Fix the "Not secure" warning on your website

  • ssl
  • https
  • security
  • mixed-content

Updated

A "Not secure" warning means the browser can't confirm a private (HTTPS) connection to your site. Either the site has no valid SSL certificate, it's still loading on an http:// address, or a secure page pulls in an image or script over http://. Fix them in that order: certificate, site address, redirect, then insecure content.

Check what the browser says

Click the icon to the left of the address in the browser bar.

  • "Your connection to this site is not secure" on an http:// address: the site isn't using HTTPS. Check the certificate, then the site address.
  • A full-page warning such as "Your connection is not private": the certificate is missing, expired, or doesn't cover this address (for example it covers www. but not the bare domain). That's for your host to fix.
  • A secure-looking address with a warning or a broken padlock: the page is secure but loads something over http://. See "Fix insecure content" below.

1. Make sure there's a valid certificate

Most hosts give every site a free SSL certificate (often from Let's Encrypt) and renew it automatically. In your hosting dashboard, look for SSL, and check it covers both yourdomain.com and www.yourdomain.com.

If a certificate stopped renewing after you changed your domain's DNS, the host may need to issue it again.

2. Switch WordPress to https

  1. Go to Settings → General.
  2. Change WordPress Address (URL) and Site Address (URL) from http:// to https://. Change nothing else.
  3. Click Save Changes. You'll be asked to log in again.

If the two fields are grayed out, your host or wp-config.php sets them. Ask your host to change them.

Get this right before you save: a typo in either field can lock you out of the admin until your host corrects it.

3. Redirect http to https

Visitors and old links still use http:// addresses. Most hosts have a Force HTTPS switch that redirects them all. Turn it on, then type your address with http:// and check you land on the https:// version.

4. Fix insecure content

A secure page that loads an image, script, or embed over http:// gets a warning, and the browser often blocks that file.

  1. Open the page, then open the browser's developer tools (right-click → Inspect) and go to the Console tab.
  2. Look for "Mixed Content" messages. Each names the http:// address.
  3. Edit the page or setting that adds it and change the address to https://. Most often it's an image inserted before the switch, a hand-pasted embed code, or a script in your theme's header settings.
  4. If the other site doesn't offer HTTPS, remove the file or host it on your own site.

Old links to your own pages in content keep working through the redirect, but changing them to https:// saves a hop.

If your site runs on Dirigible

  • Audit broken links, in Dirigible → Tools & Maintenance, flags images, scripts and embeds still loaded over insecure http:// addresses, with a link to edit each page. See Content gardening tools.
  • On live sites served over HTTPS, the theme tells browsers to keep using HTTPS for the site from then on.

If the certificate keeps failing or the warning only appears on some devices, ask your host or web team to look at the certificate and redirects together, since the fix depends on how your hosting and DNS are set up.