76/100 SECURITY SCORE

Certificate Information

Subject
CN=chicafinanciera.top
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 25, 2026
Valid Until
July 24, 2026 72 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
B8:D4:FA:2A:BA:A4:BE:5B:EC:A8:75:C0:08:8A:F8:7B:52:1C:F8:9A:CA:DA:BC:4E:97:CF:13:8B:FB:04:D1:1C
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
certifiedtel.com *.certifiedtel.com

Other domains in certificate

betflikuk.bet *.betflikuk.bet
bf61026.cc *.bf61026.cc
binovawaste.com *.binovawaste.com
birminghammomonline.net *.birminghammomonline.net
bkm123.bet *.bkm123.bet
bloksappai.com *.bloksappai.com
boxinggeorgia.com *.boxinggeorgia.com
byoapa.com *.byoapa.com
camelluck.bet *.camelluck.bet
chicafinanciera.top *.chicafinanciera.top
chicasempresarias.top *.chicasempresarias.top
iaemprendedores.top *.iaemprendedores.top
ibmsouthsudan.org *.ibmsouthsudan.org
jdmtpe.life *.jdmtpe.life
jjjzd.plus *.jjjzd.plus
kam8050.cc *.kam8050.cc
karachi.love *.karachi.love
karlssonslife.info *.karlssonslife.info
kn365.org *.kn365.org
listkitsolutionsnetwork.com *.listkitsolutionsnetwork.com
lookup-personal-loans-se-ad-gpt2.sbs *.lookup-personal-loans-se-ad-gpt2.sbs
lottosod.org *.lottosod.org
mabet888.org *.mabet888.org
meenewching.com *.meenewching.com
mofksoa52df6g.com *.mofksoa52df6g.com
moluo.co *.moluo.co
mthwb2pcstlmsedgzgz.com *.mthwb2pcstlmsedgzgz.com
mustbezero.com *.mustbezero.com
nevermoreacademy.org *.nevermoreacademy.org
ngyywz6.com *.ngyywz6.com
nhnrkwygdb.com *.nhnrkwygdb.com
novusagentic.com *.novusagentic.com
overbet.info *.overbet.info
passagetoindonesia.com *.passagetoindonesia.com
pg-soft.world *.pg-soft.world
pg15k.world *.pg15k.world
pgcat555.bet *.pgcat555.bet
ppchvoy.com *.ppchvoy.com
pun123.pro *.pun123.pro
r29rr.icu *.r29rr.icu
rhnwjnd1026.vip *.rhnwjnd1026.vip
river28.me *.river28.me
ruaypang.pro *.ruaypang.pro
seehomesfirstaz.com *.seehomesfirstaz.com