy.my
*.tushijiy.my
uwbjx.loan
*.uwbjx.loan
vermiped.com
*.vermiped.com
w13722356.com
*.w13722356.com
wc19.cc
*.wc19.cc
www8376v.com
*.www8376v.com
wwwy134b.com
*.wwwy134b.com
xdrfz.qpon
*.xdrfz.qpon
xtok.pink
*.xtok.pink
yiqituan.cc
*.yiqituan.cc
zprdie.my
*.zprdie.my
Other domains in certificate