SSL Warning / "Not Secure" Website

Browsers show a "Not Secure" label or a full-page certificate warning when people visit your site — and most visitors will turn back rather than click through.

Common signs of this issue

Safe checks you can do yourself

None of these require sharing passwords with anyone.

What this usually means

The padlock comes from an SSL/TLS certificate — a small file proving your site is really yours and encrypting traffic to it. "Not Secure" and certificate warnings mean that certificate is missing, expired, or issued for a different name than the one visitors are using. It says nothing about your site being hacked — but visitors can't tell the difference, which is exactly why it costs trust.

The most common single cause on small business sites is an expired certificate whose auto-renewal silently failed — often because the domain's DNS changed, the site moved hosts, or a renewal check couldn't reach the site. The second most common is a certificate that covers only one of www/non-www.

Since certificates are free on nearly every modern host and renew automatically once set up correctly, this is a problem you should only ever have to fix properly once. If it recurs every few months, the renewal setup is broken — fix the cause, not each expiry.

What not to do

When to get help

Installing a certificate, covering both www and non-www, forcing https everywhere, and confirming auto-renewal is a routine, well-bounded job — minutes to an hour for someone who does it weekly. If a scary full-page warning is showing to customers right now, treat it as a same-day fix: the cost of the warning compounds hourly, and the fix doesn't get cheaper by waiting.

Not sure what to do next?

Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.

Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.

Frequently asked questions

Is SSL the same as HTTPS?

Effectively yes — installing an SSL/TLS certificate is what lets your site load over https:// with a padlock instead of a "Not Secure" label. HTTPS is the secure connection; the certificate is what makes it possible.

Do I have to pay for SSL?

Usually no. Most hosts include free certificates (Let's Encrypt / AutoSSL) that renew automatically. Paid certificates still exist for special cases, but a typical small business site doesn't need one.

Why did my SSL suddenly stop working?

Most certificates last about 90 days and renew automatically — until a renewal silently fails, often after a DNS change or host move. The site then breaks on the expiry date even though nobody touched anything. Your host can usually see exactly why the renewal failed.

Does a 'Not Secure' warning mean my site was hacked?

No — it's a certificate problem, not an intrusion. But if the warning appeared alongside strange redirects or content changes, review the hacked-site guide too, since attackers sometimes break https as a side effect.

Why is my site secure without www but not with it (or vice versa)?

The certificate was issued for only one form of your address. It needs to cover both example.com and www.example.com — a standard option when the certificate is set up, and a quick reissue if it wasn't.

Will fixing SSL help my Google rankings?

It removes a penalty rather than adding a boost: https is a confirmed (light) ranking signal, and warned pages lose clicks and trust. Fixing it is table stakes, and it also stops browsers labeling your brand "Not Secure" in front of customers.

Related free guides

WordPress site down?

Seeing “There has been a critical error on this website”?

Our guided repair tool logs in over secure FTPS and fixes the most common WordPress failures — safely, with every change backed up and reversible. Start with a free scan, no password needed.

Fix My WordPress Site → Free scan · No download of your site · Reversible