WP Clinic
Log in Sign up

SECURITY FINDING

Missing HSTS header (no forced HTTPS)

What it is

Your site doesn't tell browsers to always use a secure (HTTPS) connection. Without this header, a visitor who types the plain http:// address, or clicks an old http:// link, can be sent over an insecure connection first, which an attacker on the same network could intercept.

How to fix it

Add the Strict-Transport-Security (HSTS) header at your server or CDN so browsers always upgrade to HTTPS on this domain. If you're not sure how, install the WordPress Plugin: its Security tab applies fixes like this one automatically.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.