How to Install an SSL Certificate on WordPress

Secure WordPress with a free SSL certificate using AutoSSL in cPanel, then force every page to load over HTTPS.

· Updated · 4,023 views

An SSL certificate encrypts traffic and shows the padlock in browsers. On cPanel you can issue a free certificate through AutoSSL and then configure WordPress to use HTTPS everywhere.

Issue the Certificate

  1. In cPanel, open SSL/TLS Status under the Security section.
  2. Confirm your domain shows a valid AutoSSL certificate. If not, select the domain and click Run AutoSSL.
  3. Wait a few minutes for the free Let's Encrypt certificate to be issued.

Update WordPress URLs

  1. Go to Settings > General.
  2. Change both WordPress Address and Site Address from http:// to https://.
  3. Save changes, which logs you out; log back in over HTTPS.

Force HTTPS Everywhere

To redirect all traffic to the secure version, add this to .htaccess above the WordPress block:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]

Fix Mixed Content

After enabling HTTPS, some images or scripts may still load over http://, breaking the padlock. Resolve this by:

  • Running a search-and-replace from http://yourdomain to https://yourdomain in the database.
  • Or installing a plugin like Really Simple SSL to rewrite insecure URLs automatically.

Once the padlock shows on every page, your site is fully secured.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.