HSTS
HSTS (HTTP Strict Transport Security) is a security response header that instructs browsers to only ever connect to a site over HTTPS. ScanMalware records it from the Strict-Transport-Security header.
HSTS is a positive hardening signal that helps prevent protocol-downgrade and cookie-hijacking attacks, though it does not vouch for the content of the site itself — a phishing page can set HSTS too.
Commonly deployed alongside HSTS
Of the 104,509 public scans where HSTS was detected, these are the technologies most often present on the same site. The share is the percentage of HSTS sites that also ran each one.
| Technology | Category | Share of HSTS sites |
|---|---|---|
| HTTP/3 | wappalyzer | 32.6% |
| X-UA-Compatible | miscellaneous | 31.12% |
| Open-Graph-Protocol | miscellaneous | 31.09% |
| Cloudflare | wappalyzer | 27.02% |
| jQuery | wappalyzer | 24.92% |
| Cloudflare Bot Management | wappalyzer | 22.94% |
| MetaGenerator | miscellaneous | 19.87% |
| Google Analytics | wappalyzer | 19.54% |
| Script | miscellaneous | 17.75% |
| JQuery | miscellaneous | 16.94% |
| Google Tag Manager | wappalyzer | 15.74% |
| PHP | wappalyzer | 15.14% |
| PoweredBy | miscellaneous | 13.77% |
| WordPress | cms | 11.8% |
How ScanMalware detects HSTS
HSTS is detected by analysing the response headers, HTML markup, JavaScript runtime and asset URLs captured when ScanMalware loads the site in a real headless browser.
From any scan you can pivot into related signals — JARM TLS fingerprints, ASN ownership and BGP routing, certificate history, JavaScript analysis and the overall security verdict — to understand not just that HSTS is present, but how it is being used. Open the full search interface for HSTS →
Recent public scans featuring HSTS
A rolling sample of recent public scans where HSTS was detected. Listing a site here is not a safety judgement — open a scan to see its full verdict.
| Site | Scanned |
|---|---|
| Alkosto Hiperahorro | Orgullosamente Colombiano https://frontend-clone-alkosto.vercel.app/ | 2026-07-22 |
| Iniciar sesión en tu cuenta Microsoft https://php-web-server--unitech2factor.replit.app/ | 2026-07-22 |
| facebook https://facebooks-logins.onrender.com/ | 2026-07-22 |
| Pistola de Pressão Co2 Glock W119 Delta BlowBack Metal 4.5mm - Magalu https://magazineluiza-promo.vercel.app/ | 2026-07-22 |
| Iniciar https://php-web-server--zurdacovas.replit.app/indexx.html | 2026-07-22 |
| Iniciar https://php-web-server--zurdacovas.replit.app/ | 2026-07-22 |
| 502 Bad Gateway https://monespacesante-fr-enrolement-124.vercel.app/checkout?dn=www.hexaetudes.fr&pid%1003 | 2026-07-22 |
| SAP0 https://sapitplokogoto.vercel.app/#[email protected] | 2026-07-22 |
Frequently asked questions about HSTS
- Does using HSTS mean a website is unsafe?
- No. HSTS is a stack component, not a verdict. ScanMalware scores the whole page — its scripts, redirects, certificates, threat-intelligence matches and behaviour — so a site using HSTS can be perfectly safe or actively malicious.
- How many sites using HSTS has ScanMalware scanned?
- HSTS has been detected in 104,509 public scans on ScanMalware.com. Each scan is a real headless-browser visit, and the figure updates as new URLs are submitted.
- What technologies are commonly used with HSTS?
- Across scanned sites, HSTS is most often seen alongside HTTP/3, X-UA-Compatible and Open-Graph-Protocol. The full co-occurrence breakdown is listed on this page.
Browse all profiled technologies on the technology index, or scan a URL to see its full stack.