Fix library · Security

HTTPS: the padlock, and why browsers insist on it

Without HTTPS, browsers put the words “Not secure” next to your address, in front of every visitor, permanently. Certificates have been free and automatic for years now, so this is no longer a budget question — it is usually a switch in your hosting control panel that nobody has turned on.

The site is not using HTTPS

What SEOPert detected

Your site is served over http rather than https.

What this means

Your site isn’t using HTTPS. Browsers label it “Not secure”, visitors lose trust, and Google prefers secure sites.

How to fix it

  1. Turn on a free SSL certificate with your web host (often called AutoSSL or Let’s Encrypt).
  2. Then redirect all http:// visits to https:// (see the next check).
On Shopify, Wix, Squarespace and Webflow
  1. Your platform provides HTTPS for connected domains. In your domain settings, make sure SSL/HTTPS is turned on, then re-run the audit.

If you are handing this to a developer

Install a valid TLS certificate and 301-redirect all HTTP requests to HTTPS.

Check it worked. Open http://yoursite.com: it should move to https:// and show a padlock with no warning.

Check your own site

See which of these apply to you.

The free audit checks up to 10 pages and tells you exactly what it found, in the same plain language as these guides. No account, no card.

Free · No account · Results in under a minute · Public websites only