why does my site say “not secure”? and why the fix takes ten minutes

web · Aug 6, 2026 · 4 min read

the "not secure" label is the browser being blunt: the connection to your site is unencrypted, so anyone between the visitor and your server — a wifi network, an isp, a compromised router — can read or alter what travels. it is not an accusation about your content. it is a statement about the pipe.

what is actually missing

one thing: a valid ssl/tls certificate, which turns http into https. the certificate does two jobs — it encrypts the traffic, and it proves the domain is really yours. modern browsers show "not secure" for every http page: not a penalty, just the visible side of a default the whole web adopted.

what it does NOT mean, despite the panic it causes:

  • it does not mean you have a virus.
  • it does not mean your site was hacked.
  • it does not mean google will remove you. it is a ranking signal at the margins and a trust signal everywhere.

the fix, honestly timed

  • on a builder or a managed platform: minutes. the setting is usually a toggle in the domain panel: enable ssl / force https. the certificate is issued automatically and renews itself. most "my site says not secure" cases are just this toggle sitting off — or it sitting on while the site still answers on http, which leads to the real second step below.
  • on your own hosting: free either way. certificates from let's encrypt cost nothing and most hosts install them from the panel in a few clicks. if your host charges yearly for ssl, that is an anachronism worth changing hosts over.
  • the part people forget: the redirect. enabling the certificate is half the fix. the site must also answer http://... by sending visitors to https://... automatically (a 301, kept forever). without the redirect you get the worst case: old links and bookmarks keep landing on the http version, flags follow, and some visitors get both versions cached.

mixed content: the last stubborn flag

sometimes the certificate is on, the redirect works, and the browser still grumbles. that is mixed content: the page is https but something inside it — an image, a script, a font — is still loaded over http. the browser refuses to call the page secure while any piece of it arrives unprotected. the fix is finding the http references and updating them to https (or hosting them locally). run one scan, fix the handful of urls, done — it is almost always a handful, not an invasion.

why it matters beyond the label

the padlock is the smallest promise a site can make: nothing watches between you and me. every trust signal on your page — real photos, honest prices, reviews — stands on that floor. i wrote the trust layer in what makes people trust a website; the technical floor comes first, because none of the rest survives the moment a stranger's browser says otherwise.

FAQ

do i need to buy a certificate?

almost never. free automatic certificates cover every normal site. paid certificates add things a small business site does not need — extended validation badges died out of the browsers years ago.

does https make my site slower?

the opposite now: modern https allow faster connections (http/2 requires it). the old slowness argument died a decade ago.

the warning shows only for me — why?

you are likely on the http version from an old bookmark or a cached link, while everyone else is redirected correctly. test in a private window with the bare domain typed fresh; that is the version strangers see.

the closing thought

"not secure" is one of the few technical errors a fix for which is genuinely ten minutes and free. if your site still ships it, that is not a budget problem or a knowledge problem — it is a saturday-morning problem, and it has waited long enough.

if you are near Parma and want the technical floor — https, speed, the basics — set once and correctly: