What "Not secure" means
Your site isn't using a padlock (https), or the padlock is broken. Visitors see a warning, and anything they type can be read on the way. The fix is usually free and takes your web host minutes.
Check yours now with Site health.
Why it matters
- Visitors leave
Browsers say "Not secure" right by your address, and some show a full-page warning first. Many people stop there.
- Forms aren't private
Names, emails and anything typed into a form travel as plain text that someone on the same Wi-Fi could read.
- Google prefers the padlock
Secure sites have had a small head start in Google's results since 2014.
How to fix it
- Ask your web host to switch on a free security certificate (usually called SSL or Let's Encrypt; on cPanel hosting it's AutoSSL). Most hosts do it automatically.
- Ask them to send everyone who types
http://tohttps://(a "redirect"). - Run Link Check: anything it marks Not secure (a picture or link still on http) keeps the warning on that page. Change those addresses to https.
- Check again with Site health in a few minutes.
If it was fine and now it isn't
The certificate has probably run out. Most now last 90 to 200 days (200 days at most since March 2026) and usually renew themselves, but renewals can fail quietly. Site health shows the date; ask your host to renew it.