37 Audits
šŸ”’

HSTS Preload Checker

Security Checker

Validates HSTS preload header configuration

Security
20 credits
Per check
~30 seconds
Average runtime
Active
Status

How it works

This checker validates the Strict-Transport-Security header to ensure it's properly configured for HSTS preload inclusion. The checker retrieves the Strict-Transport-Security header, validates max-age, includeSubDomains, and preload directives, and ensures proper configuration for preload inclusion.

What this checker validates

This checker validates the Strict-Transport-Security header to ensure it's properly configured for HSTS preload inclusion. It retrieves the Strict-Transport-Security header, validates max-age, includeSubDomains, and preload directives, and ensures proper configuration for preload inclusion.

Output Documentation

StatusConditionTest Logic
SUCCESSHSTS preload configuredHeader includes max-age≄1yr, includeSubDomains, and preload
WARNINGHSTS present but incompleteHeader present but missing required preload directives
FAILHSTS header missingNo Strict-Transport-Security header found

Risks and Considerations

Security Vulnerabilities: Without HSTS, users may be vulnerable to protocol downgrade attacks and man-in-the-middle attacks. User Data Exposure: Unencrypted connections can expose sensitive user data. Compliance Issues: Many security standards require HSTS implementation.

Ready to start auditing?

Add this checker to your monitoring setup and start identifying issues on your websites today.

Ā© 2025 37 Audits. All rights reserved. Audit your websites with confidence.

Supported by

Featured on Dofollow.Tools

Made with ā¤ļø in Floripa