Skip to content

How to Secure WordPress with SSL and HTTPS

0
667
How to Secure WordPress with SSL and HTTPS
HTTPS is no longer an upgrade you bolt on to a WordPress site — it is the baseline. Every mainstream browser marks plain http:// pages as "Not secure", payment gateways refuse to operate without it, and Google has treated it as a ranking signal for years. If you run a WordPress site of any kind, and especially an eCommerce site, the question is not whether to use HTTPS but whether yours is configured correctly end to end. The good news is that the hard part — obtaining and renewing a certificate — is now free and automatic on essentially every reputable host. This guide covers how TLS works at a high level, how to get a certificate, how to migrate an existing site from HTTP to HTTPS without breaking it, and how to track down the mixed-content warnings that keep the padlock from appearing. TLS (Transport Layer Security) is the protocol that encrypts traffic between a visitor's browser and your web server. You will still see it called SSL, its long-obsolete predecessor, in host control panels and plugin names; the name stuck even though every current implementation is TLS. HTTPS is simply HTTP carried over TLS. It connects on port 443, while unencrypted HTTP uses port 80. Encryption does two jobs at once. It stops anyone between your visitor and your server — a compromised router, a hostile Wi-Fi network, an ISP injecting adverts — from reading or altering the traffic. And the certificate itself proves the server really does belong to your domain, so a visitor cannot be silently redirected to an impostor.

Why HTTPS is mandatory in practice

There are a few situations where running without HTTPS is not merely inadvisable but impossible:
  • Payments. If you run an online store or an eCommerce website on WordPress, your payment gateway will require HTTPS on the checkout flow. Card details sent over HTTP can be read by anyone on the network path.
  • Logins. Any site with a login form — which includes every WordPress site, since /wp-login.php always exists — is sending a password over the wire. Without TLS that password is readable in transit.
  • Personal and health data. If you are using WordPress for a health or medical practice and taking appointment bookings, or collecting donations, the data protection regimes that apply to you assume transport encryption as a minimum.
  • Modern browser features. Geolocation, service workers, the clipboard API and HTTP/2 and HTTP/3 are all gated behind a secure context. On HTTP they simply do not run.
Contrary to a lot of older advice, none of this requires your visitors to download or install anything. A correctly configured certificate is invisible to them. If you are also collecting data through forms, make sure the form plugin submits to an HTTPS endpoint. Formidable Forms is a capable option for building the more complex, conditional forms that tend to collect sensitive information, and it handles that correctly out of the box.

How to get a TLS certificate

For the overwhelming majority of WordPress sites, the answer is: you already have one, or you can enable it with one click, at no cost. Let's Encrypt issues free, automatically renewing domain-validated certificates, and it is integrated into cPanel, Plesk, RunCloud, and every managed WordPress host worth using. If a host still wants to sell you a basic DV certificate for an annual fee, treat that as a signal about the host. We have a step-by-step walkthrough if you want to do it by hand: install a free SSL certificate using Let's Encrypt. There are three certificate types, and the distinction matters less than vendors imply:
  • Domain Validation (DV) proves you control the domain. It is free, issued in seconds, and gives you exactly the same encryption strength as the expensive options. This is what almost every site should use.
  • Organisation Validation (OV) adds a manual check of your company's registration details. Worth considering only if a compliance framework or enterprise customer specifically demands it.
  • Extended Validation (EV) once produced a green company name in the address bar. Browsers removed that indicator years ago, so an EV certificate now looks identical to a free one to your visitors.

Managed WordPress hosts

Free, automatically renewed certificates are now table stakes among managed hosts. WP Engine, Bluehost, HostGator and InMotion Hosting all include one with their WordPress plans, as do DreamHost, Kinsta, SiteGround and Cloudways, and all of them will also install a certificate you bought elsewhere. Our WordPress hosting comparison covers how the rest of their feature sets stack up. Most managed platforms also expose a "Force HTTPS" or "Redirect to HTTPS" switch in their own dashboard. Use it in preference to hand-editing rewrite rules — it runs at the edge, before WordPress boots, and it will not be wiped out the next time a plugin rewrites your .htaccess.

