An SSL certificate encrypts traffic and shows the padlock in browsers. On cPanel you can issue a free certificate through AutoSSL and then configure WordPress to use HTTPS everywhere.
Issue the Certificate
- In cPanel, open SSL/TLS Status under the Security section.
- Confirm your domain shows a valid AutoSSL certificate. If not, select the domain and click Run AutoSSL.
- Wait a few minutes for the free Let's Encrypt certificate to be issued.
Update WordPress URLs
- Go to Settings > General.
- Change both WordPress Address and Site Address from
http://tohttps://. - Save changes, which logs you out; log back in over HTTPS.
Force HTTPS Everywhere
To redirect all traffic to the secure version, add this to .htaccess above the WordPress block:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]
Fix Mixed Content
After enabling HTTPS, some images or scripts may still load over http://, breaking the padlock. Resolve this by:
- Running a search-and-replace from
http://yourdomaintohttps://yourdomainin the database. - Or installing a plugin like Really Simple SSL to rewrite insecure URLs automatically.
Once the padlock shows on every page, your site is fully secured.