WhatsApp Us

SSL, HTTPS and mixed-content fixes · India

Website showing not secure? What the warning means and how to remove it for good

If your website is showing “Not secure” in the address bar, the browser is telling visitors that the connection is not encrypted, or that part of the page still loads over plain HTTP. The fix is usually one of four things: install a certificate, renew an expired one, force every URL onto HTTPS with 301 redirects, or clean up mixed content. BtechWaleTech is three freelance developers who diagnose the exact cause, fix it on your hosting, and set up renewal checks so the padlock stays. See our website security work too.

  • Typical causesNo SSL, expired SSL, mixed content, missing redirect
  • Free certificate optionLet's Encrypt, 90-day certificates
  • DiagnosisFrom one WhatsApp message with your URL
  • Upkeep after the fixFrom ₹8,000/mo
  • New site insteadStatic site from ₹10,000
  • AccessYour hosting, your domain, your certificate
  • SSL install and renewal
  • Mixed content cleanup
  • HTTP to HTTPS 301s
  • WordPress and Shopify
  • Search Console checks
  • Renewal monitoring
  • You keep all logins

Three freelance developers in India · replies on WhatsApp, 7 days a week

  • 4Root causes behind almost every Not secure label
  • 2Working days for an itemised quote
  • 2Months of free maintenance on sites we build
  • 7Days a week we answer on WhatsApp

The short answer

Why is my website showing not secure, and how do I fix it?

A website showing “Not secure” either has no valid SSL certificate, has one that expired or does not match the domain, is still reachable over HTTP without a redirect, or loads images and scripts over HTTP. Fix the certificate first, then add 301 redirects to HTTPS, then replace every http:// resource. Ongoing upkeep with BtechWaleTech starts at ₹8,000/mo.

If the warning appeared right after a hack or a hosting move, start with hacked website repair or read about traffic drops after a migration.

Last updated

Not secure warning: the short version
What visitors see“Not secure” beside the URL, or a full-page privacy error
Most common causeCertificate missing, expired or issued for the wrong hostname
Second most commonHTTPS page pulling http:// images, fonts or scripts
Free certificateLet's Encrypt, usually through your hosting panel
SEO stepPermanent 301 redirects, HTTPS canonicals, new sitemap
Ongoing careFrom ₹8,000/mo, renewal checks included
PaymentUPI or bank transfer in India; Wise, wire or PayPal abroad

Why choose us

Three ways people try to clear the Not secure warning

Hosting support, a one-click plugin and a developer each fix part of the problem. The difference is how much of the site they actually look at.

Three ways people try to clear the Not secure warning
What matters Hosting support ticket One-click SSL plugin BtechWaleTech
Installs the certificate Usually yes, on their own servers No; it relies on one already existing Yes, on any host you use
Finds mixed content in the database Rarely Rewrites output on the fly, often partly Searches and replaces it at the source
Sets proper 301 redirects Sometimes, if asked Often a PHP redirect, not a server rule Server-level rule, single hop
Fixes www vs non-www mismatch If you describe it clearly No Checked for every hostname
Updates canonicals and sitemap No Partly Yes, plus Search Console
Works on non-WordPress sites Depends on the host No, WordPress only Static, custom, Shopify, WordPress
Checks renewal afterwards Automatic renewal, no alerts to you No Expiry alerts in maintenance plans
Explains the cause to you Short ticket reply No Written note on WhatsApp
Cost Included in hosting Free or paid plugin licence Quoted after diagnosis; upkeep from ₹8,000/mo

If your host is responsive and your site is small and clean, a support ticket may be all you need; call a developer when the warning survives the certificate install.

Pricing

What it costs when a website is showing not secure

Most padlock problems are small jobs, and we quote them after looking at the site, not before. A certificate that simply expired on a clean static site takes minutes. A WordPress site with years of http:// links stored in page-builder data, a proxy causing redirect loops and a missing www record takes longer, so it costs more. The table below shows our starting prices for ongoing maintenance and for rebuilding a site when the old one is beyond sensible repair. You get the diagnosis and an itemised quote in about two working days, and nothing is billed until you approve it in writing.

