Security
Browsers are told to stay on HTTPS
security.missing-hsts
Why this matters
Your site works over HTTPS, but it never tells browsers to remember that. The very first visit of the day can still be sent over an insecure connection before the redirect happens, which is the window an attacker on shared Wi-Fi needs.
Who fixes it
You can, usually
Roughly how long
15 minutes
Care needed
Test before and after
How to fix it
Add `Strict-Transport-Security: max-age=31536000; includeSubDomains` to your HTTPS responses. Start with a short max-age and raise it once you are confident every subdomain serves HTTPS.
On your platform
WordPress
Not a WordPress setting — it comes from your host or your CDN. In Cloudflare it is under SSL/TLS → Edge Certificates → HTTP Strict Transport Security, and the panel walks you through it. On Apache hosting it can go in `.htaccess`. Whichever you use, start with `max-age=300` and check every subdomain you own still loads over HTTPS before raising it to a year — that includes shop, blog, mail and any staging site.
Shopify
Already handled, and not yours to change. Shopify serves storefronts over its own edge and sends this header itself, so if it is being reported the response that was checked probably did not come from Shopify — a parked domain, a redirect service, or a subdomain pointing somewhere else. Worth checking what that hostname actually resolves to before doing anything.
Drupal
Either at the web server, or with the Security Kit (`seckit`) module, which has an HSTS section and needs no server access. Set a short max-age first: Drupal sites often sit alongside subdomains for staging or files, and `includeSubDomains` covers all of them at once.
Joomla
The System – HTTP Headers plugin (Joomla 4 and 5) includes HSTS with its own max-age and includeSubDomains options, so this needs no server access. Start with a small max-age and raise it once you are sure every subdomain serves HTTPS.
How we score it
Failing this check takes up to 12 points off your security score. It is a fact about your site rather than a measurement, so it reads the same on every scan until you change something.
Does your site pass this one?
This check runs on every scan, along with the other 106. Free, no account, and you see the evidence for each result.
Check my siteOther security checks
- A content security policy is in placeA content security policy tells the browser which scripts it may run. Without one, anything that manages to get injected into a page — through a compromised plugin, a hijacked advert, or a comment field — runs with the same trust as your own code.
- Camera, microphone and location access are restrictedAnything embedded in your pages — an advert, a chat widget, a map — can ask the visitor for access to their camera, microphone or location, and the request appears to come from you.
- Cookies are only sent over an encrypted connectionA cookie without the Secure flag is sent over a plain, unencrypted connection as readily as over an encrypted one. Anyone sharing a network with the visitor — a café, a hotel, an office guest network — can read it, and a single request to the http version of the site is enough to expose it, even when every page normally redirects to https. The flag costs nothing and there is no reason for a cookie on a secure site to be missing it.
- File types cannot be second-guessedWithout this header a browser may ignore what your server says a file is and guess instead. An uploaded image that is secretly a script can then be run as one.
- Folders are not browsableYour server is showing a file listing instead of a page. Anyone can read it and see exactly what is in that folder — backups, spreadsheets, database dumps, anything left there and forgotten.
- Login cookies are hidden from scripts on the pageA session cookie marked HttpOnly can be sent to the server but cannot be read by JavaScript running on the page. Without that flag, any script that ends up on the site — through a compromised plugin, a hijacked advert, or a comment field that did not escape its input — can read a logged-in session and use it from somewhere else. It is the difference between a script injection being an embarrassment and being an account takeover.