HSTS: sites that demand https are never reached over plaintext, not even once
A site can tell a browser it must only ever be reached over https (HTTP Strict Transport Security). Floati parsed that header for compression but never acted on it, so it would still make the one plaintext request an attacker on your network needs to strip TLS or plant a redirect. Now the engine enforces HSTS. When a site sends Strict-Transport-Security over a secure connection, the engine remembers it and, from then on, upgrades every http request to that host to https BEFORE any socket is opened - so the insecure request simply never goes out. It honours max-age (including max-age=0 to un-pin), includeSubDomains, and ignores the header when it arrives over plaintext (per the spec, so an attacker cannot forge or clear a pin). It also ships a small curated preload subset of the highest- traffic always-https hosts, so those are upgraded even on the very first visit of a fresh session, closing the trust-on-first-use gap for them. This closes the scorecard's note that HSTS was parsed but not enforced. Security moves 39 to 40; overall holds at 52.