Remediation

Missing HSTS header

The site did not return a `Strict-Transport-Security` header on the HTTPS response. Without HSTS, browsers are more exposed to downgrade and SSL stripping scenarios, especially on first visit or when users follow insecure links.

What this usually means

Fix path

Safe rollout advice

Verify after change