Detect HSTS
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
01
Websites using HSTS
12,220 hostnames in the PluginView corpus for this technology.
| Hostname | Last seen |
|---|---|
| google.com | 8/3/2026 |
| youtube.com | 8/6/2026 |
| facebook.com | 8/6/2026 |
| wikipedia.org | 8/6/2026 |
| instagram.com | 8/6/2026 |
Whole list · $366.60 (12,220 × $0.03)
Sign in to purchase02
What a detection means
- Establishes
- One or more public signals on the scanned page matched a known HSTS signature at the time of the scan.
- Does not establish
- A sitewide install of HSTS, an active vendor contract, exclusive use, or that HSTS is still in place today.
03
How to check a site for HSTS
- 1. Enter the website URL in the scan form — homepage, pricing, checkout, or login pages usually expose the strongest HSTS signals.
- 2. PluginView reads only public responses and scores them against proprietary HSTS fingerprints. Rule bodies and identifiers are not published.
- 3. Review the confidence score and text explanation for HSTS on the results page.
04
FAQ: detecting HSTS
- Can PluginView detect HSTS without logging in?
- Yes. PluginView only reads publicly accessible responses when checking for HSTS. It does not bypass authentication or paywalls.
- What category is HSTS?
- HSTS is classified under Security in the PluginView directory.
- Does PluginView publish HSTS fingerprint rules?
- No. Detection uses proprietary fingerprint rules that are not published. Scan results explain matches in plain language without disclosing rule bodies or identifiers.