LochStudios  /  Help Centre  /  Troubleshooting  /  Fix "Not secure" and mixed-content warnings

Fix "Not secure" and mixed-content warnings

Clear Not secure and mixed-content warnings with AutoSSL on our shared hosting, Certbot on a VPS, and leftover http:// URLs updated to https://.

Updated

Not secure in the address bar, and mixed content in the console, are two different jobs.

  • Not secure (or a full-page certificate warning) means the browser did not accept a certificate for this name. The page is still on HTTP, or the certificate is missing, expired, or for a different hostname.
  • Mixed content means the page itself loaded over HTTPS, then asked for an image, script, stylesheet, or font over plain http://. The padlock is there, then the browser warns or blocks those files.

On Beginner and Standard shared hosting (cPanel) in Australia, AutoSSL issues a Let's Encrypt certificate once the name points at this account. Open cPanel from the portal. Do not guess a hostname.

On a VPS, install TLS yourself with Certbot. Credentials and the console are on that server in the portal.

On a dedicated server, open a support ticket and we will walk you through a certificate.

Unsure which warning you have, or a step is unclear? Open a support ticket and we will help.

Background: Understanding SSL/TLS and HTTPS.

See what the browser is telling you

  1. Open the exact URL visitors use, including www if that is how people type it.
  2. Look at the address bar.
  3. Click the padlock, the warning icon, or the Not secure label and read the certificate details.

Typical cases:

What you seeWhat it usually meansWhere to start
Not secure on http://yourdomain.comNo HTTPS redirect, or no certificate yetShared hosting: AutoSSL, then Force HTTPS Redirect
Full-page warning, name does not matchYou opened a hostname the certificate does not coverConfirm DNS, then run AutoSSL for that name
Full-page warning, expiredThe certificate on this name has lapsedShared hosting: run AutoSSL again. VPS: renew with Certbot
Padlock, but images or layout missingMixed content: leftover http:// filesFix the URLs on the site
Padlock, console shows mixed contentSame as above, even if the page still looks fineFix the URLs on the site

You can also open Developer Tools (F12, or right-click then Inspect), then the Console tab. Mixed content is listed there with the exact http:// URL the page requested.

To read the public certificate from outside your own cache, use SSL Labs. Enter the hostname. Wait for the grade. A missing or unmatched name shows up there even when your laptop still has an old answer.

Shared hosting: issue or refresh the certificate

The name must already resolve to this account. AutoSSL proves control over HTTP. If DNS still points elsewhere, no certificate is issued.

If the domain is registered with us, it is already on AtlasDNS. Open Domains → the domain → DNS in the portal and keep the A records for @ and www on this account's shared IP (cPanel General Information → Shared IP Address).

If the domain is registered elsewhere, set its nameservers to ours, then manage records in the portal:

ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au

AtlasDNS is the default. Do not send the domain to a third-party DNS host. Full steps: Point your domain at your hosting. Changes are often quick, but they can take a while to show everywhere. See DNS propagation explained.

Then:

  1. Sign in at the portal, open the hosting service, and click Log in to cPanel.
  2. Open SSL/TLS Status.
  3. Find the domain and www (and any addon, alias, or subdomain you need).
  4. Run AutoSSL if a certificate is not there yet, or if the row is expired or missing names. Wait for a valid cert on that row.
  5. In cPanel Domains, turn Force HTTPS Redirect on for that name.
  6. Visit https://yourdomain.com and https://www.yourdomain.com in a private window.

You do not need a 301 in Redirects for same-host HTTP to HTTPS. See Set Up a Domain Redirect. Do not paste a RewriteRule into .htaccess as the first HTTPS step. Force HTTPS Redirect is the control on this hosting.

Stay on AutoSSL. Do not buy a certificate from another CA as the first step. If you already have a certificate and key file we need to install, open a support ticket.

Skip CAA records unless you have a reason. A CAA that names the wrong issuer stops AutoSSL. If you want one set, open a support ticket. See DNS record types explained.

If SSL/TLS Status still shows no certificate after the name has resolved here, open a support ticket. Tell us the domain.

You do not restart Apache on shared hosting. AutoSSL installs the certificate on the account. After a valid row appears, reload the site in a private window.

The name on the certificate must match the URL

AutoSSL issues Domain Validation certificates for the specific names on this account that already resolve here (the apex, www, addons, aliases, subdomains). It does not issue a * wildcard.

If the warning says the certificate is for a different hostname:

  1. Click the warning and read the names the certificate covers.
  2. Confirm you are visiting a name that is supposed to live on this account.
  3. For a new subdomain, addon, or alias, add it in cPanel first, point DNS at this account, then run AutoSSL again on SSL/TLS Status.
  4. Check both the apex and www. Visitors often type one while the certificate only has the other until AutoSSL has run for both.

