Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=solstarter.io
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
March 20, 2026
Valid Until
June 18, 2026 52 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
2E:F5:B4:4E:B0:A2:07:27:1E:EF:02:41:B2:13:2B:C7:CC:B2:E1:A6:F9:D9:D0:53:0D:D5:50:80:C7:D5:E7:93
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
wazza.com *.wazza.com *.beta.wazza.com *.staging.wazza.com *.wazza.wazza.com

Other domains in certificate

*.admin.naturalbodybuilding.asia *.alpha.naturalbodybuilding.asia *.analytics.naturalbodybuilding.asia *.app.naturalbodybuilding.asia *.apps.naturalbodybuilding.asia *.autodiscover.naturalbodybuilding.asia *.beta-insight.naturalbodybuilding.asia *.bi-beta.naturalbodybuilding.asia *.bi.naturalbodybuilding.asia *.dashboard-integration.naturalbodybuilding.asia *.dashboard.naturalbodybuilding.asia *.data-test.naturalbodybuilding.asia *.data.naturalbodybuilding.asia *.demo-analytics.naturalbodybuilding.asia *.dev.naturalbodybuilding.asia *.development.naturalbodybuilding.asia *.ebmail.naturalbodybuilding.asia *.exchange.naturalbodybuilding.asia *.explorer.naturalbodybuilding.asia *.gp.naturalbodybuilding.asia *.home.naturalbodybuilding.asia *.hotfix-report.naturalbodybuilding.asia *.hotfix-visualization.naturalbodybuilding.asia *.hotfix.naturalbodybuilding.asia *.insight.naturalbodybuilding.asia *.intranet.naturalbodybuilding.asia *.m.naturalbodybuilding.asia *.mail.naturalbodybuilding.asia naturalbodybuilding.asia *.naturalbodybuilding.asia *.news.naturalbodybuilding.asia *.ogtpbportal.naturalbodybuilding.asia *.outlook.naturalbodybuilding.asia *.poc-bi.naturalbodybuilding.asia *.poc.naturalbodybuilding.asia *.preview-bi.naturalbodybuilding.asia *.prod.naturalbodybuilding.asia *.production-insight.naturalbodybuilding.asia *.production.naturalbodybuilding.asia *.qa-insight.naturalbodybuilding.asia *.qa.naturalbodybuilding.asia *.ra.naturalbodybuilding.asia *.remote.naturalbodybuilding.asia *.remoteapp.naturalbodybuilding.asia *.remoto.naturalbodybuilding.asia *.report-development.naturalbodybuilding.asia *.reporting.naturalbodybuilding.asia *.sandbox-explorer.naturalbodybuilding.asia *.sandbox.naturalbodybuilding.asia *.shop.naturalbodybuilding.asia *.stats.naturalbodybuilding.asia *.superset-demo.naturalbodybuilding.asia *.superset.naturalbodybuilding.asia *.test.naturalbodybuilding.asia *.ts.naturalbodybuilding.asia *.vpn1.naturalbodybuilding.asia *.wap.naturalbodybuilding.asia *.web.naturalbodybuilding.asia *.www.naturalbodybuilding.asia *.zforvts.naturalbodybuilding.asia
*.admin.prioeprofit.my *.app.prioeprofit.my *.assets.prioeprofit.my *.demo.prioeprofit.my *.dev.prioeprofit.my *.hostmaster.prioeprofit.my *.kiyyvhostmaster.prioeprofit.my *.odrwladmin.prioeprofit.my prioeprofit.my *.prioeprofit.my *.test.prioeprofit.my
solstarter.io *.solstarter.io
*.4fbc2396-10eb-11ec-870b-3cfdfe9e819c.wmtcarrers.com *.6b022ec3-8493-42d3-b26c-455af9cd55a2.wmtcarrers.com *.api.wmtcarrers.com *.dev.wmtcarrers.com *.ep1dmw2eyp.wmtcarrers.com *.media.wmtcarrers.com *.web.wmtcarrers.com *.webmail.wmtcarrers.com wmtcarrers.com *.wmtcarrers.com *.workflow.wmtcarrers.com