Security

SSL Certificate Errors Explained: "Not Secure" Warnings and How to Fix Them

Why browsers show "Not secure" or certificate warnings on your website (expired certificates, mixed content, wrong domain) and how to fix each one so visitors trust your site again.

SSL Certificate Errors Explained: "Not Secure" Warnings and How to Fix Them
On this page
  1. "Not secure" in the address bar
  2. "Your connection is not private" / certificate expired
  3. Certificate doesn't match the domain
  4. Padlock missing or "partially secure" (mixed content)
  5. Warnings after moving hosts or domains
  6. Google or browser "deceptive site" warnings
  7. Prevent SSL problems
Key takeaways
  • "Not secure" usually means no certificate or http pages; expired or mismatched certificates cause warnings.
  • Mixed content (http files on https pages) removes the padlock.
  • Use auto-renewing certificates, one preferred domain version and monitoring.

A "Not secure" label or a full-screen certificate warning scares visitors away instantly and damages trust. The good news: SSL problems are usually quick to fix once you know the cause.

"Not secure" in the address bar

Cause: the site loads over http instead of https, or has no certificate.
Fix: install a certificate (most hosts provide free, auto-renewing ones), then redirect all http traffic to https and update the WordPress site URL settings.

"Your connection is not private" / certificate expired

Cause: the certificate expired and didn't auto-renew.
Fix: renew or reissue it in your hosting panel. Check that auto-renewal is working. Renewals can fail when DNS points somewhere unexpected.

Certificate doesn't match the domain

Cause: the certificate covers example.com but not www.example.com (or vice versa), or a new domain was added without a certificate.
Fix: issue a certificate covering all versions of your domain and redirect everything to one preferred version.

Padlock missing or "partially secure" (mixed content)

Cause: the page loads over https, but some images, scripts or styles still load over http.
Fix: update old http links in content, theme settings and page builder sections to https. Tools and plugins can find and fix mixed content.

For a step-by-step clean-up, see how to fix mixed content warnings in WordPress.

Warnings after moving hosts or domains

Cause: the certificate wasn't issued on the new host before DNS switched, or DNS still points to the old server.
Fix: issue the certificate on the new host and check DNS records. Plan this step in any migration; see WordPress migration.

Google or browser "deceptive site" warnings

These aren't SSL problems. They usually mean malware or phishing was detected. See signs your WordPress site is hacked.

Prevent SSL problems

  • Use hosting with automatic certificate renewal
  • Monitor certificate expiry; see uptime monitoring
  • Keep one preferred domain version with proper redirects
  • Check for mixed content after redesigns

For the basics of how domains, hosting and SSL fit together, see domain, hosting and SSL explained.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now