glimanaDocs Open Glimana →

Issue guide · Security

No HTTP → HTTPS redirect

SeverityHigh
CategorySecurity
ScopeWhole site
EffortSmall
Verified byManually
Rule keyhttp_to_https_redirect_missing

Short answer

Glimana requested the http:// version of your home page and got a 200 response that stayed on http://. The site has HTTPS, but nothing sends HTTP visitors (and crawlers following old links) to it. Add a server-wide 301 redirect from http:// to https:// so that every URL has exactly one secure version.

Why it matters

This issue affects connection security. Without the redirect, anyone who types the domain without https://, or follows an old link, browses the insecure copy. Search engines see two versions of every page and have to pick one; the signals (links, engagement) are split between them until they do.

How Glimana detects it

At the start of each crawl Glimana probes the four host variants (http://, https://, with and without www). The rule fires when an http:// variant returns 200 and its final URL still starts with http://. The evidence names the variant.

How to fix it

Add to the top of .htaccess (Apache):

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

or enable the redirect in Really Simple SSL / your host panel. On Cloudflare, turn on SSL/TLS › Edge Certificates › "Always Use HTTPS".

Shopify redirects HTTP to HTTPS automatically once the certificate is active. If this fires, the domain's DNS is pointing somewhere else for HTTP or the certificate is still pending under Settings › Domains.

Nginx:

server {
    listen 80;
    server_name example.com www.example.com;
    return 301 https://$host$request_uri;
}

Prefer doing it at the edge (load balancer, CDN) so the application never sees HTTP.

How the fix is verified

This rule is verified manually because the probe runs once per crawl and some CDNs cache the old behaviour for a while. Mark the task done after confirming with curl -I http://example.com/ that the response is 301 with a Location: https://… header; the rule stops firing on the next crawl.

Sources