Guide
WordPress says "Not secure" even with SSL
WordPress says "Not secure" with a working SSL certificate when it still uses http addresses somewhere: in its settings, in old pictures and links, or in code.
The SSL certificate (what gives you the padlock) lives on your web host. WordPress then has to use it everywhere: in its own two addresses, in every picture and link in your pages, and in your theme and plugins. Miss one and the browser warns visitors.
Work down the steps in order. Each one fixes a different version of the warning.
If you run your own WordPress
- Check the certificate works. Run Site health on your address. If it says the padlock is broken, the problem is on your web host, not in WordPress: send them the message below. If it works, carry on.
- Switch WordPress itself to https. In your WordPress dashboard, go to Tools, Site Health. If it says Your website does not use HTTPS and HTTPS is already supported for your website, click Update your site to use HTTPS. That changes both of WordPress's addresses, and from then on WordPress swaps old http links to your own site in your pages for https ones as it shows them.
- No button? If Site Health says your WordPress Address is controlled by a PHP constant, the addresses are set in a file called
wp-config.php(asWP_HOMEandWP_SITEURL). Ask your web person to change them to https. Otherwise you can do it by hand: Settings, General, change WordPress Address (URL) and Site Address (URL) to start with https, then Save Changes. Do this only once step 1 shows a working padlock: changing them before the certificate works can lock you out. - Send http visitors to https. People with old bookmarks or links still arrive at the http address. Site health shows whether they're sent on to the padlock version; if not, ask your web host to redirect http to https.
- Fix the leftovers (mixed content). WordPress's swap in step 2 only covers links to your own site. Pictures, videos, fonts and scripts loaded from other sites over http still set off the warning, and so do addresses typed into theme or page builder settings, such as a logo or background picture. See the next section.
- Clear the caches. A caching plugin, your host's cache or a content delivery network can keep serving the old http version. Clear each one, then check in a private window.
Find what's still on http
If the address starts with https but the browser still says the page isn't fully secure, something on that page comes over plain http. Common places in WordPress:
- pictures inserted years ago, before the switch, with their full http address,
- a logo, header or background picture set in the theme's settings,
- an embed (a form, map, video or booking widget) pasted in from another site,
- a script or font added by an old plugin or a theme edit.
Two PageKiwi tools find them:
- Link Check lists every picture, script, frame and stylesheet on a page that still loads over http, and marks each one Not secure. It works on any page anyone can visit.
- PageKiwi for WordPress, our free plugin, checks from inside your dashboard. It flags Not secure when your site's address starts with http, lists the pages whose pictures load over http (open the page, click the picture, choose Replace and pick it again from the Media Library, then save), and finds links to your own site that still use http.
Change each address to https. If that version doesn't load, upload the file to your Media Library and use that instead. On a site with hundreds of pages, ask your web person to search the database for http:// and replace it carefully, with a backup first.
WordPress.com: "SSL certificate pending"
On WordPress.com (the hosted service), the certificate is made for you when you add a domain. It usually takes a few minutes and can take up to 24 hours, and the site may say "Not secure" until then.
- Go to Domains in your Hosting Dashboard, select your domain, and under Settings click Domain security.
- It says either SSL certificate active (working) or SSL certificate pending (still being made).
- Still pending after 24 hours? Click Provision certificate on the same page to ask for it again.
- Active, but still warned? An embed on the page has an http address. Change
http://tohttps://, or upload the file to WordPress.com, which always serves uploads over https.
Send this to your web host
Not sure what to say? Copy this into an email, add your website's address, and send it.
Hi, Our WordPress site, [your website address], still shows "Not secure". Could you: 1. Check the SSL certificate is installed and covers both the www. and the plain address. 2. Redirect everyone who arrives on http:// to https://. 3. If WordPress's addresses are set in wp-config.php (WP_HOME and WP_SITEURL), change them to https://. 4. Clear any server cache or content delivery network cache once it's done. If any pictures or scripts still load from http:// addresses, please tell me which, so I can fix them. Thanks
Check it's fixed, and stays fixed
- Site health shows the padlock working, when the certificate runs out and who issued it, and whether http visitors and the www address reach the secure site.
- Site Watch checks every night and emails you when something changes, including a certificate within 14 days of running out.
Facts checked on Oct 8, 2026.