Why does my website say not secure?
- hosting
- tls
- certificates
- maintenance
You usually hear about it from a customer. Somebody rings to book, mentions in passing that your website “says it’s not safe”, and you open it on your phone and there it is, grey text next to the address: Not secure.
The first thing worth knowing is what the browser is actually complaining about. It is not saying your site has been hacked. It is saying the connection between the visitor and your server is not protected, or that the certificate meant to protect it is missing, out of date or made out for a different name. That is a narrower problem, and usually one that can be fixed the same day.
I look after small business websites for a living, most of them built by somebody else, and when one of them shows this warning it is almost always one of four things.
One: the site was never on HTTPS at all
Chrome started labelling every plain HTTP page “Not secure” in July 2018, with Chrome 68. Google announced it five months earlier on the Chromium blog, so nobody was ambushed.
Eight years on I still meet sites that were built before that, or built cheaply after it, and have simply never had a certificate. The site works. Nothing is broken in the sense the owner would recognise. The browser has just been telling every visitor for years that the page is unprotected, and anyone typing into the contact form is sending it across the internet in the clear.
This is the easiest of the four to fix. A certificate costs nothing from Let’s Encrypt, and setting one up plus a redirect from HTTP to HTTPS is an afternoon’s work on a server you can get into.
Two: the certificate expired
This one looks different. Instead of grey text in the address bar, the visitor gets a full-page warning before the site loads at all, and most of them close the tab.
Certificates expire by design, and nearly every host now renews them automatically. The failure is that automatic renewal stops working without telling anybody. A DNS record gets moved, a firewall rule changes, a renewal script points at a folder somebody tidied away. The old certificate keeps working for weeks, so nothing looks wrong on the day the fault appears. I wrote about that delay in more detail in what the care plan actually covers, because it is the main reason “renews automatically” and “gets checked” are two separate promises.
There used to be a safety net here. Let’s Encrypt emailed you when a certificate was close to expiring. They stopped on 4 June 2025, having announced it that January, and their reason was fair: most people had automation by then, and keeping millions of email addresses tied to certificate records sat badly with their privacy position. But it means a site whose renewal quietly broke no longer gets a warning in anybody’s inbox first. The customer is the warning.
Three: the certificate is for the wrong name
Your site might answer on www.yourbusiness.co.uk and on yourbusiness.co.uk. Those are two names. If the certificate only covers one of them, the other throws a warning, and which one a customer sees depends on what they typed or which old link they clicked.
The same thing happens after a move. The domain gets pointed at a new host, the old certificate is still sitting on the old server for a name that no longer lives there, and for a few confused days both machines claim to be your website.
Four: the page is secure, but something on it is not
This is the fiddly one. The page itself arrives over HTTPS with a valid certificate, but it pulls something in over plain HTTP: an image hard-coded years ago, an old embedded widget, or a form that submits to an http:// address. Browsers either block the insecure piece, which breaks the page in some odd small way, or they downgrade the padlock and warn. Either way, the owner sees a site that mostly works and has no idea why the browser is unhappy.
Finding it means reading the page source or the browser’s developer console. Fixing it means changing each old address, which on a site built by somebody else can be scattered through a theme, a plugin setting and a database field all at once.
How to tell which one you have
Two minutes, no technical skill needed.
Click the icon to the left of the web address and open the certificate details. If there is no certificate at all, it is number one. If there is one, look at the expiry date, then look at the name it was issued to and compare it with what is in the address bar. Then try your site with and without the www and see whether both behave the same.
If the certificate is in date, the name matches and the warning is still there, it is probably number four, and that is the point to hand it to somebody who can read the page source.
This is going to happen more often, not less
Until March this year a publicly trusted certificate could last up to 398 days. The CA/Browser Forum, the body where the certificate authorities and the browser makers agree the rules, voted on 11 April 2025 to shrink that in stages. Certificates issued from 15 March 2026 can last 200 days at most. From 15 March 2027 the limit drops to 100 days. From 15 March 2029 it is 47.
That is the end of the arrangement a lot of small businesses still have, where somebody buys a certificate once a year from a reseller and pastes it in by hand. At 47 days, a manual renewal is a job you do eight times a year, and one missed reminder takes the site down. If your certificate is renewed by a person rather than by software, I would change that now, while the limit is still 200 days and there is time to do it calmly.
What I do about it
It is part of the website care plan: £49 a month, no minimum term, and it does not matter whether I built the site. The certificate renews automatically and I also check it, uptime monitoring tells me when the site goes down before a customer does, and taking a site over starts with reading it, which is where numbers one, three and four usually turn up.
I should be clear about the limits.
The padlock only means the connection is private. It says nothing about whether the site itself is any good, and a certificate on a neglected site is still a neglected site.
If the warning is red and says something like “Deceptive site ahead”, that is not a certificate problem. It means Google has flagged the site as harmful, which usually means somebody has got into it, and cleaning up after that is separate work I would want to look at before quoting.
And I can only fix a certificate for a name I can point. If nobody can get into the account where your domain is registered, that has to be solved first, and I have written about how that tends to go when you move a site.
If your site is showing the warning today, send me the address. I will tell you which of the four it is.
