SSL Certificate Errors Explained: "Not Secure" Warnings and How to Fix Them
Why browsers show "Not secure" or certificate warnings on your website (expired certificates, mixed content, wrong domain) and how to fix each one so visitors trust your site again.

On this page
- "Not secure" usually means no certificate or http pages; expired or mismatched certificates cause warnings.
- Mixed content (http files on https pages) removes the padlock.
- Use auto-renewing certificates, one preferred domain version and monitoring.
A "Not secure" label or a full-screen certificate warning scares visitors away instantly and damages trust. The good news: SSL problems are usually quick to fix once you know the cause.
"Not secure" in the address bar
Cause: the site loads over http instead of https, or has no certificate.
Fix: install a certificate (most hosts provide free, auto-renewing ones), then redirect all http traffic to https and update the WordPress site URL settings.
"Your connection is not private" / certificate expired
Cause: the certificate expired and didn't auto-renew.
Fix: renew or reissue it in your hosting panel. Check that auto-renewal is working. Renewals can fail when DNS points somewhere unexpected.
Certificate doesn't match the domain
Cause: the certificate covers example.com but not www.example.com (or vice versa), or a new domain was added without a certificate.
Fix: issue a certificate covering all versions of your domain and redirect everything to one preferred version.
Padlock missing or "partially secure" (mixed content)
Cause: the page loads over https, but some images, scripts or styles still load over http.
Fix: update old http links in content, theme settings and page builder sections to https. Tools and plugins can find and fix mixed content.
For a step-by-step clean-up, see how to fix mixed content warnings in WordPress.
Warnings after moving hosts or domains
Cause: the certificate wasn't issued on the new host before DNS switched, or DNS still points to the old server.
Fix: issue the certificate on the new host and check DNS records. Plan this step in any migration; see WordPress migration.
Google or browser "deceptive site" warnings
These aren't SSL problems. They usually mean malware or phishing was detected. See signs your WordPress site is hacked.
Prevent SSL problems
- Use hosting with automatic certificate renewal
- Monitor certificate expiry; see uptime monitoring
- Keep one preferred domain version with proper redirects
- Check for mixed content after redesigns
For the basics of how domains, hosting and SSL fit together, see domain, hosting and SSL explained.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


