What does it mean when a website is showing Not secure?
It means the browser cannot confirm that the page travelled to the visitor over an encrypted HTTPS connection. Google's own Chrome help page describes the label plainly: the site does not use a private connection, so someone may be able to view or change what the visitor sends and receives.
That wording matters, because it tells you the warning is about the connection, not about malware. Chrome uses a separate, red “Dangerous” warning when Google Safe Browsing has flagged a site as harmful. A website showing not secure is usually a configuration problem, while a Dangerous page is a security incident. If you see the red one, skip ahead to cleaning a hacked website, because a certificate will not help.
There are three versions of the problem you might be looking at. The grey “Not secure” text beside the URL appears when the page loads over plain HTTP, or when parts of it do. A full-screen “Your connection is not private” page appears when a certificate exists but is expired, self-signed or issued for a different name. And a padlock with a small warning, or a broken padlock in some browsers, points to mixed content on an otherwise secure page.
Each version has a different fix, which is why pasting random advice from forums often makes things worse. Identify which one you have before touching anything.
Why is my website showing not secure all of a sudden?
A site that had a padlock last month and lost it this week almost always has an expired or failed certificate renewal. Free certificates are short-lived by design, so renewal runs automatically, and when that automation breaks nobody notices until visitors complain.
Renewal fails for ordinary reasons. The domain's DNS was moved to a new provider and the host can no longer prove control. Someone added a Cloudflare proxy or changed nameservers. The hosting plan was downgraded and AutoSSL was switched off. A developer who set things up used their own email for alerts and has since moved on.
The other sudden cause is a change on the site itself. A new plugin, a slider, a chat widget or an embedded form begins loading a script from an http:// address, and the browser downgrades the page. Theme updates occasionally do the same when an old image path is hard-coded in a template.
- Certificate expired and auto-renewal failed silently
- DNS or nameserver change broke domain validation
- Hosting plan or server changed and SSL was not reissued
- New widget, plugin or embed pulling an http:// file
- www or a subdomain added without its own certificate
If your emails started bouncing at the same time, the DNS change is the likely link; our page on emails going to spam covers the record checks.
How to check why your website is showing not secure, in five minutes
You can find the cause yourself with nothing more than Chrome on a laptop. These steps tell you which of the four problems you have, so you can describe it accurately to your host or to us.
- Click the icon left of the address. If it says the connection is not secure, the page itself is on HTTP or the certificate is bad.
- Type the address with https:// in front. If it loads with a padlock, the certificate works and you only need redirects.
- If HTTPS shows a privacy error, click “Advanced” and read the reason: expired, wrong name (NET::ERR_CERT_COMMON_NAME_INVALID) or untrusted issuer.
- Open DevTools (F12), go to the Console tab and reload. Mixed content lines name the exact http:// file that is causing trouble.
- Try both www and non-www versions. A certificate that covers only one of them is extremely common.
- Note the expiry date shown in the certificate viewer, and who issued it.
Send us the answers to those six checks on WhatsApp and we can usually tell you the fix in the first reply. When the checks point to server or DNS work you cannot reach yourself, that is the point to bring in a developer for the bug.
No SSL certificate installed: the simplest cause to fix
If the site has never had a certificate, every page is served over HTTP and Chrome labels all of it Not secure. The fix is to issue a certificate for every hostname you use and then redirect HTTP to HTTPS.
On most Indian shared hosting with cPanel, the tool is called SSL/TLS Status or AutoSSL. It issues a free certificate for the domain and its www version, often within minutes, provided the domain's DNS points at that server. Plesk has a similar Let's Encrypt extension. On a cloud server you install a client such as Certbot, or put the site behind a load balancer or CDN that issues certificates for you.
Old sites built years ago are the usual suspects here. They were launched when HTTPS felt optional, the developer never came back, and the owner assumed hosting “includes security”. Hosting often does include a free certificate; someone still has to switch it on and point the site at it.
Once the certificate exists, do not stop. Without redirects, visitors who type your name or click an old link still land on the HTTP version, see the warning and leave. The next sections handle that.
Expired or mismatched certificates: why a padlock can still fail
A certificate is valid only for the names written into it and only until its end date. If either condition fails, the browser shows a full-page error rather than the small Not secure label, and most visitors turn back.
