No HSTS header
warningYour site is served over HTTPS but doesn't send a Strict-Transport-Security header. Without it, the first visit (or a link typed as http://) can be intercepted and downgraded to plain HTTP before the redirect happens — a foothold for man-in-the-middle attacks on public Wi-Fi.