Cloudflare
Security & compliance
Releases
Always Use HTTPS is off
Part of the Edge TLS posture check · fix arrives as a guide
What it is
"Always Use HTTPS" is off, so plain HTTP requests are served rather than redirected.
Why it matters
The first request from a user who types the bare domain travels unencrypted, which is enough to steal a session cookie not marked Secure or to inject content before the redirect would have happened.
How to fix it
Enable Always Use HTTPS so HTTP is redirected at the edge, and pair it with HSTS so browsers stop making the plain request at all after the first visit.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.