If you specifically need a paid certificate

Wildcard certificates covering unlimited subdomains, or certificates with a warranty and formal support attached, are still sold by commercial certificate authorities. SSL2BUY resells across most of the major authorities, and GoDaddy, Sectigo (formerly Comodo), DigiCert and GeoTrust sell direct. Note that Let's Encrypt and ZeroSSL both issue free wildcard certificates as well, via DNS validation, so check whether you actually need to buy one before you do.

Migrating an existing site from HTTP to HTTPS

A new site is trivial: install the certificate first, then install WordPress, and every URL it generates will already be https://. Moving a site that has been running on HTTP for years takes more care, because thousands of absolute http:// URLs are sitting in your database inside post content, widget options and serialised theme settings. Work through it in this order. 1. Install and verify the certificate. Load https://yourdomain.com directly and confirm it resolves without a certificate error before you change anything in WordPress. If it errors here, stop and fix it — everything below assumes a working certificate. 2. Take a full backup. Database and files. The URL rewrite in step 4 touches your entire database and you want to be able to undo it. 3. Update the two WordPress URL settings. Under Settings → General, change WordPress Address (URL) and Site Address (URL) from http://yourdomain.com to https://yourdomain.com. If those fields are greyed out, they are being set by WP_HOME and WP_SITEURL constants in wp-config.php; edit them there instead. 4. Rewrite the URLs inside your content. This is the step people skip, and it is the reason the padlock does not appear afterwards. If you have WP-CLI available — every decent host provides it — this is the safest option because it handles serialised data correctly:
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tables --precise --dry-run
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tables --precise
Run it with --dry-run first and read the report. If you would rather work in the dashboard, Better Search Replace does the same job, including serialised data, and has a dry-run mode of its own. It is actively maintained and tested against current WordPress. A note if you are following an older tutorial: Velvet Blues Update URLs was the tool usually recommended for this, but it was closed on the WordPress plugin directory in May 2024 over a security issue and can no longer be installed. Use one of the two options above instead. 5. Redirect HTTP to HTTPS. Prefer your host's force-HTTPS toggle. If you are on your own Apache server and need to do it in .htaccess, place this above the # BEGIN WordPress block:
<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteCond %{HTTPS} !=on
  RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]
</IfModule>
On nginx, the equivalent belongs in your server block:
server {
  listen 80;
  server_name yourdomain.com www.yourdomain.com;
  return 301 https://$host$request_uri;
}
If your site sits behind a reverse proxy or CDN such as Cloudflare, check %{HTTP:X-Forwarded-Proto} rather than %{HTTPS}, or you will create a redirect loop. 6. Force HTTPS in the admin area. Add this to wp-config.php, above the /* That's all, stop editing! */ line:
define( 'FORCE_SSL_ADMIN', true );
If an older guide told you to also set FORCE_SSL_LOGIN, ignore it. That constant was deprecated and removed in WordPress 4.0; FORCE_SSL_ADMIN now covers both the login screen and the dashboard. Make sure you type straight quotes — some tutorials have had curly quotes pasted into them over the years, which is a PHP syntax error and will take your site down. 7. Tell Google. Add the https:// property in Search Console and submit your sitemap again. Update the site URL in Google Analytics, and in any third-party service that calls back into your site.

Fixing mixed content

Mixed content is the usual reason a migrated site shows a broken padlock rather than a closed one: the page itself came over HTTPS, but an image, script or stylesheet on it was requested over HTTP. Browsers block active mixed content (scripts, iframes) outright and warn about passive mixed content (images, media). Find the offenders first. Open your browser's developer console on the affected page — it names every insecure request explicitly, which is faster than guessing. Step 4 above resolves the great majority of them, because most are absolute URLs stored in your own content. What remains is usually hard-coded http:// URLs inside a theme or plugin, or assets loaded from a third party that has no HTTPS version. For those, SSL Insecure Content Fixer is the targeted tool: it rewrites insecure requests at several configurable levels, from a light content filter up to full output buffering. It is actively maintained and tested against current WordPress. Start at the lowest setting that works, because the heavier levels cost performance. If you would rather have one plugin handle the certificate detection, the redirect and the mixed content together, Really Simple Security (previously Really Simple SSL) is the well-maintained all-in-one choice, and it is updated frequently against current WordPress releases. It is genuinely useful on shared hosting where you do not control the server configuration. On a managed host where you can force HTTPS at the platform level and run a proper search-replace, you do not need it — doing the migration properly leaves you with nothing for it to fix. Whichever route you take, treat a mixed-content plugin as a patch over URLs that are wrong in the database, not as a substitute for correcting them.

