We build Next.js, Shopify, Laravel, Flutter, in Noida, India. Free 1-page audit, no obligation.
Get a free quote- Website Development Quotation: Format and Sample (2026)September 28, 2026
- DLT Template Rejected? Fixes and Samples That Pass (2026)September 27, 2026
- Unified Bharat e-Charge (UBC), Explained for EV OperatorsSeptember 25, 2026
- AI Chatbot Development Cost in India (2026): Build and RunSeptember 25, 2026
Website Says "Not Secure" in Chrome? How to Fix It (2026)
Over the last two days we looked at the websites of small businesses across India before writing to any of them: clinics, coaching institutes, a CA practice, a preschool. The most common problem wasn't speed and it wasn't design. It was two words at the left of the address bar: Not secure.
What surprised me is how many of those sites already had an SSL certificate. They just weren't using it. The fix was sitting in the hosting panel the whole time, one toggle away. So this is the guide I'd send any owner who has seen that warning on their own site and wondered whether it matters, whether they've been hacked, and what it should cost to fix.
What "Not secure" actually means
Chrome shows "Not secure" when a page loads over plain http instead of https. Everything between the visitor's phone and your server travels unencrypted, so anyone on the same Wi-Fi, or anywhere along the way, can read it or change it. It does not mean your site has been hacked. It means the connection isn't protected.
To a visitor, though, it reads as "don't trust this". It gets worse the moment they tap into a form: Chrome repeats the warning next to the field they're typing their phone number into. For a clinic or a CA firm, whose whole pitch is trust, that's a strange first impression to give.
Two other warnings get mixed up with it, and they're different problems. A full-page red screen saying "Your connection is not private" means there is a certificate but something is wrong with it, usually that it has expired or doesn't cover the address you typed. That one is worse, because most people close the tab. And an https page that loads fine but whose site information says parts of the page aren't secure has mixed content, which we'll get to.
Why it matters more in 2026 than it used to
Google said in late 2025 that Chrome would start turning on its "Always Use Secure Connections" setting by default, with Chrome 154 around October 2026. With that setting on, Chrome asks the visitor for permission before opening a public site over plain http. Instead of a small grey label, some of your visitors will get an interruption they have to click through. Plenty won't bother.
The second change is quieter. The industry body that sets the rules for certificates voted to shorten how long one can last. From 15 March 2026 the maximum is 200 days, dropping to 100 days in March 2027 and 47 days by March 2029. If your SSL is a paid certificate that someone renews once a year from a calendar reminder, that routine no longer works. Renewal has to be automatic, or it will lapse, and a lapsed certificate gives you the red full-page warning rather than the grey label.
Google has also used https as a ranking signal since 2014. It's a light one and it won't rescue a thin page. The bigger cost is simpler than rankings: people who land on your site and leave.
Check your own site in two minutes
- Open a private window and type your address starting with http:// rather than https://. If the address bar stays on http, you have the most common problem on this page.
- Try it with and without www. Both versions should end up on the same https address.
- Click the small icon to the left of the address. Chrome replaced the padlock with a settings-style icon in 2023, so don't go looking for a lock. The panel that opens should say the connection is secure.
- If you're comfortable with it, press F12, open the Console tab and reload. Any line that starts with "Mixed Content" is an http image, script or font on an https page.
If you or your developer are happy with a terminal, one line tells you whether the redirect exists:
bashcurl -sI http://example.com | head -3
# what you want to see:
HTTP/1.1 301 Moved Permanently
Location: https://example.com/A 200 on the http address means the redirect isn't there. A 302 means there is one but it's marked temporary, which is worth fixing too, because Google treats a permanent 301 as the signal to move your rankings over to the https address.
The four causes we keep finding
1. The certificate is there, the redirect isn't
This is the one we saw most. The host issued a free certificate when the site was set up, so https works if you type it. Nobody ever switched on the redirect, so every old link, every visiting card printed with http://, and every visitor who types the address without https lands on the insecure version.
2. The certificate covers one name and not the other
The certificate was issued for example.com but visitors arrive at www.example.com, or the other way round. Chrome shows the full-page warning with an error ending in COMMON_NAME_INVALID. It often appears after a domain moves between providers and only one name gets set up again.
3. The certificate expired
Usually a paid certificate bought from a reseller with no auto-renew, or a free one whose automatic renewal started failing quietly after someone changed the DNS. Nothing warns you until visitors do, and most of them don't. They just leave.
4. Mixed content
The page itself is https, but it pulls images, scripts or fonts over http. This is nearly always WordPress after a move from http to https, where the old addresses are still written into posts, theme settings or page-builder layouts. Chrome upgrades some of these requests and blocks others, so the symptom can be a missing image, a broken slider or a contact form that quietly stops sending.
