Open
Cached
·
just now
86/100
SECURITY SCORE
Certificate Information
Subject
CN=vivaaerobus.com
Issuer
C=US, O=Let's Encrypt, CN=E7
Valid From
October 10, 2025
Valid Until
January 08, 2026
50 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
BA:D6:15:80:AF:8A:24:7C:6E:92:58:75:A9:02:6A:6E:03:F3:4E:2D:E5:95:70:CE:95:00:90:F5:5E:6E:D3:87
Alternative Names
Security Configuration
TLS Protocols
TLS 1.0
TLS 1.1
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
Warnings
- • TLS 1.1 is deprecated and should be disabled
- • TLS 1.0 is deprecated and should be disabled
HTTP Security Headers
Status
Strict-Transport-Security
Excellent
max-age=31536000 ; includeSubDomains ; preload
Content-Security-Policy
Basic
default-src; frame-ancestors; img-src; +9 more
default-src 'self' 'unsafe-eval' 'unsafe-inline' *.quantummetric.com *.creativecdn.com *.openstreetmap.org fonts.gstatic.com fonts.googleapis.com *.dy-api.com *.dynamicyield.com *.y.uno *.accenture.com share-itinerary-prod.s3.amazonaws.com *.vivaaerobus.com *.prerender.io *.vivaaerobus.io data: *.cdn-net.com *.bidflyer.com *.fareplace.com; frame-ancestors 'self'; img-src 'self' 'unsafe-eval' 'unsafe-inline' vb-profile-photo-prod.s3.amazonaws.com *.openstreetmap.org *.staticv.me *.mastercard.com *.visa.com *.americanexpress.com *.riskified.com *.y.uno *.mercadopago.com *.mercadolibre.com *.mercadolivre.com *.dynamicyield.com data: braze-images.com *.clearsale.com.br services.rappi.com *.pinterest.com envivarevista.com multimedia.amadeus.com assets.airtrfx.com web-widget.smartlinks.dev *.hertzmexico.com smartlinksdev.s3.us-east-2.amazonaws.com cybba-bucket.s3.amazonaws.com *.cybba.solutions *.cybba.us *.adnxs.com *.stackadapt.com *.adsrvr.org share-confirmation-prod.s3.amazonaws.com share-confirmation-2-prod.s3.amazonaws.com *.wp.com *.crazyegg.com images.ctfassets.net *.accenture.com *.vivaaerobus.com data: *.cdn-net.com *.safetypay.com *.bidflyer.com *.fareplace.com *.google-analytics.com *.googleapis.com *.google.com *.google.com.mx *.vivaaerobus.com *.facebook.com *.cloudflare.com *.ckeditor.com *.doubleclick.net *.placeholder.com *.googletraveladservices.com *.kayak.com *.criteo.com *.criteo.net *.cartrawler.com services.paynet.com.mx api.openpay.mx ota-cars.imgix.net *.bing.com platform-api.sharethis.com cdn.apixu.com ad.soicos.com data: *.cdn-net.com *.paypalobjects.com *.paypal.com *.cdn.viajala.com *.viajala.com viajala.com *.playbuzz.com *.uplift-platform.com *.openpay.mx ct-supplierimage.imgix.net ct-microsites-core.imgix.net cdn.smooch.io media.smooch.io www.gravatar.com *.cloudfront.net *.usabilla.com photos.hotelbeds.com *.analytics.google.com *.amazon-adsystem.com analytics.google.com; style-src 'self' 'unsafe-eval' 'unsafe-inline' *.fontawesome.com *.quantummetric.com *.openstreetmap.org *.prod.y.uno *.dynamicyield.com fonts.googleapis.com fonts.gstatic.com *.accenture.com *.vivaaerobus.com web-widget.smartlinks.dev hello.myfonts.net d3u0jcwe5p7qrc.cloudfront.net data: *.cdn-net.com *.bidflyer.com *.fareplace.com *.google.com *.google.com.mx maxcdn.bootstrapcdn.com *.vivaaerobus.com *.cloudflare.com *.googleapis.com *.ckeditor.com *.cartrawler.com platform-api.sharethis.com cdn.apixu.com *.paypal.com *.playbuzz.com cdn.uplift-platform.com *.uplift.com cdn.smooch.io *.cloudfront.net *.recurly.com cdn.jsdelivr.net *.vivaaerobus.io; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.quantummetric.com *.creativecdn.com *.openstreetmap.org p11.techlab-cdn.com *.aexp-static.com *.mastercard.com *.visa.com *.americanexpress.com *.riskified.com maps.googleapis.com *.tealiumiq.com *.tiqcdn.com *.tiqcdn.cn *.dynamicyield.com *.mercadopago.com *.clearsale.com.br sdk-web.y.uno *.accenture.com omnisnippet1.com forms.soundestlink.com vivaaerobus.tuexperiencia.com *.vivaaerobus.com services.rappi.com cybba-bucket.s3.amazonaws.com web-widget.smartlinks.dev *.cybba.solutions *.rtb123.com *.cybba.us *.adnxs.com *.stackadapt.com *.adsrvr.org *.pinterest.com *.pinimg.com blob: data: *.cdn-net.com *.bidflyer.com *.fareplace.com *.googletagservices.com cdnjs.cloudflare.com code.jquery.com maxcdn.bootstrapcdn.com *.google.com cdn.jsdelivr.net *.google-analytics.com analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.facebook.net *.googleadservices.com *.ckeditor.com *.cloudfront.net *.google-analytics.com *.gstatic.com *.criteo.com *.criteo.net *.google.com.mx *.cartrawler.com bat.bing.com platform-api.sharethis.com cdn.apixu.com *.viajamas.com *.crazyegg.com *.skyscanner.net *.cdn-net.com *.paypal.com *.paypalobjects.com *.cdn.viajala.com *.viajala.com *.bidflyer.com *.fareplace.com *.kueskipay.com *.kueskipay.io *.playbuzz.com *.ipify.org cdn.uplift-platform.com *.uplift.com cdn.smooch.io api.smooch.io *.appboycdn.com *.usabilla.com *.securitytrfx.com *.recurly.com *.cludo.com s.go-mpulse.net analytics.tiktok.com; frame-src 'self' 'unsafe-eval' 'unsafe-inline' *.quantummetric.com *.creativecdn.com *.openstreetmap.org *.prod.y.uno *.mastercard.com *.visa.com *.americanexpress.com *.riskified.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com www.youtube.com player.vimeo.com *.wistia.net *.dynamicyield.com *.y.uno *.accenture.com vivaaerobus.tuexperiencia.com *.vivaaerobus.com em-frame.securitytrfx.com data: *.cdn-net.com *.bidflyer.com *.fareplace.com *.booking.com *.rentalcars.com *.google.com *.youtube.com *.criteo.com *.facebook.com *.facebook.net *.doubleclick.net *.safetypay.com *.cartrawler.com platform-api.sharethis.com cdn.apixu.com *.cdn-net.com *.sandbox.paypal.com *.paypal.com us.creativecdn.com *.playbuzz.com *.uplift.com d6tizftlrpuof.cloudfront.net *.usabilla.com www.googletagmanager.com; font-src 'self' 'unsafe-eval' 'unsafe-inline' *.fontawesome.com *.openstreetmap.org *.dynamicyield.com fonts.googleapis.com fonts.gstatic.com *.accenture.com web-widget.smartlinks.dev *.vivaaerobus.com data: *.cdn-net.com *.bidflyer.com *.fareplace.com *.bootstrapcdn.com *.gstatic.com *.cartrawler.com *.playbuzz.com cdn.smooch.io cdn.jsdelivr.net; connect-src 'self' 'unsafe-eval' 'unsafe-inline' *.quantummetric.com *.creativecdn.com *.openstreetmap.org p11.techlab-cdn.com *.prod.y.uno *.mastercard.com *.visa.com *.americanexpress.com *.riskified.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com maps.googleapis.com *.tealiumiq.com *.tiqcdn.com *.tiqcdn.cn *.dynamicyield.com *.dy-api.com *.y.uno analytics.tiktok.com forms.soundestlink.com api.omnisend.com extranet.tuexperiencia.com *.doters.com epa-realtime.uc.r.appspot.com gtm-nlc6d72-yzbiy.uc.r.appspot.com pu8ewcfeqc.execute-api.us-east-1.amazonaws.com *.smartlinks.dev *.uplift.com envivarevista.com gtm-5nlvl8m-mtywz.uc.r.appspot.com *.pinterest.com *.akstat.io *.lottiefiles.com cdn.contentful.com c.go-mpulse.net share-confirmation-prod.s3.amazonaws.com share-confirmation-2-prod.s3.amazonaws.com services.rappi.com *.accenture.com *.vivaaerobus.com microservices.dev.rappi.com *.crazyegg.com search.reservamos.mx data: *.cdn-net.com *.bidflyer.com *.fareplace.com wss://*.bidflyer.com wss://*.fareplace.com *.facebook.com *.google-analytics.com analytics.google.com *.viajamas.com *.skyscanner.net *.cdn-net.com *.paypal.com *.bidflyer.com *.fareplace.com api.kueskipay.io/v1/validate-keys api.kueskipay.com/v1/validate-keys api.kueskipay.io/v1/payments api.kueskipay.com/v1/payments api.kueskipay.com/v1/tracking *.playbuzz.com *.uplift-platform.com *.cartrawler.com api.smooch.io 5e46bc82c3d8d5000fb5c147.webloader.smooch.io 5e46bc82c3d8d5000fb5c147.config.smooch.io sdk.iad-03.braze.com wss://api.smooch.io api.ipify.org api.usabilla.com fcxagjrscb.execute-api.us-east-1.amazonaws.com aymr6n32mf.execute-api.us-east-1.amazonaws.com d6tizftlrpuof.cloudfront.net *.usabilla.com *.securitytrfx.com docs.google.com 0nvj6ws2wg.execute-api.us-east-1.amazonaws.com *.cludo.com *.analytics.google.com stats.g.doubleclick.net *.akamaihd.net; form-action 'self' 'unsafe-eval' 'unsafe-inline' *.openstreetmap.org *.accenture.com *.vivaaerobus.com data: *.cdn-net.com *.bidflyer.com *.fareplace.com *.vivaaerobus.com *.facebook.net *.facebook.com *.cdn-net.com *.playbuzz.com docs.google.com; media-src 'self' 'unsafe-eval' 'unsafe-inline' *.openstreetmap.org *.accenture.com *.vivaaerobus.com data: *.cdn-net.com *.bidflyer.com *.fareplace.com cdn.smooch.io; worker-src 'self' blob: *.vivaaerobus.com; child-src 'self' blob:;
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports