WordPress SSL Not Working: 10 Fixes for 'Not Secure' Warning

You installed an SSL certificate. You paid for it. You confirmed it's installed. But your browser still shows a warning: "Your connection is not private" or displays "Not Secure" in the address bar instead of a padlock.

Worse: the padlock appears on some pages but not others. Or your contact form suddenly stopped working. Or payment processing fails.

Here are the 10 most common WordPress SSL problems and the exact fix for each one. Most take 5-10 minutes to resolve.


Before You Start: Verify Your Certificate

Is your SSL certificate actually installed? Click the padlock icon (or "Not Secure" warning) in your browser's address bar. A popup shows the certificate details. Check:

  • Is the domain name correct? (Should match your site's domain)
  • Is the certificate valid? (Not expired)
  • Does it show as "Trusted"?

Alternative: Use SSL Shopper's SSL Checker tool or Why No Padlock. Enter your domain and it shows exactly what's wrong.


Fix #1: WordPress URL Settings Are Wrong (Most Common)

The problem: You installed SSL, but WordPress is still trying to load pages over HTTP instead of HTTPS.

Why it happens: You forgot to update the WordPress URL settings after installing SSL.

The fix:

  1. Go to WordPress Admin > Settings > General.
  2. Look at two fields:
    • "WordPress Address (URL)" — should be https://yourdomain.com (not http://)
    • "Site Address (URL)" — should be https://yourdomain.com (not http://)
  3. If either is still http://, change it to https://
  4. Click Save Changes.
  5. Clear your browser cache (Ctrl+Shift+Delete) and refresh your site.

Important: Make sure both URLs match (either both with www or both without www). Mismatch causes certificate errors.

Expected result: Padlock appears and stays consistent across all pages.


Fix #2: Mixed Content Error (HTTP Resources on HTTPS Page)

The problem: Your site loads over HTTPS, but some images, stylesheets, scripts, or iframes still load over HTTP. Browser shows "Not Secure" warning.

Why it happens: Old content in your database has HTTP links. Or a plugin is loading assets over HTTP. Or images were uploaded before SSL was enabled.

How to find it:

  1. Open your site in Chrome.
  2. Right-click > Inspect > Console tab.
  3. Look for red or yellow warnings mentioning "Mixed Content" or HTTP.
  4. The warning will show exactly which resource is loading insecurely (e.g., "https://yourdomain.com blocked mixed content from http://cdn.example.com/image.jpg").

The fix (Easy Way): Install Really Simple SSL plugin (free).

  1. Install and activate Really Simple SSL from WordPress.org.
  2. The plugin auto-detects your SSL certificate and fixes most mixed content on the fly.
  3. It rewrites insecure URLs as pages load.
  4. Go to Really Simple SSL > Settings and enable "Capture full page (recommended)".
  5. Save and reload your site.
  6. Most mixed content errors disappear within minutes.

The fix (Manual Way): Replace old HTTP URLs in your database.

  1. Install and activate Better Search Replace plugin.
  2. Go to Tools > Better Search Replace.
  3. In "Search for:" enter http://yourdomain.com
  4. In "Replace with:" enter https://yourdomain.com
  5. Click "Replace" (make a backup first if nervous).
  6. Repeat for any CDN URLs or external domains if needed.

Note: Really Simple SSL is easier for most people. Use Better Search Replace if Really Simple SSL doesn't catch everything.


Fix #3: SSL Certificate Expired

The problem: Browser shows "Your connection is not private — the certificate has expired."

Why it happens: Your SSL certificate's expiration date has passed. Modern SSL certificates (as of 2026) expire faster than they used to — typically every 200 days instead of yearly.

The fix:

  1. Go to your hosting control panel (cPanel, Plesk, etc.).
  2. Find the SSL/HTTPS section.
  3. Click "Manage" or "Edit" next to your certificate.
  4. Click "Renew" (most hosts offer free renewal for Let's Encrypt).
  5. Wait 5-15 minutes for the renewal to process.
  6. Clear your browser cache and reload your site.
  7. Check the padlock — it should now show as valid.

If your host doesn't have auto-renewal:

  1. Set a calendar reminder 30 days before expiration to renew manually.
  2. Or use a plugin like Really Simple SSL which monitors expiration.
  3. Or contact your hosting provider and ask to enable auto-renewal for Let's Encrypt.

Important 2026 update: Certificate lifespans are shrinking. As of March 15, 2026, new certificates expire every 200 days (6 months). In 2027, they'll expire every 100 days. Set reminders or enable auto-renewal now to avoid gaps.