Plugins this guide used to recommend, and why they are gone

This article has been published for a long time, and the plugin landscape around SSL has not aged well. Three tools it previously recommended have since been pulled from the WordPress plugin directory. If you followed this guide years ago and any of them are still installed, uninstall them:
  • WordPress HTTPS (SSL) — closed on the plugin directory on 13 June 2022, with the stated reason being a security issue. It cannot be installed and will never receive another update. This is the most important one to remove: it was widely installed, and an unmaintained plugin whose job is to handle your site's TLS behaviour is a genuinely bad thing to leave running.
  • WPSSL (WordPress with SSL) — closed on 23 October 2018 for a guideline violation. It was built for WordPress 3.x and forced per-page HTTPS, a pattern that has no reason to exist now that whole-site HTTPS is free.
  • Admin SSL — still listed, but its last release was in April 2011 and it declares compatibility only up to WordPress 3.1. Everything it did is now covered by the single FORCE_SSL_ADMIN constant shown above. Do not install it.
The general lesson is worth stating plainly: with security tooling, an abandoned plugin is worse than no plugin. It keeps its hooks into your authentication and request handling while nobody is left to fix it when something is found. Before installing anything security-related, check the "Last updated" and "Tested up to" fields on its plugin directory page.

Restricting content behind a secure checkout

Restrict Content Pro — Stripe Payment Gateway

Restrict Content Pro Stripe Payment Gateway If you are selling memberships rather than products, this add-on keeps subscribers on your own site for the entire registration and payment flow instead of bouncing them to an external gateway. Card details are tokenised by Stripe and never stored on your server. This only works if HTTPS is already in place across the site. A payment form on an HTTP page will be blocked by the browser, and Stripe will refuse the request. More Info & Download

After HTTPS: the rest of the checklist

Transport encryption protects data in transit. It does nothing about a vulnerable plugin, a weak administrator password, or a compromised file on disk — if malicious code is already running on your site, the fact that it is served over HTTPS is irrelevant. Once the padlock is in place, the work that actually moves the needle is:
  • Enable automatic updates for WordPress core, plugins and themes, and delete anything you are not using.
  • Use a password manager for administrator accounts and turn on two-factor authentication.
  • Keep offsite backups you have actually tested restoring from.
  • Rate-limit and monitor login attempts.
For the monitoring and firewall side, Wordfence Security and Sucuri Security are both actively maintained and tested against current WordPress. Sucuri also sells a managed website firewall and cleanup service if you would rather someone else watched it for you. Pick one firewall plugin, not several — they hook the same requests and fight each other.

Wrap up

Getting HTTPS onto a WordPress site in 2026 is a much shorter job than this article's length suggests, because the expensive, fiddly part went away: certificates are free and renew themselves. What is left is doing the migration carefully — certificate first, then the two URL settings, then a proper database search-replace, then the redirect — and resisting the urge to paper over the leftovers with a plugin. And if you are working from an older SSL tutorial, check the plugins it names against the directory before you install them. Several of the ones that dominated this space for a decade are now closed, some of them for security issues. If you need a hand setting up HTTPS, ask in the comments below.
Editorial StaffE
WRITTEN BY

Editorial Staff

Editorial Staff at WPArena is a team of WordPress experts led by Jazib Zaman. Page maintained by Jazib Zaman.

Responses (0 )

  • ‌
    ‌
    ‌
    ‌
    ‌
    ‌
  • ‌
    ‌
    ‌
    ‌
    ‌
    ‌
  • ‌
    ‌
    ‌
    ‌
    ‌
    ‌