Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=arenamerchants.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 09, 2026
Valid Until
June 07, 2026
47 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
E6:12:29:3F:2A:CB:EB:BF:AF:8A:30:B5:6F:F2:FB:EB:6D:C8:E3:C2:F1:B3:A8:DA:5D:EF:A1:5F:88:94:33:38
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
uralita.com
*.uralita.com
3dprinters56123.sbs
*.3dprinters56123.sbs
arenamerchants.com
*.arenamerchants.com
*.ww25.arenamerchants.com
askreddit.club
*.askreddit.club
*.ww38.askreddit.club
exerciseprofessionals.co.uk
*.exerciseprofessionals.co.uk
exrcise.me
*.exrcise.me
fitnessmagazine.uk
*.fitnessmagazine.uk
fitnessmodel.pro
*.fitnessmodel.pro
fitnesssponsorship.com
*.fitnesssponsorship.com
fitnesstalentmodel.com
*.fitnesstalentmodel.com
fitphotography.co.uk
*.fitphotography.co.uk
futurefaves.co
*.futurefaves.co
*.sitemaps.futurefaves.co
*.www.futurefaves.co
hj240bfd1.com
*.hj240bfd1.com
iacantennas.com
*.iacantennas.com
inkdmuscle.com
*.inkdmuscle.com
intimacypills.com
*.intimacypills.com
investing-stocks-926964269.click
*.investing-stocks-926964269.click
mallufollowers.xyz
*.mallufollowers.xyz
*.ww38.mallufollowers.xyz
*.www.mallufollowers.xyz
matematikcenter.com
*.matematikcenter.com
*.vpn.matematikcenter.com
*.autodiscover.nbrseries.online
*.cpcalendars.nbrseries.online
*.cpcontacts.nbrseries.online
*.integration.nbrseries.online
*.jenkins.nbrseries.online
*.mail.nbrseries.online
nbrseries.online
*.nbrseries.online
*.pipeline-test.nbrseries.online
*.pipeline.nbrseries.online
*.webdisk.nbrseries.online
*.webmail.nbrseries.online
*.ww25.nbrseries.online
*.www.nbrseries.online
oploverz.life
*.oploverz.life
*.ww38.oploverz.life
realtyonexpocyprus.com
*.realtyonexpocyprus.com
sponsoredathlete.uk
*.sponsoredathlete.uk
steamproof.com
*.steamproof.com
strengthfacility.com
*.strengthfacility.com
thaidelmar.com
*.thaidelmar.com
tryjumpermediateam.net
*.tryjumpermediateam.net
visitgympie.com
*.visitgympie.com
vksg.org
*.vksg.org
warungangsa.sbs
*.warungangsa.sbs
whpop.org
*.whpop.org
worxpowertools.com
*.worxpowertools.com
wxxcy33.cc
*.wxxcy33.cc
yogafitnessclass.com
*.yogafitnessclass.com
zeronews24.com
*.zeronews24.com
Other domains in certificate