HSTS
HSTS forces browsers to always connect to your site over secure HTTPS, even if someone tries to load it over plain HTTP.
What it is
HSTS (HTTP Strict Transport Security) is a response header your server sends that tells the browser: "from now on, only ever talk to me over HTTPS." Once a browser has seen this header, it refuses to connect over insecure HTTP for the duration you specify.
This closes a small but dangerous window: the moment before a visitor is redirected from HTTP to HTTPS, where an attacker could intercept the connection.
Why it matters
Even if your site redirects HTTP to HTTPS, that very first insecure request can be hijacked by an attacker on the same network — a technique called SSL stripping. HSTS eliminates that window by making the browser skip HTTP entirely on future visits.
How Pentrawl checks it
Pentrawl inspects your site's response headers for a Strict-Transport-Security header. If it's present, the check passes; if it's missing, we flag it as an issue.
How to fix it
Add the Strict-Transport-Security header to your server configuration. Start with a shorter max-age while testing, then raise it to a year once you're confident HTTPS works everywhere.
Strict-Transport-Security: max-age=31536000; includeSubDomains