Starting prices in INR and USD
ServiceIndia (INR)Worldwide (USD)Typical timelineWhat is included
Static website from ₹10,000 from US$150 1 to 2 weeks Up to 100 pages, Responsive design, Contact form and enquiry setup, Basic SEO tags and sitemap
SEO website (299+ pages) from ₹20,000 from US$300 3 to 5 weeks 299+ SEO pages, Keyword and page planning, Schema, sitemap, and internal linking, Design to deployment included
Ecommerce store from ₹50,000 from US$750 4 to 8 weeks Product and category pages, Payment gateway setup, Order and inventory basics, Performance tuning
Android & iOS app from ₹40,000 from US$600 6 to 10 weeks Android and iOS app (Flutter or React Native), Login, forms and push notifications, Admin panel and API connection, Google Play and App Store publishing
Custom web app or software from ₹60,000 from US$900 6 to 12 weeks Custom features and APIs, User accounts and roles, Admin panel, Deployment and handover
AI automation from ₹40,000 from US$600 2 to 4 weeks Workflow mapping, Tool and CRM integrations, AI agent or automation build, Testing and handover
Monthly SEO from ₹10,000/mo from US$150/mo Ongoing, monthly Technical fixes, On-page and content work, Local SEO and listings, Search Console reporting
Maintenance and support from ₹8,000/mo from US$120/mo Ongoing, monthly Content updates, Bug fixes, Backups and security checks, Speed and uptime checks

All prices are starting points, quoted in INR for India and USD for international clients, not fixed quotes. Final cost depends on the number of pages, features, integrations, content, and timelines. Share your requirement and you get an itemised estimate with nothing hidden. See full pricing.

What does it mean when a website is showing Not secure?

It means the browser cannot confirm that the page travelled to the visitor over an encrypted HTTPS connection. Google's own Chrome help page describes the label plainly: the site does not use a private connection, so someone may be able to view or change what the visitor sends and receives.

That wording matters, because it tells you the warning is about the connection, not about malware. Chrome uses a separate, red “Dangerous” warning when Google Safe Browsing has flagged a site as harmful. A website showing not secure is usually a configuration problem, while a Dangerous page is a security incident. If you see the red one, skip ahead to cleaning a hacked website, because a certificate will not help.

There are three versions of the problem you might be looking at. The grey “Not secure” text beside the URL appears when the page loads over plain HTTP, or when parts of it do. A full-screen “Your connection is not private” page appears when a certificate exists but is expired, self-signed or issued for a different name. And a padlock with a small warning, or a broken padlock in some browsers, points to mixed content on an otherwise secure page.

Each version has a different fix, which is why pasting random advice from forums often makes things worse. Identify which one you have before touching anything.

Why is my website showing not secure all of a sudden?

A site that had a padlock last month and lost it this week almost always has an expired or failed certificate renewal. Free certificates are short-lived by design, so renewal runs automatically, and when that automation breaks nobody notices until visitors complain.

Renewal fails for ordinary reasons. The domain's DNS was moved to a new provider and the host can no longer prove control. Someone added a Cloudflare proxy or changed nameservers. The hosting plan was downgraded and AutoSSL was switched off. A developer who set things up used their own email for alerts and has since moved on.

The other sudden cause is a change on the site itself. A new plugin, a slider, a chat widget or an embedded form begins loading a script from an http:// address, and the browser downgrades the page. Theme updates occasionally do the same when an old image path is hard-coded in a template.

  • Certificate expired and auto-renewal failed silently
  • DNS or nameserver change broke domain validation
  • Hosting plan or server changed and SSL was not reissued
  • New widget, plugin or embed pulling an http:// file
  • www or a subdomain added without its own certificate

If your emails started bouncing at the same time, the DNS change is the likely link; our page on emails going to spam covers the record checks.

How to check why your website is showing not secure, in five minutes

You can find the cause yourself with nothing more than Chrome on a laptop. These steps tell you which of the four problems you have, so you can describe it accurately to your host or to us.

