WordPress

How to Install a Free SSL Certificate on a WordPress Site

Get the padlock on WordPress and keep it. Enable free SSL in cPanel, fix stored http:// URLs in the database, and clear mixed-content warnings for good.

A WordPress site showing a secure padlock in the browser

Getting an SSL certificate onto WordPress takes about five minutes. Getting the padlock to stay clean takes a little longer, because WordPress stores its own address in the database and copies it into every link and image.

This guide does both: the certificate, and the cleanup afterwards that most tutorials skip.

Why the padlock matters

  • Browsers label HTTP sites "Not secure". On a contact or checkout page, people leave.
  • Logins travel in plain text without it — including your own wp-admin password.
  • Google treats HTTPS as a ranking signal. Small, but it is free.
  • Modern browser features refuse to run on HTTP — camera, microphone, location.

Step 1: Get the certificate

Almost every host now gives one free. Try these in order.

Option A: AutoSSL in cPanel

Open cPanel and look for SSL/TLS Status. Your domains are listed. Select them and press Run AutoSSL. Wait a few minutes and the padlock icon turns green.

This is the easiest route and it renews itself. Try it first.

Option B: Let's Encrypt in cPanel

Some hosts have a Let's Encrypt SSL tool instead. Choose your domain, include the www version, and issue. Also automatic renewal.

Option C: Ask the host

If neither exists, open a support ticket and ask them to enable free SSL. Any decent host does this within the hour. Do not pay for a basic certificate — a paid DV certificate gives a visitor exactly the same padlock as a free one.

Option D: Your own server

Running your own VPS rather than shared hosting? Use Certbot — see how to install a free SSL certificate on Ubuntu.

Check it worked

Open https://yourdomain.com. If the page loads at all over HTTPS, the certificate is installed. The warning triangle comes next.

Step 2: Tell WordPress its new address

This is the part that is specific to WordPress, and the step people miss.

Go to Settings → General and change both fields to https://:

  • WordPress Address (URL)
  • Site Address (URL)

Save. WordPress logs you out. Log back in at the https:// address.

If the fields are greyed out, they are hard-coded in wp-config.php. Edit that file instead:

define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');

Step 3: Fix the old URLs in the database

Every image, internal link and setting you saved before today still says http://. Those old URLs are what cause the warning triangle.

The easy way

Install Better Search Replace. Then:

  1. Tools → Better Search Replace
  2. Search for: http://yourdomain.com
  3. Replace with: https://yourdomain.com
  4. Select all tables
  5. Tick "Run as dry run" first and look at the count it reports
  6. Untick dry run and run it for real

Back up the database before this. A search and replace across every table is not something you want to undo by hand.

Use the full domain, not just http://. Replacing the bare protocol also rewrites links to other websites, which breaks them.

The command-line way

If your host has WP-CLI:

wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tables --dry-run
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tables

This handles serialised data correctly, which a raw SQL query does not. Never run a plain UPDATE ... REPLACE() on wp_options — it corrupts serialised theme settings.

Step 4: Force HTTPS for everyone

The site now works on HTTPS, but the HTTP version is still reachable. Two live copies split your Google ranking and leave an insecure version online.

Add this at the very top of .htaccess, above the WordPress block:

<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
</IfModule>

Test it:

curl -I http://yourdomain.com

You want 301 and a Location: header pointing at the HTTPS address.

Step 5: Clear the remaining mixed content

Still seeing a warning triangle? Something on the page loads over HTTP.

Open the page, press F12, and look at the Console tab. It names every insecure resource. Common culprits:

  • Images pasted with a full http:// URL in a post
  • Theme options holding a logo or background URL
  • Widgets containing hand-written HTML
  • External scripts — fonts, analytics, an embedded map

Fix your own URLs at the source. For an external resource that genuinely has no HTTPS version, replace the service — in 2026 there is no good reason for one to be HTTP-only.

