What it checks
Whether HTTPS responses carry a Strict-Transport-Security header, and whether its max-age is long enough to protect occasional visitors.
A pass means: HSTS tells browsers to use HTTPS only.
Possible findings
HSTS is not enabled
Severity: MediumConfidence: ConfirmedKind: Recommended hardening
What we found
HTTPS responses do not include a Strict-Transport-Security header.
Why it matters
HSTS tells browsers to only ever use HTTPS for your site. Without it, the first request a visitor makes can be downgraded to HTTP by an attacker on the same network.
How to fix it
Add Strict-Transport-Security: max-age=31536000; includeSubDomains to HTTPS responses once every subdomain serves HTTPS. Start with a short max-age if you are unsure, then raise it.
HSTS max-age is short
Severity: LowConfidence: ConfirmedKind: Recommended hardening
What we found
The Strict-Transport-Security max-age is under six months.
Why it matters
A short max-age means browsers forget the HTTPS-only rule quickly, so the protection lapses for occasional visitors.
How to fix it
Raise max-age to at least one year (31536000 seconds).