  • Click the icon left of the address. If it says the connection is not secure, the page itself is on HTTP or the certificate is bad.
  • Type the address with https:// in front. If it loads with a padlock, the certificate works and you only need redirects.
  • If HTTPS shows a privacy error, click “Advanced” and read the reason: expired, wrong name (NET::ERR_CERT_COMMON_NAME_INVALID) or untrusted issuer.
  • Open DevTools (F12), go to the Console tab and reload. Mixed content lines name the exact http:// file that is causing trouble.
  • Try both www and non-www versions. A certificate that covers only one of them is extremely common.
  • Note the expiry date shown in the certificate viewer, and who issued it.

Send us the answers to those six checks on WhatsApp and we can usually tell you the fix in the first reply. When the checks point to server or DNS work you cannot reach yourself, that is the point to bring in a developer for the bug.

No SSL certificate installed: the simplest cause to fix

If the site has never had a certificate, every page is served over HTTP and Chrome labels all of it Not secure. The fix is to issue a certificate for every hostname you use and then redirect HTTP to HTTPS.

On most Indian shared hosting with cPanel, the tool is called SSL/TLS Status or AutoSSL. It issues a free certificate for the domain and its www version, often within minutes, provided the domain's DNS points at that server. Plesk has a similar Let's Encrypt extension. On a cloud server you install a client such as Certbot, or put the site behind a load balancer or CDN that issues certificates for you.

Old sites built years ago are the usual suspects here. They were launched when HTTPS felt optional, the developer never came back, and the owner assumed hosting “includes security”. Hosting often does include a free certificate; someone still has to switch it on and point the site at it.

Once the certificate exists, do not stop. Without redirects, visitors who type your name or click an old link still land on the HTTP version, see the warning and leave. The next sections handle that.

Expired or mismatched certificates: why a padlock can still fail

A certificate is valid only for the names written into it and only until its end date. If either condition fails, the browser shows a full-page error rather than the small Not secure label, and most visitors turn back.

Name mismatches catch people out constantly. The certificate covers example.in but the site is linked everywhere as www.example.in. A shop subdomain was added later. The hosting company's shared certificate appears because the domain is not yet attached properly. Each of these needs a certificate that lists every hostname, or a wildcard for subdomains, plus a decision about which single version is the real address.

Expiry is the other half. Let's Encrypt's FAQ says its default certificates last 90 days and recommends renewing every 60, so automation is not optional. Paid certificates last longer today, but the CA/Browser Forum ballot SC-081 set a schedule that reduces the maximum validity of public TLS certificates from 398 days to 47 days, in stages between March 2026 and March 2029. In practice, manual renewal once a year is ending for everyone.

Symptom: ERR_CERT_DATE_INVALID

The certificate has expired or the visitor's device clock is wrong. Check the end date first.

Symptom: ERR_CERT_COMMON_NAME_INVALID

The certificate belongs to another hostname. Reissue it to cover the name visitors actually use.

Symptom: ERR_CERT_AUTHORITY_INVALID

Self-signed or missing intermediate certificate. Install the full chain from your issuer.

Mixed content: the reason a site with SSL still shows not secure

Mixed content happens when a page loaded over HTTPS asks for an image, script, font or frame over HTTP. MDN's documentation on the topic explains how modern browsers react: images, audio and video are automatically upgraded to HTTPS, while scripts, stylesheets, iframes, fonts and fetch requests are blocked outright.

So mixed content shows up two ways. Sometimes you see a degraded padlock. More often, something quietly breaks: a slider stops moving, a font falls back to Times New Roman, an enquiry form's script never loads. Owners report “the site looks strange on HTTPS” without realising it is the same problem.

Where do the http:// links live? On WordPress, mostly in the database: post content, widget settings, page-builder JSON and theme options saved when the site was on HTTP. On static and custom sites, in templates and CSS files. Third-party embeds from old map, video or chat providers are a third source.

The durable fix is to change the links at their source with a proper search-and-replace that understands serialised data, then fix templates and CSS by hand. A Content-Security-Policy header with the upgrade-insecure-requests directive, which MDN also describes, is a useful safety net for anything you miss, but it is not a substitute for cleaning the site.

How do I redirect HTTP to HTTPS without losing Google rankings?

Use a permanent server-side redirect from every HTTP URL to the matching HTTPS URL, in a single hop, and keep it in place. Google Search Central's site-move documentation recommends permanent redirects such as 301 or 308 and says they should be kept for as long as possible, generally at least a year.

“Matching” is the part people skip. Redirecting every old page to the home page throws away the links and rankings those inner pages earned. The rule should carry the path across, so http://example.in/services/ becomes https://example.in/services/ exactly.

Decide your one canonical form first: HTTPS, with or without www. Then make sure the other three combinations (http with www, http without, and the HTTPS version you did not choose) each land on the canonical in one step. Chains of two or three redirects slow the first visit and waste crawl budget on large sites.

After the switch, update internal links, canonical tags and the XML sitemap to HTTPS, and add or check the HTTPS property in Google Search Console. The same documentation notes that for a move to HTTPS you do not need the Change of Address tool, which is meant for domain changes; you just keep both versions verified and let Google recrawl. If you are also changing the domain, that is a larger job covered on changing a domain without losing SEO.

Free vs paid SSL certificate: which one fixes the warning?

For removing the Not secure label, a free certificate works exactly as well as a paid one. Browsers show the same padlock for any valid, trusted certificate; the encryption strength is the same.

Let's Encrypt, a nonprofit, issues free domain-validated certificates and states in its FAQ that it has no plans to issue organisation-validated (OV) or extended-validation (EV) certificates, because those checks cannot be automated. Most hosting panels in India use Let's Encrypt or a similar free issuer under the hood.

Paid certificates still have uses. Some procurement or banking partners ask for an OV certificate showing your company details. A few legacy systems need a certificate type that free issuers do not supply. Some owners prefer a vendor with phone support. None of these change what the address bar shows to an ordinary visitor.

Choose free (DV) when

You run a business site, blog, clinic, school or online store and just need the padlock and encryption. Automate renewal and forget it.

Choose paid OV when

A partner, tender or payment arrangement asks for organisation validation in writing, or your IT policy requires a specific issuer.

Avoid

Buying a paid certificate as a “fix” for mixed content or missing redirects. It will not remove the warning if those problems remain.

Fixing a website showing not secure on WordPress, Shopify and custom builds

The logic is the same everywhere, but the switches live in different places. Here is where to look on the platforms we meet most often.

WordPress

Set both WordPress Address and Site Address to https:// under Settings, General. Run a serialisation-safe search-and-replace for the old http:// domain. Clear every cache layer: plugin, server and CDN. If the site sits behind a proxy and loops, the server needs to trust the forwarded HTTPS header.

Shopify

Shopify issues certificates for connected domains itself. When one will not issue, the usual reason is a DNS record pointing somewhere else. Theme code or an old app snippet calling http:// assets can still cause mixed content.

Wix, Squarespace and other builders

HTTPS is managed by the platform. Problems nearly always trace back to domain connection records or custom code embeds.

Static and custom sites

Install the certificate on the server or CDN, write the redirect in the web server config (Nginx, Apache or the host's rules file), and grep the codebase for http:// references.

WordPress owners dealing with more than the padlock, such as updates and backups, can compare our WordPress maintenance plans. If the same site throws a white screen instead, see the WordPress critical error fix guide.

Does a website showing not secure hurt SEO?

Honestly, the direct ranking effect is small, but the indirect damage is real. Google's page experience documentation lists “Are your pages served in a secure fashion?” among its self-assessment questions and links a Search Console HTTPS report, while also saying that page experience aspects beyond Core Web Vitals do not directly lift rankings on their own.

The indirect costs are where it hurts. Visitors who see a warning bounce back to the results page. Links shared on WhatsApp open to an unsettling label. Duplicate HTTP and HTTPS versions split signals when redirects are missing, and Google may pick the wrong one as canonical. Broken scripts from blocked mixed content can stop forms, tracking and structured data from working.

AI assistants and AI Overviews also draw on pages that search engines consider trustworthy and crawlable. A clean HTTPS setup with one canonical version is simply part of being a page worth citing. No one can guarantee rankings, so treat HTTPS as removing a handicap rather than as a growth trick.

  • Check the HTTPS report and the Pages report in Search Console after the fix
  • Confirm Google has picked the HTTPS URL as canonical with URL Inspection
  • Resubmit the HTTPS sitemap
  • Watch clicks for a few weeks; small wobbles during recrawl are normal

If rankings fell for reasons beyond the certificate, our traffic drop recovery page explains a fuller audit.

