Cached · just now
76/100 SECURITY SCORE

Certificate Information

Subject
CN=witty.it
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 03, 2026
Valid Until
August 01, 2026 71 days
Public Key
RSA 4096 bit Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
28:E6:00:3A:6B:95:31:4B:F5:26:91:63:78:79:24:55:69:FB:D5:06:4C:37:50:C5:1B:87:4C:1F:DF:CB:89:BB
Alternative Names

Security Configuration

TLS Protocols
TLS 1.2 TLS 1.3
Forward Secrecy
Supported (Modern clients use PFS)

HTTP Security Headers

Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured Analyze
Content-Security-Policy-Report-Only
Missing
Not configured Analyze
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Add Strict-Transport-Security header with max-age of at least 1 year
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

CAA Records (Certificate Authority Authorization)

CAA Records
Not Configured (Any CA can issue certificates)
CAA Issues
  • No CAA records configured - any CA can issue certificates
Recommendations
  • Implement CAA records to restrict which CAs can issue certificates for your domain
  • This adds an extra layer of security against unauthorized certificate issuance
  • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
  • Consider adding 'iodef' record to receive security incident reports

Subject Alternative Names

90 domains
witty.it *.witty.it *.analytic.witty.it *.api.witty.it *.app.witty.it *.bi.witty.it *.dashboard.witty.it *.demo.witty.it *.hostmaster.witty.it *.https.witty.it *.itwww.witty.it *.staging.witty.it *.superset.witty.it *.viz.witty.it *.wwe.witty.it *.www.witty.it

Other domains in certificate

hubsettlement.com *.hubsettlement.com *.jfeeue.hubsettlement.com
*.bitcoin.kedarnathhelicopter.in *.booking.kedarnathhelicopter.in *.in.kedarnathhelicopter.in kedarnathhelicopter.in *.kedarnathhelicopter.in *.live.kedarnathhelicopter.in *.mlm.kedarnathhelicopter.in *.webmail.kedarnathhelicopter.in *.xyz.kedarnathhelicopter.in
kitchen-appliances.sbs *.kitchen-appliances.sbs *.www.kitchen-appliances.sbs
*.gio.l98fzscq.xyz l98fzscq.xyz *.l98fzscq.xyz *.w32.l98fzscq.xyz *.ww25.l98fzscq.xyz
*.106fe838-e64c-483c-a1e0-b9a60652b976.ngocanhsinger.com *.a.ngocanhsinger.com *.aniqmail.ngocanhsinger.com *.api.ngocanhsinger.com *.app.ngocanhsinger.com *.backup.ngocanhsinger.com *.beta.ngocanhsinger.com *.bilcou4moe.ngocanhsinger.com *.blog.ngocanhsinger.com *.cloud.ngocanhsinger.com *.crm.ngocanhsinger.com *.d3b3691c-2952-4c09-ad2f-d702d82e8db2.ngocanhsinger.com *.dashboard.ngocanhsinger.com *.dcowzz3kuf.ngocanhsinger.com *.dev.ngocanhsinger.com *.e3fd02b0-b659-4252-bd42-859437859015.ngocanhsinger.com *.f06b307a-c3b0-4402-809a-db56dac100ff.ngocanhsinger.com *.forums.ngocanhsinger.com *.help.ngocanhsinger.com *.hengshui.ngocanhsinger.com *.hostmaster.ngocanhsinger.com *.loljzyltzon90sr.ngocanhsinger.com *.m.ngocanhsinger.com *.marketing.ngocanhsinger.com *.mrnfsstore.ngocanhsinger.com ngocanhsinger.com *.ngocanhsinger.com *.ohki3.ngocanhsinger.com *.old.ngocanhsinger.com *.outlook.ngocanhsinger.com *.qa.ngocanhsinger.com *.rd.ngocanhsinger.com *.rds.ngocanhsinger.com *.rdweb.ngocanhsinger.com *.staging.ngocanhsinger.com *.uat.ngocanhsinger.com *.vwww.ngocanhsinger.com *.w9u9gw.ngocanhsinger.com *.web.ngocanhsinger.com *.wiki.ngocanhsinger.com *.www.ngocanhsinger.com *.z3kuf.ngocanhsinger.com *.zmwiev2.ngocanhsinger.com
*.dev.pandamouse.pro *.flowiseai.pandamouse.pro *.lime.pandamouse.pro *.mwww.pandamouse.pro pandamouse.pro *.pandamouse.pro *.vpn.pandamouse.pro *.wildcard.pandamouse.pro
*.m.tacomaimaging.com tacomaimaging.com *.tacomaimaging.com