Once you have an SSL certificate installed, you should force every request to use HTTPS. Otherwise visitors can still reach the insecure http:// version, which shows a "Not Secure" warning and weakens your security.
Use the cPanel Toggle
The easiest method requires no editing:
- Log in to cPanel.
- Open Domains under the Domains section.
- Find your domain in the list.
- Switch the Force HTTPS Redirect toggle to on.
This adds a server-level redirect for that domain immediately.
Force HTTPS with .htaccess
If your hosting setup does not show the toggle, add a redirect rule to the .htaccess file in your public_html folder. Place these lines at the top, above any existing WordPress rules:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
The R=301 flag makes the redirect permanent, which is best for SEO.
Update Your Site Settings
A redirect alone is not always enough:
- In WordPress, set both the Site Address and WordPress Address to
https://under Settings, General. - Update any hardcoded
http://links in your theme or content. - Update the canonical URL in any SEO plugin.
Verify the Redirect
- Open a private browser window.
- Type the plain
http://yourdomain.comaddress. - Confirm the browser jumps to
https://automatically. - Test a few internal pages too.
If the redirect loops endlessly, your application may already be forcing HTTPS on its own. Remove one of the duplicate redirects so they do not conflict.