What the Not secure label does to enquiries, forms and payments

The warning shows up exactly where it costs most: on contact forms, login boxes and checkout pages. A visitor about to type a phone number sees the word “Not secure” next to your brand and hesitates.

For a clinic, coaching institute or local service business in India, most enquiries arrive on a phone, often through a link someone forwarded on WhatsApp. That visitor has no loyalty yet. A browser warning is enough to make them tap the next result instead.

Online stores have a harder rule. Payment providers and card networks expect checkout on HTTPS, and modern browsers restrict features like location access, service workers and some payment interfaces to secure contexts. A store with mixed content may find that its checkout script is blocked entirely, which looks to the owner like “payments stopped working”.

We cannot give you a percentage of lost leads, because nobody honestly can for your site. What you can do is check your own analytics: compare form submissions or WhatsApp clicks for a month before and after the padlock returns.

Website showing not secure in India: hosting panels, old developers and domain access

In India the technical fix is usually easy; access is the hard part. We often start a job by working out who holds the domain, the hosting login and the DNS, because the original developer registered them under their own email.

Low-cost shared hosting plans commonly include a free certificate, but some older plans need it enabled in the panel, and some resellers charge for it. Before buying anything, check the SSL/TLS or AutoSSL section of your panel. If you cannot log in, ask the provider to reset access to the email on the account, or have the domain transferred to your name first.

Two other local patterns come up often. Sites moved behind a free CDN proxy with “flexible” SSL can enter redirect loops, because the CDN talks to the server over HTTP while WordPress insists on HTTPS. And government or tender portals sometimes reject links that trigger certificate errors, which can block a vendor application at the last minute.

  • Domain registered in the business owner's name and email
  • Hosting login and DNS access in your hands, not only the developer's
  • Renewal alerts going to an inbox someone reads
  • GST invoice from the host kept, so plan details are traceable

If access is completely lost, our developer left the project midway page explains how to recover accounts safely.

Should you fix a website showing not secure yourself or hire someone?

Do it yourself when the diagnosis shows a single, simple cause and you have panel access. Hire help when the warning survives the certificate, when you see redirect loops, or when the site is an online store taking payments.

A good test is whether the five-minute check above gave you one clear answer. “No certificate on a static site” is a DIY job: enable AutoSSL, add a redirect, done. “Certificate present, padlock still broken, forms not sending, loops on some pages” means several problems at once, and trial-and-error on a live store costs sales.

When you do hire, ask for three things in writing: what the cause was, what exactly was changed, and how renewal will be monitored. Anyone who fixes it without explaining leaves you unable to fix it next time.

DIY is fine

Brochure site, one hostname, panel access, no payments, no custom code.

Get a developer

WordPress with a page builder, a proxy or CDN, several subdomains, a checkout, or no idea who controls the DNS.

For regular care rather than a one-off rescue, see hiring a website maintenance freelancer.

How much does it cost to fix a website showing not secure?

The certificate itself can cost nothing. What you pay for is the time to diagnose, clean mixed content, set redirects and verify everything, and that depends on how messy the site is.

Our approach is to look first and quote second, because an honest quote for “SSL fix” is impossible without seeing the site. A small static site with an expired certificate is at the cheap end. A large WordPress site full of page-builder data, several subdomains and a CDN in front sits at the other end. Very old sites on unsupported PHP sometimes make a rebuild the more sensible spend.

For ongoing care, our maintenance starts at ₹8,000/mo (US$120/mo for clients abroad), which covers certificate watch alongside updates and backups; website charges are explained in depth on website maintenance charges. If rebuilding wins, a static site starts at ₹10,000 and an online store at ₹50,000, each with two months of free maintenance after launch.

  • Number of hostnames and subdomains involved
  • Where http:// links are stored: database, templates or third-party embeds
  • Whether a CDN or proxy sits in front of the server
  • Access: ready logins versus account recovery first
  • Platform: static, WordPress, Shopify or custom code

How to keep the padlock: a renewal and HTTPS checklist

Most repeat warnings come from renewal automation breaking silently. Prevention is mostly about making sure a human hears about problems before visitors do.

  • Auto-renewal enabled and tested once by forcing a renewal
  • Expiry alert emails going to a shared business inbox
  • An external monitor that checks the certificate date weekly
  • Every hostname listed on the certificate, including www
  • Single-hop 301 rules for all http and non-canonical variants
  • No http:// references left in the database or templates
  • Content-Security-Policy upgrade-insecure-requests as a backstop
  • HSTS header added only after everything above is stable
  • New plugins, embeds and widgets checked in the Console before going live

A note on HSTS: it tells browsers to use HTTPS only for your domain for a set period. It is valuable, but if you enable it and later break the certificate, visitors cannot click past the error at all. Turn it on last. Monitoring is something we set up under website uptime monitoring.

Worked example: a coaching institute site showing Not secure

Here is a hypothetical case to show how the steps fit together. Say a coaching institute in Lucknow runs a WordPress site built five years ago. Parents start messaging that the admission form page says “Not secure”, and the institute's own staff notice the home page slider has stopped.

The five-minute check shows a valid certificate on the non-www domain, but every brochure link and ad points to www, which has no certificate. On the HTTPS version, the Console lists a dozen blocked http:// scripts from the slider plugin's saved settings and a form embed from an old provider.

The fix runs in order. Reissue the certificate for both hostnames. Choose the www version as canonical because printed material already uses it. Write one server rule sending all variants there. Run a database search-and-replace for the old http address, update the slider settings and replace the form embed with the site's own form. Clear caches, then check the Console again on a phone over mobile data.

Afterwards, update the sitemap, verify the property in Search Console and switch on renewal alerts to the institute's shared email. The next admission season starts with a padlock, and the institute knows exactly what was changed and why.

HTTPS and Not secure fixes for websites across India

We work remotely, so a website showing not secure in any state is fixed the same way: you share access, we diagnose, quote and fix while you watch the changes on WhatsApp. Local context still shapes the job.

Hotels and homestays in Udaipur and Dehradun take booking enquiries from travellers who notice warnings instantly. Traders in Surat and Ludhiana send catalogue links over WhatsApp to buyers who have never met them. Clinics and schools in Indore, Bhopal and Raipur collect phone numbers through forms. Tourism and export businesses in Kochi and Guwahati serve overseas visitors whose browsers are strict about certificates.

If the site is old enough that the certificate is only one of many problems, you may be better served by a planned rebuild; our redesign cost guide helps you weigh that up before paying for repairs.

Diagnosis

Match what you see to the likely cause and fix

Read the browser message carefully; each one points to a different repair.

Match what you see to the likely cause and fix
What the browser showsLikely causeFixWho can do it
Grey “Not secure” on every page No certificate, or site served on HTTPIssue certificate, add 301 to HTTPSOwner with panel access
Padlock on https://, warning on http:// Redirect missingServer-level single-hop 301Owner or developer
NET::ERR_CERT_DATE_INVALID Certificate expired, renewal failedRenew, then repair the automationHost or developer
NET::ERR_CERT_COMMON_NAME_INVALID Certificate issued for another hostnameReissue covering www and subdomainsDeveloper
Padlock with warning, broken scripts Mixed content from http:// filesSearch-and-replace at source, fix templatesDeveloper
“Too many redirects” after enabling SSL Proxy or CDN in flexible mode, conflicting rulesFull SSL on origin, one redirect ruleDeveloper
Red “Dangerous” page Safe Browsing flag, likely malwareClean the site, request reviewDeveloper; see hacked site repair

Certificates

Free vs paid SSL certificates compared

Validity figures reflect Let's Encrypt's FAQ and the CA/Browser Forum schedule that shortens maximum lifetimes to 47 days by March 2029.

Free vs paid SSL certificates compared
PointFree DV (e.g. Let's Encrypt)Paid DVPaid OV / EV
Removes Not secure label YesYesYes
Encryption strength SameSameSame
Validity 90 days, renewed automaticallyLonger today, shrinking by 2029Longer today, shrinking by 2029
Company identity checked No, domain control onlyNo, domain control onlyYes
Renewal effort Automated by host or clientManual or automatedManual paperwork plus install
When it makes sense Nearly every small business siteHost does not support free issuancePartner or tender requires it

Costs

Repair, maintain or rebuild: starting points

All figures are starting prices. One-off SSL repairs are quoted after diagnosis; see full pricing.

Repair, maintain or rebuild: starting points
SituationWhat we doStarting priceTypical time
Expired certificate on a clean site Renew, fix automation, verifyQuoted after a lookSame day once access is ready
SSL present, mixed content and loops Database cleanup, redirect rules, cachesQuoted after diagnosisA few working days
Ongoing padlock and update watch Renewal alerts, backups, updates, small fixesFrom ₹8,000/moMonthly
Old site not worth repairing Rebuild as a fast static site on HTTPSFrom ₹10,0001–2 weeks
Store rebuilt with secure checkout New ecommerce site, UPI and card checkoutFrom ₹50,0004–8 weeks
Search visibility after the switch Monthly technical SEO and reportingFrom ₹10,000/moOngoing

Across India

Businesses we help when their website is showing not secure

All of this is remote work. The notes explain why the warning matters for common businesses in each city.

How it works

How we clear a Not secure warning

  1. Send the URL

    Message your website address on WhatsApp, plus a screenshot of the warning if you have one. We run the checks from our side and tell you the likely cause in plain words.

  2. Confirm access

    We work out who controls the domain, DNS and hosting. If a former developer holds them, we guide you through recovering the accounts in your own name first.

  3. Itemised quote

    Within about two working days you get a written list of fixes and a price for each. Nothing is billed until you approve it in writing.

  4. Fix in the right order

    Certificate first, then redirects, then mixed content, then canonicals and sitemap. Each change is noted so you can see exactly what moved.

  5. Test on real devices

    We open the site on phones over mobile data and in several browsers, check the Console for blocked files and confirm forms and checkout work.

  6. Watch renewal

    Expiry alerts go to your inbox, and on a maintenance plan we check the certificate every month so the warning does not quietly return.

Questions

Website showing not secure: common questions

Why is my website showing not secure in Chrome?

Chrome shows Not secure when a page loads over plain HTTP, when the SSL certificate is missing, expired or issued for a different hostname, or when a secure page pulls images, scripts or fonts over HTTP. Click the icon beside the address to see which it is. Each cause needs a different fix, so diagnose before changing settings.

How do I remove the Not secure warning from my website?

Install a valid SSL certificate that covers every hostname you use, including www. Then add a permanent 301 redirect from every HTTP URL to its HTTPS version. Finally, replace any http:// links for images, scripts and fonts inside the site. Clear caches and check the browser console to confirm nothing is still loading insecurely.

My website has SSL but still shows not secure. Why?

The usual reason is mixed content: the page loads over HTTPS but requests some files over HTTP, often from old database content, theme settings or third-party embeds. The other common reason is that the certificate covers only one hostname, such as the domain without www, while visitors use the other version. The browser console names the offending files.

How much does it cost to fix a website showing not secure?

The certificate can be free through Let's Encrypt. The work is in diagnosis, redirects and cleaning mixed content, so BtechWaleTech quotes after looking at the site, with an itemised list in about two working days. Ongoing maintenance that includes certificate monitoring starts at ₹8,000/mo, and nothing is billed before you approve the quote in writing.

Is a free SSL certificate good enough?

Yes, for removing the warning and encrypting traffic. A free domain-validated certificate from Let's Encrypt shows the same padlock and uses the same encryption as a paid one. Paid organisation-validated certificates matter only when a partner, tender or internal policy specifically requires company verification. Just make sure free certificates renew automatically, because they last 90 days.

How long does an SSL certificate last?

Let's Encrypt certificates last 90 days by default and are meant to renew automatically about every 60 days. Paid certificates currently last longer, but the CA/Browser Forum has agreed to reduce the maximum lifetime of public TLS certificates in stages from March 2026 until it reaches 47 days in March 2029, so automated renewal is becoming essential for everyone.

Does not secure affect Google ranking?

The direct effect is modest. Google's page experience guidance asks whether pages are served securely, but says aspects other than Core Web Vitals do not directly boost rankings. The indirect effects matter more: visitors leave, HTTP and HTTPS duplicates split signals, and blocked scripts can break forms and tracking. Nobody can guarantee rankings after an HTTPS fix.

Will switching to HTTPS lose my SEO?

