Issue
security: HTTP Strict Transport Security (HSTS)
Error
Secure connection upgrade not enforced.
Why is this a problem
HSTS is a security feature that ensures a website is only accessible over HTTPS. It helps to prevent man-in-the-middle attacks, such as protocol downgrade attacks, by enforcing that browsers always communicate with the server over a secure connection. Without HSTS, an attacker could intercept traffic on a non-secure connection and compromise user data.
Prevalence
This is a sitewide issue
Description
Site upgrades to a secure connection.
Documentation
ScanGov HTTP Strict Transport Security (HSTS) docs
21st Century Integrated Digital Experience Act
CISA Website Security
CISA Cybersecurity Performance Goals
Issue
security: HTTP Strict Transport Security (HSTS)
Error
Secure connection upgrade not enforced.
Why is this a problem
HSTS is a security feature that ensures a website is only accessible over HTTPS. It helps to prevent man-in-the-middle attacks, such as protocol downgrade attacks, by enforcing that browsers always communicate with the server over a secure connection. Without HSTS, an attacker could intercept traffic on a non-secure connection and compromise user data.
Prevalence
This is a sitewide issue
Description
Site upgrades to a secure connection.
Documentation
ScanGov HTTP Strict Transport Security (HSTS) docs
21st Century Integrated Digital Experience Act
CISA Website Security
CISA Cybersecurity Performance Goals