Do not delete a working certificate as a first try. Run AutoSSL for the name you actually use.

VPS

There is no AutoSSL on a stock VPS. Install a certificate on the server. Certbot (Let's Encrypt) is the usual path: Get a Free SSL Certificate with Certbot.

Point the name at the VPS IPv4 shown on that service in the portal first. Open 80 and 443 on the host firewall. See Set up a UFW firewall on Ubuntu and First steps on a new VPS.

After Certbot installs a certificate it reloads the web server for you. If you edited the vhost by hand, reload Apache or Nginx from the shell on that VPS.

An expired Certbot certificate usually means the renewal timer is off. Follow the renewal section in the Certbot article, or open a support ticket and we will walk through the server with you.

Mixed content: the page is HTTPS, the files are not

Once the padlock is there, leftover http:// URLs are the usual reason the browser still complains. Scripts and stylesheets loaded over HTTP are often blocked. Images may show a warning and still appear, or they may not.

Force HTTPS Redirect sends visitors to https://. It does not rewrite http:// URLs inside the page. Those leftover addresses are mixed content.

Find the insecure URL

  1. Open the site over https://.
  2. Open Developer Tools (F12), then Console.
  3. Look for a line that names an http:// image, script, stylesheet, or font.
  4. Note that URL. That is the file you need to change.

HTML and static files

  1. Sign in at the portal, open the hosting service, and click Log in to cPanel.
  2. Open the File Manager on the site's document root (public_html for the primary domain).
  3. Search for http://.
  4. Change resource URLs (images, CSS, JS, fonts, embeds) to https:// when that host actually serves HTTPS. Prefer a root-relative path (/images/logo.png) when the file lives on this site.
  5. Save and reload in a private window.

Do not change http:// inside comments, example text, or a third-party endpoint that is HTTP-only. If an external host has no HTTPS, replace that asset or drop it.

An FTP client works the same way. See Create an FTP Account and Connect.

WordPress

  1. In cPanel Domains, turn Force HTTPS Redirect on.
  2. In WordPress go to Settings → General. Set WordPress Address and Site Address to the https:// URLs, then save.
  3. Posts, widgets, and theme options often still store the old http:// site URL. Prefer a tool that understands serialised PHP. A raw replace in every table can break widgets. Better Search Replace (Plugins → Add New) is the usual in-dashboard tool. Find http://yourdomain.com and replace with https://yourdomain.com. Run a dry run first.
  4. Hardcoded http:// in the active theme or a custom plugin still needs a File Manager edit.

Prefer WordPress Toolkit or Installatron for a new site. More HTTPS steps: Secure Your WordPress Site. Moving a site and rewriting URLs: Back Up and Migrate a WordPress Site.

To change only the two core options (home and siteurl) while you get into wp-admin, use phpMyAdmin. Then finish the rest of the URLs with Better Search Replace.

If you are not comfortable changing the database, open a support ticket. Tell us the domain. We will help.

Embeds and third-party files

  • Images on another domain: use that host's https:// URL, or upload the file to this account.
  • Fonts, maps, videos, analytics, and ads: use the current HTTPS embed from that service.
  • Old http:// video, map, or font links are a common leftover after a site is moved to HTTPS.

A page that only works because mixed content is allowed is not finished. Fix the URLs.

Verify the fix

  1. Open https://yourdomain.com and https://www.yourdomain.com in a private window.
  2. Confirm the padlock. The certificate should match the name, show a future expiry, and name a trusted CA (Let's Encrypt on AutoSSL and Certbot).
  3. Open the console again. Mixed-content lines should be gone.
  4. Optional: run the hostname through SSL Labs.

If the padlock is missing only on your PC, flush the local DNS cache and try another network. See This site can't be reached.

What renews on its own

  • AutoSSL renews Let's Encrypt certificates on shared hosting. You do not upload a file or mark a calendar date.
  • Certbot on a VPS renews with its timer. Keep that timer enabled.
  • A certificate we installed from a file you supplied does not renew itself. Open a support ticket before it expires if you need a replacement installed.

If a site collects a login, an email, or a card number, leave Force HTTPS Redirect on.

Need hosting first? Browse shared hosting, VPS, or dedicated. After the account is ready: Getting started after you order hosting.

If it is still not secure

Open a support ticket and include:

  • The exact URL (apex, www, or subdomain)
  • Whether you see Not secure, a full-page warning, or mixed content
  • The wording from the browser or the console
  • Whether SSL/TLS Status already shows a valid certificate (shared hosting)
  • Any recent DNS, domain, or site-URL change

We will check the certificate and the leftover URLs with you.

Do not wait on an email thread. Open a support ticket and we will help.

Related


Was this article helpful?

← Back to Troubleshooting