Fix library · Security
Sending every visitor to the secure version
This one is easy to miss because the site looks fine to you: you have a certificate, you type your address, you get the padlock. But anyone who types the address without https://, or follows an old link, may still land on an insecure copy that loads perfectly happily alongside the secure one. Both versions need to end at the same place.
http:// does not redirect to https://
What SEOPert detected
The http:// version of your site loads instead of redirecting to https://.
What this means
Visitors who type your address without https:// get an insecure copy of your site instead of being sent to the secure one.
How to fix it
- Turn on “force HTTPS” / “redirect to HTTPS” with your host. In cPanel this is under Domains → “Force HTTPS Redirect”.
On WordPress
- Turn on “Force HTTPS Redirect” in your hosting control panel, or ask your host to enable it. Make sure Settings → General uses https:// addresses.
On Shopify, Wix, Squarespace and Webflow
- Your platform redirects to HTTPS once SSL is enabled for your domain. Check your domain’s SSL settings.
If you are handing this to a developer
301-redirect http://* to https://* at the server or CDN.
Check it worked. Type http://yoursite.com into the address bar: it should change to https:// on its own.
Related
Check your own site
See which of these apply to you.
The free audit checks up to 10 pages and tells you exactly what it found, in the same plain language as these guides. No account, no card.