How to Install a Free SSL Certificate on a WordPress Site
Get the padlock on WordPress and keep it. Enable free SSL in cPanel, fix stored http:// URLs in the database, and clear mixed-content warnings for good.
Getting an SSL certificate onto WordPress takes about five minutes. Getting the padlock to stay clean takes a little longer, because WordPress stores its own address in the database and copies it into every link and image.
This guide does both: the certificate, and the cleanup afterwards that most tutorials skip.
Why the padlock matters
- Browsers label HTTP sites "Not secure". On a contact or checkout page, people leave.
- Logins travel in plain text without it — including your own wp-admin password.
- Google treats HTTPS as a ranking signal. Small, but it is free.
- Modern browser features refuse to run on HTTP — camera, microphone, location.
Step 1: Get the certificate
Almost every host now gives one free. Try these in order.
Option A: AutoSSL in cPanel
Open cPanel and look for SSL/TLS Status. Your domains are listed. Select them and press Run AutoSSL. Wait a few minutes and the padlock icon turns green.
This is the easiest route and it renews itself. Try it first.
Option B: Let's Encrypt in cPanel
Some hosts have a Let's Encrypt SSL tool instead. Choose your domain, include the www version, and issue. Also automatic renewal.
Option C: Ask the host
If neither exists, open a support ticket and ask them to enable free SSL. Any decent host does this within the hour. Do not pay for a basic certificate — a paid DV certificate gives a visitor exactly the same padlock as a free one.
Option D: Your own server
Running your own VPS rather than shared hosting? Use Certbot — see how to install a free SSL certificate on Ubuntu.
Check it worked
Open https://yourdomain.com. If the page loads at all over HTTPS, the certificate is installed. The warning triangle comes next.
Step 2: Tell WordPress its new address
This is the part that is specific to WordPress, and the step people miss.
Go to Settings → General and change both fields to https://:
- WordPress Address (URL)
- Site Address (URL)
Save. WordPress logs you out. Log back in at the https:// address.
If the fields are greyed out, they are hard-coded in wp-config.php. Edit that file instead:
define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');
Step 3: Fix the old URLs in the database
Every image, internal link and setting you saved before today still says http://. Those old URLs are what cause the warning triangle.
The easy way
Install Better Search Replace. Then:
- Tools → Better Search Replace
- Search for:
http://yourdomain.com - Replace with:
https://yourdomain.com - Select all tables
- Tick "Run as dry run" first and look at the count it reports
- Untick dry run and run it for real
Back up the database before this. A search and replace across every table is not something you want to undo by hand.
Use the full domain, not just http://. Replacing the bare protocol also rewrites links to other websites, which breaks them.
The command-line way
If your host has WP-CLI:
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tables --dry-run
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tables
This handles serialised data correctly, which a raw SQL query does not. Never run a plain UPDATE ... REPLACE() on wp_options — it corrupts serialised theme settings.
Step 4: Force HTTPS for everyone
The site now works on HTTPS, but the HTTP version is still reachable. Two live copies split your Google ranking and leave an insecure version online.
Add this at the very top of .htaccess, above the WordPress block:
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
</IfModule>
Test it:
curl -I http://yourdomain.com
You want 301 and a Location: header pointing at the HTTPS address.
Step 5: Clear the remaining mixed content
Still seeing a warning triangle? Something on the page loads over HTTP.
Open the page, press F12, and look at the Console tab. It names every insecure resource. Common culprits:
- Images pasted with a full http:// URL in a post
- Theme options holding a logo or background URL
- Widgets containing hand-written HTML
- External scripts — fonts, analytics, an embedded map
Fix your own URLs at the source. For an external resource that genuinely has no HTTPS version, replace the service — in 2026 there is no good reason for one to be HTTP-only.
Step 6: Update everything else
Easy to forget, and each one causes a real problem:
- Google Search Console — the HTTPS site is a separate property. Add it and resubmit the sitemap, or your data quietly stops updating.
- Google Analytics — update the site URL in the property settings.
- Cloudflare — set SSL mode to Full (strict). Leaving it on Flexible with a real certificate causes an endless redirect loop.
- Social profiles and email signatures — update the links.
- Any Android app pointing at the site — see the WebView guide; Android blocks plain HTTP by default.
Common problems
"Too many redirects" / redirect loop
Almost always Cloudflare set to Flexible SSL while the server also forces HTTPS. Change Cloudflare to Full (strict). Otherwise, check you have not added the redirect rule twice — once in .htaccess and once in a plugin.
The padlock has a warning triangle
Mixed content. Console tab in F12 lists what. See Step 5.
The site loads but the styling is gone
CSS files are being blocked as mixed content. The search and replace in Step 3 usually fixes it. Clear any caching plugin afterwards.
Locked out of wp-admin after switching
The two URLs in Settings disagree. Set both in wp-config.php using the WP_HOME and WP_SITEURL lines above.
The certificate expired
AutoSSL usually renews on its own. If it stopped, run AutoSSL manually and check the domain still points at this server — expired DNS is the usual reason renewal fails silently.
Only some pages show the padlock
Those pages contain hard-coded HTTP links. Search and replace catches most; the rest are in theme or widget settings.
Do I need a plugin for this?
Plugins like Really Simple SSL work, and they are a reasonable choice if you are uncomfortable editing files. They rewrite insecure URLs as the page loads.
But that is a patch, not a fix — the database still holds http:// everywhere, and the rewriting costs a little performance on every request. If you ever remove the plugin, the problem comes straight back.
Doing it properly once, as above, is better. Use the plugin as a temporary measure if you must, then do the real cleanup and remove it.