Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=preplu.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
May 10, 2026
Valid Until
August 08, 2026
60 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
F4:1F:17:83:97:47:AB:E7:BC:10:43:21:FE:09:79:BC:5B:65:A1:1F:0C:74:16:6C:D1:02:A5:1E:77:19:CC:9C
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
xclassvn.bio
*.xclassvn.bio
4it.me
*.4it.me
*.api.4it.me
*.app.4it.me
*.devhome.4it.me
*.domains.4it.me
*.home.4it.me
*.image.4it.me
*.mail.4it.me
*.mails.4it.me
*.old.4it.me
*.php.4it.me
*.question.4it.me
*.sa.4it.me
*.todo.4it.me
*.wuyishan.4it.me
*.ww38.4it.me
*.zabbix.4it.me
apogeetest.net
*.apogeetest.net
*.c03.apogeetest.net
*.ww25.apogeetest.net
*.ww38.apogeetest.net
av168y.com
*.av168y.com
*.ww25.av168y.com
*.25.av8av.com
av8av.com
*.av8av.com
*.wvw.av8av.com
*.ww25.av8av.com
avfls.makeup
*.avfls.makeup
*.bi.avfls.makeup
*.buv.avfls.makeup
*.dej.avfls.makeup
*.dmi.avfls.makeup
*.ww25.avfls.makeup
bdyka.xyz
*.bdyka.xyz
*.ww25.bdyka.xyz
bgwealth.live
*.bgwealth.live
bosevyo.com
*.bosevyo.com
*.ww38.bosevyo.com
*.32.heiliaowang56273.buzz
heiliaowang56273.buzz
*.heiliaowang56273.buzz
*.desktop.homedetop.com
homedetop.com
*.homedetop.com
*.ww11.homedetop.com
huaxi.live
*.huaxi.live
*.b2b.lifetimemufflerbrake.com
*.beta.lifetimemufflerbrake.com
*.demo.lifetimemufflerbrake.com
*.es.lifetimemufflerbrake.com
lifetimemufflerbrake.com
*.lifetimemufflerbrake.com
*.magento.lifetimemufflerbrake.com
*.new.lifetimemufflerbrake.com
*.shop.lifetimemufflerbrake.com
*.test.lifetimemufflerbrake.com
*.ww25.lifetimemufflerbrake.com
*.ww38.lifetimemufflerbrake.com
*.www.lifetimemufflerbrake.com
*.books.palaustudio.com
*.cdn.palaustudio.com
*.hr.palaustudio.com
*.mx.palaustudio.com
*.news.palaustudio.com
palaustudio.com
*.palaustudio.com
pcx.bet
*.pcx.bet
preplu.com
*.preplu.com
*.random.preplu.com
showbands.live
*.showbands.live
*.billing.waclighitng.com
*.jocuri.waclighitng.com
*.map.waclighitng.com
waclighitng.com
*.waclighitng.com
Other domains in certificate