Vulnerabilities/

Strict-Transport-Security Header is Missing

Impact: Low

Description

The HTTP Strict-Transport-Security response header (often abbreviated as HSTS) lets a web site tell browsers that it should only be accessed using HTTPS, instead of using HTTP. Mozilla

Recommendation

Configure your server to send this header for all pages. You can see references for possible values.

References

Last updated on February 15, 2021

Use SmartScanner Free version to test for this issue

Download