No HTTPS detected: how to move a WordPress site to HTTPS safely
No HTTPS means the page is served over plain HTTP, without an SSL/TLS certificate encrypting the connection. Browsers label such pages "Not secure", and anything visitors type, including passwords and form entries, travels unencrypted. The fix is to install a certificate, switch WordPress's URLs to https://, and 301-redirect every HTTP URL to its HTTPS version.
This is rated critical because it affects trust on every page, and because most hosts now provide free certificates, so there is little reason left to run without one. Google has used HTTPS as a lightweight ranking signal for years; the bigger costs are the browser warning and the visitors it scares off.
What it looks like in the HTML
Before
http://example.com/checkout/
After
https://example.com/checkout/
<!-- and http://example.com/checkout/ answers 301 → https://example.com/checkout/ -->
Why it matters
HTTPS encrypts traffic between the browser and your server, so nobody on the same network can read or alter it. Chrome and other browsers mark HTTP pages as not secure, and show stronger warnings on HTTP pages with forms. Many modern browser features, such as geolocation and service workers, only work on HTTPS.
For search, HTTPS is a confirmed but small ranking signal. The practical SEO issue is consistency: a site reachable on both HTTP and HTTPS has two copies of every page until redirects and canonicals point one way.
Before you start: check what was audited
This check looks at the URL that was audited. If you typed http:// into the audit and your site already redirects to HTTPS, the flag is about the URL you entered, not your site. Open http://yoursite.com in a browser: if the address bar ends up on https://, rerun the audit with the HTTPS URL. If it stays on HTTP, or the HTTPS version shows a certificate error, work through the steps below.
How to fix it in WordPress
- Get a certificate. Most hosts offer free Let's Encrypt certificates from their control panel, often with one click. If you use a CDN such as Cloudflare, it can provide one at the edge, but also set up a certificate on the origin server so the whole path is encrypted.
- Take a backup. You are about to change the site's URLs.
- Switch WordPress to HTTPS. Under Settings → General, change both WordPress Address (URL) and Site Address (URL) to
https://. You will be logged out and need to log back in on HTTPS. - Redirect all HTTP traffic. Set up a site-wide 301 from HTTP to HTTPS at the server or host level: many hosts have a "force HTTPS" switch, or you can add a rule in
.htaccess(Apache) or the server config (Nginx). This keeps old links and bookmarks working and consolidates signals on the HTTPS URLs. - Fix mixed content. Old posts often contain
http://links to your own images and files, which browsers block or warn about on an HTTPS page. Run a search-and-replace on the database (for example with WP-CLI'swp search-replace 'http://example.com' 'https://example.com'), then check pages for remaining warnings in the browser console. - Update external references. Update your Google Search Console property (a Domain property covers both protocols), your sitemap submission, and links in your social profiles.
Hydrogen SEO follows WordPress's site URL, so its canonical tags, sitemap and Open Graph URLs switch to HTTPS once step 3 is done. HTTPS is part of the Security & HTTPS area of its site health score.
How to check the fix
Run curl -I http://example.com/ and confirm a 301 response with a Location header on https://. Visit a few old posts and check the padlock and the console for mixed content warnings. View source and confirm rel="canonical" URLs start with https://. Then run the free SEO audit on the HTTPS URL. See the redirects guide if you need more detail on 301s.
Common questions
Is HTTPS a Google ranking factor?
Yes, but a lightweight one. The larger effects are browser security warnings and user trust.
Will moving to HTTPS hurt my rankings?
A move with clean 301 redirects from every HTTP URL to its HTTPS equivalent is routine. Expect some fluctuation while Google recrawls, not a lasting loss.
What is mixed content?
An HTTPS page that loads images, scripts or styles over HTTP. Browsers block or flag it, so update those URLs to HTTPS.