Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=wgt.it
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
April 16, 2026
Valid Until
July 15, 2026 74 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
16:C8:DF:84:DB:8F:89:DF:17:E2:BE:E5:C6:04:AB:E0:84:77:C4:66:85:E3:E8:72:2E:8F:97:66:77:D3:9D:11
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
wgt.it *.wgt.it *.admin.wgt.it *.api.wgt.it *.app.wgt.it *.mailmaya.wgt.it

Other domains in certificate

*.05b431f9-1bec-4144-b3c8-a5cbeb16d6cc.asemedical.top *.63fc8f6b-4033-4491-af51-ae40ad2ae2b3.asemedical.top *.75298f11-5668-4527-a00a-3b63ebf5887a.asemedical.top *.96c54.asemedical.top *.api.asemedical.top *.app.asemedical.top asemedical.top *.asemedical.top *.backup.asemedical.top *.billing.asemedical.top *.correo.asemedical.top *.dev.asemedical.top *.f570b306-d310-4196-b26b-d8e5a4354d92.asemedical.top *.members.asemedical.top *.rozbdnew.asemedical.top *.rustore.asemedical.top *.staging.asemedical.top *.test.asemedical.top *.tnsolqjc.asemedical.top *.www.asemedical.top
blockchainhub.it *.blockchainhub.it *.www.blockchainhub.it
burubumdesi.org *.burubumdesi.org *.shrink.burubumdesi.org
businesstrust.it *.businesstrust.it *.chart.businesstrust.it *.com.businesstrust.it *.dash.businesstrust.it *.dashboard.businesstrust.it *.dashs.businesstrust.it *.hostmaster.businesstrust.it *.preprod.businesstrust.it *.superset-ci.businesstrust.it *.superset.businesstrust.it *.visual.businesstrust.it
*.analytic.dottorati.it *.bandi.dottorati.it *.bando.dottorati.it *.bi.dottorati.it *.dash.dottorati.it *.dashboard.dottorati.it *.data.dottorati.it *.demo.dottorati.it dottorati.it *.dottorati.it *.status.dottorati.it
instructing.com.au *.instructing.com.au *.mail.instructing.com.au
jamesspiderkaka.com *.jamesspiderkaka.com *.m.jamesspiderkaka.com
kaf.com.pl *.kaf.com.pl *.www.kaf.com.pl
*.alwaili.mxsa.com *.factorym.mxsa.com mxsa.com *.mxsa.com *.ytfy.mxsa.com
*.admin.myshowcase.it *.backend.myshowcase.it *.data.myshowcase.it *.demo.myshowcase.it *.dev.myshowcase.it *.hostmaster.myshowcase.it myshowcase.it *.myshowcase.it *.remote.myshowcase.it *.reporting.myshowcase.it *.staging.myshowcase.it
*.ku.pamo.in pamo.in *.pamo.in
*.hostmaster.rnn-info.de rnn-info.de *.rnn-info.de *.www.rnn-info.de
*.rd.unisplays.com unisplays.com *.unisplays.com