Exposure
Your app does not require a secure connection
Missing HTTP Strict Transport Security
What this means
Your app does not tell browsers to talk to it over a secure connection only. A user's first request can travel in the clear — along with whatever they type.
Why it matters
On an open network — a cafe, an airport, a hotel — a stranger can intercept or alter such a request. The user notices nothing.
When this is not a problem
For apps reachable only on an internal network the risk is considerably lower.
How to fix it
- Add a Strict-Transport-Security header to every response.
- Set a lifetime of at least one year (max-age=31536000).
Prompt for your AI agent
Add a Strict-Transport-Security header with a lifetime of at least a year to all responses so browsers always use a secure connection.
Verify the fix: repeat the request and confirm the header is present
Is your app doing this?
Find out in about a minute — the first scan is free.
