By Sarah Dia, HostDroplet Support
Not secure even though I have SSL — it’s one of the most confusing warnings a site owner runs into. You installed an SSL certificate, your site loads over https://, and yet your browser still stamps it with that unsettling Not Secure label. It’s confusing and a little alarming, but the fix is usually simpler than it looks.
Here’s the reassuring part: in the vast majority of cases, your SSL certificate isn’t broken at all. The warning is almost always caused by one specific, sneaky issue — and once you know what to look for, it’s straightforward to fix. Let’s find the real cause.
First, an important distinction
There are two very different things people lump together as “not secure,” and they have completely different fixes:
- A “Not Secure” label — your page still loads, but the padlock is missing or crossed out. This is usually mixed content or a missing redirect, and your certificate is fine.
- A full “Your connection is not private” error page — the browser blocks the site entirely. This means the certificate itself is the problem: expired, missing, or not covering your domain.
Figuring out which one you’re seeing tells you exactly where to look. Let’s take them in order.
Step 1 — Confirm your certificate is actually valid
Start by ruling out the certificate itself. Run your domain through our SSL Checker and follow how to check if SSL is working on your website. You’re looking for three things: the certificate is present and not expired, and it covers the exact hostname you’re visiting (both www and non-www). If the certificate is missing or expired, that’s your issue — see how to enable SSL in cPanel to install or renew one. Most hosts issue free certificates automatically through Let’s Encrypt, so there’s no reason to be without one.
If the checker says your certificate is valid and covers your domain — and you’re still seeing “Not Secure” — then the certificate isn’t the problem, and you’re almost certainly dealing with the next cause.
Step 2 — The usual culprit: mixed content
This is the reason behind most “Not Secure despite SSL” cases. Mixed content happens when your page loads over HTTPS but pulls in at least one resource — an image, script, stylesheet, or font — over insecure http://. That single insecure element is enough for the browser to declare the whole page not fully secure, even though your certificate is perfectly valid. You can read the technical explanation in MDN’s mixed content documentation.
These insecure references are usually hardcoded http:// links left behind in your content, theme, or database — very common on sites that were set up before SSL was added. To find and fix them:
- Scan your site with our Mixed Content Checker to see exactly which resources are loading insecurely.
- Update those references from
http://tohttps://. Our guide on fixing mixed content errors in WordPress walks through doing this safely across your content and database. - Re-scan to confirm every resource now loads over HTTPS.
Step 3 — Make sure you’re forcing HTTPS
Sometimes the certificate is valid and there’s no mixed content, but visitors still land on the http:// version of your site — which is, by definition, not secure. Two things fix this. First, in WordPress go to Settings → General and make sure both your WordPress Address and Site Address use https://. Second, set up a redirect so all traffic is forced to the secure version — follow how to redirect HTTP to HTTPS in cPanel. For an extra layer that tells browsers to only ever use HTTPS, our guide on HSTS explains how to enforce it at the browser level.
Step 4 — Clear your caches
After fixing mixed content or redirects, your browser or a caching layer may still be serving the old insecure version, making it look like nothing changed. Clear your site cache, your browser cache, and Cloudflare’s cache if you use it, then reload — our guide on clearing cache in WordPress covers each layer. Test in a private/incognito window for a clean result.
When it’s a full certificate error instead
If you’re getting a hard “Your connection is not private” block rather than a “Not Secure” label, the certificate itself needs attention. The usual causes are an expired certificate (renew it), a certificate that doesn’t cover the exact hostname (make sure it includes both www and non-www, and that you redirect to your canonical version), or one that simply didn’t install correctly. The SSL Checker will point to which of these applies. If you can’t resolve it, our support team can confirm and reissue the certificate for domains hosted with us.
Why this is worth fixing properly
A “Not Secure” warning does real damage: visitors hesitate or leave, forms feel unsafe to fill in, and HTTPS is a genuine trust and ranking signal for search engines. It’s also a foundational piece of your site’s overall protection — our guide on what an SSL certificate is explains how it fits into keeping your site and visitors safe. Clearing the warning isn’t cosmetic; it protects both your credibility and your conversions.
What to do this week
- Confirm your certificate is valid and covers your domain (SSL Checker).
- Scan for mixed content and update any
http://resources tohttps://. - Set both site URLs to HTTPS and force an HTTP-to-HTTPS redirect.
- Clear every cache and re-test in an incognito window.
- If you get a full certificate error rather than a label, renew or reinstall the certificate.
Frequently asked questions
My SSL is valid but the site still says Not Secure. Why?
Almost always mixed content — one or more resources on the page are still loading over http://. Find them with a mixed content scan and switch them to https://, and the padlock returns.
What exactly is mixed content?
It’s when a secure HTTPS page loads an insecure HTTP resource (an image, script, or stylesheet). Browsers treat the whole page as not fully secure until every resource loads over HTTPS.
I fixed everything but it still shows Not Secure. What now?
You’re likely seeing a cached version. Clear your site, browser, and Cloudflare caches and check again in a private window before assuming the fix didn’t work.
Does the Not Secure warning hurt my SEO?
Yes, indirectly and directly. HTTPS is a positive ranking signal, and the warning drives visitors away, which harms engagement. Resolving it helps both trust and search performance.
The bottom line
If your site shows Not Secure even though you have SSL, don’t assume your certificate failed. Confirm it’s valid, then hunt down the one insecure resource that’s almost certainly the cause. Start with our SSL Checker and Mixed Content Checker, and if you want the bigger picture, our guide on what an SSL certificate is is the natural next read.


