Deep SSL/TLS Vulnerability Test

This report provides a deep analysis of the SSL/TLS configuration of pentest-tools.com. It checks for protocol support, cipher strength, and known vulnerabilities.

Scan Results

 Start 2026-04-24 06:34:52        -->> 76.76.21.21:443 (pentest-tools.com) <<--

 rDNS (76.76.21.21):     --
 Service detected:       HTTP

 Testing for server implementation bugs 

 No bugs found.

 Testing HTTP header response @ "/" 

 HTTP Status Code             200 OK
 HTTP clock skew              -1 sec from localtime
 HTTP Age (RFC 7234)          0
 Strict Transport Security    180 days=15552000 s, includeSubDomains
 Public Key Pinning           --
 Server banner                Vercel
 Application banner           --
 Cookie(s)                    2 issued: 1/2 secure, 1/2 HttpOnly
 Security headers             X-Frame-Options: SAMEORIGIN
                              X-Content-Type-Options: nosniff
                              Content-Security-Policy: base-uri 'self';
                                font-src 'self' data:
                                https://*.pentest-tools.com https://vercel.live
                                https://fonts.gstatic.com
                                https://script.hotjar.com
                                https://assets.vercel.com self; form-action
                                'self' https://*.pentest-tools.com;
                                frame-ancestors 'self'
                                https://*.pentest-tools.com
                                https://*.vercel.app
                                https://pentesttools.onfastspring.com
                                https://*.cloudfront.net; img-src 'self' https:
                                data: https://*.pentest-tools.com
                                https://pentesttools.onfastspring.com
                                https://*.google-analytics.com
                                https://googletagmanager.com
                                https://*.googletagmanager.com
                                https://*.analytics.google.com
                                https://*.google.com https://ssl.gstatic.com
                                https://www.gstatic.com
                                https://*.g.doubleclick.net
                                https://googleads.g.doubleclick.net
                                https://google.com https://static.hotjar.com
                                https://script.hotjar.com
                                https://*.onfastspring.com self
                                cdn-cookieyes.com self https://*.posthog.com;
                                object-src none; script-src-attr 'none';
                                style-src 'self' 'unsafe-inline'
                                https://*.pentest-tools.com
                                https://*.googletagmanager.com
                                https://vercel.live/fonts
                                https://fonts.googleapis.com
                                https://googletagmanager.com
                                https://tagmanager.google.com
                                https://static.hotjar.com
                                https://script.hotjar.com
                                https://*.onfastspring.com self unsafe-inline;
                                script-src 'self' 'unsafe-inline' 'unsafe-eval'
                                https://*.pentest-tools.com https://*.bing.net
                                https://*.bing.com https://*.bing-int.com
                                https://*.posthog.com
                                https://cdn.jsdelivr.net/npm/workbox-cdn@5.1.4/workbox/workbox-sw.js 
                                ttps://cdn.jsdelivr.net/npm/workbox-cdn@5.1.4/workbox/workbox-core.prod.js 
                                ttps://cdn.jsdelivr.net/npm/workbox-cdn@5.1.4/workbox/workbox-precaching.prod.js 
                                ttps://cdn.jsdelivr.net/npm/workbox-cdn@5.1.4/workbox/workbox-strategies.prod.js 
                                ttps://cdn.jsdelivr.net/npm/workbox-cdn@5.1.4/workbox/workbox-routing.prod.js 
                                ttps://www.google.com
                                https://*.googletagmanager.com
                                https://*.google-analytics.com
                                https://*.google.com
                                https://*.googleadservices.com
                                https://*.adservice.google.com
                                https://adservice.google.com
                                https://tagmanager.google.com
                                https://googleads.g.doubleclick.net
                                https://*.doubleclick.net
                                https://www.googleadservices.com
                                https://*.googlesyndication.com
                                https://static.hotjar.com
                                https://script.hotjar.com https://vercel.live
                                https://cdn.vercel-insights.com
                                https://va.vercel-scripts.com
                                https://*.sentry.com https://*.sentry-cdn.com
                                https://*.onfastspring.com
                                https://*.cloudfront.net
                                https://*.hs-scripts.com
                                https://js.hubspotfeedback.com/feedbackweb-new.js 
                                ttps://js.hubspot.com https://*.usemessages.com
                                https://*.hs-analytics.net
                                https://*.hscollectedforms.net
                                https://*.hs-banner.com https://*.usefathom.com
                                https://*.debugbear.com self unsafe-inline self
                                cdn-cookieyes.com unsafe-inline self
                                https://*.posthog.com;
                                upgrade-insecure-requests; default-src 'self'
                                https://*.pentest-tools.com self; worker-src
                                'self' blob:; connect-src 'self' ws: wss:
                                https://*.pentest-tools.com https://*.bing.net
                                https://*.bing.com https://*.bing-int.com
                                https://ptt.eu-central-1.linodeobjects.com
                                https://content.pentest-tools.com
                                https://google-analytics.com
                                https://*.google-analytics.com
                                https://googletagmanager.com
                                https://*.googletagmanager.com
                                https://stats.g.doubleclick.net
                                https://googleadservices.com
                                https://*.googleadservices.com
                                https://www.google.co.in
                                https://www.google.co.id https://www.google.com
                                https://analytics.google.com
                                https://adservice.google.com
                                https://*.google.com https://google.com
                                https://www.google.id https://www.google.com.br
                                https://www.google.co.uk https://www.google.ca
                                https://www.google.com.au https://www.google.ro
                                https://*.analytics.google.com
                                https://*.g.doubleclick.net
                                https://*.googlesyndication.com
                                https://*.hotjar.com https://*.hotjar.io
                                wss://*.hotjar.com
                                https://vitals.vercel-insights.com
                                https://vitals.vercel-analytics.com
                                https://vercel.live https://*.sentry.io
                                https://*.onfastspring.com
                                https://js.hs-banner.com https://*.hubspot.com
                                https://api.hsforms.com
                                https://*.hscollectedforms.net
                                https://*.usefathom.com https://*.debugbear.com
                                self unsafe-inline self *.cookieyes.com
                                cdn-cookieyes.com https://*.posthog.com self;
                                frame-src 'self' https://*.pentest-tools.com
                                https://*.googletagmanager.com
                                https://*.optimize.google.com
                                https://*.youtube.com
                                https://*.youtube-nocookie.com
                                https://*.simplecast.com
                                https://td.doubleclick.net
                                https://vars.hotjar.com https://vercel.live
                                https://*.onfastspring.com
                                https://*.hubspot.com self
                                https://*.posthog.com https://*.linkedin.com;
                                report-uri
                                https://o1040042.ingest.sentry.io/api/6008920/security/?sentry_key=ea284f2b974341f888d14e98a637f6e0&sentry_environment=production;
                              Permissions-Policy: camera=(),
                                display-capture=(), fullscreen=(),
                                geolocation=(), microphone=()
                              Cross-Origin-Opener-Policy:
                                same-origin-allow-popups
                              X-XSS-Protection: 0
                              Permissions-Policy: camera=(),
                                display-capture=(), fullscreen=(),
                                geolocation=(), microphone=()
                              Referrer-Policy: no-referrer
                              Cache-Control: public, max-age=0, must-revalidate
 Reverse Proxy banner         --