Not if it is done properly. Use permanent server-side 301 redirects from each HTTP URL to the matching HTTPS URL, update canonicals, internal links and the sitemap, and verify the HTTPS property in Search Console. Google's documentation says redirects should stay for at least a year and that recrawling can take a few weeks on medium sites.

Why did my website suddenly start showing not secure?

A sudden change almost always means the certificate expired because auto-renewal failed, often after a DNS or nameserver change, a hosting move or a plan downgrade. The other cause is a newly added plugin, widget or embed that loads a file over HTTP. Check the certificate's expiry date first, then the browser console.

What is mixed content and how do I fix it?

Mixed content is an HTTPS page that loads some resources over HTTP. Browsers upgrade images and media automatically but block scripts, stylesheets, iframes and fonts, which breaks sliders, forms and layouts. Fix it by replacing http:// links at the source, in the database, templates and CSS, and add the upgrade-insecure-requests header as a safety net.

How do I fix not secure on a WordPress website?

Set WordPress Address and Site Address to https:// in Settings, General. Run a search-and-replace that handles serialised data to change old http:// links in the database. Add a server-level redirect to HTTPS, clear plugin, server and CDN caches, and fix loops caused by a proxy. Plugins that rewrite links on the fly are a stopgap, not a cure.

Why is my Shopify store domain showing not secure?

Shopify issues SSL certificates for domains connected to it, so a missing padlock usually means the domain's DNS records do not point to Shopify correctly, or the certificate is still waiting on those records. On a working domain, a theme file or leftover app code that loads an http:// asset can also trigger the warning.

What does “Your connection is not private” mean?

It is a full-page certificate error. The site offered a certificate, but the browser rejected it: it has expired, it names a different domain, it is self-signed, or part of the certificate chain is missing. Click Advanced to read the exact error code. Renewing or reissuing the certificate with the full chain normally resolves it.

Can I fix the Not secure warning myself?

Often, yes. If your site is simple, you have hosting panel access and the only problem is a missing certificate, enabling AutoSSL or Let's Encrypt and adding a redirect may be enough. Bring in a developer when the warning remains after the certificate is installed, when you see redirect loops, or when an online checkout is involved.

Is a website showing not secure dangerous to visit?

Not necessarily. Not secure means the connection is not encrypted, so data typed into forms could be read or altered in transit, especially on public Wi-Fi. It does not mean the site contains malware. Chrome uses a separate red Dangerous warning when Google Safe Browsing has flagged a site as harmful.

What is HSTS and should I enable it?

HSTS is a response header that tells browsers to use only HTTPS for your domain for a set period. It prevents downgrade attacks and removes a redirect hop. Enable it only after the certificate, redirects and mixed content are all stable, because if the certificate later breaks, visitors cannot click through the error while HSTS is active.

Why do I get “too many redirects” after enabling SSL?

Usually two systems disagree about HTTPS. A CDN or proxy in flexible mode talks to your server over HTTP, the server or WordPress redirects back to HTTPS, and the loop repeats. Fix it by using full SSL between the proxy and the origin server and keeping one redirect rule in one place.

Who should own my SSL certificate and hosting?

You should. The domain, hosting account and any paid certificate should be in the business owner's name, with renewal alerts going to an inbox you read. BtechWaleTech works inside your accounts and hands back full access, so the next developer or your own staff can renew or move things without asking anyone's permission.

Do you fix not secure warnings for sites outside India?

Yes. The work is fully remote, so the host's location does not matter. International clients are quoted in USD, pay by Wise, bank wire or PayPal, and maintenance starts at US$120/mo. We overlap with your working hours for any call and share every change in writing.

Website par Not secure kyu dikh raha hai aur kaise hatayein?

Aam taur par SSL certificate nahi laga hota, expire ho gaya hota hai, ya site HTTP par khul rahi hoti hai. Kabhi SSL hone ke baad bhi purani http:// images ya scripts warning laati hain. Pehle certificate theek karein, phir HTTPS par 301 redirect lagayein, phir http links badlein. URL WhatsApp par bhejein, hum cause bata denge.

Next step

Send us the URL that shows Not secure

One WhatsApp message with your website address is enough to start. We tell you the cause, quote the fix line by line, and leave your hosting and domain in your hands.