Missing Strict-Transport-Security header
Strict-Transport-Security tells a browser to refuse plain HTTP for your domain, even before it makes the request.
Why it matters
Strict-Transport-Security tells a browser to refuse plain HTTP for your domain, even before it makes the request. Without it, an attacker on the same network can intercept the very first connection and downgrade it, which is the one moment your HTTPS redirect cannot protect. This costs one header and closes the gap.
How ShipReady detects it
Shared tables and rules for the two halves below. Split because this check was a hybrid: nine rules read the headers of a response we already have, which genuinely differ between routes, while missing-https-redirect probes the http:// equivalent of the origin — one fact, and running it per page would issue the same request ten times.
Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.3.0.
How to fix it
This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.
Add a Strict-Transport-Security header to enforce HTTPS.
Frequently asked questions
- What does "Missing Strict-Transport-Security header" mean?
- Strict-Transport-Security tells a browser to refuse plain HTTP for your domain, even before it makes the request.
- How serious is it?
- ShipReady rates this medium. Fix soon. Meaningfully weakens a defence or degrades how the site works.
- How do I fix it?
- Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
- Can I check my own site?
- Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check.
Related checks
Does your site have this?
ShipReady checks this and 73 other things across up to ten pages of your site. Free, no signup.
Scan my site