Fix #4: SSL Certificate Domain Mismatch

The problem: Browser shows "Your connection is not private — the certificate is for a different domain."

Why it happens: Your SSL certificate was issued for yourdomain.com, but your site loads as www.yourdomain.com (or vice versa). Or your certificate was issued for example.com but you installed it on test.example.com.

The fix:

Step 1: Check what domain your certificate covers

  1. Click the padlock icon (or warning) in your browser.
  2. Look at "Issued to" or "Common Name" — this is the domain your cert covers.
  3. Compare it to your site's URL in the address bar.

Step 2: Make your site URL match the certificate

If certificate is for yourdomain.com but site loads as www.yourdomain.com:

  1. Go to WordPress > Settings > General.
  2. Change both URLs to match your certificate exactly.
  3. If certificate is for yourdomain.com, use that (no www).
  4. If certificate is for www.yourdomain.com, use that (with www).
  5. Click Save Changes.

Step 3: Force redirect to matching URL

  1. Install Really Simple SSL or use manual .htaccess redirect.
  2. This forces all traffic to the URL that matches your certificate.

If your certificate is wrong domain: Contact your SSL provider or hosting support and request a certificate reissue for the correct domain.


Fix #5: Untrusted Certificate Authority (NET::ERR_CERT_AUTHORITY_INVALID)

The problem: Browser shows "Your connection is not private — NET::ERR_CERT_AUTHORITY_INVALID" or "The certificate authority is unknown."

Why it happens: Your SSL certificate was issued by a certificate authority (CA) your browser doesn't recognize. Or your certificate is self-signed (not from a trusted CA).

The fix:

  1. Uninstall your current SSL certificate.
  2. Install a free SSL certificate from Let's Encrypt instead. Let's Encrypt is trusted by all browsers.
  3. On most hosts, you can enable Let's Encrypt free SSL from your control panel (AutoSSL or similar).
  4. If your host doesn't offer it, ask them to install it.
  5. The new certificate will be trusted immediately.

Don't: Use self-signed certificates on live sites. Self-signed certs trigger warnings in every browser.


Fix #6: Incomplete SSL Certificate Chain

The problem: SSL checker tools say your certificate is invalid, but it looks fine in the browser. Or it works on some browsers but not others.

Why it happens: Your SSL certificate is installed, but the intermediate certificate (chain) is missing. Browsers can't verify the full chain of trust.

The fix:

  1. Go to your hosting control panel > SSL/HTTPS section.
  2. Look for "Certificate Chain" or "Intermediate Certificate."
  3. Make sure it's installed (not empty).
  4. If empty, click "Install" or "Add" and follow the prompts.
  5. Some hosts auto-install the chain. If yours doesn't, contact support.

Verify it worked: Use SSL Shopper to check. If it shows "Certificate chain is complete," you're fixed.


Fix #7: Too Many Redirects / Redirect Loop

The problem: Browser shows "ERR_TOO_MANY_REDIRECTS" or "Redirect loop detected."

Why it happens: You enabled HTTPS redirect, but WordPress is also forcing redirect, OR your site redirect is looping back on itself.

The fix:

Step 1: Check your WordPress settings

  1. Go to Settings > General.
  2. Make sure both "WordPress Address" and "Site Address" are HTTPS and exactly the same.
  3. Save.

Step 2: Disable redirect in Really Simple SSL

  1. If you have Really Simple SSL installed, go to Really Simple SSL > Settings.
  2. Turn off "Enable automatic redirect" temporarily.
  3. Reload your site.
  4. If it works, the plugin's redirect was the issue. You can turn it back on or rely on server-level redirect instead.

Step 3: Check your server redirect (Advanced)

  1. If using Apache, check your .htaccess file for conflicting redirects.
  2. Remove duplicate redirect lines.
  3. Or contact your hosting provider for help.

Fix #8: CDN or Reverse Proxy Misconfiguration

The problem: Your SSL works, but mixed content warnings appear. Or certificate errors on some pages.

Why it happens: You're using a CDN (Cloudflare, Bunny CDN, etc.) or reverse proxy, but it's not configured to pass HTTPS through correctly.

The fix:

For Cloudflare:

  1. Go to Cloudflare dashboard > SSL/TLS > Overview.
  2. Make sure "SSL/TLS encryption mode" is set to "Full" or "Full (strict)".
  3. Do NOT use "Flexible" mode (it downgrades to HTTP).
  4. Save.

