Lessons

The "Strict HTTPS" header

Even if you opened the page on an encrypted channel, you can still make a request on an open connection. Even if the server automatically redirects you to a secure channel, but the request has already been made. So the useful data contained in it has already been transmitted over an open connection.

To prevent this from happening, you need to tell the user’s browser to force only the encrypted connection to be used.

More details how to improve the security of Nginx and Apache servers.

Check your website
It's free and will take from 11 to 45 seconds

We use cookies. By continuing to use the site, you agree to the processing of personal data in accordance with privacy policy. I agree