WordPress “not secure” warning: certificates, HTTPS and mixed content
2026-10-01 · 3 min read
Security warnings have different causes. Identify the warning before changing certificates, URLs or redirects.
In this article
A browser may label an HTTP connection insecure, reject an invalid certificate or warn about dangerous content. These are different situations. Installing a certificate does not clean a compromised website, and a valid certificate does not guarantee every site function is secure.
Record the exact warning
Keep the full address, including “www”, the message and any error code. Check the device date and try another browser. A warning limited to one machine is useful evidence too.
| Situation | What to check |
|---|---|
| Address starts with HTTP | Working HTTPS and the correct redirect |
| Expired or wrong-domain certificate | Renewal, covered names and hosting installation |
| HTTPS loads but some images fail | Resources still requested over HTTP |
| Redirect loop | WordPress, proxy/CDN and server configuration |
| Malware or phishing warning | Investigate compromise, not just the certificate |
Check the certificate before changing WordPress
Ask the host to confirm validity and covered names. With a proxy or CDN there may be two connections to protect: visitor to CDN and CDN to server. Their configuration must work together.
Changing WordPress addresses to HTTPS before the server is ready can lock you out. Agree the change and recovery plan with whoever manages hosting.
Correct old references carefully
Mixed content occurs when an HTTPS page requests resources over HTTP. Investigate images, stylesheets and integrations. A global database replacement requires a backup and a tool compatible with serialised data. Check payment integrations and callbacks that depend on fixed addresses too.
Verify the whole experience
Open the versions with and without “www”, follow redirects and test inner pages, images, forms and payments in a test environment. Check how renewal works to avoid another failure at expiry.
The official WordPress HTTPS documentation explains the fundamentals. For malware warnings, start with compromise triage. A screenshot of the warning and the affected domain help us begin a support assessment without guessing the cause.
Need help with this case?
Feitura support starts from €10 per hour of work. Suggest your hours or choose “I cannot estimate”. You can also propose a different budget; we agree the scope and price before starting. Request an assessment or explore website maintenance.
Website support
Would you like help with this?
Describe the problem, estimate the hours or tell us your budget. We review the request before starting.
€10 / hour
VAT exempt. No payment with this request.
Get help I have a different budgetHear about new articles
Create a free account, confirm your email, and get one email when we publish something new. No lists sold, no drip machines.
Create a free accountThe account also lets you comment and like articles.
Comments (0)
No comments yet — start the conversation.
Sign in to join the conversation. Sign in · Create an account