Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=nostalgia-90.party
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 02, 2026
Valid Until
July 31, 2026
73 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
6C:50:BA:C8:97:E5:E8:8D:DA:35:0A:B9:57:49:F4:8E:72:94:0A:8F:57:5D:89:91:BC:A4:F5:6F:D8:43:36:AE
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
wimbled.com
*.wimbled.com
*.cloud.wimbled.com
*.e008cb85-ecac-4aaa-9773-1e22f87e8dc5.wimbled.com
*.mx.wimbled.com
*.remote.wimbled.com
*.staging.wimbled.com
*.www.wimbled.com
*.5c89bc53-0c43-4ca0-a37f-9a3637ec056e.777-cebola777.bet
*.67428a30-632b-4d1b-978e-6be8f6b811db.777-cebola777.bet
777-cebola777.bet
*.777-cebola777.bet
*.9a356424-d0b9-4a78-b147-3d4551d55b9d.777-cebola777.bet
*.api.777-cebola777.bet
*.bi9ccd.777-cebola777.bet
*.dev.777-cebola777.bet
*.hr.777-cebola777.bet
*.members.777-cebola777.bet
*.new.777-cebola777.bet
*.share.777-cebola777.bet
*.test.777-cebola777.bet
*.wxywjbi9ccd.777-cebola777.bet
atfxcom.info
*.atfxcom.info
*.mail.atfxcom.info
*.mx01.atfxcom.info
*.pam.atfxcom.info
*.ww17.atfxcom.info
*.zimbra.atfxcom.info
*.hostmaster.mbfp.org
mbfp.org
*.mbfp.org
*.random.mbfp.org
*.dev.myfetchasquadssupport.com
myfetchasquadssupport.com
*.myfetchasquadssupport.com
*.03680c4a-8f6a-4ace-bc2d-2b1b92f2e28f.nostalgia-90.party
*.0c753cd4-5731-43d1-b737-fbbba6a564b8.nostalgia-90.party
*.3g.nostalgia-90.party
*.admin.nostalgia-90.party
*.api.nostalgia-90.party
*.app.nostalgia-90.party
*.autoconfig.nostalgia-90.party
*.backup.nostalgia-90.party
*.cgabnyvz.nostalgia-90.party
*.correo.nostalgia-90.party
*.dashboard.nostalgia-90.party
*.dev.nostalgia-90.party
*.exchange.nostalgia-90.party
*.files.nostalgia-90.party
*.game.nostalgia-90.party
*.gnshystore.nostalgia-90.party
*.home.nostalgia-90.party
*.kdutwsbjpxns.nostalgia-90.party
*.mail.nostalgia-90.party
*.mail02.nostalgia-90.party
*.mailer.nostalgia-90.party
*.marketing.nostalgia-90.party
*.new.nostalgia-90.party
nostalgia-90.party
*.nostalgia-90.party
*.ns.nostalgia-90.party
*.qa.nostalgia-90.party
*.sbjpxns.nostalgia-90.party
*.secure.nostalgia-90.party
*.shop.nostalgia-90.party
*.smtp.nostalgia-90.party
*.smtpauth.nostalgia-90.party
*.springboot.nostalgia-90.party
*.stage.nostalgia-90.party
*.staging.nostalgia-90.party
*.stg.nostalgia-90.party
*.store.nostalgia-90.party
*.uat.nostalgia-90.party
*.v1.nostalgia-90.party
*.vpn.nostalgia-90.party
*.web.nostalgia-90.party
*.zimbra.nostalgia-90.party
*.app.xn--o3cdaf9bygta.com
*.hostmaster.xn--o3cdaf9bygta.com
*.m.xn--o3cdaf9bygta.com
*.sitemap.xn--o3cdaf9bygta.com
*.workspace.xn--o3cdaf9bygta.com
*.www.xn--o3cdaf9bygta.com
xn--o3cdaf9bygta.com
*.xn--o3cdaf9bygta.com
*.com.zloja.online
*.conheca.zloja.online
zloja.online
*.zloja.online
Other domains in certificate