Why does your website say "not secure"?
The padlock in the address bar means the page is sent encrypted. Without it, the browser writes "not secure" next to your address, and that is the first thing a new customer sees.
How the checker measures it
The site answers over https. Visitors and Google see it as secure.
The site has no https. Browsers warn your visitors, and Google prefers showing secure sites.
This check carries 15 of 100 points.
Why it matters
Chrome and Safari mark sites without https as "not secure". It makes no difference that you only have a contact page. The warning looks the same as on a site trying to trick people.
Google has preferred secure sites in its results for many years. Two equal sites, and the one with the padlock ranks higher.
Forms on a site without https are sent in plain text. If a customer types their phone number on your site, it can be read along the way.
How to fix it
- Log in to your web host and look for SSL or https. With most hosts it is switched on in the control panel, often at no cost.
- Turn on redirection from http to https so that old links land in the right place.
- Check that every image and script loads over https. A single http image is enough to make the padlock disappear.
- Run the checker again. The row should be green.
https is included from day one, in the Start package as well as in a one-off build. See what it costs.
What it looks like in practice
A common situation: the site was built a few years ago, it works, and nobody has touched it since. The address starts with http. On a phone it says "not secure" to the left of the address, and on a computer Chrome writes the same words out in full. The owner never sees it, because they open the site from a bookmark and never look at the top line.
The checker does one thing here. It fetches the page over https and sees whether the server answers. If it does not, the row turns red, and the check carries 15 of 100 points, the same as mobile and contact details. There is no half mark. Either the site can be reached securely or it cannot.
The second common situation is halfway there. The certificate exists, but old links still point at the http address, or an image or a script loads over http inside a page that is otherwise secure. The padlock can then disappear on that one page while the front page looks spotless.
The fix is rarely big. With most hosts the certificate is switched on from the control panel, and after that it is the redirect and the old links that take the time.
Questions and answers
Do I have to pay for https?
With most hosts the certificate is part of the subscription and is switched on with a button in the control panel. If your provider charges extra for it, it is worth asking why, because the free option has been standard for many years.
I do not sell anything on the site, does it matter anyway?
Yes. The browser warning looks the same whatever the page contains, and it meets the visitor before they have read a line. And if you have a form, what comes in is sent in plain text.
What happens to my old http links?
They keep working if you turn on redirection from http to https, which is a couple of clicks with most hosts. Without the redirect the site sits on two addresses at once, and anyone arriving from an old link gets the warning.
Free site check
How healthy is your website, really?
Enter your web address and I'll check the page right away: secure connection, mobile-friendliness, load time, visibility on Google, and contact paths. You get a score from 0 to 100 and see exactly where it falls short. Free, and no account needed.
✓ Want the full review? I'll go through the site in depth and come back with a plan, free and with no obligation.
✓ Thanks! The full review will land in your inbox shortly.
I personally look at every site that's submitted. Albin
The other checks
The checker looks at nine things. Each has its own page.
