Skip to main content
New: 190 SEO checks now available. See what's new
lowSecurityHSTS_MAX_AGE_SHORT

HSTS max-age is shorter than a year — the fix

Strict-Transport-Security is present but its max-age is under 31536000 seconds, so browsers forget the HTTPS-only rule quickly.

Where this fits: security in SEO

Security issues erode both rankings and trust. HTTPS has been a ranking signal since 2014, and browsers actively warn users away from insecure or mixed-content pages — a warning interstitial is a 100% bounce rate. Missing security headers rarely block indexing, but they widen your attack surface, and a hacked site (injected spam, malicious redirects) can be removed from results entirely. Security is the SEO work you do so you never have to do recovery work.

Why hsts max-age is shorter than a year hurts your rankings

A short max-age narrows the window in which a returning visitor is protected from a downgrade attack, and it disqualifies the site from browser preload lists. The header is doing part of its job.

This is a low-severity issue: a polish item. Fix it in batches during scheduled maintenance; the win is cumulative quality, not a step change.

How to fix it

Raise max-age to at least 31536000 (one year). Add includeSubDomains once every subdomain serves HTTPS, and preload if you intend to submit to the HSTS preload list.

Strict-Transport-Security: max-age=31536000; includeSubDomains

Security best practices

  • Serve everything over HTTPS and redirect HTTP with a single 301.
  • Send HSTS, X-Content-Type-Options, and a Content-Security-Policy on every response.
  • Eliminate mixed content — one insecure asset breaks the padlock.
  • Keep dependencies and CMS plugins patched; most site hacks are known-CVE exploits.
  • Monitor Search Console's security section — Google often knows you're hacked before you do.

The full library: SEO best practices, by category.

Frequently asked questions

What does "HSTS max-age is shorter than a year" mean?

Strict-Transport-Security is present but its max-age is under 31536000 seconds, so browsers forget the HTTPS-only rule quickly.

Why does hsts max-age is shorter than a year matter for SEO?

A short max-age narrows the window in which a returning visitor is protected from a downgrade attack, and it disqualifies the site from browser preload lists. The header is doing part of its job.

How do I fix hsts max-age is shorter than a year?

Raise max-age to at least 31536000 (one year). Add includeSubDomains once every subdomain serves HTTPS, and preload if you intend to submit to the HSTS preload list.

How serious is this issue?

This is a low-severity issue: a polish item. Fix it in batches during scheduled maintenance; the win is cumulative quality, not a step change. It belongs to the security family of checks.

How do I find every page affected by this on my site?

Run a free Dr Urls audit: it crawls your site, detects hsts max-age is shorter than a year on every affected page, shows example URLs, and generates a ready-to-use fix task. Re-scan after fixing to verify the issue is gone.

Does your site have this issue?

A free Dr Urls audit crawls your site, finds every page affected by hsts max-age is shorter than a year, and hands you a ready-made fix task.

Check my site free

Related security guides