Even with SSL installed, there's a brief window where a visitor's first request to your site could occur over unencrypted HTTP — HSTS closes that gap.
The Vulnerability It Fixes
Without HSTS, an attacker on the same network could intercept that first unencrypted request before the redirect to HTTPS happens, a technique known as SSL stripping.
How HSTS Works
Once a browser has visited your HTTPS site once, HSTS tells it to always connect via HTTPS from then on, automatically, without ever attempting an unencrypted connection again.
Enabling It
HSTS is enabled through a response header, configurable in Plesk or your server configuration — confirm your SSL setup is stable before enabling it, since it's not instantly reversible for returning visitors.
Español
Deutsch