Why Does My Website Say "Not Secure"? SSL Warnings Explained for Small Business Owners

A customer mentions your website says "Not Secure" right next to the address, or you noticed it yourself while checking your site on your phone. Either way, it is unsettling: does this mean you got hacked? Is customer data at risk? Usually neither. Most of the time it means one specific, well-understood thing is missing, and it is one of the more straightforward fixes on this whole blog - often free, and rarely more than an hour of work.

What the "Not Secure" warning actually means

Every browser, Chrome, Safari, Firefox, and Edge, checks whether a page loads over HTTPS, the encrypted version of the connection between your visitor's device and your server. HTTPS scrambles the data in transit so nobody sitting on the same network, coffee shop Wi-Fi, an airport hotspot, can read or tamper with what gets typed into your site: names, emails, card numbers, anything in a form. Plain HTTP has none of that protection, so browsers flag it in plain language right in the address bar.

"Not Secure" is not a claim that your site is infected or that your business did something wrong. It is a factual label: this specific connection is not encrypted, or something about the encryption is broken. The three situations that trigger it are almost always one of a short list, covered below.

Why browsers show this warning now

This was not always the norm. HTTPS used to be reserved for login pages and checkout forms, and a plain HTTP site with a neutral, unlabeled address bar was completely ordinary. That changed starting in 2018, when Chrome began actively labeling any page without HTTPS as "Not Secure," rather than staying silent about it. Every other major browser followed the same approach within a couple of years. The web's default flipped: encrypted is now assumed, and anything else gets called out.

Google had already been nudging the web in this direction for years before that. Back in 2014, Google announced that HTTPS would count as a ranking signal in search results, a small one at first, explicitly to encourage more sites to adopt it. That signal is still part of how Google evaluates pages today.

The three usual causes

1

No SSL certificate installed at all

The site is still running on plain HTTP. Nothing is technically broken, it was simply never set up with an SSL/TLS certificate, which is the credential a server presents to prove it is who it says it is and to unlock the encrypted connection. This is the most common cause on older sites and ones built by a DIY tool years ago that never migrated.

The fix: install a certificate. Most hosts now offer this for free.

2

The certificate expired

SSL certificates are not permanent. They are issued for a fixed window, often 90 days for the free ones, and need to renew automatically or manually before that window closes. A site that had HTTPS working fine for months can suddenly start showing "Not Secure" or a scarier certificate-error page the day the old certificate lapses, usually because a renewal step silently failed.

The giveaway: the warning appeared out of nowhere on a site that used to be fine.

3

Mixed content

The page itself loads over HTTPS, but it pulls in an image, a script, or a stylesheet from an old HTTP link buried in the page code, often left over from a redesign or a copy-pasted embed. The browser sees that one insecure piece and downgrades its trust in the whole page, sometimes labeling it "Not Secure" and sometimes showing a smaller warning icon depending on what exactly is unencrypted.

The fix: find every hardcoded http:// reference in your page code and change it to https://.

Why it costs you real customers, not just looking bad

The warning sits directly next to your web address, which means every single visitor sees it before they read a word of your homepage. For a business that depends on people trusting it enough to fill out a form, book online, or enter payment details, that is a bad first impression at the worst possible moment. Some visitors will not even understand what it means technically, but they understand the color and the word "Not Secure" well enough to hit the back button.

It also affects whether people find you in the first place. Since Google's 2014 announcement, HTTPS has stayed part of how Google evaluates a page for search ranking. It is a modest factor next to content quality and backlinks, but it is one more small disadvantage stacked against a site that already has bigger fish to fry, and it is one of the cheapest to remove entirely.

How to check your own site

Open your website in a new browser tab and look at the address bar. A plain padlock icon with no extra label means you are fine. If instead you see the words "Not Secure," a padlock with a small warning triangle, or a red padlock with a line through it, something on this page needs attention. Click the icon in most browsers and it will tell you specifically what it found, including whether the certificate is missing, expired, or valid but undermined by mixed content.

That is also exactly the kind of thing our free audit flags automatically, alongside speed, SEO, accessibility, and security, translated out of technical jargon and into what it actually means for your business.

The fixes, in order of how common they are

Frequently asked questions

What does "Not Secure" mean on a website?

It means your browser is loading the page over plain HTTP instead of encrypted HTTPS, or it found a valid HTTPS connection undermined by an expired certificate or unencrypted content mixed into an otherwise secure page. Chrome, Firefox, Edge, and Safari all flag this in the address bar so visitors know before they type anything into the page.

Does a "Not Secure" warning hurt my Google ranking?

Yes. Google has used HTTPS as a ranking signal since 2014, and it has repeated that guidance many times since. It is a small factor next to content and links, but on top of the ranking hit, the warning also scares away the visitors who do land on your page, so the real cost is usually the lost trust and lost conversions, not the ranking penalty alone.

How much does it cost to fix a "Not Secure" warning?

Often nothing. Most hosting providers now include a free SSL certificate through Let's Encrypt, and turning it on is usually a setting in your hosting dashboard, not a purchase. The remaining work, like fixing mixed-content warnings or setting up a redirect from HTTP to HTTPS, is typically a short, one-time cleanup.

How do I check if my website has an SSL problem?

Look at your own site's address bar. A padlock icon with no warning means you are fine. A "Not Secure" label, a padlock with a warning triangle, or a red crossed-out padlock all mean something needs attention. Our free audit checks this along with speed and SEO and tells you plainly what is wrong.

The cheapest way to find out

Run the free audit below. We check your site's SSL setup, along with speed, SEO, accessibility, and security, using the same tooling browsers and Google use, and email you a plain-English report of exactly what is wrong and how it gets fixed. If something needs fixing, it is a flat $149 for your fixable speed/image/SEO/broken-link issue, or $299 for everything, with before-and-after proof once it is done.

Find out if your site has security warnings - free

Enter your website and email. We'll run the full speed, SEO, accessibility, and security audit with Google's own tooling and email you the report within the hour.