SECURITY FINDING
Missing HSTS header (no forced HTTPS)
What it is
Your site doesn't tell browsers to always use a secure (HTTPS) connection. Without this header, a visitor who types the plain http:// address, or clicks an old http:// link, can be sent over an insecure connection first, which an attacker on the same network could intercept.
How to fix it
Add the Strict-Transport-Security (HSTS) header at your server or CDN so browsers always upgrade to HTTPS on this domain. If you're not sure how, install the WordPress Plugin: its Security tab applies fixes like this one automatically.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.