Skip to content

HTTP security configuration

Redirecting HTTP to HTTPS

Whether a plain HTTP request to the site is answered with a redirect to the same address over HTTPS.

Part of the External Security Check. Free during the preview.

What it checks

Whether a plain HTTP request to the site is answered with a redirect to the same address over HTTPS.

A pass means: Plain HTTP requests are redirected to HTTPS.

Possible findings

HTTP is not redirected to HTTPS

Severity: MediumConfidence: ConfirmedKind: Security issue

What we found

A plain HTTP request was answered without a redirect to HTTPS.

Why it matters

Visitors who type the address or follow an old link stay on an unencrypted connection, where traffic can be read or altered.

How to fix it

Redirect every HTTP request to the same path over HTTPS with a 301 or 308. Most hosts and CDNs have an "Always use HTTPS" setting.

References