http:// requests are properly redirected to HTTPS, whether HSTS is configured to lock that behaviour in at the browser level, and whether the redirect chain itself is clean and direct.Many sites install an SSL certificate but still leave the plain http:// version of the site accessible. That means anyone who types your domain without https://, clicks an old link, or gets sent there by an out-of-date bookmark lands on the unencrypted version — even though the secure version exists right next to it.
http://yourdomain.com should immediately and permanently redirect to https://yourdomain.com, with no detour through an insecure page first.Without enforcement, a user on public Wi-Fi who reaches the HTTP version even briefly is exposed to interception during that request, and to an attacker rewriting the page before the redirect fires (a technique called SSL stripping). Real preload list inclusion is what closes this gap entirely — without it, even a correctly-configured redirect can't protect a user's very first visit.
Most modern hosts (Kinsta, WP Engine, Cloudflare) offer a one-click "Force HTTPS" toggle in the dashboard. Once your HSTS header has a sufficient max-age and includeSubDomains, submit your domain at hstspreload.org for the strongest possible guarantee.
PEKRYON scans your website across 26 modules. We take the time needed for accurate results — no server access needed.
Scan My Website Free → Learn More