I get the security score F in webPageTest site saying The following security headers are missing from the website:
Strict Transport Security
X Content Type Options
X Frame Options
Content Security Policy
X XSS Protection
If I click on the Enable HSTS button under Edge Certificate/ SSL/TLS, that will take care of them? Does it also help speed or performance optimization? Please advise.
I just want to make sure before committing HSTS cuz the note is kind of intimidating. If I enable it can I turn it off for some reason? I sometime need to pause Cloudflare to check plugin conflict, in that case do I need to turn HSTS off first, then pause?
I strongly suggest that you not use HSTS if your origin web server does not have its own TLS/SSL certificate for your domain. The minimum setting is 1 month, so if you don’t have HTTPS working on your site at any point, it will take a month for any return visitors to be able to view your site without HTTPS.