All fixes

Replace a self-signed certificate

tls-cert-selfsigned

A self-signed certificate is trusted by nobody, so visitors get a warning page and non-browser clients fail outright. Issue a real one.

Why this matters

Your site uses a self-signed certificate. Browsers show a warning page that blocks most visitors. Not exploitable — MitM requires users to actively bypass browser warnings, which modern browsers make very difficult.

Nginx

  1. 1 Replace the self-signed certificate with one from a trusted CA
  2. 2 Let's Encrypt provides free certificates
bash
# Install Certbot and get a free certificate
sudo certbot --nginx -d example.com

Does your app still have this?

Scan your domain