Name mismatches catch people out constantly. The certificate covers example.in but the site is linked everywhere as www.example.in. A shop subdomain was added later. The hosting company's shared certificate appears because the domain is not yet attached properly. Each of these needs a certificate that lists every hostname, or a wildcard for subdomains, plus a decision about which single version is the real address.
Expiry is the other half. Let's Encrypt's FAQ says its default certificates last 90 days and recommends renewing every 60, so automation is not optional. Paid certificates last longer today, but the CA/Browser Forum ballot SC-081 set a schedule that reduces the maximum validity of public TLS certificates from 398 days to 47 days, in stages between March 2026 and March 2029. In practice, manual renewal once a year is ending for everyone.
Symptom: ERR_CERT_DATE_INVALID
The certificate has expired or the visitor's device clock is wrong. Check the end date first.
Symptom: ERR_CERT_COMMON_NAME_INVALID
The certificate belongs to another hostname. Reissue it to cover the name visitors actually use.
Symptom: ERR_CERT_AUTHORITY_INVALID
Self-signed or missing intermediate certificate. Install the full chain from your issuer.
Mixed content: the reason a site with SSL still shows not secure
Mixed content happens when a page loaded over HTTPS asks for an image, script, font or frame over HTTP. MDN's documentation on the topic explains how modern browsers react: images, audio and video are automatically upgraded to HTTPS, while scripts, stylesheets, iframes, fonts and fetch requests are blocked outright.
So mixed content shows up two ways. Sometimes you see a degraded padlock. More often, something quietly breaks: a slider stops moving, a font falls back to Times New Roman, an enquiry form's script never loads. Owners report “the site looks strange on HTTPS” without realising it is the same problem.
Where do the http:// links live? On WordPress, mostly in the database: post content, widget settings, page-builder JSON and theme options saved when the site was on HTTP. On static and custom sites, in templates and CSS files. Third-party embeds from old map, video or chat providers are a third source.
The durable fix is to change the links at their source with a proper search-and-replace that understands serialised data, then fix templates and CSS by hand. A Content-Security-Policy header with the upgrade-insecure-requests directive, which MDN also describes, is a useful safety net for anything you miss, but it is not a substitute for cleaning the site.
How do I redirect HTTP to HTTPS without losing Google rankings?
Use a permanent server-side redirect from every HTTP URL to the matching HTTPS URL, in a single hop, and keep it in place. Google Search Central's site-move documentation recommends permanent redirects such as 301 or 308 and says they should be kept for as long as possible, generally at least a year.
“Matching” is the part people skip. Redirecting every old page to the home page throws away the links and rankings those inner pages earned. The rule should carry the path across, so http://example.in/services/ becomes https://example.in/services/ exactly.
Decide your one canonical form first: HTTPS, with or without www. Then make sure the other three combinations (http with www, http without, and the HTTPS version you did not choose) each land on the canonical in one step. Chains of two or three redirects slow the first visit and waste crawl budget on large sites.
After the switch, update internal links, canonical tags and the XML sitemap to HTTPS, and add or check the HTTPS property in Google Search Console. The same documentation notes that for a move to HTTPS you do not need the Change of Address tool, which is meant for domain changes; you just keep both versions verified and let Google recrawl. If you are also changing the domain, that is a larger job covered on changing a domain without losing SEO.
Free vs paid SSL certificate: which one fixes the warning?
For removing the Not secure label, a free certificate works exactly as well as a paid one. Browsers show the same padlock for any valid, trusted certificate; the encryption strength is the same.
Let's Encrypt, a nonprofit, issues free domain-validated certificates and states in its FAQ that it has no plans to issue organisation-validated (OV) or extended-validation (EV) certificates, because those checks cannot be automated. Most hosting panels in India use Let's Encrypt or a similar free issuer under the hood.
Paid certificates still have uses. Some procurement or banking partners ask for an OV certificate showing your company details. A few legacy systems need a certificate type that free issuers do not supply. Some owners prefer a vendor with phone support. None of these change what the address bar shows to an ordinary visitor.
Choose free (DV) when
You run a business site, blog, clinic, school or online store and just need the padlock and encryption. Automate renewal and forget it.
Choose paid OV when
A partner, tender or payment arrangement asks for organisation validation in writing, or your IT policy requires a specific issuer.
Avoid
Buying a paid certificate as a “fix” for mixed content or missing redirects. It will not remove the warning if those problems remain.