For other CDNs:

  1. Check your CDN's settings for "SSL" or "HTTPS" mode.
  2. Set it to pass through HTTPS requests securely (not downgrade to HTTP).
  3. Make sure the CDN's own SSL certificate is valid.

If confused: Contact your CDN's support. They can verify settings in 5 minutes.


Fix #9: Browser Cache Issue (False Alarm)

The problem: Your browser shows "Not Secure" but other browsers show the padlock correctly.

Why it happens: Your browser cached the old HTTP version of your site.

The fix:

  1. Clear your browser cache (Ctrl+Shift+Delete on most browsers).
  2. Close all browser tabs and reopen your site.
  3. If using incognito/private mode, reload.
  4. The padlock should now appear.

This is always worth trying first. It's usually the issue if SSL works on other devices/browsers but not yours.


Fix #10: Forms/Payment Processing Stopped Working After SSL

The problem: Contact forms won't submit. WooCommerce checkout fails. reCAPTCHA won't load.

Why it happens: You enabled SSL and now endpoints (form handlers, payment processors) are failing because they expect HTTPS but your site is sending HTTP requests (or vice versa). Or mixed content is blocking JavaScript.

The fix:

Step 1: Fix mixed content (see Fix #2)

Install Really Simple SSL and set to "Capture full page." This fixes 80% of form/payment issues post-SSL.

Step 2: Force HTTPS sitewide

  1. Go to Settings > General and ensure both URLs are HTTPS.
  2. Install Really Simple SSL or use a plugin like Force HTTPS.
  3. This ensures all requests use HTTPS consistently.

Step 3: Disable plugins temporarily

  1. Deactivate all plugins except the form/payment plugin.
  2. Test the form.
  3. If it works, reactivate plugins one by one to find the culprit.

Step 4: Contact form/payment plugin support

If issue persists, contact the form or payment plugin's support. They can verify endpoints are HTTPS-compatible.


SSL Issue Diagnostic Flowchart

  1. Padlock shows but cert seems wrong? → Fix #1 (Check WordPress URL settings)
  2. "Not Secure" warning appears? → Fix #2 (Mixed content) or Fix #3 (Expired cert)
  3. "Not Secure" on some pages, padlock on others? → Fix #2 (Mixed content) or Fix #9 (Cache)
  4. "Certificate is for a different domain"? → Fix #4 (Domain mismatch)
  5. "Certificate authority is unknown"? → Fix #5 (Untrusted CA)
  6. SSL Checker shows incomplete chain? → Fix #6 (Incomplete chain)
  7. "Too many redirects" error? → Fix #7 (Redirect loop)
  8. Mixed content and using a CDN? → Fix #8 (CDN misconfiguration)
  9. Works on other browser/device? → Fix #9 (Browser cache)
  10. Forms/payments stopped working? → Fix #10 (Mixed content blocking JavaScript)

FAQ

Q: Does Really Simple SSL slow my site down?

A: Minimal impact. It rewrites URLs on the fly, which adds negligible overhead (less than 0.1 seconds). If you're concerned, use manual database replacement (Better Search Replace) instead.

Q: Why do some pages show the padlock and others don't?

A: Mixed content. Some pages have HTTP resources, others don't. Install Really Simple SSL to fix sitewide.

Q: Should I pay for an SSL certificate or use Let's Encrypt?

A: Use Let's Encrypt (free). It's trusted by all browsers. Premium certificates are only useful if you need special features (wildcard for subdomains, EV for green address bar). For most sites, Let's Encrypt is perfect.

Q: My certificate renewed, but browser still shows "Not Secure." Why?

A: Clear browser cache (Ctrl+Shift+Delete). If still showing, check for mixed content (Fix #2). SSL issues after renewal are usually cache or mixed content, not the cert itself.

Q: Do I need to do anything to maintain my SSL certificate?

A: If your host auto-renews (most do with Let's Encrypt), no. If manual renewal, set a calendar reminder 30 days before expiration.


The Real Talk

95% of WordPress SSL issues are either (1) wrong URL settings (Fix #1) or (2) mixed content (Fix #2). Start there. If you're still seeing warnings after 10 minutes, install Really Simple SSL and let it fix it automatically. Most people waste hours troubleshooting something that a 2-minute plugin fixes instantly.

SSL should be boring. Get it working, stop thinking about it, and move on to content that actually converts visitors.