Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=westorium.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
April 17, 2026
Valid Until
July 16, 2026
64 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
33:A9:D4:1A:DE:86:D1:D1:99:6C:65:94:5A:2A:C2:81:2A:1D:53:A7:4E:98:87:5F:FA:4F:71:59:33:0B:8E:61
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
westorium.com
*.westorium.com
*.0e396e79-8fde-4342-a308-06f90e1c0fde.westorium.com
*.assets.westorium.com
*.cms.westorium.com
*.cpanel.westorium.com
*.dan.westorium.com
*.en.westorium.com
*.laravel.westorium.com
*.mailgate.westorium.com
*.post.westorium.com
54zp.cc
*.54zp.cc
98349.one
*.98349.one
apartamentszwedzki.pl
*.apartamentszwedzki.pl
cashabibacked.co
*.cashabibacked.co
construction-jobs-8n8m7f0l7q7.sbs
*.construction-jobs-8n8m7f0l7q7.sbs
coolairexperts.co
*.coolairexperts.co
egagentic.com
*.egagentic.com
ena-taruwoshi.com
*.ena-taruwoshi.com
eninnolab.net
*.eninnolab.net
f03.my
*.f03.my
festr.lol
*.festr.lol
fire-safety-us714.click
*.fire-safety-us714.click
italy-trip-11.sbs
*.italy-trip-11.sbs
keq9286.cc
*.keq9286.cc
kickstartwithcampaignugc.com
*.kickstartwithcampaignugc.com
knzifkezo06hrj.cc
*.knzifkezo06hrj.cc
kuswidhld.cc
*.kuswidhld.cc
littlemanapproved.com
*.littlemanapproved.com
miyagawamokuzai.com
*.miyagawamokuzai.com
newswirejetcore.com
*.newswirejetcore.com
nwmu73.top
*.nwmu73.top
quivel.com
*.quivel.com
snowreel.art
*.snowreel.art
softwareentwickler-job.de
*.softwareentwickler-job.de
td60491.cc
*.td60491.cc
*.desktop.theclassifiedpost.com
*.hostmaster.theclassifiedpost.com
*.metrics.theclassifiedpost.com
*.mobile.theclassifiedpost.com
*.newjersey.theclassifiedpost.com
*.news.theclassifiedpost.com
*.staging.theclassifiedpost.com
theclassifiedpost.com
*.theclassifiedpost.com
*.www.theclassifiedpost.com
venice-istanbul-railway-vacation.sbs
*.venice-istanbul-railway-vacation.sbs
*.api.vulkan-champion.space
*.app.vulkan-champion.space
*.beta.vulkan-champion.space
*.cloud.vulkan-champion.space
*.core.vulkan-champion.space
*.crm.vulkan-champion.space
*.laravel.vulkan-champion.space
*.mobile.vulkan-champion.space
*.qa.vulkan-champion.space
*.stage.vulkan-champion.space
*.test.vulkan-champion.space
vulkan-champion.space
*.vulkan-champion.space
xeh56.icu
*.xeh56.icu
yc555.vip
*.yc555.vip
Other domains in certificate