The logic is the same everywhere, but the switches live in different places. Here is where to look on the platforms we meet most often.
WordPress
Set both WordPress Address and Site Address to https:// under Settings, General. Run a serialisation-safe search-and-replace for the old http:// domain. Clear every cache layer: plugin, server and CDN. If the site sits behind a proxy and loops, the server needs to trust the forwarded HTTPS header.
Shopify
Shopify issues certificates for connected domains itself. When one will not issue, the usual reason is a DNS record pointing somewhere else. Theme code or an old app snippet calling http:// assets can still cause mixed content.
Wix, Squarespace and other builders
HTTPS is managed by the platform. Problems nearly always trace back to domain connection records or custom code embeds.
Static and custom sites
Install the certificate on the server or CDN, write the redirect in the web server config (Nginx, Apache or the host's rules file), and grep the codebase for http:// references.
WordPress owners dealing with more than the padlock, such as updates and backups, can compare our WordPress maintenance plans. If the same site throws a white screen instead, see the WordPress critical error fix guide.
Does a website showing not secure hurt SEO?
Honestly, the direct ranking effect is small, but the indirect damage is real. Google's page experience documentation lists “Are your pages served in a secure fashion?” among its self-assessment questions and links a Search Console HTTPS report, while also saying that page experience aspects beyond Core Web Vitals do not directly lift rankings on their own.
The indirect costs are where it hurts. Visitors who see a warning bounce back to the results page. Links shared on WhatsApp open to an unsettling label. Duplicate HTTP and HTTPS versions split signals when redirects are missing, and Google may pick the wrong one as canonical. Broken scripts from blocked mixed content can stop forms, tracking and structured data from working.
AI assistants and AI Overviews also draw on pages that search engines consider trustworthy and crawlable. A clean HTTPS setup with one canonical version is simply part of being a page worth citing. No one can guarantee rankings, so treat HTTPS as removing a handicap rather than as a growth trick.
- Check the HTTPS report and the Pages report in Search Console after the fix
- Confirm Google has picked the HTTPS URL as canonical with URL Inspection
- Resubmit the HTTPS sitemap
- Watch clicks for a few weeks; small wobbles during recrawl are normal
If rankings fell for reasons beyond the certificate, our traffic drop recovery page explains a fuller audit.
What the Not secure label does to enquiries, forms and payments
The warning shows up exactly where it costs most: on contact forms, login boxes and checkout pages. A visitor about to type a phone number sees the word “Not secure” next to your brand and hesitates.
For a clinic, coaching institute or local service business in India, most enquiries arrive on a phone, often through a link someone forwarded on WhatsApp. That visitor has no loyalty yet. A browser warning is enough to make them tap the next result instead.
Online stores have a harder rule. Payment providers and card networks expect checkout on HTTPS, and modern browsers restrict features like location access, service workers and some payment interfaces to secure contexts. A store with mixed content may find that its checkout script is blocked entirely, which looks to the owner like “payments stopped working”.
We cannot give you a percentage of lost leads, because nobody honestly can for your site. What you can do is check your own analytics: compare form submissions or WhatsApp clicks for a month before and after the padlock returns.
Website showing not secure in India: hosting panels, old developers and domain access
In India the technical fix is usually easy; access is the hard part. We often start a job by working out who holds the domain, the hosting login and the DNS, because the original developer registered them under their own email.
Low-cost shared hosting plans commonly include a free certificate, but some older plans need it enabled in the panel, and some resellers charge for it. Before buying anything, check the SSL/TLS or AutoSSL section of your panel. If you cannot log in, ask the provider to reset access to the email on the account, or have the domain transferred to your name first.
Two other local patterns come up often. Sites moved behind a free CDN proxy with “flexible” SSL can enter redirect loops, because the CDN talks to the server over HTTP while WordPress insists on HTTPS. And government or tender portals sometimes reject links that trigger certificate errors, which can block a vendor application at the last minute.
- Domain registered in the business owner's name and email
- Hosting login and DNS access in your hands, not only the developer's
- Renewal alerts going to an inbox someone reads
- GST invoice from the host kept, so plan details are traceable
If access is completely lost, our developer left the project midway page explains how to recover accounts safely.
Should you fix a website showing not secure yourself or hire someone?
Do it yourself when the diagnosis shows a single, simple cause and you have panel access. Hire help when the warning survives the certificate, when you see redirect loops, or when the site is an online store taking payments.
