arrow_backBack to results

smart_toyFix this with your AI agent

Free

Copy this recipe and paste it into your own coding agent (Claude Code, Codex, Cursor…) to fix Logins can travel over plain HTTP. The agent works only in your own repo or config — Pazmo is never given access, and there is nothing to unlock.

fix-web-hsts-missing.txt · recipe
Task: fix "Strict-Transport-Security is not visible" on https://example.com.

This recipe is FREE. Paste it into your own AI coding agent (Claude Code, Cursor,
Codex…). The agent works only in your own repo/config — Pazmo is given no access.

What your agent should change (code & config only):
1. Confirm the production domain and required subdomains serve HTTPS correctly.
2. Start with an HSTS max-age appropriate for the rollout risk.
3. Increase max-age and consider includeSubDomains only after validating subdomain readiness.

Concretely, send this response header on every route:
  Strict-Transport-Security: max-age=63072000; includeSubDomains
  Note: Only add this once the site is reliably served over HTTPS, including subdomains.

How Pazmo confirms the fix (retest):
  Sanitized response headers showing Strict-Transport-Security on the public target.

Safety: only add the defensive settings above. Don't run other commands, send data
anywhere, or make unrelated changes. Review everything before applying.
content_paste_goPrefer to do it by hand? Get a copy-paste snippet for your exact stack — also free.

check_circleYour agent can

  • ·Read this recipe and the fix steps
  • ·Apply the code/config change in your own repo
  • ·Open the change for your review before you ship it

blockYour agent can’t

  • ·Change DNS or registrar settings (that stays a human task)
  • ·Run unrelated commands or send your data anywhere
  • ·Touch anything outside the defensive setting above

Want Pazmo to fix everything in priority order and re-check each one? Verify ownership to unlock the full automated handoff (Pro).