How to Fix "Not Secure" Warnings and Mixed Content Errors

If your browser shows "Not Secure", a broken padlock, or a "Your connection is not private" page, visitors may leave before your site even loads. If your site is hosted with Instant Access Internet Services, this guide helps you find the cause and fix "Not Secure" warnings and mixed content errors on your website.

First, work out which warning you have

What you seeUsual cause
A full-page warning such as "Your connection is not private" or "Warning: Potential Security Risk Ahead"No valid certificate for that exact name, or it has expired
"Not Secure" in the address bar, and the address starts with http://The site isn't being forced to HTTPS
The address starts with https:// but there's no padlock or a warning iconMixed content: some images, scripts or styles load over http://

Fix 1: Make sure you have a valid certificate

  1. In cPanel, go to Security > SSL/TLS Status.
  2. Check that both example.com and www.example.com show a valid certificate.
  3. If either is unsecured, read the error in the Certificate Status column and see Free SSL Certificates: How AutoSSL and SSL/TLS Status Work. AutoSSL runs automatically several times a day, so once the cause is fixed the certificate usually appears within a few hours.

Just changed nameservers? The certificate can't be issued until DNS points to us. Give it a few hours (DNS Propagation: Why Domain Changes Take Time and How to Check).

Fix 2: Force HTTPS

A certificate alone doesn't send visitors to the secure version. In cPanel, go to Domains > Domains and turn on Force HTTPS Redirect for your domain. Full steps are in How to Force HTTPS on Your Website.

Fix 3: Find and fix mixed content

Find the insecure items

  1. Open the page in Chrome, Edge or Firefox.
  2. Press F12 (or right-click the page and choose Inspect) and open the Console tab.
  3. Reload the page. Look for "Mixed Content" messages. Each one lists the http:// address of an image, script, font or stylesheet.

Free online scanners such as "Why No Padlock" or JitBit's SSL check can also list them for you.

Fix it on a WordPress site

  1. Log in to WordPress and go to Settings > General.
  2. Make sure WordPress Address (URL) and Site Address (URL) both start with https://. Save.
  3. Old posts and pages may still contain http://example.com links to images. Use a search-and-replace plugin (for example Better Search Replace) to replace http://example.com with https://example.com in the database. Back up first (How to Back Up and Restore WordPress in WP Toolkit).
  4. Check your theme and page builder settings, widgets and custom HTML blocks for hard-coded http:// addresses, including logos and background images.
  5. If you use LiteSpeed Cache, go to LiteSpeed Cache > Toolbox and click Purge All so visitors get the fixed pages.

Fix it on a hand-built (HTML/PHP) site

  1. In cPanel, open Files > File Manager and edit the files the console pointed to (How to Edit a File in cPanel File Manager).
  2. Change http:// to https:// in src and href addresses, or use relative paths like /images/logo.png for your own files.
  3. If an item comes from another website that doesn't support HTTPS, download a copy to your own site or find a secure replacement.

Optional safety net

You can ask browsers to upgrade leftover http:// requests automatically by adding this line to the .htaccess file in public_html:

Header always set Content-Security-Policy "upgrade-insecure-requests"

This only works if the other site also serves the file over HTTPS, and it hides the real problem, so fix the links too.

Common questions

The padlock is fine on the home page but not on other pages

Mixed content is per page. Check the pages that show the warning with the browser console.

It's fixed on my computer but a visitor still sees the warning

Their browser may have the old page cached. Ask them to reload with Ctrl+F5 (Cmd+Shift+R on Mac) or try a private window. Also purge your site's cache.

The warning is on mail.example.com or in my email app

Use the server name shown on your account's Connect Devices page. secure.instantaccess.net always has a valid certificate. See How to Find Your Email Settings with Connect Devices.

Related guides

Still stuck? Open a support ticket and the Instant Access Internet Services team will help.

Ultrafast LiteSpeed hosting from InstantAccess.net: free SSL, free backups, cPanel included, no contracts. Check out our $10/month hosting.
  • not secure warning website, fix mixed content, mixed content wordpress, padlock missing https, your connection is not private, ssl warning chrome
  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

How to Use Microsoft 365 or Google Workspace Email with Your Domain

You can keep your website with us and use Microsoft 365 (Outlook) or Google Workspace (Gmail) for...

Our Nameservers: How to Point Your Domain to Your Hosting

To make your website and email work on your hosting account, your domain has to point to the...

DNS Propagation: Why Domain Changes Take Time and How to Check

When you change your nameservers or edit a DNS record, some people see the change right away...

How to Set Up Dynamic DNS in cPanel

Dynamic DNS (DDNS) lets you reach a device on a home or office connection, such as a camera, NAS...

Free SSL Certificates: How AutoSSL and SSL/TLS Status Work

Every hosting account includes free SSL certificates, so your website loads over HTTPS with a...