Fix the "Not secure" warning on your website
A "Not secure" warning means the browser can't confirm a private (HTTPS) connection to your site. Either the site has no valid SSL certificate, it's still loading on an http:// address, or a secure page pulls in an image or script over http://. Fix them in that order: certificate, site address, redirect, then insecure content.
Check what the browser says
Click the icon to the left of the address in the browser bar.
- "Your connection to this site is not secure" on an
http://address: the site isn't using HTTPS. Check the certificate, then the site address. - A full-page warning such as "Your connection is not private": the certificate is missing, expired, or doesn't cover this address (for example it covers
www.but not the bare domain). That's for your host to fix. - A secure-looking address with a warning or a broken padlock: the page is secure but loads something over
http://. See "Fix insecure content" below.
1. Make sure there's a valid certificate
Most hosts give every site a free SSL certificate (often from Let's Encrypt) and renew it automatically. In your hosting dashboard, look for SSL, and check it covers both yourdomain.com and www.yourdomain.com.
If a certificate stopped renewing after you changed your domain's DNS, the host may need to issue it again.
2. Switch WordPress to https
- Go to Settings → General.
- Change WordPress Address (URL) and Site Address (URL) from
http://tohttps://. Change nothing else. - Click Save Changes. You'll be asked to log in again.
If the two fields are grayed out, your host or wp-config.php sets them. Ask your host to change them.
Get this right before you save: a typo in either field can lock you out of the admin until your host corrects it.
3. Redirect http to https
Visitors and old links still use http:// addresses. Most hosts have a Force HTTPS switch that redirects them all. Turn it on, then type your address with http:// and check you land on the https:// version.
4. Fix insecure content
A secure page that loads an image, script, or embed over http:// gets a warning, and the browser often blocks that file.
- Open the page, then open the browser's developer tools (right-click → Inspect) and go to the Console tab.
- Look for "Mixed Content" messages. Each names the
http://address. - Edit the page or setting that adds it and change the address to
https://. Most often it's an image inserted before the switch, a hand-pasted embed code, or a script in your theme's header settings. - If the other site doesn't offer HTTPS, remove the file or host it on your own site.
Old links to your own pages in content keep working through the redirect, but changing them to https:// saves a hop.
If your site runs on Dirigible
- Audit broken links, in Dirigible → Tools & Maintenance, flags images, scripts and embeds still loaded over insecure
http://addresses, with a link to edit each page. See Content gardening tools. - On live sites served over HTTPS, the theme tells browsers to keep using HTTPS for the site from then on.
If the certificate keeps failing or the warning only appears on some devices, ask your host or web team to look at the certificate and redirects together, since the fix depends on how your hosting and DNS are set up.