·
HSTS header was missing
Challenge mygoldfinger.com wasn't sending an HSTS header, so a visitor's first request could be downgraded to insecure HTTP.
Action GreenLight flagged it with the exact fix. We added Strict-Transport-Security: max-age=31536000; includeSubDomains.
Result HTTPS is now enforced on every visit; a re-scan reads OK.