Your browser is saying it can't confirm a private, encrypted connection to your site. Either the site has no HTTPS certificate, the certificate has expired, it doesn't cover the exact address being visited (with or without www, or a subdomain), or the page loads something over plain http. Certificates are available free, and most hosts install and renew them automatically, so this is usually fixed in your hosting dashboard.
What's the problem
Chrome shows "Not secure" next to your address, or a full-page warning before anyone sees your site. Visitors leave, and anyone asked to log in or pay sees a reason not to.
Why it happens
- No HTTPS at all. The site is served over plain
http. Browsers label that "Not secure", because anything sent to the site could be read or changed on the way. - The certificate expired. The most common free certificates last 90 days and are meant to renew automatically. If the renewal breaks, say because the domain moved or a server changed, the certificate quietly runs out.
- It doesn't cover this address. A certificate for
yoursite.comdoesn't automatically coverwww.yoursite.comorshop.yoursite.com. Each address needs to be included. - Mixed content. The page is HTTPS, but it loads a script, form or image over
http. Browsers block or upgrade those requests, and some show the page as not fully secure.
How to fix it
- Click the icon next to the address in the browser. It says whether there's no certificate, an expired one, or one issued for a different name.
- In your hosting dashboard, turn on HTTPS for every address you use, with and without
www. Most hosts issue free certificates and renew them for you. - If you manage your own server, check the renewal job is running, and renew now if the certificate has lapsed.
- Redirect
httptohttps, so nobody lands on the insecure version. - Fix mixed content. Open the browser console and change any
http://links to scripts, images, forms or fonts tohttps://.
When to call Preventionlabs
A lone expired certificate is a do-it-yourself fix, and the steps above cover it. Call us when "Not secure" is just the visible part of a bigger problem: a site nobody can update, logins and user data you're not confident about, a server nobody maintains. HTTPS is one item on the MVP-level protection checklist in every resurrection, alongside logins, access control, data exposure and the rest.
Submit your project for a free assessmentFree assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.
Sources
- Google Chrome Help: Check if a site's connection is securebrowser docs
To resolve this issue, the site owner must secure the site and your data with HTTPS.
- Let's Encrypt: About Let's Encryptcertificate authority
We give people the digital certificates they need in order to enable HTTPS (SSL/TLS) for websites, for free, in the most user-friendly way we can.
- Let's Encrypt: FAQcertificate authority
Our default certificates are valid for 90 days.
- MDN Web Docs: Mixed contentweb reference
Browsers mitigate the risks of mixed content by auto-upgrading image, video, and audio mixed content requests from HTTP to HTTPS, and block insecure requests for all other resource types.