No HSTS header
hsts_missingShort answer
Your HTTPS home page is served without a Strict-Transport-Security header. HSTS tells browsers to use HTTPS for your domain automatically on future visits, even if the user types http:// or follows an insecure link, which closes the small window in which a redirect could be intercepted. Google's John Mueller has said security headers don't affect search; this is valuable for security, not for SEO. Add the header with a max-age of at least one year.
Why it matters
Without HSTS, every first request a returning visitor makes to http:// is still a plaintext request that an attacker on the same network could intercept before the redirect. HSTS removes that request entirely. It is a requirement for many security audits and for HSTS preload inclusion in browsers.
How Glimana detects it
The rule looks at the root page of the site (depth 0). It fires when the page is served over HTTPS and the response has no Strict-Transport-Security header.
How to fix it
Watch out
Only add HSTS once every subdomain you include is served correctly over HTTPS. A browser that has seen the header will refuse HTTP for the whole max-age; there is no quick undo. Start with a short max-age (e.g. 300) to test, then raise it.
Add to .htaccess: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" (requires mod_headers). Really Simple SSL Pro and several security plugins have an HSTS toggle. On Cloudflare: SSL/TLS › Edge Certificates › HSTS.
Shopify sends HSTS on its own domains and on custom domains with an active certificate. If this fires, the certificate is pending or the request went through a proxy that strips headers.
Nginx: add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; inside the HTTPS server block. Add preload only if you intend to submit to hstspreload.org.
How the fix is verified
Re-crawl; the task closes when the root page carries the header.