"Not Secure" next to your website address: what it means and how to fix it
Chrome shows Not Secure when your page loads over plain http:// instead of https://, or when a secure page pulls in something over plain http. Visitors see it before they see your site. Many leave.
What to do, in order
- Get a certificate. Most hosts give one free through Let's Encrypt. In cPanel look for SSL/TLS Status or AutoSSL. On Wix, Squarespace and Shopify it is automatic once the domain is connected correctly.
- Send everyone to https. Having a certificate is not enough if the http address still works. Turn on "Force HTTPS" in your host or add a redirect rule. On WordPress also set both addresses in Settings, General to start with
https://.
- Fix mixed content. If the padlock is missing on an https page, an image, script or font is still loading over http. Open the page, press F12, and read the Console. Each warning names the file. Change its address to https.
- On WordPress, replace old addresses in the database. A search-and-replace plugin can change
http://yourdomain.com to https://yourdomain.com everywhere. Take a backup first.
Check it yourself
Run curl -sI http://yourdomain.com. You want a 301 and a location: line starting with https://. A 200 means the insecure address still serves the page.
Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.