Guide

WordPress says "Not secure" even with SSL

WordPress says "Not secure" with a working SSL certificate when it still uses http addresses somewhere: in its settings, in old pictures and links, or in code.

In short: https is like sealing your page in an envelope, and the padlock says it's sealed. If one picture or script still comes by plain http, it's a postcard taped to the outside, and the browser stops vouching for the whole envelope.

The SSL certificate (what gives you the padlock) lives on your web host. WordPress then has to use it everywhere: in its own two addresses, in every picture and link in your pages, and in your theme and plugins. Miss one and the browser warns visitors.

Work down the steps in order. Each one fixes a different version of the warning.

If you run your own WordPress

  1. Check the certificate works. Run Site health on your address. If it says the padlock is broken, the problem is on your web host, not in WordPress: send them the message below. If it works, carry on.
  2. Switch WordPress itself to https. In your WordPress dashboard, go to Tools, Site Health. If it says Your website does not use HTTPS and HTTPS is already supported for your website, click Update your site to use HTTPS. That changes both of WordPress's addresses, and from then on WordPress swaps old http links to your own site in your pages for https ones as it shows them.
  3. No button? If Site Health says your WordPress Address is controlled by a PHP constant, the addresses are set in a file called wp-config.php (as WP_HOME and WP_SITEURL). Ask your web person to change them to https. Otherwise you can do it by hand: Settings, General, change WordPress Address (URL) and Site Address (URL) to start with https, then Save Changes. Do this only once step 1 shows a working padlock: changing them before the certificate works can lock you out.
  4. Send http visitors to https. People with old bookmarks or links still arrive at the http address. Site health shows whether they're sent on to the padlock version; if not, ask your web host to redirect http to https.
  5. Fix the leftovers (mixed content). WordPress's swap in step 2 only covers links to your own site. Pictures, videos, fonts and scripts loaded from other sites over http still set off the warning, and so do addresses typed into theme or page builder settings, such as a logo or background picture. See the next section.
  6. Clear the caches. A caching plugin, your host's cache or a content delivery network can keep serving the old http version. Clear each one, then check in a private window.

Find what's still on http

If the address starts with https but the browser still says the page isn't fully secure, something on that page comes over plain http. Common places in WordPress:

  • pictures inserted years ago, before the switch, with their full http address,
  • a logo, header or background picture set in the theme's settings,
  • an embed (a form, map, video or booking widget) pasted in from another site,
  • a script or font added by an old plugin or a theme edit.

Two PageKiwi tools find them:

  • Link Check lists every picture, script, frame and stylesheet on a page that still loads over http, and marks each one Not secure. It works on any page anyone can visit.
  • PageKiwi for WordPress, our free plugin, checks from inside your dashboard. It flags Not secure when your site's address starts with http, lists the pages whose pictures load over http (open the page, click the picture, choose Replace and pick it again from the Media Library, then save), and finds links to your own site that still use http.

Change each address to https. If that version doesn't load, upload the file to your Media Library and use that instead. On a site with hundreds of pages, ask your web person to search the database for http:// and replace it carefully, with a backup first.

WordPress.com: "SSL certificate pending"

On WordPress.com (the hosted service), the certificate is made for you when you add a domain. It usually takes a few minutes and can take up to 24 hours, and the site may say "Not secure" until then.

  1. Go to Domains in your Hosting Dashboard, select your domain, and under Settings click Domain security.
  2. It says either SSL certificate active (working) or SSL certificate pending (still being made).
  3. Still pending after 24 hours? Click Provision certificate on the same page to ask for it again.
  4. Active, but still warned? An embed on the page has an http address. Change http:// to https://, or upload the file to WordPress.com, which always serves uploads over https.

Send this to your web host

Not sure what to say? Copy this into an email, add your website's address, and send it.

Hi,

Our WordPress site, [your website address], still shows "Not secure". Could you:

1. Check the SSL certificate is installed and covers both the www. and the plain address.
2. Redirect everyone who arrives on http:// to https://.
3. If WordPress's addresses are set in wp-config.php (WP_HOME and WP_SITEURL), change them to https://.
4. Clear any server cache or content delivery network cache once it's done.

If any pictures or scripts still load from http:// addresses, please tell me which, so I can fix them.

Thanks

Check it's fixed, and stays fixed

  • Site health shows the padlock working, when the certificate runs out and who issued it, and whether http visitors and the www address reach the secure site.
  • Site Watch checks every night and emails you when something changes, including a certificate within 14 days of running out.

Facts checked on Oct 8, 2026.

PageKiwi Tips

Plain-English website tips by email, coming soon. Unsubscribe in one click.

  • The two dates that take a website offline, and how to never miss them
  • A three-minute accessibility check anyone can do
  • How to spot a fake "your domain is expiring" email

We email you a link to confirm first. Never sold or shared. What we keep · Past tips

Know someone this would help? Share it

Quick question

Did this guide help with your problem?