How to fix each one
Get a certificate, and a free one is fine
Let's Encrypt certificates are free, trusted by every browser, and renew themselves. Most hosts used in India issue one from the control panel, often under a menu called SSL or AutoSSL. A paid certificate doesn't make Chrome show anything different; the green company-name bar that paid certificates used to buy was removed back in 2019. If a reseller is offering to sell you a certificate as the fix for "Not secure", check first whether your host already gives you one for nothing.
Force the redirect
Many hosting panels have a "Force HTTPS" switch next to the certificate. If yours doesn't and the site runs on Apache, which most shared hosting does, these three lines at the top of the .htaccess file send every http request to https with a permanent redirect:
apacheRewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]On nginx it's a separate server block that listens on port 80 and does nothing else:
nginxserver {
listen 80;
server_name example.com www.example.com;
return 301 https://example.com$request_uri;
}If the domain runs through Cloudflare, the setting is called Always Use HTTPS. Whichever route you take, make it a 301, and send both www and non-www to the one address you want Google to show.
WordPress needs two more steps
- Under Settings, General, change both the WordPress Address and the Site Address to start with https. Take a backup first; a typo here can lock you out of the admin.
- Replace the old http addresses stored in the database. A search-and-replace plugin such as Better Search Replace does it in a few minutes; run it as a dry run first and read what it plans to change.
- Page builders like Elementor keep their own generated CSS files. Regenerate them, clear any caching plugin, then reload the site with the Console open and confirm the Mixed Content lines are gone.
Cover both names, then pick one
Ask for a certificate that includes both example.com and www.example.com; most panels do this by default if both names already point at the server. Then choose one as the real address and redirect the other to it, so there's a single version of every page for Google to index.
Make renewal something nobody has to remember
Confirm in the panel that auto-renew is on. If you're on a paid certificate with a yearly renewal, the 200-day limit means it's time to move to the host's free, automatically renewed one. And set up any uptime monitor that checks certificate expiry, so you hear about a failed renewal a couple of weeks before your visitors do.
Add HSTS last, not first
HSTS is a header that tells browsers to only ever use https for your domain. It's worth having, but add it after the site has run cleanly on https for a few weeks. It tells browsers to remember the rule for months, so if something breaks on https afterwards, you can't simply switch back to http while you fix it.
Tell Google about the move
Redirects do most of the work on their own, but a few minutes here saves weeks of waiting. In Search Console, a domain property covers http, https, www and non-www together, so use that if you set one up. Resubmit the sitemap with https addresses. Update the website link on your Google Business Profile and your social profiles, and any internal links that still point at http. Rankings carry across with 301 redirects; a week or two of movement afterwards is normal.
What it should cost to fix
If the host already provides free SSL, fixing the first three causes is usually under an hour of work. A WordPress site with a lot of mixed content can take a few hours, mostly spent finding where the old addresses are hiding. None of it needs a new website. If someone quotes you a redesign to get rid of "Not secure", get a second opinion, because that's a settings job, not a rebuild.
It's also the kind of problem that tends to come with company. A site with no redirect often has an old copyright year in the footer, an out-of-date WordPress version and a slow first load. That's what our website maintenance guide is about, and why we'd rather check the whole site once than fix one warning and leave the rest.
Not sure which of the four your site has? Send us the address and we'll check it and tell you, free, whether it's a ten-minute fix or something bigger.
Get a free site checkFrequently asked questions
Does "Not secure" mean my website has been hacked?
Do I need to buy an SSL certificate?
Why does my site still say "Not secure" when I already have SSL?
Will moving from http to https hurt my Google rankings?
How often does an SSL certificate need renewing now?
Founder of buildbyravirai, a web development agency based in Noida, India. 5+ years shipping Next.js, WordPress, Shopify, and Laravel projects for clients in India, USA, Canada, and the UK.
Working with us in your city
Keep Reading
Website Development Quotation: Format and Sample (2026)
What a website development quotation in India should contain, a sample format you can copy, fair 2026 prices, and how to compare three quotes.
Website Security for Indian Businesses 2026: The Basics That Actually Stop Most Attacks
The plain-language guide to website security basics for Indian business owners in 2026: what actually attacks your site, and the few things that protect it.
AI Website Builders vs Hiring a Developer in India 2026: The Honest Take
AI can build a website in two minutes, so why pay a developer? The honest answer: what AI website builders are good at, where they fall apart, and the hidden costs.
Website Maintenance & AMC Cost in India 2026: What You Actually Pay For
A website is not a one-time purchase. The honest guide to what website maintenance and an AMC cost in India in 2026, what is included, and when you need a plan.
DLT Template Rejected? Fixes and Samples That Pass (2026)
Why DLT SMS templates get rejected or fail with "template not found" in 2026, the pre-tagging rules behind it, and sample templates that get approved.