 Testing vulnerabilities 

 Secure Renegotiation (RFC 5746)           supported (OK)
 Secure Client-Initiated Renegotiation     not vulnerable (OK)
 CRIME, TLS (CVE-2012-4929)                not vulnerable (OK)
 BREACH (CVE-2013-3587)                    potentially NOT ok, "br gzip" HTTP compression detected. - only supplied "/" tested
                                           Can be ignored for static pages or if no secrets in the page
 POODLE, SSL (CVE-2014-3566)               not vulnerable (OK)
 TLS_FALLBACK_SCSV (RFC 7507)              No fallback possible (OK), no protocol below TLS 1.2 offered
 SWEET32 (CVE-2016-2183, CVE-2016-6329)    not vulnerable (OK)
 FREAK (CVE-2015-0204)                     not vulnerable (OK)
 DROWN (CVE-2016-0800, CVE-2016-0703)      not vulnerable on this host and port (OK)
                                           make sure you don't use this certificate elsewhere with SSLv2 enabled services, see
                                           https://search.censys.io/search?resource=hosts&virtual_hosts=INCLUDE&q=C97E697F02BF82B11A243BE7ABFF4280E3FB3F4B941B47C491CBDA24FDC09D58
 LOGJAM (CVE-2015-4000), experimental      not vulnerable (OK): no DH EXPORT ciphers, no common prime detected
 BEAST (CVE-2011-3389)                     not vulnerable (OK), no SSL3 or TLS1
 LUCKY13 (CVE-2013-0169), experimental     not vulnerable (OK)
 Winshock (CVE-2014-6321), experimental    not vulnerable (OK)
 RC4 (CVE-2013-2566, CVE-2015-2808)        no RC4 ciphers detected (OK)


 Done 2026-04-24 06:35:51 [  68s] -->> 76.76.21.21:443 (pentest-tools.com) <<--


About this Scan

This scan uses testssl.sh to check for:

  • Protocols: SSLv2, SSLv3, TLS 1.0, TLS 1.1, TLS 1.2, TLS 1.3
  • Vulnerabilities: Heartbleed, POODLE, FREAK, Logjam, DROWN, etc.
  • Cipher Suites: Weak ciphers, perfect forward secrecy (PFS) support.

Run Another Scan Recent Scans