Cloudflare Security & compliance Releases

Always Use HTTPS is off

Part of the Edge TLS posture check · fix arrives as a guide

What it is

"Always Use HTTPS" is off, so plain HTTP requests are served rather than redirected.

Why it matters

The first request from a user who types the bare domain travels unencrypted, which is enough to steal a session cookie not marked Secure or to inject content before the redirect would have happened.

How to fix it

Enable Always Use HTTPS so HTTP is redirected at the edge, and pair it with HSTS so browsers stop making the plain request at all after the first visit.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.