{"host":"crawlcheck.io","current":"max-age=31536000; includeSubDomains","current_judged":{"present":true,"max_age":31536000,"include_subdomains":true,"preload_token":false,"preload_eligible":false,"finding":null},"http_redirects_to_https":true,"options":[{"id":"safe","header":"max-age=31536000","when":"Use this unless you are sure every subdomain serves HTTPS. It does not touch subdomains and cannot lock anyone out of one.","judged":{"present":true,"max_age":31536000,"include_subdomains":false,"preload_token":false,"preload_eligible":false,"finding":null}},{"id":"preload","header":"max-age=63072000; includeSubDomains; preload","when":"Only if every subdomain (mail., shop., old staging hosts) serves HTTPS, and you intend to submit to hstspreload.org - browsers then refuse plain HTTP on the whole domain, and removal takes months.","judged":{"present":true,"max_age":63072000,"include_subdomains":true,"preload_token":true,"preload_eligible":true,"finding":null},"requirements":[{"req":"http:// redirects to https://","ok":true},{"req":"the homepage answers over HTTPS","ok":true}]}],"how":{"cloudflare":"SSL/TLS > Edge Certificates > HTTP Strict Transport Security (HSTS) > Enable; set Max Age 12 months; tick Include subdomains and Preload only for the preload option.","nginx":"add_header Strict-Transport-Security \"<header>\" always;   (inside the HTTPS server block)","apache":"Header always set Strict-Transport-Security \"<header>\"   (in the SSL vhost or .htaccess, mod_headers on)","wordpress":"On Cloudways/most hosts use the host's SSL panel or the Cloudflare setting above; a plugin header is sent only on PHP pages, not on static files."},"note":"the scanner raises HSTS_MISSING for no header and HSTS_PRELOAD_INELIGIBLE for a preload token without 31536000 + includeSubDomains; both options above pass that rule"}