Step 6: Update everything else

Easy to forget, and each one causes a real problem:

  • Google Search Console — the HTTPS site is a separate property. Add it and resubmit the sitemap, or your data quietly stops updating.
  • Google Analytics — update the site URL in the property settings.
  • Cloudflare — set SSL mode to Full (strict). Leaving it on Flexible with a real certificate causes an endless redirect loop.
  • Social profiles and email signatures — update the links.
  • Any Android app pointing at the site — see the WebView guide; Android blocks plain HTTP by default.

Common problems

"Too many redirects" / redirect loop

Almost always Cloudflare set to Flexible SSL while the server also forces HTTPS. Change Cloudflare to Full (strict). Otherwise, check you have not added the redirect rule twice — once in .htaccess and once in a plugin.

The padlock has a warning triangle

Mixed content. Console tab in F12 lists what. See Step 5.

The site loads but the styling is gone

CSS files are being blocked as mixed content. The search and replace in Step 3 usually fixes it. Clear any caching plugin afterwards.

Locked out of wp-admin after switching

The two URLs in Settings disagree. Set both in wp-config.php using the WP_HOME and WP_SITEURL lines above.

The certificate expired

AutoSSL usually renews on its own. If it stopped, run AutoSSL manually and check the domain still points at this server — expired DNS is the usual reason renewal fails silently.

Only some pages show the padlock

Those pages contain hard-coded HTTP links. Search and replace catches most; the rest are in theme or widget settings.

Do I need a plugin for this?

Plugins like Really Simple SSL work, and they are a reasonable choice if you are uncomfortable editing files. They rewrite insecure URLs as the page loads.

But that is a patch, not a fix — the database still holds http:// everywhere, and the rewriting costs a little performance on every request. If you ever remove the plugin, the problem comes straight back.

Doing it properly once, as above, is better. Use the plugin as a temporary measure if you must, then do the real cleanup and remove it.

Where to go next

Questions people ask

Is free SSL as good as a paid certificate?
For an ordinary website, yes. A free Let's Encrypt certificate gives visitors exactly the same padlock and the same encryption as a paid DV certificate. Paid certificates only add things most sites never need, such as organisation validation or a warranty.
Why does my WordPress site still show "Not secure" after installing SSL?
The certificate is installed but WordPress still thinks its address is http. Change both URLs in Settings then General to https, then run a search and replace across the database to update the old links stored in your content.
What is mixed content and how do I fix it?
Mixed content means the page loads over HTTPS but something on it — an image, script or stylesheet — is still requested over HTTP, so the browser shows a warning triangle. Press F12 and open the Console tab; it lists every insecure resource by URL.
Why do I get "too many redirects" after enabling SSL?
Almost always Cloudflare set to Flexible SSL while your server also forces HTTPS, which creates a loop. Change the Cloudflare SSL mode to Full (strict). Also check you have not added the redirect rule twice.
How do I update old http links in the WordPress database?
Use the Better Search Replace plugin, or WP-CLI search-replace. Search for your full http URL and replace with the https version, across all tables, and run a dry run first. Back up the database before you start.
Can I just use the Really Simple SSL plugin?
It works, but it is a patch rather than a fix. It rewrites insecure URLs as each page loads, so the database still holds http everywhere and there is a small cost on every request. If you remove the plugin, the problem returns immediately.
Do I need to tell Google Search Console about the change?
Yes. The https version counts as a separate property. Add it in Search Console and resubmit your sitemap, otherwise your reporting quietly stops updating while you assume everything is fine.
Why is my site styling broken after switching to HTTPS?
The CSS files are being blocked as mixed content. Run the database search and replace, then clear your caching plugin — a cached copy of the old page will keep showing the broken version.
How do I force all visitors onto HTTPS?
Add a rewrite rule at the very top of .htaccess, above the WordPress block, that redirects when HTTPS is off. Test it with curl -I on the http address and confirm you get a 301 with a Location header.
What if my host does not offer free SSL?
Open a support ticket and ask — most enable it within the hour. If they refuse or charge for basic SSL, that is a strong reason to change host, because free automatic SSL has been standard for years.

Written by Habib Baloch

I build Android apps, websites and Ubuntu servers, and write down exactly how I did it.

Ask me about this guide →