Header Security
Shopify HSTS Header Check
The HSTS (Strict-Transport-Security) header forces HTTPS connections on your Shopify store. Check its presence and learn how to configure it to enhance security.
What this test checks
This test checks whether the HSTS header is present on your Shopify store. This header forces browsers to connect exclusively over HTTPS, protecting your customers against downgrade attacks and connection hijacking. Its absence exposes your site to security risks.
Our recommendation
Add the HSTS header with a minimum duration of 31536000 seconds (1 year) in your Shopify server configuration. Use Shopify's built‑in security settings to configure this header. Test your configuration with browser developer tools.
Security tests