'Not secure' warning or expired SSL certificate: the fix
A browser warning next to your name costs you visitors within minutes, and it is nearly always one of four things. Here is what each warning means, how to tell which one you have, and the fix, which is usually free and takes under an hour.
Few things empty a website faster than a browser warning. “Not secure” in the address bar, or a full-page “Your connection is not private”, and most visitors leave without reading it. The cause is nearly always one of four things, all of them fixable, most of them free.
What the warnings mean
“Not secure” next to the address. The page is being served over plain HTTP, with no certificate at all. Everything a visitor types, including form contents, crosses the network in the clear. Browsers have flagged this since 2018.
“Your connection is not private” with NET::ERR_CERT_DATE_INVALID. The certificate expired. It was fine until a date, and that date passed.
A name mismatch. The certificate is for one name and the visitor used another: www versus no www, or an old domain. The browser refuses to trust it.
Mixed content: a padlock with a warning, or no padlock. The page itself is secure but it loads an image, script or style over plain HTTP. One old image address in a template is enough.
How to tell which one you have
Click the warning or the padlock in the address bar and read what it says. Chrome and Firefox both name the problem. Or paste the address into our scanner: it reports whether the certificate is valid, when it expires, and whether the site forces HTTPS.
The fixes
No certificate at all. Get one. Every reasonable host issues free certificates through Let’s Encrypt from the control panel, and renews them automatically. Cloudflare provides one at the edge in minutes. If your host charges for a basic certificate in 2026, that is a reason to look at the host.
Expired. Renew it, and then find out why it did not renew itself. Usually the automatic renewal failed silently: a changed DNS record, a firewall blocking the renewal check, a card that expired at the certificate seller. Fix the renewal, not just the certificate, or you are back here in three months.
Name mismatch. The certificate needs to cover every name people use to reach the site, both www and bare domain at minimum. Reissue it with both names, or use a wildcard. Then set one of them as the canonical address and redirect the other to it.
Mixed content. Find the plain HTTP address in the page. Browser developer tools list it under the console. On WordPress it is usually an old image or a hardcoded script address in the theme or a widget; a search-and-replace of http://yourdomain with https://yourdomain across the database fixes most of it. Then force HTTPS at the server so nothing can load insecurely again.
After the fix
Three things people skip:
- Force HTTPS. A redirect from every HTTP address to its HTTPS version, at the server. Otherwise old links and typed addresses still land on the insecure version.
- Send the HSTS header, which tells browsers to use HTTPS for your site for the next year even if someone types http. Only once everything works over HTTPS.
- Update the site address in your platform’s settings and in Search Console, so internal links and sitemaps use HTTPS.
Why this keeps happening
Certificates expire, renewals fail, and nobody is watching. The fix is not a better certificate, it is a check that runs every day and tells someone two weeks before expiry. That is a standard part of looking after a site, and it is why we include certificate monitoring in every care plan. In the meantime the scanner shows the expiry date, which is worth checking once a month if nobody else is.
See where your own site stands.
The scanner checks the things this guide talks about, in about ten seconds, no signup.
More from the guides
Hacked WordPress: the cleanup order that holds
Most hacked sites get cleaned twice. The first time removes what you can see. Here is the full order we use so the second time is never needed: contain, find the door, clean, rotate, patch, watch.
Is my website hacked? Twelve signs, and a five-minute check
Most hacked sites look normal to their owners for weeks. The signs show up in Google, in your inbox and on other people's phones first. Here are the twelve we check, and a five-minute routine that catches most of them.
Deceptive site ahead: what it means and the fix order
Chrome is not warning about your design. Google Safe Browsing found phishing or malware on your domain. Here is what the red screen means, how to find the cause, and how to get the flag removed without it coming back.