Key facts
- 'Not secure' in the address bar means the page was loaded over HTTP, not HTTPS
- NET::ERR_CERT_DATE_INVALID means the SSL certificate has expired
- NET::ERR_CERT_COMMON_NAME_INVALID means the certificate does not cover that exact name, often www versus non-www
- Mixed content is an HTTPS page loading images or scripts over HTTP, which removes the padlock
- Free Let's Encrypt certificates are offered by most hosts and renew automatically when set up properly
- Under CA/Browser Forum Ballot SC-081, certificates issued from 15 March 2026 last a maximum of 200 days, falling to 47 days by 2029
- dijitul fixes SSL problems at £45 an hour + VAT
Which warning are you seeing?
There are three different problems that look similar to visitors:
- 'Not secure' next to the address: the page is on http://. Either there is no certificate, or there is one but visitors are not redirected to HTTPS.
- A full-page 'Your connection is not private' warning: the certificate is broken. The code underneath tells you why: ERR_CERT_DATE_INVALID (expired), ERR_CERT_COMMON_NAME_INVALID (wrong name), or ERR_CERT_AUTHORITY_INVALID (self-signed or incomplete chain).
- HTTPS but no padlock, or a warning in the padlock menu: mixed content. The page is secure but some images, fonts or scripts still load over HTTP.
Click the icon left of the address and choose the connection or certificate details to confirm which you have. A free checker such as SSL Labs' server test also shows the expiry date, the names covered and any chain problems.
Fix 1: install or renew the certificate
Most UK hosts offer free Let's Encrypt or AutoSSL certificates in cPanel or Plesk. Make sure the certificate covers both yourdomain.co.uk and www.yourdomain.co.uk. If it fails to issue, the usual reasons are DNS pointing somewhere else, a Cloudflare proxy blocking validation, or a CAA DNS record that does not allow that certificate authority.
Renewals matter more than ever. The CA/Browser Forum's Ballot SC-081 limits certificates issued from 15 March 2026 to 200 days, then 100 days from March 2027 and 47 days from March 2029. Manually installed, paid certificates now need renewing far more often, so automatic renewal is the sensible default for almost every small business site.
Fix 2: force every visitor onto HTTPS
Having a certificate is not enough if the site still answers on HTTP. Add a permanent 301 redirect from http to https, either with your host's 'Force HTTPS' switch, a rule in .htaccess on Apache or LiteSpeed, or in Cloudflare's 'Always Use HTTPS' setting. Pick one place, not several, or you risk a redirect loop ('too many redirects').
In WordPress, go to Settings, General and make sure both the WordPress Address and Site Address start with https://. Once everything works, consider an HSTS header so browsers always use HTTPS, but only after you are sure every subdomain has a valid certificate.
Fix 3: clear out mixed content
Mixed content usually comes from old URLs saved in the database: images in posts, theme settings, page builder data and widgets that still say http://. Press F12 and look at the Console tab; Chrome lists every insecure resource. On WordPress, a database search and replace from http://yourdomain to https://yourdomain fixes most of it. WP-CLI's wp search-replace command handles serialised data safely; never run raw SQL replacements on serialised fields. Take a backup first.
Hard-coded links in theme files, external scripts from old services and embedded forms or maps from providers that do not support HTTPS need fixing or replacing by hand.
After the clean-up, reload key pages with the console open and confirm it is empty of 'Mixed Content' warnings. Check your contact form, checkout and login pages in particular, since browsers treat insecure form submissions most strictly and may warn visitors before they send anything.
When to call dijitul
Call us if the certificate will not issue, you get redirect loops, the warning only shows on some pages, or you are on a host that charges for certificates you do not understand. We fix the certificate, redirects and mixed content in one go and check the site in several browsers, at £45 an hour + VAT. See our SSL certificate support page or get in touch.
On any of our support plans, from £25 a month + VAT, certificate expiry is part of what we keep an eye on alongside uptime and security monitoring, so a lapsed certificate does not quietly put customers off. If the site is completely down rather than showing a warning, start with website down: what to do.
Frequently asked questions
Why does Chrome say my website is not secure?
Chrome marks any page loaded over plain HTTP as 'Not secure', because data sent to it is not encrypted. Either your site has no SSL certificate or visitors are not being redirected to the HTTPS version. Installing a certificate and adding a 301 redirect to HTTPS fixes it.
Does a 'not secure' warning hurt my business?
It puts visitors off, especially on pages with contact or payment forms, and browsers show stronger warnings when a form is on an insecure page. Google has also used HTTPS as a ranking signal for years. It is usually a quick, low-cost fix worth doing straight away.
Are free SSL certificates as good as paid ones?
For most small business websites, yes. A free Let's Encrypt certificate gives the same encryption and padlock as a basic paid certificate. Paid certificates add organisation validation or warranties, which few small sites need. The bigger risk is a certificate that does not renew automatically.
Why does my site have HTTPS but no padlock?
That is mixed content: the page loads over HTTPS but pulls some images, scripts or fonts over HTTP. Open the browser console to list them, then update the URLs, usually with a careful database search and replace. dijitul can fix this for £45 an hour + VAT.
What does NET::ERR_CERT_COMMON_NAME_INVALID mean?
The certificate does not include the exact address visitors typed. Often it covers yourdomain.co.uk but not www.yourdomain.co.uk, or it belongs to the hosting server's own name. Reissue the certificate to include every name the site answers on.
How often do SSL certificates need renewing now?
Under the CA/Browser Forum's Ballot SC-081, certificates issued from 15 March 2026 can last at most 200 days, dropping to 100 days in March 2027 and 47 days in March 2029. Free certificates from hosts already renew automatically; manual paid ones need watching.
Related
Get it fixed
One-off fixes are £45 an hour + VAT. You'll know the likely cost before we start.