Plain http does not redirect
7.2%
of the 3,044 free scans considered in the last 30 days raised this finding. That is 219 scans across 209 distinct sites. 95% interval 4.5% to 11.4%.
What it means
A visitor or link landing on the http address stays on the insecure version instead of being sent to the secure one.
How to fix it
Add a permanent 301 redirect from http:// to https:// at the server or CDN, for every path, so an old link cannot land anyone on the insecure copy.
How to check it yourself
Run curl -sI http://example.com and check the response. A 301 redirect to the https address means it works; staying on http means it does not.
What fixed looks like
Requesting the plain http address returns a 301 redirect to the https version, for every path.
How we measured this
Go Voltic scans a site and records which findings it raises. The share above is over every free four-page scan in the last 30 days that loaded at least one page, which is 3,044 scans. Deep scans of paid reports and of the research sweep read a site at a different depth and are a separate population, never in this denominator. It is not a survey and it is not an estimate: it is a count of what our own scanner found. Sites are counted once each in the distinct-sites figure, so a site scanned twice does not weigh double there.
The interval is a 95% Wilson interval. A share printed without its sample size reads as certainty and is indistinguishable from a guess, so both are always shown. Figures on this page were computed on 2026-09-08.
The same share sits beside every other finding on the benchmarks page, which also carries the whole table as CSV and JSON and says how to cite it.
Check your own site
The free scan reads four pages and reports every finding it raises, including this one. It takes about ten seconds and asks for nothing but the address.