A good test is whether the five-minute check above gave you one clear answer. “No certificate on a static site” is a DIY job: enable AutoSSL, add a redirect, done. “Certificate present, padlock still broken, forms not sending, loops on some pages” means several problems at once, and trial-and-error on a live store costs sales.
When you do hire, ask for three things in writing: what the cause was, what exactly was changed, and how renewal will be monitored. Anyone who fixes it without explaining leaves you unable to fix it next time.
DIY is fine
Brochure site, one hostname, panel access, no payments, no custom code.
Get a developer
WordPress with a page builder, a proxy or CDN, several subdomains, a checkout, or no idea who controls the DNS.
For regular care rather than a one-off rescue, see hiring a website maintenance freelancer.
How much does it cost to fix a website showing not secure?
The certificate itself can cost nothing. What you pay for is the time to diagnose, clean mixed content, set redirects and verify everything, and that depends on how messy the site is.
Our approach is to look first and quote second, because an honest quote for “SSL fix” is impossible without seeing the site. A small static site with an expired certificate is at the cheap end. A large WordPress site full of page-builder data, several subdomains and a CDN in front sits at the other end. Very old sites on unsupported PHP sometimes make a rebuild the more sensible spend.
For ongoing care, our maintenance starts at ₹8,000/mo (US$120/mo for clients abroad), which covers certificate watch alongside updates and backups; website charges are explained in depth on website maintenance charges. If rebuilding wins, a static site starts at ₹10,000 and an online store at ₹50,000, each with two months of free maintenance after launch.
- Number of hostnames and subdomains involved
- Where http:// links are stored: database, templates or third-party embeds
- Whether a CDN or proxy sits in front of the server
- Access: ready logins versus account recovery first
- Platform: static, WordPress, Shopify or custom code
How to keep the padlock: a renewal and HTTPS checklist
Most repeat warnings come from renewal automation breaking silently. Prevention is mostly about making sure a human hears about problems before visitors do.
- Auto-renewal enabled and tested once by forcing a renewal
- Expiry alert emails going to a shared business inbox
- An external monitor that checks the certificate date weekly
- Every hostname listed on the certificate, including www
- Single-hop 301 rules for all http and non-canonical variants
- No http:// references left in the database or templates
- Content-Security-Policy upgrade-insecure-requests as a backstop
- HSTS header added only after everything above is stable
- New plugins, embeds and widgets checked in the Console before going live
A note on HSTS: it tells browsers to use HTTPS only for your domain for a set period. It is valuable, but if you enable it and later break the certificate, visitors cannot click past the error at all. Turn it on last. Monitoring is something we set up under website uptime monitoring.
Worked example: a coaching institute site showing Not secure
Here is a hypothetical case to show how the steps fit together. Say a coaching institute in Lucknow runs a WordPress site built five years ago. Parents start messaging that the admission form page says “Not secure”, and the institute's own staff notice the home page slider has stopped.
The five-minute check shows a valid certificate on the non-www domain, but every brochure link and ad points to www, which has no certificate. On the HTTPS version, the Console lists a dozen blocked http:// scripts from the slider plugin's saved settings and a form embed from an old provider.
The fix runs in order. Reissue the certificate for both hostnames. Choose the www version as canonical because printed material already uses it. Write one server rule sending all variants there. Run a database search-and-replace for the old http address, update the slider settings and replace the form embed with the site's own form. Clear caches, then check the Console again on a phone over mobile data.
Afterwards, update the sitemap, verify the property in Search Console and switch on renewal alerts to the institute's shared email. The next admission season starts with a padlock, and the institute knows exactly what was changed and why.
HTTPS and Not secure fixes for websites across India
We work remotely, so a website showing not secure in any state is fixed the same way: you share access, we diagnose, quote and fix while you watch the changes on WhatsApp. Local context still shapes the job.
Hotels and homestays in Udaipur and Dehradun take booking enquiries from travellers who notice warnings instantly. Traders in Surat and Ludhiana send catalogue links over WhatsApp to buyers who have never met them. Clinics and schools in Indore, Bhopal and Raipur collect phone numbers through forms. Tourism and export businesses in Kochi and Guwahati serve overseas visitors whose browsers are strict about certificates.
If the site is old enough that the certificate is only one of many problems, you may be better served by a planned rebuild; our redesign cost guide helps you weigh that up before paying for repairs.