Why does my website say "Not secure", and how do I fix it?
Browsers show "Not secure" when a page loads over plain HTTP instead of HTTPS, or when the HTTPS setup is broken: an expired or missing SSL certificate, a certificate for the wrong domain, or a secure page loading insecure images and scripts. Most fixes take minutes to hours: install a free certificate, redirect HTTP to HTTPS and fix mixed content.
- Usual cause
- No HTTPS / expired SSL
- Certificate cost
- Usually free
- Fixed for you
- from $400


4.9
patient rating displayed on the live site
The five common causes
- No SSL certificate at all: the site only works over http://
- The certificate expired: auto-renewal failed or the host changed
- Wrong domain on the certificate: it covers example.com but not www.example.com (or the reverse)
- No redirect: https:// works, but visitors and old links still land on http://
- Mixed content: a secure page loads an image, script or form over http://
How to check which one it is
Run your address through a free SSL checker: it shows whether there's a certificate, who issued it, which domains it covers and when it expires. Then open the site with https:// and http://, with and without www, and see where each ends up. In the browser, click the warning icon for details; developer tools list any mixed-content warnings.
How to fix it
- Turn on the free certificate in your hosting panel (most hosts offer Let's Encrypt), covering both the www and non-www address
- Add a permanent (301) redirect from http:// to https://, and pick one version of www
- Replace http:// links to images, scripts and fonts with https://
- Update the site address in your CMS (for WordPress: Settings, then General)
- Check auto-renewal so it doesn't expire again, and re-test
Does "Not secure" hurt my business?
Yes. Visitors see the warning next to your address, especially on contact and payment forms, and many leave. Google uses HTTPS as a ranking signal, and payment providers require it. It's usually a cheap fix with an immediate effect.
Quick diagnosis
| What you see | Likely cause | Fix |
|---|---|---|
| "Not secure" on every page | No certificate, or no HTTPS redirect | Install SSL, redirect HTTP to HTTPS |
| "Your connection is not private" | Expired certificate or wrong domain | Renew; include www and non-www |
| Warning on some pages only | Mixed content (http:// images or scripts) | Change links to https:// |
| Worked yesterday, broken today | Auto-renewal failed or host changed | Renew and check auto-renew |
If you'd rather not touch the server, Website rescue fixes it for a fixed price, most within a week.
Questions about the "Not secure" warning
Usually not. Most hosts include free certificates from Let's Encrypt. Paid certificates add extra validation, which a small-business site rarely needs.
Not usually. The warning is about the connection, not malware. If you also see redirects to strange sites or Google warns about harmful content, that's different and needs a security check.
Installing a certificate and redirect often takes under an hour; mixed content on a large or old site can take longer.
Yes. Website rescue fixes "Not secure" warnings, broken pages and dead forms from $400, with a free diagnosis first.