76/100 SECURITY SCORE

Certificate Information

Subject
CN=asistore.xyz
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 22, 2026
Valid Until
July 21, 2026 83 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
14:2D:68:DA:15:6F:13:9D:68:CF:06:8D:D5:3F:2E:A5:DB:9B:21:3D:68:5C:44:68:D2:88:E1:25:00:CE:AF:66
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

89 domains
kibrisemlakbul.com *.kibrisemlakbul.com

Other domains in certificate

1alliancegrp.com *.1alliancegrp.com
259950.cn *.259950.cn
3168e2.com *.3168e2.com
70416.loan *.70416.loan
919180.xyz *.919180.xyz
95704.blog *.95704.blog
ac80106.cc *.ac80106.cc
asistore.xyz *.asistore.xyz
backyard-renovation-51050.click *.backyard-renovation-51050.click
barefootbonito.com *.barefootbonito.com
bd9d6.com *.bd9d6.com
beach.clothing *.beach.clothing
best-depression-test-4324-0x.sbs *.best-depression-test-4324-0x.sbs
i-tools.org *.i-tools.org
jackeries.com *.jackeries.com
kaamuu.club *.kaamuu.club
karen.cfd *.karen.cfd
kodpung88th.com *.kodpung88th.com
kommand.xyz *.kommand.xyz
lawfirmnewyork.city *.lawfirmnewyork.city *.v2.lawfirmnewyork.city
logicrazor.com *.logicrazor.com
love-calculator.co *.love-calculator.co
moringatea.net *.moringatea.net
nftea.biz *.nftea.biz
oaklandbandtis.com *.oaklandbandtis.com
ovsbw.town *.ovsbw.town
pickworld.net *.pickworld.net
playgame168casino.com *.playgame168casino.com
playgame168casino1.com *.playgame168casino1.com
playgame168gg.com *.playgame168gg.com
playgame168thai.com *.playgame168thai.com
recallrexford.com *.recallrexford.com
rivendelljournal.org *.rivendelljournal.org
saintjunienlescombes.com *.saintjunienlescombes.com
serenityharborlacosta.com *.serenityharborlacosta.com
sim-card-in.today *.sim-card-in.today
sincsd.org *.sincsd.org
swan888th.com *.swan888th.com
targasolde.sbs *.targasolde.sbs
tdcuizent.com *.tdcuizent.com
themasterbaker.org *.themasterbaker.org
themelrosecoop.com *.themelrosecoop.com
ticketsrevolution.com *.ticketsrevolution.com