Open
Cached
·
just now
76/100
SECURITY SCORE
Certificate Information
Subject
CN=starwars-descriptions.com
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
February 04, 2026
Valid Until
May 05, 2026
84 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
93:DD:88:53:5B:E8:DD:CB:23:3E:96:5C:7A:53:B3:9D:7E:F6:3B:A7:E7:2D:6C:C0:40:E8:1D:11:65:C9:53:D3
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
90 domains
zenspharma.com
*.zenspharma.com
starwars-descriptions.com
*.starwars-descriptions.com
techfixz.top
*.techfixz.top
techtoolss.net
*.techtoolss.net
tejoyr.academy
*.tejoyr.academy
telftaxg.com
*.telftaxg.com
ufound.it
*.ufound.it
uo3.live
*.uo3.live
urbanspots.com
*.urbanspots.com
urbantravelperspectives.xyz
*.urbantravelperspectives.xyz
websiteoptimization.it
*.websiteoptimization.it
weddingslovegate.beauty
*.weddingslovegate.beauty
whimsicaltraveldiaries.xyz
*.whimsicaltraveldiaries.xyz
whirlwindtravelstories.xyz
*.whirlwindtravelstories.xyz
wholesalejerseyus.com
*.wholesalejerseyus.com
wingspirit.com
*.wingspirit.com
winorio.io
*.winorio.io
wolfsgarten.com
*.wolfsgarten.com
wrerjl.academy
*.wrerjl.academy
wrexhamprison.com
*.wrexhamprison.com
wxlnr.net
*.wxlnr.net
xaann.net
*.xaann.net
xamoban.com
*.xamoban.com
xmcthx.com
*.xmcthx.com
xn--4dbsn7b.com
*.xn--4dbsn7b.com
xn--9kqy4scvnxgay21e2rs.com
*.xn--9kqy4scvnxgay21e2rs.com
xn--dpvn2b.com
*.xn--dpvn2b.com
xn--eqr28veq0a.com
*.xn--eqr28veq0a.com
xn--jxq13oxman32cekas39r.xyz
*.xn--jxq13oxman32cekas39r.xyz
xn--myvq21d.com
*.xn--myvq21d.com
xn--projeo-7ta5a.com
*.xn--projeo-7ta5a.com
xn--pss44zlu8a.com
*.xn--pss44zlu8a.com
xn--v4qq7x2jyspe.com
*.xn--v4qq7x2jyspe.com
xs8qmydl.com
*.xs8qmydl.com
xscj5w33m.buzz
*.xscj5w33m.buzz
xyawd.app
*.xyawd.app
xyohz.net
*.xyohz.net
y47133422.vip
*.y47133422.vip
y47164282.vip
*.y47164282.vip
y47172499.vip
*.y47172499.vip
y47182831.vip
*.y47182831.vip
yclgvke89.buzz
*.yclgvke89.buzz
ymacpj.pro
*.ymacpj.pro
yourlocaltheguardian.com
*.yourlocaltheguardian.com
yourubc.com
*.yourubc.com
Other domains in certificate