security / security headers / hsts
Security headers

HSTS

HSTS forces browsers to always connect to your site over secure HTTPS, even if someone tries to load it over plain HTTP.

Severity if missing
High
Category
Security headers
Standard
RFC 6797

What it is

HSTS (HTTP Strict Transport Security) is a response header your server sends that tells the browser: "from now on, only ever talk to me over HTTPS." Once a browser has seen this header, it refuses to connect over insecure HTTP for the duration you specify.

This closes a small but dangerous window: the moment before a visitor is redirected from HTTP to HTTPS, where an attacker could intercept the connection.

Why it matters

Even if your site redirects HTTP to HTTPS, that very first insecure request can be hijacked by an attacker on the same network — a technique called SSL stripping. HSTS eliminates that window by making the browser skip HTTP entirely on future visits.

The risk
Without HSTS, visitors can be silently downgraded to an insecure connection on their first request, exposing them to interception on untrusted networks like public Wi-Fi.

How Pentrawl checks it

Pentrawl inspects your site's response headers for a Strict-Transport-Security header. If it's present, the check passes; if it's missing, we flag it as an issue.

How to fix it

Add the Strict-Transport-Security header to your server configuration. Start with a shorter max-age while testing, then raise it to a year once you're confident HTTPS works everywhere.

Recommended
Strict-Transport-Security: max-age=31536000; includeSubDomains
Check your domain's HSTS in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →