Strict-Transport-Security not enforced
The site did not return an HSTS header, leaving the browser without protection against protocol downgrade attempts (e.g., SSL stripping on first-visit or staging environments).
Description
Responses did not include the Strict-Transport-Security header. Without HSTS, browsers do not enforce HTTPS-only access on first visit or after the policy expires. This widens the window for SSL-stripping or downgrade attacks when users connect over hostile networks.
Impact
Informational. Defense-in-depth gap rather than a directly exploitable bug.
Recommendation
Return Strict-Transport-Security: max-age=63072000; includeSubDomains; preload on all responses. Consider submitting the domain to the HSTS preload list once the policy has been stable for a few weeks.
All Your Base: Acknowledged. Zealynx: Acknowledged.