Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=webuyhighlinecars.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 15, 2026
Valid Until
July 14, 2026
62 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F8:D4:1A:68:1F:D6:97:D6:E1:4D:94:C0:18:60:7F:D4:95:37:D0:EA:9A:42:80:65:10:77:3E:04:8F:DB:B2:58
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
varadhifarms.com
*.varadhifarms.com
detoxbath.com
*.detoxbath.com
dine616.com
*.dine616.com
gesunderschlaf.com
*.gesunderschlaf.com
hougland.com
*.hougland.com
jeffcott.com
*.jeffcott.com
labsharegroup.com
*.labsharegroup.com
*.89.mgy.cm
mgy.cm
*.mgy.cm
mishique.com
*.mishique.com
misterbank.com
*.misterbank.com
mobilenail.com.au
*.mobilenail.com.au
monfee.com
*.monfee.com
*.14150a7c-3803-4e08-81d7-e3b439fc74e6.mthashana.co.za
*.admin.mthashana.co.za
*.api.mthashana.co.za
*.app.mthashana.co.za
*.backoffice.mthashana.co.za
*.backup.mthashana.co.za
*.blog.mthashana.co.za
*.coltech.mthashana.co.za
*.dev.mthashana.co.za
*.extranet.mthashana.co.za
*.forum.mthashana.co.za
*.help.mthashana.co.za
*.hqrdkapp.mthashana.co.za
*.login.mthashana.co.za
*.m.mthashana.co.za
*.members.mthashana.co.za
mthashana.co.za
*.mthashana.co.za
*.news.mthashana.co.za
*.newsletter.mthashana.co.za
*.notexistscoltech.mthashana.co.za
*.old.mthashana.co.za
*.shop.mthashana.co.za
*.support.mthashana.co.za
*.uat.mthashana.co.za
*.ww.mthashana.co.za
*.ww1.mthashana.co.za
*.www.mthashana.co.za
nasdaq.au
*.nasdaq.au
plentpass.com
*.plentpass.com
prendafacil.com
*.prendafacil.com
restoringthekootenai.org
*.restoringthekootenai.org
sandie.au
*.sandie.au
seeforyourself.org
*.seeforyourself.org
smski.com
*.smski.com
themoslem.com
*.themoslem.com
thienha.com
*.thienha.com
ticktes.com
*.ticktes.com
torlai.com
*.torlai.com
unitedcopyguild.com
*.unitedcopyguild.com
wcosteam.net
*.wcosteam.net
*.git.webuyhighlinecars.com
webuyhighlinecars.com
*.webuyhighlinecars.com
wikiclass.com
*.wikiclass.com
yankees.au
*.yankees.au
yew.au
*.yew.au
Other domains in certificate