9sBlog

Why Does My Website Say Not Secure?

The 'Not secure' warning means your site has no valid HTTPS certificate. Here is what it means, how owners fix it, and what visitors should do about it.

A laptop on a desk showing a website in a browser

“Not secure” in the address bar means the page is served over plain HTTP, or its security certificate is invalid or expired. The connection is not encrypted, so anything typed into it can be read in transit. For a site owner the fix is a TLS certificate and a move to HTTPS; for a visitor it is a reason not to enter a password or a card number. The exact wording depends on the cause: an expired or wrong-date certificate throws a full-page NET::ERR_CERT_DATE_INVALID error in Chrome, while a plain HTTP page instead shows a gray “Not secure” label beside the address.

What the warning actually means

A TLS certificate (often called SSL) does two things: it encrypts the traffic between the browser and the server, and it confirms the site is really being served for that domain. Without a valid one, Chrome and Edge mark the site “Not secure.” A common surprise is a site that installed a certificate and still shows the warning — that is usually mixed content, where an otherwise secure page still loads some images or scripts over HTTP.

CauseWhat you seeFix
No HTTPS at all“Not secure” on every pageInstall a certificate
Expired certificateWarning or a full error pageRenew it
Mixed content“Not secure” after adding SSLLoad every asset over HTTPS

If it’s your site

Get a certificate — most hosts offer a free one through Let’s Encrypt with a one-click toggle in the control panel — then force an HTTPS redirect so every visitor lands on the secure version, and set the certificate to auto-renew before it expires. Finally, fix any mixed content by updating hard-coded http:// links to https://. On WordPress, nine steps to secure the site covers this alongside the other basics.

If you’re just visiting

Treat “Not secure” as a stop sign for anything private: do not enter a password, card number, or personal details on that page. It does not always mean the site is malicious — a plain blog over HTTP is not dangerous to read — but the connection is exposed. A padlock alone is not proof a site is trustworthy either, since scammers get certificates too, so also check whether a website is legit, and be extra careful on shared networks — see whether public Wi-Fi is safe. Browsers are getting stricter, too: Chrome is moving toward a full-page warning before it loads any HTTP site, on by default later in 2026.

For owners, a free certificate plus an HTTPS redirect clears the warning for good — an afternoon’s job at most. For visitors, “Not secure” plus a login form is the moment to close the tab.

Common questions

Is it safe to enter a credit card on a “Not secure” website?

No. A plain-HTTP page is not encrypted, so a card number or password can be read by anyone on the same network. Treat it as a stop sign for anything private; a plain blog you are only reading is lower risk, but never submit payment or login details.

How do I fix the NET::ERR_CERT_DATE_INVALID error on my site?

That error means the certificate has expired or its dates are wrong. Renew or reissue it — most hosts offer free Let’s Encrypt certificates that auto-renew — confirm the server clock is correct, then reload, and the error clears once a valid certificate is served.

Why does my website still say not secure after I installed an SSL certificate?

This is almost always mixed content: the page loads over HTTPS but still pulls some images or scripts over HTTP. Update those hard-coded http:// links to https:// so every asset loads securely, and the warning goes away.

Does a “Not secure” warning affect my Google ranking?

Only modestly. Google has treated HTTPS as a lightweight ranking signal since 2014, and from October 2026 Chrome plans to warn before loading any HTTP site by default, so the larger cost is lost visitor trust rather than a direct ranking penalty.

Discussion

    Leave a comment