HTTPS redirect
An HTTPS redirect ensures that visitors who arrive over insecure HTTP are automatically sent to the secure HTTPS version of your site.
What it is
Even with a valid certificate, a site can often still be reached over plain, unencrypted HTTP. An HTTPS redirect fixes that: when someone requests the HTTP version, your server responds with a redirect that sends them straight to HTTPS.
It ensures that no matter how a visitor arrives, they end up on the encrypted version of your site.
Why it matters
If HTTP works and doesn't redirect, some visitors will browse your site unencrypted — their traffic readable by anyone on the network. Redirecting every HTTP request to HTTPS guarantees that all traffic is protected, and it's the foundation that HSTS builds on.
How Pentrawl checks it
Pentrawl requests the plain HTTP version of your site and checks whether it redirects to HTTPS. A correct redirect passes; serving content over HTTP without redirecting is flagged as an issue.
How to fix it
Configure your web server to redirect all HTTP traffic to HTTPS with a permanent (301) redirect. The exact configuration depends on your server, but the effect should be the same everywhere.
return 301 https://$host$request_uri;