security / security headers / https redirect
Security headers

HTTPS redirect

An HTTPS redirect ensures that visitors who arrive over insecure HTTP are automatically sent to the secure HTTPS version of your site.

Severity if missing
High
Category
Security headers
Standard
RFC 7231

What it is

Even with a valid certificate, a site can often still be reached over plain, unencrypted HTTP. An HTTPS redirect fixes that: when someone requests the HTTP version, your server responds with a redirect that sends them straight to HTTPS.

It ensures that no matter how a visitor arrives, they end up on the encrypted version of your site.

Why it matters

If HTTP works and doesn't redirect, some visitors will browse your site unencrypted — their traffic readable by anyone on the network. Redirecting every HTTP request to HTTPS guarantees that all traffic is protected, and it's the foundation that HSTS builds on.

The risk
Without an HTTPS redirect, visitors can browse your site over an unencrypted connection, exposing their data to interception.

How Pentrawl checks it

Pentrawl requests the plain HTTP version of your site and checks whether it redirects to HTTPS. A correct redirect passes; serving content over HTTP without redirecting is flagged as an issue.

How to fix it

Configure your web server to redirect all HTTP traffic to HTTPS with a permanent (301) redirect. The exact configuration depends on your server, but the effect should be the same everywhere.

Effect (nginx example)
return 301 https://$host$request_uri;
Check your domain's HTTPS redirect in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →