The "Not Secure" label appears in the browser address bar when a page is loaded over plain HTTP instead of HTTPS, or when an SSL certificate is missing, expired, or misconfigured. Fixing it restores trust and protects visitor data.
Common Causes
- No SSL certificate is installed for the domain.
- The certificate has expired.
- The site loads over HTTP because HTTPS is not forced.
- The page pulls images or scripts over insecure HTTP (mixed content).
- The certificate does not match the domain name.
Step-by-Step Fix
- In cPanel, open SSL/TLS Status and run AutoSSL to issue a free certificate.
- Wait for the green padlock to appear next to your domain.
- Force HTTPS using the cPanel Force HTTPS Redirect toggle.
- Reload your site over
https://and check the padlock.
Diagnose the Exact Problem
Click the warning in the address bar and read the message:
| Message | Meaning | | --- | --- | | No certificate | SSL not installed | | Certificate expired | Renewal needed | | Not fully secure | Mixed content present | | Name mismatch | Certificate is for another domain |
Clear Lingering Warnings
After installing the certificate:
- Clear your browser cache or test in a private window.
- Check both
wwwand non-wwwversions are covered. - Scan the page source for
http://links and update them tohttps://.
If AutoSSL cannot issue a certificate, confirm your domain's DNS points to the correct server. A misdirected domain will always fail validation. For assistance, reach support on WhatsApp at +254 796 358081.