KhanyaSec Security CheckBeta
ChecksTermsScan

Checks

HSTS missing max-age

Strict-Transport-Security is present but has no max-age directive, so browsers ignore it as HSTS.

Why it matters

Without max-age the header does not create an HTTPS-only rule.

What to do

Add max-age=31536000.

Reference

HSTS max-age and directive syntax are defined by RFC 6797.

RFC 6797 — HTTP Strict Transport Security (HSTS)

Scan a siteAll results
KhanyaSec Security CheckBeta

KhanyaSec is in public beta. Results are informational and may change.

Informational only. Passive checks of publicly reachable signals. We do not collect email or other personal data; scanned URLs and scan date/time may be stored for statistics.

Bugs, suggestions, and comments: contact@khanyasec.dev

Free scanChecksTerms of UsePrivacy