76/100 SECURITY SCORE

Certificate Information

Subject
CN=luxuriousbeing.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 19, 2026
Valid Until
May 20, 2026 86 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
15:0D:F2:67:D8:69:65:95:9C:7A:EB:B3:C7:0B:39:1F:73:99:22:F8:17:DA:6F:18:32:F4:94:29:44:1D:15:7A
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
pidro.com *.pidro.com *.access.pidro.com *.admin.pidro.com *.api.pidro.com *.apps.pidro.com *.blog.pidro.com *.client.pidro.com *.cloud.pidro.com *.connect.pidro.com *.connectvpn.pidro.com *.demo.pidro.com *.dev.pidro.com *.gateway.pidro.com *.gitlab.pidro.com *.hostmaster.pidro.com *.login.pidro.com *.m.pidro.com *.mail.pidro.com *.mobile.pidro.com *.office.pidro.com *.portal.pidro.com *.rdp.pidro.com *.rds.pidro.com *.rds1.pidro.com *.rdweb.pidro.com *.remote.pidro.com *.remoteaccess.pidro.com *.secureaccess.pidro.com *.ssl.pidro.com *.sslvpn.pidro.com *.ts.pidro.com *.tyxoqremoteaccess.pidro.com *.vpn.pidro.com *.vpn1.pidro.com *.vpn2.pidro.com *.vpnssl.pidro.com *.web.pidro.com *.webconnect.pidro.com *.webmail.pidro.com *.webvpn.pidro.com *.ww11.pidro.com *.ww16.pidro.com *.ww25.pidro.com *.ww38.pidro.com *.ww5.pidro.com

Other domains in certificate

*.admin.luxuriousbeing.com *.api.luxuriousbeing.com *.app.luxuriousbeing.com *.cloud.luxuriousbeing.com *.demo.luxuriousbeing.com *.dev.luxuriousbeing.com *.firewall.luxuriousbeing.com *.fjnwatest.luxuriousbeing.com luxuriousbeing.com *.luxuriousbeing.com *.mail.luxuriousbeing.com *.oud.luxuriousbeing.com *.rd.luxuriousbeing.com *.rdweb.luxuriousbeing.com *.remote.luxuriousbeing.com *.staging.luxuriousbeing.com *.test.luxuriousbeing.com
*.admin.movimientodetierras.com *.app.movimientodetierras.com *.assets.movimientodetierras.com *.blog.movimientodetierras.com *.demo.movimientodetierras.com *.dev.movimientodetierras.com *.finance.movimientodetierras.com *.hostmaster.movimientodetierras.com *.m.movimientodetierras.com movimientodetierras.com *.movimientodetierras.com *.shop.movimientodetierras.com *.sitemaps.movimientodetierras.com *.test.movimientodetierras.com *.ww1.movimientodetierras.com *.ww16.movimientodetierras.com *.ww38.movimientodetierras.com
*.admin.villaplaza.com *.m.villaplaza.com villaplaza.com *.villaplaza.com *.ww1.villaplaza.com *.ww11.villaplaza.com *.ww16.villaplaza.com *.ww25.villaplaza.com *.ww38.villaplaza.com *.ww41.villaplaza.com