HTTP Strict Transport Security (HSTS)

Description: Forces browsers to use HTTPS for your site, reducing downgrade and cookie hijacking risks.

How it works: When enable_hsts is on, AegisShield sends the Strict-Transport-Security header so browsers remember to use HTTPS.

How to access / configure:

  1. WP Admin → AegisShield → Security Headers.
  2. Enable HSTS.
  3. Confirm your site is fully HTTPS first, then Save Changes.

Recommended setting: Enable only after confirming HTTPS is permanent and working across all subpages.