HTTP Strict Transport Security

HTTP Strict Transport Security (HSTS) is a security enhancement for a website or web application that prevents any communication to go through an unencrypted connection – an unencrypted connection goes through HTTP while an encrypted one goes through HTTPS. Using HSTS can also prevent man-in-the-maddle attackers to intercept traffic going through to your website.


HSTS addresses the following threats:

  • Website run on HTTPS connections contains HTTP links or serves content over HTTP

  • A man-in-the-middle attacker intercepts traffic from a victim user using an invalid certificate


