Why Is My Website Showing "Not Secure" in Chrome?

VenbitThe Venbit TeamJuly 24, 20264 min read

The short answer

A 'Not Secure' label in Chrome means your site's SSL certificate is expired, missing, or not being used properly, so the browser can't confirm the connection is encrypted. The fix is to install or renew a valid certificate and make sure every page loads over https. Most hosts offer free SSL, so this is usually quick to resolve.

Key takeaways

  • 'Not Secure' is about SSL, the padlock and https, not a hack.
  • The most common cause is a certificate that expired or was never installed.
  • Most hosts provide free SSL through Let's Encrypt; you may just need to enable it.
  • 'Mixed content' can flag a page as not fully secure even with a valid certificate.
  • Once fixed, force https everywhere so visitors never see the warning again.

When Chrome shows "Not Secure" next to your web address, it's telling visitors your site doesn't have a valid SSL certificate, the thing that encrypts the connection and puts https at the front of your URL. It's not saying you've been hacked. It's saying the browser can't confirm the connection is private. The cause is almost always a certificate that expired, was never installed, or isn't being applied to every page. The good news: SSL is usually free now, so fixing this is quick.

CauseHow commonThe tell
Expired SSL certificateVery commonIt worked before; a full 'Your connection is not private' screen may appear
No certificate installedCommonA brand-new site, or one that never had https set up
Mixed content on the pageCommonPadlock is missing on specific pages that load images or scripts over http
Site not forcing httpsCommonThe http version of the page still loads and shows the warning
Certificate name mismatchOccasionalWarning about the certificate not matching the domain, often on www vs non-www
Why a site shows 'Not Secure'

Confirm whether the certificate is expired or missing

Click the "Not Secure" text or the icon to the left of the address in Chrome, then look at the certificate or connection details. It'll tell you whether there's a certificate at all and, if so, when it expired. An expired date means you had SSL and it lapsed, usually because auto-renewal failed. No certificate at all means one was never installed for this domain. That one distinction points you straight to the right fix.

Install or renew the SSL certificate

If the certificate is missing or expired, this is the core fix. Most hosting providers now include free SSL through Let's Encrypt, and many offer a one-click button in the control panel to install or reissue it. Log into your host, find the SSL or security section, and enable or renew it. If your host doesn't offer free SSL, a service like Cloudflare can provide it, or you can buy a certificate. Once a valid certificate is in place, allow a little time for it to take effect, then reload your site.

Certificates from Let's Encrypt renew automatically every 90 days when set up correctly. If yours expired, that auto-renewal broke somewhere, so after reinstalling, confirm renewal is actually running so you don't land back here in three months.

Force https on every page

A valid certificate isn't enough on its own if visitors can still reach the insecure http version of your pages. You want every request redirected to https. On WordPress, set both your Site Address and WordPress Address to the https version under Settings, and a plugin or a rule in your server config can force the redirect site-wide. This closes the gap so nobody stumbles onto an unencrypted page and sees the warning.

Clear up mixed content

Sometimes the certificate is valid and https is forced, but one page still won't show the padlock. That's usually "mixed content": the page itself loads securely, but it pulls in an image, script, or stylesheet over insecure http. The browser flags the whole page as not fully secure. Find the offending resources (Chrome's developer console lists them) and update those links to https. A search-and-replace across your database can catch old hard-coded http image URLs in one pass.

When to hand it off

Enabling free SSL from a host's one-click button is genuinely simple, and if that clears the warning, you're done. It gets more involved when auto-renewal keeps failing, when a certificate name mismatch needs server-level attention, or when stubborn mixed content is buried across a large site. Those are worth handing to someone who works with certificates and DNS regularly, especially since a misstep can take the site offline entirely. If the one-click route doesn't solve it, that's your signal to get help.

How we keep the padlock from ever dropping

An expired certificate is one of the most visible, and most avoidable, trust failures a site can have. On our maintenance plans, starting at $99 a month, we track SSL expiry dates and make sure auto-renewal actually runs, so your visitors never hit a "Not Secure" warning in the first place. We also watch for mixed content after edits and force https site-wide. We're based near Seattle, and we handle this kind of fix within one business day if it ever does come up.

More website answers

Every question in this series, from Website Problems, Solved.

Symptoms & emergencies19
What happens if...9
Cost & pricing7
Plans & hiring10
Ownership & switching9
Platform-specific7
Seattle & local2
Venbit

The Venbit Team

Web design & SEO, Seattle

Venbit is a Seattle-area web design, SEO, and digital marketing studio. Since 2011 we've designed, built, and ranked small-business websites for clients across the Puget Sound and around the country, so the numbers and advice here come from real projects, not a content mill.

Common questions

Questions, answered straight.

Straight answers about website fixes for your business. If yours isn't here, ask us directly and we'll give it to you straight.

Ask the team

No. 'Not Secure' is strictly about SSL, whether your connection is encrypted and the certificate is valid. It has nothing to do with malware or a break-in. A hacked site is flagged differently, usually with a red 'Deceptive site ahead' or 'This site may harm your computer' warning. 'Not Secure' just means the certificate is expired, missing, or misapplied.

For most small business sites, nothing. Let's Encrypt provides free certificates, and the majority of hosts now include them with a one-click install. Cloudflare also offers free SSL. Paid certificates exist for specific needs like extended validation, but a standard site doesn't need one. If a host is charging extra just for basic SSL, that's worth questioning.

It can. Google has treated https as a ranking signal for years, and more importantly, the warning scares visitors away, which raises your bounce rate and costs you conversions. Even if the direct ranking effect is small, the trust hit is real. Fixing SSL protects both your search visibility and the visitors who'd otherwise leave on sight.

Free certificates from Let's Encrypt are only valid for 90 days and are meant to renew automatically. If yours keeps expiring, the auto-renewal process is broken, often because of a host configuration issue or a certificate that was installed manually without renewal set up. Fixing the renewal automation, not just reinstalling, is what stops it from recurring.

Free 30-minute strategy call

Let's talk about your project.

Tell us what you need and we'll give you an honest read on the project, the timeline, and what it takes, before you spend a dollar. Based in Seattle, working across the Puget Sound.

4.8 on Google 5.0 on Yelp